Skip to main content
SUMMER BREAK · Orders placed between 7 and 23 August 2026 will be received as usual and processed starting from Monday, 24 August 2026.
Palace Merano

Cookie Policy

Last update: August 6, 2026

Cookies and Other Tracking Tools

This section describes the types of cookies and other tracking tools (pixel cookies, web beacons, device identifiers, localStorage) used on the Site, implementing the Guidelines of the Italian Data Protection Authority of 10 June 2021 and art. 122 of Legislative Decree 196/2003 as amended.

The cookies and other tracking tools used by the Site fall, according to the purpose pursued, into the following categories; which of them are actually present depends on the platform the Site is built with and on the features enabled:

  • Technical cookies (necessary): indispensable for the operation of the Site or for the services requested by the user (session, authentication, security, storage of the cookie choice). They are installed by the Controller, either directly or through providers acting as processors, and do not require prior consent under art. 122(1) of the Italian Privacy Code.
  • Functionality and experience cookies: they store user choices (language, light/dark theme, interface preferences, embedded media content) in order to offer additional features. They qualify as technical cookies where they give effect to a choice expressed by the user in order to provide the requested service; they require prior consent where they are not strictly necessary for that service.
  • Analytics/statistical cookies: they collect information on the use of the Site. They require prior consent, unless the tool is configured so as to be assimilable to technical cookies under the Garante Guidelines of 10 June 2021 (truncated IP address, no cross-linking with other processing, no sharing with third parties, use limited to this Site alone).
  • Profiling/marketing cookies: they create profiles on the user to show personalised advertising and targeted content. They require explicit and granular prior consent.

Consent banner: on first access to the Site a banner is displayed allowing the user to accept, refuse or customise the use of non strictly necessary cookies (functionality, analytics and marketing), with three equally prominent actions (Garante 2021 + EDPB Guidelines 03/2022). The choice made is stored on the user's device for the period indicated in the technical cookies table; in line with the Italian Data Protection Authority's Guidelines of 10 June 2021, the banner is not shown again before six months have elapsed since it was last displayed, unless the user clears their browsing data or changes their preferences.

The user can change or withdraw consent at any time, through the cookie preferences control available on the Site or from the browser settings. For details of each identifier used, including how long the expressed preference is stored, please refer to the tables in the sections below.

First-party Technical Cookies and Identifiers

The Site uses cookies and identifiers strictly necessary for its operation. These technical identifiers are installed by the Controller, either directly or through providers acting as processors, and do not require the data subject's consent, in accordance with Art. 122(1) of Italian Legislative Decree 196/2003 and the Italian DPA Guidelines of 10 June 2021.

The table below describes the technical identifiers by the function they perform: the actual names depend on the platform the Site is built with and on the services enabled, and those shown in brackets are only common examples.

Server-side consent record: where the Site keeps proof of the choice expressed in the banner, the record (accepted or rejected categories, technical visitor identifier, date and time, source) is transmitted to the Controller and stored in its compliance infrastructure for as long as necessary to discharge the burden of proof of consent (Art. 7.1 GDPR), within the periods set out in the section on retention periods. The record contains no directly identifying data, only the technical browser identifier: it is therefore pseudonymous, not anonymous, data.

Note: the list above sets out the technical identifiers typically present; the actual set depends on the platform and on the configuration of the Site at the time of the visit. The presence of additional identifiers not listed here can be checked by the user at any time through the browser developer tools.

To disable technical identifiers, the user must act directly on the browser settings. Disabling them may impair the operation of the Site.

Consent management and withdrawal

On first access to the Site, a banner is shown that allows you to accept, refuse or customise the use of non strictly necessary cookies (functionality, analytics and marketing). Strictly technical cookies are installed regardless of consent, in compliance with art. 122(1) of Italian Legislative Decree 196/2003 and the Italian Data Protection Authority guidelines of 10 June 2021.

The data subject may modify or withdraw consent at any time:

  • by using the cookie preferences control available on the Site;
  • by deleting cookies already installed from the browser settings (the procedure varies depending on the browser).

Consent may be withdrawn at any time and as easily as it was given, and withdrawal does not affect the lawfulness of processing carried out before the withdrawal (art. 7.3 GDPR).

Proof of consent (art. 7.1 GDPR): depending on the platform the Site is built with, the choice expressed in the banner may be stored solely on the user's device or also kept server-side for evidentiary purposes. In the latter case the data stored is: random browser identifier (UUID), chosen cookie categories, date and time, cryptographic hash of the user-agent, country of origin (no full IP address). No directly identifying data is stored or shared with third parties (name, email address, IP address): the record relates to the browser only and constitutes pseudonymous, not anonymous, data. It is kept for as long as necessary to discharge the burden of proof, within the periods set out in the section on retention periods, after which it is deleted.

Local Storage (localStorage and sessionStorage)

The Site uses browser-side storage technologies (localStorage and sessionStorage) to provide the requested functionalities and improve the user experience. These technologies are equated with cookies under Art. 122(1) of Italian Legislative Decree 196/2003: where they are not strictly necessary for the service requested by the user, their use requires consent under Art. 6.1.a GDPR and the aforementioned Art. 122.

The keys actually present depend on the platform the Site is built with and on the features enabled; locally stored data typically includes:

  • User selected language;
  • Layout and interface arrangement preferences;
  • User cookie consent state (where the Site keeps proof of consent, a copy is retained server-side — see the technical cookies section);
  • Application session data (partially filled forms, operations in progress);
  • Authentication tokens (for registered users).

Most of this data stays on the user device and is not transmitted to the Controller. The only exceptions — expressly declared — are the consent record (where replicated server-side for the burden of proof under Art. 7.1 GDPR) and, where enabled, compliance telemetry (see dedicated clause).

Local data remains stored until it is manually deleted from the browser settings, through the browsing data deletion feature, or, where the Site provides for it, through the dedicated local data deletion control.

Google Tag Manager (GTM)

Provider: Google Ireland Ltd (Ireland) — parent company Google LLC (USA).
Purpose: orchestration and conditional loading of analytics, marketing and functional tags (e.g. GA4, Meta Pixel) on the Site.
Data processed: loading of the GTM container transmits to Google servers the user's IP address, user-agent and page URL, even before activation of specific tags.
Retention: Google Cloud logs as per provider policies (typically 14-30 days for network logs).
Transfer: United States (Google LLC). Where the provider adheres to the EU-US Data Privacy Framework, the transfer is based on the relevant adequacy decision of the European Commission (Article 45 GDPR); otherwise, or should that decision cease to apply, the Standard Contractual Clauses under Article 46 GDPR with supplementary measures apply.
Legal basis: prior consent of the data subject under art. 6(1)(a) GDPR and art. 122(1) of Italian Legislative Decree 196/2003, collected via the cookie banner before loading the container. The qualification as "technical processing exempt from consent" has been superseded by the Italian DPA's cookie Guidelines of 10 June 2021 (decision no. 231), which require prior consent for any identifier not strictly necessary for Site operation.
Provider privacy policy: business.safety.google/privacy

Google Analytics 4 (Google Ireland Limited)

We use Google Analytics 4 to analyse the use of the Site in aggregated form, identify areas for improvement and optimise user experience.

  • Purpose: statistical analysis of traffic and user behaviour
  • Data collected: device identifiers, IP address (masked by Google, not stored in clear text for GA4 properties), pages visited, dwell time, interactions, custom events
  • Legal basis: prior consent under art. 6(1)(a) GDPR and art. 122(1) of Italian Legislative Decree 196/2003: the service is activated only after consent, because not all the minimisation conditions required by the Italian DPA's cookie Guidelines of 10 June 2021 (decision no. 231) in order to treat analytics cookies as technical cookies are met
  • Retention: 14 months (GA4 property setting)
  • Configuration: single domain, no cross-site tracking; the "Google Signals" and "Data Sharing > Modeling" options are disabled, to avoid mixing with advertising profiling purposes that would require separate consent
  • Transfer: United States (Google LLC). Where the provider adheres to the EU-US Data Privacy Framework, the transfer is based on the relevant adequacy decision of the European Commission (Article 45 GDPR); otherwise, or should that decision cease to apply, the Standard Contractual Clauses under Article 46 GDPR with supplementary measures apply.
  • Provider privacy policy: policies.google.com/privacy

Brevo SAS (formerly Sendinblue)

We use Brevo as a provider for transactional emails (confirmations, service notifications) and, subject to consent, for email marketing and newsletters. Brevo acts as Data Processor under art. 28 GDPR.

  • Purpose: sending transactional emails and, with consent, promotional communications and newsletters
  • Data collected: email address, name, opening and click events of the messages sent
  • Tracking pixels in emails: messages may contain tracking pixels, i.e. invisible images that detect the opening of the message and clicks on links, in order to measure the effectiveness of the communications and interest in the content offered. Storing and reading them on the recipient's device requires consent under art. 122(1) of the Italian Privacy Code (Legislative Decree 196/2003)
  • Legal basis: performance of the contract for sending transactional emails (art. 6.1.b GDPR); consent for promotional communications (art. 6.1.a GDPR); consent for the tracking of openings and clicks (art. 6.1.a GDPR and art. 122(1) of the Italian Privacy Code)
  • Withdrawal of consent: Consent may be withdrawn at any time and as easily as it was given, and withdrawal does not affect the lawfulness of processing carried out before it (art. 7.3 GDPR). Withdrawal may also cover tracking alone, while still receiving the messages: simply write to the Data Controller at the contact details given in this notice; to stop all mailings, the unsubscribe link is available at the bottom of every email
  • Retention: for the duration of the relationship and until unsubscription; the record evidencing the consent given (art. 7.1 GDPR) is kept in minimised form for the period indicated in the section of this notice devoted to retention periods
  • Transfer: The provider states that it processes data on infrastructure located in the European Union; any transfers to third countries are covered by the safeguards under Chapter V GDPR.
  • Provider privacy policy: brevo.com/legal/privacypolicy

Stripe

Provider: Stripe Payments Europe Ltd (Ireland) — Stripe Inc. group (USA).
Purpose: online payment processing, card data tokenisation, fraud prevention (Stripe Radar).
Data collected: cookie identifiers (__stripe_mid, __stripe_sid), card token, amount, currency, IP address, technical browser characteristics used for anti-fraud purposes.
Retention: __stripe_mid 1 year, __stripe_sid 30 minutes.
Cookies: the cookies used to securely provide the payment service requested by the user are strictly necessary and do not require prior consent under art. 122(1) of the Italian Privacy Code (Legislative Decree 196/2003); any further cookies or identifiers used for fraud analysis that is not strictly necessary to the requested service are installed only with the user's consent.
Legal basis: performance of the contract or of pre-contractual measures for payment processing (art. 6.1.b GDPR); for anti-fraud cookies and identifiers that are not strictly necessary, the user's consent (art. 6.1.a GDPR and art. 122(1) of the Italian Privacy Code).
Transfer: processing in Ireland (EU); for anti-fraud functions data may be transferred to the United States. Where the provider adheres to the EU-US Data Privacy Framework, the transfer is based on the relevant adequacy decision of the European Commission (Article 45 GDPR); otherwise, or should that decision cease to apply, the Standard Contractual Clauses under Article 46 GDPR with supplementary measures apply.
Privacy policy: stripe.com/privacy

PayPal

Provider: PayPal (Europe) S.à r.l. et Cie, S.C.A. (Luxembourg) — PayPal Holdings Inc. group (USA).
Purpose: online payment processing via PayPal account or credit card, fraud prevention.
Data collected: cookie identifiers (x-pp-s, l7_az, ts, tsrce), transaction data (amount, currency, order ID), IP address, payer's PayPal account data, technical device characteristics used for anti-fraud purposes.
Retention: transaction data is retained by the provider, under its own responsibility as an independent controller, for the period required by the anti-money-laundering and payment-record retention obligations to which it is subject as a payment institution (normally 10 years).
Cookies: the cookies used to securely provide the payment service requested by the user are strictly necessary and do not require prior consent under art. 122(1) of the Italian Privacy Code (Legislative Decree 196/2003); any further cookies or identifiers used for fraud analysis that is not strictly necessary to the requested service are installed only with the user's consent.
Legal basis: performance of the contract or of pre-contractual measures for payment processing (art. 6.1.b GDPR); for anti-fraud cookies and identifiers that are not strictly necessary, the user's consent (art. 6.1.a GDPR and art. 122(1) of the Italian Privacy Code).
Transfer: processing in Luxembourg (EU); for anti-fraud functions data may be transferred to the United States. Where the provider adheres to the EU-US Data Privacy Framework, the transfer is based on the relevant adequacy decision of the European Commission (Article 45 GDPR); otherwise, or should that decision cease to apply, the Standard Contractual Clauses under Article 46 GDPR with supplementary measures apply.
Privacy policy: paypal.com/en/legalhub/privacy-full

Sentry (Functional Software, Inc. — EU data region)

This Site uses Sentry, a technical application error-monitoring tool, to detect and fix malfunctions and ensure the stability and security of the service.

  • Purpose: technical error monitoring, diagnostics and Site security/stability (essential tool, no profiling).
  • Data collected: technical error data (browser and operating system type, the affected page, the technical exception trace). No personal data is collected by default; any email addresses contained in messages are redacted and session recording (Session Replay) is not enabled.
  • Legal basis: the Controller's legitimate interest in the security and proper functioning of the Site (Art. 6(1)(f) GDPR; see Recital 49). No cookies are used and no consent is required.
  • Retention: error events are stored for a limited period according to Sentry's settings (typically 90 days), after which they are deleted.
  • Transfer: data is hosted on infrastructure located in the European Union (Frankfurt, Germany). Any access by the provider, based in the United States, entails a transfer to a third country. Where the provider adheres to the EU-US Data Privacy Framework, the transfer is based on the relevant adequacy decision of the European Commission (Article 45 GDPR); otherwise, or should that decision cease to apply, the Standard Contractual Clauses under Article 46 GDPR with supplementary measures apply.
  • Provider's privacy policy: sentry.io

How to manage preferences

You can manage your cookie preferences in two ways:

  1. From the Site: use the cookie preferences control available on the Site to reopen the choice panel.
  2. From your browser settings (the paths indicated may vary depending on the version installed):
    • Google Chrome: Settings → Privacy and security → Cookies and other site data
    • Mozilla Firefox: Settings → Privacy & Security → Cookies and Site Data
    • Safari: Settings (or Preferences) → Privacy → Cookies and website data
    • Microsoft Edge: Settings → Privacy, search and services → Cookies

For newsletters and promotional emails: use the unsubscribe link at the bottom of every message, or write to the Controller at the contact details given in this notice.

Note: disabling first-party technical cookies may prevent the Site from functioning correctly (e.g. language persistence, cart session).

Additional opt-out tools for advertising networks:

Contacts for cookie questions

For any question about cookie usage on this site:

  • Email: info@palace.it
  • Address: Via Cavour 2/4, 39012 Merano (BZ), Italia

For more details on data processing collected via cookies, see the Privacy Policy of the site.