Privacy policy
Last reviewed: 23 July 2026
This page explains what personal data we process when you book a taxi, why, on what legal basis and for how long, under Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
Data controller
The controller is the taxi operator that owns this site: ⚠️ EDITAR company name, tax ID ⚠️ EDITAR, address ⚠️ EDITAR (Toledo, Spain). For any privacy matter you can write to ⚠️ EDITAR (privacy email).
No data protection officer has been appointed: the circumstances that require one (art. 37 GDPR and art. 34 LOPDGDD) do not apply, as there is no large-scale processing and no special categories of data.
What data we process and why
Booking does not require an account: we ask only for the data strictly needed to provide the service, and we collect it from you (never from third parties). Name and mobile phone are required; email is optional, and your tax ID is only requested if you ask for an invoice.
| Processing | Data | Legal basis (art. 6 GDPR) | Retention |
|---|---|---|---|
| Booking management and provision of the service | Name, mobile, email (optional), language, pickup and destination (addresses and coordinates), flight number (optional), luggage and extras | Performance of a contract (6.1.b) | Identifying data is anonymised 12 months after the service |
| Online payment | Amount, payment identifier and, as a reference, card brand and last 4 digits — never the full number | Performance of a contract (6.1.b) | Linked to the booking; accounting records, 6 years |
| Invoicing (only if you request an invoice) | Tax ID, company name, amounts | Legal obligation (6.1.c): commercial and tax law | 6 years |
| Service notifications (confirmation, reminder, driver assigned) | Email or phone, booking language | Performance of a contract (6.1.b) — never marketing | Anonymised with the booking (12 months) |
| Security and fraud prevention | IP address, technical browser signals, request counters | Legitimate interest (6.1.f): protecting the service and preventing fraud | Technical logs: 30 days |
| Audience measurement and campaign attribution | Aggregated browsing data without cookies or personal identifiers; referring domain and campaign parameters of the booking | Legitimate interest (6.1.f): first-party channel measurement | Aggregated, non-identifiable data only |
What we do not do with your data
- We do not create customer accounts or profiles: each booking stands alone.
- We do not send marketing: only messages about the service you booked.
- We do not sell or share your data for commercial purposes.
- We make no automated decisions with legal effects and no profiling: prices come from public rates that are the same for everyone.
- The service is not aimed at children under 14, who cannot make a booking.
Payment: Stripe
You enter your full card details directly into the secure forms of Stripe, the payment gateway (PCI DSS certified): they never reach our servers. We only store the amount, the transaction identifier and a non-sensitive reference (card brand and last 4 digits).
Stripe acts as a processor and, for payment fraud prevention, also as an independent controller under its own privacy policy.
Who accesses your data (processors)
We do not disclose your data to third parties except where legally required. To run the service we use providers that process data on the controller's behalf under art. 28 GDPR agreements:
- Supabase — the service database, hosted in the European Union.
- Vercel — web hosting and aggregated, cookieless analytics.
- Stripe — payment processing (see previous section).
- Resend — service emails (confirmations, reminders).
- Mapbox — geocoding of pickup and destination addresses: it receives the address being looked up, never your name or contact details.
- Cloudflare — content delivery network and anti-bot protection of the forms.
- Sentry — technical error reporting, with personal data scrubbed before sending.
- Holded — invoicing (only if you request an invoice).
International transfers
Some of these providers are US companies. Transfers rely on the EU-US Data Privacy Framework or on the European Commission's standard contractual clauses, depending on the provider (⚠️ EDITAR: per-provider verification and filing to be completed with legal counsel).
How long we keep your data
- Booking identity data (name, mobile, email): anonymised 12 months after the service. The booking is kept afterwards only as a statistical and accounting record, with no identifiable person.
- Invoicing data: 6 years, as required by commercial and tax law.
- Technical logs: 30 days, and they never contain personal data.
- The booking management link expires 24 hours after the service ends.
Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction of processing and portability at any time by writing to ⚠️ EDITAR (privacy email).
As there are no user accounts, we verify your identity with your booking code and a match against the mobile or email used to book; if you no longer have the code, we will search by your mobile number and always reply to the mobile or email registered in the booking, never to a third party claiming them.
We reply within one month at most (art. 12.3 GDPR). If you request erasure and an invoice exists, invoicing data must be kept for 6 years by legal obligation: we anonymise everything else and tell you so expressly.
If you believe we have not handled your rights properly, you can lodge a complaint with the Spanish Data Protection Agency (AEPD, C/ Jorge Juan 6, 28001 Madrid).
Security
We apply technical and organisational measures proportionate to the risk: encrypted communications, role-based access control enforced in the database itself, an immutable audit log of sensitive actions and strict data minimisation (personal data never appears in URLs or technical logs).
If a security breach with risk to your rights ever occurred, we would notify the AEPD within 72 hours and, if the risk were high, you as well (arts. 33 and 34 GDPR).
Changes to this policy
Any change to this policy will be published here with its revision date. If a change affected processing already under way, we would notify you through the contact channels of your booking.