Skip to content

Privacy Policy

Information notice pursuant to Articles 13-14 of EU Regulation 2016/679 (GDPR)

Data controller

The data controller is the operator of the website treniamo.it, contactable at:

info@treniamo.it

Data collected and purposes

Treniamo does not require an account. This section describes website data; app processing is described separately below. We process the following data:

  • Usage data and interaction reconstruction (ARVX): Pages visited, load times, device and browser type, used to improve the service. With Google Analytics consent and TCF publisher purposes 1, 8 and 10, ARVX also performs session replay of public pages only: navigation, clicks, focus, scrolling, performance and exposure, the visible text inside the public page boundary and the values of the non-sensitive public controls inside that boundary (search, date, time, selections and option state). Always excluded: passwords, tokens, OTPs, payment data, email, phone, addresses, identities, tax data, messages, free-text areas, hidden fields, sensitive-autocomplete fields and any data-arvx-private area, as well as the admin area, API, non-public pages, third-party iframes and raw URLs or queries.
  • Search journey measurement (ARVX): With your consent we collect anonymous technical events about the train search journey: the start and end of a search, the outcome (found, no results, error, interrupted), autocomplete requests and the values of the non-sensitive public controls inside the public boundary, including search, date, time, selections and option state. The events use only closed numeric codes and a temporary reference valid only within the single browsing session. We do not collect passwords, sensitive fields, free text outside the public boundary, identities or addresses. The data is used to measure whether search works and to compare groups and periods in aggregate form.
  • Cookie consent logs: Consent ID, accepted categories, timestamp, hashed IP address (non-reversible) and browser string (user agent). Stored to demonstrate consent under GDPR.
  • Error data: Technical information about site errors, without queries, cookies or page content, used exclusively to resolve technical issues.
  • Data entered in the refund form: Name, email and travel details entered in the refund assistant. This data is processed exclusively in the browser and is never sent to our servers.

Treniamo app for Android and iOS

This section covers the Treniamo app and supplements the controller and rights information on this page. Section updated: 9 September 2026. The app does not require an account, name, email address or contacts. It does process installation identifiers and technical data: it is not a service that processes no personal data.

To provide the features you request, the server assigns a random installation identifier; its credential is kept in the device’s protected credential store. Requests include the app platform and version, station and train details, dates and times needed for the service. Search text is sent to the APIs to retrieve results but is not included in analytics events. Connections also make technical information, such as the IP address, available to the systems delivering and protecting the service.

After you request the feature and grant system permission, the app uses foreground location to find the nearest station. It sends coordinates rounded to three decimal places, approximately 100 metres, to the server without the installation’s personal credential. This does not automatically make the connection anonymous. Map centring uses location on the device. We do not use background location.

Our usage statistics and error reports require the “Usage statistics” consent, which is off initially. Events include screens, search type and result count, notification permission outcomes, widgets and interactions with Omio offers, without search text. They are associated with the installation and retained for 90 days. Error reports include error class, screen, stack fingerprint, date, version and platform; we do not send raw stacks. Our Arvos technical system receives these reports without the installation identifier. Turning consent off stops local sending and clears the queue; once the revocation reaches the server, it rejects new events and starts deleting associated events.

If you enable alerts and grant notification permission, we process the Expo push token, language, version, preferences and followed trains with date and delay threshold. Expo forwards tokens and notification content to Google Firebase Cloud Messaging on Android and Apple Push Notification service on iOS. You can disable alerts in the app or revoke permission in system settings.

Ads use Google Mobile Ads and the UMP choice form, separately from consent to our own statistics. Ad requests depend on the choices permitted by the form and service configuration; on iOS, use of IDFA also requires tracking permission. Google and the partners identified in the form may process advertising or app identifiers, IP address, interactions and diagnostic data for advertising, measurement and fraud prevention. Refusing personalisation or tracking does not mean that all technical processing stops. You can review your choices in “Ad privacy” and system settings.

Expo also delivers app updates and receives an installation identifier for its own service and technical version information. Maps use Google Maps on Android and Apple MapKit on iOS, with processing under those services’ policies. Opening Omio/Impact offers or web pages makes the browser contact those services; their privacy policies and cookie choices also apply. Pages on our website retain their own consent panel. These activities are not governed solely by the app’s usage statistics switch.

Favourites, recent items, caches, settings and board snapshots for widgets are stored locally. The credential is in Keychain/Keystore; advertising choices are managed by Google’s SDK. Widgets may request the selected station’s board from the server. Requests from the app to our APIs use HTTPS.

“Delete my data” revokes the current server identity and removes associated push registrations and alerts. Deletion from analytics copies continues through a queue and is not instantaneous. Consent to our statistics is turned off; later requests may create a new identity. Local favourites and settings remain available. The command does not automatically erase browser cookies or data held independently by providers, or technical data without a link to the installation. You can contact the controller at the address on this page to exercise your rights.

Legal basis for processing

Consent (Art. 6.1.a GDPR)

For analytics cookies (Google Analytics), advertising cookies (Google AdSense) and ARVX interaction reconstruction, conditioned on Google Analytics signals and TCF publisher purposes 1, 8 and 10. Consent can be withdrawn at any time via the "Manage cookies" panel in the footer.

Legitimate interest (Art. 6.1.f GDPR)

For essential technical cookies required for the site to function and for consent log recording.

Third parties and external services

The following third-party services may process data:

  • Google Analytics (Google LLC)

    Anonymized analysis of site usage. Only with consent.

  • Google AdSense (Google LLC)

    Contextual and personalized advertising on the site. Advertising cookies are only activated with explicit user consent.

    Google Ads privacy policy

  • Omio / Impact (Omio Travel GmbH, impact.com Inc.)

    Some pages contain affiliate links to Omio, labelled as "Ad". Clicking them redirects to omio.com through the Impact tracking platform, which records the click and may set cookies on the destination domain to attribute purchases. Treniamo earns a commission on purchases at no extra cost to the user. No tracking cookies are set on treniamo.it before the click.

  • Cloudflare (Cloudflare Inc.)

    CDN and DDoS protection. Processes connection data for security purposes.

Data transfers outside the EU

Some third-party services (Google Analytics and Cloudflare) may transfer data outside the European Economic Area. Such transfers are protected by Standard Contractual Clauses (SCCs) approved by the European Commission and/or the EU-US Data Privacy Framework.

Data retention period

  • Cookie consent logs: 3 years (GDPR legal obligation)
  • Google Analytics data: per Google's policies (26 months)
  • Railway event data: 2 years (anonymous, non-personal data). ARVX archive: the current maximum quota is 2 GiB and no automatic purge is configured; retention is therefore not tied to an automatic expiry.
  • Detailed technical error events: 21 days

Data subject rights (Arts. 15-22 GDPR)

As a data subject, you have the right to:

  • Access: obtain confirmation of data concerning you and receive a copy
  • Rectification: request correction of inaccurate or incomplete data
  • Erasure: request deletion of data ("right to be forgotten")
  • Restriction: request restriction of processing
  • Portability: receive data in a structured, machine-readable format
  • Objection: object to processing based on legitimate interest
  • Withdraw consent: withdraw consent at any time without affecting the lawfulness of prior processing

How to exercise your rights

To exercise your rights, send a request to:

info@treniamo.it

We will respond within 30 days of receiving your request.

Complaint to the supervisory authority

You have the right to lodge a complaint with the Italian supervisory authority:

Garante per la protezione dei dati personali (Italian Data Protection Authority)

Website: www.garanteprivacy.it

Last updated: 17 September 2026