ManageTransfer
PricingLog in
ITEN

Privacy policy

Last updated: 2 October 2026

This policy explains what data managetransfer.it collects, why it uses it, how long it keeps it and what your rights are, as required by EU Regulation 2016/679 (GDPR). This English version is provided for convenience; if it differs from the Italian version, the Italian version prevails.

1. Data controller

The data controller is managetransfer.it, located at Italia, . You can contact the controller with any privacy question at info@managetransfer.it.

2. What data we process

If you send files:

  • the files you upload, with their names and sizes;
  • the optional message for the recipient;
  • your email address, if you provide it;
  • the download and management passwords, which are stored only in an irreversible encrypted form (hash): not even the operator can read them;
  • the date and time of the transfer and of your acceptance of the terms.

If you create an account or subscribe to a plan:

  • email address and password, stored only in encrypted form (hash);
  • chosen plan, subscription status and renewal date, Stripe customer and subscription IDs;
  • the list of your active transfers and the date you accepted the terms.

You enter your payment details (card or other method, billing address) directly on Stripe's pages: the controller does not receive or store your full card details.

If you receive files:

  • your email address, if the sender entered it to send you the link;
  • the number of downloads and the date of the last download, which are shown to the sender.

For all visitors:

  • the IP address and technical connection data (browser, date and time, page requested), recorded in the server logs for security purposes;
  • the technical cookies described in section 7.

The site does not use analytics, advertising or profiling tools and does not load resources from external services (fonts and scripts are hosted on the site itself).

Please do not upload files containing health data or other special categories of personal data about other people unless you have a valid legal basis to do so.

3. Why we process it and on what legal basis

  • Providing the service: storing the files, protecting them with a password, showing them to the recipient, sending the email with the link and letting you manage or delete the transfer. Legal basis: performance of the service you requested (Art. 6(1)(b) GDPR).
  • Managing your account and subscription: logging in, password recovery, activating, renewing and canceling your plan through Stripe. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
  • Security and abuse prevention: limiting the number of emails sent from the same IP address, protecting the site from attacks and handling reports of illegal content. Legal basis: the controller's legitimate interest in keeping the service secure (Art. 6(1)(f) GDPR).
  • Legal obligations: keeping accounting and tax records of payments and responding to requests from the competent authorities. Legal basis: legal obligation (Art. 6(1)(c) GDPR).

The data required by the form is necessary to use the service. Optional fields, such as email addresses and the message, can be left empty.

4. Other people's email addresses

If you enter a recipient's email address, we use it only to send them the link to the transfer, once, and we show it to you on the management page. We do not use it for any other purpose and do not share it with third parties. Whoever enters it confirms they are entitled to do so.

5. How long we keep the data

  • Files, file names, message, email addresses and encrypted passwords: until the expiry chosen by the sender (from 1 to 90 days) or until early deletion from the management page. After expiry they are deleted from the server automatically.
  • Incomplete transfers: deleted within 24 hours.
  • Account data: for as long as the account exists. You can delete it at any time from the "My account" page once your subscription has ended.
  • Payment records: for 10 years, as required by Italian tax and civil law (Art. 2220 of the Civil Code).
  • IP address used for the anti-spam limit: 1 hour.
  • Server technical logs: for the period set by the hosting provider, normally no longer than a few months.

6. Who we share the data with

The data is stored on the servers of Mochahost, which provides the site's hosting and email service and acts as data processor on behalf of the controller. The data is not sold or shared with anyone else, except for requests from authorities as required by law.

Payments are handled by Stripe Payments Europe, Ltd. (Ireland), which processes payment data as an independent controller for its own legal and anti-fraud obligations and as a processor otherwise, according to its own policy (stripe.com/privacy). Stripe may transfer some data to the United States under the EU-U.S. Data Privacy Framework and the standard contractual clauses approved by the European Commission.

The files and the message are visible to the people the sender gives the link and password to.

The data is processed within the European Union. Should a transfer outside the EU become necessary in the future, it will only take place with the safeguards required by the GDPR.

7. Cookies

The site uses only two technical cookies, created only when needed:

  • mt_session: created when you log in to your account or enter a transfer password, and keeps you signed in. It lasts up to 30 days, or until you log out.
  • mt_lang: created only if you choose the site language manually (IT/EN), and remembers your choice for one year.

As these are technical cookies needed for the service to work or to remember a choice you made, they do not require your consent. The site does not use profiling or third-party cookies. When you pay you are taken to Stripe's pages, which use their own cookies according to their own policy.

8. Security

Files are stored under random names in a folder that cannot be accessed directly from the web, they can only be downloaded with the link and the correct password, and passwords are stored only in encrypted form. We recommend using the site over a secure connection (https) and choosing strong passwords.

9. Your rights

At any time you can ask the controller to access, correct or delete your data, restrict its processing, object to processing based on legitimate interest, or receive it in a readable format (Articles 15-22 GDPR). You can also delete your files immediately from the management page. To exercise your rights, write to info@managetransfer.it.

If you believe the processing of your data breaches the GDPR, you can lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or with the supervisory authority of your country.

10. Changes

This policy may be updated. The version in force is always the one published on this page, with the date of the last update.

© 2026 managetransfer.it · Files are deleted automatically when they expire
Terms and conditionsPrivacy