Privacy Policy
Last updated: 12 August 2026. This is the information notice for livinglocal.ai under Articles 13 and 14 of the GDPR.
In plain terms
LivingLocal is a travel-discovery site operated by Instal S.r.l. You can use all of it without telling us who you are: there is no account, no login, no newsletter, no contact form and no payment on this site. We ask for no personal data, and we sell none.
- Analytics only if you say yes. Google Analytics, loaded through Google Tag Manager, is the one optional tool we use. It does not load until you agree, and refusing changes nothing about what the site does for you.
- The AI assistant sends your messages to Google. What you type in the chat is transmitted to Google's Gemini API to generate the reply, and Google keeps a copy for a short period to police abuse of its own service. Please do not type personal details into it.
- Booking links are affiliate links. When you go to GetYourGuide, Headout or Viator/Tripadvisor to book, the link identifies us as the referrer so we earn a commission, at no extra cost to you. From that point the partner's own privacy policy applies.
- Photos and maps come from other people's servers. Loading them discloses your IP address to those hosts. Every one of them is named in Who receives your data.
- We hold data about people who never came here. Traveller reviews copied from the booking platforms carry personal data about their authors, and an AI model analyses those reviews for us. If you wrote one, the part that concerns you is Information that does not come from you.
Everything below sets this out properly: what is processed, why, on what legal basis, who receives it, for how long, and what you can demand from us — see Your rights.
Who is responsible for your data
The data controller is Instal S.r.l., which operates LivingLocal at https://livinglocal.ai.
- Registered office: Via del Tiratoio 1, 50124 Firenze, Italy
- VAT number / tax code (P. IVA e C.F.): 06681730484
- Data protection enquiries and requests: privacy@instal.com
- General contact: hello@instal.com
- Data Protection Officer: dpo@instal.it
This page is the complete notice for livinglocal.ai and it is the one that governs this site. Instal S.r.l. also publishes group-level legal documents covering the company and its other products; those do not apply here.
What we process, why, and on what legal basis
Each activity below is listed with its purpose and its lawful basis under Article 6 of the GDPR. Where the basis is consent, the activity does not happen at all until you give it, and stops when you withdraw it.
1. Delivering the website
Every request your browser makes carries the technical data any web server needs: your IP address, your browser and operating system, the address requested, the time, the response status and, where your browser sends it, the page you came from. Our hosting provider handles this on our behalf to serve pages and keep the service available and secure. Our own application code does not store it and does not write it to any log; the only place it reads your IP address is the rate limits described in section 9.
Legal basis: performance of the service you requested (Art. 6(1)(b)) and our legitimate interest in operating a working, secure site (Art. 6(1)(f)).
2. Remembering your privacy choice
When you answer the cookie banner we store your decision in a first-party cookie on your device, so we neither ask again on every page nor act on a choice you did not make. It records which categories you accepted, when, how, and which version of the policy you saw. Details are in the Cookie Policy.
Legal basis: our legal obligation to be able to demonstrate consent (Art. 6(1)(c) with Art. 7(1)) and our legitimate interest in honouring your choice (Art. 6(1)(f)). Storing this cookie is exempt from consent because it is what makes your consent choice work.
3. Showing photos and maps
Images on this site, and the background video on the home page, are served from our own cloud storage. The maps on activity pages use vector tiles from OpenFreeMap, operated by Hyperknot Software Kft., a company registered in Hungary; it states that it does not log IP addresses by default, reserving the right to log them for up to 30 days to investigate a security incident. It publishes nothing about where its servers are, and the tile responses show they are delivered by Cloudflare, named in the recipients table below.
Your browser fetches all of these itself, which discloses your IP address and browser to those hosts. We send them nothing further about you and set no cookie of our own through them; what each host does on its own side is governed by its own privacy policy, linked for every one of them under Who receives your data.
Legal basis: delivering the content you asked to see (Art. 6(1)(b)) and our legitimate interest in serving media efficiently (Art. 6(1)(f)).
4. Site search
What you type into the search box travels in the page address and is used on our servers to run the query against our catalogue. We do not keep a search history and cannot connect one search to another. If — and only if — you have consented to analytics, the search term is also sent to Google Analytics as an event. PostHog is told that a search happened, but the term itself is removed before the event reaches it. Please do not type personal details into the search box.
Legal basis: providing the feature you used (Art. 6(1)(b)); for the analytics copy of it, your consent (Art. 6(1)(a)).
5. The trip quiz and our recommendations
The quiz records your answers in the page address and sends them to our recommendation service — a service we operate ourselves, running on Google Cloud — which returns matching activities. The answers are preference choices from fixed lists: who you are travelling with, the age bands of any children in your party, themes, pace, budget, duration, time of day, region, whether you want something that works in the rain, accessibility needs, whether you want skip-the-line entry, and whether your dates are fixed or flexible. There is no free-text field and nothing identifies you. The service receives no IP address, no cookie and nothing about your browser, and neither it nor we keep a record of the session. With analytics consent, a summary of your answers is also sent to Google Analytics and to PostHog.
Legal basis: providing the feature you used (Art. 6(1)(b)); for the analytics copy of it, your consent (Art. 6(1)(a)).
6. The AI travel assistant
The chat widget is an AI system, not a person. To produce a reply, the text of your messages in that conversation, together with the language of the site, is sent from our server to Google's Gemini API. Your browser never contacts Google for this, so nothing is stored on your device. If your message describes what you want to do, the assistant also passes the preferences it understood to the same recommendation service the quiz uses.
We keep nothing: the conversation is not written to any database and not written to our logs, and it is gone when you reload the page. On Google's side, Google's terms for the Gemini API require the paid tier for any service made available to users in the European Economic Area, and Google states that on that tier it does not use prompts or replies to improve or train its products. Google does keep prompts and replies for up to 55 days for the sole purpose of detecting and preventing abuse of its service; it states that this copy is not used to train any model other than its own abuse-detection systems, and that only authorised Google staff can reach it through an internal review process. See Google's Gemini API Additional Terms and its usage policies.
The Gemini API is a global service: Google publishes no EU-only processing guarantee and no zero-retention option for it. That is why we ask you not to type your name, contact details, payment information, health information or anything else personal into the assistant. It can suggest activities perfectly well without them.
If you have consented to analytics, we send Google Analytics and PostHog the number of characters in your message and never the message itself. Replies are generated automatically and can be wrong or out of date; check anything that matters — prices, opening times, availability — with the operator before you rely on it.
Legal basis: providing the feature you chose to use (Art. 6(1)(b)) and our legitimate interest in offering a useful discovery tool (Art. 6(1)(f)). Using it is entirely optional.
7. Analytics
With your consent we use Google Analytics 4, loaded through Google Tag Manager, to understand which destinations, pages and experiences people look at, whether search and the quiz lead anywhere useful, and which booking links get clicked. Google receives your IP address, browser and device characteristics, the pages you view and the interactions we send as events — including search terms, quiz answers and the identity of the experience behind a booking click — associated with a pseudonymous identifier stored in your browser. This involves a transfer to Google in the United States.
The Google Tag Manager container is requested only after you agree to at least one optional category, because that container is also where any advertising tag would live. Granting Advertising alone therefore loads it too.
The same consent also loads PostHog, which we use to see how a visit unfolds rather than only what it totalled: the order pages are opened in, where a search or the quiz is abandoned, which cards are clicked. It receives your IP address, your browser, the pages you view and the interactions we choose to send, against a pseudonymous identifier kept in your browser as both a cookie and a localStorage entry. It is configured to send only the interactions we specify rather than to capture every click automatically, and two fields are removed before an event reaches it: whatever you typed into the search box, and the text of any error message. It also receives a report when the site hits an unexpected error, so that we can find and fix it.
PostHog processes this on our behalf and on our instructions, under a data processing agreement, on its European infrastructure with servers in Frankfurt, Germany. A transfer safeguard is still needed and is listed under Transfers outside the EEA: PostHog Inc. is established in the United States, and its own published list of providers includes Cloudflare for edge routing, which operates across a worldwide network whose locations Cloudflare determines.
Legal basis: your consent, and nothing else (Art. 6(1)(a) GDPR, Art. 122 of the Italian Data Protection Code). We do not claim legitimate interest for analytics. You can withdraw at any time with . Every cookie involved is listed in the Cookie Policy.
8. Booking links and affiliate commission
Booking happens on the partner's site. The links that take you there carry our affiliate and campaign parameters, so the partner can attribute the referral and pay us a commission at no extra cost to you. Those parameters are visible to the partner, and may include a language and currency preference for the page it opens. The links are marked as sponsored.
Once you land on the partner's site, that partner is an independent controller and its own privacy and cookie policies apply. We never receive your booking, payment or traveller details from them. If you have consented to analytics, we record the click as an event in Google Analytics, including the experience, its price and where on the page you clicked.
Legal basis: our legitimate interest in being paid for referrals we generate, which is what funds a site that is free to use (Art. 6(1)(f)); the analytics event is based on your consent (Art. 6(1)(a)).
9. Security, abuse prevention and diagnostics
When something breaks, our code records the error itself and not who triggered it: our error logs contain no IP address, no user agent and no request identifier. Our hosting provider keeps its own request logs, which do include IP addresses, to defend against attack and abuse.
One further use of your IP address is worth stating plainly. Two parts of the site cost us real money or real database time to answer — replies from the AI assistant, and each batch of cards in the swipe feed — so that neither can be flooded, each request to them is counted against the IP address it came from. That address is sent to Upstash, a hosted Redis service acting as our processor, where it is used as the key of a counter and expires automatically about two minutes later. Nothing else travels with it — not the text of your message, not what you were looking at, not which cards you were shown.
Legal basis: our legitimate interest in the security, integrity and availability of the service and in controlling the cost of running it (Art. 6(1)(f)), a purpose Art. 32 GDPR expressly recognises.
10. Complying with the law
Where we are legally required to retain or disclose information — for example on a lawful request from an authority — we will do so.
Legal basis: compliance with a legal obligation (Art. 6(1)(c)); where we defend a legal claim, our legitimate interest (Art. 6(1)(f)).
Nothing about you is required
You do not have to provide any personal data to use LivingLocal, and there is no consequence if you provide none: browsing, searching, the quiz and every booking link work regardless. Analytics is optional and refusing it removes no functionality. Using the AI assistant is optional too — the only consequence of not typing anything into it is that it cannot suggest anything.
Browsing needs no account and no login, and we ask for no name, email address or phone number. Our consent tool offers a separate Advertising choice, switched off unless you turn it on.
Please do not volunteer special-category data (health, beliefs, and so on), including in the chat.
Information that does not come from you
Our catalogue is compiled from the booking platforms whose experiences we index — GetYourGuide, Headout and Viator/Tripadvisor — and from open sources such as Wikidata, Wikipedia and OpenStreetMap for places and landmarks.
Part of that material is traveller reviews, and those can contain personal data about the reviewer: the display name shown on the original platform, the country they gave, the title and text of the review, the rating and the date. We may show the review in an automatically translated form, and in shortened form, so readers can judge an experience. We collected all of it from the platform, not from the reviewer.
We also summarise reviews automatically, using Google's Gemini as our processor, so that an activity page can show how positive its reviews are overall and which aspects of the experience travellers mention most. Only those aggregate results are published: no reviewer is singled out, scored publicly, or ranked against another.
Legal basis: our legitimate interest in presenting trustworthy, comparable information about the experiences we list (Art. 6(1)(f)) — the same basis covers both reproducing a review and analysing it, since a summarised, comparable read of many reviews is the point of showing them at all. If a review of yours appears here and you want it removed, write to privacy@instal.com and we will take it out of our copy, together with the summary derived from it. You can object to the analysis alone, under Art. 21(1), without asking for the review itself to go. The original stays on the platform that published it, which you would need to contact separately.
Who receives your data
Every recipient is named below. Providers who act on our instructions are processors; platforms you choose to go to are independent controllers.
- Google — in several separate roles: Google Tag Manager and Google Analytics 4, only after you consent; the Gemini API, which generates the assistant's replies from the text you type and which also performs the review analysis described under Information that does not come from you; Google Cloud, which runs our recommendation service and our cloud storage.
- Vercel Inc. — hosts this website as our processor and keeps the request logs described above. The server-side code that builds our pages runs in Vercel's Frankfurt region.
- Neon, LLC — hosts the read-only database this site queries. It holds our catalogue of experiences, places and reviews. Nothing about visitors is ever written to it.
- Upstash — holds the short-lived counters that cap how many assistant and swipe-feed requests come from one connection, as described in section 9.
- GetYourGuide, Headout and Viator/Tripadvisor — the booking platforms. They receive nothing until you click a booking link, at which point they learn that the referral came from us, and become independent controllers for everything that follows on their own site.
- Photo and map hosts contacted directly by your browser — listed in the table below.
- Authorities, courts and professional advisers — only where we are legally obliged to disclose, or need to establish or defend a legal claim.
| Recipient | Contacted by | What it does |
|---|---|---|
| OpenFreeMap (Hyperknot Software Kft.) tiles.openfreemap.org | Your browser | Supplies the vector map tiles shown on activity pages, and is operated by Hyperknot Software Kft., a company registered in Hungary. Your browser fetches the tiles directly, which discloses your IP address and browser to it. No cookie or other storage is involved. Its published policy is that it does not log IP addresses by default, but that it may switch IP logging on for up to 30 days to investigate a security incident or misuse; anonymised logs without IP addresses are kept indefinitely. |
| Cloudflare, Inc. (CDN in front of the map tiles) tiles.openfreemap.org | Your browser | Delivers those same map tiles as OpenFreeMap’s content delivery network, so it is Cloudflare — not OpenFreeMap’s own servers — that answers your browser first and receives your IP address. Cloudflare is a US company operating a worldwide network, and OpenFreeMap publishes no statement about which country the tiles are served from. No cookie or other storage is involved. |
| GetYourGuide cdn.getyourguide.com | Your browser | Hosts the activity photos supplied by GetYourGuide. Images load straight from its CDN, so your IP address and browser are disclosed to it. |
| Viator / Tripadvisor hare-media-cdn.tripadvisor.com, media.tacdn.com, dynamic-media.tacdn.com | Your browser | Hosts the activity photos supplied by Viator and Tripadvisor — the majority of the photography on this site. Images load straight from its CDN, so your IP address and browser are disclosed to it. |
| Headout cdn-imgix.headout.com | Your browser | Hosts the activity photos supplied by Headout. Images load straight from its CDN, so your IP address and browser are disclosed to it. |
| Unsplash images.unsplash.com | Your browser | Hosts part of the editorial and illustrative photography used on our own pages. |
| Google Cloud Storage storage.googleapis.com | Your browser | Google Cloud Storage holds the images and the home-page background video we store ourselves. Serving them discloses your IP address and browser to Google as our storage provider. |
| Vercel Blob (legacy image host) * *.public.blob.vercel-storage.com | Your browser | A storage service we used for images before moving them to Google Cloud Storage. An older stored image address could still point here, in which case serving it would disclose your IP address and browser to Vercel. |
| Vercel Inc. livinglocal.ai | Your browser | Hosts and serves this website from a data centre in Frankfurt, Germany. Like any web server it processes the technical data of each request, including your IP address, on our behalf and on our instructions. |
| Google (Gemini API) generativelanguage.googleapis.com | Our server only | Generates the replies of the AI travel assistant. Only our server contacts Google, so nothing is stored in your browser; what is transmitted is the text of your messages in that conversation and the language of the site. |
| Google Cloud Run (our recommendation service) *.run.app, oauth2.googleapis.com | Our server only | Runs the service that matches your answers to activities. Our server sends it the preferences you chose in the quiz, or the ones the assistant understood from your message, and it returns a ranked list. It receives no IP address, no cookie and nothing about your browser, and it keeps no record of the request. |
| Upstash *.upstash.io | Our server only | Counts how many chat requests come from one internet connection, so that nobody can run up our costs by flooding the assistant. Your IP address is used as the counter key and expires automatically about two minutes later. Nothing else about the request — least of all what you typed — is sent there. |
| Neon, LLC (part of Databricks) *.neon.tech | Our server only | Hosts the database this site reads. It holds our catalogue of experiences, places and reviews. The site only ever reads from it: nothing about you is written there. |
| PostHog (PostHog Inc.) eu.i.posthog.com, eu-assets.i.posthog.com | Your browser | Measures how the site is used, once you allow analytics: which pages you open, in which order, and the interactions we have chosen to record. Your browser sends those events to it directly, which discloses your IP address and browser to it as well. It processes them on our behalf and on our instructions, on PostHog’s European infrastructure with servers in Frankfurt, Germany. PostHog names Cloudflare among its own providers for edge routing, and Cloudflare decides which of its worldwide locations handles the traffic, which is why PostHog also appears in the transfer table below. |
OpenFreeMap (Hyperknot Software Kft.)
tiles.openfreemap.org- Contacted by
- Your browser
- What it does
- Supplies the vector map tiles shown on activity pages, and is operated by Hyperknot Software Kft., a company registered in Hungary. Your browser fetches the tiles directly, which discloses your IP address and browser to it. No cookie or other storage is involved. Its published policy is that it does not log IP addresses by default, but that it may switch IP logging on for up to 30 days to investigate a security incident or misuse; anonymised logs without IP addresses are kept indefinitely.
Cloudflare, Inc. (CDN in front of the map tiles)
tiles.openfreemap.org- Contacted by
- Your browser
- What it does
- Delivers those same map tiles as OpenFreeMap’s content delivery network, so it is Cloudflare — not OpenFreeMap’s own servers — that answers your browser first and receives your IP address. Cloudflare is a US company operating a worldwide network, and OpenFreeMap publishes no statement about which country the tiles are served from. No cookie or other storage is involved.
GetYourGuide
cdn.getyourguide.com- Contacted by
- Your browser
- What it does
- Hosts the activity photos supplied by GetYourGuide. Images load straight from its CDN, so your IP address and browser are disclosed to it.
Viator / Tripadvisor
hare-media-cdn.tripadvisor.com, media.tacdn.com, dynamic-media.tacdn.com- Contacted by
- Your browser
- What it does
- Hosts the activity photos supplied by Viator and Tripadvisor — the majority of the photography on this site. Images load straight from its CDN, so your IP address and browser are disclosed to it.
Headout
cdn-imgix.headout.com- Contacted by
- Your browser
- What it does
- Hosts the activity photos supplied by Headout. Images load straight from its CDN, so your IP address and browser are disclosed to it.
Unsplash
images.unsplash.com- Contacted by
- Your browser
- What it does
- Hosts part of the editorial and illustrative photography used on our own pages.
Google Cloud Storage
storage.googleapis.com- Contacted by
- Your browser
- What it does
- Google Cloud Storage holds the images and the home-page background video we store ourselves. Serving them discloses your IP address and browser to Google as our storage provider.
Vercel Blob (legacy image host) *
*.public.blob.vercel-storage.com- Contacted by
- Your browser
- What it does
- A storage service we used for images before moving them to Google Cloud Storage. An older stored image address could still point here, in which case serving it would disclose your IP address and browser to Vercel.
Vercel Inc.
livinglocal.ai- Contacted by
- Your browser
- What it does
- Hosts and serves this website from a data centre in Frankfurt, Germany. Like any web server it processes the technical data of each request, including your IP address, on our behalf and on our instructions.
Google (Gemini API)
generativelanguage.googleapis.com- Contacted by
- Our server only
- What it does
- Generates the replies of the AI travel assistant. Only our server contacts Google, so nothing is stored in your browser; what is transmitted is the text of your messages in that conversation and the language of the site.
Google Cloud Run (our recommendation service)
*.run.app, oauth2.googleapis.com- Contacted by
- Our server only
- What it does
- Runs the service that matches your answers to activities. Our server sends it the preferences you chose in the quiz, or the ones the assistant understood from your message, and it returns a ranked list. It receives no IP address, no cookie and nothing about your browser, and it keeps no record of the request.
Upstash
*.upstash.io- Contacted by
- Our server only
- What it does
- Counts how many chat requests come from one internet connection, so that nobody can run up our costs by flooding the assistant. Your IP address is used as the counter key and expires automatically about two minutes later. Nothing else about the request — least of all what you typed — is sent there.
Neon, LLC (part of Databricks)
*.neon.tech- Contacted by
- Our server only
- What it does
- Hosts the database this site reads. It holds our catalogue of experiences, places and reviews. The site only ever reads from it: nothing about you is written there.
PostHog (PostHog Inc.)
eu.i.posthog.com, eu-assets.i.posthog.com- Contacted by
- Your browser
- What it does
- Measures how the site is used, once you allow analytics: which pages you open, in which order, and the interactions we have chosen to record. Your browser sends those events to it directly, which discloses your IP address and browser to it as well. It processes them on our behalf and on our instructions, on PostHog’s European infrastructure with servers in Frankfurt, Germany. PostHog names Cloudflare among its own providers for edge routing, and Cloudflare decides which of its worldwide locations handles the traffic, which is why PostHog also appears in the transfer table below.
* Declared because the current configuration could still reach it, although we have not observed it in use. It is listed rather than omitted so that this table errs towards telling you more.
Transfers outside the European Economic Area
Some of the recipients above are, or belong to groups, established in the United States, so data can be transferred outside the EEA. This concerns above all analytics data sent to Google when you consent, the text you send to the Gemini API, and platform-level processing by Vercel — even though our server-side code runs in Vercel's Frankfurt region.
Such transfers are only made on one of the safeguards in Chapter V of the GDPR: an adequacy decision — for the United States, the EU–US Data Privacy Framework adopted by the European Commission on 10 July 2023, where the recipient is certified under it — or the European Commission's Standard Contractual Clauses under Art. 46(2)(c), with additional measures where needed. For the three providers we contract with, this is what each of them publishes:
| Provider | What it does for us | Safeguard it states it relies on |
|---|---|---|
| Google LLC | Analytics (with your consent), the Gemini API behind the AI assistant, the storage that serves our images and background video, and the cloud that runs our recommendation service. | EU–US Data Privacy Framework; UK Extension to the EU–US Data Privacy Framework; Swiss–US Data Privacy Framework; Standard Contractual Clauses the provider's own statement |
| Vercel Inc. | Hosting: every request to this site passes through it. | EU–US Data Privacy Framework; UK Extension to the EU–US Data Privacy Framework; Swiss–US Data Privacy Framework; Standard Contractual Clauses the provider's own statement |
| Neon, LLC (covered by Databricks, Inc.) | The database this site reads its catalogue from. | EU–US Data Privacy Framework; UK Extension to the EU–US Data Privacy Framework; Swiss–US Data Privacy Framework the provider's own statement |
| PostHog Inc. (formerly Hiberly Inc.) | Product analytics (with your consent). Your data is stored on European servers, but PostHog’s own edge and routing provider operates worldwide, so a safeguard is needed. | EU–US Data Privacy Framework; UK Extension to the EU–US Data Privacy Framework; Swiss–US Data Privacy Framework; Standard Contractual Clauses the provider's own statement |
Google LLC
- What it does for us
- Analytics (with your consent), the Gemini API behind the AI assistant, the storage that serves our images and background video, and the cloud that runs our recommendation service.
- Safeguard it states it relies on
- EU–US Data Privacy Framework; UK Extension to the EU–US Data Privacy Framework; Swiss–US Data Privacy Framework; Standard Contractual Clauses
the provider's own statement
Vercel Inc.
- What it does for us
- Hosting: every request to this site passes through it.
- Safeguard it states it relies on
- EU–US Data Privacy Framework; UK Extension to the EU–US Data Privacy Framework; Swiss–US Data Privacy Framework; Standard Contractual Clauses
the provider's own statement
Neon, LLC (covered by Databricks, Inc.)
- What it does for us
- The database this site reads its catalogue from.
- Safeguard it states it relies on
- EU–US Data Privacy Framework; UK Extension to the EU–US Data Privacy Framework; Swiss–US Data Privacy Framework
the provider's own statement
PostHog Inc. (formerly Hiberly Inc.)
- What it does for us
- Product analytics (with your consent). Your data is stored on European servers, but PostHog’s own edge and routing provider operates worldwide, so a safeguard is needed.
- Safeguard it states it relies on
- EU–US Data Privacy Framework; UK Extension to the EU–US Data Privacy Framework; Swiss–US Data Privacy Framework; Standard Contractual Clauses
the provider's own statement
Certifications are renewed annually, so we describe what each provider currently states rather than warranting it ourselves; you can check any of them against the Data Privacy Framework list at dataprivacyframework.gov.
The photo and map hosts your browser contacts are a different case: we have no contract with them, so we cannot warrant their transfer arrangements, and each one's own privacy policy is linked in the table above. We would rather say so plainly than reassure you about them. The map tiles are the clearest illustration: the operator is registered in Hungary and publishes that it does not log IP addresses by default, which sounds like a purely European affair, but it publishes nothing about where its servers are, it reserves the right to log IP addresses for up to 30 days during a security incident, and the tiles in fact reach you through Cloudflare's worldwide network. We therefore make no claim that tile requests stay inside the EEA.
You are entitled to ask us for a copy of the safeguards we rely on. Write to privacy@instal.com. If you would rather no analytics data left the EEA at all, refuse or withdraw the analytics category — that is enough to stop it.
How long anything is kept
- Your cookie choice: about six months on your device, after which we ask again. Clearing your cookies deletes it immediately. The exact duration is in the Cookie Policy.
- Analytics data at Google: the pseudonymous identifier lives in your browser for up to two years unless you clear it or withdraw consent, in which case we expire the cookies set on our own domain. The analytics data itself is held in Google Analytics 4. You can ask us to delete the data associated with you at any time — write to us and we will action it.
- Analytics data at PostHog: the pseudonymous identifier lives in your browser for up to one year as a cookie, and alongside it in
localStorage, which carries no expiry of its own — withdrawing consent removes both, and so does clearing your browsing data. PostHog publishes no fixed retention period for the event data itself, so rather than quote a figure we will tell you the retention configured on our project if you ask. You can have the data associated with you deleted at any time — write to us and we will action it. - Your chat messages: nothing is kept by us — no database record, no log entry, and the conversation is discarded when you leave the page. Google keeps prompts and replies for up to 55 days for abuse detection, as described in section 6.
- The rate-limit counters: the IP address used as their key expires about two minutes after the request.
- Searches and quiz answers: not stored by us at all. They exist in the page address, therefore in your own browser history, and — with your consent — as analytics events subject to the window above.
- Server request logs: our hosting provider Vercel keeps a runtime log of each request — the IP address it came from, the path and query string, the browser user agent, the status code and the serving region — and deletes it automatically under the retention schedule it publishes, which is at most 30 days and on most plans a matter of hours or days. Our own error logs contain no data about you and are kept only as long as needed to fix the problem.
- Reviews: we state a criterion rather than a number, because there is no fixed period — a review stays in our copy of the catalogue for as long as the experience it describes is listed here, and its summary goes with it. Removing a review on request, as described under Information that does not come from you, removes both at once.
- Correspondence with us (for example a rights request by email): as long as needed to deal with it and to show that we did, then deleted, unless a legal retention period applies.
Your rights, and how to use them
Under the GDPR you can exercise all of the following, free of charge, by writing to privacy@instal.com:
- Access (Art. 15) — confirmation of whether we process data about you, and a copy of it.
- Rectification (Art. 16) — correction of inaccurate or incomplete data.
- Erasure (Art. 17) — deletion, where one of the grounds in the GDPR applies.
- Restriction (Art. 18) — that we pause processing while a dispute about it is resolved.
- Data portability (Art. 20) — data you provided under consent or contract, in a structured, machine-readable format.
- Objection (Art. 21) — to processing based on our legitimate interest, including the affiliate attribution and the review corpus described above.
- Withdrawal of consent (Art. 7(3)) — at any time, as easily as you gave it: use , or the same control in the footer of every page, and switch a category off or choose "Reject all". Withdrawal does not affect processing that was lawful while your consent was in place.
How to make a request
Send one email to privacy@instal.com saying which right you want to exercise and enough detail for us to find whatever it concerns — for example the wording of a review you want removed, or the date and rough time of a chat. You do not need a particular form of words, and we do not ask for an identity document as a matter of course; we would only ask for something more if we had a genuine doubt about who is writing.
We answer within one month of receiving your request. If it is complex we may extend that by up to two further months, and we will tell you within the first month that we are doing so and why. Making a request costs you nothing.
Because there is no account to look you up by, we often cannot tell which data — if any — relates to you. Where that is the case we will say so and explain why, as Art. 11(2) and Art. 12(2) allow. For analytics data held by Google under its own identifier, the quickest route is usually to withdraw consent here and then use Google's own controls.
If you want to complain
You have the right to lodge a complaint with a supervisory authority (Art. 77). In Italy that is the Garante per la protezione dei dati personali:
- Piazza Venezia 11, 00187 Roma, Italy
- protocollo@gpdp.it · PEC protocollo@pec.gpdp.it · +39 06 696771
- How to file a complaint (reclamo) — the authority explains the procedure and provides a form. Filing is free.
You may instead go to the supervisory authority of your own EEA country of residence or workplace, and you may also seek a remedy before the courts. You do not have to come to us first, though we would rather hear from you and put it right.
Automated processing and recommendations
Two features work automatically. The quiz and the assistant both pass the preferences you state to our recommendation service, which ranks the experiences in our catalogue against them — theme, region, price band, duration, accessibility, rating — and returns the closest matches. The assistant then describes those results in language generated by an AI model. Ranking on collection pages follows the same kind of catalogue-quality criteria and is not personalised to you.
These are suggestions about what to do on holiday. They produce no legal effect and nothing else that significantly affects you, so this is not automated decision-making within the meaning of Art. 22 GDPR. No profile is built from your behaviour over time, and nothing you do on the site changes what another visitor sees. You are entitled to know how the suggestions are produced, which is why it is set out here.
We also summarise traveller reviews automatically, which concerns the reviewers rather than you as a visitor; it is described under Information that does not come from you. Art. 22 GDPR does not apply to it either.
Children
LivingLocal is not directed at children. Our Terms and Conditions require users to be at least 18. Under Italian law, consent for an information-society service can only be given directly from the age of 14. We do not knowingly process personal data about children; if you believe a child has provided data to us, write to privacy@instal.com and we will delete it.
One clarification, since the quiz asks about it: the age bands you can select for children travelling with you are a filter for suitable experiences. They tell us nothing about an identifiable child, and we do not store them.
How we protect your data
We take appropriate technical and organisational measures under Art. 32 GDPR. The most effective one is structural: we collect almost nothing. There are no accounts and therefore no passwords to leak, no payment data, and no visitor data in our database — the site only ever reads from it, and never writes anything about you.
- All traffic is encrypted in transit with HTTPS (TLS).
- Access to production systems is restricted to authorised personnel and authenticated per service.
- Our application logs are deliberately minimal and record no IP address, user agent or request identifier. The only place our code handles your IP address is the rate limits in section 9, where it is a counter key that expires in about two minutes.
- Every provider we depend on is named above, one by one, with the hosts it is contacted at — so you can check them for yourself.
Cookies and similar technologies
The Cookie Policy lists every cookie and comparable technology this site can place on or read from your device, with its provider, purpose and duration, and explains the consent mechanism in detail. You can change your mind at any time with .
Changes to this policy
We update this page when what we do changes, and re-date it at the top. This version was published on 12 August 2026.
Separately from the text of the notice, the consent configuration — the categories and the tools inside them that you are asked about — carries its own version number, currently version 2, in force since 12 August 2026. If we add or change one of those tools we raise that number, your stored choice stops being valid, and we ask you again with every optional category switched off, rather than assuming your old answer still applies. Correcting or clarifying the wording here does not re-open a choice you already made.
Contact us
For anything to do with your personal data — a question, a request, a complaint about how we handled one:
- Email: privacy@instal.com
- Data Protection Officer: dpo@instal.it
- Post: Instal S.r.l., Via del Tiratoio 1, 50124 Firenze, Italy
For anything else — a copyright takedown, a question about the Terms, or general enquiries — see the contact list in our Terms and Conditions.