Public area
Public pages set no analytics, advertising or profiling cookies and do not use localStorage or sessionStorage. Language is determined by the /it or /en URL, without browser storage.
Administrative session
The private area uses necessary first-party Auth.js cookies for sign-in, CSRF verification and the admin session. The sign-in link expires after 10 minutes; the administrative session may last up to 30 days and is refreshed during use. Cookies are configured by the framework with HttpOnly, SameSite and Secure protection over HTTPS.
Stripe and external content
Stripe may set its own technical and anti-fraud technologies when the guest opens the hosted checkout on stripe.com. Maps are not embedded: Google Maps links open another website only when selected by the user. Images and fonts are served by this website; there are no videos, pixels or third-party anti-spam systems.
Consent and changes
Because the current inventory contains only necessary technologies or technologies activated on external websites at the user’s request, no consent banner is shown. Before adding non-essential tools, they must be blocked in advance, an explicit choice collected, and this page updated.
