Privacy Policy
How we collect, use, and protect your personal data
Last updated: January 2025
1. Data Controller
The controller of your personal data is:
2. Data We Collect
When you make a booking, we collect the following data:
- Full name
- Email address
- Phone number
- Rental dates and booking details (vehicle group, protection, mileage package)
- Driver age
- Any optional special requests
We do not collect payment card data directly — all payments are processed by Stripe (see section 5).
3. How We Use Your Data
We use your data for:
- Processing and confirming your booking
- Sending booking confirmations and pickup information by email
- Communicating with you about your reservation (changes, cancellations, support)
- Complying with legal and accounting obligations
We do not use your data for marketing purposes and we do not share it with third parties for advertising.
4. Legal Basis for Processing (GDPR)
Under the General Data Protection Regulation (GDPR), our processing is based on:
- Contract performance — processing bookings and payments.
- Legal obligation — maintaining transaction records.
- Legitimate interest — communicating with you about your reservation.
5. Third-Party Service Providers
We use the following trusted third-party providers to operate our services:
Stripe, Inc.
Payment processor — handles all credit card transactions. Payment data never passes through our servers.
stripe.com/privacyResend
Email delivery service — used to send booking confirmations and notifications.
resend.com/privacyThese providers act as data processors under appropriate data processing agreements.
6. Data Retention
We retain booking data for 5 years following completion of the rental, in order to comply with Italian legal and accounting requirements. You may request deletion of your data at any time by contacting us at fco@xautomobility.com.
7. Cookies
| Name | Purpose | Duration |
|---|---|---|
| next-auth.session-token | Admin authentication session (admin area only, not set for regular visitors) | 30 days |
We do not use any tracking, advertising, or analytics cookies.
8. Your Rights
Under GDPR, you have the following rights regarding your personal data:
- Right of access to your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restriction of processing
- Right to data portability
- Right to object to processing
To exercise any of these rights, please contact us at: fco@xautomobility.com
You also have the right to lodge a complaint with the Italian data protection authority (Garante per la protezione dei dati personali — garante.it).
9. Changes to This Policy
We may update this Privacy Policy from time to time. Any material changes will be posted on this page with an updated "Last updated" date.