Privacy notice
Last updated: 24 September 2026
This English version is a translation provided for convenience. If there is any conflict between the two, the Italian version prevails.
In short: we only collect the data we need to prepare and deliver your order, reply to your messages and keep the website secure. We don't use profiling cookies, we don't track your browsing, and we never sell or pass your data on to anyone. Details about cookies are in our cookie policy.
Who the data controller is
Agricola Tarantino, run by Francesco Tarantino, Via Oreto 413, 90124 Palermo (PA), Italy.
Email: info (at) agricolatarantino.com, phone +39 328 157 9543.
Registered business name: Francesco Tarantino, VAT number IT06961090823.
We have not appointed a data protection officer (DPO), as this is not required for a business like ours.
What data we process, why, and on what legal basis
1. Orders placed on the website
- Data: first name and surname, email, phone number, delivery address, notes, products ordered, amounts.
- Why: to confirm, prepare and deliver your order or arrange collection, and to let you know by email if that service is switched on.
- Legal basis: performance of the contract and of pre-contractual steps taken at your request (Art. 6(1)(b) GDPR). For tax and accounting records: legal obligation (Art. 6(1)(c) GDPR).
- Where: in a Cloudflare D1 database. Confirmation emails, if switched on, are sent through the Resend service.
You need to give us this data to place an order: without a name, contact details and an address we can't fulfil it.
2. Apiary visit bookings
- Data: first name and surname, email, phone number, type of visit, day, time, number of people, notes (for example children's ages or allergies, if you tell us), website language.
- Why: to arrange your visit, confirm or cancel it, and email you the summary and an event to add to your calendar.
- Legal basis: pre-contractual steps and contract at your request (Art. 6(1)(b) GDPR). Any allergy information you choose to give us is used only to run the visit safely.
- Where: in a Cloudflare D1 database. Emails are sent through the Resend service. The calendar event doesn't include your name or notes.
To prevent fake bookings, we email you a link to open within 30 minutes: if you don't open it, the request is cancelled and deleted within a day. We accept no more than two future bookings per email address and per phone number. If a booking is abusive (false details, pranks, spam), we may block the email address, phone number and network it came from: we only keep an encrypted fingerprint that cannot be traced back to the original, for as long as the block stays in place (legitimate interest in protecting the service, Art. 6(1)(f) GDPR).
3. Security and abuse prevention
- Data: the IP address the order or booking comes from, stored only as an encrypted fingerprint (a salted hash) that cannot be traced back to the address; technical data from the Cloudflare Turnstile anti-bot check; the hosting provider's technical logs.
- Why: to block fake orders, automated submissions and attacks on the website.
- Legal basis: our legitimate interest in protecting the website and the people who use it (Art. 6(1)(f) GDPR).
4. Messages and enquiries
- Data: whatever you send us by email, phone or WhatsApp.
- Why: to reply to you, for example about swarm removal, an apiary visit or a general question.
- Legal basis: pre-contractual steps taken at your request, or our legitimate interest in replying to you (Art. 6(1)(b) and 6(1)(f) GDPR).
5. Visitor statistics
- Data: aggregate visit data collected with Cloudflare Web Analytics, which uses no cookies, creates no persistent identifiers and shows us no personal data. We also use Google Search Console, which installs nothing on the website and only gives us aggregate search data.
- Why: to understand which pages are useful and improve the website.
- Legal basis: our legitimate interest in measuring use of the website in aggregate form (Art. 6(1)(f) GDPR).
6. Website language
- Data: on your first visit the website reads the
Accept-Languageheader that your browser sends with every request, so it can show you the page in Italian or English. This information is not stored or linked to you. Only if you choose a language yourself with the switcher at the top of the page do we save your choice (itoren) in the technical cookie__Host-agt_lingua. - Why: to show you the website in a language you understand and remember the language you chose.
- Legal basis: providing the service you asked for, and our legitimate interest in making the website understandable (Art. 6(1)(b) and 6(1)(f) GDPR).
7. Private area for the people who run the website
- Data: for the people who manage the website, the technical passkey data (public key, credential ID, usage counter) stored in Cloudflare D1, and a technical session cookie. No passwords and no biometric data: your fingerprint or face never leaves your device.
- Why: to allow secure access to /accesso and /admin for authorised people only.
- Legal basis: our legitimate interest in keeping the website secure (Art. 6(1)(f) GDPR).
This data only concerns the people who run the website, not visitors or customers.
How long we keep it
- Order data: 24 months from the order, to handle deliveries, complaints and guarantees. If a receipt or invoice was issued for the order, the tax and accounting data alone is kept for 10 years, as required by law (Art. 2220 of the Italian Civil Code).
- Booking data: 24 months from the day of the visit, then deleted automatically.
- IP fingerprint and anti-abuse data: only as long as strictly necessary, and 30 days at most.
- Hosting provider's technical logs: a few days, in line with Cloudflare's policies.
- Messages: as long as needed to reply, then 12 months at most.
- Chosen language: 12 months in the cookie on your device, or until you delete it. The
Accept-Languageheader is not kept. - Private area session: 8 hours at most, or until you sign out.
- Passkeys of the people who run the website: for as long as the person remains authorised; they are deleted when the passkey is revoked.
- Statistics: aggregate data only, with no personal data.
Who we share it with
Your data is never made public. It is processed on our behalf, as data processors (Art. 28 GDPR), only by the providers we need to run the website:
- Cloudflare, Inc.: website hosting (Workers), the database for orders, bookings and the private area (D1), the Turnstile anti-bot check, Web Analytics statistics.
- GitHub, Inc.: storage for the website's content (text, photos, products). It holds data about the people who run the website only, not about customers.
- Resend: sending emails about orders and bookings, if that service is switched on.
- The courier, only for orders being shipped, and our accountant for tax obligations.
Transfers outside the European Union
Some providers are based in the United States. Transfers take place under the EU-US Data Privacy Framework, for certified providers, and the Standard Contractual Clauses approved by the European Commission (Art. 46 GDPR).
Cookies and browser storage
The website only uses technical tools: the cart saved in your browser's localStorage (product codes and quantities only, no personal data), the cookie that remembers the language you picked with the switcher, the anti-bot check when you place an order, and two technical cookies for the people who run the website (the session and the private-area menu links). Our statistics use no cookies. That is why no consent banner is needed. Full details, including durations and providers, are in the cookie policy.
Your rights
At any time you can ask us to (Arts. 15 to 22 GDPR):
- tell you whether we process your data and give you a copy (access);
- correct or complete it (rectification);
- delete it, where no legal obligation requires us to keep it (erasure);
- limit how it is used (restriction);
- give it to you in a readable format so you can take it elsewhere (portability);
- stop processing based on legitimate interest (objection).
Just write to info (at) agricolatarantino.com: we reply within one month. If you believe your data is being handled improperly, you can lodge a complaint with the Italian Data Protection Authority, Garante per la protezione dei dati personali.
We do not make automated decisions or carry out profiling.
Changes
If we change the way we handle data, we will update this page and the date at the top.