Privacy Policy
1. In short
Before the formal version, here's what actually happens.
- If you join the ESCO waiting list you give us one contact — phone or email — and we use it to tell you when a spot opens in your city. If you choose the phone we message you on WhatsApp or SMS: we don't call.
- If you write through the miutifin.com contact form, we keep what you enter so we can reply about your project.
- If you become an ESCO member, we keep your account, your taste preferences and what you save: that's the data that lets the app compose journeys for you.
- We record when you gave consent, because the law requires us to be able to prove it.
- We rely on a small number of trusted providers. We don't sell your data, we don't run profiled advertising, we don't pass it to marketers.
- You can ask to see or delete your data at any time. We reply within 30 days.
The rest of this page is the formal version of those six lines.
2. Who processes your data
The data controller is [LEGAL ENTITY NAME], registered at [FULL ADDRESS], VAT [NUMBER], operating miutifin.com and the ESCO service.
For anything about your data, write to miutifin.ask@gmail.com.
We have not appointed a Data Protection Officer: we don't fall within the cases where the GDPR makes it mandatory.
3. What we collect
It depends on how you interact with us. We never collect more than a specific purpose requires.
3.1 If you write through the miutifin.com form
- Full name, company, work email
- Project type and, if you provide it, an indicative budget
- The message you write
- Your consent and the date you gave it
3.2 If you join the ESCO waiting list
- Your phone number or your email — one of the two, your choice. We don't ask for both.
- Your consent and the moment you gave it (date and time).
- Which part of the site you signed up from and which language you were browsing in.
- A one-way fingerprint of your IP address: it only serves to count sign-ups from the same connection and prevent abuse. The address cannot be recovered from it.
If you leave an email, we also store a normalised form of it (without dots and without the +suffix some providers ignore) to spot duplicate sign-ups from the same mailbox.
3.3 If you subscribe to the newsletter
- Your email address
- Optionally, your phone number
3.4 If you become an ESCO member
When you complete registration after an invitation, we collect:
- Authentication data: email, password (stored as a hash, never in clear text), session tokens
- Profile: username, nickname, avatar (optional), short bio (optional), city, birthday (optional)
- Taste preferences: preferred categories, music interests, price tier, day/night preference, dress code
- Activity: places you save, events you attend, ratings you give, journeys you compose
Preferences and activity are what allow ESCO to compose personalised journeys: without that data the service cannot work.
3.5 Technical data (anyone visiting)
- Device and browser: type, version, language
- IP address: our hosting providers receive it to deliver pages. On the waiting list we only keep an encrypted fingerprint, to limit repeated attempts.
3.6 Public numbers
The pages show aggregate counts — how many people are on the list, how many cities are live, how many sign-ups came this week. They are sums: no individual can be identified from them.
4. Why we use them
| Purpose | Data used |
|---|---|
| Running the service: accounts, journeys, preferences, invites | Account data, preferences, activity |
| Telling you when the beta opens in your city | Waiting list phone or email |
| Replying to your project enquiry | Contact form data |
| Proving you gave consent | Consent and timestamp |
| Preventing automated sign-ups and abuse | IP fingerprint, attempt count |
| Improving the product | Aggregate statistics, no individual tracking |
| Meeting legal obligations | Whatever is required at the time |
We don't use your data for profiled advertising and we don't make fully automated decisions producing legal effects on you. ESCO's suggested journeys are proposals: the choice stays yours.
5. Legal basis
| Processing | Legal basis (GDPR art. 6) |
|---|---|
| miutifin contact form | Pre-contractual measures — art. 6.1.b |
| ESCO waiting list | Your consent — art. 6.1.a |
| Newsletter | Your consent — art. 6.1.a |
| Account and member features | Contract performance — art. 6.1.b |
| Security and abuse prevention | Legitimate interest — art. 6.1.f |
| Aggregate statistics | Legitimate interest — art. 6.1.f |
| Regulatory obligations | Legal obligation — art. 6.1.c |
Where the basis is consent you can withdraw it whenever you want, by writing to the address at the bottom. Withdrawal doesn't make what we did before unlawful.
Our legitimate interest in abuse prevention is keeping the service working and the list clean. We assessed it doesn't override your rights: the IP address is never stored in clear text.
6. Who we share them with
We don't sell your data and we don't give it to advertisers or marketing networks. It's only processed by the providers running our infrastructure.
| Provider | What it processes |
|---|---|
| Supabase — database, authentication, storage | Accounts, profile, preferences and content. Region: [CHECK YOURS: Frankfurt / other] |
| Vercel — website hosting | Technical request data (IP, headers) for delivery and security |
| Anthropic / OpenAI — journey composition | Only the preference signals needed for a single composition. No profile data, no identifiers. Inputs are not used to train their models. |
| Google Places — place data | Place lookups and coordinates needed to show you venues |
All providers are bound by data processing agreements under GDPR art. 28.
7. Transfers outside the EU
Our main infrastructure is in the European Union. Some providers — notably the AI and hosting ones — are US-based and may process data outside the EU. In those cases the transfer is protected by:
- Standard Contractual Clauses approved by the European Commission
- or an adequacy decision, such as the EU–US Data Privacy Framework
- plus technical safeguards: encryption, minimisation of what is sent, no training on inputs
8. How long we keep them
| Data | Retention |
|---|---|
| Contact form messages | 24 months from the last exchange |
| Waiting list contact (not approved) | 18 months, then deleted |
| Active member accounts | For the life of the account, plus 30 days after deletion |
| Newsletter subscribers | Until you unsubscribe |
| Consent and timestamp | For the duration of processing and 5 years after, as evidence |
| IP fingerprint | Deleted within 30 days |
| Aggregate statistics | Indefinitely: they contain no personal data |
If you ask us to delete your data we do it within 30 days, unless a law requires us to keep something longer (invoices, for example).
9. How we protect them
We protect personal data with technical and organisational measures proportionate to the risk:
- Encryption in transit (TLS 1.2+) and at rest
- Passwords stored only as hashes, never in clear text
- Row-level security on every table: each person only reaches their own data
- The browser can neither read nor write the contact list: every sign-up goes through our server, and the database grants no public read permission
- The IP address is stored only as a one-way fingerprint, with a per-connection attempt limit
- Access limited to the team members who need it
- Regular security reviews and dependency updates
No system is 100% secure. If we detect a breach affecting you, we'll notify you and the supervisory authority within 72 hours, as required by GDPR art. 33–34.
10. Your rights
At any time you can ask us to:
- Access the data we hold about you and receive a copy
- Correct anything wrong or incomplete
- Delete everything about you
- Restrict or object to processing based on legitimate interest
- Receive your data in a format another service can read
- Withdraw consent, without having to explain why
Just write to miutifin.ask@gmail.com. We reply within 30 days, free of charge, unless a request is manifestly unfounded or excessive.
If you think we're handling your data improperly you can contact the Italian Garante per la protezione dei dati personali (garanteprivacy.it) or the authority in your country of residence.
12. Children
The platform is not intended for anyone under 16 and we don't knowingly collect their data. If you believe a minor has left us their contact, write to us: we delete it immediately.
13. Changes
We may update this policy. Material changes are communicated to active members by email at least 14 days in advance. The date and version at the top show the latest revision.
14. Contact
For any question or request about your data: miutifin.ask@gmail.com
We aim to reply within 24 hours, and always within the 30 days the GDPR allows.
Questa informativa è disponibile anche in italiano — cambia lingua dalla barra di navigazione.