Legal
Privacy Policy
Last updated · 3 May 2026
Exclusive Tuscany is operated from Florence by its founders. This policy explains, in plain language, what personal information we collect when you use this website and what we do with it.
Who controls your data
Exclusive Tuscany, Via dei Servi 12, 50122 Firenze, Italia. The data controller for the purposes of UK GDPR and EU GDPR is the founders at that address. You can reach us at hello@exclusivetuscany.com.
What we collect, and why
When you submit the enquiry form, we ask for your name, email address, party size, approximate dates, and any context you choose to add. We use this only to answer your enquiry — usually within a working day, by email or, if you prefer, by phone. We do not add you to a marketing list. There is no marketing list.
For abuse prevention, our enquiry endpoint records a one-way hash of your IP address for a rolling one-hour window so we can rate-limit automated submissions. This hash is not linked to your identity and is discarded after the window ends.
Where your data lives
Our enquiry messages are delivered via Resend, a transactional email provider with EU-region processing. Rate-limit hashes are stored in Upstash, also EU-region. The site itself runs on Vercel. Editorial content is held in Sanity. Each is a recognised sub-processor and we have data-processing agreements with them. We do not sell, rent or share your data with anyone outside that list.
Cookies and analytics
We use Google Analytics to understand how visitors find us — which pages they read, which villas they look at, which sub-region notes they spend time on. That requires a small analytics cookie on your device. We do not use advertising cookies, retargeting pixels, or third-party trackers of any kind. IP addresses are anonymised before they reach Google.
If you visit from the UK, the EU, the EEA, or Switzerland, we show a consent banner on your first visit and only load Google Analytics after you click Accept. Your choice — accepted or declined — is remembered for one year via a small first-party cookie. To revisit the banner, clear the et-cookie-consent cookie in your browser settings.
Visitors from outside those jurisdictions do not see a banner — no opt-in regime applies — and Google Analytics loads on first visit. Vercel Analytics also runs in the background; it is privacy-respecting (no cookies, no personal identifiers) and is not gated by consent.
The Sanity Studio at /studio uses functional cookies that authenticate editors; visitors who are not signed in never encounter them.
How long we keep things
Enquiry correspondence is retained for as long as it is useful for the conversation it began — typically the duration of the trip and a year afterwards in case you return — and then deleted. You can ask us to delete it sooner.
Your rights
Under UK GDPR and EU GDPR you have the right to access, correct, port or erase the personal data we hold about you, to object to or restrict our processing of it, and to lodge a complaint with a supervisory authority (the ICO in the UK, the Garante in Italy). To exercise any of these rights, write to hello@exclusivetuscany.com. We will reply within thirty days.
Children
This site is intended for adults. We do not knowingly collect personal data from anyone under sixteen.
Updates
If we change anything material we update the date at the top of this page and, where appropriate, write to existing correspondents.
This policy is provided in good faith but is not legal advice. If you need a definitive ruling on your circumstances, please consult a qualified lawyer.