Privacy Policy

Last Updated: May 20, 2026

Private Rome Excursions ("we", "us", "our") is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store and protect your personal information when you use our website at privateromeexcursions.com or make a booking with us.

We are subject to the EU General Data Protection Regulation (GDPR) (Regulation 2016/679) as a business operating in Rome, Italy, within the European Union.

1. Who We Are (Data Controller)

Business name: Private Rome Excursions
Address: Via Tunisi, 43, 00192 Rome RM, Italy
Email: info@privateromeexcursions.com
Phone: +39 351 419 9425

For all data protection enquiries or to exercise your rights, contact us at the email above.

2. What Data We Collect

We collect the following categories of personal data:

  • Identity data: First name, last name
  • Contact data: Email address, phone number
  • Booking data: Tour selected, date, number of guests, special requests
  • Payment data: Payment is processed by Stripe. We do not store card numbers — Stripe holds all payment data under their own PCI-DSS compliance.
  • Technical data: IP address, browser type, pages visited, time on site (collected via Vercel Analytics only with your consent)
  • Communications data: Messages sent via our contact form or email
  • Newsletter data: Email address (only if you explicitly opt in)

We do not collect sensitive personal data (health, religion, ethnicity, etc.).

3. How We Use Your Data

PurposeLegal Basis
Process and confirm your bookingContract performance (Art. 6(1)(b) GDPR)
Send booking confirmation and tour detailsContract performance
Respond to your contact form enquiriesConsent (Art. 6(1)(a) GDPR)
Send marketing newslettersConsent — you can unsubscribe at any time
Improve our website (analytics)Consent — only if you accept analytics cookies
Comply with legal obligations (tax, accounting)Legal obligation (Art. 6(1)(c) GDPR)
Prevent fraud and ensure securityLegitimate interests (Art. 6(1)(f) GDPR)

4. Third-Party Data Processors

We share your data only with trusted processors who help us deliver our services:

ProcessorPurposeLocation
StripePayment processingUSA (SCCs)
SupabaseDatabase (bookings, tours)USA/EU (AWS)
VercelWebsite hosting & analyticsUSA (SCCs)
ResendTransactional emailUSA (SCCs)
TwilioSMS notifications (optional)USA (SCCs)

SCCs = Standard Contractual Clauses approved by the European Commission for international transfers.

We do not sell your personal data to any third party.

5. Cookies

We use the following types of cookies:

CookieTypePurposeDuration
admin_authNecessaryAdmin authentication sessionSession
pre_cookie_consentNecessaryStores your cookie preferences1 year
va_* (Vercel)AnalyticsAnonymous page view statistics1 year

You can manage your cookie preferences at any time using the cookie banner at the bottom of the page. You can also disable cookies in your browser settings, though this may affect site functionality.

6. Data Retention

  • Booking data: Retained for 10 years to comply with Italian tax and accounting law
  • Contact form messages: Retained for 2 years, then deleted
  • Newsletter subscriptions: Retained until you unsubscribe
  • Analytics data: Aggregated, anonymised — no personal retention

7. Your Rights Under GDPR

As an EU resident, you have the following rights:

  • Right of access: Request a copy of all personal data we hold about you
  • Right to rectification: Ask us to correct inaccurate data
  • Right to erasure ("right to be forgotten"): Request deletion of your data
  • Right to restriction: Ask us to limit how we use your data
  • Right to data portability: Receive your data in a machine-readable format
  • Right to object: Object to processing based on legitimate interests or for marketing
  • Right to withdraw consent: Withdraw consent at any time without affecting prior processing

To exercise any of these rights, email us at info@privateromeexcursions.com with the subject line "Data Request". We will respond within 30 days at no charge.

You also have the right to lodge a complaint with the Italian data protection authority (Garante): www.garanteprivacy.it

8. Data Security

  • All data is transmitted over HTTPS (SSL/TLS encryption)
  • Payment data is handled exclusively by Stripe (PCI-DSS Level 1 certified)
  • Database access is protected by Row Level Security (RLS) policies
  • Admin access requires authentication with secure session tokens
  • We do not store credit card numbers or CVV codes

9. Children's Privacy

Our services are not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by updating the "Last Updated" date at the top of this page. Continued use of our website after changes constitutes acceptance of the updated policy.

Contact Our Data Protection Contact

Private Rome Excursions
Via Tunisi, 43, 00192 Rome RM, Italy
info@privateromeexcursions.com
+39 351 419 9425

Chat with us on WhatsApp
Private Rome Excursions | Skip the Line Rome & Vatican Tours