EasyApe LogoEasyApe
EasyApe LogoEasyApe
EasyApe

The app that revolutionises the aperitivo experience, making every choice effortless.

https://easyape.it

Follow us

@easyape_officialTikTokLinkedIn

EasyApe web

Download the appFind aperitivoVenues in MilanFor venues

Legal

Privacy PolicyTerms and ConditionsCookie Policy

Download the app

Download on the App StoreGet it on Google Play

© 2026 EasyApe. Made with ❤️ in Milan.

P. IVA 14632770963

App users document

Your Privacy

Privacy notice for EasyApe app users: data processed, purposes, legal bases, retention, sharing and privacy rights.

Version
App users version - English translation prepared for web publication.
Official URL
easyape.it/privacy-policy?lang=en
ItalianoEnglish

Contents

  1. 1. Who processes the data
  2. 2. What data we process
  3. 3. Source of the data
  4. 4. How EasyApe uses personal data and for how long
  5. A) Providing the requested services
  6. B) Payment management
  7. C) Compliance with legal obligations
  8. D) Support and assistance
  9. E) Find the nearest venue
  10. F) Marketing
  11. G) App improvement
  12. H) Claims, exercise and protection of rights
  13. I) Activities connected with corporate transactions
  14. 5. Server location and transfers outside the EU
  15. 6. Who we share data with
  16. 7. Your privacy rights
  17. 8. Who you can contact
  18. 9. Changes

Hi, this is the privacy notice for the EasyApe application (the "App"), provided to help users find and book the aperitivo experience that best matches their preferences at venues in the city.

This notice is addressed to users ("Users") who use the App. It explains how we process, protect and retain personal data under Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR").

This notice is part of the Terms of Service, which also defines terms used but not defined in this document.

01

1. Who processes the data

Who is the data controller?

The data controller is the natural or legal person who determines the purposes and means of processing personal data. In practice, it is the person who collects and manages Users’ personal data and is legally responsible for it.

The data controller is CENTARO TOMMASO, VAT number 14632770963, with registered office/domicile at Viale Gorizia 9, 20144 Milan, Italy, email: info@easyape.it.

02

2. What data we process

We process the following information:

2.1 Data provided voluntarily

Identity data (first name, last name, date of birth, gender).

Contact data (email address, phone number).

Data relating to reservations and events (venue, time, party size and similar details).

Geolocation data, where enabled by the User.

Profile data, such as tastes, preferences, favorite venues, saved items and loyalty activity.

Information provided when you communicate with us, including interactions with our chatbot or AI assistant.

Review and rating information.

Payment-related information. Full payment card processing is handled by Stripe, as described below.

Some features may allow you to optionally share, with your consent, information about food preferences (for example kosher or halal foods). Such information may constitute special categories of personal data under Article 9 GDPR.

2.2 Data collected automatically

App and device usage data, such as IP address, device type, operating system type and version, browser data and MAC address where available.

Information about App anomalies, crashes and errors.

Information relating to technical support requests.

Analytics and measurement data, such as page views, app events, feature usage, download clicks, referral or campaign parameters and consent preferences. Depending on the channel and consent settings, these may be processed through tools such as Google Analytics/Firebase, PostHog and, where configured and allowed, Meta Pixel.

03

3. Source of the data

3.1 Data provided by other Users

We may receive some personal information about you from other EasyApe Users through features such as "Friends", "Groups" or "Referral".

3.2 Single Sign-On (SSO)

We may collect or receive personal information associated with your other accounts, for example Google or Apple, for App registration and login. In that case, we receive your personal data directly from those third parties without requiring you to enter additional information.

04

4. How EasyApe uses personal data and for how long

What is the legal basis for processing?

The legal basis is the condition that allows us to lawfully process personal data. For more information, you can read Article 6 of Regulation (EU) 2016/679 ("GDPR").

Which legal bases do we rely on?

There may be different legal bases that justify data processing.

Each legal basis is identified below.

Consent: processing takes place on the basis of your explicit and unambiguous expression of will.

Contract: processing is necessary to enter into or perform our contract.

Legitimate interest: processing is necessary to pursue one of our legitimate interests. For each processing activity based on this legal basis, we have assessed that your rights and interests do not override ours.

Legal obligation: processing is necessary to comply with a legal obligation to which we are subject.

05

A) Providing the requested services

We process data to perform pre-contractual and contractual obligations arising from the provision of the services, including:

registration, App login and account management;

venue browsing, reservation requests and reservation management;

sending communications and updates strictly related to reservations through push notifications and email;

participation in the "EasyApe points" loyalty program and operational management of the activities needed to let you use and receive the benefits connected with your participation in the program;

assistance through the chatbot or AI assistant regarding venues that match your tastes and preferences.

Legal basis: contract.

Retention period: until the Account is deleted and, afterwards, where strictly necessary, for the applicable limitation period under Article 2947 paragraphs 1 and 3 of the Italian Civil Code.

06

B) Payment management

We process information to manage payment of amounts ordered or due in connection with reservations.

Important: except for the encrypted credit card number or payment reference data needed to connect the payment flow, payment data entered by the User is processed exclusively and directly by the Stripe payment platform, to which the App redirects or connects during payment.

Legal basis: contract.

Retention period: for the limitation period provided by law (ten years from data provision), without prejudice to any additional retention periods required to protect our legitimate interests, such as handling complaints, reports, legal proceedings or data subject requests.

07

C) Compliance with legal obligations

We process data to comply with legal obligations and respond to requests from competent authorities.

Legal basis: legal obligation.

Retention period: for the period strictly necessary to comply with the legal obligations to which we are subject and, in any case, for a maximum period of 10 years.

08

D) Support and assistance

We process data to provide Users with proper administration and timely responses to support and assistance requests.

Legal basis: contract.

Retention period: for the time strictly necessary to handle your information request or verify your report, and in any case for no longer than 24 months.

09

E) Find the nearest venue

To allow you to identify on a map the venues closest to you and aligned with your tastes, we process personal data relating to your location only if you have consented to and enabled geolocation on your device.

Legal basis: consent.

Retention period: for the time strictly necessary to use the requested services. Location data will not be stored or used for other purposes, without prejudice to retention periods required by law or legitimate reasons. You can disable device geolocation at any time, even temporarily, through your device settings or App settings.

10

F) Marketing

With your consent, we may send promotional and commercial communications through automated tools, such as email, push notifications or SMS.

Legal basis: consent.

Retention period: until consent is withdrawn and, afterwards, for the time and to the extent necessary to comply with legal obligations or protect our rights and legitimate interests, for example handling complaints, reports, legal proceedings or data subject requests, within the applicable limitation periods. Processing carried out on the basis of consent before withdrawal remains lawful.

11

G) App improvement

We collect and retain usage data for statistical analysis connected with improving the App, performed in anonymous or aggregated form where possible.

This may include analytics events, performance data, page views, feature usage and crash or error information. On the website, analytics storage and marketing tracking depend on the cookie choices available in the cookie banner and preferences panel.

Legal basis: legitimate interest for strictly necessary, aggregate or privacy-preserving measurement; consent where required for analytics or marketing cookies and similar tracking technologies.

12

H) Claims, exercise and protection of rights

We may process your data to manage complaints and to exercise or protect our rights.

Legal basis: legitimate interest.

Retention period: for the time strictly necessary to allow us to defend our rights and legitimate interests in judicial and out-of-court contexts and, in any case, for the maximum applicable limitation period under Article 2947 paragraphs 1 and 3 of the Italian Civil Code.

13

I) Activities connected with corporate transactions

We may need to process your personal data to carry out extraordinary transactions such as mergers, acquisitions, demergers, transfers of business units and similar operations.

Legal basis: legitimate interest.

Retention period: for the period strictly necessary to complete the transaction or transactions and, afterwards, for the time and to the extent necessary to comply with legal obligations or protect our rights and legitimate interests.

14

5. Server location and transfers outside the EU

As a rule, we do not transfer data to countries outside the European Union. However, because some important infrastructure service providers are based outside the European Union, for example hosting or cloud providers, your data may be stored on servers located outside Europe when you use our services.

Important: in these cases, we ensure that personal data is processed in compliance with applicable law by adopting appropriate safeguards, such as adequacy decisions, standard contractual clauses approved by the European Commission or other safeguards provided by the GDPR, as well as suitable security measures to protect the confidentiality of your data.

More information about transfers and adopted safeguards can be requested by writing to us at the contact details indicated in section 8.

15

6. Who we share data with

The persons who may become aware of your personal data, within the limits strictly necessary to fulfill the purposes indicated in this notice, are persons formally authorized by EasyApe.

In addition to EasyApe internal personnel, personal data may be disclosed to external parties that may act as independent controllers or processors in order to provide the service. In particular, your data may be disclosed to:

venues or commercial partners where this is necessary to manage reservations, events, orders, check-in or customer support;

companies that provide IT services necessary for the platform to work, such as hosting, cloud infrastructure, database, authentication and storage providers, including Supabase where used;

the payment platform provider connected with the App, namely Stripe;

analytics, measurement and marketing technology providers used to understand product performance and campaign effectiveness, such as Google Analytics/Firebase, PostHog and, where configured and consented to, Meta Pixel;

persons, companies or professional firms that provide assistance and consulting services to the Controller;

entities or authorities to whom disclosure of your personal data is mandatory under legal provisions or orders from competent authorities.

To learn which processors are involved, you can contact us using the methods indicated in section 8.

16

7. Your privacy rights

What are privacy rights?

The GDPR grants important rights that you can exercise by contacting the Data Controller.

To learn more about your rights, you can read Chapter 3 of the GDPR.

You may exercise the following rights:

right to withdraw consent;

right of access to data;

right to rectification;

right to erasure or deletion;

right to restriction of processing;

right to data portability;

right to object;

right to lodge a complaint with the competent national authority, the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali).

17

8. Who you can contact

For any communication relating to the processing of your data, including exercising your rights, you can write to us by email at: info@easyape.it.

18

9. Changes

If our data processing policy changes, we will promptly notify you by publication in the App or by another appropriate method.