Booking Privacy Notice
This section explains how personal data is used to respond to booking requests, provide and support the Locker service, communicate with customers and secure the premises. It is provided under Articles 13 and 14 of the EU General Data Protection Regulation (“GDPR”). A separate Cookie Notice should describe non-essential website cookies and similar technologies.
1.1 Controller and contact
StowCity is the controller for the booking and Locker data described in this notice. Privacy requests may be sent to hello@stowcity.com. If a data protection officer is appointed, updated contact details will be published on the website.
1.2 Data we process
Depending on how you interact with us, we process:
- name, email address, telephone or WhatsApp number, language and other contact details;
- requested location, date, period, Locker category, bag count, Booking reference and status;
- payment status, amount, currency, transaction reference, invoice details and limited anti-fraud information, but normally not the full payment-card number;
- access credentials and records such as code creation, Locker opening/closing events, terminal events and technical or security logs;
- messages, calls, support requests, complaints, incident records and property-recovery information;
- website or device data that is necessary for security and operation, such as IP address, browser information and timestamps; and
- images recorded by clearly signposted CCTV systems at locations where CCTV is installed.
We obtain data from you, a person booking for you, our website or terminal, the Locker and access system, payment and communications providers, and security systems. If another person supplies your data, they must be authorised to do so and should show you this notice.
1.3 Why we process data and our legal bases
| Purpose | GDPR legal basis |
|---|---|
| Respond to a request; confirm, manage and perform a Booking; issue an access credential; take payment; provide support; send operational updates; deal with late or forgotten property. | Steps requested before entering a contract and performance of the contract (Article 6(1)(b)). |
| Send booking and service messages by email, telephone, SMS or WhatsApp, including confirmation, access instructions, changes, reminders needed for collection, security alerts and support responses. | Steps requested before entering a contract and performance of the contract (Article 6(1)(b)). In an urgent safety situation, legitimate interests may also apply (Article 6(1)(f)). |
| Issue invoices, maintain tax and accounting records, respond to authorities and comply with legal duties. | Compliance with a legal obligation (Article 6(1)(c)). |
| Protect customers, premises and property; secure accounts, Lockers and systems; prevent and investigate misuse or fraud; establish, exercise or defend legal claims. | StowCity’s and customers’ legitimate interests in safety, security, service integrity and legal protection (Article 6(1)(f)). |
| Operate signposted CCTV where installed, without audio or facial recognition, to prevent and investigate theft, vandalism and safety incidents. | Legitimate interests in protecting people and property (Article 6(1)(f)), after assessing necessity and proportionality. |
| Send newsletters, offers or other promotional electronic messages. | Your separate, optional consent (Article 6(1)(a)) where required. Marketing consent is not a condition of a Booking. |
Booking contact is not marketing. By supplying an email address and/or telephone or WhatsApp number for a booking request, you ask StowCity to use the supplied channels for messages reasonably necessary to arrange and operate that Booking. We do not rely on marketing consent for these service messages, and opting out of marketing does not stop them. Tell us if you prefer email where a channel choice is operationally possible.
We will not use a required acceptance checkbox as consent for advertising. Promotional email, SMS, WhatsApp or calls will be sent only where we have a valid, separately recorded permission or another specific exception permitted by applicable electronic-communications law. Consent can be withdrawn at any time without affecting the Booking or processing already carried out lawfully.
1.4 Is the data required?
Fields marked as required are needed to assess or perform the Booking, provide an access credential, take payment or meet a legal requirement. Without them, we may be unable to accept or provide the service. Optional fields are identified as such. Data required only for marketing is always optional.
1.5 Who receives the data
Authorised StowCity staff and contractors access data only where needed for their role. We may disclose relevant data to service providers that host the website and booking platform; operate Lockers, access control, support, email, SMS or messaging; process payments; provide accounting, cybersecurity, CCTV or physical security; or assist with insurance, professional advice, claims and property recovery. These providers are bound by data-protection duties where they act as processors.
A communications or payment provider may also process limited data as an independent controller under its own privacy notice. In particular, using WhatsApp involves the service operated by the relevant Meta group company. We may disclose data to police, courts, emergency services, regulators or other authorities where required or lawfully necessary. We do not sell booking data.
1.6 Transfers outside the European Economic Area
Some technology or communications providers may process data outside the European Economic Area. Where the destination is not covered by an EU adequacy decision, we use an approved safeguard such as the European Commission’s Standard Contractual Clauses and, where appropriate, supplementary measures. You may contact us for information about the safeguard relevant to your data.
1.7 How long we keep data
- Unconfirmed requests: normally up to 6 months after the last contact, unless needed for a complaint, security issue or legal claim.
- Booking, payment and support records: for the Booking and then normally up to 10 years where necessary for Italian accounting, tax, contract and legal-claim requirements.
- Locker access and security logs: normally up to 12 months, or longer only where a specific incident, dispute or legal duty requires preservation.
- CCTV recordings: where CCTV is installed, normally no more than 72 hours and usually less, with automatic deletion. A longer period may apply over closures or where footage must be preserved for a specific incident, claim or authority request.
- Marketing records: until consent is withdrawn or the data is no longer needed, with periodic review and normally no longer than 24 months from the last meaningful interaction unless consent is renewed. We may retain a minimal suppression record to respect an opt-out.
We may keep data longer where a law requires it or for the duration of an actual or reasonably anticipated claim, investigation or enforcement process. Data is then deleted or irreversibly anonymised.
1.8 Your GDPR rights
Subject to the conditions in the GDPR, you may ask for access to and a copy of personal data; correction; deletion; restriction; or portability of data you supplied where processing is automated and based on contract or consent. You may object at any time to direct marketing, and you may object on grounds relating to your situation to processing based on legitimate interests. You may withdraw consent at any time.
Send a request to hello@stowcity.com. We may ask for information reasonably needed to verify identity and protect other people’s data. You also have the right to complain to the Italian Data Protection Authority (Garante per la protezione dei dati personali), or to the supervisory authority in the EU/EEA country where you live or work or where the alleged infringement occurred.
1.9 Automated decisions and security
We do not make decisions producing legal or similarly significant effects about customers solely by automated means. We use proportionate technical and organisational measures designed to protect data, but no system can be guaranteed completely secure. Please keep access credentials confidential and contact us promptly about suspected misuse.
1.10 CCTV information at the location
Where CCTV is used, a visible first-layer notice is placed before entry to the monitored area. It identifies the controller, the security purpose and where to read this full notice. Cameras are positioned to minimise unnecessary capture. Requests concerning footage should identify the location, date, approximate time and the person concerned so that we can assess the request while protecting other people’s rights.
For more information about the GDPR legal bases and rights described above, see the official text of Regulation (EU) 2016/679.