Privacy Policy

Last updated: March 26, 2026

This Privacy Policy explains how E'Bitual collects, uses, and protects personal data in accordance with the GDPR and Portuguese law.

1. Controller and contact

The data controller is E'Bitual. Please refer to the Legal Notice for full company details and contacts.

2. Data we collect

We collect only data necessary to provide the service.

  • Account data: name, email, phone number, password (hashed).
  • Billing data: billing name, NIF/VAT number, billing address, city, postal code, and country. Collected for invoicing purposes under Portuguese fiscal law (Art. 6(1)(c) GDPR — legal obligation).
  • Booking data: pickup and dropoff addresses, dates, times, vehicle preferences, special requests.
  • Payment data: transaction references and status (card data is handled by Easypay). Invoice PDFs are stored for your re-download and retained per Portuguese fiscal law.
  • Technical data: IP address, device and browser information, login timestamps.

3. Purposes and legal basis

We process data to provide the service, manage bookings, process payments, and communicate with you.

Legal bases include contract performance (GDPR Art. 6(1)(b)), legal obligations (Art. 6(1)(c)), and legitimate interests (Art. 6(1)(f)) for security and fraud prevention.

4. Data sharing and processors

We share data only with service providers necessary to operate the platform.

  • Easypay (payment processing — PCI-DSS compliant). E'Bitual does not store credit card numbers, CVVs, or payment credentials.
  • Resend (transactional email delivery). Receives your email address and name to deliver service notifications.
  • Railway (application hosting). Hosts our backend infrastructure within the EU.
  • Cloudflare (CDN, DNS, and DDoS protection). May process IP addresses and request metadata for security purposes.
  • Cloudinary (media storage). Stores vehicle and service images uploaded by administrators.
  • Google Maps (address validation and routing).
  • Assigned chauffeurs and partner operators (to deliver the service).

5. International transfers

If data is transferred outside the EEA (e.g., Google services), we rely on appropriate safeguards such as Standard Contractual Clauses.

6. Data retention

We retain data only for as long as necessary for contractual and legal obligations.

Booking and payment records may be retained up to 10 years in accordance with Portuguese fiscal law.

7. Your rights

Under the GDPR, you have the right to access (Art. 15), rectify (Art. 16), erase (Art. 17), restrict (Art. 18), object to processing (Art. 21), and request data portability (Art. 20). You may also withdraw consent at any time.

You can lodge a complaint with the Portuguese supervisory authority (CNPD).

8. Cookies

We use cookies to operate the website. You can accept all cookies, reject non-essential cookies, or customize your preferences at any time via the cookie settings accessible from the bottom of any page.

  • Strictly necessary — authentication tokens, session security, CSRF protection. These cannot be disabled as the service requires them.
  • Functional — language preference, theme (light/dark), cookie consent choice. These remember your settings across visits.
  • Analytics — currently none. If added in the future, they will require your explicit consent.

9. Security

We use technical and organizational measures to protect data, including TLS encryption and access controls.

10. Changes to this policy

We may update this policy from time to time. Material changes will be communicated on the website.