GVA TO ALPS
  • Home
  • Services
  • Our Fleet
  • FAQ
  • Contact
Book Now

Privacy Policy

Effective date: 15 May 2026

EN FR
Back to Home

This Privacy Policy applies to all services of Best Geneva Transports Sàrl (trading as GVA TO ALPS), including the website gvatoalps.com and any communication by phone, WhatsApp, email or messaging. It describes what data we collect, how we use it, on what legal basis, with whom we share it, how long we keep it, and what your rights are.

This Policy is drafted in accordance with the revised Swiss Federal Act on Data Protection (revFADP / nFADP) of 25 September 2020, in force since 1 September 2023, and with the EU General Data Protection Regulation (GDPR, Regulation 2016/679) for data subjects residing in the EU/EEA.

1. Data Controller

Best Geneva Transports Sàrl (GVA TO ALPS)

Rue Vermont 42, 1202 Geneva, Switzerland

UID / VAT: CHE-291.444.283 — Commercial Register of Geneva

Managing Director: Gheorghe Gavrilita

Email: info@gvatoalps.com

Phone / WhatsApp: +41 78 744 31 14

You may contact us by email, phone, WhatsApp or postal mail at the address above for any matter relating to the processing of your data.

2. Data we collect

2.1 Data you provide when booking

When you complete the booking form or contact us by WhatsApp / email to book a transfer, we collect:

  • Identity: first name, last name
  • Contact details: email address, phone number (mobile recommended)
  • Transfer details: pickup location, destination, date, time, number of passengers, luggage, ski equipment, required child seats
  • Flight / connection information: flight number, airline, arrival date and time — required to monitor delays and ensure pickup
  • Free-text message: any additional information you share with us (special requirements, pets, etc.)
  • Payment data: if you pay by card, card details are entered directly on the platform of Stripe Inc. and are never stored on our servers (see section 4)

2.2 Data collected automatically

  • Technical data: IP address, browser type and version, operating system, language, pages visited, timestamps, referring site
  • Cookies and similar identifiers: see our Cookie Policy
  • Server logs: retained by our hosting provider (Hostinger) for security and diagnostic purposes

2.3 Data from other communications

When you write to us by email, WhatsApp or phone, we keep the content of the exchange as long as needed to follow up (quote, booking, complaint handling).

3. Purposes and legal bases

PurposeLegal basis (revFADP / GDPR)Retention
Performance of the transport contract (booking, pickup, flight monitoring, invoicing)Contract performance (Art. 31(2)(a) revFADP; Art. 6(1)(b) GDPR)10 years (Swiss accounting obligation, CO Art. 958f)
Card payment processing (Stripe)Contract performance; legitimate interest in payment security (Art. 6(1)(b) and (f) GDPR)10 years
Replying to your enquiries (email, WhatsApp, phone)Legitimate interest; pre-contractual measures (Art. 6(1)(b) and (f) GDPR)2 years after last contact
Audience analytics (Microsoft Clarity, Google Analytics)Consent (Art. 6(1)(b) revFADP; Art. 6(1)(a) GDPR)See cookie policy — typically 14 months
Marketing and ad-conversion tracking (Google Ads)Consent (Art. 6(1)(b) revFADP; Art. 6(1)(a) GDPR)See cookie policy — typically 90 days
Site security, fraud prevention, access logsLegitimate interest (Art. 31(2)(c) revFADP; Art. 6(1)(f) GDPR)12 months
Legal obligations (tax, accounting, lawful requests)Legal obligation (Art. 6(1)(c) GDPR)As required by law (up to 10 years)

4. Recipients and processors

To deliver the service we share certain data with the following providers acting as processors or joint controllers. All transfers outside the EU / Switzerland to third countries (notably the United States) are covered either by the EU Commission Standard Contractual Clauses and the EU–US Data Privacy Framework, or by the FDPIC standard clauses for flows from Switzerland.

ProviderData transferredCountryPurpose
Hostinger International Ltd.All website and database dataGermany (EU)Hosting
REVERT MKT S.R.L. (RO CUI 50930476) — Strada Zorelelor 4, Gherăești, Neamț, RomaniaAdministrative access to the site (CMS, FTP/SSH, logs) for technical maintenanceRomania (EU — intra-EU transfer)Website development, maintenance and monitoring; Art. 28 GDPR DPA in place
Stripe Inc.Name, email, amount, booking reference, card dataUnited States (DPF + SCCs)Card payment processing (CHF)
HighLevel Inc. / LeadConnector LLC (sub-processors include Amazon Web Services, Google Cloud, Twilio, Mailgun, HighLevel India — full list at gohighlevel.com/sub-processors)Booking data (identity, contact, trip, message)United States + India — covered by EU 2021 SCCs, EU–US, UK and Swiss–US Data Privacy Framework certification (active), and HighLevel's auto-incorporated Data Processing Addendum.CRM, booking management, customer communication
Microsoft Corporation (Clarity)Truncated IP, navigation, mouse moves, clicksUnited States / EU (DPF + SCCs)User-experience analytics — only with consent
Google LLC / Google Ireland Ltd.Cookie ID, navigation events, conversion dataIreland + United States (DPF + SCCs)Google Analytics and Google Ads — only with consent
Meta Platforms Ireland Ltd. (WhatsApp Business)Your phone number and message content when you write to us on WhatsAppIreland + United StatesCustomer messaging (at your initiative)
Transport sub-contractorsFirst name, phone, pickup location, flight numberSwitzerland / France (depending on route)Actual provision of transport when we sub-contract
Authorities, lawyers, accountants, insurersOn lawful request or in case of disputeSwitzerland / EULegal obligations

We never sell your personal data and do not use it for direct marketing without your consent.

5. Cookies and similar technologies

This site uses essential cookies (session, language preference) and — only after your consent — analytics and marketing cookies. The full list is set out in our Cookie Policy. You can change your preferences at any time via the "Cookie settings" link in the footer.

6. Data retention

We retain your data only for as long as needed for the purpose, in accordance with section 3. After these periods, data are deleted or irreversibly anonymised. Accounting records related to payments (invoices, Stripe transactions) are retained for 10 years pursuant to the Swiss Code of Obligations (Art. 958f CO).

7. Security

We implement appropriate technical and organisational measures to protect your data against loss, unauthorised access, disclosure or destruction: site-wide HTTPS/TLS, strong passwords, restricted access to the admin panel, regular backups, web application firewall (WAF), card data tokenisation by Stripe (we do not store any card data).

8. Your rights

Under revFADP and GDPR you have the following rights regarding your personal data:

  • Right of access to your data and to information about its processing
  • Right of rectification of inaccurate or incomplete data
  • Right to erasure ("right to be forgotten"), subject to our legal retention obligations
  • Right to restriction of processing
  • Right to portability of your data (GDPR)
  • Right to object to processing based on legitimate interest, in particular to direct marketing
  • Right to withdraw consent at any time (without affecting prior processing)
  • Right not to be subject to a decision based solely on automated processing producing legal effects (we do not engage in purely automated decision-making)

To exercise these rights, write to info@gvatoalps.com. We may ask for proof of identity for manifestly excessive requests or to protect your data against impersonation.

9. Complaint to a supervisory authority

If you consider that the processing of your data does not comply with the law, you may lodge a complaint with:

  • Switzerland: Federal Data Protection and Information Commissioner (FDPIC / EDÖB), Feldeggweg 1, 3003 Bern — www.edoeb.admin.ch
  • EU / EEA: the data protection authority of your country of residence (e.g. CNIL in France, BfDI in Germany)

10. Minors

Our services are intended for adults (16+). We do not knowingly collect data from minors under 16 without parental consent. When a booking involves children (child seats, accompanied minors), the booking is made by an adult who assumes that responsibility.

11. Changes

We may update this Policy to reflect legal or service developments. The version in force is always the one published on this page, with the effective date shown at the top. Material changes will be signalled where reasonably possible.

12. Automated decisions and profiling

We do not use solely automated decision-making producing legal effects or significantly affecting you. The automated price calculation is a decision-support tool that can be checked by our team before confirmation.

GVA TO ALPS

Premium private transfers from Geneva Airport to the finest Alpine destinations.

Quick Links

  • Home
  • Services
  • Our Fleet
  • FAQ

Legal

  • Imprint
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy
  • Cookie settings

Contact

  • info@gvatoalps.com
  • +41 78 744 31 14

© 2026 Best Geneva Transports Sàrl (GVA TO ALPS). All rights reserved.