Skip to content

Privacy Policy

Information notice pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018.

Version 2026-09-14.2 · Last updated 2026-09-14

1. Data controller

The data controller is PRONTOMIGO S.R.L., società a responsabilità limitata, with registered office at Via Pola Interna n. 51, 41012 Carpi (MO), Italia, VAT number 04273350365, fiscal code 04273350365.

For questions about this notice or to exercise your rights, contact info@prontomigo.com or send certified email (PEC) to prontomigo@pec.it. If a Data Protection Officer is appointed and publication of their contact details is required, those details will be added to this notice.

2. Scope of this notice

This Privacy Policy describes how PRONTOMIGO S.R.L. processes personal data when you:

  • use the public website, customer web portal or any of the customer, provider and merchant mobile applications;
  • register or maintain an account as a customer, merchant, delivery rider, trucker or transport company;
  • place food or grocery marketplace orders, book van/truck transport, or use live delivery workflows;
  • submit onboarding applications, compliance documents or payout details for administrative review;
  • apply for a job through Careers / Lavora con noi;
  • communicate with support, safety, compliance, recruiting or admin teams;
  • subscribe to marketing communications where offered.

This notice does not apply to third-party websites or services linked from our platform. Merchants and independent providers may process customer data as separate controllers to fulfil an order or transport service; their own notices apply to that independent processing.

PRONTOMIGO S.R.L. acts as a technology intermediary. Regulated road-freight work is made available only to providers that declare and must maintain the authorisations, registrations and insurance required for the job; ProntoMigo separately remains responsible for obligations applicable to its platform role. Stripe processes customer card payments and connected-recipient onboarding, while ProntoMigo's systems coordinate PaymentIntents, refunds, ledger records and separate merchant/provider transfers.

3. Categories of personal data processed

Depending on how you use the platform, we may process the following categories of data:

Account and identity data: name, email address, telephone number, password hash, profile photo, preferred language, role, verification status.

Order and transport data: delivery and pickup addresses, order contents, goods description, declared dimensions/weight/value for van/truck bookings, service type, instructions, proof-of-delivery photos or signatures, ratings, support tickets, chat or call metadata.

Location data: GPS position during active food/grocery deliveries, scheduled van/truck transport or assigned jobs; approximate location derived from IP address on the website; saved addresses you choose to store.

Payment and payout data: payment method tokens, transaction identifiers, amounts, refunds, chargebacks, payout references and, for partners, bank payout details such as account-holder name, IBAN/BIC, country/currency and Stripe Connect verification status. We do not store full payment card numbers and normally rely on Stripe or another approved provider to store sensitive bank credentials.

Provider and merchant compliance data: identity documents, fiscal code, Partita IVA, SDI/PEC details, merchant licences, food-safety/HACCP evidence, driving licences, vehicle registration, insurance certificates, Albo autotrasportatori/REN details, background-check results where permitted by law, and admin review notes.

Technical and usage data: device identifiers, app version, operating system, log files, crash reports, anti-fraud signals, cookies and similar technologies on the website.

AI-assistance metadata: where AI features are enabled, we may process limited content you submit for assistance (for example menu/catalog images or text for import drafts, support ticket context already visible to agents, published help-article text, and cargo or document images for extraction suggestions), together with technical run metadata such as model identifiers, token usage and input/output hashes. We do not store raw AI prompts in our audit tables.

Marketing and communications data: newsletter preferences, campaign attribution, records of consent.

Recruitment / careers candidate data: name, email, telephone number, city/area, optional profile URL, availability notes, answers to vacancy screening questions, PDF curriculum vitae, application locale, source path, optional privacy-safe marketing attribution (for example UTM parameters), privacy-notice version and acknowledgement time, and recruiter workflow metadata (status, assignee, internal notes, access events).

We do not intentionally process special categories of data under Article 9 GDPR unless required by law or explicitly provided by you for a specific purpose (for example, accessibility needs communicated to support). We do not use biometric identification or emotion recognition.

4. Sources of data

We collect personal data:

  • directly from you when you register, place orders, upload documents or contact support;
  • automatically through your device when you use location-enabled features or our apps;
  • from merchants and providers to the extent necessary to fulfil your request;
  • from payment processors such as Stripe;
  • from authentication providers if you choose social login;
  • from public registers or verification partners where required for provider onboarding.

5. Purposes and legal bases of processing

We process personal data only where a legal basis applies under Article 6 GDPR:

PurposeTypical legal basis
Creating and managing your accountPerformance of a contract (Art. 6(1)(b))
Processing food, grocery, van/truck transport and payment flowsPerformance of a contract (Art. 6(1)(b))
Connecting you with merchants and independent providersPerformance of a contract (Art. 6(1)(b))
Stripe Connect onboarding, payouts, refunds and payment reconciliationPerformance of a contract; legal obligation; legitimate interest (Art. 6(1)(b), (c), (f))
Admin review of merchant, rider and transport-company applicationsPerformance of a contract; legitimate interest; legal obligation where applicable (Art. 6(1)(b), (c), (f))
Verifying Albo/REN, vehicle, insurance, food-safety and tax complianceLegal obligation where applicable; legitimate interest in a lawful and safe marketplace (Art. 6(1)(c), (f))
Live tracking during active servicesPerformance of a contract; legitimate interest in service safety and reliability (Art. 6(1)(b), (f))
Customer support, complaints, evidence handling and dispute resolutionPerformance of a contract; legitimate interest; legal obligation where applicable (Art. 6(1)(b), (c), (f))
Fraud prevention and platform securityLegitimate interest (Art. 6(1)(f))
Accounting, tax, DAC7 and regulatory recordsLegal obligation (Art. 6(1)(c))
Service analytics and product improvementLegitimate interest (Art. 6(1)(f)); consent for non-essential cookies (Art. 6(1)(a))
AI-assisted catalog import drafts, support/ops drafts, help answers and document/cargo suggestions (when features are enabled)Performance of a contract; legitimate interest in efficient onboarding and support (Art. 6(1)(b), (f)); human review remains required before publication or account decisions
Recruiting candidates who apply via Careers / Lavora con noiPre-contractual steps at the candidate’s request and legitimate interest in assessing applications (Art. 6(1)(b), (f)); consent is not used as the primary basis for CV processing
Marketing communicationsConsent (Art. 6(1)(a)) where required

Where we rely on legitimate interest, we balance our interests against your rights and implement safeguards such as minimisation, access controls and retention limits. You may object to processing based on legitimate interest as described in Section 11.

6. Recipients and processors

Personal data may be shared, according to the feature used, with:

  • Merchants and independent providers involved in fulfilling the order or transport booking;
  • Supabase for authentication, hosted PostgreSQL data and object storage;
  • Stripe for card processing, fraud/payment controls, connected-recipient verification and payouts;
  • Google Maps Platform for Places, geocoding, route distance, ETA and map display;
  • Resend for contact, recruiting and transactional email when configured, and Expo for mobile build/update and push-delivery infrastructure;
  • Vercel, Railway and other selected hosting/infrastructure providers for the website, dashboards, API and workers, according to the production deployment;
  • OpenAI only when a flag-enabled AI feature is used, to generate a draft or cited help answer from limited submitted content. API requests use the provider's available no-storage setting; raw prompts are not stored in ProntoMigo's AI audit table;
  • verification providers, professional advisers, auditors, insurers and claims handlers where actually engaged and necessary;
  • public authorities and regulators where disclosure is required by law or necessary to protect rights and safety.

Processors are appointed under Article 28 GDPR where required. Provider roles, configurations and subprocessors can change; an updated list and relevant safeguards are available from info@prontomigo.com.

7. International data transfers

Provider and project locations follow the accounts and production regions configured for each service. Some providers or their subprocessors may process data outside the European Economic Area. Where Chapter V GDPR applies, we rely on an adequacy decision or appropriate safeguards such as the European Commission's Standard Contractual Clauses, together with supplementary measures where required.

You may request information about the transfers relevant to your data and a copy or summary of the applicable safeguards at info@prontomigo.com.

8. Retention periods

We retain data only for the relevant purpose. The current application defaults are:

  • Account and profile: while the account is active. After an eligible, verified self-service deletion, the authentication identity, profile and role-specific personal data are deleted or redacted promptly. Deletion may first be blocked by active orders/jobs, unresolved refunds, payouts, invoices, dues or support matters.
  • Orders, transport, payment, ledger, invoice and tax records: generally up to 10 years where required for accounting, tax, DAC7, contract or claims compliance; retained rows are minimised or redacted after account deletion where possible.
  • Delivery proof, support and safety evidence: for the applicable complaint, insurance or limitation period, or longer only under a documented legal hold.
  • Live job locations: intermediate points on completed trails are trimmed after 7 days; location records are deleted after 30 days by default, unless a documented dispute, safety or legal hold applies. Exact retained provider points are not exposed after a terminal or revoked job.
  • Provider compliance evidence: 10 years from upload by the current default. Merchant compliance documents: 7 years from upload by the current default. Access remains restricted and the record may survive account deletion until its retention date.
  • Operational records: published outbox records 90 days; audit logs 365 days; terminal notification-delivery records 180 days; expired quotes, revoked device tokens and expired tracking shares 30 days. These worker defaults may be changed only through controlled retention configuration.
  • AI catalog-import source files: 30 days after a terminal state (published, failed or cancelled). AI audit metadata contains feature/model identifiers, hashes and usage metrics rather than raw prompts; it is kept only for security, budget and quality governance under the applicable audit schedule.
  • Anonymous help: server session and browser pseudonymous key up to 24 hours.
  • Careers applications and CVs: 730 days from the last status change by default, followed by CV deletion and irreversible anonymisation of identifying fields. A separate employee notice applies if a candidate is hired.
  • Cookie choice: 180 days unless changed or cleared sooner; first-party campaign attribution, if consented, 30 days.

When a period ends, data is deleted or irreversibly anonymised. Restricted backup copies may persist only for the documented technical backup cycle and are not returned to ordinary production use. A legal hold overrides automated deletion only for the data and duration necessary.

9. Consequences of not providing data

Providing account, contact, payment and service data is necessary to create an account, place orders, book van/truck transport and receive services. Without this information we cannot perform our contract with you.

For merchants, riders and transport providers, onboarding, compliance and payout information is necessary for admin review, Stripe Connect activation, legal eligibility checks and account approval. Without required documents or payout details, we may be unable to approve or activate your account.

Location data is necessary for live tracking during active deliveries and scheduled van/truck transport. You may disable location permissions in device settings, but certain features will not function.

Marketing data is optional. Refusing marketing consent does not affect access to core services.

10. Automated decision-making, profiling and AI assistance

PRONTOMIGO S.R.L. uses deterministic systems to calculate quotes and ETAs, validate eligibility and detect operational or fraud signals. Eligible dispatch candidates are ordered by proximity to pickup, current active workload, longest-wait/fairness rotation and a stable tie-breaker; service/vehicle eligibility and online availability are gates. Lawful refusal of an offer is not a punitive ranking factor.

Merchant browse results are ordered alphabetically after service-area and account-status eligibility filtering; customers may optionally apply an open-now filter. Product search uses text relevance with product-name ordering as a tie-breaker. The current code has no paid merchant placement or personalised merchant ranking.

When separately enabled by feature flag, AI may generate draft-only suggestions for catalog import, internal support/operations briefs, cited public help answers and cargo/document extraction. AI does not autonomously set prices, approve refunds, publish catalogs, approve compliance documents, assign or suspend providers, close support tickets, or block payments or payouts. Humans remain responsible for those actions.

We do not use AI for biometric identification, emotion inference, hidden punitive scoring of job refusals or automated recruitment ranking/rejection. Significant account, work-access and payout restrictions are subject to human decision or review where required by law.

Providers are not required to share job tracking outside an authorised active target. You may request information, human intervention or review of a significant algorithm-supported decision at info@prontomigo.com.

10a. Careers and recruitment candidates

If you apply through https://www.prontomigo.com/careers, PRONTOMIGO S.R.L. is the controller of your candidate data.

Categories: identity and contact details, location/city area, screening answers, optional profile URL and availability notes, PDF CV, technical metadata needed to secure the submission, and the privacy-notice version you acknowledged.

Purpose: assess suitability for the role you applied for and manage the recruiting pipeline.

Legal basis: pre-contractual steps at your request and legitimate interest in recruiting (Art. 6(1)(b), (f) GDPR).

Recipients: authorised ProntoMigo recruiting staff (SUPER_ADMIN in v1); cloud storage and email processors under Article 28 GDPR agreements. CVs are stored in a private bucket and accessed only through short-lived audited download links.

Retention: normally 24 months from the last status change, then CV deletion and anonymisation of candidate-identifying fields. A minimal non-identifying operational record (for example that a retention deletion occurred for a vacancy) may remain.

No automated hiring: we do not score, rank, or reject candidates by automated means in this system.

Marketing: Careers applications do not create marketing consent. Marketing remains optional and separate if offered later.

Your rights: email info@prontomigo.com to request access, correction, withdrawal of an application, or deletion. Verified requests are handled by authorised recruiting admins with reason, confirmation and audit trail — not by ordinary support roles.

11. Your rights under GDPR

Subject to applicable law, you have the right to:

  • Access your personal data and obtain a copy (Art. 15);
  • Rectify inaccurate or incomplete data (Art. 16);
  • Erase data in certain circumstances (Art. 17);
  • Restrict processing in certain circumstances (Art. 18);
  • Data portability for data you provided, where processing is based on contract or consent and automated (Art. 20);
  • Object to processing based on legitimate interest, including profiling (Art. 21);
  • Withdraw consent at any time without affecting prior lawful processing (Art. 7(3));
  • Obtain human intervention and contest a qualifying solely automated decision (Art. 22).

Eligible customer, provider and merchant accounts also have self-service deletion in their account/settings area. If you cannot sign in, email info@prontomigo.com. We respond without undue delay and within one month, extendable by two months where legally permitted for complex requests, and may request proportionate identity verification.

You may lodge a complaint with the Italian Data Protection Authority at https://www.garanteprivacy.it or with the supervisory authority in your EU Member State of residence.

12. Security measures

We implement appropriate technical and organisational measures under Article 32 GDPR, including encryption in transit, role-based access controls, secure development practices, logging, monitoring and staff training.

If you believe your account has been compromised, contact info@prontomigo.com immediately.

13. Children

Customer and partner accounts are intended only for persons aged 18 or over. We do not knowingly provide accounts to children. If you believe a child has submitted personal data, contact info@prontomigo.com so we can investigate and take the action required by law.

14. Cookies and similar technologies

Our website uses cookies and similar technologies. Essential cookies are necessary for security and basic functionality. Analytics and marketing cookies are used only with your consent through our cookie banner.

For full details, see our Cookie Policy at https://www.prontomigo.com/cookies. You may change your preferences at any time from the cookie settings link in the website footer.

15. Changes to this Privacy Policy

We may update this Privacy Policy to reflect legal, technical or business changes. The "Last updated" date at the top indicates the current version. Material changes will be notified through the app, website or email where appropriate.

If you continue using our services after the effective date of an update, you acknowledge the revised policy unless applicable law requires express consent.

16. Contact

Data controller: PRONTOMIGO S.R.L. Registered office: Via Pola Interna n. 51, 41012 Carpi (MO), Italia Privacy requests: info@prontomigo.com Phone: 059 3970958 PEC: prontomigo@pec.it General support: info@prontomigo.com