Updated 3 October 2026

Privacy policy

This policy explains which personal data we process when you use fare.work and the Farework coworking space, why we process it, who we share it with, how long we keep it and what your rights are. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR). The Italian version is the binding one; this English text is a courtesy translation.

1. Data controller

Crosta Mirko, VAT no. 07635431211, Piazzetta Gagliardi 6, 80137 Naples, Italy. For any question or request about your data write to hi@fare.work or to the certified email mirkocrosta@legalmail.it. No data protection officer has been appointed: it is not required for a business of this size.

2. What data we process

  • Account data: name, email, phone, password (stored only in encrypted, unreadable form), chosen language.
  • Booking data: date, time, space, attendance or no-show, cancellations, package credit, active subscriptions and their renewals.
  • Payment data: outcome of the payment, amount, method (card, cash, card terminal, bank transfer) and the transaction identifier at the provider. We never see or store your card number: only Stripe handles it.
  • Billing data: if you ask for an invoice, company or personal name, VAT number, tax code, address, SDI recipient code or certified email.
  • Access data: when you open the door from your customer area we record your email, the time and the outcome.
  • Reviews: text, rating and the name you gave, published on the website.
  • Communications: which messages we sent you, when, and whether you asked us to stop.
  • Technical data: IP address, browser type and pages requested, in the hosting provider's logs, for as long as needed to run the service and protect it from abuse.

3. Why we process it and on what basis

We do not ask for consent to run the service. We ask for your consent (Art. 6(1)(a)) only for the Google tools that measure visits and advertising, described in the cookie policy: without your yes they are not loaded, and you can change your mind at any time from “Cookie preferences”, at the bottom of every page.

The Google map on the “Where we are” page loads only if you open it with a click: until then Google receives nothing.

We take no automated decisions with legal effects on you. We send no newsletters or promotional messages.

After a booking we may email you to ask how it went and invite you to leave a review. Every such email carries a “Stop writing to me” link: one click, and from then on you only get service emails about your bookings.

  • To perform our contract with you (Art. 6(1)(b) GDPR): managing your account, bookings, credit, subscriptions, payments, door opening, confirmation, reminder and cancellation emails.
  • To comply with legal obligations (Art. 6(1)(c)): issuing receipts and invoices, keeping tax records, answering the authorities.
  • For our legitimate interests (Art. 6(1)(f)): security of the premises and of the app, the door-opening log, prevention of abuse and fraud, publication of reviews, asking for a review after a booking, defence of our rights.

4. If you do not give us the data

Name, email and payment data are needed to book: without them, no booking can be made. The phone number is used only to contact you about a problem with a booking. Billing data is needed only if you want an invoice.

5. Who we share it with

Data is neither sold nor passed on for commercial purposes. It is seen only by the providers we need to run the service, appointed as processors or acting as independent controllers according to their role:

Some providers are based in the United States: transfers rely on the adequacy decision for the EU-US Data Privacy Framework and, where needed, on the European Commission's standard contractual clauses.

  • Stripe Payments Europe Ltd (Ireland): card payments and subscription renewals.
  • Vercel Inc. (United States): hosting of the app and technical logs.
  • Neon Inc.: the app's database, with servers in Frankfurt (European Union).
  • Resend Inc. (United States), sending from Amazon Web Services servers in Ireland: transactional emails (confirmations, reminders, cancellations) and review requests.
  • Nuki Home Solutions GmbH (Austria): opening the door from the app.
  • Google Ireland Ltd: the map on the “Where we are” page, only after your click; Gmail for part of our email; Google Analytics and Google Ads, only with your consent.
  • Serverplan S.r.l. (Italy): Farework's mail server.
  • Meta Platforms Ireland Ltd: WhatsApp, Facebook and Instagram, if you write to us there (see section 6).
  • Our tax advisor and Upya's accounting system, for invoices and tax compliance; the Italian tax authority, through its exchange system, for electronic invoices and receipts.

6. Tools we use to deal with you

Besides the app, we talk to customers through everyday tools. When you use them, your data also passes through their providers:

These channels are not connected to the app: what you write there does not end up in your account, and bookings are confirmed only through the app.

  • Email: the mailbox hi@fare.work is hosted on a Serverplan S.r.l. server (Italy); some replies are sent from Gmail, i.e. Google Ireland Ltd.
  • WhatsApp and phone (+39 331 703 9652): for quick notices about bookings, if you write or call us. WhatsApp belongs to Meta Platforms Ireland Ltd and processes your number and chat metadata under its own rules.
  • Facebook and Instagram: if you message the Farework pages, the message goes through Meta Platforms Ireland Ltd.

7. Video surveillance

There are cameras on the premises, signposted at the entrance. They cover the common areas for the safety of people and property, on the basis of our legitimate interest. The footage is not linked to the app or to bookings.

Recordings are kept for 24 hours, up to 72 hours on closing days, and are then deleted automatically, unless needed for an investigation or a request from the authorities. Only the controller can view them.

8. How long we keep it

  • Account: as long as it is active. You can ask for its deletion at any time; data we must keep by law stays for the periods below.
  • Bookings, payments, receipts and invoices: 10 years from the end of the year of issue, as required by tax law.
  • Door-opening log: 12 months.
  • Communications log: 24 months. Your choice to stop receiving them is kept for as long as needed to honour it.
  • Reviews: as long as they stay published; you can ask us to remove them.
  • Hosting technical logs: a few days, according to the provider's settings.

9. Your rights

You can ask us at any time to access your data, correct it, delete it, restrict its processing, receive it in a machine-readable format or transfer it to another controller, and you can object to processing based on legitimate interest. An email to hi@fare.work is enough: we reply within one month.

From your customer area you can already view and correct your profile and billing details.

If you believe the processing breaks the law you can lodge a complaint with the Italian data protection authority (www.garanteprivacy.it) or with the authority of the country where you live.

10. Security

Data travels encrypted (HTTPS) and is stored on systems protected by credentials and encryption. Access to the administration area is reserved to the controller. Passwords are stored in encrypted, non-recoverable form.

11. Minors

The service is intended for adults. We do not knowingly collect data from anyone under 18.

12. Changes

We update this policy whenever something changes in the processing or in the providers. The version in force is the one published on fare.work with the date at the top.

Message us