Privacy Policy
Last updated: 28 August 2026
This Privacy Policy describes how Max Rome Executive Chauffeur collects, uses and protects the personal data of visitors to the website www.maxromeexecutivechauffeur.it (the "Website") and of our customers, in accordance with Regulation (EU) 2016/679 (the "GDPR") and Italian data protection legislation.
1. Data Controller
| Controller | Massimiliano Romano, operating as "Max Rome Executive Chauffeur" |
|---|---|
| Address | Via G.B. Pergolesi, 48 — 00052 Cerveteri (RM), Italy |
| VAT number | 11885461001 |
| Contact for privacy matters | maxromeexecutivechauffeur@outlook.it |
2. Data we collect
We collect only the data strictly necessary to provide our services:
- Reservation data — when you book a transfer or tour through our booking form: full name, e-mail address, telephone number, travel date and time, pickup location (e.g. hotel or address), number and type of vehicle chosen (car or van), the selected route and price, flight number (if you provide it) and any special requests you include.
- Contact data — when you send a message through the contact form: name, e-mail address, telephone number (optional), preferred date and time, and your message.
- Review data — when you publish a review: your name, country of origin (optional), star rating and comment. Reviews are published on the Website.
- Technical data — limited technical information transmitted automatically when you visit the Website (e.g. IP address, browser type), used solely to ensure the correct functioning and security of the Website.
We do not collect payment card details. Payment for services is made directly to the driver (cash or card as agreed); the Website does not process online payments.
3. Purposes and legal bases of processing
| Purpose | Legal basis (GDPR) |
|---|---|
| Handling and fulfilling your reservation, contacting you for pickup coordination, informing the assigned driver | Performance of a contract / pre-contractual steps — Art. 6(1)(b) |
| Publishing customer reviews on the Website | Consent — Art. 6(1)(a) (granted when you submit a review) |
| Compliance with legal obligations (tax and accounting records, regulatory requirements for NCC transport) | Legal obligation — Art. 6(1)(c) |
| Responding to your messages, handling complaints and disputes | Legitimate interest of the controller — Art. 6(1)(f) |
| Ensuring the security and proper functioning of the Website | Legitimate interest of the controller — Art. 6(1)(f) |
4. How we share your data
Your data is shared only to the extent necessary:
- The driver assigned to your service — receives your name, pickup details, date, time and flight information where relevant.
- Technical service providers acting as data processors under Article 28 GDPR:
- Supabase (database hosting for reservations, contact messages and reviews);
- Vercel Inc. (website hosting);
- Resend (transactional e-mail delivery of booking confirmations).
- Public authorities, where required by law (e.g. tax administration, police controls).
We do not sell, rent or trade your personal data to any third party, and we do not use it for marketing or profiling.
5. International data transfers
Some processors (Vercel, Resend) may store or process data in the United States. Where such transfers occur, they rely on the safeguards provided by the GDPR, including the EU standard contractual clauses, and are limited to the technical operation of the Website and e-mail delivery.
6. Data retention
- Reservation and contact data: kept for the time necessary to provide the service and handle any follow-up, and no longer than 24 months after the service date.
- Invoicing and accounting records: kept for 10 years, as required by Italian tax law.
- Published reviews: kept until you withdraw your consent or request their removal.
- Technical data: kept only for the duration of the browsing session or as long as needed for security purposes.
7. Security
We implement appropriate technical and organisational measures to protect your data, including encrypted HTTPS connections, access control to our systems, and processing through providers that maintain certified security standards. No method of transmission or storage is completely secure; we strive to use commercially acceptable means to protect your data.
8. Your rights under the GDPR
As a data subject you have the right to:
- Access your data and obtain a copy — Art. 15;
- Rectification of inaccurate or incomplete data — Art. 16;
- Erasure ("right to be forgotten") — Art. 17;
- Restriction of processing — Art. 18;
- Data portability — Art. 20;
- Objection to processing based on legitimate interest — Art. 21;
- Withdrawal of consent at any time (e.g. for reviews), without affecting the lawfulness of prior processing — Art. 7(3).
To exercise any of these rights, write to maxromeexecutivechauffeur@outlook.it. We will respond within one month.
You also have the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it), if you believe your data has been processed unlawfully.
9. Cookies
For information on cookies and similar technologies used by the Website, please read our Cookie Policy.
10. Children
Our services are not directed at minors. Bookings must be made by an adult, who is responsible for the accuracy of the data provided.
11. Changes to this policy
We may update this Privacy Policy from time to time. The version published on this page is always the current one. Material changes will be highlighted on the Website.