SantoTransfer

Privacy Policy

Last updated August 29, 2026 · Santorini Rides · TAXI SERVICE ΜΟΝΟΠΡΟΣΩΠΗ Α.Ε.

We keep this short and honest. We collect only what we need to run your booking, we never see your full card number, and you can ask us about your data at any time.

1. Data controller

TAXI SERVICE ΜΟΝΟΠΡΟΣΩΠΗ Α.Ε. (trading as Santorini Rides), Ormos Athiniou 0, 84700 Santorini (Thira), Cyclades, Greece. For anything about your personal data write to info@santorinirides.com.

2. What we collect

When you book: your name, email address, phone number, pickup and drop-off addresses, flight or ferry number, passenger and luggage counts, any notes you add, and your booking history with us.

When you use the site: technical data such as IP address, device and browser type, pages viewed, and the cookies described in our Cookie Policy.

3. Card payments — what we do not collect

We do not collect, process or store full card numbers, CVV/CVC codes, expiry dates or cardholder authentication data. Online card payments are processed by Viva.com (Viva Payments), which acts as an independent controller for the payment transaction under its own privacy notice. We receive only a transaction reference, the amount, a status and, at most, the card brand and the last four digits.

4. Why we may use your data (legal bases)

  • Performance of the contract: to arrange, confirm and carry out your transfer or excursion and to contact you about it.
  • Legal obligation: invoicing, accounting and tax retention under Greek law.
  • Legitimate interest: preventing fraud and abuse, keeping the site secure, and improving the service.
  • Consent: marketing messages and non-essential cookies (analytics). You can withdraw consent at any time.

5. Who receives your data

We share data only with providers who help us run the service, under contracts that bind them to protect it:

  • Viva.com (Viva Payments) — card payment processing.
  • Supabase — our database and admin authentication, hosted in the EU (Frankfurt).
  • Vercel — website hosting and delivery.
  • Resend — transactional email (booking confirmations, reminders).
  • Google (Places API) — to look up the hotel or address you type; and Google Analytics 4, only if you accept analytics cookies.
  • Cloudflare Images — delivery of photos on the site (no personal data).
  • Our drivers receive your name, phone number, pickup details and flight/ferry number to perform the service.

6. International transfers

Our data is stored in the European Union. Some providers (Vercel, Google, Cloudflare, Resend) are US companies that may process data outside the EU; where they do, transfers rely on the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

7. How long we keep it

Booking and invoicing records are kept for as long as Greek tax law requires (currently at least five years after the end of the tax year). Contact-form messages are kept for one year. Marketing consent is kept until you withdraw it. Technical logs are kept for a short period for security.

8. Your rights

You have the right to access, rectify and erase your data, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent at any time without affecting earlier processing.

You also have the right to lodge a complaint with the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα, www.dpa.gr).

9. How to exercise them

Email info@santorinirides.com from the address you booked with, quoting your booking reference if you have one. We answer within one month.

Questions about this page? Contact us