Who controls the data
The transfer company that creates a booking decides why passenger information is used and is normally the data controller. PaxWhere processes that information to provide the service. Company-account data is handled by PaxWhere for account administration, security and service delivery.
Information processed
- Company account email, company name, country, city and emergency contact number.
- Booking reference, passenger name, flight number, scheduled landing time and meeting-point instruction.
- Passenger-declared progress, help and contact-button events, plus timestamps and operational events.
- Authentication, security and technical logs needed to operate and protect the service.
What PaxWhere does not collect
PaxWhere does not request GPS location, continuous location tracking, passport details, payment-card information or passenger accounts. A passenger link is public to its recipient and protected by a long, unguessable booking token.
Purposes and legal basis
Data is used to provide airport-transfer coordination, authenticate Operations users, preserve a timestamped event record, respond to help requests and keep the service secure. Transfer companies are responsible for choosing an appropriate legal basis and providing any passenger notice required in their jurisdiction.
Service providers and international processing
PaxWhere uses Supabase for authentication, Google for optional Google sign-in, and OpenAI Sites and its hosting infrastructure to deliver the application. These providers process limited data under their own security and data-processing terms. Data may be processed outside the passenger’s country with the safeguards offered by the relevant provider.
Choices and rights
Passengers should contact the transfer company that sent the link to request access, correction, restriction or deletion. Company-account holders can make privacy requests at info@paxwhere.com. Requests may be retained where necessary to meet security, dispute or legal obligations.