Privacy Policy
Last updated: October 2026
This Privacy Policy explains how personal data are collected and processed through the website www.trufflehuntintuscany.it, in accordance with Regulation (EU) 2016/679 (“GDPR”) and applicable Italian data protection legislation.
1. Data Controller
The Data Controller is:
SAN GIMIGNANO TRUFFLE EXPERIENCE DI ATTANASIO DOMENICO
VAT No. IT01361170523
Via Antonio Gramsci 16
53037 San Gimignano (SI), Italy
Email: info.sgtruffleexperience@gmail.com
2. Personal Data We Process
Depending on how you use the website, we may process the following categories of personal data:
- name and surname;
- email address;
- telephone number;
- booking date and time;
- number of participants;
- information relating to adults and children included in the booking;
- selected experience;
- booking status;
- information voluntarily entered in booking forms, contact forms or messages;
- information concerning dietary requirements, food allergies or intolerances, where voluntarily provided;
- information relating to requested transportation or pick-up services;
- technical information relating to access to and use of the website;
- referring website, referral source or campaign information;
- information necessary to manage a payment card guarantee;
- communications exchanged in connection with a booking or enquiry.
3. Booking Management and Provision of Services
Personal data are processed in order to:
- receive and manage booking requests;
- confirm, modify or cancel reservations;
- communicate with customers regarding their booking;
- organise and provide truffle hunting experiences;
- organise cooking classes, lunches, wine tastings or other activities included in the selected experience;
- coordinate transportation, pick-up or transfers where included or requested;
- respond to customer requests;
- manage administrative matters connected with the booking.
The legal basis for this processing is the performance of a contract or the taking of steps at the customer’s request prior to entering into a contract, pursuant to Article 6(1)(b) GDPR.
4. Online Booking System – Amelia
The website uses Amelia as its online booking management system.
When a booking is made, information entered by the customer is stored in the website’s WordPress database.
This may include:
- name and surname;
- email address;
- telephone number;
- selected experience;
- selected date and time;
- number of participants;
- booking status;
- additional information voluntarily provided by the customer.
These data are processed for the purpose of managing the reservation and providing the requested service.
5. Contact Forms and Enquiries
The website may collect personal data through contact forms used for information, availability or booking-related enquiries.
If you contact San Gimignano Truffle Experience through the website, by email or through a contact form, the information provided will be processed in order to respond to your request.
Where the request concerns a possible booking or service, the legal basis is Article 6(1)(b) GDPR.
For other general enquiries, processing may be based on the legitimate interest of the Data Controller in responding to communications received, pursuant to Article 6(1)(f) GDPR.
6. Dietary Requirements, Allergies and Intolerances
Some experiences offered through the website include meals, cooking classes, food tastings or wine tastings.
Customers may therefore voluntarily provide information regarding food allergies, intolerances or other dietary requirements.
Such information may constitute special categories of personal data within the meaning of Article 9 GDPR.
These data are processed only where necessary to organise and provide the requested service safely and appropriately.
Customers are requested to provide only information that is relevant and necessary for this purpose.
Such information will not be used for marketing or unrelated purposes.
7. Payment Card Guarantee – Stripe
Certain bookings may require customers to provide a valid payment card as a guarantee.
Payment card information is processed securely through Stripe.
Full payment card details are not stored in the website’s WordPress database.
The website may retain technical identifiers and information necessary to associate the payment method processed by Stripe with the relevant booking and to manage the booking guarantee.
Where the card is requested solely as a booking guarantee, no immediate payment is made unless otherwise expressly stated during the booking process.
The card may be charged only in accordance with the booking, cancellation and no-show conditions communicated to the customer before confirmation.
Stripe processes personal data in accordance with its own privacy and data-protection terms and may act, depending on the processing activity, as a data processor or independent data controller.
8. Combined Experiences and Third-Party Providers
Some experiences offered through the website may include services provided in cooperation with third parties, such as:
- wineries;
- restaurants;
- cooking-class venues;
- farms;
- transportation providers;
- other local activity providers.
Where necessary to provide the booked experience, relevant customer information may be communicated to the provider involved in the service.
Only information reasonably necessary to organise and provide the booked service will be shared.
Depending on the specific service and contractual arrangement, such providers may process personal data as independent data controllers or as service providers acting on behalf of the Data Controller.
9. Transportation and Pick-Up Services
Where a booking includes transportation, pick-up or transfer services, personal data may be processed in order to:
- organise the requested transport;
- identify the pick-up point;
- communicate timing or logistical information;
- coordinate with the transport provider.
Where necessary, relevant booking information may be communicated to the transport provider.
The legal basis is Article 6(1)(b) GDPR.
10. Booking Source and Referral Tracking
The website records information relating to how a customer reached the website or booking page.
This information may include:
- referring website;
- referral domain;
- campaign parameters, including UTM parameters;
- booking source;
- referral type;
- date on which referral information was acquired.
This information may be associated with the relevant booking.
It is used for internal administrative, statistical and commercial purposes, including:
- identifying the source of a booking;
- measuring the effectiveness of promotional or referral channels;
- identifying, where applicable, a commercial or referral partner associated with a booking;
- determining commissions or commercial attribution relating to a booking.
Where technically possible, booking-source information may be transmitted through the booking flow without the use of persistent cookies.
Where the user has provided the relevant cookie consent, the website may also use a first-party attribution cookie to remember the booking source across future visits.
This information is not used for behavioural advertising or cross-site profiling and is not used for automated decision-making producing legal or similarly significant effects on customers.
11. Website Analytics – SlimStat
The website uses SlimStat Analytics to obtain statistical information regarding use of the website.
SlimStat is configured in a privacy-oriented manner.
In particular:
- IP addresses are masked;
- browser fingerprinting is disabled;
- SlimStat does not set its own tracking cookie;
- statistical data are stored locally in the website’s WordPress database;
- analytics data are retained for a maximum of 420 days;
- archived records are not retained after the applicable retention period;
- geographic information is limited to country-level data.
SlimStat may process information such as:
- page views;
- referring websites;
- browser information;
- device information;
- operating system;
- country of origin;
- technical navigation information.
These data are used to understand how the website is used, identify technical issues, evaluate traffic sources and improve the website and its services.
12. Hosting – Aruba
The website and its database are hosted through services provided by Aruba S.p.A.
As a consequence, personal and technical data processed through the website may be stored and processed on the hosting infrastructure used to operate the website.
Aruba may process data where necessary for:
- website hosting;
- database hosting;
- security;
- backups;
- maintenance;
- technical operation of the website.
Where required by applicable data-protection law, Aruba and other providers processing personal data on behalf of the Data Controller act as data processors pursuant to Article 28 GDPR.
13. Email Communications
The website uses email services to send communications connected with:
- booking confirmations;
- booking modifications;
- cancellations;
- customer enquiries;
- availability requests;
- booking reminders;
- logistical information;
- other service-related communications.
The main email address used by the Data Controller is:
info.sgtruffleexperience@gmail.com
Email communications may therefore also involve the technical infrastructure of the relevant email service provider.
14. Technical and Security Data
Technical information may be processed where necessary for:
- ensuring the correct functioning of the website;
- preventing misuse, fraud or unauthorised access;
- diagnosing technical problems;
- maintaining website and booking-system security;
- protecting the website, database and users.
The legal basis for this processing is the legitimate interest of the Data Controller in maintaining a secure and functional website, pursuant to Article 6(1)(f) GDPR.
15. Legal, Accounting and Administrative Obligations
Personal data may be processed where necessary to comply with applicable:
- tax obligations;
- accounting obligations;
- administrative requirements;
- legal obligations;
- requests from competent public authorities.
The legal basis is Article 6(1)(c) GDPR.
16. Provision of Personal Data
The provision of data marked as mandatory during the booking or contact process is necessary to manage the request or reservation.
Failure to provide required information may make it impossible to process the request or provide the requested service.
The provision of optional information is voluntary.
17. Recipients of Personal Data
Personal data may be accessed or processed, where necessary, by:
- persons authorised by the Data Controller;
- Aruba S.p.A. and other hosting providers;
- website developers and technical maintenance providers;
- booking-management software providers;
- Stripe and other payment-service providers;
- email and communication providers;
- wineries, restaurants, cooking-class providers and other activity providers involved in the booked experience;
- transportation providers where applicable;
- accountants, tax advisers and other professional advisers;
- public authorities or other entities where disclosure is required by law.
Access is limited to what is necessary for the performance of the relevant functions.
Where required, service providers acting on behalf of the Data Controller are appointed as data processors pursuant to Article 28 GDPR.
Personal data are not sold to third parties.
18. International Data Transfers
Some service providers used in connection with the website, payment processing, email communications or other technical services may process personal data outside the European Economic Area.
Where personal data are transferred outside the European Economic Area, such transfers are carried out in accordance with Chapter V GDPR.
Where applicable, this may include reliance on:
- an adequacy decision adopted by the European Commission;
- Standard Contractual Clauses;
- other safeguards recognised under applicable data-protection law.
19. Data Retention
Personal data are retained only for as long as necessary for the purposes for which they were collected and for any additional period required by applicable law.
In particular:
- booking data are retained for the period necessary to manage the booking and subsequent administrative, accounting or legal requirements;
- accounting and tax documentation is retained for the periods required by Italian law;
- contact requests that do not result in a booking are retained only for the period reasonably necessary to respond to the request;
- SlimStat analytics data are retained for a maximum of 420 days;
- referral and booking-source information may be retained together with the relevant booking where necessary for administrative, statistical or commercial-attribution purposes;
- security and technical logs are retained for the period reasonably necessary for security and technical-management purposes.
Data may be retained for a longer period where necessary for the establishment, exercise or defence of legal claims.
20. Cookies and Similar Technologies
The website uses cookies and similar technologies for technical, booking-related, statistical and other purposes.
The website may use first-party storage mechanisms to remember information relating to the origin of a booking or referral source.
SlimStat Analytics is configured not to set its own tracking cookie.
Technical cookies and technologies necessary for the operation of the website or for providing a service requested by the user may be used without prior consent where permitted by applicable law.
Where consent is required for a particular cookie or tracking technology, it will be used only after the user has provided the required consent.
Further information about cookies and similar technologies used by the website, including their purposes and duration, is available in the website’s Cookie Policy.
21. Embedded Content and Third-Party Services
The website may display embedded content or services provided by third parties, including:
- maps;
- review widgets;
- external media;
- booking or activity-related content.
These services may process technical information or use cookies or similar technologies.
Where consent is required for such technologies, the relevant third-party content should only be activated after the user has provided the appropriate consent.
22. Automated Decision-Making and Profiling
The website does not carry out automated decision-making producing legal effects or similarly significant effects on users within the meaning of Article 22 GDPR.
The website does not use personal data to create behavioural profiles for automated decision-making of this kind.
23. Rights of Data Subjects
Under Articles 15 to 22 GDPR, depending on the circumstances, you may have the right to:
- obtain confirmation as to whether your personal data are being processed;
- obtain access to your personal data;
- request rectification of inaccurate or incomplete data;
- request erasure of personal data;
- request restriction of processing;
- object to processing based on legitimate interests;
- receive personal data in a structured, commonly used and machine-readable format where the right to data portability applies;
- withdraw consent at any time where processing is based on consent.
Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
Requests regarding personal data may be sent to:
info.sgtruffleexperience@gmail.com
The Data Controller may request information necessary to verify the identity of the person making the request where appropriate.
24. Right to Lodge a Complaint
If you believe that your personal data have been processed in breach of applicable data-protection legislation, you have the right to lodge a complaint with the competent supervisory authority.
In Italy, the competent authority is:
Garante per la Protezione dei Dati Personali
You may also contact the Data Controller directly before submitting a complaint in order to request clarification or resolution of the issue.
25. Changes to this Privacy Policy
This Privacy Policy may be updated from time to time to reflect:
- changes to the website;
- changes to booking or payment systems;
- changes to services offered;
- changes to service providers;
- changes to data-processing activities;
- changes to applicable legislation or regulatory guidance.
The latest version will always be published on this page together with the date of the most recent update.
