Legal
Customer Privacy Notice
Golden Transfers is a trading name of Golden Transfers Ltd, company number 17351254. This notice explains how Golden uses personal information when you visit our website, ask for a quotation, book or take a journey, or contact us. Golden is the controller for the booking, dispatch, payment administration, support and compliance information it determines how and why to use.
Contact [email protected], marking your message “Privacy”, or call 0330 5202 560. You can write to Golden Transfers Ltd trading as Golden Transfers, [COMPLETE: Golden correspondence address]. This is an administrative correspondence address, not a public booking office. Registered office: 1 Castle Court, Castle Street, Fareham, United Kingdom, PO16 9QD. ICO registration: [COMPLETE: applicable registration reference or documented fee assessment outcome].
1 Services covered
This notice covers requests and journeys arranged through Golden’s approved channels, including corporate travel, airport and cruise transfers, event transport and bookings from tour operators, hotels and travel agents. We receive information from travellers and from authorised business bookers. Golden’s actual website, dispatch platform, payment, tracking and communication suppliers must be listed in the completion schedule before publication.
We distinguish an enquiry from an accepted journey. Optional account profiles, tracking links, call recording or app features require accurate additional information where used; their availability is not established by this document.
2 Information we use
Contact and booking information: names, telephone numbers, email addresses, pickup and destination, journey dates and times, passenger and luggage numbers, booking references, fare and instructions.
Journey administration: the accepting licensed operation, subcontract acceptance, provider identity, driver and vehicle details, dispatch and arrival events, amendments, cancellations and support records.
Assistance information: practical requirements such as a suitable vehicle, help boarding or an assistance dog. We seek only what is necessary; a diagnosis is usually unnecessary.
Financial information: agreed charges, payment status, processor references, refunds and disputes. The exact card data visible to Golden depends on the approved payment integration. Full card credentials must not be sent in ordinary email or messages.
Communications and safety information: enquiries, complaints, lost property descriptions, relevant evidence, and incident or safeguarding information where necessary and lawful.
Technical information: IP address, request times, browser information, hosting logs and enquiry protection data. Security identifiers, including hashed IP addresses if used, can remain personal information; describe actual controls and retention.
Device storage and campaign information: cookie preferences and, where the appropriate consent is given, campaign attribution. GT09 explains the technologies and the changes required before publication.
We receive information directly from you and, where appropriate, from a person authorised to book for you, a parent or guardian, an employer, hotel, school, travel agent, driver, operator or service provider. We will supply privacy information to people whose data we receive indirectly within the applicable legal timeframe, including at first communication or disclosure where required, unless a lawful exception applies.
3 Why we use information and our lawful bases
We identify a lawful basis for each actual purpose. The following describes the intended allocation; using multiple labels does not permit unrelated uses.
| Purpose | Ordinary lawful basis and limits |
|---|---|
| Quote or booking requested by the contracting customer | Steps requested before a contract and performance of the contract, Article 6(1)(b), for information objectively necessary for that task. |
| Arranging a journey for a passenger who is not our contracting customer | Legitimate interests, Article 6(1)(f), in arranging the requested journey and communicating with the passenger, subject to a balancing assessment and their reasonable expectations. |
| Statutory operator records and lawful regulatory disclosures | Legal obligation, Article 6(1)(c), where a specific legal duty applies. The relevant licence and requirement are recorded internally. |
| Payments refunds and accounting | Contract for necessary payment administration with the customer; legal obligation for required accounting records; legitimate interests for necessary fraud prevention and disputes, with the activity distinguished in our records. |
| Customer service complaints and civil claims | Contract where necessary to provide the agreed service, and legitimate interests in resolving problems and establishing or defending claims. Mandatory complaint and rights duties use legal obligation. |
| Website and information security | Legitimate interests in preventing abuse, securing the service and diagnosing faults, using proportionate logs and retention. |
| Optional email or message marketing | Consent, or another specifically assessed route permitted by electronic marketing law where its conditions are satisfied. Use a separate, optional and unticked marketing choice where consent is the selected route. |
| Optional device storage or advertising measurement | Consent where required by PECR, with a corresponding lawful basis for personal data. Any narrow statutory exception must be separately assessed and explained. |
| Serious emergency | Vital interests where its legal conditions are met; another applicable basis may cover safety reporting or statutory duties. This is not a general basis for routine bookings. |
Where legitimate interests apply, you can ask about our assessment and object. We consider the effect on individuals, use less intrusive alternatives where practicable and do not assume our interests always prevail.
4 Health safeguarding and sensitive information
Health information and information revealing certain other protected characteristics require an additional legal condition as well as an ordinary lawful basis. Practical assistance details can reveal health information even if a diagnosis is omitted. Criminal offence information has separate restrictions.
We will explain the relevant additional condition for the service concerned. For an optional saved assistance profile, explicit consent may be appropriate if the choice is specific, informed and freely given and an alternative is available. Merely typing a health detail into a form does not automatically constitute explicit consent. We will not make lawful disability assistance conditional on unnecessary disclosure or an invalid consent choice.
Other conditions may apply to legal claims, an emergency where a person cannot consent, or a qualifying safeguarding or substantial public interest purpose with the required UK statutory safeguards. They are used only where their specific conditions are met. Access is restricted to those who need the information for the task.
[COMPLETE: describe the actual Article 9 and, where relevant, Article 10 and Data Protection Act conditions used for routine assistance and safeguarding; identify any appropriate policy document and amend collection forms accordingly].
5 Who receives information
We share the minimum relevant journey and contact details with the assigned driver, Transport Provider and licensed operators involved in fulfilment. A driver or operator may be a separate controller for its own legal, safety and transport records. Its role is determined by its actual decisions, not simply by being described as a contractor. We can identify the relevant provider and its privacy contact.
Approved suppliers may handle information for us, such as hosting, email, dispatch, telephone support, outsourced booking staff, accounting and payment services. A processor must act under an appropriate written contract and instructions. Some providers, including payment firms for their own fraud prevention or legal duties, may also act as controllers.
Where necessary and lawful, information may be shared with licensing authorities, police, safeguarding bodies, courts, insurers and professional advisers. We assess the purpose and authority for a request; not every request makes disclosure compulsory. Necessary disclosures may protect safety or establish legal claims as well as meet a legal duty.
[COMPLETE: actual hosting, email, dispatch, BPO and payment suppliers; their relevant roles and privacy information]. We do not sell passenger lists or authorise suppliers to use booking data for their own marketing or AI training without a separately assessed lawful arrangement and appropriate transparency.
6 Payments and location information
If card payment facilities, including Stripe, are offered, the payment page or link will identify the provider and relevant processing information. We retain transaction references and accounting records needed for the booking. Receipt of a fare as transport provider agent does not make every payment processing purpose an agency activity for data protection purposes.
If a journey tracking service is activated, we use the location information necessary to dispatch, follow the journey and deal with safety or service issues. We will state whose location is collected, when tracking operates and who can see it. Optional passenger device location must have a clear alternative such as entering an address. A tracking link should be shared only with intended recipients.
[COMPLETE: whether tracking or payment links are actually used, providers, location intervals, access controls and retention; remove unused features from the published version].
7 Calls cameras and automated decisions
These documents do not establish that Golden records calls or operates CCTV. If we introduce recording, we will provide a notice at the relevant point, explain the purpose and lawful basis, and specify retention and access. An independently controlled driver camera requires the appropriate operator or driver notice and allocation of responsibility. Continuous audio recording is not assumed necessary.
We have not identified an approved system making solely automated decisions with legal or similarly significant effects under this pack. Ordinary routing or dispatch support is not automatically such a decision. Before introducing significant automated refusal, profiling or another qualifying decision, we will assess applicable legal conditions and safeguards, provide relevant information and a route to human review where required.
8 International access and transfers
Information accessed by a separate overseas BPO or other organisation may be a restricted international transfer even where the server remains in the UK. We identify recipient countries and apply an appropriate lawful mechanism, such as applicable UK adequacy regulations or a suitable UK International Data Transfer Agreement or UK Addendum with the required assessment and safeguards.
[COMPLETE: countries, recipients, transfer mechanism and how a person may request information about safeguards]. An ordinary confidentiality or processing clause alone does not complete a required transfer arrangement. If there are no restricted transfers, say so only after verifying suppliers, remote support and subprocessors.
9 Retention
We keep information only for as long as justified by the relevant purpose and legal requirements, then delete it or make it effectively anonymous. The expiry of a browser item is different from the retention of an email, server log or accounting record. A live dispute or safeguarding matter may justify a documented hold on relevant records; it does not justify retaining every record indefinitely.
| Record | Public retention information to complete from GT23 |
|---|---|
| Enquiries that do not become bookings | [COMPLETE: approved period measured from last meaningful contact]. |
| Booking and dispatch records | [COMPLETE: actual period and trigger, meeting each applicable licence minimum]. |
| Financial and contractual records | [COMPLETE: categories and periods meeting applicable tax and other legal duties, avoiding blanket retention of unnecessary journey or health detail]. |
| Complaints incidents and rights requests | [COMPLETE: approved periods and case-specific safeguarding criteria]. |
| Hosting security and form protection logs | [COMPLETE: actual log periods and automated deletion of rate limit files]. |
| Optional recordings and tracking | [COMPLETE: actual periods or confirm not in use]. |
| Marketing consent and suppression | Keep evidence while needed to demonstrate the choice; retain a minimal suppression record to honour an opt out, with review. |
10 Marketing and website choices
You can refuse optional marketing and still enquire or book. You can withdraw marketing consent using an unsubscribe route or the contact above. Booking updates about an accepted journey are service communications, although promotional content within them would require its own assessment.
GT09 explains website storage and choices. Complete its inventory from Golden’s actual deployed systems, including any embedded supplier. Technologies used by another trading brand are not automatically used by Golden Transfers.
11 Your rights
Depending on the circumstances, you may request access, correction, erasure, restriction or portability of your information and object to processing. You can withdraw a consent without affecting processing that was lawful before withdrawal. Rights have legal conditions and exceptions; for example, required booking records may need to be retained despite an erasure request.
Contact us through any reasonable route. You do not have to use a particular form or legal wording. We may seek proportionate evidence of identity or authority where needed. We normally respond within one calendar month. Where a lawful extension, clarification or other timing rule applies, we will explain it and follow the applicable requirements.
12 Privacy complaints
Tell us what happened and the outcome you seek. We will acknowledge a privacy complaint within 30 days, investigate and respond without undue delay, and keep you informed. This is an acknowledgement deadline, not a promise that every complaint will take 30 days or be resolved on that date.
You can complain to the Information Commissioner’s Office through the ICO complaints service or telephone 0303 123 1113. You retain rights to seek a legal remedy. Our internal process does not remove the right to approach the regulator.
13 Publication and changes
Effective date: [COMPLETE: approval date]. We will update this notice when actual processing changes and provide further information where required. The preparation date is 15 September 2026. Before publication, complete the supplier, sensitive data, retention and international transfer fields and align the website, forms and working practices with this notice.
14 Corporate and tour booking disclosures
A corporate client may provide employee or guest contact information, cost-centre references and authorised travel instructions. A tour operator may provide a proportionate passenger manifest and tour-leader contact. We normally need the practical journey and assistance information, not passport copies, full rooming lists, a complete package itinerary or medical history.
We may share necessary status and billing information with the authorised contracting client or tour operator. An employer does not receive unrestricted live location, health information or every personal communication merely because it pays. Traveller-facing information must identify Golden and the relevant transport arrangement. GT18 records controller sharing and cooperation, including safe contact routes, passenger rights and any overseas recipients. We do not infer that all business-client processing is processor activity.