Privacy policy
Personal data processing · GDPR and Spanish LOPDGDD
1. Data controller
Jose Ignacio Muñoz Delgado, tax ID 48628752J, Av. Hospital, 10, 03550 Sant Joan d'Alacant (Alicante, Spain). Contact: bookings@rodascooters.com · WhatsApp +34 641 18 16 79.
2. Data we process
- Identity: name, surname, sex, nationality, date of birth, ID type and number.
- Rider: driving licence details (category, number, date of issue, validity, issuing country, support number).
- Contact and address: email, phone, postal address.
- Booking and payment: dates, vehicle, amount and payment reference (the full card number is never stored).
We do not request or keep copies/scans of your ID or licence: we verify the document and record only the necessary data (data minimisation, Spanish DPA criteria for vehicle rental).
3. Purpose and legal basis
- Managing the rental — contract performance (art. 6.1.b GDPR).
- Renter registry reported to the Spanish Ministry of the Interior (SES.HOSPEDAJES) within 24h — legal obligation (art. 6.1.c; Royal Decree 933/2021).
- Tax obligations — legal obligation.
- Identifying the rider in traffic offences — legal obligation (RLD 6/2015).
- Marketing, only with your consent — art. 6.1.a.
4. Retention
- Rental and RD 933/2021 registry data: 3 years from the end of the service.
- Tax data and invoices: as required by tax law.
- Payment data: deleted once the deposit is released.
5. Recipients
We do not sell your data. It is shared only when necessary with: the Ministry of the Interior (SES.HOSPEDAJES), the traffic authority (DGT), the payment gateway (Stripe) and, in case of accident, the insurer — as processors with the required guarantees.
6. Your rights
You may exercise access, rectification, erasure, restriction, portability and objection by writing to bookings@rodascooters.com. You may also complain to the Spanish Data Protection Agency (www.aepd.es).
7. Security
We apply technical and organisational measures (restricted authenticated access, encryption in transit, no card number storage). High-risk breaches are notified within 72 hours (art. 33 GDPR).