Privacy policy

**Last updated: 27 July 2026**

This Privacy Policy explains how Home Ecosystems SrL collects and uses personal
data when you visit home-ecosystems.com, buy or request products and services,
contact us, create a Home Ecosystems app account, use optional cloud services,
or otherwise interact with Home Ecosystems.

Who is responsible for your data

The data controller is:

Home Ecosystems SrL 
Via San Margherita 117  
22010 San Bartolomeo Val Cavargna  
CO, Italy  
General and legal email: info@home-ecosystems.com  
Support email: support@home-ecosystems.com  
Telephone: +41 79 742 65 73  
REA: CO - 434793  
VAT / Partita IVA: 04302350139  
Codice Fiscale: 04302350139

For privacy questions or requests, email support@home-ecosystems.com with the
subject “Privacy request”. If a data protection officer is appointed, this
policy will be updated with the relevant contact details.

Separate website and app accounts
A Shopify customer account used on our website and a Home Ecosystems app
account are separate accounts. Creating, changing or deleting one does not
automatically create, change or delete the other. If you want both accounts
deleted, identify both in your request.

Most local controller setup and control can be used without a Home Ecosystems
app account. An app account is required for account-linked features such as
verified subscriptions, controller ownership and optional remote services.

Personal data we collect
Depending on how you use our services, we may collect:
- **Identity and contact data:** name, email address, billing and shipping
  address, telephone number if provided, account identifiers and communication
  preferences.
- **Order and transaction data:** products or services ordered, quotations,
  order status, payment status, taxes, delivery, returns and refunds. Payment
  card details are processed by the applicable payment provider; we generally
  receive confirmation and transaction references rather than full card data.
- **Website and Shopify account data:** account details, cart and checkout
  activity, browser/device information, IP address, cookie identifiers, consent
  choices and site interactions.
- **App account data:** authentication identifiers, email address, account
  status, accepted service-term versions and subscription entitlements.
- **Controller and service data:** controller identifier, model, firmware
  version, capabilities, ownership or membership, cloud permissions, connection
  status and service events.
- **Operational ecosystem data:** only when an applicable cloud feature is
  enabled, this may include configured channel or sensor names, channel state,
  sensor readings, ecosystem values, alerts, history and command acknowledgments.
- **Support and diagnostic data:** messages, attachments and diagnostic records
  you choose to send, plus security, error and service logs needed to investigate
  a problem.
- **Marketing data:** your consent and preferences and, if you opted in,
  engagement with messages.
- **PlantArt project data:** project requirements, site information,
  measurements, photographs, approvals and installation or delivery details
  supplied for a quotation or commission.

Do not send us Wi-Fi passwords, controller passwords, certificate private keys
or other secrets in email or support attachments. Local network and controller
credentials used by the app are intended to remain on your device or controller
and are not part of ordinary cloud telemetry.

How we collect data
We collect data:
- directly from you when you order, register, configure, contact or instruct us;
- from the website, app, controllers and cloud services when you use them;
- from Shopify, payment providers, Apple or Microsoft when they confirm a
  transaction or subscription event;
- from delivery, installation and support partners where needed to complete a
  contract; and
- from security and service providers that help us prevent abuse and operate the
  services.

Why we use data and our legal bases
We use personal data where necessary:
- **to perform a contract or take requested pre-contract steps**, including
  quotations, orders, delivery, app authentication, controller ownership,
  subscription entitlement, remote services and support;
- **to comply with legal obligations**, including tax, accounting, product
  safety, consumer protection, fraud prevention and responding to lawful
  requests;
- **for legitimate interests**, including securing accounts and controllers,
  preventing abuse, maintaining and improving reliability, handling complaints,
  protecting legal claims and understanding aggregated service performance,
  where those interests are not overridden by your rights;
- **with your consent**, for optional marketing, non-essential cookies or
  tracking, and other processing for which consent is required; and
- **to protect vital interests** in the exceptional circumstances where that
  legal basis applies.

We do not use ecosystem readings or controller activity for targeted
advertising. We do not make decisions producing legal or similarly significant
effects about you solely by automated processing.

Cloud monitoring, remote control and history
Home Ecosystems is designed to operate locally. Optional remote features use
account, entitlement and per-controller permissions.

When remote monitoring or control is enabled, operational messages may pass
through an encrypted cloud messaging service. A remote command contains the
information needed to identify the controller and requested action; the
controller publishes an acknowledgment or resulting state so the app can show
the outcome.

Live operational messages are not intended to be a permanent history. If a
history or analytics feature is enabled for your plan, selected roll-ups and
sensor or ecosystem measurements may be retained for up to 12 months, unless a
shorter period is required by your settings, account status or law. Credentials,
private keys and Wi-Fi passwords are not intended to be included in operational
history.

Sharing and service providers
We share only the data reasonably needed for the relevant purpose. Categories
of recipients may include:

- **Shopify**, which hosts the online shop, checkout and Shopify customer
  accounts;
- **payment providers** used at checkout;
- **Apple and Microsoft**, for app distribution, in-app purchases,
  subscription management and store-provided transaction events;
- **Supabase**, for app authentication, account and controller relationships,
  entitlements and related backend functions;
- **Amazon Web Services**, for authorised Internet of Things messaging and
  related cloud infrastructure;
- **Resend or the currently disclosed email provider**, for transactional email
  such as account confirmation, password reset, service and alert messages;
- **carriers, fulfilment, installation and service providers**, to deliver or
  perform an order;
- **professional advisers, insurers, auditors and public authorities**, where
  reasonably necessary or legally required; and
- **a purchaser or successor**, subject to appropriate safeguards, in a genuine
  reorganisation, financing, acquisition or sale of the business.

Providers act under their own terms where they are independent controllers, or
under processing arrangements where they process data on our behalf.

If you follow an external link, such as Buy Me a Coffee, a social network or an
independent seller, that service processes data under its own privacy policy.

International transfers
Some providers may process data outside Italy or the European Economic Area.
Where required, we rely on an adequacy decision, approved contractual
safeguards such as the European Commission's standard contractual clauses, or
another lawful transfer mechanism. You may contact us for information about the
applicable safeguards.

Retention
We keep personal data only for as long as needed for the stated purpose and
applicable legal obligations. In particular:

- order, invoice, tax and accounting records are retained for the period
  required by applicable Italian and other mandatory law;
- app account and controller-association data are retained while the account is
  active and then deleted or restricted, except where a limited record is
  required for law, security, fraud prevention or legal claims;
- optional history is retained for up to 12 months unless a shorter period
  applies;
- security and diagnostic logs are retained for a limited period proportionate
  to reliability, security and investigation needs;
- support and project correspondence is retained while needed to perform the
  request and establish or defend legal claims; and
- marketing data is retained until you withdraw consent or object, subject to a
  minimal suppression record needed to honour that choice.

Backups may retain deleted data for a limited rotation period before secure
overwriting. During that period, backup data is isolated from ordinary use.

Cookies and similar technologies
The website uses technologies needed for security, navigation, cart, checkout,
language, customer account and consent preferences. Where required by law,
non-essential analytics, personalisation or advertising technologies are used
only after consent.

You can use the website's privacy or cookie controls to change optional choices.
Browser settings can also block cookies, but blocking essential cookies may
prevent checkout or account features from working.

Before publication, Home Ecosystems will verify that the cookie banner, Shopify
Customer Privacy settings, installed apps and pixels match this disclosure.

Communications
We send transactional messages needed for an account, order, subscription,
controller service, security event, requested alert or support case. These are
not marketing messages.

We send marketing only where permitted and, where required, with consent. You
can unsubscribe using the link in a marketing message or by contacting us.
Unsubscribing from marketing does not stop necessary service communications.

Security
We use organisational and technical measures intended to protect personal data,
including access controls, encrypted connections, per-device cloud
authorisation and secret-management procedures. No system can guarantee
absolute security.

You are responsible for protecting your email and store accounts, controller
passwords, local network and devices. Contact us promptly if you believe an
account or controller has been compromised.

Your rights
Subject to the conditions and exceptions in applicable law, you may have the
right to:

- access your personal data;
- correct inaccurate or incomplete data;
- request erasure;
- restrict processing;
- receive certain data in a portable format;
- object to processing based on legitimate interests and object at any time to
  direct marketing; and
- withdraw consent without affecting processing that was lawful before
  withdrawal.

Email support@home-ecosystems.com with the subject “Privacy request”. We may ask
for information reasonably needed to verify your identity and protect the
account. There is no charge in ordinary cases.

You may delete a Home Ecosystems app account through the app or the account
deletion page. Deleting an app account does not cancel an Apple or Microsoft
subscription and does not automatically delete a separate Shopify customer
account.

You also have the right to lodge a complaint with the Italian supervisory
authority:

**Garante per la protezione dei dati personali**  
https://www.garanteprivacy.it

You may instead contact the supervisory authority in the EU/EEA country where
you live or work, or where you believe an infringement occurred.

Children
Our shop, products, commissions and account-linked services are not directed to
children. A person placing an order or accepting paid service terms must have
the legal capacity to do so. A parent or guardian should contact us if they
believe a child supplied personal data without appropriate authorisation.

Changes to this policy
We may update this policy to reflect product, provider, legal or operational
changes. The current version and its effective date will be published here.
Where a material change requires notice or consent, we will provide it through
an appropriate channel before the change takes effect.

Contact
Privacy questions and requests: info@home-ecosystems.com or
support@home-ecosystems.com  
Postal address: Home Ecosystems SrL, Via San Margherita 117, 22010 San
Bartolomeo Val Cavargna, CO, Italy.