NOVA FLUX

Privacy policy

Last updated: 16 July 2026

Data controller

NOVA FLUX (SAS), registered office at 60 rue François Ier, 75008 Paris, SIREN 103 359 733, is the controller responsible for processing personal data collected on this website, operated under the trade name "NOVA FLUX". Contact: rh2.20@icloud.com.

Data collected and purposes

When you book, we collect: name, phone number, email, pickup and drop-off addresses, pickup date and time, number of passengers and bags, and any comments. This data is necessary to perform the transport contract (legal basis: performance of a contract, Article 6.1.b of the GDPR).

No banking data is collected on the site: payment for the ride is made directly on board, to the driver.

Recipients and processors

Data is accessible to the driver assigned to the ride (notified by text) and to our technical processors: Google Maps Platform (route calculation), Twilio (booking text messages), Resend (confirmation emails), Vercel Inc. (website hosting) and Neon (database, hosted in Frankfurt, Germany). Some of these providers are located outside the European Union and offer adequate safeguards (standard contractual clauses).

Retention periods

Booking data is kept for 3 years from the last ride, for commercial and accounting purposes. Related accounting records are kept for 10 years in accordance with the French Commercial Code. Bookings cancelled before payment are deleted after 12 months.

Your rights

You have the right to access, rectify, erase, restrict and object to the processing of your data, as well as data portability and the right to define post-mortem directives. To exercise these rights, write to rh2.20@icloud.com with proof of identity. We respond within one month. You may also contact the CNIL (cnil.fr).

Cookies and trackers

The site uses no advertising cookies or audience-measurement trackers. Only strictly necessary technical processing is used: loading the Google Maps scripts for address autocomplete, which may set its own functional cookies subject to Google's policy.

Security

Exchanges with the site are encrypted (HTTPS). Access keys to third-party services are stored server-side and never exposed to the browser, except for the public mapping key, which is restricted to our domain.