Legal
Privacy policy
Last updated 19 September 2026
1. Who we are
Voala Tour, based in Portugal, is the data controller for the personal data described in this policy — meaning we decide why and how it's processed. This policy applies to Customers, Companies, Drivers, Partners, and anyone else who uses voalatour.com. For any privacy request or question, contact us at geral@voalatour.com.
2. Data we collect
- Account data: name, email address, password (stored hashed, never in plain text), and account role.
- Booking data: traveler name, phone number, pickup and drop-off location, number of travelers, and any note left for a driver.
- Company/Driver/Partner data: business name, description, vehicle details, and an optional profile photo.
- Payment data: handled entirely by Stripe — we receive confirmation that a payment succeeded, not your card number or full card details.
- Technical data: basic device/browser information generated automatically when you use the platform, for security and to keep the service working correctly.
3. Why we process it, and on what legal basis
- To create and run your account, and to process a booking — necessary to perform our contract with you (GDPR Art. 6(1)(b)).
- To process payments and payouts — necessary to perform that same contract.
- To keep the platform secure and prevent fraud or misuse — our legitimate interest (Art. 6(1)(f)), balanced against your rights.
- To respond when you contact us directly — our legitimate interest in providing support, or performance of a contract if you're already a user.
- To meet accounting, tax, or legal obligations — legal obligation (Art. 6(1)(c)).
We don't use your data for automated decision-making or profiling that produces legal or similarly significant effects, and we don't send marketing communications without your separate consent.
4. Who we share it with
We share booking details only with the Company, Driver, or Partner actually involved in that booking, and only to the extent needed to deliver the service. We use the following processors to run the platform, under data processing agreements consistent with GDPR:
- Supabase — database, authentication, and file storage, hosted in the EU (Ireland).
- Stripe — payment processing and payouts. Stripe may process data outside the EEA (e.g. in the United States); where it does, it relies on the European Commission's Standard Contractual Clauses or an equivalent safeguard recognized under GDPR.
We don't sell personal data, and we don't share it with third parties for their own marketing purposes.
5. International transfers
Our primary database is hosted in the EU. Where a processor we use (such as Stripe) transfers data outside the EEA, that transfer is covered by Standard Contractual Clauses or another safeguard recognized as adequate under GDPR Chapter V.
6. Cookies and local storage
We use your browser's local storage to keep you signed in between visits. This is strictly functional — it's what lets the platform recognize you without asking you to log in on every page — and isn't used for advertising or cross-site tracking. We don't currently use analytics or advertising cookies; if that changes, we'll update this policy and request consent where required under the ePrivacy rules.
7. Data retention
We keep account data for as long as your account is active. Booking and payment records are kept for the period required by Portuguese tax and accounting law (generally up to 10 years for invoicing records) even after an account is closed. Data no longer needed for a legal or legitimate business reason is deleted or anonymized.
8. Security
We rely on our processors' access controls, encryption in transit, and row-level database permissions to restrict who can see what — a Customer's booking data, for example, is only reachable by that Customer and the Company/Driver/Partner assigned to it. No system is 100% secure, but we take reasonable technical and organizational measures appropriate to the data involved.
9. Your rights
Under the GDPR, you have the right to: access the personal data we hold about you; have inaccurate data corrected; request erasure ("right to be forgotten"), subject to our legal retention obligations; request a portable copy of your data; object to or request restriction of certain processing; and withdraw consent at any time where processing is based on it. To exercise any of these, contact geral@voalatour.com — we'll respond within the timeframe required by law.
10. Complaints
If you believe we haven't handled your data correctly, please contact us first so we can try to resolve it. You also have the right to lodge a complaint directly with Portugal's data protection authority, the Comissão Nacional de Proteção de Dados (CNPD) — cnpd.pt — or with the supervisory authority of your own EU member state.
11. Children
Voala Tour isn't directed at children, and accounts require you to be at least 18. We don't knowingly collect personal data from anyone under that age; if we learn we have, we'll delete it.
12. Changes to this policy
We may update this policy as the platform or applicable law evolves. The "last updated" date at the top always reflects the current version; where a change is material, we'll take reasonable steps to bring it to your attention.
13. Contact
Questions or requests about your personal data: geral@voalatour.com.