Last updated: 20 June 2026
Privacy Policy
Privacy notice under Regulation EU 2016/679 for Travelwithany visitors, users, customers and newsletter subscribers.
Controller and contacts
The data controller is Travelwithany, VAT ID IT03353080215, website travelwithany.com. For privacy requests write to info@travelwithany.com or use the channels on the Contact page.
Data we process
- Identity and contact data: name, surname, email, phone, country.
- Request data: travel dates, travellers, budget, preferences and messages.
- Form anti-spam data: approximate completion time, hidden honeypot field, submission frequency, links and anomalous text patterns.
- Account data: email, profile, role, language, marketing consent, security and login logs.
- Booking data: stay or trip, dates, status, amounts, operational notes and admin communications.
- Newsletter data: email, optional name, language, source and subscription status.
- Technical data: user agent, visited URLs, referrer and proprietary analytics events only after consent. IP addresses are not stored in plain text in the analytics tables designed for the project.
Purposes and legal bases
- Replying to requests and proposals: pre-contractual measures requested by the user.
- Managing accounts, bookings and support: contract or pre-contractual measures.
- Sending newsletters and marketing communications: consent, withdrawable at any time.
- Transactional emails, confirmations, replies and security notices: contract, legal obligations or legitimate security interest.
- Protecting the website, accounts and admin panel: legitimate interest in preventing abuse, fraud and unauthorized access.
- Proprietary analytics: user consent through the cookie/storage banner.
Suppliers and recipients
Data may be processed by technical and operational suppliers required for the service: Supabase for database and authentication, Brevo for email, Render for application hosting, Cloudflare and Cloudflare R2 for CDN, security and media, plus local stays, guides, transfer providers or partners involved in a request or booking.
Media uploaded to Cloudflare R2
Images and videos uploaded by admins are stored on Cloudflare R2 and served through a public CDN domain. Admins must upload only files for which Travelwithany has rights, consent or a valid license, avoiding private documents or unnecessary personal data.
International transfers
Some suppliers may process data outside the European Economic Area. Where this happens, processing relies on appropriate safeguards such as adequacy decisions, standard contractual clauses or equivalent GDPR mechanisms.
Retention
- Contact requests: for the time needed to manage the request and reasonable commercial history.
- Bookings and administrative documents: for applicable civil, tax and accounting retention periods.
- Newsletter: until unsubscribe or consent withdrawal.
- Security and audit logs: for security, abuse prevention and administrative traceability.
- Deleted accounts: profile data is deleted or anonymized except for records that must be retained, including bookings, reviews and submitted requests.
Your rights
You may request access, rectification, erasure, restriction, portability, objection and withdrawal of consent where applicable. You may also lodge a complaint with the Italian Data Protection Authority.
Security
The site uses Supabase authentication, RLS policies, admin roles, audit logging, backend rate limits, form anti-spam controls, logged transactional emails and MFA TOTP planned for admins/super admins on first access. No system is risk-free; relevant incidents will be handled under applicable law.
Legal references
You can consult Regulation EU 2016/679 and the Italian Data Protection Authority.