This privacy policy describes how PrivateDrive (MHIRA PRIV8DRIVE SASU, RCS Paris 989 823 802) collects, uses, and protects your personal data in accordance with the General Data Protection Regulation (GDPR, EU Regulation 2016/679) and applicable French data protection laws. Last updated: 20 May 2026.
When using our service, we collect the following data: first and last name, email address, phone number, pickup and destination addresses, payment information (securely processed by Stripe, never stored on our servers), flight number (optional), passenger preferences (child seat, accessibility), browsing data (cookies, see dedicated section), booking history, and WhatsApp/SMS conversations within the scope of customer support.
Your data is used to: process and manage your transportation bookings, send you confirmations and updates via email, WhatsApp and SMS, assign a chauffeur and monitor your flight, improve our services and your user experience, prevent fraud (anti-bot analysis, payment validation), and comply with our legal and accounting obligations.
The processing of your data is based on: the performance of the transportation contract (Article 6.1.b of GDPR) for operational booking data, your consent (Article 6.1.a) for non-essential cookies and marketing communications, legitimate interest (Article 6.1.f) for fraud prevention and service security, and our legal obligations (Article 6.1.c) for accounting and tax retention.
Your personal data is retained according to the following durations: accounting data (invoices, payments): 10 years in accordance with Article L.123-22 of the French Commercial Code; booking data (chauffeur PII, addresses, flights): 5 years after last service, then anonymisation; browsing data and funnel analytics: 90 days, then anonymisation; WhatsApp/SMS conversations: 3 years for customer service traceability; security logs: 6 months. Upon expiry of these durations, your data is permanently deleted or anonymised.
Under Articles 15 to 22 of GDPR, you have the following rights: access, rectification, erasure (right to be forgotten), restriction of processing, data portability, objection, and right to withdraw consent at any time. To exercise these rights, from your logged-in client area at /ride/dashboard use the "Export my data" and "Delete my account" functions. Otherwise contact us at contact@privatedrive.co. Response within 30 days maximum. You may also lodge a complaint with the CNIL, the French data protection authority (3 Place de Fontenoy, 75007 Paris, www.cnil.fr).
To provide our service, we rely on the following subprocessors, selected for their technical and organisational guarantees: Stripe Payments Europe Ltd (Ireland) for payment processing; Twilio Inc. (United States, Standard Contractual Clauses) for SMS and WhatsApp Business; Google Ireland Limited / Google LLC (United States, DPF + SCC) for Google Tag Manager, Google Analytics 4, Google Maps Platform, and Google Ads; Sentry Inc. (United States, Standard Contractual Clauses) for error monitoring; Sendinblue/Brevo (France) for transactional email; Cloudflare Inc. (United States, DPF) for CDN and DDoS protection; MongoDB Atlas hosted at OVH (Roubaix, France) for the database; OVH SAS (France) for application hosting. The full list can be provided upon request at contact@privatedrive.co.
Some subprocessors process your data from the United States (Twilio, Google, Sentry, Cloudflare). These transfers are governed by the Standard Contractual Clauses adopted by the European Commission (Decision 2021/914) and, where applicable, by the Data Privacy Framework (DPF) to which these companies have adhered. We do not authorise any transfer to a third country lacking adequate safeguards within the meaning of Articles 44 to 49 of GDPR.
Essential cookies support authentication, language preferences, consent and security. Analytics and advertising are optional, disabled by default and offered separately. With your analytics consent, pd_analytics_visitor identifies a browser for at most 180 days from creation; pd_analytics_session distinguishes sessions and expires after 30 minutes of inactivity. The Google Analytics tag may then load on public pages and use its measurement cookies. Navigation events and eligible purchases may be sent to Google Analytics from the browser or our server using pseudonymous identifiers. The data we prepare for this measurement does not include customer contact details, form contents or journey addresses. For some eligible new purchases, the amount excluding tax and the tax amount are included in the purchase event. If you allowed audience measurement before payment, our server may record the purchase in Google Analytics even after you close the page. The temporary link between your consent and that purchase remains valid for up to 48 hours and is then automatically deleted. A control cookie, valid until the same expiry, lets your browser send a withdrawal request. Once our server receives that request, it blocks sends that have not yet started; it does not cancel a send already started or data already transmitted. If you are offline, the request will be retried when the site can communicate with our server again. Google Ads and the Google Tag Manager container remain disabled. You can accept, reject or change your choices through “Manage cookies” in the footer. Withdrawal stops optional collection in your browser and deletes the relevant measurement identifiers; sending the withdrawal request to our server follows the conditions described above. Without cookies or identifiers, opening a public page notifies our team of a visit (country, page, referring site and device type); your IP address is used only to filter out bots, our team and duplicates, held in memory for 30 minutes and never stored. This signal is not sent if you reject audience measurement.
We implement appropriate technical and organisational measures (TLS 1.3 encryption in transit, bcrypt hashing for credentials, network isolation, encrypted backups, access logs, principle of least privilege, regular security audits). In the event of a data breach likely to affect your rights and freedoms, we commit to notifying the CNIL within 72 hours and informing you in the shortest possible timeframe in accordance with Articles 33 and 34 of GDPR.
For any question regarding the protection of your personal data, you can contact us at: contact@privatedrive.co. Response within 30 days maximum.