Skip to main content

    Privacy Policy

    Introduction

    Welcome to https://toursofmilan.com ("Website"), operated by Tours of Milan ("we", "us", or "our").

    We are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your information when you visit our Website or use our services.

    By using our Website, you consent to the practices described in this Privacy Policy. If you do not agree with this policy, please do not use our Website.

    Information We Collect

    Information You Provide Directly

    When you fill out forms on our Website (such as the contact form or the review form), we may collect the following personal data:

    • Contact information: first name, last name, email address, phone number and country code
    • Inquiry details: message content, preferred contact method (email or phone), referral source, whether the request relates to a corporate event
    • Tour preferences: selected tour, travel dates, number of participants, destination
    • Review data: star rating, review text, country of origin

    Information Collected Automatically

    When you submit a form or visit our Website, limited technical information is collected:

    • IP address: used for CAPTCHA verification and fraud prevention. For reviews, the IP address associated with a submission may be stored alongside the review record as part of our abuse-prevention measures.
    • Browser and device information: collected through standard server logs by our hosting provider
    • Source page: the URL of the page from which you submitted a form, so we can respond with the correct context

    How We Use Your Information

    We use your personal data for the following purposes:

    • To respond to your inquiries: processing contact form submissions and booking requests
    • To manage reviews: displaying approved tour reviews on our Website
    • To send communications: confirmation emails, booking follow-ups, and responses to your messages
    • To ensure security: verifying form submissions through CAPTCHA to prevent spam and abuse
    • To improve our services: reviewing aggregated technical logs to maintain and enhance the Website

    Legal Basis for Processing

    We process your personal data based on the following legal grounds:

    • Consent: when you submit a form, you explicitly consent to the processing of your data by accepting this Privacy Policy
    • Legitimate interest: for security measures, fraud prevention, and Website improvement
    • Contractual necessity: when processing is required to fulfill a booking request or respond to an inquiry

    Third-Party Services and Data Processors

    To operate the Website we rely on a small number of external service providers, selected for their compliance with applicable data protection regulations and their security practices. We disclose the categories of providers we use below rather than detailed technical information about our infrastructure.

    • Hosting, content delivery and CAPTCHA provider (United States): serves the Website, applies security protections, and performs CAPTCHA verification on form submissions. This provider may process your IP address and basic request metadata for security purposes.
    • Database provider (United States): stores the data you submit through our forms (contact requests, booking inquiries and reviews) in a secured environment.
    • Transactional email provider (European Union): delivers confirmation and notification emails triggered by your submissions.
    • FareHarbor (United States): on pages where direct online booking is offered, bookings are handled by FareHarbor, a third-party booking platform. When you interact with a FareHarbor booking widget, FareHarbor may set its own cookies, store identifiers in your browser, and collect booking-related information directly. Their practices are governed by the FareHarbor Privacy Policy.

    Where we or our providers transfer personal data outside the European Economic Area, such transfers are made on the basis of the safeguards required by applicable law (typically the European Commission's Standard Contractual Clauses).

    Data Retention

    We retain your personal data only for as long as necessary to fulfill the purposes described in this policy:

    • Contact form submissions and booking requests: retained for the duration necessary to process your inquiry and for a reasonable period thereafter for follow-up purposes
    • Reviews: retained for as long as they remain published on the Website, or until you request their removal
    • Security logs: retained for a limited period as required for fraud prevention and security

    Your Rights

    Under applicable data protection laws, you have the following rights:

    • Access: request a copy of the personal data we hold about you
    • Rectification: request correction of inaccurate or incomplete data
    • Erasure: request deletion of your personal data ("right to be forgotten")
    • Restriction: request that we limit the processing of your data
    • Data portability: request your data in a structured, machine-readable format
    • Objection: object to the processing of your data based on legitimate interest
    • Withdraw consent: withdraw your consent at any time without affecting the lawfulness of prior processing

    To exercise any of these rights, please contact us at [email protected].

    Cookies and Browser Storage

    Our Website does not set first-party cookies for advertising or cross-site tracking. The cookies and browser storage that may be present fall into the following categories:

    • Strictly necessary: our security and CAPTCHA provider may set short-lived cookies required to detect bots and keep the Website available. These are not used to profile you and cannot be disabled without breaking core functionality.
    • Booking provider: if you interact with a FareHarbor booking widget, FareHarbor may set cookies and store identifiers (including in your browser's local storage) to operate the booking flow and attribute bookings. This only occurs when you engage with a booking widget.
    • Analytics (only where enabled): on specific sites, a standard web analytics script may be loaded to measure aggregated usage. Where present, it will be disclosed on the site and may set analytics cookies. It is not used for advertising.

    No advertising cookies, remarketing pixels or cross-site tracking scripts are loaded by us on this Website.

    Children's Privacy

    Our Website is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us at [email protected] so we can promptly delete it.

    Changes to This Policy

    We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. The updated policy will be posted on this page with a revised "Last modified" date. We encourage you to review this policy periodically.

    Contact Us

    If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at:

    Tours of Milan

    Email: [email protected] Website: https://toursofmilan.com

    TripAdvisor Certificate of Excellence

    Got questions? We're at your service.

    Contact us by email, WhatsApp, or through our online form to start planning your perfect Milan experience.

    How do you prefer to be contacted?