This version has not yet been reviewed by legal counsel. It accurately describes how the platform currently works, but its wording may change before launch.
1. Controller
[TO COMPLETE: exact legal name, registered address, UID number, and a contact email address for data protection matters.]
This document is governed by the Swiss Federal Act on Data Protection (revised FADP, in force since 1 September 2023). Where the data subject is in the European Union, the GDPR may apply in parallel.
2. Passenger data
| Data | Why it is collected |
|---|---|
| Name | So the driver can identify the passenger |
| Phone number | Contact before and during the ride |
| Email address | Booking confirmation and receipt |
| Pickup and destination addresses, and their coordinates | Price calculation, ride assignment, execution |
| Date and time of the ride, estimated distance and duration | Pricing and scheduling |
| Amount, commission and Stripe transaction identifiers | Payment and accounting |
| Rating and comment, if given | Service quality and driver eligibility |
Card details are never stored by ValTransfer. They go directly to Stripe, which holds them. ValTransfer keeps only technical transaction identifiers, which cannot be used to charge a card.
3. Driver data
This data is supplied by the partner company that engages the driver. Some of it is sensitive personal data under the FADP and is protected accordingly.
| Data | Why it is collected |
|---|---|
| First name, last name, date of birth | Identification |
| Email address and phone number | Ride coordination |
| OASI (AVS) number | Identity verification and legal obligations — sensitive data |
| Driving licence, B121 professional licence, cantonal authorisation | To verify the right to carry passengers professionally |
| Date the criminal record extract was checked | Passenger safety — sensitive data |
| Date the debt collection extract was checked | Partner reliability |
| Professional liability insurance | Cover in case of loss |
| Vehicle: make, model, year, plate | So the passenger can identify the vehicle |
| Vehicle location and its timestamp | Assigning the nearest ride and tracking execution |
| Average rating, number of ratings, completed rides | Service quality and commission reduction calculation |
Only the dates on which the criminal record and debt collection extracts were checked are kept — never the contents of those documents.
4. Location data
Vehicle position is recorded to assign rides and track their execution. It concerns the driver's vehicle, not the passenger's phone. No position is kept after the ride beyond what is needed to settle a possible dispute.
[TO COMPLETE: exact retention period for position data.]
5. Recipients
- The partner company and its driver receive the name, phone number, addresses and time, without which the ride cannot happen.
- Stripe processes the payment and receives the data needed for the transaction.
- Cal.com is used for scheduling and receives what is entered in the booking widget.
- Google Maps / Distance Matrix is queried to compute distances and durations from the addresses.
- Authorities, where the law requires it.
No data is sold or shared for advertising purposes.
[TO COMPLETE: server hosting country and safeguards for transfers outside Switzerland.]
6. Retention
Ride data is kept for the statutory retention period for accounting records in Switzerland, namely ten years for anything touching invoicing and payment. Data not covered by that obligation is deleted earlier — see Account & data deletion.
7. Your rights
- Access: obtain a copy of the data concerning you.
- Rectification: correct inaccurate data.
- Erasure: request deletion, within the limits of statutory retention.
- Objection: object to a specific processing activity.
- Portability: receive your data in a usable format.
To exercise these rights see Account & data deletion. You may also contact the Swiss Federal Data Protection and Information Commissioner (FDPIC).
8. Security
Passwords are never stored in clear text. API keys are kept as a non-reversible hash. Traffic to the site is encrypted (HTTPS). Incoming webhooks are cryptographically signature-verified before processing: an unsigned request is rejected.
9. Changes
Any substantial change to this document will be flagged on this page with a new update date.