Skip to main content
SUMMER BREAK · Orders placed between 7 and 23 August 2026 will be received as usual and processed starting from Monday, 24 August 2026.
Palace Merano

Cookie Policy

Last update: August 11, 2026

Cookies and Other Tracking Tools

This section describes the types of cookies and other tracking tools (pixel cookies, web beacons, device identifiers, localStorage) used on the Site, implementing the Guidelines of the Italian Data Protection Authority of 10 June 2021 and art. 122 of Legislative Decree 196/2003 as amended.

The cookies and other tracking tools used by the Site fall, according to the purpose pursued, into the following categories; which of them are actually present depends on the platform the Site is built with and on the features enabled:

  • Technical cookies (necessary): indispensable for the operation of the Site or for the services requested by the user (session, authentication, security, storage of the cookie choice). They are installed by the Controller, either directly or through providers acting as processors, and do not require prior consent under art. 122(1) of the Italian Privacy Code.
  • Functionality and experience cookies: they store user choices (language, light/dark theme, interface preferences, embedded media content) in order to offer additional features. They qualify as technical cookies where they give effect to a choice expressed by the user in order to provide the requested service; they require prior consent where they are not strictly necessary for that service.
  • Analytics/statistical cookies: they collect information on the use of the Site. They require prior consent, unless the tool is configured so as to be assimilable to technical cookies under the Garante Guidelines of 10 June 2021 (truncated IP address, no cross-linking with other processing, no sharing with third parties, use limited to this Site alone).
  • Profiling/marketing cookies: they create profiles on the user to show personalised advertising and targeted content. They require explicit and granular prior consent.

Consent banner: on first access to the Site a banner is displayed allowing the user to accept, refuse or customise the use of non strictly necessary cookies (functionality, analytics and marketing), with three equally prominent actions (Garante 2021 + EDPB Guidelines 03/2022). The choice made is stored on the user's device for the period indicated in the technical cookies table; in line with the Italian Data Protection Authority's Guidelines of 10 June 2021, the banner is not shown again before six months have elapsed since it was last displayed, unless the user clears their browsing data or changes their preferences.

The user can change or withdraw consent at any time, through the cookie preferences control available on the Site or from the browser settings. For details of each identifier used, including how long the expressed preference is stored, please refer to the tables in the sections below.

First-party Technical Cookies and Identifiers

The Site uses cookies and identifiers strictly necessary for its operation. These technical identifiers are installed by the Controller, either directly or through providers acting as processors, and do not require the data subject's consent, in accordance with Art. 122(1) of Italian Legislative Decree 196/2003 and the Italian DPA Guidelines of 10 June 2021.

The table below describes the technical identifiers by the function they perform: the actual names depend on the platform the Site is built with and on the services enabled, and those shown in brackets are only common examples.

Server-side consent record: where the Site keeps proof of the choice expressed in the banner, the record (accepted or rejected categories, technical visitor identifier, date and time, source) is transmitted to the Controller and stored in its compliance infrastructure for as long as necessary to discharge the burden of proof of consent (Art. 7.1 GDPR), within the periods set out in the section on retention periods. The record contains no directly identifying data, only the technical browser identifier: it is therefore pseudonymous, not anonymous, data.

Note: the list above sets out the technical identifiers typically present; the actual set depends on the platform and on the configuration of the Site at the time of the visit. The presence of additional identifiers not listed here can be checked by the user at any time through the browser developer tools.

To disable technical identifiers, the user must act directly on the browser settings. Disabling them may impair the operation of the Site.

Consent management and withdrawal

On first access to the Site, a banner is shown that allows you to accept, refuse or customise the use of non strictly necessary cookies (functionality, analytics and marketing). Strictly technical cookies are installed regardless of consent, in compliance with art. 122(1) of Italian Legislative Decree 196/2003 and the Italian Data Protection Authority guidelines of 10 June 2021.

The data subject may modify or withdraw consent at any time:

  • by using the cookie preferences control available on the Site;
  • by deleting cookies already installed from the browser settings (the procedure varies depending on the browser).

Consent may be withdrawn at any time and as easily as it was given, and withdrawal does not affect the lawfulness of processing carried out before the withdrawal (art. 7.3 GDPR).

Proof of consent (art. 7.1 GDPR): depending on the platform the Site is built with, the choice expressed in the banner may be stored solely on the user's device or also kept server-side for evidentiary purposes. In the latter case the data stored is: random browser identifier (UUID), chosen cookie categories, date and time, cryptographic hash of the user-agent, country of origin (no full IP address). No directly identifying data is stored or shared with third parties (name, email address, IP address): the record relates to the browser only and constitutes pseudonymous, not anonymous, data. It is kept for as long as necessary to discharge the burden of proof, within the periods set out in the section on retention periods, after which it is deleted.

Local Storage (localStorage and sessionStorage)

The Site uses browser-side storage technologies (localStorage and sessionStorage) to provide the requested functionalities and improve the user experience. These technologies are equated with cookies under Art. 122(1) of Italian Legislative Decree 196/2003: where they are not strictly necessary for the service requested by the user, their use requires consent under Art. 6.1.a GDPR and the aforementioned Art. 122.

The keys actually present depend on the platform the Site is built with and on the features enabled; locally stored data typically includes:

  • User selected language;
  • Layout and interface arrangement preferences;
  • User cookie consent state (where the Site keeps proof of consent, a copy is retained server-side — see the technical cookies section);
  • Application session data (partially filled forms, operations in progress);
  • Authentication tokens (for registered users).

Most of this data stays on the user device and is not transmitted to the Controller. The only exceptions — expressly declared — are the consent record (where replicated server-side for the burden of proof under Art. 7.1 GDPR) and, where enabled, compliance telemetry (see dedicated clause).

Local data remains stored until it is manually deleted from the browser settings, through the browsing data deletion feature, or, where the Site provides for it, through the dedicated local data deletion control.

Google Tag Manager (GTM)

Provider: Google Ireland Ltd (Ireland) — parent company Google LLC (USA).
Purpose: orchestration and conditional loading of analytics, marketing and functional tags (e.g. GA4, Meta Pixel) on the Site.
Data processed: loading of the GTM container transmits to Google servers the user's IP address, user-agent and page URL, even before activation of specific tags.
Retention: Google Cloud logs as per provider policies (typically 14-30 days for network logs).
Transfer: United States (Google LLC). Where the provider adheres to the EU-US Data Privacy Framework, the transfer is based on the relevant adequacy decision of the European Commission (Article 45 GDPR); otherwise, or should that decision cease to apply, the Standard Contractual Clauses under Article 46 GDPR with supplementary measures apply.
Legal basis: prior consent of the data subject under art. 6(1)(a) GDPR and art. 122(1) of Italian Legislative Decree 196/2003, collected via the cookie banner before loading the container. The qualification as "technical processing exempt from consent" has been superseded by the Italian DPA's cookie Guidelines of 10 June 2021 (decision no. 231), which require prior consent for any identifier not strictly necessary for Site operation.
Provider privacy policy: business.safety.google/privacy

Google Analytics 4 (Google Ireland Limited)

We use Google Analytics 4 to analyse the use of the Site in aggregated form, identify areas for improvement and optimise user experience.

  • Purpose: statistical analysis of traffic and user behaviour
  • Data collected: device identifiers, IP address (masked by Google, not stored in clear text for GA4 properties), pages visited, dwell time, interactions, custom events
  • Legal basis: prior consent under art. 6(1)(a) GDPR and art. 122(1) of Italian Legislative Decree 196/2003: the service is activated only after consent, because not all the minimisation conditions required by the Italian DPA's cookie Guidelines of 10 June 2021 (decision no. 231) in order to treat analytics cookies as technical cookies are met
  • Retention: 14 months (GA4 property setting)
  • Configuration: single domain, no cross-site tracking; the "Google Signals" and "Data Sharing > Modeling" options are disabled, to avoid mixing with advertising profiling purposes that would require separate consent
  • Transfer: United States (Google LLC). Where the provider adheres to the EU-US Data Privacy Framework, the transfer is based on the relevant adequacy decision of the European Commission (Article 45 GDPR); otherwise, or should that decision cease to apply, the Standard Contractual Clauses under Article 46 GDPR with supplementary measures apply.
  • Provider privacy policy: policies.google.com/privacy

Brevo SAS (formerly Sendinblue)

We use Brevo as a provider for transactional emails (confirmations, service notifications) and, subject to consent, for email marketing and newsletters. Brevo acts as Data Processor under art. 28 GDPR.

  • Purpose: sending transactional emails and, with consent, promotional communications and newsletters
  • Data collected: email address, name, opening and click events of the messages sent
  • Tracking pixels in emails: messages may contain tracking pixels, i.e. invisible images that detect the opening of the message and clicks on links, in order to measure the effectiveness of the communications and interest in the content offered. Storing and reading them on the recipient's device requires consent under art. 122(1) of the Italian Privacy Code (Legislative Decree 196/2003)
  • Legal basis: performance of the contract for sending transactional emails (art. 6.1.b GDPR); consent for promotional communications (art. 6.1.a GDPR); consent for the tracking of openings and clicks (art. 6.1.a GDPR and art. 122(1) of the Italian Privacy Code)
  • Withdrawal of consent: Consent may be withdrawn at any time and as easily as it was given, and withdrawal does not affect the lawfulness of processing carried out before it (art. 7.3 GDPR). Withdrawal may also cover tracking alone, while still receiving the messages: simply write to the Data Controller at the contact details given in this notice; to stop all mailings, the unsubscribe link is available at the bottom of every email
  • Retention: for the duration of the relationship and until unsubscription; the record evidencing the consent given (art. 7.1 GDPR) is kept in minimised form for the period indicated in the section of this notice devoted to retention periods
  • Transfer: The provider states that it processes data on infrastructure located in the European Union; any transfers to third countries are covered by the safeguards under Chapter V GDPR.
  • Provider privacy policy: brevo.com/legal/privacypolicy

Stripe

Provider: Stripe Payments Europe Ltd (Ireland) — Stripe Inc. group (USA).
Purpose: online payment processing, card data tokenisation, fraud prevention (Stripe Radar).
Data collected: cookie identifiers (__stripe_mid, __stripe_sid), card token, amount, currency, IP address, technical browser characteristics used for anti-fraud purposes.
Retention: __stripe_mid 1 year, __stripe_sid 30 minutes.
Cookies: the cookies used to securely provide the payment service requested by the user are strictly necessary and do not require prior consent under art. 122(1) of the Italian Privacy Code (Legislative Decree 196/2003); any further cookies or identifiers used for fraud analysis that is not strictly necessary to the requested service are installed only with the user's consent.
Legal basis: performance of the contract or of pre-contractual measures for payment processing (art. 6.1.b GDPR); for anti-fraud cookies and identifiers that are not strictly necessary, the user's consent (art. 6.1.a GDPR and art. 122(1) of the Italian Privacy Code).
Transfer: processing in Ireland (EU); for anti-fraud functions data may be transferred to the United States. Where the provider adheres to the EU-US Data Privacy Framework, the transfer is based on the relevant adequacy decision of the European Commission (Article 45 GDPR); otherwise, or should that decision cease to apply, the Standard Contractual Clauses under Article 46 GDPR with supplementary measures apply.
Privacy policy: stripe.com/privacy

PayPal

Provider: PayPal (Europe) S.à r.l. et Cie, S.C.A. (Luxembourg) — PayPal Holdings Inc. group (USA).
Purpose: online payment processing via PayPal account or credit card, fraud prevention.
Data collected: cookie identifiers (x-pp-s, l7_az, ts, tsrce), transaction data (amount, currency, order ID), IP address, payer's PayPal account data, technical device characteristics used for anti-fraud purposes.
Retention: transaction data is retained by the provider, under its own responsibility as an independent controller, for the period required by the anti-money-laundering and payment-record retention obligations to which it is subject as a payment institution (normally 10 years).
Cookies: the cookies used to securely provide the payment service requested by the user are strictly necessary and do not require prior consent under art. 122(1) of the Italian Privacy Code (Legislative Decree 196/2003); any further cookies or identifiers used for fraud analysis that is not strictly necessary to the requested service are installed only with the user's consent.
Legal basis: performance of the contract or of pre-contractual measures for payment processing (art. 6.1.b GDPR); for anti-fraud cookies and identifiers that are not strictly necessary, the user's consent (art. 6.1.a GDPR and art. 122(1) of the Italian Privacy Code).
Transfer: processing in Luxembourg (EU); for anti-fraud functions data may be transferred to the United States. Where the provider adheres to the EU-US Data Privacy Framework, the transfer is based on the relevant adequacy decision of the European Commission (Article 45 GDPR); otherwise, or should that decision cease to apply, the Standard Contractual Clauses under Article 46 GDPR with supplementary measures apply.
Privacy policy: paypal.com/en/legalhub/privacy-full

Google Ads (conversion + remarketing)

Provider: Google Ireland Limited (Ireland) — parent: Google LLC (USA).
Purpose: measurement of Google Ads campaign conversions, click-id (gclid) persistence for attribution, remarketing on the Google network and partners.
Data collected: cookie identifiers (_gcl_au, _gcl_aw, _gcl_dc, _gac_*), Google Ads click-id, conversion pages, conversion value (if transmitted), IP address.
Retention: 90 days (_gcl_au cookie), 30-90 days for conversion identifiers.
Transfer: United States (Google LLC). Where the provider adheres to the EU-US Data Privacy Framework, the transfer is based on the relevant adequacy decision of the European Commission (Article 45 GDPR); otherwise, or should that decision cease to apply, the Standard Contractual Clauses under Article 46 GDPR with supplementary measures apply.
Legal basis: prior consent under art. 6(1)(a) GDPR and art. 122(1) of Italian Legislative Decree 196/2003; without consent the tags are not loaded.
Provider privacy policy: policies.google.com/privacy

Matomo (self-hosted analytics)

Provider: Matomo instance (open-source software) installed on infrastructure of the Controller or of a technical supplier appointed by the Controller as processor pursuant to art. 28 GDPR.
Purpose: statistical analysis of Site usage and measurement of the effectiveness of advertising campaigns.
Data collected: cookie identifiers (_pk_id, _pk_ses, _pk_ref), pages visited, referrer source, interactions, device and browser type, IP address.
Retention: _pk_id ~13 months, _pk_ref 6 months, _pk_ses 30 minutes; statistical data is retained according to the configuration of the instance.
Transfer: the place of processing depends on the installation: where the instance is hosted on infrastructure located in the European Union, processing takes place within the Union; any transfers to third countries are subject to the safeguards under Chapter V of the GDPR.
Legal basis: consent under art. 6(1)(a) GDPR and art. 122(1) of Italian Legislative Decree 196/2003. The guidelines on cookies and other tracking tools issued by the Italian data protection authority on 10 June 2021 (decision no. 231) allow analytics to be exempted from consent only where the tool is configured so that the statistics are aggregate and relate to the Site alone, the data is neither combined with other processing nor transmitted to third parties and, where the tool is operated by a third party, at least the fourth component of the IP address is masked; failing those conditions, consent is always required. Consent may be withdrawn at any time and as easily as it was given, and withdrawal does not affect the lawfulness of processing carried out before it (art. 7(3) GDPR).
Software: Matomo open-source (matomo.org/privacy-policy). To exercise your rights, contact the Controller.

Meta Pixel (Facebook / Instagram)

Provider: Meta Platforms Ireland Limited (Ireland) — parent Meta Platforms Inc. (USA).
Purpose: remarketing, conversion measurement, Facebook/Instagram Ads campaign optimisation.
Data collected: cookie identifiers (_fbp, _fbc), pages visited, conversion events, IP address.
Retention: 90 days (cookie _fbp); data processed by Meta is retained according to the provider's policies.
Roles: for the collection and transmission of data through the pixel, the Controller and Meta act as joint controllers pursuant to art. 26 GDPR (see CJEU, case C-40/17, Fashion ID); Meta's subsequent processing for its own purposes remains its exclusive responsibility. The essence of the joint controllership arrangement is made available to the data subject by the provider.
Transfer: data may be transferred to the United States. Where the provider adheres to the EU-US Data Privacy Framework, the transfer is based on the relevant adequacy decision of the European Commission (Article 45 GDPR); otherwise, or should that decision cease to apply, the Standard Contractual Clauses under Article 46 GDPR with supplementary measures apply.
Legal basis: prior consent pursuant to art. 6(1)(a) GDPR and art. 122(1) of Italian Legislative Decree 196/2003, collected through the cookie banner before the pixel is activated. Consent may be withdrawn at any time and as easily as it was given, and withdrawal does not affect the lawfulness of processing carried out before it (art. 7(3) GDPR).
Provider privacy policy: facebook.com/privacy/policy

Microsoft Clarity

Provider: Microsoft Ireland Operations Limited (Ireland) — parent: Microsoft Corporation (USA).
Purpose: behavioural analytics (heatmaps, session recordings), Site UX improvement.
Data collected: cookie identifiers (_clck, _clsk, MUID), pages visited, click/scroll events, viewport size, country, IP address (anonymised by the provider).
Retention: 1 year (_clck, MUID cookies); data processed by the provider is retained according to its own policies.
Transfer: data may be transferred to the United States. Where the provider adheres to the EU-US Data Privacy Framework, the transfer is based on the relevant adequacy decision of the European Commission (Article 45 GDPR); otherwise, or should that decision cease to apply, the Standard Contractual Clauses under Article 46 GDPR with supplementary measures apply.
Legal basis: prior consent under art. 6(1)(a) GDPR and art. 122(1) of Italian Legislative Decree 196/2003, collected through the cookie banner before the tool is activated. Consent may be withdrawn at any time and as easily as it was given, and withdrawal does not affect the lawfulness of processing carried out before it (art. 7(3) GDPR).
Provider privacy policy: privacy.microsoft.com/privacystatement

Sentry (Functional Software, Inc. — EU data region)

This Site uses Sentry, a technical application error-monitoring tool, to detect and fix malfunctions and ensure the stability and security of the service.

  • Purpose: technical error monitoring, diagnostics and Site security/stability (essential tool, no profiling).
  • Data collected: technical error data (browser and operating system type, the affected page, the technical exception trace). No personal data is collected by default; any email addresses contained in messages are redacted and session recording (Session Replay) is not enabled.
  • Legal basis: the Controller's legitimate interest in the security and proper functioning of the Site (Art. 6(1)(f) GDPR; see Recital 49). No cookies are used and no consent is required.
  • Retention: error events are stored for a limited period according to Sentry's settings (typically 90 days), after which they are deleted.
  • Transfer: data is hosted on infrastructure located in the European Union (Frankfurt, Germany). Any access by the provider, based in the United States, entails a transfer to a third country. Where the provider adheres to the EU-US Data Privacy Framework, the transfer is based on the relevant adequacy decision of the European Commission (Article 45 GDPR); otherwise, or should that decision cease to apply, the Standard Contractual Clauses under Article 46 GDPR with supplementary measures apply.
  • Provider's privacy policy: sentry.io

Compliance Telemetry (privacy-safe audit)

To verify that this Privacy/Cookie Policy matches the actual technical configuration of the Site, the Controller may enable a diagnostic function that detects technical information about the browser environment of visitors. The function is not enabled on every site: it is switched on by the Controller and, when active, the detection takes place once per page visited, a few seconds after loading.

What is collected: exclusively the names of the cookies and browser storage keys (localStorage and sessionStorage), the names of recognised third-party libraries, the domains of the scripts and embedded elements loaded in the page, the path of the visited page and the technical browser identifier already used to record the cookie choice.

What is NOT collected: the values of cookies and storage keys, the content of data saved in the browser, the user's identity, user communications or input, profiling data.

Purpose: to identify any undeclared tracking tools or obsolete declarations and update this notice in a timely manner, implementing the Italian DPA Guidelines of 10 June 2021 and the accountability principle (Art. 5.2 and Art. 25 GDPR).

Legal basis: the detection entails reading information stored in the user's terminal equipment. To the extent that it is not strictly necessary to provide the service requested by the user, it requires the data subject's consent under Art. 6.1.a GDPR and Art. 122(1) of Italian Legislative Decree 196/2003.

Nature of the data and retention: the information detected includes a browser identifier and therefore constitutes pseudonymous, not anonymous, data; it does not allow the Controller to identify the user directly. It is kept for the time strictly necessary for compliance checks and in any case for no longer than 90 days.

Consent may be withdrawn at any time through the cookie preferences control available on the Site; to withdraw consent or exercise their rights the data subject may also write to info@palace.it.

How to manage preferences

You can manage your cookie preferences in two ways:

  1. From the Site: use the cookie preferences control available on the Site to reopen the choice panel.
  2. From your browser settings (the paths indicated may vary depending on the version installed):
    • Google Chrome: Settings → Privacy and security → Cookies and other site data
    • Mozilla Firefox: Settings → Privacy & Security → Cookies and Site Data
    • Safari: Settings (or Preferences) → Privacy → Cookies and website data
    • Microsoft Edge: Settings → Privacy, search and services → Cookies

For newsletters and promotional emails: use the unsubscribe link at the bottom of every message, or write to the Controller at the contact details given in this notice.

Note: disabling first-party technical cookies may prevent the Site from functioning correctly (e.g. language persistence, cart session).

Additional opt-out tools for advertising networks:

Contacts for cookie questions

For any question about cookie usage on this site:

  • Email: info@palace.it
  • Address: Via Cavour 2/4, 39012 Merano (BZ), Italia

For more details on data processing collected via cookies, see the Privacy Policy of the site.