1. Controller and contact
The entity configured below is the controller for the processing described here. If information is missing, the site does not invent the operator identity and explicitly marks the configuration that must be completed.
- Legal business name
- Not configured — complete before commercial launch.
- Operator address
- Not configured — complete before commercial launch.
- Company number
- Not configured — complete before commercial launch.
- VAT number
- Not configured — complete before commercial launch.
For a GDPR request, question or complaint about your data:
Use the contact details in your booking confirmation or your passenger account.
2. Data we process
We may process your name, email, phone, language, account identifier, pickup and destination addresses, dates and times, passenger count, vehicle, flight number, journey notes, price, payment method and status, Stripe references, booking status, assigned driver and message history. Technical providers may also generate limited security logs. Stripe receives card details directly; Taxi2Airport Brussels does not store your full card number.
3. Purposes and legal bases
- Prepare a quote and create or perform a booking: pre-contractual steps and contract.
- Collect, reconcile or refund a payment: contract and accounting obligations.
- Create an account, show your journeys and save your profile: contract and requested service.
- Send WhatsApp confirmations and manage dispatch: performance of the service.
- Prevent fraud, secure access and defend legal claims: legitimate interests.
- Retain required records: legal obligation.
We do not ask for special-category data. Only include information strictly necessary for the journey in free-text notes.
4. Providers and recipients
Data is available only to authorised people and, depending on the journey, to Supabase (database and authentication), Vercel (hosting), Stripe (payment), Meta/WhatsApp (messages), OpenRouteService and public or open geocoding and routing services. Drivers receive only what they need to carry out the transfer. An address may be sent to a mapping provider to calculate the route, without your payment details.
5. International transfers
Some providers may process data outside the European Economic Area. Where the GDPR requires it, transfers must rely on an adequacy decision or appropriate safeguards such as standard contractual clauses. You may ask for information about applicable safeguards.
6. Retention
Data is kept as long as needed for the booking, customer care, dispute prevention and legal obligations. Payment and booking records may be retained for the applicable accounting or tax period. Account profiles are retained while the account is active, then deleted or anonymised when no longer necessary, subject to legal retention duties. Technical and messaging logs are reviewed and deleted according to their operational and security purpose.
7. Security
Administrative access is authenticated and role-restricted. Supabase tables use row-level security, so customers can read only their own bookings. Privileged keys remain server-side, Stripe webhooks are signature-verified, sensitive requests are validated and communications use HTTPS. No system is infallible, so please report unusual activity promptly.
8. Cookies and local storage
The site uses a functional cookie to remember language choice. Supabase may retain account session tokens in browser storage. Stripe and other providers may use their own technical storage when you open their services. The current site does not integrate advertising or marketing profiling tools.
9. Automated calculation
The fare is calculated automatically from route distance, duration, vehicle and the active fare settings. This is not a solely automated decision producing a significant legal effect based on a personal profile.
10. Your rights
Depending on the processing, you may request access, correction, deletion, restriction or portability, or object to processing. You may withdraw consent where consent is the legal basis. We may ask for proof of identity. You may also complain to the Belgian Data Protection Authority. Some rights may be limited where the law requires retention.
11. Updates
This notice may change when services or legal duties change. The version published here applies from 28 July 2026.