Privacy Policy
How we handle personal data across Trip Booker.
Draft — pending legal review
This page is a working draft prepared ahead of formal legal sign-off. It is not yet a finalised legal document and should not be relied on as one. last updated 28 September 2026.
1. Who we are
Trip Booker is a trading name of Quexo Limited, a company registered in England and Wales (company number [Company number]), registered office at [Registered office address]. Quexo Limited is UK VAT-registered (VAT number [VAT number]).
For any question about this policy, contact us at [email protected]. A dedicated data protection contact will be confirmed here once appointed: [Data Protection Officer / privacy contact details].
2. Who is the controller of your data
Trip Booker serves four separate groups of people — customers, coach operators, drivers, and Quexo's own staff — and the controller changes depending on which group you're in and what the data is for:
- Your Trip Booker account (platform identity). Your email, name, phone number, and sign-in history — the record that lets you log in once and see bookings across every operator you've used — is controlled by Quexo Limited.
- Your booking with a specific operator. The trip you booked, your passenger details, emergency contact, and any notes you gave that operator are controlled by that operator — they decide why the data is collected and how long it's kept for their own records (subject to the retention rules below). Quexo Limited processes this data on the operator's behalf, as their data processor, under a data processing agreement set out in our operator Terms of Service.
- Operator, driver, and admin account data. If you're an operator dashboard user, a driver, or a Quexo staff member, Quexo Limited is the controller of your account data, in the same way any software provider is the controller of its own users' account records.
In practice this means: if you have a question about a specific booking (its price, your seat, a refund), the operator you booked with is usually the right first point of contact. If you have a question about your Trip Booker account itself, or about how the platform works, contact us directly.
3. What we collect
We only collect what the service actually needs to run safely:
- Customers — email address, name, and phone number if you create a Trip Booker account; sign-in event history; optionally a linked Google or Apple identity if you choose social sign-in.
- Bookings — the name, email, and phone number you give at checkout (whether or not you create an account), your chosen pickup point, and payment status. We never see or store your card details — see section 6.
- Passengers — for every seat booked, a passenger name, an emergency contact name and phone number (required for every booking without exception — this is a duty-of-care requirement so the operator and driver can act quickly if something happens on the day), and an optional free-text notes field for things like allergies, mobility needs, or medical conditions relevant to the trip. Where filled in, that notes field may contain what UK GDPR treats as special category data (health information); we hold it strictly for passenger-safety purposes, and it's visible only to the operator running the trip and the driver assigned to it.
- Operators — business details, the dashboard users' email, name, and role, sign-in history and IP address, and (if enabled) a two-factor authentication secret.
- Drivers — email, name, and, if the driver chooses to add them, a profile photo, short bio, and Instagram handle shown to passengers. Drivers can see the passenger manifest — including emergency contacts and any medical notes — for trips they're assigned to, and nothing else; every manifest view is logged.
- Everyone — basic technical data generated by using the site (IP address, browser user agent, timestamps of requests) for security and fraud-prevention purposes.
4. Why we use it, and our legal basis
| Purpose | Legal basis |
|---|---|
| Taking and confirming a booking, running your account | Performance of a contract |
| Emergency contact and medical/accessibility notes | Vital interests / legitimate interests (passenger safety), and explicit consent where special category data is volunteered |
| Processing payment via Stripe | Performance of a contract |
| Fraud prevention, bot protection, audit logging, account security | Legitimate interests |
| Keeping financial and booking records | Legal obligation (UK tax and accounting law) |
| Marketing emails from an operator you've booked with | Consent (opt-in, withdrawable at any time) |
5. Who we share it with
We don't sell personal data. We share it only where necessary to run the service, with the following sub-processors:
| Sub-processor | What for |
|---|---|
| Stripe | Payment processing and operator payouts. Stripe is the regulated payment institution — Trip Booker never holds or sees your full card details (see section 6). |
| Resend | Sending transactional email — sign-in links, one-time codes, booking confirmations. |
| DigitalOcean | Application hosting, and private object storage ("Spaces") for images such as trip photos and pickup-point photos. |
| Cloudflare | Content delivery network, DDoS protection and web application firewall in front of every request, and the Turnstile bot-detection widget on sign-in and sign-up forms. |
| Sentry | Error monitoring, so we can find and fix bugs quickly. Only active where a Sentry project has been configured for the environment you're using; request bodies and query parameter values are configured never to be sent to it. |
We do not load any third-party font, analytics, or advertising service on the platform. Some of these sub-processors operate outside the UK; where they do, appropriate safeguards (such as the UK's International Data Transfer Addendum or equivalent standard contractual clauses) are in place.
6. Payment data
Card details are entered directly into Stripe's own secure form elements — they never touch Trip Booker's servers. This keeps us in the lightest tier of card-industry compliance (PCI SAQ A). Trip Booker is not a payment institution; Stripe is the regulated entity that holds and moves the money (see our Terms of Service and Customer Terms).
7. Cookies
We use a small number of strictly necessary cookies — no advertising cookies, no third-party tracking cookies:
- Session cookie — keeps you signed in. Scoped to the exact subdomain you're on (an operator's site, or the main Trip Booker site) so a session on one can't be read from another.
- CSRF token — a security token embedded in the session, used to confirm form submissions genuinely came from our own pages.
- Trusted-device cookie (operators only) — set for 30 days after an operator confirms a two-factor code on a device, so they aren't asked for a code again on every sign-in from that browser. Revocable at any time from the operator dashboard.
- Cloudflare Turnstile — where a sign-in or sign-up form is protected by Turnstile's bot-detection widget, Cloudflare may set its own cookie or use similar local state as part of that check.
8. How long we keep it
| Data | Retention |
|---|---|
| Active account data | Until you ask us to delete it |
| Bookings, payouts, and commission invoices | 7 years — a UK financial record-keeping requirement |
| Security audit logs | 2 years |
| Sign-in links and one-time codes | 30 days past expiry |
| Database backups | 30 days |
9. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Ask us to delete your data. In practice: your account is de-identified and any bookings you've placed are kept but stripped of personal identifiers (name, email, and phone replaced; emergency contacts and notes removed) — we can't fully erase booking records outright, because UK tax law requires us to keep financial records for 7 years, but nothing personally identifying remains in them after this process.
- Export your data in a portable, machine-readable (JSON) format.
- Object to or ask us to restrict certain processing, including marketing.
- Withdraw consent at any time for anything based on consent (e.g. marketing emails).
To exercise any of these rights, contact us at [email protected], or contact the operator directly if your request relates to a specific booking they control.
9a. How to make a request
Email [email protected] from the address on your account and tell us what you'd like — a copy of your data, or for it to be deleted. We'll verify it's really you before doing anything, and respond within one month, as UK GDPR requires. If your request is really about a specific booking (its price, a refund, changing details), the operator you booked with can usually help faster — see section 2.
Requests are handled by a member of the Quexo team, not automatically — an export is a downloadable file we prepare for you, and a deletion replaces your name, email, and phone number with an anonymised placeholder everywhere we hold them (except on financial records we're legally required to keep for 7 years, and account rows we've already deleted in this way). Neither is instant, but both are logged so we can show we met the deadline.
10. Complaints
If you're unhappy with how we've handled your data, we'd like the chance to put it right first — contact us at [email protected]. You also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), at ico.org.uk or by phone on 0303 123 1113. Our ICO registration number: [ICO registration number].
11. Children
Trip Booker is not directed at children, and Trip Booker accounts are intended for adults booking trips. Passenger details for children travelling with a booking adult are provided by that adult.
12. Changes to this policy
We'll update the date at the top of this page whenever we make a material change, and — while this remains a draft — expect the content itself to change as legal review progresses.