Privacy Policy

Version 1.1

Last update: 2026-01-03

Executive Summary

  • We comply with GDPR and protect your personal data
  • We only collect information necessary to provide the service
  • We never sell your data to third parties
  • You can access, rectify or delete your data at any time
  • We use SSL/TLS encryption and robust security measures

1. Data Controller

Identity: Alejandro Santalla Sanchez

Address: Calle Músico Pau Casals 16, 3ºA

Contact email: hola@itineramio.com

Data Protection Officer: hola@itineramio.com

Alejandro Santalla Sanchez is the data controller of your personal data in accordance with the General Data Protection Regulation (GDPR - EU 2016/679) and Organic Law 3/2018 on Personal Data Protection and guarantee of digital rights (LOPDGDD).

2. Data We Collect

2.1 Registration Data

When you create an account, we collect:

  • Full name
  • Email address
  • Password (encrypted)
  • Phone number (optional)
  • Company information (optional)

2.2 Usage Data

During use of the service, we collect:

  • Information about created properties
  • Content of digital manuals (texts, images, videos)
  • Platform interaction data
  • Usage metrics and analytics
  • Guest reviews and comments

2.3 Technical Data

We automatically collect:

  • IP address
  • Browser type and version
  • Operating system
  • Device information
  • Pages visited and time spent
  • Referrer URL
  • Cookies and similar technologies (see our Cookies Policy)

2.4 Billing Data

To process payments, we collect:

  • Credit/debit card information (processed by Stripe)
  • Billing address
  • Tax ID (for Spanish billing)
  • Transaction history

Note: Payment data is processed directly by Stripe and we do not store it on our servers.

3. Purpose of Processing

We use your personal data for the following purposes:

Service Provision

  • Manage your account and authentication
  • Create and manage digital manuals
  • Generate unique QR codes
  • Process guest reviews
  • Provide analytics and metrics

Billing and Payments

  • Process subscriptions and payments
  • Issue invoices
  • Manage refunds
  • Prevent fraud

Communications

  • Send service notifications
  • Respond to support inquiries
  • Send important service updates
  • Marketing communications (only with your consent)

Improvement and Development

  • Analyze usage patterns
  • Improve features
  • Detect and fix bugs
  • Develop new features

Legal Compliance

  • Comply with legal obligations
  • Respond to legal requests
  • Protect our rights and property

5. Data Recipients

We share your personal data only with trusted third parties that help us provide the service:

Stripe

Payment and subscription processing

Policy: stripe.com/privacy

Supabase

Storage and database (EU servers)

Policy: supabase.com/privacy

Resend

Transactional email delivery

Policy: resend.com/legal/privacy-policy

Vercel

Hosting and application deployment

Policy: vercel.com/legal/privacy-policy

Important: All our service providers are subject to data processing agreements (DPA) that ensure GDPR compliance and protection of your personal data.

6. Data Retention

We retain your personal data for the time necessary to fulfill the purposes described:

  • Account data: During the validity of your subscription + 6 years (tax legal obligation)
  • Billing data: 6 years (Art. 30 Commercial Code)
  • Technical cookies: Maximum 12 months
  • Analytics/marketing cookies: Maximum 24 months (with your consent)
  • Security logs: Maximum 90 days

After the retention period, your data will be securely deleted or anonymized for statistical analysis.

7. Your Rights

According to GDPR, you have the following rights over your personal data:

Right of Access

Know what personal data we have about you

Right of Rectification

Correct inaccurate or incomplete data

Right of Erasure

Request deletion of your data ("right to be forgotten")

Right to Object

Object to processing of your data in certain circumstances

Right of Restriction

Request restriction of processing of your data

Right to Portability

Receive your data in structured format and transfer it to another controller

How to exercise your rights?

You can exercise any of these rights by sending an email to:

hola@itineramio.com

Include: full name, registered email, copy of ID, and description of request. We will respond within a maximum of 30 days.

If you consider that we have not properly addressed your rights, you can file a complaint with the Spanish Data Protection Agency (AEPD). (AEPD).

8. Security Measures

We implement appropriate technical and organizational measures to protect your personal data:

Encryption

  • SSL/TLS in all communications
  • Password encryption with bcrypt
  • Encryption of data at rest

Authentication

  • JWT tokens with expiration
  • Mandatory email verification
  • Secure sessions with HttpOnly cookies

Restricted Access

  • Principle of least privilege
  • Two-factor authentication (admin)
  • Regular access audits

Monitoring

  • Security and audit logs
  • Detection of suspicious activities
  • Automatic daily backups

Important: Despite our security measures, no method of transmission over the Internet is 100% secure. We recommend using strong and unique passwords, and never sharing your access credentials.

9. Cookies and Similar Technologies

We use cookies and similar technologies to improve your experience. For more information, see our Cookies Policy.

You can manage your cookie preferences at any time from your browser settings.

10. International Transfers

We store your data primarily on servers located in the European Union (Supabase eu-north-1 region).

Some of our service providers (such as Vercel or Stripe) may process data outside the EEA. In these cases, we ensure that:

  • The destination country has an adequate level of protection recognized by the European Commission
  • Standard Contractual Clauses (SCC) approved by the EU are applied
  • The provider complies with the EU-US Data Privacy Framework

11. Minors

Our service is intended for persons over 18 years of age. We do not intentionally collect personal information from minors.

If you become aware that a minor has provided personal data without parental consent, contact us immediately at hola@itineramio.com.

12. Changes to this Policy

We reserve the right to update this Privacy Policy to reflect changes in our practices or due to legal requirements.

We will notify you of material changes by email or through a prominent notice on the platform at least 30 days before they take effect. We recommend reviewing this policy periodically.

13. Contact

For any questions about this Privacy Policy or the processing of your personal data, you can contact us at:

Responsible: Alejandro Santalla Sanchez

Privacy Email: hola@itineramio.com

Support Email: hola@itineramio.com

Address: Calle Músico Pau Casals 16, 3ºA

Manual Digital Apartamentos Turísticos | Software Gestión Airbnb | Itineramio