1. Data controller
The controller is Latte e Menta Società a Responsabilità Limitata Semplificata, registered office at Via Carso 60, 30013 Cavallino-Treporti (VE), Italian tax and VAT number 04420290274, REA VE-412447. Privacy contacts: latteementasolutions@gmail.com; certified email lattementaemanuel@pec.it.
2. Personal data processed
Depending on the service used, we may process:
- browsing and security data, such as IP address, date and time, requested URL, user agent, device data and diagnostic logs;
- contact data, such as name, email, telephone or WhatsApp number and message;
- rental and tour booking data: name, email, telephone, language, dates and times, selected service or departure, bicycle type and quantity, number of riders and any children or child seats, bicycle preference, pickup or delivery method and delivery address where required;
- contractual and operational data: booking reference, online or back-office source, service status, acceptance and version of terms, operational notes, discounts, amounts, deposits, balances, refunds and Stripe session or payment identifiers;
- service-document and check-in data: riders' names and signatures, status of a parent or guardian and, where another adult accompanies a minor, details of the written authorisation; type and last four digits of the group leader's original identity document; results of operational checks concerning adult status or authorisation of a minor, the internal technical requirement and e-bike control, and child-seat compatibility and fastening;
- authorised back-office user data, such as name, email, role, sign-in events and security logs;
- measurement data, only after consent: pages viewed, interactions, booking funnel events, online identifiers and campaign parameters such as UTM, gclid, gbraid and wbraid.
The booking engine does not request or record measured height, a child's weight, diagnoses, medicines or other health data, and does not retain a copy of an identity document. The internal 165 cm requirement and child-seat limits are checked without recording height or weight. Health data must not be entered in online forms or back-office notes.
Any medical certificate voluntarily submitted for a specific refund request is handled separately from the booking engine, with restricted access and solely to assess the request and any related dispute. In an emergency, only the data strictly necessary for the intervention may be disclosed to rescue services.
3. Purposes and legal bases
We process data to:
- keep the site and booking engine available, secure and resistant to abuse, based on the controller's legitimate interest in security, continuity and the protection of its rights;
- answer enquiries and manage availability, bookings, rentals, tours, check-in, date changes, cancellations and assistance, to take pre-contractual steps and perform the requested contract;
- verify identity, authorisation for minors, bicycle or child-seat compatibility and essential safety conditions, to perform the service and pursue the legitimate interest in the safety of customers, staff and third parties;
- manage payments, refunds, accounting and tax or administrative obligations, to perform the contract and comply with the law;
- create, send and retain confirmations, accepted terms, service documents and evidence of operations, to perform the contract, comply with the law and establish, exercise or defend legal claims;
- send service emails. WhatsApp is used only when the user initiates contact or gives the separate consent requested; consent is optional and can be withdrawn;
- measure site use and campaigns with Google and Meta only after consent, which can be withdrawn at any time in Cookie settings.
Booking data is not used for newsletters or direct marketing without a separate legal basis and notice. A signature acknowledging the privacy notice is not marketing consent.
The service is not designed to collect special-category data. If health information must be processed in a genuine emergency to protect the data subject or another person, processing will be limited to what is necessary and rely on the applicable basis under Article 9 GDPR, including vital interests where its conditions are met.
4. Services, recipients and providers
Data may be processed by authorised personnel and service providers appointed as processors where required, including:
- Cloudflare for DNS, network, HTTPS, security, Workers, D1 database, Queues and technical logs of the booking engine;
- OpenAI Sites for publication and technical management of the main site while that service remains in use;
- Google for Google Tag Manager, Google Analytics 4 and Google Ads after consent, and Gmail and Apps Script for service emails. The new booking engine's booking data and operational calendar are stored in D1, not Google Sheets;
- Stripe for hosted Checkout, payment methods, fraud prevention, refunds and transaction data. Latte e Menta does not receive the full card number;
- Meta Platforms Ireland for Meta Pixel after advertising consent and WhatsApp for user-initiated or separately authorised communications. The first release of the new booking engine does not include automated WhatsApp delivery;
- BookYourRent / Tecnosoft Informatica SRL only for any historical or transitional rental bookings still held in the former service; it must not receive new bookings after the complete cutover.
Data may also be disclosed to accountants, advisers, payment institutions, insurers where involved, authorities or other parties when required by law, contract or legal defence. Data is not sold or publicly disclosed.
5. Payments and automated decisions
Payment takes place on Stripe's hosted page. Stripe may run automated fraud checks under its own notice. Latte e Menta does not make solely automated decisions producing legal or similarly significant effects; availability, safety and operational suitability may still be checked manually.
7. Retention
- enquiries not connected to a booking: normally up to 12 months after closure;
- unpaid, expired or abandoned booking attempts: up to 12 months, unless needed longer for a specific dispute;
- completed bookings or bookings cancelled after a contract was concluded, payments, refunds, accepted terms, service and check-in documents: for the period required by contractual, accounting and tax duties and legal defence, normally up to 10 years;
- medical certificates submitted for a refund request: only as long as needed to decide the request and deal with a dispute, then deleted or redacted unless retention is required by law;
- service messages and delivery evidence: for the period linked to the booking or legal defence;
- optional consents and evidence of their management: until withdrawal and, for evidence only, for the applicable limitation period thereafter;
- GA4 user- and event-level data: up to 14 months under the property settings;
- cookie preferences: 6 months, unless deleted earlier by the user;
- back-office sessions and technical or security logs: only as long as needed for security and under provider retention terms.
After these periods, data is deleted or anonymised unless the law or an ongoing dispute requires further retention.
8. Transfers outside the EEA
International providers may process data outside the EEA. Transfers rely, as applicable, on an adequacy decision, the EU-US Data Privacy Framework, standard contractual clauses or another mechanism under Articles 44 et seq. GDPR. Further details are available in each provider's notice.
9. Data-subject rights
Where applicable, data subjects may request access, rectification, erasure, restriction, portability and objection, and withdraw consent without affecting earlier lawful processing. Contact latteementasolutions@gmail.com. A complaint may also be lodged with the Italian Data Protection Authority.
10. Minors
An adult must make the booking. A minor rider's parent, person exercising parental responsibility or guardian signs; another accompanying adult must present specific written authorisation from the persons legally entitled to give it. Only the information necessary to verify that status or authorisation is recorded. For children in child seats, we record the number, not weight or health data.
11. Required data and security
Mandatory data is needed to answer, create the booking, take payment or perform the service. Analytics, advertising and WhatsApp consents are optional and refusal does not prevent booking.
We use measures appropriate to the risk, including HTTPS, limited and separated access, two-step authentication for the Stripe team, least-privilege keys, back-office controls, administrative audit events and personal links that are not intended for publication. The original identity document is inspected only; no copy is acquired or attached.
12. Personal document links
Confirmations and service documents may be provided through a personal link. Recipients must keep it secure and not publish it. If it is misdirected, lost or suspected of unauthorised access, contact Latte e Menta immediately so that appropriate measures can be taken.
13. Updates
This notice may change when services, providers or applicable rules change. The date above identifies the current version. Material changes will be highlighted and consent requested again where required.
