Latte e Menta SRLS

Privacy and cookies

Information on personal data processing under Articles 12 and 13 of Regulation (EU) 2016/679.

Updated 1 August 2026

1. Data controller

The controller is Latte e Menta Società a Responsabilità Limitata Semplificata, registered office Via Carso 60, 30013 Cavallino-Treporti (VE), Italian tax and VAT no. 04420290274, REA VE-412447. Contact: latteementasolutions@gmail.com; certified email lattementaemanuel@pec.it.

2. Personal data we process

Depending on the service used, we may process:

  • technical browsing data, including IP address, time, requested URL, user agent, device, security and diagnostic logs;
  • contact data such as name, email, phone/WhatsApp number and message content;
  • rental data, including dates, chosen model, delivery or pickup place and information entered in BookYourRent;
  • tour data, including name, email, WhatsApp contact, language, number and height of riders, bike preference, optional accommodation and a child’s weight when needed to verify child-seat safety limits;
  • order and payment data, including tour, departure, amount, status and identifiers. Latte e Menta does not receive the full card number, which is collected directly by Stripe;
  • measurement data, only with consent, including pages, interactions, funnel events, online identifiers and campaign parameters such as UTM, gclid, gbraid and wbraid.

3. Purposes and legal bases

Website, security and abuse prevention

service delivery and the controller’s legitimate interest in security, continuity and legal defence.

Enquiries, quotations, rentals and tours

pre-contractual steps and performance of the requested contract.

Payments, receipts and accounting

performance of the contract and compliance with legal, tax and administrative obligations.

Email, phone and WhatsApp support

contract, pre-contractual steps or legitimate interest in managing the customer relationship.

Site analytics and campaign measurement

consent, withdrawable at any time through Cookie settings.

Booking data is not used for newsletters or direct marketing without a separate legal basis and specific information.

4. Providers and recipients

Data may be processed by authorised staff and necessary service providers, appointed as processors where required:

Cloudflare / OpenAI Sites

hosting, network, HTTPS, security and technical logs

Privacy ↗
Google

Tag Manager, GA4 and Google Ads after consent; Apps Script, Sheets and email for schedules, orders and messages

Privacy ↗
BookYourRent – Tecnosoft Informatica SRL

e-bike availability, prices and rental booking management

Privacy ↗
Stripe

checkout, payments, fraud prevention, refunds and transaction data

Privacy ↗
WhatsApp Ireland / Meta

communications voluntarily started by the user

Privacy ↗

Data may also be disclosed to accountants, advisers, payment institutions or authorities when required by law, a contract or legal defence. Data is not sold or publicly disclosed.

6. Retention

  • enquiries not linked to a booking: normally up to 12 months after closure;
  • bookings, payments, accounting records and legal claims: for the statutory period, normally up to 10 years;
  • GA4 user- and event-level data: up to 14 months under the property setting;
  • cookie preferences: 6 months unless deleted earlier by the user;
  • technical and security logs: for the period strictly needed and under provider schedules.

After these periods, data is deleted or anonymised unless further retention is required by law or a dispute.

7. Transfers outside the EEA

International providers may process data outside the EEA. Transfers rely on an adequacy decision, the EU-US Data Privacy Framework where applicable, Standard Contractual Clauses or another mechanism under Articles 44 et seq. GDPR. Provider notices contain further details.

8. Your rights

Where applicable, you may request access, rectification, erasure, restriction, portability and objection, and withdraw consent for the future. Contact latteementasolutions@gmail.com. You may also lodge a complaint with the Italian Data Protection Authority.

9. Children

Bookings must be made by an adult. Information about participating children is supplied by a parent or guardian and is used only to organise the service and verify child-seat safety requirements.

10. Security and required data

We use risk-appropriate technical and organisational safeguards, including HTTPS, access controls and provider checks. Mandatory data is needed to respond or complete a booking; without it the requested service may not be available.

11. Updates

This notice may change when services, providers or applicable law change. The date above identifies the current version. Material changes will be highlighted and consent requested again where required.

Back to home