Last updated: 22 July 2026
Privacy Policy
This page describes how the personal data of users who browse and use camminodihasekura.it is processed, including the purchase of the pilgrim credential, the request for the certificate of completion and the contact forms. Data is processed in accordance with Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 (Privacy Code) as amended by Legislative Decree 101/2018.
Types of Data Collected
Among the personal data collected by this website, either independently or through third parties:
- —Trackers and usage data (collected automatically while browsing)
- —Contact forms: first and last name, email address, phone number and the content of the enquiry
- —User account: email address, login credentials and order history for users who create a profile in the members’ area
- —Credential purchase: first and last name, email, phone number, billing address, shipping address (printed credential only), payment information, order ID
- —Pilgrim credential: the pilgrim’s name associated with the unique, personal credential code
- —Certificate request: name, credential code and an image (photo or scan) of the stamped credential uploaded by the user
- —Statistics: number of users, session statistics
Data marked as mandatory is necessary in order to provide the requested service. Failure to provide it makes it impossible to complete the purchase, submit the enquiry or issue the certificate. Users are responsible for any third-party personal data they communicate through this website.
Method and Place of Processing
Method: The Controller adopts appropriate security measures to prevent unauthorised access, disclosure, modification or destruction of data. Processing is carried out using IT and telematic tools. In addition to the Controller, data may be accessed by internal parties (administrative and technical staff, volunteers responsible for verifying completed routes) or external parties (couriers and postal services, payment providers, technical providers and hosting providers) appointed as Data Processors where necessary.
Place: Data is processed at the Controller’s operating offices and in any other place where the parties involved are located. Some transfers may take place to third countries (e.g. Google servers) in compliance with the safeguards laid down by the GDPR.
Retention period: Order data is retained for 10 years to meet tax obligations (art. 2220 of the Italian Civil Code). Identifying data linked to the credential is retained for as long as necessary to verify the route and issue the certificate. Images of the stamped credential are deleted once verification is complete. Contact form data is retained for as long as necessary to respond to the enquiry. Analytics data collected through Google Analytics 4 is deleted after 14 months.
Purposes of Processing
- —Platform and hosting services — running the website and the online shop through WooCommerce
- —Order and payment management — issuing and shipping the credential, together with related tax and legal obligations
- —User account management — access to the members’ area and consultation of the order history
- —Issuing the certificate — verification of the stamped stages and issuing of the certificate of completion
- —Handling enquiries — responding to requests submitted through the forms on the website
- —Statistics — traffic analysis through Google Analytics 4 (with IP anonymisation)
- —Spam protection — anti-abuse filters on the website forms
- —Protection of the Controller’s rights — prevention of fraudulent activity and legal defence where necessary
Pilgrim Credential and Certificate
The credential is personal, numbered and issued in the pilgrim’s name: each credential carries a unique code linked to that name. This link is necessary in order to guarantee the authenticity of the document and to award the certificate only to those who have actually walked the route.
To request the certificate, users upload an image of the stamped credential. The image is used solely to verify the stages completed and is neither published nor disseminated. If the image contains information that is not required for verification, users are advised to obscure it before uploading.
The Controller may keep a register of completed routes containing the pilgrim’s name and credential code, in order to allow subsequent checks and to reissue the certificate at the request of the data subject.
Donations and Bank Transfers
Donations supporting the restoration works and any shipping surcharges are paid by direct bank transfer to the account indicated on the website. These transactions take place outside this website: the related data is processed by the banks involved and by the account holder, according to their respective privacy notices.
Third Parties Involved
- —Google Ireland Limited (Google Analytics 4) — Ireland — Privacy Policy — Opt-out
- —[PAYMENT PROVIDER] — online payment processing — Privacy Policy
- —Couriers and postal services — process the recipient’s name, address and contact details in order to deliver the printed credential
- —Hosting provider — storage of data on the servers hosting the website
Legal Basis of Processing (EU)
The Controller processes personal data where one of the following conditions applies:
- —The user has given consent for one or more specific purposes
- —Processing is necessary for the performance of a contract with the user or for pre-contractual measures
- —Processing is necessary for compliance with a legal obligation
- —Processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party
User Rights (GDPR)
Within the limits set by law, users have the right to:
- —Withdraw consent at any time, without affecting processing already carried out
- —Object to processing, in particular for direct marketing purposes (free of charge and without giving reasons)
- —Access their data and obtain a copy of it
- —Rectify inaccurate or incomplete data
- —Restrict processing in certain circumstances
- —Erase their data (right to be forgotten), subject to legal obligations
- —Data portability in a machine-readable format to another controller
- —Lodge a complaint with the Italian Data Protection Authority
Requests may be submitted using the details provided in the Contact section of the website. The Controller will reply within 30 days.
This website uses trackers. A tracker is any technology — e.g. cookies, unique identifiers, web beacons, embedded scripts, e-tags, fingerprinting — that allows users to be tracked by collecting or storing information on their device.
Technical cookies — necessary for the operation of the website, the shopping cart and the members’ area (WooCommerce), for storing the selected language and consent preferences. They do not require consent.
Analytics cookies — Google Analytics 4, with IP anonymisation. Used for statistical traffic analysis. They require prior consent.
You can manage or withdraw your cookie consent at any time through the banner on the website or through your browser settings.
System Logs and Maintenance
For operation and maintenance purposes, this website and any third-party services it uses may collect system logs, i.e. files that record interactions and which may contain personal data such as the user’s IP address.
Legal Defence and Legal Obligations
Users’ personal data may be used by the Controller in court or in the preparatory stages of legal action, to defend against misuse of this website or the related services. Users acknowledge that the Controller may be required to disclose data by order of public authorities.
Definitions and Legal References
- —Personal Data: any information that, directly or indirectly, makes a natural person identified or identifiable.
- —Usage Data: information collected automatically (IP address, browser, OS, pages visited, session duration, etc.).
- —User / Data Subject: the natural person using this website.
- —Data Controller: the party that determines the purposes and means of processing the personal data collected through this website.
- —Data Processor: a third party that processes data on behalf of the Controller.
- —Cookie: a small piece of data stored in the user’s browser.
- —Tracker: any technology (cookies, web beacons, fingerprinting, etc.) that allows users to be tracked.
- —European Union (EU): any reference to the EU includes all current member states of the EU and the European Economic Area.
Changes to this Privacy Policy
The Controller reserves the right to make changes at any time, notifying them on this page and updating the date shown. Where changes concern processing based on consent, new consent will be requested if necessary.
This notice is provided pursuant to art. 13 of Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018. In the event of any discrepancy between the language versions of this notice, the Italian text shall prevail.

