Privacy
How your information is used
Italy with Isa keeps the information needed to run your account and save the trips you choose to plan. It does not sell your personal information.
Account and trip data
When you create an account, the service stores your email address, first name, newsletter choice, password hash and verification status. Your city choices, taste preferences, saved trips, day plans and visited-place markers are stored with your account so they work across devices. Session cookies keep you signed in; they are not advertising cookies.
Email and sign-in providers
Verification, password-reset and account-deletion confirmation emails are sent through Resend when production email is enabled. Reset and deletion links are short-lived and single-use; only a one-way hash of each private token is stored. If Google sign-in is enabled and you choose it, Google provides the account identity needed to sign you in. Those providers process data under their own notices.
Your copy and your right to delete
From Profile you can download a JSON copy of your account details, newsletter choice, sign-in methods and validated trip-planner state. The export does not contain password hashes, provider identifiers, sessions or private account tokens.
You can also request permanent account deletion from Profile. Password accounts must confirm the current password, and every account must use the short-lived link delivered to its verified email address. Confirmation deletes the live account together with its saved trips and preferences, sessions, and outstanding verification, reset and deletion tokens. Restricted disaster-recovery snapshots expire automatically after no more than 31 days and are not used for ordinary account access.
Optional analytics and search reporting
If Google Analytics is enabled, it does not load until you choose “Allow analytics.” It then records page views and broad actions such as creating a trip or adding a place to a planner. Google receives a random browser identifier, device/browser information, the page path without its query string, approximate location derived from the request, and those broad actions. The first-party _ga and _ga_* cookies expire no later than 60 days after the latest consented visit. Italy with Isa does not send Google your account name, email address, trip name, trip ID, or saved itinerary.
The purpose is to understand which guides and planner features are useful and improve the service. The legal basis is your consent. Advertising storage, ad personalisation, and Google Signals are disabled. Event-level and user-level retention must be set to two months in the Analytics property. Google may process analytics data outside the EEA under its applicable data-protection safeguards; see Google’s privacy policy.
Choose “Privacy choices” in the footer at any time to withdraw or grant consent. Withdrawal stops Google Analytics, removes its available first-party cookies, and does not affect your account or planner. For privacy questions, contactitalywithisa@gmail.com.
Google Search Console provides aggregated information about how pages appear in Google Search. Its ownership-verification tag does not track visitors.
Maps and optional walking routes
Map tiles come from OpenStreetMap, so the tile service receives ordinary web-request data such as an IP address. Street-following walking routes are optional. Only after you choose “Load walking route” does Italy with Isa send the selected day’s ordered coordinates from its server to OpenStreetMap.de’s OSRM service. The routing provider receives the itinerary coordinates and the Italy with Isa server address, not your browser address. If you do not choose it, the planner uses local distance estimates.
Bookings and live transport
Hotel, ticket, restaurant and live-transport actions open the named official provider in a new tab. Italy with Isa does not collect payment details. Once you follow an external link, that provider’s privacy and booking terms apply.
Security and changes
Passwords are stored as salted hashes, session tokens are hashed at rest, and account and trip responses are marked not to be cached by shared systems. This notice will be updated when new providers or data uses are added.
Last updated: 15 August 2026.