Cookies Policy

Version 1.1 - Last updated: June 27, 2026

Transparency Note

This Policy applies to the website, reservation pages, mobile app, and the Local Way web-app (collectively, the 'Platform'). It integrates the general Privacy Policy. Operational details regarding active tracking methods are always available via the 'Manage cookie preferences' utility module integrated into the Platform banner configuration.

Data Controller

Data Controller: Local Way S.r.l.
Registered Office: Via Libero Attardi 85, 92020 Santo Stefano Quisquina (AG), Italy
VAT / Tax Code: 03109950844
REA: AG-227566
Share Capital: Euro 13,333.00 i.v.
Privacy Contacts: [email protected] (Subject: Privacy) - PEC: [email protected]

1. What are cookies and similar technologies

Cookies are small string files written onto user infrastructure endpoints via active browsers or web-applications. Equivalent digital instruments embrace native local storage repositories, embedded mobile software development toolkits (SDKs), pixel tracking flags, clear web tags, distinct terminal properties, or any device storage access routine. They fall into first-party identifiers managed directly by Local Way structural architectures, or third-party mechanisms operated by external data processing partners.

2. Categories, purposes and legal bases

CategoryMain PurposesLegal Basis / Consent
Technical & strictly necessarySecured authenticated access routing, system session tokens, infrastructural protection mechanisms, platform fraud detection patterns, preference retention logs, persistent checkout processes, and operational itinerary reservation flows.Technical execution necessity supporting requested service delivery or legitimate platform architectural security configurations. User consent mechanisms are not legally mandated, although public informational summaries remain strictly mandatory.
PreferencesSaving auxiliary optional layout selections including structural platform language parameters, regional location tags, or target viewport presentation variables.Explicit visitor authorization tokens, given that these components do not dictate foundational platform system functionality.
AnalyticalInfrastructural analysis metrics, execution speed reports, application error diagnostic reviews, and continuous Platform performance optimization.Granular programmatic consent, except under architectures engineered to map direct equivalent structural parameters of standard technical elements inside current regional statutes.
Marketing / ProfilingDynamic campaign measurement, demographic interest cluster profiling, delivering contextually tailored advertising layouts, and limiting duplicate advertisement iteration counts.Freely allocated, contextually explicit, comprehensively documented consent workflows, subject to total revocation routines instantly.

3. Consent management

Whenever auxiliary non-essential tracking modules are present, initial landing visits reveal an interface enabling visitors to: (a) instantly accept all underlying optional classes; (b) reject them altogether; (c) establish modular granular parameters; or (d) exit out of the workflow module entirely while leaving only foundational technical features functional. Declining optional properties imposes zero processing penalties across basic visual browsing or primary operational services. Individual operational preferences are modifiable or subject to total cancellation at any point via the 'Manage cookie preferences' layout link inside our base footers or within native system menu hubs. Retrospective withdrawal actions do not invalidate data tasks executed prior to modifications.

4. Registry of active technologies

Our modular preference utility updates a live historical log tracking real-time components: unique identifier tags, writing parties, category tags, explicit target scopes, active retention horizons, and direct links pointing to specific privacy notices for third-party scripts. This dynamic directory is fully integrated with this Policy and overrides text summaries during core architectural upgrades.

Important notice: Local Way strictly prevents any pre-activation of optional diagnostic components or marketing scripts until an explicit affirmative selection is registered from the user.

5. Third-party cookies, payments and transfers

Distinct workflows utilize specialized secondary infrastructure suppliers handling base application hosting setups, threat security layers, consent processing tasks, single sign-on services, or transactional pipelines. Payment forms process checkout items directly through licensed providers like Stripe; these suppliers enforce separate documentation frameworks and embed strict technical properties necessary for payment execution. Where data objects transit beyond European Economic Area borders, Local Way and its respective third-party partners execute the standard validation guarantees mandated under the general GDPR framework, as expanded within the general Privacy Policy.

6. Duration

Transient session instances vanish immediately when browser programs close or terminal connections disconnect. Permanent elements remain intact matching the timeline configurations defined inside the live registry dashboard, or until manual user cache deletion routines clear them. Consent tracking metrics apply proportional lifecycle rules and prompt structural renewals when major tracking modifications launch.

7. Management via browser or device

Users can drop, isolate, or completely intercept tracking files through master browser software configuration panels or operating system preferences. Imposing complete blockades may degrade core operational structures, affecting profile access paths, transactional features, or custom display states. For non-essential assets, modifying parameters through our integrated 'Manage cookie preferences' application script remains the ideal deployment routine.

8. Updates and references

We regularly adapt this policy to align with statutory alterations, updated code logic, or procedural updates. Active variations remain continuously visible on our structural Platform nodes, marked with clear revision timestamps. If updates materially redefine structures that depend on user clearance, renewed authorization forms will prompt the visitor. This policy aligns with European Union Regulation 2016/679 ('GDPR'), standard Italian data privacy statutes, and the tracking mechanism regulatory frameworks issued by the Italian Data Protection Authority (Garante) on June 10, 2021.