Last updated: September 2026
Privacy Policy
Introduction
Amalfi Experience ("we", "us", "our") operates the platform at amalfiexperience.thevincenzolambiase.com. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our services, in accordance with the EU General Data Protection Regulation (GDPR) and Italian data protection law (D.Lgs. 196/2003 as amended by D.Lgs. 101/2018).
Data We Collect
We collect the following personal data when you use our platform:
- Full name
- Email address
- Phone number (optional)
- Payment information (processed securely via Stripe: we never store card details)
- Booking details (dates, preferences, guest count)
- Usage data (pages visited, device type, browser: collected only with your consent)
How We Use Your Data
- Processing and managing bookings for properties and experiences
- Sending booking confirmations, pre-arrival information, and review requests
- Improving our platform and services (only with consent)
- Complying with legal and fiscal obligations
Data for the police
If you stay at a property in the collection, the law requires the host to report every guest’s details to the Questura (art. 109 T.U.L.P.S.). The online check-in exists for that, and for nothing else. The legal basis is a legal obligation (art. 6.1.c GDPR), not your consent: without those details the property cannot host you.
- What is needed: name, surname, sex, date and place of birth, citizenship and, for the lead guest, the type, number and place of issue of the document.
- How we hold it: the document number is encrypted at rest (AES-256-GCM) and nobody reads it in the clear from the database. Without the key, the system refuses the data rather than storing it in the clear.
- The document photo is optional, asked only by hosts who turned it on, and deleted as soon as the host confirms the filing — in any case within seven days of departure (Garante note of 29 April 2026: reporting is not keeping).
- The document number is erased after thirty days. Name, surname and dates stay five years, the time the host must be able to produce the police receipt.
- The data goes to the Polizia di Stato through the Alloggiati Web portal, and to your host. To nobody else.
Location
Your phone’s location is used for one thing: taking a town’s stamp in the coast passport, which is earned by being there. We ask for it only when you press the stamp button, never in the background and never while the site is closed.
- Only on your action, once per stamp. You may refuse: you lose the stamp, not the rest of the site.
- We keep the coordinates of the moment you stamped and the distance from the town centre. We do not reconstruct journeys and we do not follow anyone.
- The photo you attach to a stamp is yours and stays in your passport: we do not publish it and do not show it to anyone else.
- The legal basis is consent, which is the permission you give the browser: withdraw it from your phone’s settings whenever you like.
Data we receive from booking portals
If you booked on Booking.com, Airbnb or another portal, the property may connect that portal’s calendar here. From it we receive the minimum the portal publishes.
- The dates of the stay, the name you gave the portal when the portal passes it on, and the booking reference. We do not receive an email, a phone number, or what you paid.
- It exists to stop the same night being sold twice, and to get the host the filings that are theirs to make anyway.
- The portal’s own processing is theirs and follows their notice: what we do with that data is described here.
Your Rights (GDPR Art. 15-22)
Under the GDPR, you have the following rights regarding your personal data:
- Right of access: request a copy of all data we hold about you
- Right to rectification: correct inaccurate data
- Right to erasure: request deletion of your data ("right to be forgotten")
- Right to data portability: receive your data in a structured, machine-readable format
- Right to object: object to processing based on legitimate interest
Data Retention
We retain your personal data for as long as necessary to fulfill the purposes described above. Booking data is retained for 10 years as required by Italian fiscal law. Account data is deleted within 30 days of account closure. You can request earlier deletion by contacting us.
Security
We protect your data using encryption in transit (HTTPS/TLS), secure password hashing (bcrypt), JWT-based authentication, and strict access controls. Payment data is handled exclusively by Stripe, a PCI DSS Level 1 certified processor.
Contact & Data Protection
For any questions about your data or to exercise your rights, contact us at: