Courtesy translation. This English text is provided for convenience only. The Italian version is the only legally binding text: in case of any discrepancy, the Italian version prevails.
In short. Telaio apps collect the bare minimum: whoever browses a venue's app does not register and does not provide any name, email or phone number; the loyalty card works with a random device code, never with a person's identity. Data resides in the European Union. No profiling, no advertising, no selling of data to third parties.
1. Who processes the data (the two roles)
The Telaio platform is provided by Studio Corocher di Antonio Corocher, Via Adamello 15, 31029 Vittorio Veneto (TV), Italy — VAT no. IT04743350268. Privacy contacts: [email protected] · Certified email (PEC): [email protected]
- If you are a customer of a venue (you browse or install the app of a restaurant, bar or other business): the data controller is the venue itself, whose contact details you find in its app. Studio Corocher processes the data on its behalf, as data processor (art. 28 GDPR).
- If you are the owner of a business that is a Telaio client (or interested in becoming one): the data controller for your data (account, billing, communications) is Studio Corocher.
2. What data we process — venue customers
A venue's app can be browsed without registration. No name, email or phone number is requested or collected. The only data processed are:
- A random device identifier — an opaque code generated by the system
(technical cookie
tlo_devtag, 12-month duration) that lets offers and the loyalty card work without an account. It contains no personal identifiers and is not linked to any. - Loyalty card and offers — the points collected, the rewards claimed and the offers used, associated only with that random code, with the date of use. The venue only sees aggregate statistics (how many times an offer was used), never an individual profile.
- Card recovery code — a code the user can write down to retrieve their loyalty card on a new device. Also anonymous.
- Push notifications — only if the user explicitly enables them: the technical delivery address provided by the device is stored (never a phone number). They can be disabled at any time from the app's or the phone's settings; on deactivation the address is removed.
- App language — the language the user is reading the app in is stored alongside the delivery address, and serves one purpose only: so a notification arrives in their own language rather than in Italian. It is not linked to a name, email or phone number.
- Stay dates (hotels only, and only if the user enters them) — when they arrive and when they leave, and nothing else: no name, no email, no room number. They exist so the app sends only what concerns the days they are a guest, and so the hotel can send the welcome, the departure information and the review request. The user can change or clear them at any time from the app's settings, and turning notifications off removes them from our systems along with the delivery address.
- Local preferences (app settings) — they stay on the user's device only and never reach our systems.
We use no third-party analytics, advertising, profiling or cross-site tracking.
3. What data we process — business owners
- Manager account: email address and password (stored encrypted and unreadable), business name and details, uploaded content and photos.
- Billing and payments: handled by Stripe; Studio Corocher never sees or stores payment card numbers. For payment data, Stripe acts as an independent controller (see its own policy).
- Communications: emails, WhatsApp messages and contacts exchanged for activation and support.
- Business contacts: for businesses interested in the service, the contact details provided directly or publicly available, used only to propose the service.
- Questions asked through the Manager's help: when you type a question in your own words from a "?" panel, the text is kept together with your business name, the section you were in, and the date. It serves one purpose only: to learn which answers the documentation is missing, and write them. It is not linked to you as a person — we record which business asked, never who. Before sending, the app automatically removes email addresses, telephone numbers and long digit sequences from the text, and the server removes them a second time. The text is deleted after 18 months. If you would rather not leave it, do not use that box — write to Studio Corocher on WhatsApp instead.
4. Why, and on what legal basis
- Providing the service (app, loyalty card, offers, Manager) — performance of a contract (art. 6.1.b GDPR).
- Push notifications — consent (art. 6.1.a), revocable at any time.
- Billing and tax obligations — legal obligation (art. 6.1.c).
- Platform security and aggregate statistics — legitimate interest (art. 6.1.f), with data kept to a minimum and, where possible, anonymous.
5. Where the data resides, and who processes it for us
Our systems are provided by qualified operators, appointed as processors or sub-processors:
| Provider | What it does | Where |
|---|---|---|
| Supabase | Database and authentication | European Union — Frankfurt, Germany (eu-central-1) |
| Cloudflare | App publishing, content delivery network, photo storage | Global network with EU presence; safeguards under arts. 44 ff. GDPR (standard contractual clauses / EU-U.S. Data Privacy Framework) |
| Stripe | Business owners' payments | EU/USA — EU-U.S. Data Privacy Framework |
Any transfers outside the EU take place only with the safeguards provided by the GDPR (adequacy decisions or standard contractual clauses).
6. For how long
- Anonymous loyalty and offer data: as long as the venue is active on the platform; the device cookie lasts 12 months from last use.
- Push notification addresses, app language and stay dates: until the user turns notifications off, clears the dates from the app's settings, or the delivery address technically expires — whichever happens first. They are stored together and removed together.
- Business owner accounts: for the duration of the contract. From account closure, a 30-day window allows a change of mind; then content, photos and logins are deleted permanently.
- Security copies: of the content the owner enters in the Manager (menus, descriptions, opening hours and the like) we keep security copies for a maximum of 15 days, for the sole purpose of recovering from a mistake or a fault. They contain no data beyond what is described above. When an account is deleted, they are deleted with it, within 24 hours.
- Tax and accounting documents: 10 years, as required by law.
7. Cookies and on-device storage
Telaio apps use technical means only, necessary for operation — for which no consent banner is required. Consent is needed for non-essential cookies (third-party analytics, advertising pixels, tracking): there are none here.
Cookies
| Name | Purpose | Duration |
|---|---|---|
tlo_devtag | Random device identifier, for offers and the loyalty card (anonymous, not linked to a person) | 12 months |
tlo_sess | Keeps the venue manager signed in to the Manager, so they need not log in on every open (their device only; readable by the server alone) | 30 days, renewed at every sign-in |
fh_gate | Remembers that the password for a protected preview was entered — only where that protection is switched on | Working session |
| Cloudflare | Security cookies of the network that serves the apps (protection against abuse and attacks) | See Cloudflare's own policy |
Storage on the device (these are not cookies)
The app keeps some things on the device of the person using it, so it works without a connection and opens immediately. They are not sent to us, we do not read them, and they are removed by clearing the browser's data or uninstalling the app:
| What | What it is for |
|---|---|
| A copy of the venue's content | Showing menus, rooms and services offline and without waiting for the network |
| Preferences (language, light/dark theme) | Finding the app as you left it |
| The anonymous device identifier, offers already used and offers awaiting confirmation | Making offers and the loyalty card work without asking for any personal data |
| Photos and app files already downloaded | Not downloading them again every time |
| On the venue manager's phone only: the login session, the Reserved Area code, and a note that there are unsaved changes | Staying signed in, protecting the management area, and not losing work if the connection drops |
No profiling, third-party analytics or advertising cookies, and no external analytics tool (Google Analytics, social pixels, third-party widgets): that is a choice, not an oversight, and if it ever changed this page would change with it. Payment happens on Stripe's pages, where Stripe's own cookie policy applies.
8. Your rights
You have the right to request access to your data, rectification, erasure, restriction of processing, portability, and to object to processing (arts. 15–22 GDPR), as well as to withdraw consent at any time. Write to [email protected]: we reply within 30 days. You may also lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it).
An honest note: loyalty card data cannot be traced back to an identified person — that is its virtue. For this reason, under art. 11 GDPR, we may be unable to link it to you in order to fulfil an individual request; we can however always delete the data linked to your device's code, if you point it out to us.
9. Security
All communications travel over encrypted connections (HTTPS). Passwords are stored encrypted and unreadable; access to data is governed by database-level access controls (per-business isolation). Our systems are hosted with the providers listed in art. 5, with professional-grade security measures.
10. Minors
Venue apps are simple showcases that anyone can browse, and they collect no identifying data. The service is in any case not aimed at children under 14, and we do not knowingly collect their data.
11. Updates to this policy
This policy may be updated, for example as the service evolves. The version in force, with its update date, is always available at this address.