Privacy Policy

Last updated: 21 August 2026.

1. Data controller

  • Data controller: Jose Manuel Pajaro Rodríguez.
  • Trading name: VTC O Pino.
  • Tax identification number (NIF): 78794821-H.
  • Address: Avda. de Lugo, No. 19, entrance 1, 2nd floor, apartment B, 15821 O Pino, A Coruña, Spain.
  • Email: info@vtcopino.com.
  • Telephone: +34 624 57 86 08.

2. Applicable legislation

Personal data will be processed in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), Spanish Organic Law 3/2018 on Personal Data Protection and Guarantee of Digital Rights and any other applicable legislation.

3. Personal data processed

VTC O Pino may process the following categories of personal data:

3.1. Identification and contact details

  • First name and surname.
  • DNI, NIF or another identification document.
  • Home address.
  • Telephone number.
  • Email address.
  • Details of the represented person, where applicable.

3.2. Booking request and journey details

  • Pick-up and destination addresses.
  • Coordinates and geographical information required to calculate the route.
  • Requested date and time.
  • Estimated distance and duration.
  • Number of passengers.
  • Selection of the “Luggage Only” option.
  • Information about luggage or service requirements.
  • Flight, train or ferry number, where provided.
  • Comments entered by the applicant.
  • Status of the request, approval, rejection, change or cancellation.

3.3. Contractual and invoicing information

  • Booking reference.
  • Information included in the electronic contract.
  • Price, taxes and calculation criteria.
  • Information required to issue invoices.
  • Communications and incidents connected with the service.

3.4. Payment-related information

  • Amount and currency.
  • Transaction identifier.
  • Pre-authorisation status.
  • Amount available for capture.
  • Capture, cancellation or refund status.
  • Card brand and last digits, where provided by Stripe.
  • Information required to prevent fraudulent transactions.

The complete card details and security code are entered directly into Stripe’s secure payment environment. VTC O Pino does not receive or store the complete card number or its CVC or CVV security code.

3.5. Technical information

  • IP address.
  • Date and time of access.
  • Browser and device information.
  • Technical and security logs.
  • Cookies and similar technologies, in accordance with the Cookies Policy.

4. Purposes of processing

Personal data may be processed for the following purposes:

  • Responding to questions and information requests.
  • Calculating routes, distances, estimated journey times and prices.
  • Receiving and reviewing booking requests.
  • Requesting a pre-authorisation through Stripe.
  • Checking the availability and legal and operational feasibility of the service.
  • Manually approving or rejecting the request.
  • Capturing the authorised amount when the request is approved.
  • Cancelling the pre-authorisation when the request is rejected.
  • Managing payments, refunds, incidents and complaints.
  • Generating the electronic contract in PDF format.
  • Confirming and providing the contracted service.
  • Sending emails and communications connected with the journey.
  • Issuing invoices and complying with accounting and tax obligations.
  • Communicating the legally required information to the Register of Communications for Private Hire Vehicle Services.
  • Preventing fraud, abuse, unauthorised access and security incidents.
  • Responding to data protection requests and requirements from public authorities.

5. Legal grounds for processing

5.1. Pre-contractual measures and performance of the contract

The processing required to calculate the price, manage the request, obtain the pre-authorisation, approve or reject the service, capture the amount, generate the contract and provide the transport service is based on taking pre-contractual measures requested by the data subject and, once the booking is confirmed, on the performance of the contract.

5.2. Compliance with legal obligations

The processing of contractual, tax, accounting and transport information is based on compliance with the legal obligations applicable to VTC O Pino.

This includes mandatory communications to the RVTC, document retention, invoice issuance and responding to requests from competent authorities.

5.3. Legitimate interests

VTC O Pino may process certain information to protect the security of the website, prevent fraud, verify transactions, manage complaints and establish, exercise or defend legal claims.

These processing activities will be carried out in a manner that ensures that the rights and freedoms of data subjects do not override those legitimate interests.

5.4. Consent

Where processing requires consent, such as certain non-essential cookies or marketing communications, consent will be requested separately and may be withdrawn at any time.

Withdrawal of consent will not affect the lawfulness of processing carried out before it was withdrawn.

6. Mandatory information

Information identified as mandatory is required to process the request and formalise the transport contract.

If this information is not provided or is inaccurate, VTC O Pino may be unable to calculate the service, review the request, process the pre-authorisation, confirm the booking or comply with its legal obligations.

Users should not enter unnecessary sensitive information in the comments field.

7. Sources of personal data

Personal data is mainly obtained from:

  • The person completing the booking form.
  • The person contacting VTC O Pino by email, telephone or WhatsApp.
  • Stripe, in connection with the pre-authorisation, capture, cancellation or refund status.
  • Mapping services used to obtain addresses, coordinates, routes, distances and estimated journey times.
  • The WooCommerce and WordPress systems used to manage the request.
  • VEO Transfer and the RVTC, where it is necessary to check or manage a transport communication.

If a person submits a request on behalf of someone else, they must be authorised to provide the necessary information and must inform the affected person about this Privacy Policy.

8. Recipients and service providers

Personal data may be processed by or communicated to the following recipients where necessary:

8.1. Stripe

Stripe processes the information necessary to manage the pre-authorisation, capture, cancellation, refund, payment authentication and fraud prevention.

Stripe may act as a data processor or as an independent data controller for certain processing connected with payments, security and its legal obligations. Further information is available in the Stripe Privacy Policy.

8.2. VEO Transfer and the RVTC

VTC O Pino uses VEO Transfer as the technical platform for communicating services to the Register of Communications for Private Hire Vehicle Services.

Only the information required by law will be communicated, such as:

  • The service provider’s tax identification details.
  • The intermediary’s identification, where applicable.
  • Vehicle registration number.
  • Place, date and time of the contract.
  • Place, date and time at which the service begins.
  • Place and expected date on which the service ends.

As a general rule, this communication does not include the passenger’s name, identification number, home address, telephone number or email address, unless required by applicable legislation or a valid request from a competent authority.

8.3. Mapping services

Addresses, coordinates, routes and distances may be processed using Google Maps Platform or other mapping services used by the website.

These providers may receive technical information, addresses or coordinates required to provide their services, in accordance with their respective terms and privacy policies.

8.4. Technical service providers

The following providers may also access personal data under the instructions of VTC O Pino and subject to the appropriate safeguards:

  • Website hosting providers.
  • Email service providers.
  • Maintenance, security and backup providers.
  • Tools used to manage WordPress, WooCommerce and bookings.
  • Accounting, tax or legal advisers where necessary.

8.5. Public authorities

Personal data may be communicated to tax authorities, transport authorities, law enforcement agencies, courts, tribunals or other public bodies where there is a legal obligation or valid official request.

9. International data transfers

Certain technology providers, particularly Stripe and services associated with Google, may process personal data outside the European Economic Area.

Where an international data transfer takes place, the safeguards recognised by the GDPR will be applied, including adequacy decisions, Standard Contractual Clauses approved by the European Commission or other legally valid mechanisms.

Further information can be obtained from the privacy policies of the relevant providers.

10. Data retention

Personal data will be retained for as long as necessary to fulfil the purpose for which it was collected.

  • Enquiries: for as long as necessary to respond and manage any related issue.
  • Unconfirmed requests: for as long as necessary to manage the pre-authorisation, rejection, release of the amount and any related complaint.
  • Confirmed bookings and contracts: throughout the provision of the service and subsequently for the statutory retention and limitation periods.
  • Commercial and accounting documentation: for the periods required by law, which may be up to six years.
  • Tax information: for the applicable statutory limitation periods.
  • RVTC communications: for the periods established by transport legislation and the relevant register.
  • Security information: for as long as necessary to investigate incidents and establish, exercise or defend legal claims.
  • Information processed on the basis of consent: until consent is withdrawn, without prejudice to any retention necessary to demonstrate that consent was validly obtained.

Once the relevant retention period has ended, personal data will be deleted or kept blocked solely for the purpose of meeting possible legal liabilities.

11. Automated decision-making

Booking requests are approved or rejected manually by VTC O Pino. VTC O Pino does not make decisions based exclusively on automated processing that produce legal effects concerning the applicant.

Stripe may use automated authentication, security and fraud prevention systems in accordance with its own obligations and policies. A transaction rejected by Stripe may prevent the booking from being confirmed.

12. Data protection rights

Data subjects may exercise the following rights:

  • Access: to obtain confirmation as to whether their personal data is being processed and access that data.
  • Rectification: to request the correction of inaccurate personal data.
  • Erasure: to request the deletion of personal data where legally applicable.
  • Objection: to object to certain processing activities.
  • Restriction: to request the restriction of processing in the circumstances provided by law.
  • Data portability: to receive personal data in a structured format where applicable.
  • Withdrawal of consent: to withdraw previously granted consent at any time.
  • Rights relating to automated decisions: in the circumstances recognised by the GDPR.

These rights may be exercised by submitting a request to:

  • Email: info@vtcopino.com.
  • Postal address: Avda. de Lugo, No. 19, entrance 1, 2nd floor, apartment B, 15821 O Pino, A Coruña, Spain.

The request should identify the right being exercised and provide the information necessary to verify the applicant’s identity where there are reasonable doubts concerning that identity.

13. Complaints to the Spanish Data Protection Agency

If a person considers that their personal data has not been processed correctly, they may lodge a complaint with the Spanish Data Protection Agency:

https://www.aepd.es/

Data subjects are encouraged to contact VTC O Pino first at info@vtcopino.com so that the matter can be investigated and, where possible, resolved.

14. Security

VTC O Pino implements reasonable technical and organisational measures to protect personal data against loss, alteration, unauthorised access or disclosure.

However, no system connected to the Internet can guarantee absolute security. Users should avoid sending unnecessary or particularly sensitive information through free-text fields.

15. Children

The booking form is not intended for use by children acting independently as the contracting party.

Bookings involving children must be made or authorised by their parents, guardians or legal representatives.

16. Communications by email, telephone or WhatsApp

When a person contacts VTC O Pino by email, telephone or WhatsApp, their personal data will be used to respond to the enquiry, manage the request and send any communications required in connection with the service.

Use of WhatsApp also involves the processing of personal data by its provider in accordance with its own terms and privacy policy.

17. Cookies

Information about cookies, analytics services and similar technologies is available in the Cookies Policy.

18. Changes to this Privacy Policy

VTC O Pino may amend this Privacy Policy to reflect legal, technical or operational changes affecting the service.

Where changes are significant, users will be informed through appropriate means. The date of the latest revision will appear at the beginning of this page.

1234

Preparing secure authorization…