Last updated: 07 June 2026
Data controller: Rapid Airport Transfers
Registered address: Cardinal Point, Park Road, Rickmansworth WD3 1RE
Contact: contact us · 01923 88 2424
Welcome to Rapid Airport Transfers. We are committed to protecting your personal data and your right to privacy. This policy explains, in plain English, what data we collect, how we use it, who we share it with, how long we keep it, and the rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
By booking a transfer or using our website, you consent to the data practices described below. If anything is unclear, please contact us — we will explain in more detail or take any action you ask of us within the time limits set out in this policy.
We only collect personal information that is necessary to operate, deliver and bill the airport transfer service you have booked. The information we may collect includes:
- Personal identifiers: Your full name, email address, mobile number, and pickup / drop-off address. For corporate bookings we also collect company name, billing contact, and (optionally) cost-code or PO reference.
- Booking details: Pickup and drop-off locations, flight number where applicable, journey date and time, number of passengers, luggage count, vehicle class, and any notes you provide (e.g. child-seat requirements, accessibility needs).
- Payment information: Card details are processed by Stripe, our PCI-DSS Level 1 compliant payment processor. We never see or store your full card number on our servers — we only retain a tokenised reference for refunds, alongside the last 4 digits and card brand for reconciliation.
- Website usage data: When you visit our website we automatically collect technical information including your IP address, browser type and version, operating system, referring URL, and pages visited. This is collected through server logs and analytics cookies (where you have given consent).
- Communications: Records of phone calls (we do not record audio by default), text messages and emails between you and our dispatch team, so we can resolve any disputes about booking details.
We use the information we collect strictly for the following purposes:
- To accept, confirm and deliver your airport transfer booking
- To allocate a PHV-licensed chauffeur to your journey and share the necessary contact details with that driver
- To process payment, issue receipts, and (for corporate accounts) raise monthly itemised invoices
- To monitor your inbound flight against the live airline feed so we can adjust pickup timing automatically if your flight is delayed
- To send essential booking communications: confirmation emails, the driver-allocation email the afternoon before pickup, and any necessary updates about your booking
- To comply with legal, regulatory and licensing obligations (e.g. Three Rivers District Council PHV licensing record-keeping)
- To improve our website and service through aggregated, anonymised analytics
We do not sell your data to third parties. We do not use your data for cross-context behavioural advertising. We do not enroll you in marketing communications without an explicit opt-in tick at the time of booking.
3. Legal basis for processing
Under UK GDPR Article 6, we rely on the following lawful bases for processing your personal data:
- Contract (Art. 6(1)(b)): Processing necessary to deliver the booking contract you have entered into with us — e.g. your name and pickup address are essential to provide the service.
- Legal obligation (Art. 6(1)(c)): Records we are required by law to keep, including PHV operator records (Three Rivers District Council licensing), HMRC tax records, and any data required to comply with police or court orders.
- Legitimate interests (Art. 6(1)(f)): Anonymised analytics, fraud prevention and security monitoring, after a balancing test against your privacy interests.
- Consent (Art. 6(1)(a)): Optional analytics cookies and any future marketing communications — you may withdraw consent at any time.
4. Who we share data with
Your data is shared only with the parties strictly necessary to deliver and bill your booking:
- The assigned chauffeur: Receives your name, mobile number, pickup & drop-off addresses, vehicle class and any pickup-specific notes (e.g. terminal, flight number, child seat).
- Stripe (payment processor): Processes your card payment. Stripe is GDPR-compliant and PCI-DSS Level 1. See stripe.com/gb/privacy.
- Email service: SendGrid / your email provider, used to deliver booking confirmations and driver-allocation emails.
- Live flight data provider: Used to monitor your inbound flight where you have provided the flight number.
- Three Rivers District Council: Our PHV licensing authority, who may request operator booking records as part of routine licensing inspections.
- Law enforcement: Where we are legally required to disclose data in response to a valid court order, police request, or HMRC tax enquiry.
We do not share your data with advertising networks, data brokers, social-media platforms, or any third party for marketing purposes.
5. How long we keep data
We retain personal data only for as long as is necessary for the purposes set out in this policy, after which it is securely deleted or anonymised:
- Booking records: Retained for 6 years after the journey to comply with HMRC tax record-keeping requirements (Finance Act 2008 Schedule 36).
- Payment tokens (Stripe): Retained for 7 years to support refund requests, chargeback disputes and PCI-DSS audit trail.
- PHV operator records: Retained for 2 years after the booking date for licensing inspection purposes.
- Email correspondence: Retained for 2 years from the date of the last message, unless related to an unresolved dispute or complaint.
- Server logs & analytics: Anonymised after 30 days; aggregated reports retained indefinitely with no personally identifiable information.
- Marketing consent records: Retained for as long as your consent is active, plus 1 year after withdrawal as evidence of compliance.
6. International data transfers
Our primary servers, dispatch system and business operations are based in the United Kingdom. Personal data is processed primarily in the UK. The following sub-processors may transfer data outside the UK:
- Stripe (Ireland & United States) — payment processing. Stripe operates under the EU-US Data Privacy Framework and the UK Extension to the DPF.
- Google (Ireland & United States) — Maps Places Autocomplete (only the address text you type) and analytics. Subject to the UK International Data Transfer Addendum.
- SendGrid / email provider — transactional booking emails. Subject to UK GDPR Standard Contractual Clauses.
All international transfers are protected by appropriate safeguards as required under UK GDPR Article 46 — usually the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.
We implement reasonable and proportionate technical and organisational measures to safeguard your personal data:
- Encryption in transit: All connections to our website and booking forms use HTTPS / TLS 1.2 or higher.
- Encryption at rest: Server databases are encrypted at the disk level by our hosting provider.
- Access control: Operational data (bookings, payment tokens) is accessible only to authorised dispatch and accounts staff with individual login credentials.
- Payment data isolation: Card payment data is handled entirely by Stripe under PCI-DSS Level 1. Our server never receives or stores raw card details.
- Driver vetting: All chauffeurs are DBS-checked and PHV-licensed by their local authority before being granted access to passenger data via our dispatch system.
- Breach notification: In the unlikely event of a personal data breach, we will notify the ICO within 72 hours and (where there is a high risk to your rights) notify you directly without undue delay.
8. Your UK GDPR rights
Under UK GDPR and the Data Protection Act 2018, you have the following rights regarding the personal data we hold about you. To exercise any of these rights, please contact us — we respond to all valid requests within 30 calendar days:
- Right to access (Art. 15): Request a copy of the personal data we hold about you, free of charge.
- Right to rectification (Art. 16): Ask us to correct any inaccurate or incomplete data.
- Right to erasure / right to be forgotten (Art. 17): Ask us to delete your personal data, subject to our legal obligation to retain certain booking records for HMRC and PHV licensing purposes.
- Right to restrict processing (Art. 18): Ask us to limit how we use your data in specific circumstances.
- Right to data portability (Art. 20): Receive your data in a structured, commonly used, machine-readable format (typically CSV or JSON).
- Right to object (Art. 21): Object to processing based on legitimate interests, including analytics.
- Right to withdraw consent (Art. 7): Withdraw consent for any processing based on consent (e.g. optional analytics cookies, marketing communications) at any time.
- Right not to be subject to automated decision-making (Art. 22): Our service does not involve solely automated decision-making with legal or similarly significant effects.
9. Cookies & tracking
Our website uses cookies and similar technologies to provide essential functionality and (with your consent) to help us understand how the site is used. We categorise them as follows:
- Strictly necessary & functional cookies (always on, no consent required):
- Session cookies, CSRF tokens, language preference
- Remembered booking details (pickup, drop-off) between pages of the same visit, so you do not have to re-enter them
- Tawk.to live chat and WhatsApp chat widget — these are communication channels you can use to reach our dispatch team, so they load regardless of consent (treated as functional / strictly necessary under UK GDPR guidance, since you have implicitly requested them by visiting a contactable business)
- Analytics cookies (require your explicit consent):
- Microsoft Clarity — session-recording analytics that helps us see where users get stuck on the booking form. Loads only if you click “Accept all” in the cookie banner. Microsoft Clarity anonymises IP addresses and respects Do Not Track. See Clarity's cookie list.
- Marketing / advertising cookies: None. We do not set advertising cookies, do not run remarketing campaigns, and do not share data with advertising networks or social-media pixels.
The cookie banner shown on your first visit lets you Accept or Decline non-essential analytics. Your choice is stored in your browser’s local storage and is honoured for 12 months, after which we will re-prompt you. You can change your preferences at any time using the “Cookie Preferences” link in our website footer — clicking it re-opens the banner so you can revise your choice.
If you click Decline, Microsoft Clarity never loads during your visit. The chat widgets continue to be available because they are communication tools you can use to contact us; if you would prefer the chat widgets did not load either, please contact us and we will assist on a case-by-case basis.
10. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations or industry best practice. The "Last updated" date at the top of this page indicates when the policy was last revised. Material changes (e.g. new sub-processors, changes to retention periods, new data subject categories) will be flagged with a banner on this page for at least 30 days. We recommend reviewing this page periodically.
11. Complaints & the ICO
If you have a complaint about how we have handled your personal data, please contact us first — we will respond and try to resolve the issue within 30 days. You also have the right to lodge a complaint directly with the UK supervisory authority:
- Information Commissioner's Office (ICO)
- Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
- Helpline: 0303 123 1113
- Website: ico.org.uk
You do not need to complain to us first — you can go directly to the ICO — but raising the issue with us usually results in a faster resolution.