Skip to content

Legal and compliance

Who to write to

Orders and support
[email protected]
Privacy and data rights
[email protected]
Data protection officer
[email protected]

Document 3 of 4

Cookies and tracking tools

Before you make a choice, nothing is set on this site beyond what is strictly necessary to make it work. No third-party measurement, no advertising pixels, no fonts loaded from an external domain, no embedded video, no chat widget.

The document that governs this

"Linee guida cookie e altri strumenti di tracciamento", decision no. 231 of 10 June 2021 (doc. web 9677876), published 9 July 2021 and binding since 10 January 2022. Everything below is its application.

1. The rules we apply

The subject is governed by Art. 5(3) of Directive 2002/58/EC (ePrivacy), by art. 122 of the Italian Privacy Code (Legislative Decree 196/2003), by Arts. 4(11), 6, 7 and 25 GDPR and, for Italy, by the guidelines cited above.

The underlying rule is simple: technical cookies may be set without consent; everything else requires consent that is freely given, specific, informed and unambiguous, expressed through a positive action. Silence, continued browsing and pre-ticked boxes are not consent.

The same rules apply to tracking tools other than cookies: pixels, web beacons, fingerprinting, identifiers held in local storage. The name of the technology does not change the obligation.

2. The three categories

Technical and strictly necessary cookies
They deliver the service you asked for: keeping the session, remembering the language, protecting forms, storing your cookie choice. They require no consent under art. 122 of the Italian Privacy Code and cannot be turned off without breaking the site.
Analytics cookies
They measure use of the site. They can be treated as technical cookies, and therefore used without consent, only if all four conditions in clause 4 are met. Otherwise they need consent like any other tracking tool.
Profiling and marketing cookies
They build profiles and serve personalised advertising, including on other sites. They always require consent, they are pre-set to "denied", and we use none of them today.

3. What is set before consent

Only the technical cookies listed in clause 5. In particular, before you have chosen, no connection is made to any third-party domain for measurement or advertising. These are architectural commitments, not editorial promises:

  • fonts are served from our own servers: no request to fonts.gstatic.com, which would be both a third-party connection and a transfer to the United States;
  • no video embedded from external platforms on public pages;
  • no chat, review or social-network widget loaded automatically;
  • consent state is stored in a cookie readable server-side, not in local storage, because otherwise the initial HTML would be generated without knowing what you chose;
  • third-party scripts, if there ever are any, load only inside a consent-gated component, never in the application layout.

The Stripe cookies listed in the table are set only on payment pages, where they are strictly necessary for fraud prevention, and not on the site's informational pages.

4. Analytics without consent: the four conditions

The Garante allows measurement tools to be treated as technical cookies, and therefore used without consent, only where all of the following hold.

  1. 1The IP address is masked: at least the fourth octet of an IPv4 address, or the equivalent for IPv6. The guidelines note this leaves roughly 0.4% uncertainty.
  2. 2Measurement is first-party: a single site or app, or several domains belonging to the same controller or group.
  3. 3The third party providing the tool does not combine the minimised data with its own customer files or with statistics gathered on other sites.
  4. 4The output is aggregate statistics and does not feed individual commercial decisions.

So we use an analytics stack hosted in the EU or on our own servers, cookieless and without persistent identifiers, configured with IP anonymisation. The practical consequence is that our statistics also cover people who reject everything, which makes them more reliable rather than less.

We do not use Google Analytics. In decision no. 224 of 9 June 2022 concerning Caffeina Media S.r.l. (doc. web 9782890), the Garante reprimanded the controller for transferring visitors' personal data to Google LLC in the United States without adequate safeguards and ordered it to bring processing into line within 90 days, failing which the flows would be suspended.

5. The cookies this site sets

None of these cookies profiles you. All are first-party, including the two Stripe cookies, which are set on our own domain and appear only during payment; the one exception is "m", the site's only third-party cookie, set by the m.stripe.com domain and likewise only during payment.

NameSet byPurposeDurationCategory
vincode_consentvincode (first party)Records your choice by category, the date and time you made it, the version of this notice, the version of the consent tool and the consent identifier6 monthsTechnical
NEXT_LOCALEvincode (first party)Remembers the language you selected, so automatic detection is not repeated. It has no expiry: it is discarded when you close the browser. It is set only on the redirect from the site root or when you switch language, not when you open an address that already carries the language prefixSessionTechnical
authjs.csrf-tokenvincode (first party)Protects the sign-in forms against forged cross-site requests. Set by the authentication routes, not readable from JavaScriptSessionTechnical
authjs.callback-urlvincode (first party)Keeps the address to return you to once sign-in completes. Set by the authentication routes, not readable from JavaScriptSessionTechnical
authjs.session-tokenvincode (first party)Maintains the session of a customer signed in to their account. Present only after authentication, not readable from JavaScript30 daysTechnical
__stripe_midStripe (first party)Payment fraud prevention. Set on our own domain, and only on payment pages12 monthsTechnical

We use no profiling cookies. If we ever introduce any, this table will be updated before they are activated, the change will count as a material change in the conditions of processing, and you will be asked for fresh consent.

7. How to change your choices

At the foot of every page there is a permanent link that reopens the preferences panel and shows your current consent state. You can change or withdraw it at any time, as easily as you gave it.

You can also manage cookies from your browser settings, which under privacy and security let you block or delete them, in bulk or per site.

One practical consequence: blocking technical cookies makes it impossible to complete a purchase, because the session and payment state cannot be maintained. That is not a limitation we can engineer around.

8. How this fits with the other documents

This page describes tracking tools and their duration. The personal-data processing that follows from them, your rights and the retention periods are set out in the privacy notice.

Processing of the data held in the vehicle database is covered by a further, separate notice, required by Art. 14 GDPR because that data is not collected from the data subject. Three distinct documents is what Italian practice expects, and merging them would make each one less readable.

9. Contact and updates

For any question about this page, write to [email protected].

Every version of this notice is numbered and dated. A change in the list of cookies, in their duration, or the arrival of a new supplier means the table is updated and, where consent is required, asked for again.

The other documents

None of the four stands on its own. Withdrawal lives in the refunds page, retention periods in the privacy notice, and the data-completeness clause in the terms.