Cinque Terre Trip

Privacy Policy | Cinque Terre Trip

1. Introduction

This Privacy Policy describes how the Cinque Terre Trip website (available at https://www.cinqueterretrip.info) manages the processing of personal data of users who visit it.

This notice is provided pursuant to Art. 13 of EU Regulation 2016/679 (hereinafter “GDPR” - General Data Protection Regulation) and the applicable Italian legislation on the protection of personal data.

Cinque Terre Trip is a personal informational project dedicated to tourism and useful information about the Cinque Terre. Data processing is guided by the principles of fairness, lawfulness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality, and accountability.


2. Data Controller

The Data Controller for personal data processing is:

(As this is a personal project managed by a private individual, no VAT number or certified email address (PEC) is present.)


3. Definitions

For the purposes of this Privacy Policy:


4. Types of Data Processed

The Cinque Terre Trip website has been designed and structured to minimise the collection of personal data.

Data NOT collected

The website does NOT collect in any way:

The website does not have:

During normal browsing, the computer systems and software procedures operating the website collect only the technical data strictly necessary for delivering web content and for aggregate performance analysis (e.g. anonymised IP address, HTTP request data, browser and operating system parameters).


5. Collection Method

Technical navigation data is collected automatically by the user’s browser when accessing and browsing the website’s pages, exclusively through the hosting infrastructure and the diagnostic/statistical services described below.

No direct data collection is carried out through manual input by the user.


6. Purposes of Processing

Technical and navigation data are processed exclusively for the following purposes:

  1. Service delivery and website operation: to enable the correct display and use of the website’s content.
  2. Security and maintenance: to ensure network security, prevent cyberattacks or harmful activities, and diagnose any technical malfunctions.
  3. Statistics and performance optimisation: to analyse website performance and traffic in aggregate and anonymous form in order to improve the user browsing experience.

The legal basis for processing for the purposes described above is:


8. Hosting and Infrastructure

The website is built with the Astro framework and hosted on the Vercel cloud hosting platform, provided by Vercel Inc.

Content management (CMS) is handled by Sanity CMS (Sanity AS). Sanity is used exclusively by the Data Controller in headless mode for writing and organising articles. No user or visitor of the site has access to the CMS, nor can they register, authenticate, or interact with it.


9. Vercel Analytics

The website uses Vercel Analytics, a web traffic analysis service provided by Vercel Inc.


10. Vercel Speed Insights

The website uses Vercel Speed Insights, a performance diagnostics and monitoring service provided by Vercel Inc.


11. Open-Meteo

To display weather information for Cinque Terre locations, the website makes API calls to the Open-Meteo service (Open-Meteo GmbH).


12. Web Share API

The website provides article sharing buttons that use the Web Share API, natively integrated into modern browsers (desktop and mobile).


13. Local Fonts

All typeface fonts used for the website’s design are downloaded and served locally from the website’s own servers.

No third-party remote font services (such as Google Fonts or Adobe Fonts) are used. As a result, the display of text does not involve any transmission of connection data to third-party servers.


Articles and pages on the website may contain hyperlinks to websites, platforms, or services managed by third parties.

By clicking on such links, the user leaves the Cinque Terre Trip website and enters independent web environments. The Data Controller has no control over the content, privacy policies, or data processing carried out by such external sites. Users are encouraged to consult the respective privacy policies when visiting those sites.


15. Social Networks

The website contains only a text link/icon pointing directly to the project’s Instagram profile.


16. Data Retention

Given that the website does not collect personally identifiable data submitted by users (such as forms or registrations):


17. Data Recipients

Navigation and technical data may be processed by the following parties designated as Data Processors or technical service providers:

  1. Vercel Inc.: Provider of hosting, network infrastructure, Vercel Analytics, and Speed Insights.
  2. Sanity AS: Provider of the Content Management System service (exclusively for administrator-side content management).

Data will under no circumstances be disclosed, sold, or transferred to third parties for commercial or marketing purposes.


18. Transfers Outside the EEA

The technical service providers used by the website (in particular Vercel Inc. and Sanity AS) are based or have servers that may involve the transfer of technical data outside the European Economic Area (EEA), in particular to the United States.

Such transfers are carried out in compliance with Chapter V of the GDPR, by means of:


19. Security

The Data Controller adopts appropriate technical and organisational security measures to protect the integrity and confidentiality of the website and users’ browsing.

The website uses the encrypted communication protocol HTTPS (SSL/TLS) to ensure that all connections between the user’s browser and the server are secure and protected from interception by third parties.


20. Rights of the Data Subject

As a data subject, pursuant to Articles 15–22 of EU Regulation 2016/679, you have the right to:

Note: Since the website does not collect users’ identifying data (name, email, account), it may not be possible for the Data Controller to directly identify a specific user in the anonymised technical logs, in accordance with Art. 11 of the GDPR (Processing that does not require identification).


21. How to Exercise Your Rights

You may exercise your rights at any time by sending a written communication via email to the Data Controller:

The Data Controller will respond to requests as soon as possible and in any case within 30 days of receipt.


22. Complaint to the Supervisory Authority

If you believe that the processing of personal data carried out through this website violates the provisions of the GDPR, you have the right to lodge a complaint with the competent Supervisory Authority.

In Italy, the competent authority is the Garante per la protezione dei dati personali (Italian Data Protection Authority):


23. Updates to the Privacy Policy

This Privacy Policy was last updated on 22 July 2026.

The Data Controller reserves the right to modify or update this Policy at any time, including in the event of new services or features being added to the website.


24. Contact

For any clarification, question, or request for information regarding this Privacy Policy or the processing of personal data, you may contact the Data Controller directly: