Privacy Policy

Last updated: 7 August 2026 — v5 (account registration, contact form, ideas catalogue, maps, error monitoring, TravelLab mobile app, Bentrovato section)

Data Controller

Alessio Goria

Email: alessio.goria@alessiogoria.com

Website: alessiogoria.com

Purpose of the website

alessiogoria.com is a personal portfolio and travel blog website. It is NOT a travel agency, it does NOT sell travel packages, and it does NOT provide mountain guide or tour guide services. The site serves as a meeting point for people who prepare trips and mountain outings independently. Information about routes, difficulty, and conditions is indicative and based on the author's personal experience. Each user is responsible for their own safety and decisions.

Nature of this website

This is a personal portfolio website. It does not sell products or services and does not profile users for commercial purposes.

Legal basis for processing

Personal data is processed on the following legal bases (Art. 6 GDPR):


• Consent (Art. 6.1.a): for analytics cookies (Google Analytics). Users can give or withdraw consent via the cookie banner.

• Legitimate interest (Art. 6.1.f): for server logs (security), for technical cookies necessary for the site to function, for technical error monitoring (Sentry), and for IP-based anti-abuse rate limiting.

• Performance of a contract or pre-contractual measures (Art. 6.1.b): for account registration and management, and for responding to requests sent through the contact form.

• Legal obligation (Art. 6.1.c): for data retention required by law.

Data processed and purposes

This website processes the following data:


1. Language preference: stored in the browser's localStorage (Italian/English) to maintain the selected language between visits. Never transmitted to external servers.


2. Cookie preference: stored in the browser's localStorage (cookie_consent) to remember the user's choice regarding analytics cookies.


3. Analytics data (with consent only): if the user accepts analytics cookies, Google Analytics 4 collects aggregated and anonymous visit data (pages viewed, session duration, country of origin, device type). Google Analytics 4 does not log or store IP addresses.


4. Form data: the site collects data through forms (trip proposals, participation requests, account registration). Data collected includes: name, email, message content. This data is saved in the site's database and used exclusively to manage requests.


5. Contact form: name, email, and message sent through the form on the "About me" page are delivered by email to the controller and are not saved in the site's database. Legal basis: Art. 6.1.b (responding to the request). Data is kept only as long as necessary to handle the request.


6. Authentication data: for registered users, the site stores username, first name, last name, email, and session tokens; optionally nationality, city, and year of birth, used to personalise the community's trip proposals. Passwords are encrypted (hashed).


7. "Likes" on the ideas catalogue: the like counter is anonymous and requires no account. Server-side, the IP address is processed solely for anti-abuse rate limiting, in a technical table with expiry and automatic nightly cleanup. Legal basis: legitimate interest (Art. 6.1.f, security of the service).


8. Interactive maps: when a map is displayed, the browser requests map tiles directly from the CARTO, OpenStreetMap, and OpenTopoMap servers, which receive the IP address as technical data needed to serve the request. Map fonts and libraries are hosted directly on the site (no third-party CDN).


9. Technical errors: if the site encounters errors, Sentry collects technical data (error message, browser, URL) for monitoring and resolution. Errors may also be forwarded as technical reports to triage services (Anthropic Claude API, GitHub); the reports deliberately contain no personal data beyond what may be present in the error message. Legal basis: legitimate interest (Art. 6.1.f).


10. Server logs: the web server may automatically record the visitor's IP address, browser type, pages visited, and date/time of access. These data are retained only as long as necessary for the security of the service.

Cookies and tracking technologies

This website uses the following technologies:


TECHNICAL COOKIES / LOCALSTORAGE (always active, legal basis: legitimate interest):

NameTypeDurationPurpose
langlocalStoragePersistentLanguage preference
cookie_consentlocalStoragePersistentCookie choice
auth_tokenlocalStorageSessionUser authentication
auth_userlocalStorageSessionUser session data
auth_refreshlocalStorageSessionUser session renewal
likes_catalogolocalStoragePersistentRemembers "likes" already given from this device
catalogo_tileslocalStoragePersistentMap theme preference (light/dark)
toast_msglocalStorageTemporaryTemporary service messages

These technical items are exempt from consent under Art. 122 of the Italian Privacy Code.


ANALYTICS COOKIES (with prior consent only, legal basis: consent):

NameTypeDurationPurpose
_gaCookie2 yearsGA4 identifier
_ga_*Cookie2 yearsGA4 session
_gidCookie24 hoursSession identifier

Data controller for analytics: Google Ireland Limited.

Google Analytics 4 does not log or store IP addresses by design.

Google Privacy Policy: https://policies.google.com/privacy


Users can change or withdraw their consent at any time by clicking "Manage cookies" in the site footer, or by clearing browser data.

Data collected through forms

The site collects personal data through the following forms:


1. Trip/outing proposal form: name, email, title, type, difficulty, date/period, destination, description. Data is saved in the database and visible to the controller for organising activities.


2. Participation form: name, email (optional), preferred date, message. Data is associated with the corresponding proposal.


3. Account registration: first name, last name, username, email, and password (stored only as an encrypted hash); optional: nationality, city, and year of birth, used to personalise the community's trip proposals. The account is created at the time of registration (legal basis: Art. 6.1.b).


4. Contact form ("About me" page): name, email, and message are sent by email to the controller and are not saved in the site's database. Legal basis: Art. 6.1.b (responding to the request). Retention limited to handling the request.


5. "Bentrovato" form (hellos from travel encounters): name (even just an initial), place of the encounter, message, optional photo and optional private contact (email or Instagram); see the dedicated section below for details on publication and legal basis.


Form data is NOT shared with third parties, NOT used for marketing, and NOT sold. Users can request deletion at any time by writing to alessio.goria@alessiogoria.com.

TravelLab mobile app

The site is complemented by the TravelLab mobile app, which lets users plan trips and record route waypoints independently.


Data processed by the app:

• Trips: title, type, dates, destination, description and, for mountain outings, elevation and elevation gain.

• Waypoints: route points with GPS coordinates (latitude/longitude) and elevation — location data.

• Photographs, voice notes and diary entries associated with the trip.


Where it is stored: this data is saved in a local database (SQLite) on the user's device. Photographs, voice notes and diary entries stay on the device; the app does not upload them to the server.


Synchronisation (optional): if the user logs into the app with the same account registered on the site and starts a sync, trips and their waypoints (with GPS coordinates) are sent to the site's database, so they can also be viewed from the web dashboard; the app can likewise download trips already present on the account from the site. Synchronisation is a voluntary action by the user: the app can be used without ever syncing, in which case the data stays only on the device.


Purpose: personal trip planning and archiving, with the ability to find the same data on both the app and the site using the same account. Legal basis: Art. 6.1.b (performance of a service requested by the user).


Deletion: synced trips can be removed from the app or from the site dashboard, which removes them from the site's listings; data stored only on the device (photographs, voice notes, diary) is removed by uninstalling the app. To request full deletion of the account and synced data, write to alessio.goria@alessiogoria.com.

"Bentrovato" section (travel encounters)

Whoever fills in the Bentrovato form voluntarily provides: a name (even just an initial), the place we met, a message, an optional photo and, optionally, a private contact (email or Instagram). Legal basis: consent (Art. 6.1.a GDPR), given via the form checkboxes. The hello and photo are published only after manual review; the private contact is never published nor shared and is used only for a personal reply, if authorised. To edit or remove your entry, photo or contact at any time: alessio@alessiogoria.com.

Data retention periods

Personal data is retained for the following periods:


• Analytics data (Google Analytics): 14 months (GA4 default setting)

• Form data (proposals, participations): 2 years from submission date

• Contact form data: as long as necessary to handle the request (no database persistence)

• Anti-abuse "like" technical data (IP address): until expiry, with automatic nightly cleanup

• Error monitoring data (Sentry): 90 days

• Login attempts: 24 hours

• User accounts: while active + 1 year after deactivation

• Server logs: 30 days

• Analytics cookies: see table above

• Bentrovato hellos (name, place, message, photo, private contact): as long as the section is online or until a removal request; photos of rejected entries are deleted immediately


At the end of the indicated periods, data is deleted or anonymised.

Sub-processors

The following third parties process data on behalf of the controller:


• Google Analytics (Google Ireland Limited, Ireland) — Web traffic analysis. Policy: https://policies.google.com/privacy

• Turso / LibSQL (EU) — Database for site data storage.

• Netlify (USA, with EU Standard Contractual Clauses) — Website and serverless functions hosting.

• Aruba S.p.A. (Italy) — Email service.

• Sentry (Functional Software, Inc., USA) — Technical error monitoring (error message, browser, URL). Legal basis: legitimate interest (Art. 6.1.f). Extra-EU transfer covered by Standard Contractual Clauses / EU-U.S. Data Privacy Framework. Policy: https://sentry.io/privacy/


All sub-processors operate in compliance with GDPR or have signed Standard Contractual Clauses (SCCs) approved by the European Commission.


When interactive maps are used, the browser also contacts the CARTO, OpenStreetMap, and OpenTopoMap tile servers directly; they receive the IP address as technical data needed to serve the map tiles.

Social network links

The website contains links to Instagram, Facebook, and LinkedIn profiles. These links open the respective platforms in a new tab. By clicking such links, you are subject to the privacy policies of Instagram (Meta), Facebook (Meta), and LinkedIn. The data controller has no control over data processed by these platforms.

Hosting and security

The website is hosted on Netlify, which ensures data transmission via HTTPS (encrypted connection). Netlify operates in the USA with Standard Contractual Clauses (SCCs) for the transfer of personal data outside the EEA. The hosting provider processes technical access data in compliance with GDPR.

Data breach notification procedure

In the event of a personal data breach, the controller commits to:


1. Assessing the breach within 24 hours of discovery.

2. Notifying the competent Data Protection Authority within 72 hours of discovery, if the breach poses a risk to the rights and freedoms of data subjects (Art. 33 GDPR).

3. Communicating the breach to affected data subjects without undue delay, if the breach poses a high risk to their rights and freedoms (Art. 34 GDPR).

4. Documenting all breaches, including circumstances, consequences, and remedial actions taken.


To report a suspected breach: alessio.goria@alessiogoria.com

User rights

Under Articles 15-22 of the GDPR (EU Regulation 2016/679), every user has the right to:

• access their personal data (Art. 15)

• request rectification (Art. 16) or erasure (Art. 17)

• restrict processing (Art. 18)

• object to processing (Art. 21)

• request data portability (Art. 20)

• withdraw consent at any time (Art. 7.3)

• lodge a complaint with the relevant data protection authority


The controller commits to responding within 30 days of the request.

To exercise these rights, write to: alessio.goria@alessiogoria.com

Intellectual property and photographic copyright

Photographs of trips and outings that have already taken place — those illustrating the travel diaries, the mountain pages and the photography section — are original works by Alessio Goria, protected by copyright law (Italian Law no. 633 of 22 April 1941 and subsequent amendments, as well as EU Regulation no. 2019/790).


Trip proposals and the catalogue of ideas, by contrast, concern destinations not yet visited: by definition there can be no photographs by the author. The images accompanying them come from open-licence archives (for example Wikimedia Commons) and are used under the licence stated in the caption next to each image (e.g. Creative Commons CC BY-SA), with the attribution that licence requires. For those images the terms of the respective licence apply: the restrictions below concern original photographs only.


Without prior written authorisation from the rights holder, it is strictly prohibited to:

• reproduce, copy, download or save the photographs by any means

• publish, share or redistribute the photographs on websites, social networks or other channels

• use the photographs for commercial or non-commercial purposes

• modify, adapt or create derivative works from the photographs


Any unauthorised use constitutes copyright infringement and may be prosecuted under applicable civil and criminal law.


For usage requests, licences or permissions: alessio.goria@alessiogoria.com

Changes to this policy

The data controller reserves the right to modify this policy at any time. Changes will be published on this page with an updated date at the top of the document.