Privacy policy
Last updated 10 September 2026
This page explains what runto.page does with your personal data, as required by the GDPR (Regulation EU 2016/679).
Who is responsible
runto.page is run by www.gabrielecabrini.it. Anything else you need to know or ask about your data, including a request under the rights below, goes to info@runto.page.
What we hold
- Your email address, so you can sign in and so we can send you service emails.
- Your password, stored only as a hash. It cannot be read back, by us or by anyone else, and it is never kept or logged in readable form.
- Technical logs of the requests made to the service.
Alongside that we hold the links you create and a few dates on your account, both of which the service plainly cannot work without. We ask for no name, no phone number, no address, no payment details. We hold no special category data, we run no advertising, and we buy no data about you from anyone else.
Why we hold it, and on what basis
- To give you an account and to make your links resolve. Legal basis: performance of the contract between you and us, article 6(1)(b).
- To send the emails the service depends on, meaning address confirmation, password reset and address change. Same basis. There is no marketing list to be on.
- To keep the service standing and to deal with abuse, such as links pointing at malware or accounts created in bulk. Legal basis: our legitimate interest in a service that is not harmful to others, article 6(1)(f).
We do not sell, rent or trade your data. We do not profile you, and no decision about you is taken automatically.
Cookies, or the lack of them
We set no cookies. Signing in leaves a short-lived sign-in token in your own browser, and signing out removes it. It is there only because you asked to sign in, so it needs no consent banner. There are no analytics scripts, no tracking pixels and no third-party code on any page. The redirect counter shown on the site is a single total for the whole service and holds nothing about any individual visitor.
Who else touches it
Two suppliers, both working on our instructions and only to run the service: Resend, which sends the service emails, and the provider that hosts it. Where a supplier processes data outside the European Economic Area, the transfer relies on the safeguards required by Chapter V of the GDPR. Beyond that, your data goes to nobody, except where the law or an authority obliges us.
How long we keep it
- Account data and links, for as long as the account exists.
- The codes we email you to confirm an address or reset a password, only briefly. They are single use and they stop working shortly after they are sent.
- Technical logs, only for as long as they are useful to look into a fault or an abuse.
- When an account is deleted, the address and the password are cleared and the links stop resolving. The slug itself stays out of circulation, so a link somebody has already shared cannot quietly be taken over by someone else.
Your rights
You may ask for access to your data, correction of it, erasure, restriction of how we use it, a copy in a portable format, and you may object to processing based on legitimate interest. Your email address and your links you can change yourself from the account and links pages. For everything else, including deletion, write to info@runto.page and we will answer within one month.
If you think we have handled your data badly, you can complain to the Garante per la protezione dei dati personali (garanteprivacy.it) or to the supervisory authority where you live.
Age
You need to be at least 16 to create an account.
Changes
If what we do with your data changes, this page changes with it and the date at the top moves. If a change matters to you, we will say so on the site or by email.