What we collect,
and what we don't.
Short version: we collect your email if you buy something or ask for the weekly email, we store the answers you give the trip planner, and we don't sell anything to anyone. The long version is below because you're entitled to it.
Last updated 30 July 2026Before you publish: replace the bracketed items in section 1 with your registered details. A privacy notice without an identifiable controller is not compliant, and it is the one thing here that cannot be left as a placeholder.
- Who is responsible
- What we collect and why
- Who else processes your data
- Cookies and local storage
- How long we keep things
- Your rights
- Children
- Changes
1. Who is responsible
The data controller is [REGISTERED NAME], [STREET ADDRESS, COMUNE, PROVINCE, ITALY], VAT / P.IVA [NUMBER], trading as Chianti Vivo.
For anything about your data, email ciao@chiantivivo.com. A real person reads it.
2. What we collect and why
| What | When | Why (lawful basis) |
|---|---|---|
| Email address | You subscribe to the weekly email | Your consent. One click to leave. |
| Email, name, country, city | You buy a route pass or concierge package | Performing our contract with you, and tax law. |
| Your planner answers — dates, group, interests, pace, budget | You use the trip planner | Legitimate interest in producing the itinerary you asked for. Not tied to your name unless you buy. |
| The itinerary itself | You save or share a trip | Legitimate interest, so the link you saved keeps working. |
| IP address, browser, pages requested | Every visit, in server logs | Legitimate interest in keeping the site up and stopping abuse. |
We don't sell or rent your data. We don't run advertising trackers, and there is no Facebook pixel or Google Analytics on this site. Buying something does not subscribe you to the weekly email — those are separate, and we record consent for the second one separately.
3. Who else processes your data
We are a small operation and we use other companies to run the parts we shouldn't build ourselves. Each is a processor acting on our instructions.
| Processor | What it does | What it sees |
|---|---|---|
| Netlify | Hosts the site and runs our server functions | IP address, request logs |
| Supabase | Our database | Everything we store: email, orders, itineraries |
| Stripe | Takes payment | Name, email, billing country, card details. We never see or store your card number. |
| Anthropic | Generates the itinerary | Your planner answers and our venue data. Not your name or email. |
| Resend | Sends our email | Your email address and the message |
| Google Fonts | Serves the typefaces | Your IP address, when the page loads |
| CARTO and OpenStreetMap | Map tiles | Your IP address, when you open the map |
| Open-Meteo | Today's weather | Your IP address; we ask about Greve, not about you |
| Wikimedia Commons | Serves photographs | Your IP address, when an image loads |
| Google Maps | Directions, only when you tap a link | Whatever Google normally sees. Their terms apply once you leave us. |
Some of these are based outside the EU or transfer data there. Where that happens it is covered by the European Commission's standard contractual clauses or an adequacy decision. Copies are available from the providers on request.
4. Cookies and local storage
We set no advertising or analytics cookies. There is no cookie banner because there is nothing to consent to.
Two technical exceptions, both stored on your own device and never sent to us:
- If you buy a route pass, we keep a copy of your itinerary in your browser's local storage so the pass still opens with no signal. Clear your browser data and it goes.
- Stripe sets its own cookies on its checkout pages, which are necessary to take a payment safely. That happens on Stripe's domain, under Stripe's policy.
5. How long we keep things
- Purchase records: ten years, because Italian tax law requires it.
- Newsletter address: until you unsubscribe, then removed.
- Saved itineraries: indefinitely, so shared links keep working. Ask and we'll delete yours.
- Server logs: kept by our host for a short period on a rolling basis.
When a purchase record reaches the end of its retention, we strip the personal details and keep only the anonymous financial figures our accountant needs.
6. Your rights
Under the GDPR you can ask us to show you what we hold, correct it, delete it, hand it over in a portable format, restrict what we do with it, or object to it. You can withdraw consent for the weekly email at any time, and every one of those emails has an unsubscribe link.
Email ciao@chiantivivo.com and we'll act within one month. We won't charge you and we won't make it difficult.
If we handle it badly you can complain to the Italian supervisory authority, the Garante per la protezione dei dati personali (garanteprivacy.it), or to the authority where you live.
7. Children
This is a site about wine. It isn't aimed at children and we don't knowingly collect anything from anyone under 16. If you think we have, tell us and we'll delete it.
8. Changes
If we change how any of this works we'll change this page and move the date at the top. If the change is significant and we hold your email, we'll tell you directly rather than hoping you re-read a page you've already read.
This notice describes what the site actually does, written by the people who built it. It is not legal advice, and it has not been reviewed by a lawyer. If you are the operator, have someone qualified check it before you take live payments.