The internet portal charter.flixbus.com and the booking portal integrated therein (hereinafter collectively referred to as “website”) is operated by FlixMobility GmbH, Friedenheimer Brücke 16, 80639 Munich (hereinafter referred to as “FlixMobility” or “we”). We attach great importance to the protection of your personal data. For this reason, data protection at FlixMobility GmbH has a high priority, and we strictly adhere to the legal provisions of the European General Data Protection Regulation (GDPR) and the Federal Data Protection Act in collecting, processing and using data.
1. Collection, processing and use of personal data
The processing of your personal data is based on the following legal basis:
1.1. Contractual relationship pursuant to Art. 6 para. 1 letter b of GDPR
We process the personal data voluntarily communicated to us (name, email address, telephone number) pursuant to Art. 6 para. 1 letter b of GDPR for the contractual processing of bus rental, for carrying out transportation and opening of a customer account or in the context of pre-contractual measures.
To do this, we need your first and last name and telephone number. For the required payment processing, the following data may additionally be required:
- For payment of a booked trip with the credit card, FlixMobility requires your full billing address and credit card data.
- For payment of a booked trip via SEPA debit memo, FlixMobility requires your full billing address and bank account data.
- FlixMobility needs your full billing address to pay for a booked trip by bank transfer.
1.2. Legitimate interests pursuant to Art. 6 para. 1 letter f of GDPR
Due to a legitimate interest in accordance with Art. 6 para. 1 letter f of GDPR, we process the necessary data for the following purposes:
- In addition to processing ticket orders, FlixMobility GmbH also uses your data for advertising purposes and for market and opinion research to inform you about offers tailored to your interests via regular mail or newsletters. To this end, we conduct advertising scoring for interest-based advertising based on legitimate interests pursuant to Art. 6 para. 1 letter f of GDPR. The use of your data for advertising purposes, market and opinion research and advertising scoring can be refused at any time by a message to FlixMobility GmbH, Birketweg 33, 80639 Munich or to firstname.lastname@example.org.
- As part of the payment process, your data will be passed on to Paymill, St.-Martin-Str. 63, 81669 Munich. The credit card number or other bank details are not stored at FlixMobility, but instead forwarded directly to the payment service provider.
- If payment fails with Paymill, a second payment attempt can be made by our partner Adyen BV, Simon Carmiggelstraat 6 – 50, 1011 DJ Amsterdam. To prevent and detect fraud, we send your IP address to our partner Adyen BV, Simon Carmiggelstraat 6 – 50, 1011 DJ Amsterdam. Your IP address is stored by Adyen BV in this context. All data is transmitted in encrypted form.
1.3. Consent pursuant to Art. 6 para. 1 letter a of GDPR
If you choose the direct debit payment method, you agree that your personal data (name, address, date of birth, email address and current account details) will be passed on to Paymill GmbH, St.-Martin-Str. 63, 81669 Munich or to Adyen BV, Simon Carmiggelstraat 6 – 50, 1011 DJ Amsterdam for the purpose of identity and credit check, as well as for contract processing.
The personal data collected at registration of the newsletter with your consent pursuant to Art. 6 para. 1 letter a of GDPR is used for communication with you (e.g., service messages, system notifications, email confirming your registration, sending user account information, information about your itineraries or your travel profiles) as well as for mailing newsletters.
When we get your e-mail address in connection with the sale of goods or services and you have not opted out of this, we reserve the right to send you offers regularly via email for products from our range of products that are similar to those already purchased.
You can refuse the use of your email address and the processing and use of the data for creating usage profiles at any time by sending a message to email@example.com or via the cancel registration link of the newsletter, without incurring any costs other than the transmission costs in accordance with the basic tariffs.
3. Data security
We protect the privacy of users on our website and the connected systems using technical and organizational measures. To ensure secure transfer of personal data, we use the encryption protocol SSL 3.0 (RSA-2048 for the public key infrastructure is used as the underlying encryption method). This procedure is used successfully throughout the World Wide Web. All personal data (name, address, payment data, etc.) are thereby encrypted and consequently securely transmitted on the internet. You can see via a symbol (closed padlock) in the lower window bar of your browser that you are in a secure area.
4. Data transfers to third countries
Data is processed on principle in Germany or countries of the European Union. Where processing in third countries is planned in certain cases, processing will only be carried out if the appropriateness of the level of data protection in the third country has been established by the EU Commission under Art. 45 of GDPR or on the basis of standard EU contractual clauses.
5. Storage period of data
We store the data as long as they are required for the respective processing purposes (e.g., contract processing, advertising purposes) and for fulfilling the commercial and tax law withholding provisions pursuant to Art. 6 para. 1 letter c of GDPR and Section 257 para. 1 of the German Commercial Code (HGB) and Section 147 para. 2 of the Tax Code (AO).
6. Contact details of the data controller
The data controller for processing personal data is FlixMobility GmbH, Birketweg 33 80639 Munich, email address firstname.lastname@example.org, represented by the Managing Directors André Schwämmlein, Arnd Schwierholz, Daniel Krauss, and Jochen Engert.
7. Information and complaint rights
Pursuant to the General Data Protection Regulation, you have a right to free information about your stored data and, where applicable, a right to rectification, deletion, restriction of processing and objection to your stored data. In this context, please contact FlixMobility GmbH, Birketweg 33, 80639 Munich or send us an email at email@example.com. You can contact our data protection officer at firstname.lastname@example.org. In addition, you have a right to complain about data protection to the regulatory agency with jurisdiction over us.
In addition, we use third-party cookies for retargeting and remarketing technologies to optimize our web service as well as for interest-based marketing purposes. The stored surfing behavior is analyzed using an algorithm, so that targeted interest-related product recommendations in the form of advertising banners or advertisements can then be displayed on third party websites. Without the express consent of the person concerned, the pseudonymized user profiles will not be combined with the personal data of the user of the pseudonym.
Comprehensive information about how to accomplish this on a wide variety of browsers can be found on the following websites: youronlinechoices, Network Advertising Initiative and/or Digital Advertising Alliance. You can also find information there about how to delete cookies from your computer as well as general information about cookies.
8.1. Technically required cookies
On this website, technology from AdTriba GmbH – Beim Schlump 13a, 20144 Hamburg (https://www.adtriba.com/) is used to collect and store data, with which usage profiles are created using pseudonyms. These usage profiles are used to analyse visitor behaviour in order to focus on their needs and to improve our offering. Cookies can be used for this. These are small text files that are saved locally on the page visitor’s device and so allow our website to recognize them when they visit again. Without separately issued express consent, the pseudonymized usage profiles will not be merged with the personal data of the user of the pseudonym.
8.1.2. AB Tasty
8.1.3. Google Analytics
This website uses Google Analytics, a web analysis service of Google Inc. (“Google”). Google Analytics uses “cookies”, text files, which are stored on your computer and enable analysis of the use you make of the website. In addition, this website uses the Google AMP Client ID API to link user activities to AMP pages with those on non-AMP pages via Google Analytics. The Google tracking codes of this website use the “_anonymizeIp()” function. As a result, the IP address within Member States of the European Union or in other States of the Agreement on the European Economic Area is only further processed in abbreviated form to exclude a direct personal reference. The complete IP address is only transmitted to a server from Google in the USA in exceptional cases and abbreviated there. On behalf of the operator of this website, Google uses this information to evaluate your use of this website, create reports about the website activities and provide other services connected with use of the website and Internet for the website operator. The IP address transmitted from your browser within the context of Google Analytics will not be associated with other data of Google. You can prevent storing of cookies on your computer via a corresponding setting of your browser software. However, we point out that you might not be able to use all functions of this website to their full extent in this case. You can also prevent the recording of data generated by a cookie with respect to your use of the website (incl. IP address) by Google as well as the processing of such data by Google by downloading and installing the browser plugin available via the following link: http://tools.google.com/dlpage/gaoptout?hl=en
8.2. Functional cookies
This website uses the services of Inspectlet. Inspectlet evaluates user data for statistical purposes. The following personal data of our website visitors is evaluated for this purpose: URL, country, time zone, browser type, last visit of the user on the website. All data is encrypted during the transmission and the collected data is stored using AES encryption. If the user has enabled the anonymization of the IP address, the last two octets of the IP address are removed and are not available to either the user or Inspectlet. Any data captured by the website considered sensitive will be ignored by Inspectlet. Therefore, data entered by the user will not be transmitted to our servers. All data is only stored in AWS data centers that meet ISO 27001 requirements. The data is stored for a maximum of 24 months and then deleted permanently. If you wish to object to the use of your data by Inspectlet, you can do so in the following link: https://www.inspectlet.com/optout.
8.3. Marketing cookies
8.3.1. Google AdWords
To optimize our web service as well as for product recommendations, we use the technology provided by Google Limited („Google“), Gordon House, Barrow Street, Dublin 4, Irland to create pseudonymized usage profiles about the surfing behavior of the website visitors for marketing purposes. For this purpose, cookies may be used, which make it possible to recognize an internet browser upon a repeat visit. The stored surfing behavior is analyzed using an algorithm, so that targeted interest-related product recommendations in the form of advertising banners or advertisements can then be displayed on third party websites. Without the express consent of the person concerned, the pseudonymized user profiles will not be combined with the personal data of the user of the pseudonym. The creation of pseudonymized usage profiles for interest-based advertising/ad preferences can be refused at any time by visiting the https://www.google.com/settings/ads page. You can find more information about interest-related advertising at http://www.google.com/policies/technologies/ads/.
The Mailjet program is also used to communicate with the customer. Mailjet collects and processes the following data: email address, title, first name, last name, country, if applicable sales tax identification number, password, postal address, telephone number, IP address(es) and domain name, connection and navigation data, and if the user allows, overviews of correspondence on our website. Mailjet collects personal data for the fulfillment of its contractual obligations. Mailjet only stores this data for the period of time required to provide the services and no longer than 3 months after the closure of your account (unless otherwise required by law). The message content is saved for a period of only 6 days. In accordance with the French data protection laws and the European General Data Protection Regulation 2016/679 (GDPR), you have a right of access, adjustment and removal of your personal data by sending a support-ticket via https://www.mailjet.com/support/ticket with the respective request.
8.3.3. Facebook Custom Audiences
This website uses the Retargeting-Pixel Custom Audience of the social network Facebook, 1601 South California Avenue, Palo Alto, CA 94304, USA. With the help of the Remarketing Pixel, it is possible to use the visitors of our website as a target group for the advertisements of Facebook ads. For this purpose, a Facebook cookie is stored on your PC. Please refer to the data protection (privacy settings) provisions of Facebook for information about the purpose and scope of data collection as well as the further processing and use of data by Facebook and your options for privacy settings at https://facebook.com/policy.php and https://www.facebook.com/ads/settings. You can refuse the use of Custom Audiences at www.youronlinechoices.com/de/praferenzmanagement or for users with a Facebook account here.
SOJERN's cookie collects information about your travel activities and preferences from online travel partner websites, and engage with you through personalized, relevant adverts when you're browsing other websites and social media platforms, and through SOJERN analytics services. They may also enable the storing of conversion information used to track, create reporting and optimize the performance of SOJERN campaigns. You can learn more about SOJERN and opt out at https://www.sojern.com/privacy/product-privacy-policy.
9. Social Plugins
Our website uses social plugins of the social networks Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA, Twitter, Inc., 795 Folsom St., Suite 600 San Francisco, CA 94107, USA, Google Limited („Google“), Gordon House, Barrow Street, Dublin 4, Irland, Pinterest, Inc., 635 High Street, Palo Alto, CA, USA, and Instagram Inc., 1601 Willow Road, Menlo Park, CA 94025, USA.
The plugins are located on our product page and are disabled in their initial state. If you click the appropriate button, then you are prompted in a new window to sign in to the social media provider. In this case, a cookie is placed on your computer. If you do not click the button or are not logged in to the social media provider, no cookie is placed on your computer.
If you are a user of the respective social media provider and are logged in and click the button, this information is sent to your profile at the respective social media provider. If you interact with the plugins, for example by pressing the “Like” button on Facebook or by posting a comment, the corresponding information is also transmitted directly from your browser to the social network and stored there. Please refer to the data protection (privacy settings) provisions of the following providers for information about the purpose and scope of data collection as well as the further processing and use of data by the provider as well as your rights and setting options for protecting your privacy:
- Facebook: http://www.facebook.com/policy.php
- Google+: http://www.google.com/intl/de/+/policy/+1button.html
- Pinterest: http://about.pinterest.com/privacy
- Instagram: http://instagram.com/about/legal/privacy/#