1. Introduction
RideLuxe (“we”, “us”) is committed to protecting your privacy. This policy explains how we collect, use and protect personal data in accordance with UK GDPR and the Data Protection Act 2018 (DPA 2018).
2. Data Controller
RideLuxe is the data controller. For questions about how we use your data, you may contact us via email or phone at the details below.
3. What Data We Collect
We may collect:
Personal identifiers: name, contact number, address, email
Booking details: travel dates, flight numbers, passenger count, pick‑up and drop‑off locations
Sensitive data only if required (e.g. medical needs)
We will only collect data necessary for service provision (principle of data minimisation).
4. Lawful Basis for Processing
We rely on:
Contractual necessity – to fulfil your booking
Legal obligations – such as licensing record‑keeping under DPA 2018 (e.g. retention for licensing compliance).
Legitimate interests – contacting you about your booking or service improvements, where not overridden by your rights
5. How We Use Your Data
To process bookings and payments
To contact you about bookings or changes
To comply with regulatory requirements
For internal record‑keeping and audits
6. Data Retention
We retain your personal data only as long as necessary for booking queries and to meet licensing obligations, in line with government requirements (e.g. up to several years after last contact).
7. Your Rights
Under UK GDPR you have the right to:
Be informed about how we use your data
Access the personal data we hold (Subject Access Request)
Rectify any inaccurate data
Erasure (“right to be forgotten”) where applicable
Restrict processing or object to it
Data portability, where applicable
Withdraw consent at any time if we rely on consent as a basis
You also have the right to complain to the ICO if you believe we have breached data protection laws.
8. Security and Confidentiality
We apply appropriate technical and organisational measures to safeguard your data against unauthorized access, loss, or destruction, in line with the security principle under UK GDPR.
9. Breach Notification
If a reportable personal data breach occurs, we will notify the Information Commissioner’s Office (ICO) within 72 hours and inform affected individuals if there is a high risk to their rights and freedoms.
10. Sharing Data
We will only share your personal data with:
Wigan Council (for licensing compliance if requested)
Third-party service providers (e.g. payment processors, CRM) under contract and with appropriate safeguards
We do not sell your data or use it for marketing that is not related to your booking unless you have consented.
11. Privacy by Design
We embed privacy principles into all operational processes and systems—minimising data collection, limiting access, and ensuring transparency at every step.
12. Changes to This Policy
RideLuxe may update this policy periodically. We will notify you of significant changes. The current version is accessible at all times.
13. Contact Details
For questions, data requests or complaints please contact:
RideLuxe Ltd
Email: info@rideluxeleigh.co.uk
Phone: 07385 999 581
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s independent supervisory authority for data protection.