Privacy Policy
How we collect, use, and protect your personal data
Last updated: April 2026
Information We Collect
We collect information you provide directly when booking a ride or creating an account: your name, email address, phone number, pickup and drop-off locations, and payment information. We also collect technical data such as device type, browser, IP address, and usage patterns when you interact with our platform.
How We Use Your Information
- Process and fulfill your bookings
- Communicate ride details, confirmations, and receipts
- Improve our services and user experience
- Ensure safety and prevent fraud
- Send service-related notifications (never marketing without consent)
- Comply with legal obligations
Payment Data
Payment processing is handled securely by Stripe. We do not store your full credit card number, CVV, or bank account details on our servers. Stripe is PCI DSS Level 1 certified — the highest level of payment security compliance.
Location Data
We collect pickup and drop-off addresses you provide during booking. This data is used to calculate routes and pricing via third-party mapping services (OpenStreetMap). We do not continuously track your location outside of active bookings.
Third-Party Services
We share limited data with trusted service providers who help us operate:
- Supabase — Authentication and database hosting (EU servers)
- Stripe — Payment processing
- Resend — Transactional email delivery
- OpenStreetMap / OSRM — Route calculation and geocoding
- Vercel — Website hosting and delivery
Cookies & Storage
We use strictly necessary cookies for authentication (session management). We do not use advertising cookies, tracking pixels, or analytics cookies. No cookie consent banner is required as we only use essential cookies as defined under ePrivacy regulations.
Data Retention
Booking records are retained for 6 years to comply with tax and legal obligations. Account data is retained while your account is active and for 30 days after deletion. Technical logs are automatically purged after 90 days.
Your Rights (GDPR & CCPA)
Depending on your jurisdiction, you have the right to:
- Access — Request a copy of your personal data
- Correction — Update inaccurate information
- Deletion — Request erasure of your data ("right to be forgotten")
- Portability — Receive your data in a machine-readable format
- Objection — Opt out of specific data processing
- Restriction — Limit how we process your data
Data Security
We protect your data with industry-standard measures including encrypted connections (TLS/SSL), secure authentication, role-based access controls, and regular security reviews. All data is transmitted and stored using encryption.
Children's Privacy
Our services are not directed to individuals under 18. We do not knowingly collect personal information from children. If we become aware of such collection, we will promptly delete the data.
Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will notify registered users of significant changes via email. Continued use of the platform constitutes acceptance of the updated policy.
Contact Us
For privacy-related questions, data access requests, or to exercise your rights, contact us:
Email: privacy@vipblacklane.com
Or visit our Contact page
By using VIP Black Lane, you acknowledge that you have read and understood this Privacy Policy.
