Skip to main content
GDPR Article 13 Information Notice

Privacy Policy & Personal Data Protection Notice

Last updated: September 2026 • Regulation (EU) 2016/679 (GDPR) & Italian Privacy Code (D.Lgs. 196/2003 as amended by D.Lgs. 101/2018)

PRIVACY CONTROLLER INFORMATION REQUIRED — PRE-PUBLICATION NOTICE

Engineering privacy safeguards, data minimization, and security controls are active. Before commercial legal publication, the business owner must supply the verified legal entity name, Partita IVA (VAT number), registered office address, and dedicated privacy contact email/PEC as documented in docs/24-privacy/owner-information-required.md.

1. Identity and Contact Details of the Data Controller

This service operates under the brand Luggage Storage 193 at two physical reception branches in Naples, Italy:

  • Branch A (Centro Storico): Via dei Tribunali 193, Napoli (NA), Italy
  • Branch B (Duomo / Port): Via Duomo 88, Napoli (NA), Italy
  • Operational Telephone:

Legal Entity / Owner Name: PRIVACY CONTROLLER INFORMATION REQUIRED

VAT / Partita IVA: PRIVACY CONTROLLER INFORMATION REQUIRED

Dedicated Privacy Contact / PEC: PRIVACY CONTROLLER INFORMATION REQUIRED

Data Protection Officer (DPO): Not appointed (no mandatory designation trigger under GDPR Art. 37 applies to this luggage storage operation, subject to owner confirmation).

2. Categories of Personal Data Processed

Following strict data minimization principles (GDPR Art. 5(1)(c)), we collect and process only the personal data strictly necessary for the requested service:

  • Reservation & Contact Data: Customer full name (customer_full_name), email address (customer_email), telephone number (customer_phone_number), preferred language (en, it, fr, or de), selected storage branch, drop-off date, drop-off time, declared bag count, and generated reservation reference code (LS193-*).
  • Payment & €5 Deposit Data: Deposit status (EUR 5.00), internal payment UUID, Stripe Checkout Session identifier (cs_*), Stripe webhook event identifier (evt_*), and payment timestamps. We never collect, process, or store raw payment card numbers (PAN), CVC security codes, or card expiration dates; all payment credentials are entered directly on Stripe-hosted Checkout.
  • Smart Location Coordinates (Transient Only): When you explicitly click “Use my location”, your browser provides one-time latitude and longitude coordinates via navigator.geolocation.getCurrentPosition(). Raw coordinates are processed solely in volatile memory to calculate distance to our two Naples branches using the local Haversine formula and are never persisted in any database, never stored in cookies or Web Storage, and never written to server logs.
  • Group & Transfer Inquiries: The online group inquiry calculator validates your inputs locally in the browser and generates a direct link to contact our staff via WhatsApp or telephone. It does not persist inquiry records in a backend database.
  • Technical & Security Data: Cryptographic SHA-256 hashes of client-generated reservation access tokens (access_token_hash) and payment return tokens (return_token_hash), request correlation IDs (X-Request-ID), idempotency keys, and, for internal staff login protection only, transient SHA-256 hashes of username|remoteAddress held in memory for 15 minutes to prevent brute-force attacks.

The selected language is stored in browser sessionStorage as preferred-language. The booking lookup can store the reservation reference and email as ls193_booking_recovery for the current browser session; clear session storage on a shared device.

We do not rely on generic “blanket consent” where contract performance or legitimate security interests apply. Each processing activity relies on a specific legal basis under GDPR Article 6(1):

Purposes of processing and GDPR Article 6 legal bases
Processing Activity & PurposeData CategoriesGDPR Legal Basis
Creating a reservation draft, holding branch capacity, and identifying the customer at physical drop-offFull name, email, phone number, branch, date/time, bag count, reference codeArt. 6(1)(b) — Pre-contractual measures and performance of a contract requested by the data subject
Processing the €5.00 online reservation deposit via Stripe Checkout and sending the transactional booking confirmation emailReservation reference, €5.00 EUR amount, customer email, locale, Stripe session/event IDsArt. 6(1)(b) — Performance of a contract
Fiscal, tax, and statutory accounting compliance for paid depositsPayment records, timestamps, reservation referencesArt. 6(1)(c) — Compliance with legal obligations under Italian tax and civil law
One-time Smart Location branch distance recommendation upon explicit user clickTransient latitude/longitude in volatile memory (0 persistence)Art. 6(1)(b) — User-initiated pre-contractual feature request (distinct from browser OS permission prompt)
Preventing unauthorized access to drafts, webhook replay protection, rate-limiting login abuse, and auditing staff access to customer contact recordsSHA-256 token hashes, correlation IDs, non-PII admin audit recordsArt. 6(1)(f) — Legitimate interest in application security and data protection (Art. 32 GDPR)

Note on Browser Geolocation Permission: Granting permission in your web browser’s native geolocation prompt is a technical device/browser control under ePrivacy rules and is not treated as blanket GDPR consent. Because coordinates are used solely once in memory to answer your explicit request for the nearest branch and are never stored, no persistent processing occurs.

4. Mandatory vs. Optional Data Provision

Providing your full name, email address, telephone number, branch selection, drop-off date/time, and bag count is necessary to create an online reservation draft and complete the €5 deposit checkout. If you do not provide these details, we cannot register your online booking or send your confirmation receipt, though you may still inquire in person at our reception counters subject to walk-in availability.

Using the Smart Location recommender is completely optional. Declining browser location access does not restrict your ability to view both branches or complete a reservation.

5. Recipients and Categories of Recipients

Personal data is never sold, rented, or shared with advertising networks or data brokers. Access to customer contact details within our internal administration console is restricted to authorized staff holding the explicit reservation.contact.read permission, and every view or search is recorded in an immutable security audit log.

  • Payment Service Provider (Stripe): When you initiate the €5.00 deposit payment, our backend creates a Checkout Session with Stripe Payments Europe, Ltd. (1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland). We transmit only the €5.00 EUR deposit amount, the internal reservation_reference metadata, and the return URLs. We do not transmit Draft-Access-Token, customer phone numbers, or geolocation coordinates to Stripe. Stripe processes card credentials under its Privacy Policy and Data Processing Agreement (Stripe DPA).
  • Transactional Email Delivery Provider: Used solely to deliver booking confirmation emails via SMTP (SmtpEmailGateway). Status: PRODUCTION EMAIL PROVIDER CONFIGURATION REQUIRED (simulated locally via DevEmailGateway/Mailpit in non-production environments).
  • Hosting & Database Infrastructure: Hosts the application server and PostgreSQL database. Status: PRODUCTION HOSTING CONFIGURATION REQUIRED.
  • External Communication Links (WhatsApp / Telephone / Google Maps): Clicking external links to WhatsApp (wa.me), Instagram, Facebook, or Google Maps directs your browser to those third-party services under their respective privacy terms. No third-party social or WhatsApp tracking SDKs are embedded on our website.
  • Map & Walking Routing Providers: Currently NONE. External routing and geocoding providers are unconfigured in production runtime; distance calculations run locally using the Haversine formula without transmitting coordinates to Google Maps, Mapbox, or OpenRouteService.

6. International Transfers Outside the EEA

All web fonts (Plus Jakarta Sans, Playfair Display, and Caveat) and static assets are self-hosted directly on our first-party origin so your browser does not transmit your IP address to external font CDNs during browsing.

Where payment processing via Stripe Payments Europe, Ltd. involves sub-processing or technical transfers to Stripe, Inc. in the United States, such transfers are governed by the EU-U.S. Data Privacy Framework (DPF) (European Commission Adequacy Decision of 10 July 2023) and the European Commission’s Standard Contractual Clauses (SCCs) incorporated into the Stripe Data Processing Agreement.

7. Data Retention Criteria

RETENTION DECISION REQUIRED (OQ-P1-015)

Exact retention schedules for reservation drafts, completed bookings, and security audit logs require formal sign-off from the business owner and tax accountant before commercial launch. No unapproved deletion period is claimed.

  • Smart Location Coordinates: 0 seconds persistence (discarded from memory immediately after distance calculation).
  • Capacity Holds for Unpaid Sessions: Expire automatically after 15 minutes (PT15M).
  • Admin Session & Login Rate-Limit State: Admin sessions expire after 30 minutes of inactivity; in-memory failed login counters expire after 15 minutes.
  • Paid Reservation & Accounting Records: Subject to statutory Italian tax and civil retention obligations (e.g., Art. 2220 Italian Civil Code) upon accountant confirmation.

8. Your Rights Under GDPR (Articles 15–22)

Under Regulation (EU) 2016/679, you have the right to request from the Data Controller:

  • Right of Access (Art. 15): Obtain confirmation of whether your personal data is processed and receive a copy of your reservation record.
  • Right to Rectification (Art. 16): Correct inaccurate contact details or booking metadata.
  • Right to Erasure (Art. 17): Request deletion or anonymization of personal data where retention is no longer necessary for contract execution or statutory fiscal/legal defense obligations.
  • Right to Restriction of Processing (Art. 18): Request temporary restriction of processing during a dispute or verification check.
  • Right to Data Portability (Art. 20): Receive personal data provided under contract in a structured, commonly used, machine-readable format.
  • Right to Object (Art. 21): Object at any time to processing based on legitimate interests (Art. 6(1)(f)).

To exercise your rights, please contact our support team referencing your reservation code (LS193-*) and the email address used during booking so we can verify your identity proportionately without requesting unnecessary identity documents.

Right to Lodge a Complaint (Art. 77): If you believe the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the Italian Data Protection Supervisory Authority: Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Roma (https://www.garanteprivacy.it), or the supervisory authority of your EU Member State of habitual residence or place of work.

9. Automated Decision-Making, Profiling & Cookies

We perform zero automated decision-making or behavioral profiling within the meaning of GDPR Article 22. For detailed technical information about browser storage and cookies, please consult our dedicated Cookie Policy.