Privacy & Cookie Policy
LAST UPDATED: AUGUST 16, 2026
- What this policy covers
- Who is responsible for your data
- Privacy contact
- How we protect your data
- Visiting our website
- Cookies and similar technologies
- Booking a ride
- Your account and My Ride links
- Payment and fraud prevention
- Invoices and bookkeeping
- When you contact us
- Ride emails, reminders and offers
- Service providers we work with
- Your rights
- Automated decisions
- How long we keep your data
- Changes to this policy
- Cookie Policy
What this policy covers
AmstelCab is a chauffeur service in Amsterdam. To drive you somewhere we inevitably need to know a few things about you — where to pick you up, how to reach you, and how you paid. This policy explains, in plain language, which personal data we process when you visit amstelcab.nl, book a ride, use a My Ride link, or hold an AmstelCab account, and why we process it. We handle personal data in line with the EU General Data Protection Regulation (GDPR / AVG).
Our service is intended for adults. We do not knowingly collect data from children, and our website is not aimed at them.
Who is responsible for your data
The controller for all processing described here is:
AmstelCab
Burgemeester van de Pollstraat 477
1064 AN Amsterdam, Netherlands
Chamber of Commerce (KvK): 97225444 · VAT: NL005255853B28
E-mail: info@amstelcab.com · Phone: +31 6 85141194
Privacy contact
We are a small company and have not appointed a formal data protection officer — the law does not require one for an operation of our size. Privacy questions and requests go directly to the owner: e-mail info@amstelcab.com with “Privacy” in the subject line and we will reply within a few working days.
How we protect your data
All traffic between your device and AmstelCab is encrypted (TLS — the padlock in your browser). Login works without passwords: we e-mail you a single-use code that is valid for ten minutes and stored only in hashed form. Ride links use signed tokens that expire. Card details never touch our servers — they go straight from your browser to our payment provider, Stripe. Access to booking data inside AmstelCab is limited to the people who need it to run your ride.
One honest caveat: ordinary e-mail is encrypted in transport but not end-to-end. Please don’t e-mail us copies of identity documents or other sensitive papers unless we explicitly ask and agree on a safe route.
Visiting our website
When you browse amstelcab.nl — even without booking anything — our hosting providers automatically log technical data: your IP address, the pages requested, date and time, browser type and the referring page. We use these logs to keep the site running, to debug problems, and to detect abuse such as fraudulent bookings or attacks. If you just browse without booking, we don’t know who you are.
Legal basis: our legitimate interest in operating a working, secure website (Art. 6(1)(f) GDPR).
Booking a ride
Booking works without an account. To arrange your ride we process:
- Your name, and your e-mail address and phone number so we can reach you about the ride;
- Pickup and drop-off addresses, including their map coordinates, distance and estimated duration;
- Pickup time, and return time for return trips;
- Vehicle class, number of passengers and luggage;
- Your flight number, if you give one, so we can track delays and adjust the pickup;
- Any note you write for the chauffeur, and a promo code if you use one;
- The fare, payment status and — after the ride — any rating or feedback you choose to leave.
If you book for someone else, we also process that person’s name and, optionally, their phone number and e-mail address so we can send them the ride details. Only share someone’s details with us if you have their permission. The passenger receives the itinerary and chauffeur details, but never the price or the invoice — those stay with you as the person who booked.
Your chauffeur receives what is needed to drive you and nothing more: your name, the addresses and times, flight number, passenger count and your note — never your payment details. Our dispatch team is alerted to new and cancelled bookings through WhatsApp-based messaging (a Meta service), so the core booking details pass through that channel to reach our operators quickly.
To turn typed addresses into routes and prices, the addresses you enter are looked up through mapping services (see section 13). Your flight number is checked against Schiphol’s public flight data — that request contains the flight number only, never your identity.
Legal basis: performance of the transport contract (Art. 6(1)(b) GDPR). Optional extras you provide voluntarily — a flight number, a note, feedback — rest on your consent (Art. 6(1)(a)) and our legitimate interest in running a good service (Art. 6(1)(f)).
Your account and My Ride links
An AmstelCab account is optional and passwordless. You log in with your e-mail address and a six-digit code we send you; the code is valid for ten minutes, stored only as a hash, and locked after five wrong attempts. A login keeps you signed in for thirty days. Your account can hold your name and phone number, saved addresses (like “Home”), frequently travelling companions, and your ride history. As with guest bookings: add a companion’s details only with their permission.
Every booking gets a private My Ride link so you can follow the status, and — as the payer — see the price and download the invoice. These links contain a signed token and work without logging in, which means anyone who has the link can view the ride details until the link expires (between 24 hours and 30 days, depending on how the link was issued). Treat a My Ride link like a ticket: don’t forward it to people who shouldn’t see your trip. Links shared with a fellow passenger show the journey but never the price or invoice. Once a chauffeur is assigned, the link also shows their name, vehicle, licence plate and a way to reach them.
From your account you can download a copy of your data and delete the account — see section 14.
Legal basis: performance of our agreement with you (Art. 6(1)(b) GDPR) and, for optional profile extras, your consent (Art. 6(1)(a)).
Payment and fraud prevention
Payments are handled by Stripe, a PCI-DSS-certified payment provider. You can pay by card, iDEAL, Klarna or Apple Pay. Your card or bank details go directly from your browser to Stripe; AmstelCab never sees or stores them. On our side we keep only the payment reference, the amount, the payment status and any refund status — enough to match a payment to a booking and to process refunds under our cancellation policy.
Stripe screens transactions for fraud on its own systems and may decline a payment it considers suspicious. How Stripe processes data is described in Stripe’s privacy policy.
Legal basis: performance of the contract (Art. 6(1)(b) GDPR); fraud prevention rests on our and Stripe’s legitimate interest (Art. 6(1)(f)).
Invoices and bookkeeping
After payment we generate an invoice with your name, contact details, the route, the date, and the fare including 9% VAT. You receive it by e-mail and can download it via your My Ride link or account. Because Dutch tax law obliges us to keep our administration, invoices and the booking records behind them are retained for seven years. This is a legal obligation (Art. 6(1)(c) GDPR) and not something we can delete on request within that period.
When you contact us
If you reach out by e-mail, phone or WhatsApp, we use what you send us to answer you and to handle your request. Enquiries for our concierge service (for example Ultra class requests) are forwarded by e-mail to the team that handles them. We keep correspondence as long as needed to resolve the matter and for a reasonable period afterwards in case follow-up is needed.
Legal basis: performance of (or steps prior to) a contract (Art. 6(1)(b) GDPR) and our legitimate interest in decent customer service (Art. 6(1)(f)).
Ride emails, reminders and offers
Around every booking we send service e-mails: the confirmation with your invoice, reminders before pickup, a “your chauffeur is on the way” message, and afterwards a short request to rate the ride. These are part of carrying out your booking, not marketing.
Separately, you can opt in to our newsletter — for example to receive a welcome discount code. We only send it if you signed up, and you can stop it at any time by e-mailing info@amstelcab.com — unsubscribing costs nothing and takes effect immediately.
Legal basis: contract performance for service e-mails (Art. 6(1)(b) GDPR); consent for the newsletter (Art. 6(1)(a)), which you can withdraw at any time.
Service providers we work with
We don’t run everything ourselves. The parties below process data on our behalf or as independent services we call on. Where a provider processes data outside the European Economic Area, we rely on an EU adequacy decision (including the EU-US Data Privacy Framework) or on Standard Contractual Clauses.
- Stripe — payment processing and fraud prevention (see section 9).
- Resend — delivers our transactional e-mail (confirmations, codes, invoices).
- MongoDB Atlas — hosts our booking database.
- Railway and Vercel — host our backend and website, including the server logs from section 5.
- Google — converts addresses into coordinates and distances (Maps), and serves the typefaces on this site (Fonts); both requests include your IP address.
- CARTO / OpenStreetMap — the map tiles on the booking map.
- OSRM — calculates the driving route between your addresses.
- Photon (Komoot, Germany) — powers the address suggestions while you type.
- Royal Schiphol Group — public flight data for your flight number (no personal data attached).
- WhatsApp / Meta — carries the operational booking notifications to our dispatch team (see section 7).
Your rights
Under the GDPR you can, at any time and free of charge:
- Ask what data we hold about you and receive a copy (access);
- Have incorrect data corrected (rectification);
- Have data deleted where no legal duty forces us to keep it (erasure);
- Have processing restricted or object to processing based on legitimate interest;
- Receive your data in a portable, machine-readable format (portability);
- Withdraw any consent you gave, with effect for the future.
Two of these are self-service: in your account you can download your data as a file and delete your account. Deleting the account removes your profile, saved addresses and companions; the underlying booking and invoice records are detached from the account but kept for the retention period in section 16, because bookkeeping law requires it.
For everything else, e-mail info@amstelcab.com. If you believe we handle your data improperly, you also have the right to complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens.
Automated decisions
We do not profile you and we make no automated decisions with legal effect — with one narrow exception: our payment provider’s fraud screening can automatically decline a payment that looks fraudulent, which would stop a booking from completing. If that happens to you in error, contact us and a human will look at it.
How long we keep your data
- Login and verification codes: 10 minutes, single use;
- My Ride link tokens: 24 hours to 30 days, depending on how they were issued;
- Account login session: 30 days;
- Your cookie choice: 12 months, then we ask again;
- Bookings, invoices and payment records: 7 years, the retention period Dutch tax law sets for business administration;
- Account profile, saved addresses and companions: until you delete them or your account;
- Newsletter subscription: until you unsubscribe.
When a retention period ends, we delete or anonymise the data. Where several legal bases overlap, the longest applicable period wins — most commonly the bookkeeping obligation.
Changes to this policy
We update this policy when our service, our providers or the law change. The date at the top always shows the current version. For meaningful changes we will point them out on the website rather than change things silently.
Questions about any of this? Write to info@amstelcab.com or see our Terms & Conditions.