BestFirenze
EatStayVisitShop
Legal

Privacy Policy

Last updated: January 2025

At BestFirenze, we are committed to protecting your privacy and handling your personal data transparently and responsibly. This policy explains what data we collect, why we collect it, how we use it, and the rights you have under the EU General Data Protection Regulation (GDPR) and applicable Italian data protection law.

Contents

  1. 01Who We Are (Data Controller)
  2. 02Data We Collect
  3. 03Legal Basis for Processing
  4. 04How We Use Your Data
  5. 05Data Sharing & Third Parties
  6. 06International Data Transfers
  7. 07Data Retention
  8. 08Your Rights Under GDPR
  9. 09Cookies & Tracking Technologies
  10. 10Security Measures
  11. 11Children's Privacy
  12. 12Changes to This Policy & Contact
01

Who We Are (Data Controller)

BestFirenze operates BestFirenze.com, a curated travel discovery platform for Florence, Italy. For the purposes of EU and Italian data protection law, BestFirenze is the data controller responsible for your personal data. If you have questions or concerns about this policy or how we process your data, you can contact our data protection contact at privacy@bestfirenze.com.

02

Data We Collect

We collect the following categories of personal data: • Account data — your name, email address, and hashed password when you register. • Profile data — any optional information you add, such as a bio or profile photo. • User content — reviews, ratings, photos, and place suggestions you submit. • Usage data — pages visited, search queries, clicks, feature interactions, and time spent on the platform. • Technical data — IP address, browser type and version, operating system, device identifiers, and referring URLs. • Communication data — messages you send us via email or our contact form. We do not collect sensitive categories of personal data (such as health, racial, or political data), and we do not store financial or payment information on our servers.

03

Legal Basis for Processing

We process your personal data on the following legal bases under GDPR Article 6: • Contract performance (Art. 6(1)(b)) — to create and manage your account and provide the services you have requested. • Legitimate interests (Art. 6(1)(f)) — to improve our platform, ensure security, prevent fraud, and develop new features, where these interests are not overridden by your fundamental rights. • Consent (Art. 6(1)(a)) — for optional marketing communications and non-essential cookies. You may withdraw consent at any time without affecting the lawfulness of prior processing. • Legal obligation (Art. 6(1)(c)) — to comply with applicable laws and respond to lawful requests from authorities.

04

How We Use Your Data

We use your personal data to: • Provide, operate, and maintain the BestFirenze platform. • Personalise place recommendations based on your search history and saved favourites. • Send service-related notifications, including account confirmations and security alerts. • Send optional newsletters or updates about Florence and the platform, if you have explicitly consented. • Analyse aggregate usage patterns to improve platform performance and user experience. • Detect, investigate, and prevent fraudulent activity, abuse, and violations of our Terms of Service. • Comply with legal obligations and respond to lawful requests from courts or authorities.

05

Data Sharing & Third Parties

We share personal data only where necessary, with the following categories of recipients: • Infrastructure — Supabase (database hosting; EU region). Your data is stored on Supabase's EU-hosted Postgres infrastructure. • Hosting — Vercel (CDN and serverless functions; EU-compliant infrastructure available). • Authentication — Google OAuth is offered as an optional sign-in method; if used, it is governed by Google's Privacy Policy. • Analytics — Plausible Analytics, a privacy-first, cookieless analytics tool that processes no personally identifiable information and collects only aggregate traffic statistics. • AI enrichment — OpenAI API is used solely to generate place descriptions from public information; no user personal data is included in these requests. We never sell your personal data to third parties, and we do not share your data with advertising networks or data brokers.

06

International Data Transfers

Our primary database infrastructure is hosted within the European Economic Area (EEA). Where any data is transferred outside the EEA — for example, via Vercel's global edge network or OpenAI's US-based servers — we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission under GDPR Article 46, or we rely on an adequacy decision by the Commission. You may request details of the specific safeguards applied to any transfer by contacting privacy@bestfirenze.com.

07

Data Retention

We retain your personal data only as long as necessary for the purposes for which it was collected: • Account data — held for the duration your account is active, then deleted within 30 days of account closure. • User content (reviews, photos) — retained until you delete the content or close your account. • Server access logs — automatically purged after 90 days. • Database backups — held on a rolling 30-day cycle and then overwritten. • Email communications — retained for up to 2 years for correspondence records. After applicable retention periods, data is securely deleted or irreversibly anonymised.

08

Your Rights Under GDPR

As a data subject under GDPR, you have the following rights: • Right of access (Art. 15) — request a copy of the personal data we hold about you. • Right to rectification (Art. 16) — request correction of inaccurate or incomplete data. • Right to erasure (Art. 17) — request deletion of your personal data ('right to be forgotten'), subject to legal exceptions. • Right to restriction (Art. 18) — ask us to restrict processing of your data while a dispute is resolved. • Right to data portability (Art. 20) — receive your data in a structured, machine-readable format. • Right to object (Art. 21) — object to processing based on legitimate interests, including for direct marketing. • Right to withdraw consent — for any processing based on consent, withdraw at any time without affecting prior processing. To exercise any right, email privacy@bestfirenze.com. We will respond within 30 days. You also have the right to lodge a complaint with the Italian Data Protection Authority: Garante per la Protezione dei Dati Personali, Piazza Venezia 11, 00187 Rome, Italy — www.garanteprivacy.it.

09

Cookies & Tracking Technologies

We use a minimal set of cookies and tracking technologies: • Essential cookies — required for user authentication, session management, and security (e.g., CSRF protection). These are set automatically and cannot be disabled without affecting core platform functionality. • Plausible Analytics — our analytics provider is cookieless by design; it does not set any cookies, does not collect personally identifiable information, and is fully GDPR-compliant without requiring a cookie consent banner. We do not use advertising cookies, retargeting pixels, or third-party social media tracking scripts. You can manage and delete cookies at any time through your browser settings.

10

Security Measures

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or alteration: • All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher. • Data at rest is encrypted by our infrastructure providers (Supabase, Vercel). • Access to production systems is restricted to authorised personnel only, using role-based access controls. • Passwords are never stored in plain text; we use industry-standard hashing algorithms. • We conduct regular security reviews and follow responsible disclosure practices. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform affected users without undue delay, as required by GDPR Article 33-34.

11

Children's Privacy

BestFirenze is not directed at children under the age of 16. We do not knowingly collect personal data from children. Under GDPR Article 8, the processing of a child's personal data in the context of information society services is lawful only where the child is at least 16 years old, or where consent is given or authorised by a parent or guardian. If you believe that a child under 16 has provided us with personal data without appropriate parental consent, please contact privacy@bestfirenze.com immediately and we will take prompt steps to delete the data.

12

Changes to This Policy & Contact

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated by email to registered users and by posting a prominent notice on the platform at least 14 days before the changes take effect. The 'last updated' date at the top of this policy indicates when it was last revised. Continued use of BestFirenze after the effective date of changes constitutes your acceptance of the updated policy. For any questions, requests, or complaints regarding this policy: Data Controller: BestFirenze · Florence, Italy Email: privacy@bestfirenze.com Supervisory Authority: Garante per la Protezione dei Dati Personali · www.garanteprivacy.it

BestFirenze · Florence, Italy · privacy@bestfirenze.com

Discover authentic Florence — from hidden osterie to Renaissance masterpieces. Curated by locals who know the city's heartbeat.

Made withamorein Florence

Explore

Discover

Get Started

© 2026 BestFirenze. All rights reserved.

BestFirenze
Eat
Stay
Visit
Shop
Collections
About Us
Neighborhoods
Travel Guides
Blog
Create Account
Sign In
Join BestFirenze
Privacy
Terms
Contact