Questa pagina è disponibile anche in italiano. Leggi in italiano
WHIP LIVE · Cookie Policy EN/IT

Cookie Policy

This policy explains what cookies and similar tracking technologies are used on whip.live, gdm.whip.live and the WHIP LIVE mobile apps, why they are used, who has access to the data they generate, and how you can grant, refuse or withdraw your consent at any time.

Data controller: WHIP S.r.l., Magione (PG), Italy Version — last updated — next scheduled review

01Who we are

The data controller (titolare del trattamento) for the processing described here is:

WHIP S.r.l.
Via Frà Filippo Longo 16/b — 06063 Magione (PG), Italy
Email: [email protected]
Privacy requests: [email protected]

In this document, “we”, “us” and “WHIP” mean WHIP S.r.l.; “you” or “User” means any person visiting our websites or using our apps.

This Cookie Policy is an integral part of, and should be read together with, our Privacy Policy, which describes all other processing of personal data carried out by WHIP.

02Which services this covers

This policy applies to the following WHIP properties, together referred to as the “Services”:

  • www.whip.live — the public WHIP LIVE website (product pages, content, sign-up).
  • gdm.whip.liveGDM, the WHIP cloud route-planning application for motorcyclists, cyclists, runners and hikers.
  • Any other subdomain of whip.live that links to this policy, and the WHIP LIVE mobile applications where they use equivalent SDK-based identifiers.

The Services do not cover third-party websites you may reach through links we publish. Once you leave our domains, the cookie and privacy policy of the destination site applies.

03What cookies and trackers are

A cookie is a small text file that a website asks your browser to store on your device. On each subsequent request the browser sends it back, which lets the site recognise the browser — for example to keep you logged in, remember your language, or count visits.

Alongside cookies, comparable results can be achieved with other technologies, which this policy treats identically and refers to collectively as “trackers”:

  • Local and session storage — key/value data kept by the browser for a specific site (used, for example, by our route planner to preserve your work in progress).
  • Pixels and web beacons — tiny transparent images or script calls that signal that a page or email has been opened.
  • SDK and mobile identifiers — advertising or installation identifiers used inside the mobile apps and by attribution services.
  • Device fingerprinting signals — combinations of technical attributes that can distinguish one device from another.

First-party and third-party

First-party trackers are set by WHIP under the whip.live domain. Third-party trackers are set by external providers (for example Google or Meta) whose code runs on our pages; those providers act as independent or joint controllers for their own purposes, under their own policies, which are linked in the tables below.

Session and persistent

Session trackers are erased when you close the browser. Persistent trackers survive until their stated expiry date or until you delete them manually.

05Strictly necessary

These make the Services work. Without them pages cannot be served securely, you cannot log in, and your consent choice cannot be remembered. They are activated automatically and cannot be switched off from our banner — you may still block them in your browser, but the Services will then not function correctly.

Strictly necessary trackers
TrackerProviderPurposeDuration
whip_session PHPSESSID connect.sid WHIPFirst party Maintains the browsing session and links requests to the same visitor. Session
whip_auth refresh_token WHIPFirst party Keeps you signed in to your WHIP LIVE or GDM account between visits and refreshes access tokens. Up to 12 months
cookie_consent consent_state WHIPFirst party Stores which categories you accepted or refused, plus the timestamp and version of the banner, as required evidence of consent. 6 months
csrf_token XSRF-TOKEN WHIPFirst party Protects forms and API calls against cross-site request forgery. Session
appleid_state Apple Inc.United States — policy Completes the “Sign in with Apple” authentication flow on gdm.whip.live and validates the nonce and redirect. Session
AWSALB AWSALBCORS GCLB Amazon Web Services, Inc.; Google LLCInfrastructure — AWS, Google Cloud Routes each request to a healthy backend server and keeps session affinity. Session to 7 days
Local storage: draft routes, map viewport WHIPFirst party On gdm.whip.live, keeps the route you are planning and the map position so a reload does not lose your work. Until cleared

Error and performance monitoring (Sentry and Datadog) runs on a strictly necessary basis to keep the Services stable and secure. It records technical event data and a random, non-advertising session identifier; it is not used for profiling. See Sentry and Datadog.

06Functional

These improve usability and enable optional features. Blocking them keeps the Services usable, but some conveniences and embedded content will not be available.

Functional trackers
Tracker or serviceProviderPurposeDuration
whip_lang whip_units whip_theme WHIPFirst party Remembers your language, measurement units (km or mi), and light or dark preference. 12 months
Contentful Contentful GmbHGermany — policy Delivers editorial content and media shown on our pages. Session
Intercom intercom-id-* intercom-session-* Intercom Inc.United States — policy Runs the in-product support messenger, keeps your conversation history and identifies returning users to support agents. Up to 9 months
Brevo (Sendinblue) Brevo SASFrance — policy Newsletter subscription management and open and click measurement in emails you have asked to receive. Up to 12 months
Facebook social widgets, Like button, Comments Meta Platforms Ireland Ltd.Ireland — policy Embedded social plugins and the comment widget on our content pages. Loaded only after consent; Meta may read its own cookies once loaded. Up to 24 months

07Analytics and performance

These let us count visits, understand which features are used, measure app installs and diagnose where users get stuck. The data is aggregated for reporting, but because these services use third-party or cross-service identifiers they are not exempt from consent under Italian law, so they are loaded only if you accept this category.

Analytics trackers
ServiceProviderPurpose and dataDuration
Google Analytics _ga _ga_* _gid Google Ireland Ltd.Ireland — policy, opt-out Audience measurement, traffic sources, page and event statistics. IP truncation is enabled and, in our configuration, data is not used by Google for its own advertising purposes. Cookies; usage data. Up to 24 months
Mixpanel mp_* Mixpanel, Inc.United States — policy, opt-out Product analytics: which features of WHIP LIVE and GDM are used, funnels, retention. Cookies; usage data. Up to 12 months
Branch Attribution Branch Metrics, Inc.United States — policy Deep links and install attribution — identifies which campaign or page led to an app installation. Cookies; usage data; device identifiers. Up to 12 months
Meta Analytics for Apps Meta Platforms Ireland Ltd.Ireland — policy Aggregated statistics on app and site usage. Usage data; further data as specified by the provider. Up to 24 months
Google Tag Manager GTM-PR7Q8CL Google Ireland Ltd.Ireland — policy Tag management container. It sets no analytics cookies itself but conditionally deploys the tags listed here, honouring your consent signal via Google Consent Mode. Session

08Marketing, remarketing and profiling

These build a profile of your interests in order to show you WHIP advertising on other websites and platforms, to measure whether those ads worked, and to avoid showing you the same ad repeatedly. They are the most privacy-invasive category and are never loaded without your explicit consent.

Marketing and profiling trackers
ServiceProviderPurpose and dataDuration
Meta Pixel _fbp fr _fbc
ID 254226781693241
Meta Platforms Ireland Ltd.Ireland — policy, ad preferences Conversion tracking and audience building for Facebook and Instagram advertising. Trackers; usage data. Up to 3 months
Facebook Custom Audience Meta Platforms Ireland Ltd.Ireland — policy Matches our audience lists (based on cookies and hashed email addresses) to Meta accounts, to target or exclude specific groups. Cookies; email address. Up to 24 months
Facebook Lookalike Audience Meta Platforms Ireland Ltd.Ireland — policy Finds Meta users statistically similar to our existing audience for prospecting campaigns. Trackers; usage data. Up to 24 months
Google Ads conversion tracking _gcl_au IDE Google Ireland Ltd.Ireland — policy, ad settings Attributes sign-ups and app installs to Google Ads campaigns and enables remarketing lists. Cookies; usage data. Up to 24 months
Google Ad Manager Google Ireland Ltd.Ireland — policy Serving and frequency-capping of display advertising. Cookies; usage data. Up to 24 months

These trackers involve profiling within the meaning of Art. 4(4) GDPR — inferring interests from your behaviour — but they do not produce legal effects concerning you or similarly significantly affect you. You can object at any time under Art. 21 GDPR by refusing this category.

09Payments, stores and login providers

Where the Services offer purchases or subscriptions, payment is handled entirely by the provider — we never receive or store your card number.

  • Apple App Store and Google Play Store — in-app purchases; payment data is processed by Apple and Google respectively.
  • Stripe, Inc. (United States) — card payments on the web, including fraud-prevention trackers that are strictly necessary to complete a transaction. Policy.
  • Sign in with Apple and Facebook Login — optional authentication. Only session data needed to complete the login flow is set; see Apple and Meta.
  • TestFlight (Apple) and Google Play Beta Testing — used only for beta programmes you deliberately join.

10International data transfers

Some providers listed above are established outside the European Economic Area, principally in the United States. Where a transfer occurs, it is carried out on one of the following bases:

  • the European Commission’s adequacy decision of 10 July 2023 for organisations certified under the EU–US Data Privacy Framework;
  • Standard Contractual Clauses adopted by the Commission (Implementing Decision 2021/914), supplemented where necessary by a transfer impact assessment and additional technical measures such as encryption in transit and at rest;
  • another safeguard permitted by Chapter V GDPR.

You may request a copy of the relevant safeguards by writing to [email protected].

11How long data is kept

Each tracker’s lifetime is stated in the tables above. Beyond the cookie itself:

  • Consent records are retained for six months from the last renewal, and the evidence of consent (choice, timestamp, policy version) for up to five years, as accountability evidence under Art. 5(2) GDPR.
  • Analytics event data is retained by the relevant provider according to our configuration, typically no longer than 14 months for Google Analytics and 24 months for Mixpanel, after which it is deleted or fully aggregated.
  • Marketing audiences are refreshed continuously; membership expires automatically within the durations shown.
  • Data collected under a contract or a legal obligation is retained for the period required by that contract or by Italian law.

12Managing your preferences

Through our banner

The quickest route is our own preference centre, which lets you toggle each category independently.

Through your browser

You can also block or delete cookies directly. Note that browser settings apply to all sites, and blocking strictly necessary cookies will break login and route saving.

On mobile devices

  • iOS — Settings › Privacy & Security › Tracking, and App Tracking Transparency prompts.
  • Android — Settings › Privacy › Ads › Delete advertising ID.

Industry opt-outs

Your Online Choices (EDAA), NAI, DAA.

Opt-outs are themselves stored in a cookie: clearing your cookies also clears the opt-out.

13Your rights

Under Articles 15–22 GDPR you have the right to:

  • access your personal data and obtain a copy;
  • rectify inaccurate or incomplete data;
  • erase data (“right to be forgotten”) where the conditions are met;
  • restrict processing;
  • data portability in a structured, machine-readable format;
  • object to processing based on legitimate interest, and at any time to direct marketing;
  • withdraw consent at any time, without affecting the lawfulness of processing already carried out;
  • not be subject to a decision based solely on automated processing producing legal or similarly significant effects.

To exercise any of these, write to [email protected]. We reply within one month, extendable by two further months for complex requests (Art. 12(3) GDPR).

If you believe your data is processed unlawfully you may lodge a complaint with the Italian Data Protection Authority — Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Roma — or with the supervisory authority of your country of residence or workplace.

14Changes to this policy

We may update this Cookie Policy to reflect changes in the trackers we use, in our providers, or in applicable law. The current version and its date are always shown at the top of this page. Material changes — in particular the introduction of a new category of tracker — are notified through the consent banner, and your consent is requested again before the new tracker is activated.

We review this document at least once every twelve months. The date of the next scheduled review is shown at the top of this page.

15Contact

WHIP S.r.l. — Via Frà Filippo Longo 16/b, 06063 Magione (PG), Italy
General and privacy enquiries: [email protected]
Full Privacy Policy: iubenda.com/privacy-policy/78918941

A data protection officer has not been appointed, as WHIP S.r.l. does not meet the criteria of Art. 37(1) GDPR. Privacy requests are handled directly by the controller at the address above.