Let's GO Transfer

PRIVACY POLICY

LETS GO TRANSFER APPLICATION

Version: 1.0 | Effective date: November 26, 2025

1. GENERAL PROVISIONS

1.1. Introduction

This Privacy Policy (hereinafter — "Policy") describes the data processing methods applied by VIKI KIMO PRO S.L. (NIF B75955716), registered at Avenida 348, No. 36, 1º, Castelldefels 08860, Barcelona, Spain (hereinafter — "Company", "we" or "our"), in connection with the use of our private airport transfer platform, available at www.letsgo-transfer.com, and mobile applications for iOS and Android (collectively referred to as "Service" or "Application").

LETS GO TRANSFER is a marketplace platform connecting passengers with professional drivers for private transfers and private transportation across Europe.

1.2. Contact Information

  • Data Controller: VIKI KIMO PRO S.L.
  • Legal address: Avenida 348, No. 36, 1º, Castelldefels 08860, Barcelona, Spain
  • NIF: B75955716
  • Email: info@letsgo-transfer.com

1.3. Legal Basis

This Policy has been developed in accordance with:

  • Regulation (EU) 2016/679 (GDPR)
  • Spanish Organic Law 3/2018 (LOPDGDD)
  • Spanish Law 34/2002 (LSSI-CE)

2. INFORMATION WE COLLECT

2.1. Categories of Personal Data

A. For Users (Passengers):

  • Profile data: name, email, phone number, password (encrypted), profile photo, preferred language.
  • Trip data: pickup and drop-off locations, date/time, flight information, number of passengers, luggage.
  • Payment information: card details (processed via Stripe/PayPal, we do not store full numbers), transaction history, billing data.
  • Technical data: IP address, device ID, phone model, OS version.
  • Geolocation: real-time GPS coordinates (while using the app) for vehicle dispatch and route tracking.

B. For Service Providers (Drivers):

  • Professional data: full name, NIF/NIE, driver's license details, VTC/Taxi license, insurance.
  • Vehicle data: make, model, license plate, photos, documents (ITV).
  • Financial data: bank account for payouts, tax information.
  • Geolocation: real-time GPS (including background) for order distribution.

2.2. Information from Third Parties

We may receive data from payment providers (transaction status), identity verification services, and social networks (when logging in via Facebook/Google).

3. HOW WE USE YOUR INFORMATION

We process your data on the following legal bases (under Art. 6 GDPR):

  • Performance of contract: to create accounts, process bookings and payments, connect drivers with passengers.
  • Legitimate interest: to prevent fraud, improve the service, ensure platform security.
  • Legal obligation: to comply with tax legislation and respond to authority requests.
  • Consent: to send marketing communications and use geolocation (where applicable).

4. DATA SHARING AND DISCLOSURE

4.1. Between Users

We share the passenger's name and meeting point with the driver. We share the driver's name, car make, license plate, and current location with the passenger to fulfill the service.

4.2. Service Providers (Third Parties)

We share data with trusted partners who assist in operating the Service:

  • Payment processing: Stripe, PayPal.
  • Cloud infrastructure: AWS, Google Cloud (EU servers).
  • Maps and navigation: Google Maps API.
  • Communications: Twilio, SendGrid (for SMS and email notifications).
  • Analytics: Google Analytics, Firebase.
  • Failure diagnostics: Sentry (EU region).

4.3. Crash and error reports

When an application or our service fails, a technical report about the failure is sent to Sentry so that we can find the cause. The reports are received and stored in the European Union, on de.sentry.io: a Sentry organisation is tied to its region when it is created and cannot be moved afterwards.

Before a report is sent we remove addresses, geographic coordinates, phone numbers, email addresses, card numbers and access tokens from it. Screenshots, the contents of the screen, session recording and native crash dumps are switched off and are never sent.

What a report does carry is the error itself and the place in the code where it happened, the version and build of the application, the device model and the operating system version, and the identifier of the order that was being handled. That identifier means nothing on its own, but in our own database it corresponds to you.

We have a data processing agreement with Sentry (version 5.1.0), and the data stays in the European Union.

4.4. Website analytics

The website counts how it is used, so that we know which pages are read and how many people get from a calculated price to a booking. None of it is sent until you accept cookies in the banner, and you can change that decision at any time through the Cookie Settings link in the site footer.

Each event says what happened and carries only what that step is measured by: the path of the page you were on, the price the calculator showed, the fact that an account was created, that a payment card was added, that an enquiry was sent and the class of vehicle it named, that a link to one of the app stores was followed, and - for a completed booking - the order number, the amount, the currency and the class of vehicle. The order number means nothing on its own, but in our own database it corresponds to you. Google Analytics adds by itself the technical data described above: the browser, the device and the IP address.

The addresses you type into the booking form - where you are picked up and where you are going - are not sent to analytics, in any event and in any form. Neither are their coordinates, your name, your phone number, your email address or your card details.

4.5. Legal Requirements

We may disclose data to law enforcement authorities if required by law, court order, or to protect the rights and safety of users.

5. INTERNATIONAL DATA TRANSFERS

Your data may be processed outside the European Economic Area (EEA). In such cases, we ensure data protection through Standard Contractual Clauses (SCC) approved by the European Commission, or other lawful mechanisms.

6. DATA RETENTION

We retain data for as long as necessary for the purposes stated in this Policy:

  • Active accounts: throughout the entire period of service use.
  • Tax records: 7 years (required by Spanish law).
  • Deleted accounts: personal data is deleted or anonymized within 30 days of the request, except for data we are legally required to retain.
  • Chat messages between passenger and driver: 1 year.
  • Route of a completed ride - where the car actually went: 1 year, or until an open claim about that ride is closed.

7. YOUR RIGHTS (GDPR)

As an EU data subject, you have the following rights:

  • Right of access: request a copy of your data.
  • Right to rectification: correct inaccurate data in your profile.
  • Right to erasure ("Right to be Forgotten"): request deletion of your account and data.
  • Right to restriction of processing: in cases provided by law.
  • Right to data portability: receive your data in JSON/CSV format.
  • Right to object: opt out of data processing for marketing purposes.

How to exercise your rights: email us at info@letsgo-transfer.com or use the "Data Management" feature in the app settings.

8. SECURITY

We use TLS 1.3 encryption for data transmission and AES-256 for storage. Access to data is strictly limited. Payment data is tokenized and complies with the PCI DSS standard.

9. COOKIES AND TRACKING TECHNOLOGIES

We use cookies (technical, analytical, and marketing) to operate the website and improve user experience. You can manage cookie settings in your browser or through our consent banner.

10. SPECIAL PROVISIONS

  • Spain: compliance with LOPDGDD, enhanced protection of minors' data.
  • California (CCPA): if you are a California resident, you have additional rights (right to know, right to delete, right to opt-out of data sales).

11. CONTACT

If you have questions about privacy, contact us:

  • Email: info@letsgo-transfer.com
  • DPO (Data Protection Officer): info@letsgo-transfer.com
  • Postal address: VIKI KIMO PRO S.L., Avenida 348, No. 36, 1º, Castelldefels 08860, Barcelona, Spain.

You also have the right to file a complaint with the supervisory authority — the Spanish Data Protection Agency (AEPD) at www.aepd.es.