Last updated: September 28, 2026.
This Privacy Policy explains how My Rome Trip processes personal data when you visit myrometrip.com, contact us, interact with website features, follow affiliate links or use services made available through the website. It is intended to provide the information required by the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the Italian Personal Data Protection Code (Legislative Decree 196/2003, as amended), and the rules applicable to cookies and similar technologies, including Article 122 of the Italian Privacy Code.
This policy should be read together with the Cookie Policy. Some processing depends on the features active on the page you visit and on choices you make through any consent controls made available on the website.
1. Data Controller and privacy contact
The Data Controller is the person or entity responsible for operating My Rome Trip. Privacy requests and questions about the processing described in this policy can be sent to admin@myrometrip.com.
If additional identifying or business information concerning the Data Controller is legally required for a particular request, it can be requested using the contact address above. No Data Protection Officer is indicated on the website unless one is formally appointed and communicated.
2. Scope of this Privacy Policy
This policy applies to personal data processed through My Rome Trip and to data generated by the technical operation and security of the website. It does not govern independent websites, booking platforms, social networks or other third-party services reached through external links. Those third parties process personal data under their own notices and terms.
3. Categories of personal data we may process
- Browsing and connection data: IP address, date and time of requests, requested URL, response status, browser and device information, operating system, language settings, referring page, approximate technical location derived from an IP address where a service uses it, and server or security log information.
- Contact data: name, email address and any information you voluntarily include when contacting us.
- Comment data: where comments are enabled, information entered in the comment form, IP address, browser user-agent information and moderation or anti-spam data.
- Subscription or interaction data: information provided if a Jetpack/WordPress subscription, follow, contact or similar feature is enabled and you choose to use it.
- Usage and statistical data: page views, general referral information, interactions, aggregated measurements and pseudonymous identifiers where analytics or performance functions are active.
- Cookie and similar technology data: identifiers and preferences used for technical functions, security, consent management, statistics or other purposes described in the Cookie Policy.
- Affiliate interaction data: an outbound affiliate link may include a partner or campaign identifier. When you click it, the destination provider may receive information such as the referring URL, device/browser data and the affiliate identifier.
Please do not send special-category or highly sensitive personal data unless it is genuinely necessary for a specific request. My Rome Trip does not ask visitors to provide health data, biometric data, political opinions, religious beliefs or similar sensitive information for ordinary use of the website.
4. How personal data is collected
- Directly from you when you send an email, submit information through an enabled form, subscribe to an available service or post a comment.
- Automatically when your browser communicates with the web server or with enabled website services.
- From service providers where a website feature, anti-spam service, security tool, hosting service or analytics function processes data on behalf of or in connection with My Rome Trip.
- From third-party destinations only to the extent a partner provides lawful reporting or aggregate affiliate performance information.
5. Purposes and legal bases for processing
| Purpose | Typical data | Legal basis under the GDPR |
|---|---|---|
| Provide and technically operate the website | Connection, server and device data | Legitimate interests in providing a secure and functional website; where strictly necessary, processing required to deliver a service requested by the user |
| Website security, fraud and abuse prevention, troubleshooting | IP address, logs, user-agent and security events | Legitimate interests in protecting the website, users and systems; legal obligations where applicable |
| Respond to messages and requests | Name, email address and message content | Steps taken at the user’s request, legitimate interests in correspondence, and legal obligations where applicable |
| Comment moderation and anti-spam protection | Comment content, IP address, email, user-agent | Legitimate interests in preventing abuse and maintaining the website; consent where legally required for a specific optional technology |
| Audience measurement and statistics | Usage, page-view and technical data | Consent where required for non-essential tracking; in limited cases, legitimate interests or the technical-cookie exemption only where the applicable legal conditions for privacy-preserving analytics are satisfied |
| Remember consent or necessary preferences | Preference or consent identifiers | Compliance with legal obligations and legitimate interests in documenting and respecting privacy choices |
| Affiliate attribution and commercial links | Affiliate identifiers and outbound click information | Legitimate interests for ordinary non-intrusive affiliate attribution; consent where a non-essential tracking technology is stored or accessed on the user’s device |
| Establish, exercise or defend legal claims | Relevant correspondence, logs and records | Legitimate interests and compliance with legal obligations |
Where processing relies on consent, you may withdraw consent at any time without affecting processing that was lawful before withdrawal. Where processing relies on legitimate interests, My Rome Trip considers the necessity of the processing and the impact on visitors’ rights and freedoms.
6. Server logs, hosting and website security
The hosting environment and web server may automatically record technical information needed to deliver pages, maintain availability, investigate errors and protect the website against malicious activity. These logs may include IP addresses, request times, requested resources, browser details and security events. Such data is generally retained only for the period reasonably necessary for operational, security, troubleshooting and legal purposes.
7. WordPress, Jetpack and Automattic services
My Rome Trip is built with WordPress and the database indicates that Jetpack is active. Jetpack features can process visitor information differently depending on which modules are enabled. This may include security, performance, traffic statistics, subscriptions, comments, content delivery or other WordPress-connected functions.
Jetpack is provided by Automattic. Depending on the feature, Automattic may process IP addresses, user-agent information, page views, referral information, account or subscription information, security events and other technical data. For details about processing of visitors to Jetpack-connected sites, see the Automattic Privacy Notice for Visitors to Users’ Sites and the Jetpack Privacy Center.
8. Comments, Akismet and Gravatar
If comments are enabled, WordPress may collect the data shown in the comment form together with the visitor’s IP address and browser user-agent information to support moderation and spam detection. Comments approved for publication may remain publicly visible with the display name and any other information the commenter chooses to publish.
The website database indicates that Akismet is active. Akismet, an Automattic service, may process commenter information needed to detect and block spam. More information is available in the Akismet Privacy Policy.
If Gravatar functionality is used, a value derived from an email address may be sent to Gravatar to determine whether a profile image exists. If a comment is approved, the associated profile image may be visible publicly next to the comment, depending on the site configuration.
9. Affiliate links and Booking.com
My Rome Trip contains affiliate links, including links to Booking.com. Affiliate links can contain an identifier that allows a partner to attribute a visit, booking or purchase to My Rome Trip. Clicking an affiliate link takes you to a third-party website. From that point, the third party determines its own processing of personal data, cookies, account information, searches, reservations and payments.
My Rome Trip does not receive the full payment-card or reservation data that you provide directly to a booking platform merely because you used an affiliate link. We may receive aggregate or transaction-related affiliate reporting needed to calculate commissions. Booking.com’s own privacy information is available in its Privacy Notice.
10. Cookies and similar technologies
Cookies, local storage, pixels and comparable technologies may be used for strictly necessary functions, security, preferences, statistics or other purposes. Non-essential tracking technologies are subject to the consent rules applicable under Article 122 of the Italian Privacy Code and the GDPR. For categories, purposes, consent rules and third-party information, see the Cookie Policy.
11. Embedded and externally hosted content
If an article includes externally hosted maps, videos, social media content, booking widgets or similar embeds, the external provider may receive technical information when the content is loaded and may use cookies or comparable technologies. Where such processing is not strictly necessary and requires consent, the content should be blocked until the required choice has been made. The provider’s own privacy notice applies to its independent processing.
12. Recipients and categories of service providers
Personal data may be accessible, only where necessary, to hosting and infrastructure providers, security and anti-spam services, website administration and technical support providers, analytics or performance providers where enabled, email or communication providers, professional advisers and public authorities where disclosure is required by law. Affiliate and booking providers receive data independently when you choose to visit or use their services.
Where a provider acts as a processor on behalf of My Rome Trip, processing should be governed by the contractual safeguards required by Article 28 GDPR where applicable. Some providers may instead act as independent controllers for specific activities.
13. International data transfers
Some service providers may process data outside the European Economic Area. Where the GDPR applies, transfers must rely on a valid transfer mechanism, such as an adequacy decision, the EU-U.S. Data Privacy Framework where applicable to a certified recipient, Standard Contractual Clauses, another safeguard under Chapter V GDPR, or a permitted derogation in the limited situations allowed by law. Additional technical or contractual measures may be used where required.
14. Data retention
Personal data is not intended to be kept longer than necessary for the purpose for which it was collected, taking account of security needs, legal obligations, limitation periods and the need to establish or defend legal claims. Retention may therefore differ by category:
- Server and security logs: for a limited operational or security period, subject to hosting and security requirements.
- Ordinary correspondence: for the time needed to respond and, where appropriate, for a reasonable follow-up or legal-record period.
- Comments: published comments and related moderation information may remain while the relevant content remains online, unless removal is appropriate or legally required.
- Consent records: for as long as reasonably necessary to demonstrate and respect the user’s privacy choices and comply with accountability obligations.
- Backups: deleted data may persist temporarily in protected backup copies until ordinary backup rotation or deletion occurs.
- Third-party services: providers apply their own retention periods to data they process independently or on behalf of the website.
15. Data security
Reasonable technical and organisational measures are used to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures can include access controls, software updates, anti-spam and security tools, backups and transport encryption where supported. No internet transmission or storage system can be guaranteed to be completely secure.
If a personal-data breach occurs, My Rome Trip will assess the incident and make any notification to the competent supervisory authority or affected individuals required by Articles 33 and 34 GDPR.
16. Whether providing data is mandatory
You can generally browse published content without directly identifying yourself to My Rome Trip. Providing an email address or other information is voluntary when contacting us, but information marked or objectively required for a request must be provided if you want us to respond or deliver the relevant feature. Strictly necessary technical data is generated automatically as part of normal internet communication.
17. Automated decision-making and profiling
My Rome Trip does not use visitor data to make decisions based solely on automated processing that produce legal effects or similarly significant effects within the meaning of Article 22 GDPR. Third-party platforms reached through external links may conduct their own profiling or automated processing under their own policies.
18. Your rights under the GDPR
Where the GDPR applies, and subject to the conditions and exceptions provided by law, you may have the right to:
- obtain confirmation as to whether personal data concerning you is being processed and request access to that data;
- request rectification of inaccurate data and completion of incomplete data;
- request erasure where the conditions of Article 17 GDPR are met;
- request restriction of processing under Article 18 GDPR;
- receive eligible data in a structured, commonly used and machine-readable format and request data portability under Article 20 GDPR;
- object to processing based on legitimate interests under Article 21 GDPR;
- withdraw consent at any time where processing relies on consent, without affecting prior lawful processing;
- not be subject, where applicable, to a qualifying decision based solely on automated processing under Article 22 GDPR;
- lodge a complaint with a supervisory authority.
In Italy, the supervisory authority is the Garante per la protezione dei dati personali. You may also contact the supervisory authority competent for your habitual residence, place of work or the place of an alleged infringement where the GDPR permits.
19. How to exercise your privacy rights
Send your request to admin@myrometrip.com and describe the right you wish to exercise. We may request information reasonably necessary to verify identity before disclosing, changing or deleting personal data. Requests will be handled within the time limits required by applicable law.
20. Children’s privacy
My Rome Trip is a general-audience travel information website and is not designed to intentionally collect personal data from children through registration or targeted services. If a parent or guardian believes that a child has provided personal data inappropriately, they can contact us so that the situation can be reviewed and appropriate action taken.
21. External websites and third-party controllers
Articles may link to museums, attractions, transport operators, accommodation providers, booking platforms, public authorities and other external websites. My Rome Trip is not responsible for the privacy practices of those independent services. Review the destination website’s privacy and cookie information before submitting personal data or making a booking.
22. Consent management and optional technologies
My Rome Trip provides a first-party consent management interface for optional statistics, advertising/affiliate measurement and external-content technologies. Optional categories are disabled by default. The consent choice is stored for up to 180 days in the strictly necessary first-party cookie mrt_cmp_consent_v1 and can be changed at any time through Privacy choices in the footer. The Cookie Policy contains more detailed information about categories and controls.
23. Changes to this Privacy Policy
This policy may be revised when website features, service providers, legal requirements or processing activities change. Material changes should be reflected in the policy and, where required, communicated through an appropriate notice or renewed consent mechanism.
Last updated: September 28, 2026.
