This Privacy Policy describes how personal data of users of the website Ischia Drivers (hereinafter the "Website") is collected, used, stored and protected, in compliance with Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended.
1. Data Controller
The Data Controller is Itiner srl, VAT No. IT05706061214, Secure Viaggi T.O. (Aut. Reg. Campania n. 431 del 17/09/08).
Contact: email info@ischiadrivers.com — phone +39 081.1975.1985.
2. Personal data collected
The Website collects the following categories of personal data:
Data voluntarily provided by the user
- Contact details: first name, last name, email address, international prefix and phone number.
- Passenger details: if different from the person making the booking, first name, last name, email and phone number of the passenger.
- Billing details: company name or first/last name, tax code, VAT number, address, SDI code, certified email (PEC), country.
- Notes and requests: additional information provided by the user during booking (e.g. child seats, pets, special luggage).
Data collected automatically
- Browsing data: IP address, browser type, operating system, device type, pages visited, referrer, date and time of access.
- Cookies and similar technologies: as described in the dedicated cookie section.
Data collected through third-party services
- Payment data: credit card data and other payment instrument details are collected and processed directly by Stripe, Inc. (PCI-DSS certified payment processor). The Data Controller does not have access to full card details.
3. Purposes and legal basis for processing
| Purpose | Legal basis | Data processed |
|---|---|---|
| Execution of the booking and transfer service | Performance of contract (Art. 6.1.b GDPR) | Contact details, passenger details, booking information |
| Payment and refund management | Performance of contract (Art. 6.1.b GDPR) | Contact details, payment data (via Stripe) |
| Invoice and tax document issuance | Legal obligation (Art. 6.1.c GDPR) | Billing details |
| Booking-related communications (confirmation, updates, support) | Performance of contract (Art. 6.1.b GDPR) | Email, phone, name |
| WhatsApp communications (booking confirmation, updates) | Performance of contract (Art. 6.1.b GDPR) | Phone number, name, booking details |
| Transfer assignment to Provider (NCC/Taxi driver) | Performance of contract (Art. 6.1.b GDPR) | Passenger name, pick-up/drop-off location, time, number of passengers |
| Statistical analysis and service improvement | Legitimate interest (Art. 6.1.f GDPR) | Browsing data, anonymised/aggregated data |
| Legal, tax and accounting obligations | Legal obligation (Art. 6.1.c GDPR) | All data as required |
4. Disclosure of data to third parties
Personal data may be disclosed to:
- Transfer Providers (NCC/Taxi drivers): passenger name, meeting point, time, number of passengers and luggage, as necessary for service execution.
- Stripe, Inc. (payment processor): data necessary for payment management. Stripe operates as a data processor under its own privacy policy (stripe.com/privacy).
- Google LLC: through Google Tag Manager, Google Analytics and Google Maps, for traffic analysis and mapping features. Google operates under its own privacy policy (policies.google.com/privacy).
- Spoki S.r.l.: for sending transactional WhatsApp messages related to bookings.
- Technical service providers: hosting, email services, technical support, to the extent strictly necessary.
- Competent authorities: when required by law.
Data is not sold to third parties or transferred for external marketing purposes.
5. Data transfers outside the EU
Some of the third-party services used (Stripe, Google) may involve data transfers to the United States or other non-EU countries. Such transfers are carried out on the basis of safeguards provided by the GDPR, including European Commission adequacy decisions (EU-US Data Privacy Framework) and/or Standard Contractual Clauses (SCCs).
6. Cookies and similar technologies
The Website uses cookies and similar technologies. The categories of cookies used are listed below:
| Cookie | Type | Purpose | Duration |
|---|---|---|---|
sid_vault |
Technical (necessary) | Maintains the cart and booking session. Encrypted, HttpOnly. | 30 days |
lang |
Technical (necessary) | Stores the user's language preference. | 1 day |
PHPSESSID |
Technical (necessary) | Standard PHP server session. | Session |
_gclid |
Marketing | Stores the Google Ads click identifier for conversion attribution. | 7 days |
| Google Analytics / GTM cookies | Statistical / Marketing | Traffic and conversion analysis, managed through Google Tag Manager. | Variable (see Google's policy) |
| Stripe cookies | Technical (necessary) | Anti-fraud and payment management, set by Stripe.js. | Variable (see Stripe's policy) |
Necessary technical cookies do not require consent. For statistical and marketing cookies, consent is requested on first access via the cookie banner.
Users can manage cookie preferences at any time through their browser settings or through the Website's cookie management panel, where available. Disabling technical cookies may impair the functionality of the Website.
7. Data retention period
- Booking and payment data: retained for the time necessary to perform the service and for the following 10 years for tax and accounting obligations, as required by Italian law.
- Billing data: retained for 10 years from the date of issuance of the tax document.
- Browsing data and logs: retained for a maximum of 12 months for analysis and security purposes.
- Cookies: according to the durations indicated in the table above.
8. Data subject rights
Under Articles 15-22 of the GDPR, the user has the right to:
- Access: obtain confirmation of the existence of a processing operation and access their data.
- Rectification: request correction of inaccurate or incomplete data.
- Erasure ("right to be forgotten"): request deletion of their data, within the limits provided by law.
- Restriction of processing: request restriction of processing in certain circumstances.
- Data portability: receive their data in a structured, machine-readable format.
- Objection: object to processing based on the Data Controller's legitimate interest.
- Withdrawal of consent: withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise their rights, users may contact the Data Controller at info@ischiadrivers.com.
Users also have the right to lodge a complaint with the Italian Data Protection Authority — Garante per la protezione dei dati personali (www.garanteprivacy.it).
9. Data security
The Data Controller implements appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration or disclosure. These include: encrypted communications (HTTPS/TLS), encrypted session cookies, use of PCI-DSS certified payment processors, and access to data restricted to authorised personnel only.
10. Changes to this Privacy Policy
The Data Controller reserves the right to amend this Privacy Policy at any time. Amendments take effect from the date of publication on the Website. Users are encouraged to review this page periodically.
Current version: 1.0 — Effective date: June 25, 2026.