PRIVACY POLICY AND COOKIE
1. INTRODUCTION
Rplustransfers (“we”, “our”, “us”) is committed to protecting your privacy in compliance with the EU General Data Protection Regulation (GDPR). This policy applies to www.rplustransransfers.com and all related services. Updates will be posted here, with substantial changes notified via email.
2. LEGAL BASIS FOR PROCESSING
-
Contractual Necessity: Payment processing and booking management
-
Consent: Marketing communications and non-essential cookies
-
Legal Obligation: Tax and regulatory compliance
-
Legitimate Interest: Service improvement and fraud prevention
3. INFORMATION WE COLLECT
We may collect:
-
Identification Data: Full name, date of birth, gender, tax ID, passport/ID details
-
Contact Information: Phone number, physical address, email
-
Financial Data: IBAN, SWIFT/BIC, payment card details (PCI-DSS compliant)
-
Transaction Records: Payment history, receipts, booking details
-
Technical Data: IP address, device type, browser version, geolocation
-
Biometric Data: Only if used for payment verification (e.g., facial recognition)
4. DATA SECURITY
We implement:
-
TLS/SSL encryption for all data transfers
-
Financial data tokenization
-
Annual third-party security audits
-
Intrusion detection systems
-
Two-factor authentication for system access
-
PCI-DSS compliance for payment processing
5. COOKIES & TRACKING TECHNOLOGIES
5.1 Cookie Types
Cookie Name | Type | Provider | Purpose | Duration | Essential |
---|---|---|---|---|---|
woocommerce_cart | Functional | WooCommerce | Shopping cart | Session | Yes |
_ga | Analytics | Google Analytics | Performance | 2 years | No |
NID | Third-Party | Google Maps | Map displays | 6 months | No |
__stripe_mid | Essential | Stripe | Payment security | 1 year | Yes |
5.2 International Transfers
-
Google Analytics (USA – SCCs)
-
Stripe (USA – Privacy Shield Certified)
-
PayPal (USA – GDPR Compliant Agreements)
6. DATA SHARING
We may disclose information to:
-
Payment Processors: Stripe, PayPal
-
Fraud Prevention Services: Sift, Riskified
-
Legal Authorities: When required under Portuguese Law 58/2019
-
Auditors: PCI-DSS compliance verification
-
Support Teams: Zendesk (EU-based processing)
7. YOUR RIGHTS
You have the right to:
-
Access personal data (free copy within 30 days)
-
Request correction of inaccurate information
-
Delete unnecessary data (“Right to be Forgotten”)
-
Restrict/object to processing
-
Data portability (CSV/JSON formats)
-
Withdraw consent (marketing/cookies)
-
Human review of automated decisions
Submit requests to: contact@rplustransfers.com (identity verification required)
8. DATA RETENTION
-
Transaction Records: 10 years (Portuguese legal requirement)
-
Website Analytics: 25 months
-
Marketing Data: Until consent withdrawal
-
Fraud Data: 7 years from transaction date
9. MINOR PROTECTION
Services restricted to users 18+. Any minor’s data discovered will be immediately deleted.
10. AUTOMATED DECISION-MAKING
We use AI-driven fraud scoring systems. You may request manual review of declined transactions.
11. CONTACT INFORMATION
Data Protection Officer:
Email: contact@rplustransfers.com
Address: São Lourenço, 8135-027 Almancil, Portugal
Supervisory Authority:
National Data Protection Commission (CNPD)
Av. D. Carlos I, 134 – 1.º, 1200-651 Lisboa, Portugal