FR EN

Legal

Privacy policy

What data is collected, why, how long it is kept, and what you can require.

Last updated: 21 September 2026
Document pending legal review

This version has not yet been reviewed by legal counsel. It accurately describes how the platform currently works, but its wording may change before launch.

1. Controller

[TO COMPLETE: exact legal name, registered address, UID number, and a contact email address for data protection matters.]

This document is governed by the Swiss Federal Act on Data Protection (revised FADP, in force since 1 September 2023). Where the data subject is in the European Union, the GDPR may apply in parallel.

2. Passenger data

DataWhy it is collected
NameSo the driver can identify the passenger
Phone numberContact before and during the ride
Email addressBooking confirmation and receipt
Pickup and destination addresses, and their coordinatesPrice calculation, ride assignment, execution
Date and time of the ride, estimated distance and durationPricing and scheduling
Amount, commission and Stripe transaction identifiersPayment and accounting
Rating and comment, if givenService quality and driver eligibility

Card details are never stored by ValTransfer. They go directly to Stripe, which holds them. ValTransfer keeps only technical transaction identifiers, which cannot be used to charge a card.

3. Driver data

This data is supplied by the partner company that engages the driver. Some of it is sensitive personal data under the FADP and is protected accordingly.

DataWhy it is collected
First name, last name, date of birthIdentification
Email address and phone numberRide coordination
OASI (AVS) numberIdentity verification and legal obligations — sensitive data
Driving licence, B121 professional licence, cantonal authorisationTo verify the right to carry passengers professionally
Date the criminal record extract was checkedPassenger safety — sensitive data
Date the debt collection extract was checkedPartner reliability
Professional liability insuranceCover in case of loss
Vehicle: make, model, year, plateSo the passenger can identify the vehicle
Vehicle location and its timestampAssigning the nearest ride and tracking execution
Average rating, number of ratings, completed ridesService quality and commission reduction calculation

Only the dates on which the criminal record and debt collection extracts were checked are kept — never the contents of those documents.

4. Location data

Vehicle position is recorded to assign rides and track their execution. It concerns the driver's vehicle, not the passenger's phone. No position is kept after the ride beyond what is needed to settle a possible dispute.

[TO COMPLETE: exact retention period for position data.]

5. Recipients

  • The partner company and its driver receive the name, phone number, addresses and time, without which the ride cannot happen.
  • Stripe processes the payment and receives the data needed for the transaction.
  • Cal.com is used for scheduling and receives what is entered in the booking widget.
  • Google Maps / Distance Matrix is queried to compute distances and durations from the addresses.
  • Authorities, where the law requires it.

No data is sold or shared for advertising purposes.

[TO COMPLETE: server hosting country and safeguards for transfers outside Switzerland.]

6. Retention

Ride data is kept for the statutory retention period for accounting records in Switzerland, namely ten years for anything touching invoicing and payment. Data not covered by that obligation is deleted earlier — see Account & data deletion.

7. Your rights

  • Access: obtain a copy of the data concerning you.
  • Rectification: correct inaccurate data.
  • Erasure: request deletion, within the limits of statutory retention.
  • Objection: object to a specific processing activity.
  • Portability: receive your data in a usable format.

To exercise these rights see Account & data deletion. You may also contact the Swiss Federal Data Protection and Information Commissioner (FDPIC).

8. Security

Passwords are never stored in clear text. API keys are kept as a non-reversible hash. Traffic to the site is encrypted (HTTPS). Incoming webhooks are cryptographically signature-verified before processing: an unsigned request is rejected.

9. Changes

Any substantial change to this document will be flagged on this page with a new update date.