Privacy policy
In short: we collect your name, your phone number and — if you gave them — your email and flight number. They are needed to get you on the bus and to find you at the airport. We do not sell this data, we show no advertising, and we install no third-party trackers.
1. Who is responsible for your data
The controller of personal data within the meaning of the GDPR is the carrier: its registration details are not yet published on the site. A request about your data can be sent through any channel on the contact page.
We have not appointed a Data Protection Officer: the scale and nature of the processing do not fall under Art. 37 GDPR — we carry out no systematic large-scale monitoring and process no special categories of data.
2. What data we collect
Exactly those without which the trip cannot happen. The booking form has four fields, and two of them are optional.
- Full name
- Required. It goes onto the trip’s passenger list, which the carrier hands over at the border, and it must match your passport. It is also kept when the booking never happened — see the seventh row of the retention table below.
- Phone number
- Required. The only reliable way to find you at boarding and to warn you when the pickup time changes. Stored in international format — including when the booking never happened.
- Optional. We send no automated email — your confirmation is the ticket page, which opens as soon as you book. We keep the address for written correspondence: an invoice to a company or a request about your data.
- Flight number
- Optional. Dispatch sees it and can move the pickup time by hand if the plane is late; there is no automatic flight status tracking at present. Without it the departure simply runs to schedule.
- Seat, route, date, booking code
- Created by the system itself. Without them the ticket does not exist as an object.
- Technical server logs
- IP address, request time and browser type — recorded automatically, as on any site, and needed to diagnose faults and guard against abuse.
We do not collect: payment card details (payment happens at the driver, on the bank’s terminal — card details never pass through our site at all), passport details (you show those to the border officer in person), date of birth, home address or geolocation.
3. Why, and on what legal basis
- Performance of the carriage contract — Art. 6(1)(b) GDPR. Name, phone, seat, route and flight number are processed in order to sell the ticket, get you on the bus, warn you when the pickup time changes and meet you at the airport. Without this data the contract cannot be performed. The same article also covers STEPS TAKEN AT YOUR REQUEST PRIOR TO ENTERING INTO a contract: if you pressed «Confirm» and the seat turned out to be taken, we keep your enquiry on exactly that basis — there is no contract yet.
- Compliance with a legal obligation — Art. 6(1)(c) GDPR. The passenger list of an international trip is handed over at the request of the Ukrainian and Romanian border authorities; sales documents are kept as tax law requires.
- Legitimate interest — Art. 6(1)(f) GDPR. The technical server logs and the temporary seat hold are needed so that the site does not sell one seat twice and so that a failure can be investigated. The interest is limited to the security and availability of the service.
We do not process your data on the basis of “marketing consent” — because we send no mailings. If we call or write to you about the trip (a change of pickup time, the bus, the driver), that is part of the carriage contract, not advertising.
4. Cookies
There is not a single third-party advertising or analytics script on this site: no Google Analytics, no social network pixel, no retargeting system. That is also why there is no cookie consent banner — every cookie we set is strictly necessary.
| Cookie | What for | Lifetime |
|---|---|---|
| lang | The interface language you chose. Not httpOnly: the language switch reads it from the browser. | 1 year |
| gl_hold | The token by which we recognise that the chosen seat is held by you. httpOnly — page scripts cannot read it. The seat hold itself lasts 20 minutes and expires in the database; the cookie outlives it, but means nothing without a valid record. | 1 hour |
| gl_session | A staff member’s dispatch session. Never set for passengers at all. | 30 days |
| density · scale · panes · nav_shut · dsp_zoom · dsp_tray · dsp_help · dsp_full | The employee’s view preferences: row density, text size, pane widths, collapsed menu sections and board zoom. Set by the staff member themselves, from a control; not one of them is ever set for a passenger. | 1 year |
5. Who we share data with
- The driver of your trip — your name, seat and phone, so that the driver can call if you are not at boarding. Only for their own trip and only on the day of departure.
- Border and customs authorities of Ukraine and Romania — at their request, as part of the trip’s passenger list. This is a legal obligation of the carrier and cannot be refused.
- The hosting and database provider — as a processor, under a processing agreement. It has no right to use the data for its own purposes.
- The acquiring bank — when you pay the driver by card. That transaction bypasses our site: we see only that payment happened, and the amount.
We do not sell or pass data to advertisers, data brokers or other carriers.
6. How long we keep it
| What | How long | Why exactly that long |
|---|---|---|
| An active booking | until the travel date | That is the subject of the contract. |
| A completed trip: route, date, amount | the period set by tax law | In Ukraine primary documents are kept for at least 1095 days; on the Romanian side the period is set by RO accounting law. |
| Passenger contact details (name, phone, email) | until a deletion request | Needed so that you can find your booking and so that the loyalty fare applies. We delete them on request. |
| A cancelled booking | 90 days | Enough to settle a dispute about the cancellation; after that the data is not needed. |
| Technical server logs | up to 30 days | That is how long a typical diagnostic log lives. |
| The seat-hold record | 20 minutes | The period for which the seat is taken off sale. After that the record becomes void and is deleted. |
| An unfinished booking attempt | 90 days | Everything you had entered in the form when the booking could not be completed: name, phone and — if you gave them — email, flight number and your own note. So we can call you if a seat frees up. Deleted automatically. |
7. Where data is processed
The site and the database are hosted in data centres inside the European Union, so no transfer to third countries within the meaning of Chapter V GDPR takes place. The specific provider and region: not yet stated on the site.
8. Your rights
As a data subject you have the right to:
- know and obtain a copy of the data we hold about you (Art. 15);
- correct an inaccuracy — for example a misspelt name (Art. 16);
- request erasure — when the data is no longer needed for the trip and is not retained by law (Art. 17);
- restrict processing while a dispute about accuracy or legal basis is running (Art. 18);
- receive the data in a machine-readable format and pass it to another carrier (Art. 20);
- object to processing based on legitimate interest (Art. 21);
- lodge a complaint with a supervisory authority — in Ukraine that is the Parliamentary Commissioner for Human Rights, in Romania the ANSPDCP.
We take no automated decisions producing legal effects for you. The bus pickup time is set and changed by a dispatcher.
9. How to request deletion
The channels open for such a request are shown on the contact page. In your request give the booking code and the phone number it was made with — that is enough for us to be sure the request is really yours. We reply within 30 days, as Art. 12(3) GDPR requires.
Records that tax law requires us to keep (the fact of sale, the amount, the date) cannot be deleted on request before the statutory period expires. In that case we anonymise everything that can be anonymised and keep only what we are obliged to.
10. Security
Only dispatch staff have access to passenger data, and every change is recorded in the audit log at database level — the entry is written by a trigger and cannot be deleted from the interface. Staff passwords are stored as scrypt hashes. The connection to the site is encrypted (HTTPS).
11. Children
We do not make a booking for a child without an adult and we do not address children directly. A child passenger’s data (name, age for the child fare) is supplied by the adult making the booking and is kept under the same rules as every other passenger’s.
12. Changes to this policy
If the policy changes we will publish the new version here and change the date at the top of the page. About changes affecting the legal bases for processing or the retention periods, the office calls or writes separately — by hand, to the number on the booking — to anyone whose booking is active at that moment.
Booking, paying the driver, free cancellation, luggage, delays and the carrier’s liability.