Privacy policy

This page explains what personal data we process when you book a taxi, why, on what legal basis and for how long, under Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).

Data controller

The controller is the taxi operator that owns this site: ⚠️ EDITAR company name, tax ID ⚠️ EDITAR, address ⚠️ EDITAR (Toledo, Spain). For any privacy matter you can write to ⚠️ EDITAR (privacy email).

No data protection officer has been appointed: the circumstances that require one (art. 37 GDPR and art. 34 LOPDGDD) do not apply, as there is no large-scale processing and no special categories of data.

What data we process and why

Booking does not require an account: we ask only for the data strictly needed to provide the service, and we collect it from you (never from third parties). Name and mobile phone are required; email is optional, and your tax ID is only requested if you ask for an invoice.

What we do not do with your data

  • We do not create customer accounts or profiles: each booking stands alone.
  • We do not send marketing: only messages about the service you booked.
  • We do not sell or share your data for commercial purposes.
  • We make no automated decisions with legal effects and no profiling: prices come from public rates that are the same for everyone.
  • The service is not aimed at children under 14, who cannot make a booking.

Payment: Stripe

You enter your full card details directly into the secure forms of Stripe, the payment gateway (PCI DSS certified): they never reach our servers. We only store the amount, the transaction identifier and a non-sensitive reference (card brand and last 4 digits).

Stripe acts as a processor and, for payment fraud prevention, also as an independent controller under its own privacy policy.

Who accesses your data (processors)

We do not disclose your data to third parties except where legally required. To run the service we use providers that process data on the controller's behalf under art. 28 GDPR agreements:

  • Supabase — the service database, hosted in the European Union.
  • Vercel — web hosting and aggregated, cookieless analytics.
  • Stripe — payment processing (see previous section).
  • Resend — service emails (confirmations, reminders).
  • Mapbox — geocoding of pickup and destination addresses: it receives the address being looked up, never your name or contact details.
  • Cloudflare — content delivery network and anti-bot protection of the forms.
  • Sentry — technical error reporting, with personal data scrubbed before sending.
  • Holded — invoicing (only if you request an invoice).

International transfers

Some of these providers are US companies. Transfers rely on the EU-US Data Privacy Framework or on the European Commission's standard contractual clauses, depending on the provider (⚠️ EDITAR: per-provider verification and filing to be completed with legal counsel).

How long we keep your data

  • Booking identity data (name, mobile, email): anonymised 12 months after the service. The booking is kept afterwards only as a statistical and accounting record, with no identifiable person.
  • Invoicing data: 6 years, as required by commercial and tax law.
  • Technical logs: 30 days, and they never contain personal data.
  • The booking management link expires 24 hours after the service ends.

Your rights

You can exercise your rights of access, rectification, erasure, objection, restriction of processing and portability at any time by writing to ⚠️ EDITAR (privacy email).

As there are no user accounts, we verify your identity with your booking code and a match against the mobile or email used to book; if you no longer have the code, we will search by your mobile number and always reply to the mobile or email registered in the booking, never to a third party claiming them.

We reply within one month at most (art. 12.3 GDPR). If you request erasure and an invoice exists, invoicing data must be kept for 6 years by legal obligation: we anonymise everything else and tell you so expressly.

If you believe we have not handled your rights properly, you can lodge a complaint with the Spanish Data Protection Agency (AEPD, C/ Jorge Juan 6, 28001 Madrid).

Security

We apply technical and organisational measures proportionate to the risk: encrypted communications, role-based access control enforced in the database itself, an immutable audit log of sensitive actions and strict data minimisation (personal data never appears in URLs or technical logs).

If a security breach with risk to your rights ever occurred, we would notify the AEPD within 72 hours and, if the risk were high, you as well (arts. 33 and 34 GDPR).

Changes to this policy

Any change to this policy will be published here with its revision date. If a change affected processing already under way, we would notify you through the contact channels of your booking.