Privacy Policy

Last updated: 2 August 2026 · pursuant to arts. 13 and 14 of Regulation (EU) 2016/679 («GDPR»)

Versione italiana

Courtesy translation. This English text is provided for convenience only. The Italian version is the only legally binding text: in case of any discrepancy, the Italian version prevails.

In short. Telaio apps collect the bare minimum: whoever browses a venue's app does not register and does not provide any name, email or phone number; the loyalty card works with a random device code, never with a person's identity. Data resides in the European Union. No profiling, no advertising, no selling of data to third parties.

1. Who processes the data (the two roles)

The Telaio platform is provided by Studio Corocher di Antonio Corocher, Via Adamello 15, 31029 Vittorio Veneto (TV), Italy — VAT no. IT04743350268. Privacy contacts: [email protected] · Certified email (PEC): [email protected]

2. What data we process — venue customers

A venue's app can be browsed without registration. No name, email or phone number is requested or collected. The only data processed are:

We use no third-party analytics, advertising, profiling or cross-site tracking.

3. What data we process — business owners

4. Why, and on what legal basis

5. Where the data resides, and who processes it for us

Our systems are provided by qualified operators, appointed as processors or sub-processors:

ProviderWhat it doesWhere
SupabaseDatabase and authenticationEuropean Union — Frankfurt, Germany (eu-central-1)
CloudflareApp publishing, content delivery network, photo storageGlobal network with EU presence; safeguards under arts. 44 ff. GDPR (standard contractual clauses / EU-U.S. Data Privacy Framework)
StripeBusiness owners' paymentsEU/USA — EU-U.S. Data Privacy Framework

Any transfers outside the EU take place only with the safeguards provided by the GDPR (adequacy decisions or standard contractual clauses).

6. For how long

7. Cookies and on-device storage

Telaio apps use technical means only, necessary for operation — for which no consent banner is required. Consent is needed for non-essential cookies (third-party analytics, advertising pixels, tracking): there are none here.

Cookies

NamePurposeDuration
tlo_devtagRandom device identifier, for offers and the loyalty card (anonymous, not linked to a person)12 months
tlo_sessKeeps the venue manager signed in to the Manager, so they need not log in on every open (their device only; readable by the server alone)30 days, renewed at every sign-in
fh_gateRemembers that the password for a protected preview was entered — only where that protection is switched onWorking session
CloudflareSecurity cookies of the network that serves the apps (protection against abuse and attacks)See Cloudflare's own policy

Storage on the device (these are not cookies)

The app keeps some things on the device of the person using it, so it works without a connection and opens immediately. They are not sent to us, we do not read them, and they are removed by clearing the browser's data or uninstalling the app:

WhatWhat it is for
A copy of the venue's contentShowing menus, rooms and services offline and without waiting for the network
Preferences (language, light/dark theme)Finding the app as you left it
The anonymous device identifier, offers already used and offers awaiting confirmationMaking offers and the loyalty card work without asking for any personal data
Photos and app files already downloadedNot downloading them again every time
On the venue manager's phone only: the login session, the Reserved Area code, and a note that there are unsaved changesStaying signed in, protecting the management area, and not losing work if the connection drops

No profiling, third-party analytics or advertising cookies, and no external analytics tool (Google Analytics, social pixels, third-party widgets): that is a choice, not an oversight, and if it ever changed this page would change with it. Payment happens on Stripe's pages, where Stripe's own cookie policy applies.

8. Your rights

You have the right to request access to your data, rectification, erasure, restriction of processing, portability, and to object to processing (arts. 15–22 GDPR), as well as to withdraw consent at any time. Write to [email protected]: we reply within 30 days. You may also lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it).

An honest note: loyalty card data cannot be traced back to an identified person — that is its virtue. For this reason, under art. 11 GDPR, we may be unable to link it to you in order to fulfil an individual request; we can however always delete the data linked to your device's code, if you point it out to us.

9. Security

All communications travel over encrypted connections (HTTPS). Passwords are stored encrypted and unreadable; access to data is governed by database-level access controls (per-business isolation). Our systems are hosted with the providers listed in art. 5, with professional-grade security measures.

10. Minors

Venue apps are simple showcases that anyone can browse, and they collect no identifying data. The service is in any case not aimed at children under 14, and we do not knowingly collect their data.

11. Updates to this policy

This policy may be updated, for example as the service evolves. The version in force, with its update date, is always available at this address.