Privacy Policy
1. Controller and contact details
89 Transfers is a commercial service provided by Ramon Asen Pons Miralles, with registered address at Carrer d'Eusebi Estada, 29, 8ºA, Norte, 07004 Palma, Mallorca, Balearic Islands, Spain, NIF 43208755N.
For any privacy or data protection request, you can contact:
- Email: [email protected]
- Phone / WhatsApp: +34 871 15 36 69
2. Scope of this policy
This Privacy Policy explains how 89 Transfers processes personal data when you:
- visit our website;
- start, save, or complete a booking;
- contact us by email, phone, SMS, WhatsApp, or web forms;
- verify your phone number;
- pay online or choose to pay later;
- interact with cookies, analytics, or similar technologies.
This policy complements our Terms and Conditions and Cookie Policy.
3. Categories of personal data we process
Depending on how you use our services, we may process the following categories of personal data:
3.1 Booking and contact data
- full name;
- email address;
- phone number and country code;
- message or special requests you send to us.
3.2 Journey and service data
- pickup and drop-off locations;
- travel date and pickup time;
- one-way or round-trip selection;
- passenger counts, child seats, luggage extras, bike boxes, golf bags, bulky-item requests;
- flight information that you enter for airport pickups or returns.
3.3 Commercial and payment data
- booking reference, registration ID, lead ID, trip ID, fare, discounts, payment method;
- checkout status and payment confirmation data returned by our payment providers.
We do not store your full card number in our website or app. Online card payments are handled by Stripe or the payment infrastructure used by our booking backend.
3.4 Verification and anti-fraud data
- OTP challenge identifiers;
- verification channel used (for example SMS, WhatsApp, voice, or silent verification);
- verification status;
- rate-limit and abuse-prevention signals linked to session or IP scope.
3.5 Technical and device data
- IP address and request metadata processed for security, rate limiting, and fraud prevention;
- session identifiers used to keep your booking in progress;
- language preference;
- local browser storage used to keep the booking flow working;
- diagnostic, error, and performance events.
3.6 Communications and support data
- emails, calls, WhatsApp messages, or other messages exchanged with you about your booking or support request.
3.7 Evidence in case of disputes
If there is a dispute about driver attendance, waiting time, pickup performance, damage, or extraordinary cleaning, we may process supporting evidence such as timestamps, GPS presence records, photographs, or similar records that are reasonably necessary to establish the facts.
4. How we collect personal data
We collect personal data:
- directly from you when you fill in forms, start a booking, request support, or contact us;
- from your device and browser through cookies, local storage, session storage, logs, and similar technologies;
- from our booking backend and payment flows when you confirm a booking or complete checkout;
- from OTP and verification providers when a phone verification attempt is initiated or completed;
- from collaborating operators or drivers where necessary to perform your transfer or resolve an incident.
5. Purposes and legal bases
We process personal data for the following purposes and legal bases:
5.1 To take steps at your request and perform the contract
Legal basis: Article 6(1)(b) GDPR.
This includes:
- preparing quotes and fares;
- creating and managing bookings;
- creating leads and trip records in our booking backend;
- arranging pickups, returns, and driver coordination;
- communicating operational information about your booking;
- processing cancellations, changes, refunds, and no-show handling;
- providing customer support related to your transfer.
5.2 To verify your phone number and protect the booking flow
Legal basis: Article 6(1)(b) GDPR and, where applicable, Article 6(1)(f) GDPR (legitimate interest in fraud prevention, account integrity, and abuse prevention).
This includes:
- OTP delivery and verification;
- silent verification where supported by the provider and device;
- rate limiting and challenge-to-phone binding to prevent misuse or takeover.
5.3 To manage payments and prevent payment abuse
Legal basis: Article 6(1)(b) GDPR and Article 6(1)(f) GDPR.
This includes:
- creating payment sessions;
- validating checkout redirects;
- confirming payment status;
- storing limited payment-related booking data necessary to complete or verify the transaction.
5.4 To comply with legal obligations
Legal basis: Article 6(1)(c) GDPR.
This includes:
- accounting, tax, invoicing, and record-keeping obligations;
- responding to lawful requests from courts, regulators, law enforcement, or transport authorities;
- handling consumer rights or complaint obligations that apply to us.
5.5 To keep the website secure, stable, and technically functional
Legal basis: Article 6(1)(f) GDPR and, for storage/access on user devices, the rules explained in our Cookie Policy.
This includes:
- session management for incomplete bookings;
- security logging, rate limiting, and abuse detection;
- error monitoring and technical diagnostics;
- preserving the language and state of the booking flow.
5.6 To measure analytics or advertising performance
Legal basis: Article 6(1)(a) GDPR, where consent is required.
Analytics, advertising, or similar optional technologies are only activated on the basis explained in our Cookie Policy and consent platform.
6. Who receives personal data
We may share personal data with the following categories of recipients, strictly on a need-to-know basis:
- our booking and transport operations infrastructure providers;
- collaborating operators and drivers who need the booking details to perform the transfer;
- payment and checkout providers, including Stripe where applicable;
- OTP and verification providers used to verify phone numbers, including providers such as Vonage or Twilio and their supported channels;
- hosting, caching, and infrastructure providers, including Upstash Redis for temporary booking/session storage;
- Google services when you use maps or location autocomplete, and where consent is given, analytics or advertising services;
- Sentry or similar monitoring providers for technical error monitoring and, if consent is given, enhanced analytics/replay features;
- professional advisers, insurers, auditors, banks, or collection/legal representatives where reasonably necessary;
- courts, regulators, law enforcement, or competent authorities where required by law.
We do not sell your personal data.
7. International data transfers
Some of our service providers may process data outside the European Economic Area, including in the United States. Where that happens, we rely on an appropriate transfer mechanism under applicable law, such as:
- an adequacy decision where available;
- the European Commission's Standard Contractual Clauses;
- or another lawful safeguard recognized under the GDPR.
The specific mechanism may depend on the provider and service used at the relevant time.
8. How long we keep personal data
We keep personal data only for as long as necessary for the purposes described above and for the applicable legal retention periods.
Examples from our current website stack include:
- booking session data in Redis: up to 2 hours;
- trip session data in Redis: up to 1 hour;
- temporary success-session data in Redis: up to 20 minutes;
- OTP challenge bindings and attempt budgets: up to 15 minutes;
- local browser tokens used to restore phone verification: up to 2 hours;
- local browser hashes for already verified phones: up to 1 week;
- cookie consent records: according to the duration stated in our Cookie Policy.
Operational booking, invoicing, accounting, and complaint-handling records may be retained for longer where required by tax, accounting, consumer, transport, insurance, or limitation-period rules.
9. Whether you must provide your data
Some data is necessary for us to provide the service. If you do not provide required information such as pickup details, contact details, or payment/verification data where needed, we may not be able to confirm or perform your booking.
10. Automated decision-making
We do not use solely automated decision-making producing legal or similarly significant effects within the meaning of Article 22 GDPR through this website.
We do use automated technical checks such as pricing calculation, availability/time validation, fraud-prevention controls, and OTP verification workflows, but final service performance and customer support remain subject to human oversight.
11. Security measures
We apply technical and organizational measures appropriate to the nature of the data and the risk involved. These measures include, for example:
- HTTP-only secure session cookies in production;
- server-side booking storage instead of storing full booking data in cookies;
- session rotation in sensitive verification flows;
- request sanitization and validation;
- rate limiting for booking, contact, and OTP endpoints;
- access controls for the services we use.
No internet-based service can guarantee absolute security, but we work to reduce risk and respond appropriately to incidents.
12. Your rights
Subject to the conditions and limits under applicable law, you may request:
- access to your personal data;
- rectification of inaccurate data;
- erasure of your data;
- restriction of processing;
- objection to certain processing based on legitimate interests;
- data portability where applicable;
- withdrawal of consent at any time for processing based on consent.
To exercise your rights, contact [email protected]. We may need to verify your identity before processing your request.
13. Complaints
If you believe your data protection rights have been infringed, you may also lodge a complaint with the Spanish Data Protection Agency (AEPD) or with the supervisory authority in your habitual place of residence or work in the EU.
More information: https://www.aepd.es/
14. Cookies and similar technologies
Our use of cookies, local storage, session storage, and similar technologies is explained in our Cookie Policy. Where consent is required, you can manage it through our cookie preferences tools.
15. Changes to this policy
We may update this Privacy Policy from time to time to reflect legal, operational, or technical changes. The latest version published on our website will apply.
