Privacy policy
Last updated: 17/09/2026
1. Who handles your data
The data controller is Marco Sabatini, a private individual, author and operator of the Walk Around Florence project (the walkaroundflorence.com website and the Walk Around Florence Android app). For any request about your data, write to [email protected]: I answer personally.
2. Data collected by this website
This site is a presentation page. It uses no tracking cookies, no analytics, no advertising tools and builds no user profiles.
The hosting provider (Cloudflare) automatically records technical connection data such as IP address, browser type, date and time of the request. This only keeps the site running and protects it from abuse, is kept for a short period by the provider and is not used to identify you. Legal basis: legitimate interest in the security of the service (Art. 6.1.f GDPR).
3. Data handled by the app
The Walk Around Florence app works without sign-up and without an account: you are never asked for a name, email or password.
- Location. If you grant permission, your location is used on your device only, to show the nearest stop and for navigation. It is never sent to me, never stored on any server and never used to track you. You can deny permission: the app keeps working with the standard order of stops.
- Purchases. Premium itineraries and the Photo Collection are bought through Google Play, which is the seller and the only party handling your payment details: I never see or store cards or bank data. I only receive the technical purchase confirmation needed to unlock what you bought and to restore it if you reinstall the app. This check runs on a service built with Supabase. Legal basis: performance of the contract (Art. 6.1.b GDPR).
- Preferences. Language, tour length and settings stay in your phone's memory only.
4. Who the data is shared with
I do not sell or trade personal data. Only the technical providers needed to run the service are involved: Cloudflare (website hosting and protection), Google Play (app distribution and purchases), Supabase (technical purchase verification), OpenStreetMap (in-app maps). Each processes data under its own privacy notice.
5. Transfers outside the European Union
Some of these providers are based in the United States. Transfers rely on the safeguards required by the GDPR, in particular the standard contractual clauses approved by the European Commission.
6. How long data is kept
Technical logs are kept for the short period set by the hosting provider. Launch-notice email addresses are deleted right after the notice or on your request. Purchase confirmations are kept for as long as needed to guarantee access to the content you bought.
7. Your rights
At any time you may request access to your data, rectification, erasure, restriction of processing, objection and portability, and withdraw consent already given. Write to [email protected]: I reply within one month. If you believe the processing breaches the law, you may lodge a complaint with your national data protection authority; in Italy, the Garante per la protezione dei dati personali (garanteprivacy.it).
8. Children
The service is not aimed at children and I do not knowingly collect data from anyone under 14.
9. Changes
If this notice changes, the updated version is published on this page with a new date. Version of 17/09/2026.