Privacy Policy.
Last updated: June 30, 2026
TourismIntel ("we", "us", "our") respects your privacy. This Privacy Policy describes how we collect, use, and disclose your personal data when you use the TourismIntel website (tourismintel.ai), the TourismIntel iOS and Android mobile applications, and related services (collectively, the "Service").
1. Data Controller
The data controller is:
- Mirko Lalli
- Via del Tiratoio 1, 50124 Firenze, Italy
- Email: privacy@tourismintel.ai
2. What Data We Collect
We collect the following categories of personal data:
a) Account data
- Your email address (required for magic-link sign-in)
- Your name (optional, if you provide it)
- Your professional role and topics of interest (optional, for personalization)
b) Usage data
- Articles you bookmark or read
- App screens you view
- Search queries within the app
- Device type, OS version, app version
- IP address (used for security and analytics, anonymised after 30 days)
c) Push notification data
- Apple Push Notification (APNs) tokens
- Notification preferences you set
d) Subscription data
- In-app purchase receipts (validated via Apple and RevenueCat)
- Subscription status (active / cancelled / expired)
- We do NOT collect or store credit card numbers — payments are processed by Apple directly via your Apple ID.
e) Communication data
- Emails you send us when contacting support
We do NOT collect
- Your precise location (GPS)
- Your contacts
- Your photos or media
- Your browsing history outside the Service
- Your health, financial, or biometric data
- Any data from children under 16
3. Why We Collect Data (Legal Basis under GDPR)
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide the Service (account, content) | Contract (Art. 6(1)(b)) |
| Send transactional emails (magic link) | Contract (Art. 6(1)(b)) |
| Send marketing emails (with opt-out) | Consent (Art. 6(1)(a)) |
| Send push notifications | Consent (Art. 6(1)(a)) |
| Process subscription payments | Contract (Art. 6(1)(b)) |
| Analytics and product improvement | Legitimate interest (Art. 6(1)(f)) |
| Comply with legal obligations | Legal obligation (Art. 6(1)(c)) |
4. Third-Party Processors
We share data with the following service providers under data-processing agreements (GDPR Art. 28):
- Brevo (Belgium / France) — email delivery (magic link, newsletters)
- RevenueCat, Inc. (USA) — subscription and receipt validation
- Apple Inc. (USA) — payment processing, App Store distribution, push notifications via APNs
- Google LLC (Firebase) (USA) — push notifications via FCM on Android (when applicable)
- Google LLC (Google Analytics 4) (USA) — anonymised web analytics for the tourismintel.ai website. IP addresses are anonymised at Google's edge (last octet zeroed) before storage; no advertising cookies are set; no data is used for ad personalisation. Measurement ID: G-86YRD03PPX.
- PostHog, Inc. (USA) — product analytics and session replay for the tourismintel.ai website (identified profiles only, after sign-in).
- MongoDB Inc. (USA / EU) — database hosting
- Spreaker (Italy / USA) — podcast hosting
- OpenAI (USA) — AI summarization (no personal data sent to OpenAI; only public article content is processed)
For US-based processors, we rely on Standard Contractual Clauses (SCCs) and, where applicable, supplementary measures to ensure GDPR-equivalent protection.
5. Data Retention
- Account data: retained while your account is active. Deleted within 30 days of account deletion request.
- Usage data: anonymised after 90 days; deleted after 365 days.
- Push tokens: deleted when you disable push notifications or sign out.
- Subscription receipts: retained for 10 years for tax compliance (Italian law).
- Support emails: retained for 24 months.
6. Your Rights (GDPR)
You have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Erase your data ("right to be forgotten") — see Section 7 below
- Restrict processing in certain cases
- Object to processing based on legitimate interest
- Portability — receive your data in a structured, machine-readable format
- Withdraw consent at any time (without affecting prior lawful processing)
- Lodge a complaint with your local data protection authority (in Italy: Garante per la Protezione dei Dati Personali, www.gpdp.it)
To exercise these rights, email privacy@tourismintel.ai. We respond within 30 days.
7. Account Deletion
You can delete your TourismIntel account at any time:
- In the mobile app: Settings → Account → Delete Account
- By email: send a request to privacy@tourismintel.ai from the email address linked to your account
Deletion removes all your personal data within 30 days, except where retention is required by law (e.g., subscription receipts for tax compliance).
8. Cookies and Tracking
The website tourismintel.ai uses minimal first-party cookies for session management. We do not use third-party advertising cookies and we do not share data with ad networks. The mobile app does not use cookies but uses secure on-device storage (Keychain on iOS, EncryptedSharedPreferences on Android) for authentication tokens.
For product analytics on the website, we use two GDPR-conscious tools:
- Google Analytics 4 (measurement ID G-86YRD03PPX) — used to understand aggregate visitor behaviour (pages viewed, session length, traffic sources). We enable IP anonymization, disable ad-personalisation signals, and do not use Google Signals or Remarketing. Legal basis: legitimate interest (Art. 6(1)(f) GDPR). You can opt out with the official Google Analytics Opt-out Browser Add-on or any standard tracking-blocker extension.
- PostHog — used for anonymous product-usage analytics and, only for signed-in users, session replay on the app dashboard to debug UX friction. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
No advertising, cross-site or fingerprinting technologies are used on the website or in the mobile apps.
9. Security
We use industry-standard security measures: HTTPS/TLS encryption in transit, encryption at rest for sensitive data, JWT-based authentication, hashed magic-link tokens, and role-based access control. No method of transmission over the Internet is 100% secure, however, and we cannot guarantee absolute security.
10. International Transfers
Some of our processors are located outside the European Economic Area (EEA). When we transfer data outside the EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate protection.
11. Children
The Service is not intended for users under 16. We do not knowingly collect data from children. If you become aware that a child has provided data, contact us and we will delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via email or in-app banner at least 30 days before they take effect.
13. Contact
For privacy-related questions or to exercise your rights:
- Email: privacy@tourismintel.ai
- Postal: Mirko Lalli, Via del Tiratoio 1, 50124 Firenze, Italy