Skip to content
Milan Tourism Guide
CITOFONO: 146

Privacy Policy

Last updated: 21 September 2026. This policy describes how www.milantourism.org handles information today. Where something is planned but not yet in place, it says so rather than describing it as though it were live.

Who is responsible

Milan Tourism Guide (www.milantourism.org) is an independently published travel reference site. It is the data controller for the limited personal information described below. You can reach the publisher through the contact page; that form is the correct route for any question or request about your data.

The short version

Reading a guide on this site requires no account and no personal details. We do not run a newsletter, we do not accept comments, and we do not sell anything. The only information you actively give us is what you type into the contact form. Beyond that, the site uses Google Analytics to understand which guides are read, and the web server keeps routine access logs.

Information you give us

Contact form. The form on the contact page collects your name, your email address, the topic you select and your message. It is delivered by email to the site’s publisher. We use it to read and answer your message and nothing else — you are not added to any list, and the details are not passed to any third party. Message emails are retained while they are useful for handling corrections and are deleted when they are not. Legal basis: legitimate interest in responding to correspondence you initiated.

Site search. If you use the search box, the term you type is processed to return results and may appear in server logs and in aggregate analytics. Please do not type anything personal into it.

Information collected automatically

Server logs. The hosting provider records standard web-server data for every request: IP address, date and time, the page requested, the referring page and your browser’s user-agent string. These logs are used for security, abuse prevention and diagnosing faults, and are rotated by the host on its own schedule.

Google Analytics 4. The site runs Google Analytics 4, connected through the Site Kit by Google plugin, to see which guides people read, how they arrive and which devices they use. This is reported to us only in aggregate. Analytics sets cookies and identifiers in your browser and may transmit data, including a truncated IP address, to Google. We do not use Analytics to build advertising audiences or to attempt to identify individual readers. Legal basis outside the EEA/UK: legitimate interest in understanding site usage. You can opt out entirely with Google’s browser add-on, or block analytics cookies in your browser.

Google Search Console. The site is verified in Search Console. This reports aggregate search-query and ranking data to us; it does not set cookies on your visit or identify you.

Caching. A page cache (WP Super Cache) serves stored copies of pages to reduce load. It may set a cookie to determine whether you should receive a cached or a fresh page. It does not track you between visits.

Content loaded from elsewhere

Guides link out to official sources — museums, ATM Milano, Trenitalia, the Comune di Milano and similar. Following a link takes you to a site with its own privacy policy, over which we have no control. Where a page embeds a map or a video, the provider of that embed may set cookies once the embed loads.

Your choices, and what runs before you make them

What runs before you choose depends on where you are reading from, because the law does. In the European Economic Area and the United Kingdom, and in Brazil, Chile, China, Israel, Nigeria, South Korea, Thailand, Türkiye and Vietnam, nothing beyond the strictly necessary runs until you answer the dialog on your first visit — not analytics, not Travelpayouts — and Reject all sits on that first screen next to Accept all, not behind a second click.

In the United States you are shown a bar rather than a dialog, and it is not only a notice. Analytics starts on arrival there, but advertising and booking-partner scripts stay switched off until you answer it. In Switzerland you get the dialog too, but analytics starts on arrival there and only advertising and booking-partner scripts wait for your answer. In Canada, and in the countries where notice is enough — among them Australia, New Zealand, Japan, Singapore, India and Mexico — everything described on this page starts when you arrive; the notice tells you so, and the same control switches it off. Everywhere else, and whenever we cannot tell where you are, the strictest setting applies: nothing beyond the necessary runs until you answer.

Your answer is kept on your own device, in a first-party cookie called cookie_consent_3cab39 that only this site can read, so you are not asked again on every page. It lasts about a year. The Cookie settings link in the footer of every page reopens the choice, and withdrawing is the same two clicks as agreeing: the scripts stop running, and the analytics cookies this site can reach are cleared. Travelpayouts stores nothing here under a name this site can see, so anything it has already set on its own domains has to be cleared in your browser rather than from this page.

Refusing costs you nothing. Every guide here is readable in full either way, nothing is paywalled, and no part of Milan Tourism Guide is held back from readers who say no.

If you are reading this in the United States

Several US states give you the right to opt out of the “sale” or “sharing” of personal information, and those words are broader than they sound: letting an advertising or affiliate partner receive information about your visit can count as sharing even though no money changes hands for your data and we have never sold anything of the kind. Rather than argue the definition, Milan Tourism Guide treats it as covered.

So the bar shown to US readers carries a Do not sell or share my personal information control, and the footer link is labelled Your privacy choices. Using it stops the advertising category, which is what Travelpayouts and any ad partner sit in. Travelpayouts stops running from that point; anything it set earlier on its own domains is cleared in your browser rather than from here.

This site also honours Global Privacy Control. If your browser or an extension sends a GPC signal, it is treated as a valid opt-out on arrival — you do not have to find the control and click it as well, and we do not ask again on later visits. Do Not Track is a different and long-abandoned signal, and to be straight about it: this site does not act on DNT, because nothing agreed what it ought to mean.

The record kept of your choice

Proving that a choice was offered and honoured means keeping a record of it. Each answer is logged with the date and time, the two-letter country the choice was made from, which of the rule sets above applied, a reference to the exact wording you were shown, and the choice itself, against a random identifier generated for your browser.

That record contains no name, no email address and no IP address. It holds a salted hash of your browser’s user-agent string, and the salt changes every day, so two visits on different days cannot be linked back together through it. Records are deleted after 26 months. If you want to see or delete the entries tied to your browser, ask through the contact form.

Who we share information with

We do not sell personal information and we do not share it for cross-context behavioural advertising. Information reaches only the parties that make the site work: the hosting provider (which stores the site and its logs), Google (Analytics and Search Console, as described above), and the email provider that delivers contact-form messages. We will disclose information where we are legally obliged to, and would tell you unless prohibited from doing so.

International transfers

The site’s hosting and the Google services described above involve processing in the United States. Where personal data of EEA or UK visitors is transferred, it is done under the safeguards those providers maintain, including Standard Contractual Clauses and the EU–US and UK–US Data Privacy Framework where applicable.

Your rights

If you are in the EEA or the UK, you have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to its processing, and to data portability where it applies. If you are in California, you have the right to know what is collected, to request deletion, to correct inaccurate information, and not to be discriminated against for exercising those rights. We do not sell personal information. Because our affiliate network receives information about your visit, the site treats that as potential “sharing” and offers a Do not sell or share control, described under “If you are reading this in the United States”.

In practice we hold very little: unless you have written to us, there is likely nothing on file that identifies you. To make a request, use the contact form. EEA and UK visitors also have the right to complain to their national data protection authority.

Children

This site is written for adults planning travel and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has sent us information through the contact form, write to us and it will be deleted.

Security

The site is served over HTTPS and administrative access is restricted. No website can promise perfect security, but the amount of personal data held here is deliberately minimal, which is the most effective protection available.