Transferhood Privacy Policy

Last Updated: December 2025
This Privacy Policy explains how PTS Travel Solutions Ltd. ("Company", "we", "us", or "our") collects, uses, discloses, and protects your personal data when you use our website www.transferhood.com and associated mobile applications (collectively, the "Platform"). By using the Platform, you acknowledge that you have read and understood this Privacy Policy. If you have any questions, please contact us using the details in Section 17.

1. Introduction

1.1 This Privacy Policy explains how PTS Travel Solutions Ltd. ("Company", "we", "us", or "our") collects, uses, discloses, and protects your personal data when you use our website www.transferhood.com and associated mobile applications (collectively, the "Platform").

1.2 PTS Travel Solutions Ltd. is the data controller responsible for your personal data. We are committed to protecting your privacy and processing your personal data in accordance with the EU General Data Protection Regulation (GDPR) (EU) 2016/679 and applicable Bulgarian data protection laws.

1.3 This Privacy Policy is designed to be read alongside our Terms and Conditions, which govern your use of the Platform. Certain references in this Policy — such as the dispute resolution provisions in Article 16 of our Terms and Conditions — form part of the wider contractual framework between you and us.

1.4 By using the Platform, you acknowledge that you have read and understood this Privacy Policy. If you have any questions, please contact us using the details in Section 17.

2. Data Controller & Contact Information

2.1 Data Controller
The data controller responsible for your personal data is:
PTS Travel Solutions Ltd.
Knyaz Boris I Street No. 8, Floor 5, Office 1, Sofia, Bulgaria
VAT Number: BG207914623
Website: www.transferhood.com

2.2 Data Protection Officer (DPO)
We have appointed a Data Protection Officer to oversee compliance with this Privacy Policy and applicable data protection laws. You can contact our DPO at:
Email: dpo@transferhood.com
Address: Data Protection Officer, PTS Travel Solutions Ltd., Knyaz Boris I Street No. 8, Floor 5, Office 1, Sofia, Bulgaria

2.3 General Contact Information
For any questions or requests relating to this Privacy Policy or our data processing practices:
Privacy inquiries: privacy@transferhood.com
Customer support: support@transferhood.com
Phone: +908503079000

3. Personal Data We Collect

3.1 Information You Provide Directly

a) Account Information:
Full name (first name and surname)
Email address
Phone number
Password (encrypted and never stored in plain text)
Preferred language and communication preferences

b) Booking Information:
Pick-up and drop-off locations
Travel dates and times
Number of passengers
Flight or train reference numbers
Special requests (child seats, pet transport, accessibility needs, extra luggage)
Notes or instructions for the carrier

c) Payment Information:
Credit/debit card details (processed securely by our PCI DSS compliant payment processors — we do not store full card numbers)
Billing address
Transaction history and receipts
Digital wallet information (PayPal, Google Pay, Apple Pay)

d) Passenger Information:
Names and contact details of passengers (where different from the account holder)

3.2 Information Collected Automatically

a) Technical Data:
IP address
Browser type and version
Device type and operating system
Unique device identifiers
Time zone setting and language settings

b) Usage Data:
Pages visited on our Platform
Time and date of visits
Time spent on pages and click patterns
Search queries entered on the Platform

c) Customer Service Records:
Call recordings (where applicable), retained for quality assurance and dispute resolution purposes for a maximum period of 12 months
Written communications and support tickets

d) Location Data:
General location derived from your IP address
Precise geolocation (only with your explicit consent): used solely when you initiate location-based features on the Platform or to enable pick-up confirmation and service completion tracking by Carriers. Geolocation data is retained for a maximum of 4 months from collection.

3.3 Information from Third Parties
We may receive personal data from:
Social login providers (Google, Apple) if you choose to register using these services
Payment service providers, for transaction verification
Our carrier partners, regarding service delivery and completion

4. Purposes of Data Processing

4.1 We process your personal data for the following purposes:

a) Service Provision:
Processing and managing your reservations
Connecting you with transportation carriers
Providing customer support
Sending booking confirmations and transport communications
Processing payments and refunds

b) Account Management:
Creating and maintaining your user account
Authenticating your identity
Managing your preferences and communication settings

c) Communication:
Sending service-related notifications and updates
Responding to your inquiries and support requests
Providing important notices about changes to our services or policies

d) Platform Improvement & Analytics:
Analysing Platform usage to improve our services
Understanding user preferences and behaviour
Developing new features and services
Conducting internal research and analysis using aggregated, anonymised data

e) Marketing (with your consent only):
Sending promotional offers and newsletters
Personalised advertising
Conducting surveys and requesting feedback
Marketing communications are sent only following your explicit opt-in consent. You may withdraw consent at any time by clicking the unsubscribe link in any marketing email, updating your communication preferences in your account settings, or contacting us at privacy@transferhood.com. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

f) Legal Compliance & Security:
Fraud prevention and detection
Complying with legal and regulatory obligations
Protecting our rights and the rights of others
Resolving disputes and enforcing our Terms and Conditions

5. Legal Basis for Processing

5.1 We process your personal data based on the following legal grounds under the GDPR:

a) Contract Performance (Article 6(1)(b) GDPR):
Processing necessary to perform the Transferhood Agreement and to fulfil your booking, including sharing data with assigned Carriers for service delivery.

b) Legitimate Interests (Article 6(1)(f) GDPR):
Processing necessary for our legitimate business interests, provided those interests do not override your fundamental rights and freedoms. Our legitimate interests include:
Fraud prevention and detection to protect our customers and business
Platform security and integrity maintenance
Service improvement through anonymised usage analysis
Carrier performance evaluation to ensure service quality
Business analytics and reporting
Enforcing our Terms and Conditions and protecting our legal rights
You have the right to object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

c) Consent (Article 6(1)(a) GDPR):
Processing based on your explicit consent — in particular for marketing communications and precise location data. Consent may be withdrawn at any time in accordance with Article 7 GDPR.

d) Legal Obligation (Article 6(1)(c) GDPR):
Processing necessary to comply with legal requirements, including tax, accounting, and regulatory obligations under Bulgarian law.

5.2 Mandatory vs. Optional Data
Certain data is mandatory to enter into and perform the Transferhood Agreement — specifically your name, email address, phone number, pick-up and drop-off locations, and payment information. Without this data, we cannot create your account or process bookings. Data marked as optional (such as special requests or marketing preferences) can be withheld without affecting your ability to use our core services.

6. Automated Decision-Making & Profiling

6.1 We use automated processing in the following ways:

a) Carrier Matching:
Our system automatically matches your reservation with available carriers based on location, vehicle type, capacity, and availability. This process facilitates service delivery but does not produce binding legal effects on you as a data subject.

b) Dynamic Price Calculation:
Prices are automatically calculated based on distance, vehicle type, date, time, and any additional services requested. The calculation logic is transparent and displayed during the booking process.

c) Fraud Detection:
We use automated systems to detect potentially fraudulent transactions or account activity. If a transaction is flagged, it is reviewed by our team before any restrictive action is taken.

6.2 We do not make decisions based solely on automated processing that produce legal effects or significantly affect you without human involvement, in accordance with Article 22 GDPR.

6.3 You have the right to:
Request human intervention in automated decisions
Express your point of view regarding any automated decision
Contest automated decisions that affect you
To exercise these rights, please contact us at support@transferhood.com.

7. Data Sharing & Recipients

7.1 We may share your personal data with the following categories of recipients:

a) Transportation Carriers — Joint Controller Relationship:
We share necessary booking details with assigned carriers to enable the provision of transport services. This includes passenger names and contact information, pick-up and drop-off details, flight or train numbers, and special requests.
For the purposes of Article 26 of the GDPR, PTS Travel Solutions Ltd. and the Transportation Carriers act as joint controllers with respect to certain personal data processing activities related to the provision of Transportation Services. As the designated contact point for data subjects, you may exercise your data protection rights by contacting us using the details in Section 17. Carriers are contractually prohibited from using Customer or Passenger data for marketing purposes or sharing it with third parties.
Data shared with Carriers is limited strictly to what is necessary for service fulfilment, reflecting the two-contract structure (Transferhood Agreement + Contract of Carriage) described in Article 4 of our Terms and Conditions.

b) Payment Processors:
Your payment information is processed by secure, PCI DSS compliant third-party payment processors, including providers of credit card processing, PayPal, Google Pay, and Apple Pay services.

c) Service Providers:
We engage trusted third-party service providers who assist us in operating the Platform under appropriate data processing agreements, including:
Cloud hosting providers
Email and communications service providers
Analytics providers (using anonymised or aggregated data where possible)
Customer support tools

d) Legal and Regulatory Authorities:
We may disclose your data to competent authorities to comply with legal obligations or respond to lawful requests from public authorities.

e) Business Transfers:
In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the acquiring entity, subject to equivalent data protection obligations.

7.2 We do not sell your personal data to third parties.

8. International Data Transfers

8.1 Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA) where our service providers or partner carriers are located.

8.2 When we transfer personal data outside the EEA, we ensure that appropriate safeguards are in place, including:
Standard Contractual Clauses (SCCs) approved by the European Commission, pursuant to Article 46 GDPR
Adequacy decisions issued by the European Commission recognising an equivalent level of data protection
Other legally recognised transfer mechanisms under Chapter V GDPR

8.3 You may request further information about the specific safeguards we have implemented for international transfers by contacting dpo@transferhood.com.

9. Data Retention

9.1 We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. The following retention periods apply:

a) Account Data:
Retained for the duration of your active account. Following account closure or 24 consecutive months of inactivity, your account data will be deleted or anonymised within 30 days, in accordance with Article 2.5 of our Terms and Conditions. Where applicable legal retention requirements (such as the 7-year retention of booking and payment records) mandate a longer period, those requirements take precedence.

b) Booking and Payment Records:
Retained for 7 years after the completion of the service, as required by Bulgarian tax and accounting legislation.

c) Communications Data:
Customer service communications and written correspondence retained for 3 years from the date of the last interaction, in accordance with the Bulgarian limitation period under applicable civil law.

d) Call Recordings:
Where customer service calls are recorded, recordings are retained for a maximum of 12 months, for quality assurance and dispute resolution purposes.

e) Location Data:
Precise geolocation data is retained for a maximum of 4 months from collection.

f) Marketing Preferences:
Retained until you withdraw your consent or unsubscribe from marketing communications.

9.2 After the applicable retention period, personal data is securely deleted or anonymised so that it can no longer be associated with you.

10. Your Rights

10.1 Under the GDPR, you have the following rights regarding your personal data:

a) Right of Access (Article 15 GDPR):
You have the right to obtain confirmation of whether we process your personal data and to request a copy of that data, along with information about how it is used.

b) Right to Rectification (Article 16 GDPR):
You have the right to request correction of inaccurate personal data or completion of incomplete data.

c) Right to Erasure (Article 17 GDPR):
You have the right to request deletion of your personal data in certain circumstances — the "right to be forgotten" — subject to any applicable legal retention obligations.

d) Right to Restriction of Processing (Article 18 GDPR):
You have the right to request that we restrict processing of your personal data in certain circumstances, for example while the accuracy of the data is being contested.

e) Right to Data Portability (Article 20 GDPR):
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.

f) Right to Object (Article 21 GDPR):
You have the right to object to processing of your personal data based on legitimate interests, including profiling, and to object at any time to processing for direct marketing purposes.

g) Right to Withdraw Consent (Article 7 GDPR):
Where processing is based on your consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.

h) Right to Lodge a Complaint:
You have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP) or with the supervisory authority in your country of residence within the EU. See Section 16 for CPDP contact details.

10.2 How to Exercise Your Rights
To exercise any of the rights listed above, please contact us at privacy@transferhood.com or dpo@transferhood.com. We will respond to your request within one month of receipt. This period may be extended by a further two months where necessary, taking into account the complexity and number of requests received. We will inform you of any such extension within the first one-month period.
We may need to verify your identity before processing your request. We will not charge a fee for exercising your rights, unless the request is manifestly unfounded or excessive.

11. Data Security

11.1 We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction.

a) Technical Measures:
SSL/TLS encryption for all data in transit
Encryption of sensitive data at rest
Secure payment processing via PCI DSS compliant processors
Regular security assessments and penetration testing
Firewalls and intrusion detection/prevention systems
Access controls, multi-factor authentication, and session management

b) Organisational Measures:
Regular data protection training for all staff handling personal data
Confidentiality agreements with employees and contractors
Access to personal data limited strictly to personnel who require it for their duties
Documented incident response procedures
Regular review and audit of security policies and controls

11.2 Despite our security measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security and encourage you to take steps to protect your own account credentials.

11.3 Data Breach Notification
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, in accordance with Article 34 of the GDPR. We will also notify the CPDP without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR.

12. Cookies & Tracking Technologies

12.1 We use cookies and similar tracking technologies to enhance your experience on the Platform. For full details, please refer to our Cookie Policy, available at www.transferhood.com/cookie-policy.

12.2 In summary, we use the following categories of cookies:
Essential Cookies: necessary for the Platform to function properly; cannot be disabled
Functional Cookies: enable enhanced functionality and personalisation
Analytics Cookies: help us understand how visitors interact with the Platform (using anonymised data where possible)
Marketing Cookies: used to deliver relevant advertisements — activated only with your explicit consent

12.3 You can manage your cookie preferences through the cookie consent banner displayed on your first visit, or by updating your settings at any time via the Cookie Preferences link in our website footer.

13. Children's Privacy

13.1 The Platform is not intended for individuals under 18 years of age. In accordance with Article 2.1 of our Terms and Conditions, you must be at least 18 years old to create an account or place a booking on the Platform.

13.2 We do not knowingly collect personal data from individuals under 18 years of age for the purpose of account creation or booking. If we become aware that we have inadvertently collected such data, we will take prompt steps to delete it.

13.3 Where Passengers include individuals between the ages of 14 and 17, the Customer who placed the booking is responsible for ensuring that any required parental or guardian consent has been obtained in respect of the processing of that Passenger's personal data. The Company does not independently verify the age of Passengers.

14. Third-Party Links

14.1 The Platform may contain links to third-party websites or services. We are not responsible for the privacy practices or content of those third parties.

14.2 We encourage you to review the privacy policies of any third-party websites you visit before providing any personal data to them.

15. Changes to This Privacy Policy

15.1 We may update this Privacy Policy from time to time to reflect changes in our data processing practices or applicable laws.

15.2 We will notify you of any material changes by:
Posting the updated policy on the Platform with a revised "Last Updated" date
Sending an email notification to registered users
Displaying a prominent notice on the Platform

15.3 Your continued use of the Platform after any changes constitutes your acceptance of the updated Privacy Policy. Where material changes affect the legal basis for processing or your rights, we will seek fresh consent where required.

16. Supervisory Authority

16.1 The competent supervisory authority for data protection matters relating to our processing activities is:
Commission for Personal Data Protection (CPDP)
Address: 2, Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria
Website: www.cpdp.bg
Email: kzld@cpdp.bg

16.2 You have the right to lodge a complaint with the CPDP if you believe we have processed your personal data in violation of applicable data protection law. You also retain the right to lodge a complaint with the supervisory authority in your country of residence within the EU.

16.3 We encourage you to contact us first at privacy@transferhood.com before lodging a formal complaint, so that we have the opportunity to address your concerns directly.

17. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:

PTS Travel Solutions Ltd.
Knyaz Boris I Street No. 8, Floor 5, Office 1, Sofia, Bulgaria
VAT Number: BG207914623
Privacy inquiries: privacy@transferhood.com
Data Protection Officer: dpo@transferhood.com
Customer support: support@transferhood.com
Phone: +908503079000

We are committed to addressing your concerns and will respond to all privacy-related inquiries within one month of receipt.
© 2025 PTS Travel Solutions Ltd. All rights reserved.
Privacy Policy | Transferhood