PRIVACY POLICY

Privacy and Data Protection at airportshuttles24.com

This Privacy Policy explains how Flaxoo SIA LLC collects, uses, shares, secures, and retains personal data when you browse, create an account, request or manage a transfer, or contact us.

Transparent data handling GDPR rights explained International safeguards covered
Last updated 22 July 2026

This notice applies when you browse the website, create an account, make or manage a booking, or contact us.

Update note Policy maintenance

We will update this notice when our processing, service providers, products, or legal obligations materially change.

Privacy Policy in Detail

This notice follows the transparency principles of the EU General Data Protection Regulation and explains our role, processing purposes, safeguards, and your choices.

1. Controller and Scope

Flaxoo SIA LLC, registration number 40103399358, VAT number LV40103399358, Grostonas iela 19-36, Riga, LV-1013, Latvia, is the data controller for the booking platform and website available through airportshuttles24.com. This policy applies when you browse, register, request or manage a booking, pay through the platform, communicate with support, submit a review, or otherwise interact with us. A transport Provider may be a separate controller for data it needs to operate the journey, comply with transport law, manage its driver and vehicle, or handle a claim.

2. Personal Data We Collect

Depending on your interaction, we collect identity and contact details; account and authentication data; pickup, destination, date, time, flight or train and booking details; passenger count, luggage, child-seat, accessibility and service requests; payment status, transaction reference and billing data; communications, call notes, complaints and reviews; marketing preferences; and technical data such as IP address, browser, device, language, timestamps, referral pages, security events, consent records and website interactions. Payment providers normally process full card credentials directly; we receive the transaction result and limited payment metadata.

3. Sources of Data and Other Passengers

We receive data directly from you, from a person or travel agent booking for you, from transport Providers and drivers, payment and fraud-prevention providers, customer-support channels, publicly available flight or route sources, and technical services used to operate the platform. If you give us another passenger’s data, you confirm that you are authorised to do so and will provide that person with this policy. Please give us only information that is relevant to the booking.

4. Purposes and Lawful Bases

We process data to quote, arrange, confirm, take payment for, support, amend and complete bookings; create and secure accounts; communicate operational information; verify transactions and prevent fraud; investigate complaints, incidents and legal claims; maintain records and meet tax, accounting, transport, sanctions and regulatory duties; improve reliability, accessibility and customer service; and send marketing where permitted. The lawful basis is performance of a contract or steps requested before a contract, compliance with legal obligations, our legitimate interests in operating and protecting the service and resolving disputes, consent where required, and the establishment, exercise or defence of legal claims.

5. Accessibility and Sensitive Information

A request concerning mobility, health, disability, assistance animals, or another accessibility need may reveal special-category data. Provide only what is necessary for safe and suitable transport. We process this information with explicit consent where required, to protect vital interests in an emergency, to establish or defend claims, or under another lawful condition available under applicable law. Relevant details are shared only with staff and Providers who need them to arrange the service.

6. Who Receives Personal Data

We disclose the minimum necessary data to the transport Provider and driver; payment, banking, fraud and refund providers; hosting, cloud, security, communications, mapping, customer-support and analytics suppliers; professional advisers, auditors and insurers; group companies providing central services; and competent courts, regulators, police, tax or other authorities where legally required. Data may also be disclosed in a genuine corporate transaction subject to confidentiality and lawful safeguards. We do not sell personal data. Providers acting for us are bound by data-processing and security obligations.

7. International Transfers

Some Providers or technology suppliers may process data outside Latvia or the European Economic Area, particularly when a transfer takes place abroad or a global cloud, payment, communications, or support service is used. Where EU data-protection law requires a transfer safeguard, we rely on an adequacy decision, approved standard contractual clauses, binding corporate rules where applicable, or a specific lawful exception. Supplementary technical and organisational measures are used where appropriate. Contact us to request information about the safeguard relevant to a transfer.

8. Retention

We keep personal data only for as long as necessary for the purpose collected and to meet legal, tax, accounting, insurance, fraud-prevention, complaint and limitation-period requirements. Retention depends on the record: booking and transaction records are kept for the applicable statutory period; account data while the account is active and for a reasonable period afterward; support and claim records until resolution and expiry of relevant claims; security logs for a proportionate investigation period; and consent records while needed to demonstrate compliance. Data is then deleted, securely destroyed, or irreversibly anonymised.

9. Security and Confidentiality

We use risk-based technical and organisational safeguards including access controls, authentication, secure transmission where supported, environment separation, backups, logging, supplier controls, confidentiality obligations, and incident-management procedures. Access is limited to people who need the data for authorised work. No internet service can guarantee absolute security. Keep account credentials confidential, use a unique password, and tell us promptly if you suspect unauthorised access or a fraudulent communication.

10. Your Data Protection Rights

Subject to legal conditions and exceptions, you may request access to your personal data; correction of inaccurate data; erasure; restriction; portability of data you provided; and information about recipients. You may object to processing based on legitimate interests and object at any time to direct marketing. Where processing relies on consent, you may withdraw it at any time without affecting earlier lawful processing. You may also ask for human review where a decision based solely on automated processing produces legal or similarly significant effects. We normally respond within one month and may verify identity before acting.

11. Marketing, Reviews and Communications

Booking confirmations, pickup information, security messages, receipts, service updates and responses to your request are operational communications and are not marketing. We send promotional email, SMS or similar messages only where consent or another lawful permission applies. You can unsubscribe using the message link or by contacting us. We may still send necessary service communications. Reviews and feedback may be published only in the form and scope explained when collected; ask us if you want a published review reassessed.

12. Cookies and Online Technologies

We use necessary browser storage for sessions, security, language, booking continuity and consent records. Optional analytics or advertising technologies are used only when configured and permitted by your choice. The Cookies Policy identifies current categories, purposes, examples, durations and controls. You can reject or withdraw consent for non-essential technologies without losing access to core information, although blocking essential storage may prevent requested booking or account functions from working.

13. Children and Automated Decisions

The booking account and payment service is intended for adults. A parent, guardian or authorised adult may provide a child passenger’s details when arranging transport and should provide only what is necessary for safety, capacity and legal child-restraint requirements. We do not knowingly invite children to create accounts independently. We do not ordinarily make decisions producing legal or similarly significant effects solely by automated means. If that changes for a specific service, we will provide the required information and safeguards before the processing applies.

14. External Services and Independent Controllers

The website may link to or integrate a Provider, payment service, map, social network, app store or other third-party service. That organisation may determine its own processing purposes and is responsible for its privacy notice. Review the notice presented by the relevant third party. Our policy does not govern processing independently controlled by another organisation, but we will assist with identifying the relevant recipient where reasonably possible.

15. Contact, Complaints and Updates

For a rights request or privacy question, email info@airporttaxis24.com or write to Flaxoo SIA LLC at Grostonas iela 19-36, Riga, LV-1013, Latvia. Describe the request and relevant booking or account, but do not email full payment-card details or unnecessary identity documents. You may lodge a complaint with the Latvian Data State Inspectorate at www.dvi.gov.lv or with the supervisory authority where you live or work. We may update this policy prospectively; the “Last updated” date identifies the current version.

Exercise a Privacy Right or Ask a Question

Tell us which right or processing activity your request concerns and include the relevant booking or account reference where available. We may need to verify your identity securely.