Rudy's Executive Transportation Privacy
Rudy’s Executive Transportation and its affiliated entities (collectively, "Rudy’s", "us" or "we") are committed to protecting your privacy. This Privacy Statement describes Rudy’s information practices and the choices available to you regarding Rudy’s use of information that can be used to identify you ("Personal Data").
Rudy’s respects your privacy and will only process and use your information as part of providing you with our services. This document outlines our business practices on use of personal information. We engage with our customers through our ground transportation booking tools (CBT), GDS Tools, Mobile Apps, Websites, and Web applications collectively referred to herein as "Transportation Services".
By using the Transportation Services, you acknowledge that Rudy’s will use your information in the United States, and any other country where Rudy’s operates or Rudy’s services are used. Please be aware that the privacy laws and standards in certain countries, including the rights of authorities to access your personal information, may differ from those that apply in the country in which you reside.
If you have any questions about our Privacy Statement, you can contact your Account Manager.
3. The data we process
Depending on how you interact with us either directly or through your authorized agent/booker, we process different kinds of data and in different ways. Some data is automatically processed if you communicated with us through our CBT/GDS Tools or use our Products (i.e. Channels). Data is only processed if you or your authorized agent/booker actively submit it to us (like using our web forms to create/update a reservation or use our mobile app or website to get in touch with us. We need to process your personal information in order to provide the service and run our business. By accepting our Terms and Conditions as outlined in your order confirmation and our website, you and/or your authorized agent/booker are confirming that you have read and understand this policy, including how and why we use your information.
Data we collect and/or process in the course of Booking our Transportation Services or if you communicate with us via any of our Channels:
· Registration, Account Setup, Service Usage: In order to provide set up an account, you need to provide a valid email address, full name, phone number and password. In order to book a ride, you need to provide a pick-up and drop-off addresses, and credit card information. We may need to store encrypted credit card information and use it for both billing and payment purposes
· Website and Web application Usage Data: Even if you are only a visitor to our websites or user of the Mobile App, your computer or device automatically sends technical information to our web servers that we store in log files, including the following:
o Date and time of the visit and the duration of use of the Site;
o The IP address of your device as well as your internet service provider (ISP);
o The referral/exit URL;
o The visited subsites of the Site;
o Clickstream data; and
o Information about your device (type of device, browser type and version, as well as settings, installed plug-ins, operating system).
We process Website Usage Data to allow you to surf the Site and to ensure its functionality. We also process Website Usage Data to perform analyses on the performance of the Site, to continuously improve the Site and correct errors, to ensure IT security and operation of our systems, as well as to prevent or uncover abuse. We further process this data in aggregated or pseudonymized form to analyze trends, administer the Sites, track users' movements around the Sites, and to gather demographic information about our user base as a whole or to improve marketing (including serving you personalized, interest- based ads) as well as the user experience on our Site and guaranteeing the safety of our IT systems.
We may also automatically collect device-specific information when you install, access, or use our Transportation Services. This information may include information such as the hardware model, operating system information, app version, app usage and debugging information, browser information, and device identifiers.
· Cookies: We use the following types of cookies (you may adjust the cookie settings in your browser at any time):
Permanent Cookies - These cookies are required to enable core site functionality.
o Remember log-in details and provide secure log-in
o Provide secure log-in
o Remember your task or transaction progress
o Remember how far you are through an order
Session/Functional Cookies - These cookies enable additional functionality like saving preferences, allowing social interactions, and analyzing usage for site optimization.
o Analyze site usage to provide custom content
o Remember your log-in details
o Conduct analytics to optimize site functionality
o Remember what is in your shopping cart
o Allow third parties to provide social sharing tools
o Make sure the website looks consistent
· Mobile application Usage Data: As part of mobile OS feature set, it is possible to share data between apps on mobile device. Rudy’s Mobile applications provide additional features based on users' permissions.
o Location information is used if app has the user's permission.
o Contacts Address is used if app has the user's permission. This information is used to select an address for a ride location.
o Touch and Face ID are used for login if user requested it
o Ride information is added to the device's Calendar if app has user's permission. App does not read the user's calendar.
o Camera is used to take a picture if app has user's permission.
o Microphone is used to by user's permission.
Data we process only if you submit it to us:
When you interact with us through any of our Channels, you can submit Personal Data to us in various situations, including:
Account Data: On some of our Channels ("Interactive Channels"), you can register for an account with your e-mail address, a password and/or encrypted credit card information you create. If you register, you will automatically create an account you can use to manage your Profile and Communication settings, including making updates to your Personal Data. On Interactive Sites, you can create a profile, which may include your Personal Data. We will store your account data for you to be able to communicate with others on our interactive Sites.
Location Information: When you use our Mobile App, you may consent to share your geo-location details with Rudy’s in order to automatically set your pick-up location. We may use and store information about your location to provide features and to improve and customize the Transportation Services. We will only share your geo-location details with servicing parties in order to provide you with the Transportation Services.
Feedback Information: When using the app and with your consent, Rudy’s will use your transportation reservation data in order for you to more easily provide feedback about your experience with the App and the service.
Analytics Information: We use data analytics to ensure site functionality and improve the Transportation Services. We use a mobile analytics software to allow us to understand the functionality of the App on your phone. This software may record information such as how often you use the App, what happens within the App, aggregated usage, performance data, app errors and debugging information, and where the App was downloaded from. We do not link the information we store within the analytics software to any personally identifiable information that you submit within the mobile application.
SSO Information from Companies or Third Parties: Some visitors may choose, at their discretion, to connect to Rudy’s products using a Single Sign-On managed by their company or external third-party. Rudy’s may receive information from that connected third-party application.
Affiliated Passenger Information: Rudy’s may receive or obtain information (for example, an email address) about a person who is not a registered with Rudy’s (an "affiliated passenger") in connection with certain Rudy’s features (e.g., when an additional passenger is added to the ride booking). Affiliated Passenger information is used only for ground transportation services and purposes disclosed when it was submitted to Rudy’s.
Transaction Data: In relation to your transportation request you may make online or over the telephone, we will process your contact and billing information, such as your name, address, and credit card information. You can view the exact information required in the form provided at point of purchase. We will only use this data to provide transportation services, for billing purposes, and for internal accounting.
Customer Support Data: You can communicate with us through the different web-forms and chat functionalities on our Sites. For example, you can use the contact forms to request information on the status of your transportation order, or otherwise reach out to our customer support team. In order to respond to your request, we will process your IP address and contact data as well as the contents of your request. This data is used temporarily until we provide the service and guide to resolve issue then it is deleted.
Survey Data: From time to time we may conduct surveys in respect of our products and services. Participation in our surveys is optional. However, if you respond to one of our surveys, you may provide us with personal information about you. Unless you otherwise consent, we will only use this information to determine the types of Products that may be of interest to you and to operate and improve our Product offerings.
Email/Direct Mail Campaign Data: From time to time, we may contact our customers directly by mail, email, or telephone to inform you about upgrades, new products, promotions, or special offers that you subscribed with us and you were interested in receiving (including our newsletters). However, we will not contact you with any commercial communications that are unrelated to the Products that you have purchased from us unless you have given us your prior consent to receiving such information. When responding to one of these campaigns, you may have the option to provide us with personal information, which we will use for the purpose indicated. See Section 8 below for information on how to change your account's communication preferences.
Affiliate Service Providers: We may collaborate with another affiliated transportation company to provide you with transportation services outside our local market. Our use of your Personal Data is limited to the specific transportation request in a different market that you have requested or elected to use and we will only share specific Personal Data that is required for completion of transportation request. We do not share email address or credit card information with any affiliate transportation provider.
4. How do we use your personal information?
Where we process your information without your consent, we do as follow:
Booking and improving our Transportation Services: We may use customer information as it is necessary to pursue our legitimate interests of improving our Transportation Services for our users, understanding how our Transportation Services are being used, and exploring and unlocking ways to develop and grow our business.
Keeping our Transportation Services safe and secure: We may also use customer information for safety purposes, in order to ensure the security of our Transportation Services.
Legal and Safety: Rudy’s may also retain, preserve, or release your personal information to a third party in the following limited circumstances: in response to lawful requests by public authorities; to protect, establish, or exercise our legal rights or defend against legal claims; to comply with a subpoena, court order, legal process, or other legal requirement; or when we believe in good faith that such disclosure is reasonably necessary to comply with the law, prevent imminent physical harm or financial loss, or investigate, prevent, or take action regarding illegal activities, suspected fraud, threats to our property, or violations of Rudy’s Terms & Conditions.
5. Sharing personal data with third parties
We treat your Personal Data with care and confidentially and will only pass it on to third parties to the extent described below and not beyond. We do not share, sell, rent, or trade Personal Data with third parties for any promotional purposes. Where our affiliates or service providers process Personal Data, they will do so solely on our instructions and have undertaken to comply with strict contractual requirements for the security of your data (including, but not limited to, complying with this Privacy Statement).
Rudy’s will not process or share your personal information without your consent, except based on the following legal grounds:
· It is necessary to perform the contractual obligations in our Terms & Conditions and in order to provide the Transportation Services to you;
· It is necessary to comply with a legal obligation, a court order, or to exercise or defend legal claims;
· It is necessary for the purposes of our or a third party's legitimate interests, such as those of visitors, members, or partners;
· You have expressly made the information public;
· It is necessary in the public interest;
· It is necessary to protect your vital interests, or those of others.
6. Data retention
We process and store your Personal Data as long as necessary for the fulfillment of our contractual or legal obligations. Thus, we store the data as long as our contractual relationship with you as our customer obliges us to do so. After termination of our contract, we will store Personal Data only to the extent and for as long as applicable law requires. All other data will be deleted immediately when you, as a customer, unsubscribe from our Products or other services. If the remaining data is no longer required for the fulfillment of legal obligations, it will be regularly deleted, unless its further processing is necessary for the preservation of evidence or the prevention of legal claims from becoming time-barred.
The security of your personal information is important to us. Your account information is protected by a password. It is important that you protect against unauthorized access to your account and information by choosing your password carefully and by keeping your password and computer secure, such as by signing out after using the Transportation Services.
Rudy’s follows the industry best practices to protect the personal information submitted to us, both during transmission and after it is received. Some of these standards are:
· Encryption of certain information (such as credit card numbers) using secure socket layer technology (SSL);
· Protection of the confidentiality, integrity, and availability of all customer information systems;
· Definition and monitoring of IT security standards aligned with industry regulations;
· Implementation of vulnerability management techniques according to which we scan and map our network, prioritize areas of importance and apply fixes and safeguards;
· Application of safeguard firewalls and anti-virus tools to detect/prevent attacks;
· Continuous monitoring for security risks and maintenance of patch updated infrastructure;
· Security awareness trainings to our personnel.
With regard to credit card information, we comply with the Payment Card Industry Data Security Standard ("PCI DSS") by (but not limited to) designing, implementing, and maintaining a coherent set of standards and procedures to manage risks to cardholder data – in an effort to ensure an acceptable level of Information Security risk – and by conducting yearly PCI DSS audits.
We regularly review, test and update our security policies and systems in order to meet the highest standards of data security. Unfortunately, no method of transmission over the internet or method of electronic storage is 100% secure. Therefore, while we strive to protect your personal information, we cannot guarantee its absolute security.
8. Reviewing and requesting changes to your personal data
EU users: please refer to Section 10 below for your statutory rights under the GDPR
We know that our customers value having control over their own information, so Rudy’s gives you the choice of booking or editing certain information, as well as choices about how we contact you.
Upon request, Rudy’s will make a reasonable effort to inform you regarding whether we hold any of your personal information. Customers may update, delete, access, or change their account information by editing their user, group, or booking agent records. To update a customer profile or billing information, email us at firstname.lastname@example.org. We will respond to any requests for access to personal information within 30 days after receipt of such request.
If you have signed up to receive marketing emails from Rudy’s, you can opt-out of receiving future marketing emails by following the foregoing process. Customers cannot opt-out of receiving all transactional emails related to their Rudy’s product account but may change their account settings (as described above) to reduce the frequency or eliminate certain Rudy’s notification emails.
You also have the following additional rights with respect to your information:
Data access and portability: Access to and portability of your data are available by downloading your ride history and personal data by logging into your Rudy’s product account.
Data correction and/or editing: Personal, ride, password and payment information can be easily changed by logging into your Rudy’s product account.
Account deactivation: You may request that your account be deactivated and no longer be visible. However, Rudy’s must maintain your information in order to comply with legal obligations.
Withdrawal of consent or objection to processing: You can object to data processing in certain limited circumstances. In such cases, we will cease processing your information unless we have compelling legitimate grounds to continue processing or where it is needed for legal reasons.
Where we use your data for direct marketing purposes, you can always object by withdrawing your consent, using the "unsubscribe" link in such communications or changing your marketing preference settings.
Personal, payment and ride information are required to provide your rides, receipts, cancellation notices, etc. Rudy’s cannot offer or fulfill the Transportation Services without processing this information.
Rudy’s strives to meet its customers' inquiries. If you have a concern about your service or the processing of your information, please contact customer service.
Right not to be subject to a decision based only on automated processing: Much of Rudy’s processing (booking, billing, fulfilling your ride) is automated in order to protect the security of your information and bring you high quality services. If you would like to speak to a Rudy’s agent, please contact customer support or your account manager. Decisions based on automated processing cannot be avoided when they are necessary to perform the Transportation Services or authorized by EU law.
Complaint filing: If you have used our Transportation Services while physically in the EU (i.e., you have taken a ride in the EU, and/or booked a ride while in the EU), you have the right to file a complaint against Rudy’s with the European Data Protection Supervisor ("EDPS"), regarding personal data processed specifically for those events. The EDPS's contact details are: Office of the European Data Protection Supervisor, Rue Wiertz 60, B-1047 Brussels, Belgium, email: email@example.com.
If you live in the EU, you may also file a complaint with your local data protection authority.
9. Messages from Rudy’s
On occasion, Rudy’s may need to contact you. These communications are service-related and necessary for members and Guest Checkout users. You agree that Rudy’s can send you service-related communications, such as those related to rides, transactions, your account, or security. Examples of service-related communications include an email address confirmation/welcome email when you register your account, notification of a booked ride, modification of key features or functions, and correspondence with Rudy’s support team.
When you register for an account or provide us with your email address or phone number (e.g., for a Guest Checkout booking), you can agree to receive marketing communications from us. You can unsubscribe at any time from marketing communications through the opt-out link included in the marketing communications or through your account settings.
10. Information for EU Residents:
You are not legally required to provide Rudy’s with the Personal Data described in this Privacy Statement. Further, the contractual relationship that you might have entered into with us by making a reservation for our Transportation Services does not imply any obligation to provide your Personal Data. However, you might not be able to use our Transportation Services to the full extent if you do not provide us with certain data or object to the use of these data in order to complete the transportation request.
Our Legal Basis for Processing your Personal Data
When processing your Personal Data, we rely on the General Data Protection Regulation ("GDPR"), an EU-wide legal framework for the standardization of data protection. Rudy’s primarily processes data as a controller, for the purposes explained above under Sections 1 and 2 of this Privacy Statement. These purposes represent our legitimate interests for the purposes of Article 6 (1) f) GDPR. At the same time, some of the Personal Data we process is necessary for us to perform a contract with you or in order to take steps at your request prior to entering into a contract with you. For example, if you express your interest in transportation services, such as by filling out a webform, we will process the Personal Data submitted to comply with your request. This may include sharing your Personal Data with one of our authorized affiliates, who will then use your Personal Data to complete the transportation request. In addition, we are legally obliged to provide certain information to criminal prosecution or tax authorities in individual cases upon request. In these cases, the legal basis for the processing is either legal requirements (Article 6 (1) c) GDPR) or reasons of public interest (Article 6 (1) e) GDPR).
Transferring your Data outside the EU or the EEA
Rudy’s principal place of business is in United States, which is a "Third Country" under the GDPR. Third Countries are generally not considered to afford the same level of protection that you enjoy in the EU, but Rudy’s still provides an adequate level of protection for your Personal Data - decision 2002/2/EC of the EU Commission states that Canada is deemed to provide an adequate level of data protection regarding commercial organizations such as Rudy’s. We have ensured that our service providers and affiliates have either certified under the EU-U.S. Privacy Shield Framework and will process all Personal Data received from EU member states in reliance on the Privacy Shield Framework or that they have been subjected to strict contractual provisions in their contract with us to guarantee that an adequate level of data protection for your data is guaranteed.
Your rights regarding the processing of your Personal Data As a natural person, you have certain rights as "Data Subject". You can assert the following rights against us under the GDPR:
· Your right to information and access under Article 15 GDPR,
· Your right to correction under Article 16 GDPR,
· Your right to erasure under Article 17 GDPR,
· Your right to restriction of processing under Article 18 GDPR, and
· Your right to data transferability under Article 20 GDPR.
In addition, you have a right of objection to the competent data protection supervisory authority under Article 77 GDPR, but only with respect to the data processing we conduct on our own behalf, as a controller. In the event Rudy’s acts as a processor of your data for a third party, you must refer to the entity acting as controller to assert this right.
Information about your Right of Objection under Article 21 GDPR
1. Right of objection in individual cases
In addition to the rights already mentioned, you have the right, for reasons arising from your particular situation, to object at any time to the processing of Personal Data relating to you, which is processed on the basis of Article 6 (1) e) GDPR (data processing in the public interest) and Article 6 (1) f) GDPR (data processing on the basis of a balance of interests); this also applies to profiling based on this provision within the meaning of Article 4 (4) GDPR. If you file an objection, we will no longer process your Personal Data unless we can prove compelling grounds for the processing that outweigh your interests, rights and freedoms or the processing serves to assert, exercise, or defend legal claims. Please also note that, if we terminate the processing due to your objection, the Channels and/or Services may no longer be available to you or only to a limited extent.
2. The right to object to the processing of data for advertising purposes
You also have the right to object at any time to the processing of your Personal Data for the purpose of direct marketing, including any subscription to our newsletters or personalized ads; insofar as it is associated with such direct marketing. If you object, we will no longer process your Personal Data in the future.
The objections can be made form-free and should be addressed to: firstname.lastname@example.org
Rudy’s reserves the right to change this Privacy Statement. We will provide notification of the material changes to this Privacy Statement through our website at least 30 days prior to the change taking effect. If we believe that the changes are material, we'll do one of (or both) the following: (i) post notice of the changes on the website before the changes become effective, (ii) send you an email about the changes before the changes become effective. We encourage you to check back regularly and review any updates.
85 Old Long Ridge Road
Stamford, CT 06903