Skip to content

Last updated: 10 September 2026

Privacy policy

This policy explains how Disney Paris Transfers processes personal data when you use the website or book a transfer, in line with the GDPR.

1. Who is responsible

The data controller is the operator of disneyparistransfers.com. Contact: the email address published on the site (NEXT_PUBLIC_EMAIL / contact form).

2. What we collect

When you book: name, email, phone, pickup and drop-off, date and time, passenger count, luggage, vehicle preference, child seats, flight number, message, language, and the price breakdown we calculated.

When you pay online: Stripe processes the card. We store the payment status, amount and Stripe session id — not the card number.

Technically: a language cookie, an admin session cookie (back office only), and the IP used for anti-spam rate limiting on the booking API.

3. Why we use it

To provide the transfer (contract), to email confirmations, to prevent spam (legitimate interest), and to meet accounting and legal duties. We do not sell your data.

4. How long we keep it

Bookings are kept for the time needed to run the journey and for the statutory accounting period in France. Spam logs are short-lived and reset when the server restarts unless moved to a store.

5. Your rights

You may access, correct, delete or limit your data, object to processing based on legitimate interest, and lodge a complaint with the CNIL (cnil.fr). Write to us using the contact email on this site.

6. Transfers

Hosting is on a classic Node server chosen by the operator. Stripe (payments) and the mailbox provider (SMTP) act as processors. They may process data outside the EU under their own safeguards (SCCs).