Documento legale
Privacy Policy
Aggiornato il 30 settembre 2026InComune è un'app indipendente. Non è un servizio ufficiale e non rappresenta il Comune di Novoli o altri enti pubblici.
Titolare del trattamento
Lorenzo La Grua
Email: info@incomune.app
1. Quali dati raccogliamo
Dati forniti dall'utente
- Nome e cognome - per personalizzare il profilo
- Indirizzo email - per l'autenticazione e le comunicazioni di servizio
- Password - per gli account email/password, conservata in forma crittografata (hash), mai in chiaro
- Preferiti - le entità salvate dall'utente (attività, associazioni, eventi, articoli, chiese, professionisti)
- Segnalazioni di nuove entità - quando invii una segnalazione tramite il form dedicato, raccogliamo i dati dell'entità suggerita (nome, categoria, contatti pubblici, descrizione, note). Se la segnalazione include riferimenti a persone fisiche terze (es. professionisti), garantisci di segnalare solo informazioni già pubbliche o che hai titolo a comunicare.
- Rivendiche e richieste di modifica/rimozione delle schede - se utilizzi il pulsante in fondo a ogni scheda dedicato a gestione e segnalazioni su un'attività, associazione, chiesa o professionista, raccogliamo la descrizione che fornisci, il tipo di richiesta (rivendica, modifica, rimozione), il riferimento alla scheda interessata e l'eventuale recapito di contatto opzionale. Questi dati sono visibili solo all'amministratore per la gestione della richiesta.
- Prenotazioni presso le attività - quando prenoti un appuntamento presso un'attività che ha attivato il servizio, raccogliamo il nome visualizzato, il numero di telefono (facoltativo), un'eventuale nota per l'attività, il servizio scelto, la data e l'ora richieste. Il dettaglio è nel paragrafo dedicato qui sotto.
- Iscrizione agli eventi - quando ti iscrivi a un evento che lo prevede, raccogliamo nome e cognome, il numero di eventuali accompagnatori, la data e l'ora dell'iscrizione, l'eventuale data e ora dell'ingresso se l'organizzatore ha attivato il controllo all'ingresso e, solo se l'organizzatore li richiede per quell'evento, l'email, il numero di telefono e una nota facoltativa che scegli di inserire. Se l'evento è al completo e chiedi di essere avvisato quando si libera un posto, registriamo anche questa richiesta. Il dettaglio è nel paragrafo dedicato qui sotto.
Prenotazioni e appuntamenti presso le attività
Alcune attività presenti nell'app permettono di prenotare un appuntamento direttamente da InComune. Il servizio si attiva solo se scegli di usarlo: se non prenoti nulla, non trattiamo alcun dato di prenotazione che ti riguardi.
Quali dati raccogliamo per una prenotazione:
- Nome visualizzato - il nome del tuo profilo, salvato al momento della prenotazione perché l'attività sappia chi si presenterà all'appuntamento
- Numero di telefono - facoltativo: lo fornisci solo se vuoi che l'attività possa ricontattarti in caso di imprevisti. Puoi prenotare anche senza indicarlo
- Nota per l'attività - facoltativa, il testo libero che scegli di scrivere
- Dettagli dell'appuntamento - servizio scelto, durata e prezzo indicati dall'attività al momento della prenotazione, data e ora
- Stato della prenotazione - richiesta, confermata, rifiutata, annullata da te, annullata dall'attività, scaduta, mancata presentazione o conclusa, con l'eventuale motivo della disdetta
- Nota interna dell'attività - un promemoria che l'attività può scrivere sulla prenotazione per uso organizzativo interno. Non è visibile nell'app a chi ha prenotato, ma rientra nei tuoi diritti di accesso e viene rimossa insieme agli altri dati identificativi se cancelli l'account
Chi vede questi dati: il titolare del trattamento (per far funzionare e assistere il servizio) e l'attività presso cui prenoti, tramite chi ne amministra la scheda nell'app. L'attività vede il nome visualizzato, il telefono se lo hai fornito, la nota, il servizio, la data e l'ora e lo stato della prenotazione. A parte chi amministra la scheda di quell'attività, nessun'altra attività e nessun altro utente dell'app vede le tue prenotazioni.
Base giuridica: esecuzione del servizio richiesto e misure precontrattuali adottate su tua richiesta (Art. 6.1.b GDPR). La prenotazione è un'intermediazione tecnica: l'eventuale rapporto con l'attività resta fra te e l'attività stessa.
Per quanto tempo: le prenotazioni sono conservate per 24 mesi dalla chiusura della prenotazione (appuntamento concluso, oppure prenotazione rifiutata, annullata o scaduta), poi eliminate automaticamente.
Blocco delle prenotazioni da parte di un'attività
Un'attività può decidere di non accettare più prenotazioni da un determinato utente, ad esempio dopo ripetute mancate presentazioni. Il blocco vale solo per quella attività: non limita l'uso del resto dell'app né le prenotazioni presso altre attività.
Il blocco non è nascosto: se ti riguarda, trovi una nota informativa nella scheda dell'attività e lo stato di blocco è incluso nell'export dei tuoi dati. Per chiederne il riesame puoi contattare direttamente l'attività oppure scrivere a info@incomune.app.
Base giuridica: legittimo interesse dell'attività e del titolare a prevenire abusi e usi impropri del sistema di prenotazione (Art. 6.1.f GDPR).
A supporto di questa funzione manteniamo un log tecnico dei blocchi, che registra il fatto che un blocco è stato impostato o rimosso al solo scopo di individuare comportamenti abusivi. Questo log è puramente tecnico, non è usato per profilarti e viene eliminato automaticamente entro circa 48 ore.
Iscrizione agli eventi
Alcuni eventi presenti nell'app permettono di iscriversi direttamente da InComune. Il servizio si attiva solo se scegli di usarlo: se non ti iscrivi a nessun evento, non trattiamo alcun dato di iscrizione che ti riguardi.
Quali dati raccogliamo per un'iscrizione:
- Nome e cognome - per identificarti all'ingresso dell'evento
- Numero di accompagnatori - quante persone porti con te
- Data e ora dell'iscrizione - quando ti sei iscritto
- Data e ora dell'ingresso - solo se l'organizzatore ha attivato il controllo all'ingresso per quell'evento: quando il tuo biglietto è stato convalidato
- Email, numero di telefono e nota facoltativa - solo se l'organizzatore li richiede per quell'evento: la nota è un testo libero facoltativo che scegli di inserire
- Richiesta di avviso quando si libera un posto - solo se l'evento è al completo e attivi tu stesso l'avviso: registriamo l'evento, il tuo account e la data della richiesta, al solo scopo di mandarti la notifica. Puoi disattivarlo quando vuoi, e la richiesta viene eliminata automaticamente dopo l'inizio dell'evento
- Stato dell'iscrizione e motivo di un eventuale annullamento - se l'organizzatore annulla la tua iscrizione, registriamo il motivo che indica, per potertelo comunicare
Chi vede questi dati: il titolare del trattamento (per far funzionare e assistere il servizio) e l'organizzatore dell'evento, cioè l'entità che lo pubblica (attività, associazione, chiesa, teatro, ufficio del Comune), tramite i suoi amministratori e co-amministratori. L'organizzatore non vede altri dati del tuo profilo.
Nella sua area di gestione l'organizzatore vede l'elenco degli iscritti con i dati sopra elencati, può registrare l'ingresso, può annullare un'iscrizione indicando un motivo e può esportare l'elenco in un file (formato CSV o PDF) per gestire l'ingresso anche fuori dall'app. Da quel momento il file è nelle sue mani e sotto la sua responsabilità.
Il codice QR del biglietto è un codice opaco: nessun dato personale è leggibile dal codice stesso. All'ingresso è l'organizzatore a convalidare il biglietto e a segnare l'ingresso. Può farlo anche leggendo il codice QR con la fotocamera del proprio telefono, dall'app: le immagini della fotocamera servono solo a leggere il codice e non vengono salvate né inviate. Al nostro server arriva solo il codice letto, per convalidare il biglietto.
Le notifiche legate alla tua iscrizione (conferma, annullamento, modifica di data, ora o luogo, posto liberato, promemoria il giorno prima dell'evento) sono notifiche di servizio, necessarie per gestire la tua partecipazione all'evento: le ricevi perché ti sei iscritto, anche se hai disattivato i promemoria degli eventi che segui. Puoi non riceverle più annullando l'iscrizione.
Base giuridica: esecuzione del servizio richiesto e misure precontrattuali adottate su tua richiesta (Art. 6.1.b GDPR). L'iscrizione è un'intermediazione tecnica: l'eventuale rapporto con l'organizzatore resta fra te e l'organizzatore stesso.
Per quanto tempo: le iscrizioni sono conservate per 24 mesi dalla conclusione dell'evento, poi eliminate automaticamente. Se cancelli l'account prima, le iscrizioni agli eventi non ancora cominciati vengono annullate nello stesso momento e i dati che ti identificano (nome e cognome, email, telefono, nota, motivo di un eventuale annullamento) vengono rimossi immediatamente: dell'iscrizione resta all'organizzatore solo una traccia priva di dati identificativi, intestata a «Utente eliminato» e non più collegata a te né ad alcun account, con il numero di persone, la data, l'ora, lo stato e l'eventuale ingresso registrato. Serve al conteggio delle presenze dell'organizzatore e viene eliminata alla scadenza dei 24 mesi. Le richieste di avviso per un posto libero vengono eliminate subito.
Biglietti in Google Wallet
Sui telefoni Android, quando la funzione è disponibile, se il biglietto di un'iscrizione ha il codice QR puoi aggiungerlo a Google Wallet con il pulsante «Aggiungi a Google Wallet» nella schermata del biglietto. È una scelta tua: se non tocchi il pulsante, a Google non inviamo nulla del tuo biglietto.
Cosa inviamo a Google: quando tocchi il pulsante prepariamo il pass e lo inviamo a Google, che lo conserva sui suoi server. L'invio avviene in quel momento, anche se poi non completi il salvataggio nel Wallet. Il pass contiene:
- Nome e cognome del titolare - come indicati nell'iscrizione
- Codice del biglietto - lo stesso codice QR del biglietto nell'app, che l'organizzatore legge all'ingresso
- Numero di accompagnatori - solo se porti qualcuno con te
- Stato del biglietto - valido, ingresso fatto (con l'ora dell'ingresso), iscrizione annullata, evento annullato o concluso
- Dati dell'evento - titolo, luogo e indirizzo, data e ora, il collegamento alla pagina dell'evento su incomune.app e il logo di InComune
- Identificativi tecnici - codici interni che collegano il pass alla tua iscrizione e all'evento, senza il tuo nome
Il codice QR resta un codice opaco, come nel biglietto dell'app. Come il biglietto nell'app, il pass mostra anche nome e cognome del titolare e l'eventuale numero di accompagnatori; in più, queste informazioni sono conservate anche da Google.
Aggiornamenti: se cambia lo stato della tua iscrizione (ingresso registrato, annullamento da parte tua o dell'organizzatore) o se cambiano titolo, data, ora o nome del luogo dell'evento, aggiorniamo il pass presso Google. Se l'iscrizione o l'evento vengono annullati, togliamo dal pass il codice QR e lo segniamo come non valido.
Google e i tuoi dati: Google Wallet è un servizio di Google. Sui dati del pass Google agisce come titolare autonomo del trattamento, non per nostro conto: li tratta secondo le proprie condizioni e le proprie norme sulla privacy, anche per fornire e migliorare i propri servizi. Per chi vive nello Spazio economico europeo il titolare è Google Ireland Limited (Gordon House, Barrow Street, Dublino 4, Irlanda). Se salvi il pass nel Wallet, di norma Google lo collega al tuo account Google. L'uso del Wallet è regolato dai Termini di servizio di Google, dalle Norme relative agli utenti di Google Wallet e dalle Norme sulla privacy di Google.
Base giuridica: esecuzione del servizio che hai richiesto toccando il pulsante (Art. 6.1.b GDPR), come per l'iscrizione.
Per quanto tempo: Google non consente di cancellare un pass dai suoi server. Per questo, trascorsi 30 giorni dalla fine dell'evento, togliamo dal pass nome e cognome, codice QR, accompagnatori e ora dell'ingresso e lo segniamo come scaduto. Se elimini l'account prima, avviamo la stessa operazione subito e segniamo il pass come non valido. In entrambi i casi l'operazione è automatica: se Google non risponde la ripetiamo finché non abbiamo verificato, rileggendo il pass presso Google, che nome e codice QR sono stati tolti. Da quel momento presso Google resta un pass con i soli dati dell'evento e gli identificativi tecnici, senza nome né codice, che, se lo avevi salvato, rimane nel tuo Wallet finché non lo rimuovi tu. Già entro un giorno dalla fine dell'evento, comunque, il pass compare fra quelli scaduti del Wallet. Se l'evento non ha un'ora di fine, per fine dell'evento si intendono le 6 ore successive all'inizio.
Cosa conserviamo noi: per aggiornare il pass e poterne togliere i tuoi dati, sui nostri server teniamo un record tecnico per ogni pass, con gli identificativi dell'iscrizione, dell'evento e del pass presso Google, alcune date e lo stato degli aggiornamenti. Non contiene il tuo nome né il codice del biglietto. Lo eliminiamo automaticamente dopo aver verificato che dal pass presso Google sono stati tolti i tuoi dati.
Biglietti in Apple Wallet
Sugli iPhone, quando la funzione è disponibile, se il biglietto di un'iscrizione ha il codice QR puoi aggiungerlo ad Apple Wallet con il pulsante di sistema «Aggiungi a Apple Wallet» nella schermata del biglietto. È una scelta tua: se non tocchi il pulsante, non prepariamo nessun pass.
Come nasce il pass: quando tocchi il pulsante il nostro server prepara il pass, lo firma e lo invia all'app, che lo apre nella schermata di sistema del Wallet: lì scegli se aggiungerlo. Per creare il pass non inviamo nulla ad Apple né ad altri: il pass va dal nostro server al tuo telefono. Il record tecnico descritto più sotto nasce in quel momento, anche se poi non completi l'aggiunta. Il pass contiene:
- Nome e cognome del titolare - come indicati nell'iscrizione
- Codice del biglietto - lo stesso codice QR del biglietto nell'app, che l'organizzatore legge all'ingresso
- Numero di accompagnatori - solo se porti qualcuno con te
- Stato del biglietto - quando serve: ingresso fatto (con l'ora dell'ingresso), iscrizione annullata, evento annullato o concluso
- Dati dell'evento - titolo, luogo e indirizzo, data e ora, il collegamento alla pagina dell'evento su incomune.app e il logo di InComune
- Identificativi tecnici - un codice interno che collega il pass alla tua iscrizione, senza il tuo nome, l'indirizzo del nostro servizio di aggiornamento e un codice con cui il Wallet si fa riconoscere da quel servizio
Il codice QR resta un codice opaco, come nel biglietto dell'app. Il pass è conservato nel Wallet del tuo dispositivo.
Cosa riceviamo dal Wallet: quando aggiungi il pass, il Wallet del dispositivo si registra presso il nostro servizio per riceverne gli aggiornamenti e ci comunica un identificativo del dispositivo e un token per le notifiche push, che conserviamo legati al pass con la data della registrazione. Li usiamo solo per aggiornare il pass. Ogni dispositivo su cui il pass è installato si registra per conto suo, fino a un massimo di 10 dispositivi per biglietto. Il Wallet può inviarci anche messaggi di errore tecnici sul pass: li registriamo nei log tecnici del servizio solo in forma troncata (al massimo 10 messaggi di 300 caratteri per invio) e dopo averne tolto il codice del biglietto e i codici tecnici lunghi.
Aggiornamenti: se cambia lo stato della tua iscrizione (ingresso registrato, annullamento da parte tua o dell'organizzatore) o se cambiano titolo, data, ora, nome del luogo o indirizzo dell'evento, inviamo a ogni dispositivo registrato un avviso tramite il servizio di notifiche push di Apple (APNs). L'avviso è vuoto, non contiene dati del biglietto: serve solo a far scaricare al dispositivo la nuova versione del pass dal nostro servizio. È un tentativo: il pass si aggiorna solo quando il dispositivo riceve l'avviso e si collega al nostro servizio, e finché non lo fa sul telefono resta la versione precedente. Se l'iscrizione o l'evento vengono annullati, la nuova versione non ha più il codice QR ed è segnata come non valida. Se Apple ci segnala che il token di un dispositivo non è più valido, cancelliamo quella registrazione.
Apple e i tuoi dati: i dati del biglietto non li inviamo ad Apple. Ad Apple arrivano solo, tramite APNs, il token push del dispositivo e l'avviso vuoto: per questo APNs opera come nostro fornitore tecnico (vedi il punto 3). Apple Wallet è un'app di Apple sul tuo dispositivo: se usi iCloud, Apple può conservare i pass del tuo Wallet anche in iCloud, secondo le impostazioni del tuo account Apple e secondo le condizioni e l'informativa sulla privacy di Apple. Non lo gestiamo noi e da iCloud non riceviamo nulla.
Base giuridica: esecuzione del servizio che hai richiesto toccando il pulsante (Art. 6.1.b GDPR), come per l'iscrizione.
Per quanto tempo: il pass sul tuo dispositivo resta nel Wallet finché non lo rimuovi tu. Alla fine dell'evento il pass scade: la data di scadenza è scritta nel pass stesso. Trascorsi 30 giorni dalla fine dell'evento, oppure subito se elimini l'account prima, proviamo ad aggiornare il pass su ogni dispositivo registrato per annullarlo e togliere nome e cognome, codice QR, accompagnatori e ora dell'ingresso: da quel momento il nostro servizio fornisce solo questa versione, e ripetiamo l'avviso una volta al giorno per 30 giorni, poi cancelliamo le registrazioni dei dispositivi, con i loro identificativi e token. Senza eliminazione dell'account, quindi, le registrazioni restano di norma fino a circa 60 giorni dalla fine dell'evento. Se elimini l'account mentre questi 30 giorni sono in corso, ripartono da quel momento. Se in quel periodo un dispositivo non si collega, la copia del pass su quel telefono può restare quella precedente, finché non la rimuovi tu: dopo la cancellazione delle registrazioni il pass non si aggiorna più. In ogni momento, se il Wallet di un dispositivo ci comunica che non vuole più ricevere aggiornamenti per il pass, cancelliamo subito quella registrazione. Se l'evento non ha un'ora di fine, per fine dell'evento si intendono le 6 ore successive all'inizio.
Cosa conserviamo noi: per aggiornare il pass, sui nostri server teniamo un record tecnico per ogni pass, con gli identificativi dell'iscrizione e dell'evento, alcune date e lo stato degli aggiornamenti, e le registrazioni dei dispositivi descritte sopra. Il record non contiene il tuo nome né il codice del biglietto. Lo eliminiamo automaticamente alla fine dei 30 giorni di aggiornamento descritti sopra, oppure prima, se nessun dispositivo è registrato. Se avevi aggiunto lo stesso biglietto anche a Google Wallet, lo eliminiamo solo dopo aver verificato che dal pass presso Google sono stati tolti i tuoi dati.
Schede pre-popolate da fonti pubbliche
Le schede di attività commerciali, associazioni, chiese, professionisti e luoghi pubblici di Novoli sono state create raccogliendo dati già resi pubblici dalle entità stesse: profili Google Maps / Google Business, pagine Facebook ufficiali, siti web istituzionali, comunicazioni pubbliche del Comune. I dati pubblicati si limitano a informazioni di contatto pubbliche (nome, indirizzo, telefono, email pubblica, sito, social) e non includono dati personali sensibili.
Per le schede dei professionisti (persone fisiche o ditte individuali) pre-popolate da fonti pubbliche, la base giuridica è il legittimo interesse (Art. 6.1.f GDPR), allo stesso titolo delle altre schede: i dati pubblicati si limitano a contatti già resi pubblici dal professionista. Il consenso (Art. 6.1.a GDPR) si applica invece quando è il professionista stesso a segnalarsi o a rivendicare la propria scheda. In entrambi i casi la scheda include sempre il pulsante in fondo dedicato a gestione e segnalazioni, per facilitare l'esercizio dei diritti GDPR.
Schede in evidenza (sponsorizzazione)
Il gestore della piattaforma può mettere in evidenza, per un periodo di tempo definito, la scheda di un'attività, di un evento o di un'associazione (ad esempio anteponendola nelle liste o segnalandola con un distintivo). Questa scelta è editoriale e a discrezione del gestore della piattaforma. I dati trattati sono le date di inizio e fine della messa in evidenza, associate alla scheda dell'entità: non comporta la raccolta di dati personali ulteriori rispetto a quelli già pubblicati sulla scheda stessa, e non riguarda dati di navigazione degli utenti che la visualizzano. Gli amministratori e co-amministratori della scheda ricevono una notifica quando la messa in evidenza inizia e quando termina.
Base giuridica: legittimo interesse del titolare alla gestione editoriale della piattaforma (Art. 6.1.f GDPR).
Per quanto tempo: le date di inizio e fine restano associate alla scheda finché la scheda stessa esiste nell'app.
Informativa agli interessati delle schede pre-popolate (Art. 14)
Quando pubblichiamo una scheda a partire da fonti pubbliche, i dati non ci sono forniti direttamente dall'interessato. In questi casi, ai sensi dell'Art. 14 GDPR, mettiamo a disposizione un'informativa dedicata che spiega quali dati trattiamo, da quali fonti provengono, su quale base giuridica, per quanto tempo e come opporsi, rettificare o richiedere la rimozione. La trovi qui: Informativa agli interessati delle schede (Art. 14).
Accesso con provider esterni
- L'utente può scegliere di accedere anche tramite Google o Apple
- In questo caso riceviamo dal provider i dati necessari per autenticare e creare l'account, come ad esempio indirizzo email e, se disponibile, nome
- Per questi account, le credenziali di accesso possono essere gestite dal provider esterno e alcune modifiche (ad esempio password o email di accesso) potrebbero non essere disponibili direttamente nell'app
Dati raccolti automaticamente
- Token di notifica push - identificativo tecnico del dispositivo per l'invio di notifiche (tramite Expo Push Service)
- Piattaforma - iOS o Android, per l'invio corretto delle notifiche
- Dati di utilizzo - pagine visitate, funzionalità utilizzate, durata delle sessioni, tramite PostHog Analytics (server UE). Questi dati sono associati a un identificativo tecnico pseudonimo persistente sul dispositivo (mai il tuo nome o email) e vengono raccolti solo previo tuo consenso: al primo avvio l'app chiede il consenso con un banner dedicato e, finché non lo concedi, non raccoglie alcuna statistica. Puoi concederlo o revocarlo in qualsiasi momento da Profilo, sezione «Privacy e dati». Questo identificativo è distinto dall'identità del tuo account: quando elimini l'account viene rimosso, così le statistiche già raccolte non sono più collegabili a te e restano solo in forma anonima (ed eliminate comunque entro 12 mesi).
- Report di errori e crash - stack trace JavaScript e nativo, versione dell'app, modello del dispositivo e sistema operativo, breadcrumbs tecnici (es. aggiornamenti OTA scaricati), quando l'app va in crash o genera un errore non gestito. Per la generalità degli utenti questi report sono de-identificati (nessun collegamento al tuo account); l'identificativo utente pseudonimo (UUID interno, mai email o nome) e il ruolo vengono allegati solo per gli account amministratori che gestiscono il servizio. Il monitoraggio avviene tramite Sentry, su iOS e Android. Non raccogliamo il contenuto delle schermate né screenshot, non raccogliamo l'indirizzo IP. Finalità: diagnostica tecnica e stabilità del servizio.
- Immagini di contenuto - foto e immagini caricate dagli amministratori per locandine, loghi, cover e post (non foto personali degli utenti).
Dati che NON raccogliamo
- Posizione geografica (GPS)
- Foto o immagini personali dell'utente (il caricamento immagini è riservato agli amministratori per contenuti pubblici)
- Contatti della rubrica
- Dati di pagamento
- Dati biometrici
2. Perché raccogliamo i dati
| Finalità | Base giuridica (GDPR) |
|---|---|
| Registrazione e autenticazione | Esecuzione del contratto (Art. 6.1.b) |
| Invio notifiche push | Consenso dell'utente (Art. 6.1.a) |
| Salvataggio preferiti | Esecuzione del contratto (Art. 6.1.b) |
| Analisi di utilizzo (pseudonime) | Consenso dell'utente (Art. 6.1.a) |
| Monitoraggio errori tecnici (de-identificati) | Legittimo interesse (Art. 6.1.f) |
| Comunicazioni di servizio | Obbligo legale (Art. 6.1.c) |
| Gestione e moderazione di segnalazioni inviate dagli utenti | Esecuzione del contratto (Art. 6.1.b) |
| Trattamento di dati di persone fisiche terze presenti nelle segnalazioni | Legittimo interesse (Art. 6.1.f) |
| Pubblicazione di schede di attività, associazioni, chiese e luoghi pubblici a partire da fonti pubbliche | Legittimo interesse (Art. 6.1.f) |
| Pubblicazione di schede di professionisti (persone fisiche / ditte individuali) pre-popolate da fonti pubbliche | Legittimo interesse (Art. 6.1.f) |
| Schede di professionisti auto-segnalate o rivendicate dal titolare | Consenso esplicito o auto-segnalazione (Art. 6.1.a) |
| Gestione di rivendiche e richieste di modifica/rimozione delle schede | Esecuzione del contratto e diritti dell'interessato (Art. 6.1.b, Art. 16, 17, 21 GDPR) |
| Gestione delle prenotazioni e degli appuntamenti presso le attività | Esecuzione del servizio e misure precontrattuali su richiesta dell'interessato (Art. 6.1.b) |
| Blocco delle prenotazioni disposto da un'attività e log tecnico anti-abuso (conservato max ~48 ore) | Legittimo interesse (Art. 6.1.f) |
| Gestione dell'iscrizione e dell'ingresso agli eventi da parte di chi li organizza | Esecuzione del servizio e misure precontrattuali su richiesta dell'interessato (Art. 6.1.b) |
| Creazione e aggiornamento del biglietto in Google Wallet, solo su tua richiesta | Esecuzione del servizio richiesto dall'interessato (Art. 6.1.b) |
| Creazione e aggiornamento del biglietto in Apple Wallet, solo su tua richiesta | Esecuzione del servizio richiesto dall'interessato (Art. 6.1.b) |
| Messa in evidenza (sponsorizzazione) di una scheda, decisa dal gestore della piattaforma | Legittimo interesse (Art. 6.1.f) |
Interesse legittimo perseguito (Art. 6.1.f): individuare e diagnosticare malfunzionamenti tecnici dell'app, garantire la stabilità e la sicurezza del servizio, fornire ai cittadini un punto di riferimento aggiornato sulle realtà locali a partire da informazioni già pubbliche, e prevenire abusi e usi impropri del sistema di prenotazione a tutela delle attività che lo offrono. Le analisi di utilizzo, invece, sono trattate solo previo consenso (Art. 6.1.a). I dati pubblicati sulle schede sono limitati a informazioni già rese pubbliche dalle entità stesse, l'impatto sulla privacy degli interessati è minimo, ed è sempre disponibile dal pulsante «Sei il titolare?» un canale visibile per esercitare il diritto di opposizione, rettifica o cancellazione (Art. 21, 16, 17 GDPR).
3. Con chi condividiamo i dati
I dati personali non vengono venduti, ceduti o condivisi con terze parti per finalità commerciali.
Quattro comunicazioni a soggetti diversi dai fornitori tecnici elencati qui sotto sono previste, e non hanno finalità commerciali: la prenotazione di un appuntamento, l'iscrizione a un evento, l'aggiunta di un biglietto a Google Wallet e la notifica agli altri amministratori di pagina di un'entità quando un amministratore viene aggiunto, rimosso o lascia il ruolo, le ultime due descritte più sotto. Ad oggi sono gli unici casi. I dati della prenotazione sono comunicati all'attività che hai scelto, perché possa gestire l'appuntamento; i dati dell'iscrizione sono comunicati all'organizzatore dell'evento, cioè l'entità che lo pubblica, perché possa gestire l'iscrizione e l'ingresso. Nei primi due casi la comunicazione avviene solo per l'attività presso cui prenoti o l'evento a cui ti iscrivi, e solo per i dati descritti al punto 1. Nella gestione dell'appuntamento o dell'iscrizione, l'attività o l'organizzatore agisce in autonomia rispetto alle proprie finalità: se vuoi che cancelli i dati che detiene, puoi rivolgerti direttamente a chi li detiene oppure scrivere a info@incomune.app e faremo da tramite.
I seguenti servizi tecnici trattano i dati per nostro conto (responsabili del trattamento):
| Servizio | Finalità | Sede dati |
|---|---|---|
| Supabase (supabase.com) | Database, autenticazione, storage | Francoforte, Germania (UE) |
| Expo (expo.dev) | Invio notifiche push | Stati Uniti* |
| Apple Push Notification Service (APNs) | Consegna notifiche push su dispositivi iOS e avvisi di aggiornamento dei biglietti in Apple Wallet | Stati Uniti* |
| Firebase Cloud Messaging (Google FCM) | Consegna notifiche push su dispositivi Android | Stati Uniti* |
| PostHog (posthog.com) | Analytics (dati pseudonimi) | Unione Europea |
| Sentry (sentry.io, Functional Software Inc.) | Monitoraggio errori e crash su iOS e Android (dati pseudonimi) | Unione Europea |
| Resend (resend.com, Plus Five Five, Inc.) | Invio delle email di accesso (conferma dell'indirizzo, reimpostazione della password) | Stati Uniti* (spedizione tramite Amazon SES, Irlanda) |
I servizi Expo Push Notifications, Apple (APNs), Google (FCM) e Resend trattano dati su server negli Stati Uniti. Questo costituisce un trasferimento di dati extra-UE. Per le notifiche push i dati trasferiti sono il token push del dispositivo e il contenuto della notifica: titolo e testo possono contenere il nome di un'altra persona (per esempio, per chi gestisce un'attività, il nome di chi ha prenotato o disdetto; per gli amministratori di pagina, il nome di un altro amministratore) oppure un breve messaggio scritto da un gestore o da un organizzatore (per esempio il motivo dell'annullamento di una prenotazione o di un'iscrizione), oltre al testo dei post e degli avvisi del team di InComune. Per le email di accesso il dato trasferito è l'indirizzo email, con il link di conferma o di reimpostazione. Il trasferimento verso Apple e Google si fonda sulla decisione di adeguatezza «EU-US Data Privacy Framework» (Decisione di esecuzione UE 2023/1795), cui tali società aderiscono; il trasferimento verso Expo avviene sulla base delle Clausole Contrattuali Standard (SCC) adottate dalla Commissione Europea; il trasferimento verso Resend si fonda sul Data Privacy Framework, cui la società aderisce, e sulle Clausole Contrattuali Standard. Sentry tratta i dati di crash su server nell'Unione Europea (data region UE), quindi senza trasferimento extra-UE.
Google Wallet. Se aggiungi un biglietto a Google Wallet, i dati del pass descritti al punto 1 sono comunicati a Google, che non è un nostro responsabile ma un titolare autonomo: per chi vive nello Spazio economico europeo, Google Ireland Limited (Irlanda). Google li tratta secondo le proprie condizioni e le proprie norme sulla privacy, anche per fornire e migliorare i propri servizi. Avviene solo se tocchi tu il pulsante, e solo per quel biglietto. Google dichiara che i dati possono essere trattati su server situati anche fuori dal paese in cui vivi, compresi gli Stati Uniti: per questi trasferimenti Google si basa sulla decisione di adeguatezza «EU-US Data Privacy Framework» (Decisione di esecuzione UE 2023/1795), cui Google LLC aderisce, e, dove questa non si applica, sulle Clausole Contrattuali Standard.
Apple Wallet. Se aggiungi un biglietto ad Apple Wallet, i dati del pass non sono comunicati a terzi: il pass va dal nostro server al tuo dispositivo. Ad Apple, tramite APNs, arrivano solo il token push del dispositivo e un avviso vuoto che chiede al dispositivo di scaricare la nuova versione del pass (vedi il punto 1).
Amministratori di pagina. Se sei amministratore di pagina di un'entità, quando vieni aggiunto al ruolo, ne vieni rimosso o lo lasci, gli altri amministratori della stessa entità ricevono una notifica con il tuo nome, come indicato nel tuo profilo. Il nome non compare nella scheda pubblica dell'entità: l'elenco degli amministratori lo vede solo il team di InComune.
4. Dove conserviamo i dati
I dati personali (profilo, email, preferiti, notifiche, prenotazioni, iscrizioni agli eventi) sono conservati su server nell'Unione Europea (Supabase - Francoforte, Germania). Le analisi di utilizzo sono processate su server UE (PostHog EU).
I token di notifica push e il contenuto delle notifiche (titolo e testo, vedi il punto 3) sono trasferiti negli Stati Uniti tramite Expo Push Service (Clausole Contrattuali Standard), e successivamente trasmessi ad Apple (APNs) e Google (FCM), aderenti all'EU-US Data Privacy Framework, per la consegna della notifica al dispositivo.
Le email di accesso (conferma dell'indirizzo, reimpostazione della password) sono inviate tramite Resend, che tratta i dati negli Stati Uniti (Data Privacy Framework e Clausole Contrattuali Standard) e spedisce i messaggi tramite Amazon SES da server in Irlanda.
I report di errori e crash (stack trace, metadati dispositivo, identificativo utente pseudonimo, breadcrumbs tecnici) sono trattati tramite Sentry, su iOS e Android, su server nell'Unione Europea.
Se aggiungi un biglietto a Google Wallet, il pass è conservato sui server di Google, che possono trovarsi anche fuori dall'Unione Europea (vedi il punto 3), con i tempi descritti al punto 1. Il record tecnico che ci serve per aggiornarlo resta sui nostri server nell'Unione Europea.
Se aggiungi un biglietto ad Apple Wallet, il pass è conservato sul tuo dispositivo e, se usi iCloud, secondo le impostazioni del tuo account Apple. Il record tecnico e le registrazioni dei dispositivi restano sui nostri server nell'Unione Europea; per gli aggiornamenti il token push del dispositivo è trasmesso ad Apple (APNs), come descritto al punto 3.
5. Per quanto tempo conserviamo i dati
| Dato | Durata |
|---|---|
| Profilo utente (nome, email) | Eliminato alla cancellazione dell'account |
| Accettazione dei Termini e presa visione della Privacy Policy (data, versione, come è avvenuta: registrazione o app) | Conservate per tutta la durata dell'account ed eliminate alla sua cancellazione. Incluse nell'export dei dati. |
| Preferiti | Eliminati alla cancellazione dell'account |
| Token di notifica push | Eliminati alla cancellazione dell'account o alla disattivazione delle notifiche |
| Notifiche ricevute | Eliminate alla cancellazione dell'account o dopo 30 giorni automaticamente |
| Immagini caricate da admin (locandine, loghi, cover) | Non collegate al profilo personale; rimangono associate all'entità pubblica e non vengono eliminate alla cancellazione dell'account |
| Segnalazioni di nuove entità | Conservate fino alla revisione (approvazione o rifiuto). Le segnalazioni rifiutate sono eliminate entro 90 giorni. Le segnalazioni approvate diventano parte del contenuto pubblico della scheda creata. |
| Rivendiche e richieste di modifica/rimozione | Conservate fino alla revisione (accolta o rifiutata). Le richieste rifiutate sono eliminate entro 90 giorni. Quando una rivendica viene accolta, l'utente viene assegnato come titolare della scheda. |
| Segnalazioni di contenuti (notice-and-action DSA) | Conservate fino a 12 mesi dalla chiusura della segnalazione, per documentare la corretta gestione ai sensi del Digital Services Act (Reg. UE 2022/2065), poi eliminate automaticamente. |
| Schede di entità oggetto di richiesta di rimozione accolta | La scheda viene nascosta subito a tutti gli utenti. L'eliminazione fisica avviene automaticamente dopo 7 giorni: in questa finestra l'amministratore può annullare l'eliminazione se attivata per errore. Trascorsi i 7 giorni la cancellazione è definitiva. |
| Prenotazioni (nome visualizzato, telefono facoltativo, nota, servizio, data e ora, stato, nota interna dell'attività) | 24 mesi dalla chiusura della prenotazione (appuntamento concluso, oppure prenotazione rifiutata, annullata o scaduta), poi eliminazione automatica. Se cancelli l'account prima, nome, telefono, nota, nota interna dell'attività e motivo della disdetta vengono rimossi subito: della prenotazione resta solo la traccia priva di dati identificativi, che resta disponibile all'attività per la continuità della propria agenda fino alla scadenza dei 24 mesi. |
| Iscrizioni agli eventi (nome e cognome, numero di accompagnatori, data e ora dell'iscrizione, eventuale data e ora dell'ingresso, stato e motivo di un eventuale annullamento, email/telefono/nota facoltativi se richiesti dall'organizzatore) | 24 mesi dalla conclusione dell'evento, poi eliminazione automatica. Se cancelli l'account prima, le iscrizioni agli eventi non ancora cominciati vengono annullate e i dati che ti identificano (nome e cognome, email, telefono, nota, motivo dell'annullamento) vengono rimossi subito: dell'iscrizione resta solo la traccia priva di dati identificativi, intestata a «Utente eliminato», che resta disponibile all'organizzatore per il conteggio delle presenze fino alla scadenza dei 24 mesi. |
| Richiesta di avviso quando si libera un posto (evento, account, data della richiesta) | Conservata finché non disattivi l'avviso e in ogni caso eliminata automaticamente dopo l'inizio dell'evento. È eliminata subito alla cancellazione dell'account. |
| Biglietto aggiunto a Google Wallet, presso Google (nome e cognome, codice QR, accompagnatori, stato e ora dell'ingresso, dati dell'evento) | Google non consente di cancellarlo. Trascorsi 30 giorni dalla fine dell'evento togliamo dal pass nome e cognome, codice QR, accompagnatori e ora dell'ingresso e lo segniamo come scaduto; se elimini l'account prima, avviamo subito la stessa operazione e lo segniamo come non valido. Se lo avevi salvato, il pass resta nel tuo Wallet, senza questi dati, finché non lo rimuovi tu. |
| Record tecnico del pass Google Wallet presso di noi (identificativi dell'iscrizione, dell'evento e del pass, date, stato degli aggiornamenti; nessun nome né codice del biglietto) | Eliminato automaticamente dopo aver verificato che dal pass presso Google sono stati tolti i tuoi dati, cioè dopo i 30 giorni dalla fine dell'evento o dopo la cancellazione dell'account. Il riferimento tecnico all'evento, senza dati personali, è eliminato quando per quell'evento non restano più pass. |
| Biglietto aggiunto ad Apple Wallet, sul tuo dispositivo (nome e cognome, codice QR, accompagnatori, stato e ora dell'ingresso, dati dell'evento) | Resta nel tuo Wallet finché non lo rimuovi tu, e scade alla fine dell'evento. Trascorsi 30 giorni dalla fine dell'evento, oppure subito se elimini l'account prima, per 30 giorni proviamo ad aggiornarlo per annullarlo e togliere nome e cognome, codice QR, accompagnatori e ora dell'ingresso; su un dispositivo che in quel periodo non si collega può restare la versione precedente. |
| Registrazioni dei dispositivi per Apple Wallet presso di noi (identificativo del dispositivo, token push, data della registrazione) | Cancellate alla fine dei 30 giorni di aggiornamento, cioè di norma circa 60 giorni dopo la fine dell'evento, oppure 30 giorni dopo la cancellazione dell'account. Prima, se il Wallet del dispositivo ci comunica che non vuole più aggiornamenti per il pass o se Apple ci segnala che il token non è più valido. |
| Record tecnico del pass Apple Wallet presso di noi (identificativi dell'iscrizione e dell'evento, date, stato degli aggiornamenti; nessun nome né codice del biglietto) | Eliminato automaticamente alla fine dei 30 giorni di aggiornamento, oppure prima, se nessun dispositivo è registrato. Se lo stesso biglietto è anche in Google Wallet, solo dopo aver verificato che dal pass presso Google sono stati tolti i tuoi dati. |
| Stato di blocco delle prenotazioni presso un'attività | Conservato finché l'attività non lo rimuove, perché è la condizione stessa che impedisce nuove prenotazioni presso quell'attività. È sempre visibile all'interessato nella scheda dell'attività ed è incluso nell'export dei dati. In ogni caso è eliminato alla cancellazione dell'account. |
| Log tecnico dei blocchi (anti-abuso) | Eliminato automaticamente entro circa 48 ore |
| Dati di analytics (PostHog, pseudonimi) | Alla cancellazione dell'account l'identificativo analytics viene eliminato e i dati restano solo in forma anonima (non più collegabili a te); in ogni caso eliminati entro 12 mesi. Per una cancellazione anticipata scrivere a info@incomune.app |
| Report di errori e crash (Sentry, pseudonimi) | 90 giorni (retention di default Sentry); per richiedere la cancellazione scrivere a info@incomune.app |
| Backup di sistema | Copie temporanee fino a 30 giorni per ragioni tecniche, poi sovrascritte automaticamente; non accessibili in questo periodo |
6. I tuoi diritti
In base al GDPR (Regolamento UE 2016/679), hai diritto a:
- Accesso - sapere quali dati abbiamo su di te
- Rettifica - correggere dati inesatti
- Cancellazione - eliminare il tuo account con profilo, preferiti e token push associati. I dati identificativi delle prenotazioni (nome, telefono, nota, nota interna dell'attività e motivo della disdetta) vengono rimossi contestualmente e gli appuntamenti futuri, in attesa o confermati, vengono annullati, con avviso all'attività interessata. Anche le iscrizioni agli eventi non ancora cominciati vengono annullate e i dati che ti identificano (nome e cognome, email, telefono, nota, motivo dell'annullamento) vengono rimossi contestualmente: dell'iscrizione resta solo la traccia priva di dati identificativi, intestata a «Utente eliminato». Se avevi aggiunto un biglietto a Google Wallet, avviamo subito la rimozione dal pass di nome e cognome, codice QR, accompagnatori e ora dell'ingresso e lo segniamo come non valido: Google non consente di cancellarlo, quindi, se lo avevi salvato, resta nel tuo Wallet, senza questi dati, finché non lo rimuovi tu. Se avevi aggiunto un biglietto ad Apple Wallet, per 30 giorni proviamo ad aggiornarlo sui tuoi dispositivi per annullarlo e togliere gli stessi dati: se in quel periodo un dispositivo non si collega, il pass su quel telefono può restare quello precedente, finché non lo rimuovi tu
- Portabilità - ricevere i tuoi dati in formato leggibile, scrivendo a info@incomune.app: l'export include anche le tue prenotazioni, le tue iscrizioni agli eventi e l'eventuale stato di blocco presso un'attività
- Opposizione - opporti al trattamento basato su legittimo interesse
- Revoca del consenso - disattivare le notifiche push o le statistiche di utilizzo in qualsiasi momento (da Profilo, sezione «Privacy e dati»)
Come esercitare i tuoi diritti
- Cancellazione account: direttamente dall'app (Profilo -> Elimina account)
- Notifiche: disattivabili dalle impostazioni dell'app
- Statistiche di utilizzo: puoi concedere o revocare il consenso in qualsiasi momento da Profilo, sezione «Privacy e dati»
- Rettifica per account con login social (Google/Apple): se non puoi modificare direttamente email o credenziali dall'app, scrivi a info@incomune.app
- Diritti su una scheda di entità (attività, associazione, chiesa, professionista): usa il pulsante in fondo a ogni scheda dedicato a gestione e segnalazioni per rivendicarla, richiederne la modifica o l'eliminazione. In alternativa, scrivi a info@incomune.app
- Prenotazioni: le trovi nell'app, dove puoi anche annullare quelle ancora in attesa e, entro il termine di disdetta indicato dall'attività, quelle confermate. Sono incluse nell'export dei tuoi dati, che puoi richiedere scrivendo a info@incomune.app, insieme all'eventuale stato di blocco presso un'attività
- Blocco delle prenotazioni presso un'attività: se ti riguarda, lo vedi indicato nella scheda dell'attività. Per chiederne il riesame rivolgiti all'attività oppure scrivi a info@incomune.app
- Iscrizioni agli eventi: le trovi nell'app, dove puoi anche annullarle fino all'inizio dell'evento e disattivare l'eventuale richiesta di avviso per un posto libero. Sono incluse nell'export dei tuoi dati, che puoi richiedere scrivendo a info@incomune.app
- Biglietti in Google Wallet: puoi rimuovere il pass dal tuo Wallet quando vuoi, ma presso Google resta finché non ne togliamo i tuoi dati: se vuoi che lo facciamo prima dei 30 giorni, scrivi a info@incomune.app. Per i dati che Google tratta secondo le proprie norme sulla privacy puoi rivolgerti anche a Google; per tutto il resto scrivi a info@incomune.app
- Biglietti in Apple Wallet: il pass sta sul tuo dispositivo e puoi rimuoverlo dal Wallet quando vuoi. Per le registrazioni dei dispositivi e il record tecnico che conserviamo noi scrivi a info@incomune.app; per le copie che Apple conserva in iCloud puoi rivolgerti ad Apple
- Altre richieste: scrivi a info@incomune.app
Risponderemo entro 30 giorni dalla richiesta.
Hai inoltre il diritto di presentare un reclamo al Garante per la protezione dei dati personali (www.garanteprivacy.it).
7. Età minima
InComune è destinata a utenti di almeno 14 anni. Non raccogliamo consapevolmente dati di minori di 14 anni. Se un genitore o tutore ritiene che la registrazione di un minore sia avvenuta senza consenso, può contattarci a info@incomune.app per richiedere la cancellazione dell'account.
8. Sicurezza
- Autenticazione con password crittografate (hash)
- Per gli account con login social, autenticazione delegata al provider scelto dall'utente
- Row Level Security (RLS) su tutte le tabelle del database
- Comunicazioni crittografate (HTTPS/TLS)
- Accesso ai dati limitato al titolare del trattamento
- Registrazione della data e della versione dei Termini accettati e della presa visione della presente Privacy Policy, con lo storico, per poter dimostrare quali testi ti sono stati presentati e quando (Art. 5.2 GDPR)
9. Modifiche alla privacy policy
Ci riserviamo di aggiornare questa policy. In caso di modifiche sostanziali ti avvisiamo con un messaggio nell'app, la prima volta che la apri dopo l'aggiornamento. La data dell'ultimo aggiornamento è indicata in cima a questo documento.
Il sito web incomune.app
Il sito incomune.app è un sito statico ospitato su GitHub Pages. Non utilizza cookie di profilazione né strumenti di analytics o pubblicità. I caratteri tipografici sono serviti direttamente dal nostro sito (self-hosted) e non da CDN di terze parti: di conseguenza la semplice consultazione delle pagine, incluse quelle legali, non comporta la trasmissione del tuo indirizzo IP a Google o ad altri fornitori esterni per il caricamento dei font.
10. Contatti
Lorenzo La Grua
Email: info@incomune.app
Privacy Policy
Last updated September 30, 2026InComune is an independent app. It is not an official service and does not represent the Municipality of Novoli or any other public body.
Data Controller
Lorenzo La Grua
Email: info@incomune.app
1. What data we collect
Data provided by the user
- Full name - to personalize your profile
- Email address - for authentication and service communications
- Password - for email/password accounts, stored in encrypted form (hash), never in plain text
- Favorites - entities saved by the user (businesses, associations, events, articles, churches, professionals)
- New entity suggestions - when you submit a suggestion through the dedicated form, we collect the data of the suggested entity (name, category, public contact details, description, notes). If the suggestion includes references to third-party natural persons (e.g. professionals), you warrant that you are only reporting information that is already public or that you are entitled to disclose.
- Listing claims and edit/removal requests - if you use the button at the bottom of each listing dedicated to management and reports on a business, association, church, or professional listing, we collect the description you provide, the request type (claim, edit, removal), the reference to the listing, and any optional contact details you choose to share. This data is only visible to the administrator handling the request.
- Bookings with businesses - when you book an appointment with a business that has enabled the service, we collect your display name, phone number (optional), an optional note for the business, the service selected, and the requested date and time. Details are in the dedicated paragraph below.
- Event registrations - when you register for an event that supports it, we collect your first and last name, the number of guests you bring, the date and time of your registration, the date and time of your entry if the organizer has enabled entry control, and, only if the organizer requires them for that event, your email, phone number, and an optional note you choose to add. If the event is full and you ask to be notified when a spot frees up, we also record that request. Details are in the dedicated paragraph below.
Bookings and appointments with businesses
Some businesses listed in the app allow you to book an appointment directly from InComune. The service is only activated if you choose to use it: if you never book anything, we process no booking data about you.
What we collect for a booking:
- Display name - your profile name, saved at the time of booking so the business knows who will be showing up for the appointment
- Phone number - optional: you provide it only if you want the business to be able to contact you if something changes. You can book without it
- Note for the business - optional free text you choose to write
- Appointment details - service selected, duration and price as stated by the business at the time of booking, date and time
- Booking status - requested, confirmed, rejected, cancelled by you, cancelled by the business, expired, no-show, or completed, together with any cancellation reason
- Internal note by the business - a reminder the business can attach to the booking for its own organizational use. It is not shown in the app to the person who booked, but it falls within your right of access and is removed along with the other identifying data if you delete your account
Who sees this data: the data controller (to operate and support the service) and the business you book with, through whoever administers its listing in the app. The business sees your display name, your phone number if you provided one, the note, the service, the date and time, and the booking status. Apart from whoever administers that business listing, no other business and no other user of the app sees your bookings.
Legal basis: performance of the requested service and pre-contractual measures taken at your request (Art. 6.1.b GDPR). The booking is a technical intermediation: any resulting relationship remains between you and the business.
How long: bookings are kept for 24 months from the closing of the booking (appointment completed, or booking rejected, cancelled, or expired), then automatically deleted.
Booking blocks set by a business
A business may decide to stop accepting bookings from a given user, for example after repeated no-shows. The block applies only to that business: it does not restrict the rest of the app, nor bookings with other businesses.
The block is not hidden: if it applies to you, you will find an informational note in the business listing, and the block status is included in your data export. To request a review of it, you can contact the business directly or write to info@incomune.app.
Legal basis: the legitimate interest of the business and of the data controller in preventing abuse and misuse of the booking system (Art. 6.1.f GDPR).
To support this feature we keep a technical block log, recording that a block was set or lifted, for the sole purpose of detecting abusive behavior. This log is purely technical, is not used to profile you, and is automatically deleted within approximately 48 hours.
Event registrations
Some events listed in the app allow you to register directly from InComune. The service is only activated if you choose to use it: if you never register for an event, we process no registration data about you.
What we collect for a registration:
- First and last name - to identify you at the event entrance
- Number of guests - how many people you bring with you
- Date and time of registration - when you registered
- Date and time of entry - only if the organizer has enabled entry control for that event: when your ticket was validated
- Email, phone number, and optional note - only if the organizer requires them for that event: the note is optional free text you choose to write
- Request to be notified when a spot frees up - only if the event is full and you turn the notice on yourself: we record the event, your account and the date of the request, for the sole purpose of sending you the notification. You can turn it off at any time, and the request is automatically deleted once the event has started
- Registration status and reason for any cancellation - if the organizer cancels your registration, we record the reason given, so that we can pass it on to you
Who sees this data: the data controller (to operate and support the service) and the event organizer, i.e. the entity that publishes it (business, association, church, theatre, municipal office), through its administrators and co-administrators. The organizer does not see any other data from your profile.
In its management area the organizer sees the attendee list with the data above, can record entry, can cancel a registration stating a reason, and can export the list to a file (CSV or PDF format) in order to manage entry outside the app too. From that moment the file is in the organizer's hands and under its own responsibility.
The QR code on the ticket is an opaque code: no personal data is readable from the code itself. At the entrance it is the organizer who validates the ticket and records entry. The organizer can also do so by reading the QR code with their own phone's camera, from the app: the camera images are used only to read the code and are neither saved nor sent. Only the code that has been read reaches our server, to validate the ticket.
Notifications related to your registration (confirmation, cancellation, change of date, time, or location, spot freed up, a reminder the day before the event) are service notifications, necessary to manage your participation in the event: you receive them because you registered, even if you turned off reminders for the events you follow. You can stop receiving them by cancelling your registration.
Legal basis: performance of the requested service and pre-contractual measures taken at your request (Art. 6.1.b GDPR). The registration is a technical intermediation: any resulting relationship remains between you and the organizer.
How long: registrations are kept for 24 months from the conclusion of the event, then automatically deleted. If you delete your account earlier, registrations for events that have not yet started are cancelled at the same time and the data identifying you (first and last name, email, phone number, note, reason for any cancellation) is removed immediately: all that remains with the organizer is a record stripped of identifying data, labelled «Utente eliminato» (deleted user) and no longer linked to you or to any account, with the number of people, the date, the time, the status and any recorded entry. It serves the organizer's attendance count and is deleted when the 24 months elapse. Any requests to be notified of a free spot are deleted immediately.
Tickets in Google Wallet
On Android phones, when the feature is available, if the ticket for a registration has a QR code you can add it to Google Wallet with the «Add to Google Wallet» button on the ticket screen. It is your choice: if you do not tap the button, we send nothing about your ticket to Google.
What we send to Google: when you tap the button we prepare the pass and send it to Google, which stores it on its servers. It is sent at that moment, even if you then do not complete saving it to your Wallet. The pass contains:
- Ticket holder's first and last name - as given in the registration
- Ticket code - the same QR code as the ticket in the app, which the organizer scans at the entrance
- Number of guests - only if you bring someone with you
- Ticket status - valid, entry recorded (with the time of entry), registration cancelled, event cancelled or concluded
- Event details - title, venue and address, date and time, the link to the event page on incomune.app and the InComune logo
- Technical identifiers - internal codes linking the pass to your registration and to the event, without your name
The QR code remains an opaque code, as in the ticket in the app. Like the ticket in the app, the pass also shows the holder's first and last name and the number of guests, if any; in addition, this information is also held by Google.
Updates: if the status of your registration changes (entry recorded, cancellation by you or by the organizer) or if the title, date, time or venue name of the event changes, we update the pass with Google. If the registration or the event is cancelled, we remove the QR code from the pass and mark it as no longer valid.
Google and your data: Google Wallet is a Google service. For the pass data Google acts as an independent controller, not on our behalf: it processes the data under its own terms and privacy policy, including to provide and improve its own services. For people living in the European Economic Area the controller is Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). If you save the pass to your Wallet, Google normally links it to your Google Account. Use of the Wallet is governed by the Google Terms of Service, the Google Wallet User Policy and the Google Privacy Policy.
Legal basis: performance of the service you requested by tapping the button (Art. 6.1.b GDPR), as for the registration.
How long: Google does not allow a pass to be deleted from its servers. For this reason, once 30 days have passed since the end of the event, we remove the first and last name, QR code, guests and time of entry from the pass and mark it as expired. If you delete your account earlier, we start the same operation immediately and mark the pass as no longer valid. In both cases the operation is automatic: if Google does not respond we repeat it until we have verified, by reading the pass back from Google, that the name and QR code have been removed. From then on, all that remains with Google is a pass with only the event details and the technical identifiers, with no name or code, which, if you had saved it, stays in your Wallet until you remove it yourself. In any case, within a day of the end of the event the pass already appears among the expired passes in the Wallet. If the event has no end time, the end of the event is taken to be 6 hours after it starts.
What we keep: to update the pass and to be able to remove your data from it, we keep a technical record for each pass on our servers, with the identifiers of the registration, of the event and of the pass at Google, a few dates and the status of the updates. It contains neither your name nor the ticket code. We delete it automatically once we have verified that your data has been removed from the pass at Google.
Tickets in Apple Wallet
On iPhone, when the feature is available, if the ticket for a registration has a QR code you can add it to Apple Wallet with the system «Add to Apple Wallet» button on the ticket screen. It is your choice: if you do not tap the button, we do not prepare any pass.
How the pass is created: when you tap the button our server prepares the pass, signs it and sends it to the app, which opens it in the Wallet system screen: there you choose whether to add it. We send nothing to Apple or anyone else to create the pass: the pass goes from our server to your phone. The technical record described below is created at that moment, even if you then do not complete adding it. The pass contains:
- Ticket holder's first and last name - as given in the registration
- Ticket code - the same QR code as the ticket in the app, which the organizer scans at the entrance
- Number of guests - only if you bring someone with you
- Ticket status - when relevant: entry recorded (with the time of entry), registration cancelled, event cancelled or concluded
- Event details - title, venue and address, date and time, the link to the event page on incomune.app and the InComune logo
- Technical identifiers - an internal code linking the pass to your registration, without your name, the address of our update service and a code the Wallet uses to identify itself to that service
The QR code remains an opaque code, as in the ticket in the app. The pass is stored in the Wallet on your device.
What we receive from the Wallet: when you add the pass, the Wallet on your device registers with our service to receive updates and sends us a device identifier and a push notification token, which we keep linked to the pass together with the registration date. We use them only to update the pass. Each device on which the pass is installed registers separately, up to a maximum of 10 devices per ticket. The Wallet may also send us technical error messages about the pass: we record them in the service's technical logs only in truncated form (at most 10 messages of 300 characters per submission) and after removing the ticket code and long technical codes.
Updates: if the status of your registration changes (entry recorded, cancellation by you or by the organizer) or if the title, date, time, venue name or address of the event changes, we send a notice to each registered device through the Apple Push Notification service (APNs). The notice is empty and contains no ticket data: it only prompts the device to download the new version of the pass from our service. It is an attempt: the pass is updated only when the device receives the notice and connects to our service, and until it does the previous version stays on the phone. If the registration or the event is cancelled, the new version no longer has the QR code and is marked as no longer valid. If Apple tells us that a device's token is no longer valid, we delete that registration.
Apple and your data: we do not send the ticket data to Apple. All that reaches Apple, through APNs, is the device's push token and the empty notice: for this APNs acts as our technical provider (see section 3). Apple Wallet is an Apple app on your device: if you use iCloud, Apple may also store the passes in your Wallet in iCloud, according to your Apple Account settings and to Apple's terms and privacy policy. We do not manage this and we receive nothing from iCloud.
Legal basis: performance of the service you requested by tapping the button (Art. 6.1.b GDPR), as for the registration.
How long: the pass on your device stays in the Wallet until you remove it yourself. At the end of the event the pass expires: the expiry date is written in the pass itself. Once 30 days have passed since the end of the event, or immediately if you delete your account earlier, we try to update the pass on each registered device to cancel it and remove the first and last name, QR code, guests and time of entry: from that moment our service provides only this version, and we repeat the notice once a day for 30 days, then we delete the device registrations, with their identifiers and tokens. Without account deletion, therefore, the registrations normally remain until about 60 days after the end of the event. If you delete your account while these 30 days are running, they start again from that moment. If a device does not connect during that period, the copy of the pass on that phone may remain the previous one, until you remove it yourself: once the registrations are deleted the pass is no longer updated. At any time, if the Wallet on a device tells us it no longer wants updates for the pass, we delete that registration immediately. If the event has no end time, the end of the event is taken to be 6 hours after it starts.
What we keep: to update the pass, we keep a technical record for each pass on our servers, with the identifiers of the registration and of the event, a few dates and the status of the updates, and the device registrations described above. The record contains neither your name nor the ticket code. We delete it automatically at the end of the 30 days of updates described above, or earlier if no device is registered. If you had also added the same ticket to Google Wallet, we delete it only once we have verified that your data has been removed from the pass at Google.
Listings pre-populated from public sources
Listings of businesses, associations, churches, professionals, and public places in Novoli were created from data already made public by the entities themselves: Google Maps / Google Business profiles, official Facebook pages, institutional websites, and public communications from the Municipality. Published data is limited to public contact information (name, address, phone, public email, website, social media) and does not include sensitive personal data.
For professional listings (natural persons or sole proprietorships) pre-populated from public sources, the legal basis is legitimate interest (Art. 6.1.f GDPR), on the same footing as other listings: published data is limited to contact details already made public by the professional. Consent (Art. 6.1.a GDPR) applies instead when the professional self-submits or claims their own listing. In both cases the listing always includes the button at the bottom dedicated to management and reports, to facilitate the exercise of GDPR rights.
Featured listings (sponsorship)
The platform operator may feature, for a defined period of time, the listing of a business, an event, or an association (for example by placing it higher in lists or marking it with a badge). This choice is editorial and at the platform operator's discretion. The data processed are the start and end dates of the feature period, associated with the entity's listing: this does not involve collecting any personal data beyond what is already published on the listing itself, and does not concern browsing data of the users who view it. The listing's administrators and co-administrators receive a notification when the feature period starts and when it ends.
Legal basis: legitimate interest of the controller in the editorial management of the platform (Art. 6.1.f GDPR).
How long: the start and end dates stay associated with the listing for as long as the listing itself exists in the app.
Information for data subjects of pre-populated listings (Art. 14)
When we publish a listing based on public sources, the data is not provided to us directly by the data subject. In these cases, pursuant to Art. 14 GDPR, we make available a dedicated notice explaining which data we process, the sources it comes from, the legal basis, how long we keep it, and how to object, rectify, or request removal. You can find it here: Information for listing data subjects (Art. 14).
Sign-in with external providers
- Users may also sign in with Google or Apple
- In this case, we receive from the provider the data needed to authenticate and create the account, such as email address and, if available, name
- For these accounts, login credentials may be managed by the external provider, and some changes (for example password or sign-in email) may not be available directly in the app
Data collected automatically
- Push notification token - technical device identifier for sending notifications (via Expo Push Service)
- Platform - iOS or Android, for correct notification delivery
- Usage data - pages visited, features used, session duration, via PostHog Analytics (EU servers). This data is associated with a persistent pseudonymous technical identifier on the device (never your name or email) and is collected only with your consent: on first launch the app asks for consent via a dedicated banner and, until you grant it, collects no statistics. You can grant or withdraw it at any time from Profile, «Privacy and data» section. This identifier is separate from your account identity: when you delete your account it is removed, so the statistics already collected can no longer be linked to you and remain only in anonymous form (and are deleted within 12 months in any case).
- Error and crash reports - JavaScript and native stack trace, app version, device model and OS, technical breadcrumbs (e.g. OTA updates downloaded), when the app crashes or generates an unhandled error. For the general user base these reports are de-identified (no link to your account); the pseudonymous user identifier (internal UUID, never email or name) and role are attached only for administrator accounts operating the service. Monitoring is performed via Sentry, on iOS and Android. We do not collect screen content or screenshots, and we do not collect the IP address. Purpose: technical diagnostics and service stability.
- Content images - photos and images uploaded by administrators for event posters, logos, cover photos, and posts (not personal photos of users).
Data we do NOT collect
- Geographic location (GPS)
- Personal photos or images of users (image uploads are reserved for administrators for public content)
- Address book contacts
- Payment data
- Biometric data
2. Why we collect data
| Purpose | Legal basis (GDPR) |
|---|---|
| Registration and authentication | Performance of contract (Art. 6.1.b) |
| Push notifications | User consent (Art. 6.1.a) |
| Saving favorites | Performance of contract (Art. 6.1.b) |
| Usage analytics (pseudonymous) | User consent (Art. 6.1.a) |
| Technical error monitoring (de-identified) | Legitimate interest (Art. 6.1.f) |
| Service communications | Legal obligation (Art. 6.1.c) |
| Management and moderation of user-submitted suggestions | Performance of contract (Art. 6.1.b) |
| Processing of third-party natural person data included in suggestions | Legitimate interest (Art. 6.1.f) |
| Publication of listings for businesses, associations, churches, and public places based on public sources | Legitimate interest (Art. 6.1.f) |
| Publication of professional listings (natural persons / sole proprietorships) pre-populated from public sources | Legitimate interest (Art. 6.1.f) |
| Professional listings self-submitted or claimed by the owner | Explicit consent or self-submission (Art. 6.1.a) |
| Handling of claims and edit/removal requests on listings | Performance of contract and data subject rights (Art. 6.1.b, Art. 16, 17, 21 GDPR) |
| Management of bookings and appointments with businesses | Performance of the service and pre-contractual measures at the data subject's request (Art. 6.1.b) |
| Booking blocks set by a business and technical anti-abuse log (kept for up to ~48 hours) | Legitimate interest (Art. 6.1.f) |
| Management of event registration and entry by the organizer | Performance of the service and pre-contractual measures at the data subject's request (Art. 6.1.b) |
| Creating and updating the ticket in Google Wallet, only at your request | Performance of the service requested by the data subject (Art. 6.1.b) |
| Creating and updating the ticket in Apple Wallet, only at your request | Performance of the service requested by the data subject (Art. 6.1.b) |
| Featuring (sponsoring) a listing, decided by the platform operator | Legitimate interest (Art. 6.1.f) |
Legitimate interest pursued (Art. 6.1.f): identifying and diagnosing technical issues with the app, ensuring service stability and security, providing Novoli citizens with an up-to-date reference on local entities based on already-public information, and preventing abuse and misuse of the booking system in order to protect the businesses that offer it. Usage analytics, by contrast, is processed only with your consent (Art. 6.1.a). Data published in listings is limited to information already made public by the entities themselves, the impact on data subjects' privacy is minimal, and the «Are you the owner?» button always provides a visible channel to exercise the right to object, rectify, or erase (Art. 21, 16, 17 GDPR).
3. Who we share data with
Personal data is not sold, transferred, or shared with third parties for commercial purposes.
Four disclosures to parties other than the technical providers listed below are provided for, and none has a commercial purpose: booking an appointment, registering for an event, adding a ticket to Google Wallet and notifying the other page administrators of an entity when an administrator is added, removed or leaves the role, the last two described further below. These are currently the only such disclosures. The booking data is disclosed to the business you selected, so that it can manage the appointment; the registration data is disclosed to the event organizer, i.e. the entity that publishes it, so that it can manage the registration and entry. In the first two cases the disclosure only occurs for the business you book with or the event you register for, and only for the data described in section 1. In managing the appointment or the registration, the business or the organizer acts independently for its own purposes: if you want it to delete the data it holds, you can contact it directly or write to info@incomune.app and we will pass the request on.
The following technical services process data on our behalf (data processors):
| Service | Purpose | Data location |
|---|---|---|
| Supabase (supabase.com) | Database, authentication, storage | Frankfurt, Germany (EU) |
| Expo (expo.dev) | Push notification delivery | United States* |
| Apple Push Notification Service (APNs) | Push notification delivery to iOS devices and update notices for tickets in Apple Wallet | United States* |
| Firebase Cloud Messaging (Google FCM) | Push notification delivery to Android devices | United States* |
| PostHog (posthog.com) | Analytics (pseudonymous data) | European Union |
| Sentry (sentry.io, Functional Software Inc.) | Error and crash monitoring on iOS and Android (pseudonymous data) | European Union |
| Resend (resend.com, Plus Five Five, Inc.) | Sending sign-in emails (address confirmation, password reset) | United States* (delivered via Amazon SES, Ireland) |
Expo Push Notifications, Apple (APNs), Google (FCM) and Resend process data on servers in the United States. This constitutes an extra-EU data transfer. For push notifications the transferred data is the device's push token and the content of the notification: the title and text may include another person's name (for example, for those who manage a business, the name of the person who booked or cancelled; for page administrators, the name of another administrator) or a short message written by a business or an organizer (for example the reason a booking or a registration was cancelled), as well as the text of posts and of notices from the InComune team. For sign-in emails the transferred data is the email address, with the confirmation or reset link. Transfers to Apple and Google rely on the «EU-US Data Privacy Framework» adequacy decision (Commission Implementing Decision (EU) 2023/1795), to which these companies adhere; transfers to Expo rely on the Standard Contractual Clauses (SCCs) adopted by the European Commission; transfers to Resend rely on the Data Privacy Framework, to which the company adheres, and on the Standard Contractual Clauses. Sentry processes crash data on servers in the European Union (EU data region), with no extra-EU transfer.
Google Wallet. If you add a ticket to Google Wallet, the pass data described in section 1 is disclosed to Google, which is not our processor but an independent controller: for people living in the European Economic Area, Google Ireland Limited (Ireland). Google processes it under its own terms and privacy policy, including to provide and improve its own services. This only happens if you tap the button yourself, and only for that ticket. Google states that data may be processed on servers located outside the country where you live, including the United States: for these transfers Google relies on the «EU-US Data Privacy Framework» adequacy decision (Commission Implementing Decision (EU) 2023/1795), to which Google LLC adheres, and, where it does not apply, on the Standard Contractual Clauses.
Apple Wallet. If you add a ticket to Apple Wallet, the pass data is not disclosed to third parties: the pass goes from our server to your device. All that reaches Apple, through APNs, is the device's push token and an empty notice asking the device to download the new version of the pass (see section 1).
Page administrators. If you are a page administrator of an entity, when you are added to the role, removed from it, or leave it, the other administrators of the same entity receive a notification showing your name, as it appears in your profile. Your name is not shown on the entity's public listing: only the InComune team can see the list of administrators.
4. Where we store data
Personal data (profile, email, favorites, notifications, bookings, event registrations) is stored on servers in the European Union (Supabase - Frankfurt, Germany). Usage analytics are processed on EU servers (PostHog EU).
Push notification tokens and the content of notifications (title and text, see section 3) are transferred to the United States via Expo Push Service (Standard Contractual Clauses), and subsequently forwarded to Apple (APNs) and Google (FCM), which adhere to the EU-US Data Privacy Framework, for delivery to the device.
Sign-in emails (address confirmation, password reset) are sent via Resend, which processes data in the United States (Data Privacy Framework and Standard Contractual Clauses) and delivers the messages via Amazon SES from servers in Ireland.
Error and crash reports (stack trace, device metadata, pseudonymous user identifier, technical breadcrumbs) are processed via Sentry, on iOS and Android, on servers in the European Union.
If you add a ticket to Google Wallet, the pass is stored on Google's servers, which may also be located outside the European Union (see section 3), for the periods described in section 1. The technical record we need to update it stays on our servers in the European Union.
If you add a ticket to Apple Wallet, the pass is stored on your device and, if you use iCloud, according to your Apple Account settings. The technical record and the device registrations stay on our servers in the European Union; for updates, the device's push token is transmitted to Apple (APNs), as described in section 3.
5. How long we keep data
| Data | Duration |
|---|---|
| User profile (name, email) | Deleted upon account deletion |
| Acceptance of the Terms and acknowledgement of the Privacy Policy (date, version, how it happened: sign-up or app) | Kept for the lifetime of the account and deleted when the account is deleted. Included in the data export. |
| Favorites | Deleted upon account deletion |
| Push notification token | Deleted upon account deletion or notification opt-out |
| Received notifications | Deleted upon account deletion or after 30 days automatically |
| Admin-uploaded images (posters, logos, covers) | Not linked to the personal profile; remain associated with the public entity and are not deleted upon account deletion |
| New entity suggestions | Retained until review (approval or rejection). Rejected suggestions are deleted within 90 days. Approved suggestions become part of the public content of the created record. |
| Claims and edit/removal requests | Retained until review (accepted or rejected). Rejected requests are deleted within 90 days. When a claim is accepted, the user is assigned as the listing owner. |
| Content reports (DSA notice-and-action) | Retained for up to 12 months after the report is closed, to document proper handling under the Digital Services Act (Reg. EU 2022/2065), then automatically deleted. |
| Listings subject to an accepted removal request | The listing is immediately hidden from all users. Physical deletion occurs automatically after 7 days; during this window the administrator can cancel the deletion if it was triggered by mistake. After 7 days, deletion is final. |
| Bookings (display name, optional phone number, note, service, date and time, status, internal note by the business) | 24 months from the closing of the booking (appointment completed, or booking rejected, cancelled, or expired), then automatically deleted. If you delete your account earlier, the name, phone number, note, internal note by the business, and cancellation reason are removed immediately: all that remains of the booking is a record with no identifying data, which stays available to the business for the continuity of its own schedule and its own records until the 24 months elapse. |
| Event registrations (first and last name, number of guests, date and time of registration, date and time of entry where applicable, status and reason for any cancellation, optional email/phone/note if required by the organizer) | 24 months from the conclusion of the event, then automatically deleted. If you delete your account earlier, registrations for events that have not yet started are cancelled and the data identifying you (first and last name, email, phone number, note, cancellation reason) is removed immediately: all that remains of the registration is a record stripped of identifying data, labelled «Utente eliminato» (deleted user), which stays available to the organizer for its attendance count until the 24 months elapse. |
| Request to be notified when a spot frees up (event, account, date of the request) | Kept until you turn the notice off, and automatically deleted once the event has started in any case. It is deleted immediately when you delete your account. |
| Ticket added to Google Wallet, held by Google (first and last name, QR code, guests, status and time of entry, event details) | Google does not allow it to be deleted. Once 30 days have passed since the end of the event we remove the first and last name, QR code, guests and time of entry from the pass and mark it as expired; if you delete your account earlier, we start the same operation immediately and mark it as no longer valid. If you had saved it, the pass stays in your Wallet, without this data, until you remove it yourself. |
| Technical record of the Google Wallet pass held by us (identifiers of the registration, the event and the pass, dates, update status; no name or ticket code) | Automatically deleted once we have verified that your data has been removed from the pass at Google, i.e. after the 30 days from the end of the event or after account deletion. The technical reference to the event, with no personal data, is deleted when no passes remain for that event. |
| Ticket added to Apple Wallet, on your device (first and last name, QR code, guests, status and time of entry, event details) | Stays in your Wallet until you remove it yourself, and expires at the end of the event. Once 30 days have passed since the end of the event, or immediately if you delete your account earlier, for 30 days we try to update it to cancel it and remove the first and last name, QR code, guests and time of entry; a device that does not connect during that period may keep the previous version. |
| Device registrations for Apple Wallet held by us (device identifier, push token, registration date) | Deleted at the end of the 30 days of updates, i.e. normally about 60 days after the end of the event, or 30 days after account deletion. Earlier, if the Wallet on the device tells us it no longer wants updates for the pass or if Apple tells us the token is no longer valid. |
| Technical record of the Apple Wallet pass held by us (identifiers of the registration and the event, dates, update status; no name or ticket code) | Automatically deleted at the end of the 30 days of updates, or earlier if no device is registered. If the same ticket is also in Google Wallet, only once we have verified that your data has been removed from the pass at Google. |
| Booking block status with a business | Kept until the business lifts it, since it is the very condition preventing new bookings with that business. It is always visible to the data subject in the business listing and is included in the data export. It is deleted in any case when you delete your account. |
| Technical block log (anti-abuse) | Automatically deleted within approximately 48 hours |
| Analytics data (PostHog, pseudonymous) | On account deletion the analytics identifier is removed and the data remains only in anonymous form (no longer linkable to you); deleted within 12 months in any case. To request earlier deletion write to info@incomune.app |
| Error and crash reports (Sentry, pseudonymous) | 90 days (Sentry default retention); to request deletion write to info@incomune.app |
| System backups | Temporary copies kept up to 30 days for technical reasons, then automatically overwritten; not accessible during this period |
6. Your rights
Under the GDPR (EU Regulation 2016/679), you have the right to:
- Access - know what data we hold about you
- Rectification - correct inaccurate data
- Erasure - delete your account with associated profile, favorites, and push tokens. The identifying data in your bookings (name, phone number, note, internal note by the business, and cancellation reason) is removed at the same time, and any upcoming appointments, whether pending or confirmed, are cancelled, with notice to the business concerned. Registrations for events that have not yet started are also cancelled and the data identifying you (first and last name, email, phone number, note, cancellation reason) is removed at the same time: all that remains of the registration is a record stripped of identifying data, labelled «Utente eliminato» (deleted user). If you had added a ticket to Google Wallet, we immediately start removing the first and last name, QR code, guests and time of entry from the pass and mark it as no longer valid: Google does not allow it to be deleted, so, if you had saved it, it stays in your Wallet, without this data, until you remove it yourself. If you had added a ticket to Apple Wallet, for 30 days we try to update it on your devices to cancel it and remove the same data: if a device does not connect during that period, the pass on that phone may remain the previous one, until you remove it yourself
- Portability - receive your data in a readable format by writing to info@incomune.app: the export also includes your bookings, your event registrations, and any block status with a business
- Objection - object to processing based on legitimate interest
- Withdraw consent - disable push notifications or usage analytics at any time (from Profile, «Privacy and data» section)
How to exercise your rights
- Account deletion: directly from the app (Profile -> Delete account)
- Notifications: can be disabled from the app settings
- Usage analytics: you can grant or withdraw consent at any time from Profile, «Privacy and data» section
- Rectification for social login accounts (Google/Apple): if you cannot directly update your email or credentials in the app, write to info@incomune.app
- Rights regarding an entity listing (business, association, church, professional): use the button at the bottom of each listing dedicated to management and reports to claim it, request edits, or request removal. Alternatively, write to info@incomune.app
- Bookings: you can find them in the app, where you can also cancel those still pending and, within the cancellation deadline set by the business, those already confirmed. They are included in your data export, which you can request by writing to info@incomune.app, together with any block status with a business
- Booking block with a business: if one applies to you, it is shown in that business listing. To request a review, contact the business or write to info@incomune.app
- Event registrations: you can find them in the app, where you can also cancel them until the event starts and turn off any request to be notified of a free spot. They are included in your data export, which you can request by writing to info@incomune.app
- Tickets in Google Wallet: you can remove the pass from your Wallet at any time, but it stays with Google until we remove your data from it: if you want us to do so before the 30 days, write to info@incomune.app. For the data Google processes under its own privacy policy you can also contact Google; for everything else write to info@incomune.app
- Tickets in Apple Wallet: the pass is on your device and you can remove it from your Wallet at any time. For the device registrations and the technical record we keep, write to info@incomune.app; for copies Apple keeps in iCloud you can contact Apple
- Other requests: write to info@incomune.app
We will respond within 30 days of your request.
You also have the right to file a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali - www.garanteprivacy.it).
7. Minimum age
InComune is intended for users aged 14 and over. We do not knowingly collect data from children under 14. If a parent or guardian believes a minor has registered without consent, they can contact us at info@incomune.app to request account deletion.
8. Security
- Authentication with encrypted passwords (hash)
- For social-login accounts, authentication may be delegated to the provider chosen by the user
- Row Level Security (RLS) on all database tables
- Encrypted communications (HTTPS/TLS)
- Data access restricted to the data controller
- Recording of the date and version of the Terms you accepted and of your acknowledgement of this Privacy Policy, with their history, so that we can demonstrate which texts were presented to you and when (Art. 5(2) GDPR)
9. Changes to this privacy policy
We reserve the right to update this policy. In case of substantial changes, we will notify you with a message in the app the first time you open it after the update. The date of the last update is indicated at the top of this document.
The incomune.app website
The incomune.app website is a static site hosted on GitHub Pages. It uses no profiling cookies and no analytics or advertising tools. Fonts are served directly from our site (self-hosted) rather than from third-party CDNs: as a result, simply browsing the pages, including the legal ones, does not transmit your IP address to Google or other external providers to load fonts.
10. Contact
Lorenzo La Grua
Email: info@incomune.app