Last updated: 27 June 2026
This policy describes how the personal data of users interacting with the website palermolocker.com and with the Palermo Locker automated luggage storage service is processed, in accordance with Regulation (EU) 2016/679 (“GDPR”).
1. Data Controller
The Data Controller is Michele Giglio S.n.c., registered office at Piazza Mordini 3, Palermo, VAT no. 03345900827, operating the automated luggage storage business at Via Simone Corleo 24, 90139 Palermo (PA), Italy.
Contact: email info@palermolocker.com.
2. Categories of data collected
- Booking and payment data: name, email address, booking details (locker size, date and time of deposit), payment-related data.
- WhatsApp contact data: phone number, WhatsApp profile name/identifier, message content, date and time of contact.
- Browsing and cookie data: IP address, browser type, usage data collected via cookies (see Cookie Policy).
- Communication data: content of emails or messages sent for support requests.
3. Purposes, legal bases and retention
3.1 Service booking and payment
Purpose: managing the booking, providing the storage service, issuing tax documents, sending the locker access code.
Legal basis: performance of a contract (Art. 6.1.b GDPR) and compliance with legal/tax obligations (Art. 6.1.c GDPR).
Retention: for the duration of the service and, for tax data, for the legal term (10 years).
3.2 Payments via Stripe
Online payments are processed by Stripe Payments Europe, Ltd. Card data is handled directly by Stripe under its own privacy policy. Palermo Locker does not store full payment card details.
Legal basis: performance of the contract (Art. 6.1.b GDPR).
Place of processing: Ireland / EU, with possible non-EU transfers under Stripe’s safeguards (stripe.com/privacy).
3.3 Contact and access via WhatsApp (walk-in customers)
To allow access to the unattended luggage storage premises, customers arriving without a reservation may start a conversation via WhatsApp by scanning the QR code displayed in the window. By sending the message, the customer automatically shares their phone number and receives the premises door access code in reply.
Purpose: providing the access code; ensuring the security of unattended premises by identifying those who access it; customer support.
Legal basis: performance of pre-contractual measures and of the requested service (Art. 6.1.b GDPR) and the Controller’s legitimate interest in the security of the unattended premises and the prevention of misuse (Art. 6.1.f GDPR).
Retention: for as long as necessary to manage the service and for security purposes, and in any case no longer than 12 months from the last contact, unless otherwise required by law.
Place of processing: the service is provided by WhatsApp Ireland Limited / Meta Platforms Ireland Limited, with possible transfers to third countries under WhatsApp’s privacy policy safeguards.
3.4 Security of the unattended premises
As the premises are automated and unattended, the Controller processes access data (phone number, entry time, booking details) for security, asset protection and the prevention of improper or unlawful use of the service.
Legal basis: legitimate interest of the Controller (Art. 6.1.f GDPR) and any public-security obligations.
3.5 Video surveillance
The premises are equipped with a video surveillance system, signposted by the appropriate information notices displayed before the monitored area, in accordance with the decision of the Italian Data Protection Authority and EDPB Guidelines 3/2019.
Purpose: protection of assets and the security of persons and property on automated, unattended premises; prevention and detection of unlawful acts.
Legal basis: legitimate interest of the Controller (Art. 6.1.f GDPR).
Retention: recorded images are kept for a maximum period of 7 days, after which they are automatically deleted, unless specifically requested by the Judicial or Public Security Authority within ongoing proceedings.
Scope of recording: the cameras capture only the areas necessary for the stated purposes (access zone and locker area) and are not directed at unrelated areas or irrelevant public spaces.
3.6 Cookies and statistics
The website uses technical cookies and, subject to consent, analytics and third-party cookies. Details are provided in the Cookie Policy, accessible from the consent banner and the site footer.
Legal basis: user consent for non-technical cookies (Art. 6.1.a GDPR).
4. Disclosure of data
Data may be disclosed to third parties acting as data processors or independent controllers, including: the locker management platform provider (Smart Locker / PickItUP), the payment service provider (Stripe), the messaging service provider (WhatsApp / Meta), the hosting provider (Hostinger) and, where required, the competent authorities. Data is not disclosed or sold to third parties for marketing purposes.
5. Non-EU data transfers
Some providers may process data outside the European Economic Area. In such cases, transfers take place on the basis of adequate safeguards (EU Standard Contractual Clauses or adequacy decisions).
6. Data subject rights
The data subject may exercise at any time the rights under Articles 15-22 GDPR: access, rectification, erasure, restriction, objection, data portability, and withdrawal of consent. A complaint may be lodged with the Italian Data Protection Authority (www.garanteprivacy.it). Requests should be sent to info@palermolocker.com.
7. Changes to this policy
The Controller may update this policy. The current version is always published on palermolocker.com with the date of the latest update.
