Legal · Privacy

Privacy notice

What we collect when you book, why, who else sees it and how long it survives. Clause 3 is a table — it is the only clause most people need.

Last updated 1 July 2026Version 1.0Guide Algarve, Lda · NIF 500 000 000 · RNAVT 0000

Placeholder copy — not legal advice

This document was written to show what the page looks like when it is full of real text. The clauses are plausible for a Portuguese transport and rental company, and the figures match the rest of this site, but nobody qualified has read them. A lawyer must review and rewrite this before launch.

The whole notice in four lines

We collect what is needed to drive you somewhere and to issue an invoice. The driver gets your name, your phone number and the address. Your card number never reaches us. We do not sell anything to anybody, and there are no advertising trackers on this site.

This notice sits alongside our terms of service and covers this website, our WhatsApp line, the partner portal and the driver app.

1Who is responsible for your data

1.1

The data controller is Guide Algarve, Lda. We decide what is collected and why, and we are the people you complain to first if you are unhappy with any of it.

Guide Algarve, Lda

Rua da Barroca 14, 8600 Lagos, Portugal

NIF 500 000 000 · RNAVT 0000

transpory@gmail.com

+351 936 499 889

1.2

We are not large enough to be required to appoint a Data Protection Officer and we have not appointed one. Privacy questions go to the address above and are answered by a person, not a form.

2What we collect, and what we do not

2.1

What we collect

  • What you type into a booking: name, phone, email, addresses, flight number, how many of you there are, the ages of children so the right seat is fitted.
  • What you tell us in a message, on WhatsApp or by email.
  • Payment information, handled by our payment provider. We receive a token, the last four digits and the outcome — never the full card number.
  • For e-bike rentals: the rider's name and height, the bike given out, and photographs of the bike at handover and return.
  • Technical information from this site: IP address, device, browser, pages viewed, and errors.
2.2

What we deliberately do not collect

  • Passport or identity document numbers. We do not photocopy documents to rent a bike.
  • Your location, at any time, in any form. Drivers navigate to an address you gave us; the site does not ask your browser where you are.
  • Any special-category data — health, religion, politics. If you tell us about a wheelchair or an allergy, we use it to plan the journey and delete it afterwards.
  • Advertising identifiers. There are no advertising or social-media trackers on this site.

You do not need an account and we do not create one. Your trip link is a long unguessable address; it is not a login and it carries no password.

2.3

Children

We do not knowingly collect anything from a child. The only information we hold about children is an age, given by an adult, so that the correct child seat is fitted before we arrive. It is deleted with the rest of the booking record.

3Why we use it, and on what legal basis

3.1

Every purpose we process personal data for, the basis under Article 6 of the GDPR, and how long the data survives afterwards. If a purpose is not in this table, we are not doing it.

3.2

Carrying out the booking you made

Name, phone, email, pickup and drop-off address, flight number, passenger count, ages of children, vehicle and driver assigned

Performance of a contractKept: 3 years after travel

Taking payment and issuing a fiscal document

Amount, payment method, card token and last four digits, NIF and billing address where given

Contract and legal obligationKept: 10 years (Portuguese tax law)

Telling the driver who to collect and where

First name, surname initial, phone, addresses, flight, luggage and child-seat notes

Performance of a contractKept: Visible to the driver for 48 hours around the job

Answering you on WhatsApp or by email

The conversation itself, your phone number, booking reference

Contract and legitimate interestKept: 24 months

Renting an e-bike and holding the deposit

Rider name, height, card pre-authorisation, bike serial number, condition photographs at handover and return

Contract and legitimate interestKept: 12 months after return

Paying commission to a partner hotel

Booking reference, date, product, amount, partner code — never the guest's contact details beyond the surname

Contract with the partner, legitimate interestKept: 10 years (accounting)

Keeping the site working and safe

IP address, device and browser, pages viewed, error logs

Legitimate interestKept: 14 months, aggregated after 30 days

Sending you offers you asked for

Email address, language, which products you have used

Consent, withdrawable at any timeKept: Until you withdraw consent
3.3

Where we rely on legitimate interest

We have weighed our interest against yours in each case and concluded that you would expect the processing: a company that drives you somewhere needs a message history to answer “what time is my pickup”, and needs error logs to keep its booking form working. You can object to any of it using the addresses in clause 6, and we will stop unless we have a compelling reason not to.

4Who else sees it

4.1

We do not sell personal data, we do not trade it, and we do not share it for anybody else's marketing. It goes to these people and no others:

  • The driver doing your job. First name, surname initial, phone number, pickup and drop-off, flight, and any note about luggage or child seats. The driver app shows the day being worked and nothing else — no history, no other customers.
  • A partner hotel, if the booking came through one.Only bookings made under that partner's own code, and only the surname, date, product and amount — enough to check a commission statement, not enough to build a guest list.
  • Our payment provider, which processes the card and holds the e-bike deposit as a pre-authorisation. It is a controller in its own right for fraud prevention.
  • A flight-status provider, which receives a flight number and a date. It is not told who is on the flight.
  • Our accountant and the Autoridade Tributária, for the fiscal documents Portuguese law requires us to issue and file.
  • WhatsApp, operated by Meta, if you choose to message us there. Their terms apply to that conversation as well as ours; use email if you would rather they did not.
  • Our hosting and email providers, under data-processing agreements, purely to run the software.
4.2

Outside the EEA

Our hosting, database and email are inside the European Union. Some providers — payment processing and WhatsApp among them — may transfer data to the United States. Where that happens it is covered by the European Commission's Standard Contractual Clauses and, where applicable, the EU – US Data Privacy Framework. You can ask us for a copy of the safeguards for any specific provider.

4.3

Automated decisions

We do not profile you and no decision about you is taken by software alone. Prices are published in a table and are the same for everybody; they do not change according to your device, your country or how many times you have looked at the page.

5How long we keep it

5.1

The table in clause 3 gives the retention period for each purpose. Where two periods overlap, the longer one wins for that record — a booking that carries a fiscal document is kept for the ten years Portuguese tax law demands, even though the operational part of it stops being useful after three.

5.2

After the period ends, records are deleted or irreversibly anonymised. We keep counts — how many transfers ran from Faro in July 2026 — because a number with no person attached is not personal data.

6Your rights, and how to use them

6.1

Under the GDPR you can ask us to:

  • Give you a copy of everything we hold about you, in a readable format.
  • Correct anything that is wrong — a misspelled name on an invoice, a wrong phone number.
  • Delete it, where we are not required to keep it for tax or accounting.
  • Restrict what we do with it while a dispute is being sorted out.
  • Send it to another company in a machine-readable file.
  • Object to processing based on legitimate interest, including any profiling (we do not profile).
  • Withdraw consent for marketing at any time, which does not affect anything sent before you withdrew it.
6.2

How to ask

Email transpory@gmail.com from the address on the booking, or message the number on your confirmation. We answer within 30 days and it costs nothing. We may ask one question to confirm you are who you say you are — usually a booking reference — and we will not ask you to send us a copy of an identity document to prove it.

6.3

If we get it wrong

Complain to the Portuguese supervisory authority, the Comissão Nacional de Proteção de Dados (CNPD), Av. D. Carlos I 134, 1200-651 Lisboa, cnpd.pt — or to the authority where you live, if that is elsewhere in the EU. We would rather you told us first, but you are not obliged to.

7Cookies

7.1

This site uses as few as it can. There is no advertising cookie, no tracking pixel and no social-media widget on any page.

  • Strictly necessary. Keeps a booking in progress together and protects the form against abuse. No consent needed, cannot be switched off.
  • Preference. Remembers the language you picked and the airport you last looked at. Expires after 12 months.
  • Measurement. Counts page views and where bookings drop out, with the IP address truncated before it is stored. Only set if you accept it, and the site works identically if you do not.

You can change your choice at any time from the link in the footer, or clear cookies in your browser. Declining costs you nothing — there is no feature behind that wall.

8Keeping it safe

8.1
  • Everything travels over TLS. The site is not reachable without it.
  • Access is per person and per role: a driver sees today, a partner hotel sees its own bookings, and only two people in the company can see everything.
  • Trip links are long random addresses, expire 30 days after travel, and can be revoked from the booking.
  • Backups are encrypted and held inside the EU.
  • We would tell the CNPD within 72 hours of a breach that put you at risk, and tell you directly where the risk is high.

9Changes to this notice

9.1

When this notice changes we update the date and version at the top of the page and keep the previous versions. If a change materially affects how your data is used we say so on this page for 30 days before it takes effect, and email anybody who has an active booking. We do not quietly widen what we do with data already collected.

Ask us to show you your file

One email and you get everything we hold, in a file you can read, within 30 days. No form, no fee, no identity document.

Guide Algarve, Lda — privacy

transpory@gmail.com

Rua da Barroca 14, 8600 Lagos, Portugal

Supervisory authority: CNPD, Lisboa · cnpd.pt