Legal
Privacy Policy
Information on the processing of personal data pursuant to art. 13 of EU Regulation 2016/679 (GDPR) and Legislative Decree 196/2003 as amended by Legislative Decree 101/2018.
Last updated: June 30, 2026
1. Data Controller
The Data Controller for the personal data collected through this website (guesthouselectra.com) is:
Guesthouse Electra
Address: [address to be completed]
VAT / Tax ID: [to be completed]
Email: [email to be completed]
2. Personal data collected
Depending on how you use the site, we collect the following categories of data:
Navigation data
IP address, browser type, operating system, pages visited, access times. Automatically collected by the systems that manage the site's infrastructure (Cloudflare, Amazon CloudFront).
Registration and authentication data
First name, last name, email address, password (in encrypted form), device information, and session data. Voluntarily provided by the user during registration or login via Clerk.
Booking data
First name, last name, email, phone number, stay dates, number of guests, chosen accommodation, any special requests, total amount, and payment method. Voluntarily provided during the booking process.
Payment data
Credit/debit card data is managed exclusively by Stripe, Inc. and is never transmitted to or stored on our systems. We only receive confirmation that the payment was made and a transaction identifier.
WhatsApp contact data
If you use the WhatsApp button on the site, your name, email, and message text are included in the link that opens WhatsApp. From that point on, processing is governed by the Privacy Policy of Meta Platforms, Inc.
3. Purposes and legal bases of processing
Performance of a contract
Managing bookings, processing payments, sending confirmation emails, and communications related to the stay.
Legal obligation
Retention of billing and transaction data for the tax and accounting obligations required by Italian law.
Legitimate interest
Prevention of fraud and abuse, infrastructure security, limiting automated requests (rate limiting).
Consent
Preference cookies (storing booking preferences), analytics cookies, and marketing cookies, activated only after the user's explicit choice through the cookie management panel.
4. Processors and sub-processors
To provide its services, the site relies on the following third-party providers who process personal data on behalf of the Data Controller as Data Processors (art. 28 GDPR):
Clerk, Inc.
United StatesAuthentication and user account management
Data processed: Email, name, session data, device information
Privacy Policy →Stripe, Inc.
United StatesOnline payment processing
Data processed: Transaction data, amount, email; card data is managed directly by Stripe
Privacy Policy →Resend, Inc.
United StatesSending transactional emails (booking confirmation, reminders, review requests)
Data processed: Recipient's email address, email content
Privacy Policy →Convex, Inc.
United StatesDatabase and application backend (storage of bookings, users, payments)
Data processed: All data entered during booking and registration, with the exception of bank details.
Privacy Policy →Cloudflare, Inc.
United StatesWeb traffic protection and optimization
Data processed: IP address, traffic data
Privacy Policy →Amazon Web Services, Inc.
European UnionContent delivery (CDN)
Data processed: IP address, traffic data
Privacy Policy →Google LLC
United StatesDisplay of the interactive map on the "Where we are" page
Data processed: IP address and browsing data transmitted when the Google Maps iframe loads
Privacy Policy →5. Transfer of data to third countries
Some of the providers listed are based in the United States. Data transfers to these countries take place in compliance with the safeguards set out in the GDPR, in particular through Standard Contractual Clauses (SCC) adopted by the European Commission (art. 46 GDPR). Stripe and Clerk also adhere to the EU-U.S. Data Privacy Framework.
6. Retention period
Data is retained for the periods strictly necessary for the purposes indicated:
- Navigation data: a maximum of 30 days in system logs.
- Booking and payment data: 10 years from the date of the transaction, for tax obligations (art. 2220 of the Italian Civil Code and Presidential Decree 633/72).
- Authentication data: for the entire duration of the account; deleted within 30 days of a deletion request.
- Communication emails: 12 months from the date sent.
7. Data subject rights
Pursuant to articles 15-22 GDPR, you have the right to:
- Access — obtain confirmation of processing and a copy of your data;
- Rectification — correct inaccurate or incomplete data;
- Erasure — request deletion ("right to be forgotten"), except where legally required to retain it;
- Restriction — restrict processing under certain circumstances;
- Portability — receive your data in a structured, machine-readable format;
- Objection — object to processing based on legitimate interest;
- Withdraw consent — at any time, without affecting the lawfulness of processing carried out prior to withdrawal.
To exercise your rights, write to [email to be completed]. You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) (www.garanteprivacy.it).
8. Minors
This site is not intended for individuals under 18 years of age. We do not knowingly collect personal data from minors. If you believe a minor has provided personal data without parental or guardian consent, please contact us at the address indicated above.
9. Changes to this policy
The Data Controller reserves the right to modify this policy at any time, including in response to regulatory changes or new technological integrations. Substantial changes will be communicated via a notice visible on the site or by email to registered users. The date of the last update is shown at the top of the document.