Back to home
Data protection

Privacy Policy

Entreprise BERRAHOU is committed to protecting users’ privacy in accordance with the GDPR (EU Regulation 2016/679) and French data protection law.

1. Collection of personal data

When using https://connect-cab.com and our private chauffeur services, Entreprise BERRAHOU may collect the following personal data:

• Full name: required to identify the customer and manage the booking.

• Email address: used to send booking confirmations, invoices and service-related communications.

• Phone number: used to contact the customer about their booking, including confirmation, changes and driver coordination.

• Pickup and destination addresses: required to provide the transport service and calculate routes.

• Payment data: processed securely and encrypted by our certified payment partner (Stripe); no sensitive credit card details are stored on our servers.

• Browsing data: technical and analytics cookies used to ensure operations and improve the user experience.

Mandatory nature of data: Providing required information during booking (name, phone number, addresses) is strictly necessary to conclude and fulfill the transport contract. Without this data, your booking cannot be processed.

2. Purposes of processing and legal bases

Personal data is collected and processed for the following purposes:

• Performance of transport contract (Article 6.1.b GDPR): booking management, driver dispatch, fare calculation, ride fulfillment and customer communication.

• Billing and accounting obligations (Article 6.1.c GDPR): invoice issuance, financial record keeping and compliance with tax laws.

• Security and service optimization (Article 6.1.f GDPR): fraud prevention, form protection and anonymized website performance tracking.

• Optional cookies and trackers (Article 6.1.a GDPR): audience measurement subject to your prior consent, configurable at any time.

3. Data protection and security

Entreprise BERRAHOU implements appropriate technical and organizational measures to protect the security and confidentiality of personal data:

• SSL/TLS encryption (HTTPS): all communications between your browser and our servers are encrypted.

• Secure infrastructure and databases: data hosting complies with recognized international security standards (SOC 2 Type II, ISO 27001).

• PCI-DSS certified payment: online transactions are handled directly through Stripe without sensitive card storage on our servers.

• Restricted access: only authorized personnel may access personal data strictly required for operational needs.

• API security: external integrations are protected with server-side keys and strict rate-limiting policies.

4. Data sharing and sub-processors

Personal data is never sold, rented or transferred to third parties for advertising or commercial purposes.

Data is shared solely with the following authorized recipients and sub-processors within their specific roles:

• Assigned chauffeurs: passenger name, phone number, pickup and destination addresses for ride fulfillment.

• Vercel Inc. (Web application hosting and cloud infrastructure).

• Supabase Inc. (Secure database and booking data management, EU hosting).

• Stripe Payments Europe (PCI-DSS certified online payment processing).

• Resend Inc. (Transactional email delivery for confirmations and invoices).

• Google Maps Platform (Mapping, geocoding, and address autocomplete).

• Public and judicial authorities: strictly when required by law or official legal requests.

Any data transfers outside the European Economic Area (including to the United States) are strictly governed by Standard Contractual Clauses (SCCs) approved by the European Commission or the EU-U.S. Data Privacy Framework.

5. User rights

Under the General Data Protection Regulation (GDPR) and applicable data protection laws, you have the following rights:

• Right of access (Article 15 GDPR): obtain confirmation that your data is being processed and receive a full copy.

• Right to rectification (Article 16): correct inaccurate or incomplete data.

• Right to erasure (Article 17): request deletion of your data, subject to statutory retention obligations.

• Right to restriction (Article 18): temporarily restrict processing of your data in cases provided by law.

• Right to portability (Article 20): receive your data in a structured, commonly used and machine-readable format.

• Right to object (Article 21): object at any time to data processing based on legitimate interests.

• Right to withdraw consent (Article 7.3): withdraw consent at any time for consent-based processing (e.g. analytics cookies).

• Post-mortem directives: provide instructions regarding the storage, deletion and communication of your personal data after your death.

• No automated decision-making: we do not use automated decision-making or profiling producing legal effects concerning you.

To exercise these rights, contact us by email at contact@connect-cab.com, by phone at +33 6 37 78 91 56, or by mail at: 8 Rue Roger Salengro, Bâtiment D Logement 90, 33700 Mérignac, France.

We will respond within a maximum of 30 days. In case of unresolved disputes, you have the right to lodge a complaint with the CNIL (French Data Protection Authority) at www.cnil.fr.

6. Retention periods

Personal data is kept for a period proportionate to the purpose for which it was collected:

• Booking and transport execution data: 3 years from the last service provided (customer relationship and history).

• Billing and accounting documents: 10 years in accordance with tax and commercial code obligations.

• Contact form messages: 1 year from the last interaction.

• Cookies and trackers: up to 13 months in accordance with CNIL guidelines.

After these retention periods, data is permanently deleted or irreversibly anonymized.

7. Personal Data Breach Notification

In the event of a personal data breach (including unauthorized access, loss, disclosure, destruction, or alteration of personal data), Connect Cab follows an internal incident response procedure to assess the breach, limit its impact, and protect affected individuals.

In accordance with the General Data Protection Regulation (GDPR), where required by law, we will notify the competent supervisory authority within 72 hours of becoming aware of the breach.

If the breach is likely to result in a high risk to the rights and freedoms of individuals, we will inform the affected persons without undue delay, explaining the nature of the breach, the data involved, the potential consequences, and the corrective measures taken.

We maintain an internal record of personal data incidents and regularly review our security measures to strengthen the protection of personal information.

Last updated: February 2026 · Data controller: BERRAHOU Youness