Legal

Cookie Policy

Last updated: 12 June 2026

This page lists every cookie and similar technology we use on www.italyvibe.it and how you control them. It complements the Privacy Policy.

How consent works

When you first visit the site, a banner asks you to accept or refuse cookies per category (essential / analytics / marketing). Until you decide, only essential cookies load and Google Consent Mode stays on the "denied" defaults. Your decision is stored locally and is also sent to our server as an audit-trail record (see "Server-side consent log" below). You can withdraw or change consent at any time by clicking "Cookie preferences" in the footer. Consent is requested again automatically when the policy version changes or 6 months after the last decision (Garante recommendation).

Categories

Strictly necessary (always on)

  • access_token / refresh_token — first-party session cookies issued after sign-in. HttpOnly, Secure, SameSite=Lax. Used to keep you signed in across pages and across italyvibe.it subdomains. Retention: 15 minutes (access) / 7 days (refresh).
  • role_hint — first-party, non-HttpOnly, 7 days. Used by the edge middleware to keep admin/concierge users on the right pages while the short-lived access token rotates. Not used for authorisation: every API call still verifies the signed token.
  • locale — first-party, 12 months. Stores your language preference (it / en).
  • italyvibe_anonymous_id (localStorage) — random UUID generated in your browser. Lets us tie a guest conversation to your account when you later sign in.
  • italyvibe_cookie_consent (localStorage) — your cookie decision and its policy version.

Analytics (consent required)

  • Google Analytics 4 (_ga, _ga_*) — first-party, 13 months. Loaded only after you accept the analytics category. We use IP anonymisation and Consent Mode v2; no cross-site advertising signals are sent.
  • Google Tag Manager — bootstrap loaded only after analytics consent; any tag fired through it must respect Consent Mode v2.

Marketing (consent required)

  • Meta (Facebook) Pixel — loaded only after you accept the marketing category, when configured. Used to measure campaign performance. If not configured, no marketing cookies are set at all.

Server-side consent log (transparency note)

Each accept / reject / customise action also triggers a POST to our API which writes an audit-trail row containing: the decision (per category), the policy version, the timestamp, your anonymousId (if any), the request source (banner / footer / API), a daily-rotating SHA-256 of your IP, and your User-Agent. The IP itself is never stored. Identifiers are stripped automatically after 24 months. We need this register to demonstrate compliance with Art. 7 GDPR and the Italian Garante Provvedimento 10 June 2021, on request from the supervisory authority. You can ask for a copy of YOUR rows by writing to privacy@italyvibe.it.

Disabling cookies in your browser

You can clear or block cookies via your browser settings (Chrome, Safari, Firefox, Edge — all expose this under Settings → Privacy). Doing so will sign you out and may prevent the site from working correctly. Disabling cookies in the browser is independent from withdrawing consent through the banner; both options are valid.

Contact

For any question about cookies or to exercise your GDPR rights, write to privacy@italyvibe.it. See the Privacy Policy for the full list of rights and the right to file a complaint with the Garante per la protezione dei dati personali.

Talk to Your ConciergeCookie Policy | Italy Vibe