Confidentiality
What is the purpose of the charter?
At Heetch, the protection of your personal data is a priority.
When you use the site https://www.heetch.com (the “Site”) and/or the Heetch application (the “Application”) and as part of the management of our contractual relationships with our customers, we are required to collect personal data about you.
The purpose of this policy is to inform you about the methods by which we process this data in accordance with Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the “RGPD”) and Law No. 78-17 of 6 January 1978 relating to information technology, files and freedoms (together the “Applicable Regulation”).
Capitalized terms used in this privacy policy will have the meaning given to them in the GDPR or in Heetch's terms and conditions of use.
What is personal data?
When you use the “Heetch” mobile application (hereinafter: the “Application”) and/or the website accessible at https://www.heetch.com/ (hereinafter, the “Site”) as a passenger (hereinafter the “Passenger”) or as a driver (hereinafter the “Driver”), (hereinafter referred to as the “Driver”), (hereinafter referred to together as the “Users”), we may ask you to provide us with personal data concerning you in order to use our services (hereinafter the “Driver”), (hereinafter referred to as the “Driver”), (hereinafter referred to together as the “Users”), we may ask you to provide us with personal data concerning you in order to use our services (hereinafter the “Driver”), (hereinafter referred to as the “Driver”), (hereinafter referred to as the “Driver”), (hereinafter referred to as the “Driver”), (hereinafter referred to “Services”). We ”).
What personal data does Heetch collect?
As part of our activity, we are required to collect a certain amount of information about you, and in particular:
For Passengers:
- Identification data: your first name, last name, email address, email address, telephone number, user ID, your identity card when necessary. If you choose to log in using a third-party authentication service (including Facebook Connect), certain data, such as your name, first name, email address, and photograph, may be retrieved from that service. By choosing this method, you agree that said service may communicate this data to us. We don't connect your third party account password.
- Economic and financial data: the last 4 (four) digits of the payment card if this payment method is selected and if you are located in the territory of the European Union.
- Location Data: your geolocation data is collected when the Application is open and you view the geographic map around you, as well as the history of the races completed (hereinafter the “Rides”) and the geolocation data aggregated over a radius of several hundred meters.
- Connection and internet data: your OS version, the version of the application, your IP address, your client device name, your device ID, mobile phone operating system, your advertising ID.
Other data: your city ID, your stripe customer ID, referral code, comments left by our customer service or by you as part of your use of our Services and telephone records with our customer service.
We may also collect data mentioning incidents (unpaid, bad behavior, etc.) encountered while using our Services.
For Drivers:
- Identification data: your first name, last name, email address, email address, date of birth, date of birth, telephone number, home address, driver's license, identity document, residence permit if applicable, profile photograph. If you choose to log in using a third-party authentication service (including Facebook Connect), certain data, such as your name, first name, email address, and photograph, may be retrieved from that service. By choosing this method, you agree that said service may communicate this data to us. We don't connect your third party account password.
- Data relating to your professional life: legal name and form of your company or employer, intra-community VAT number, registered office, vehicle photograph, make and model of the vehicle, registration number and date of first registration, vehicle registration document, vehicle registration certificate, VTC registration certificate, VTC registration certificate, VTC registration certificate, VTC license card and date of obtaining, variation and motorization, green card, digital badge with QR code, proof of insurance professional, employer code, cities or regions in which you Go perform Rides.
- Economic and financial data: IBAN, BIC, turnover achieved through our Services.
- Location Data: your geolocation data is collected when the Application is open and you view the geographic map around you, as well as the history of Rides performed and aggregated geolocation data over a radius of several hundred meters.
Connection and internet data: your OS version, the version of the application, your IP address.
Other data: Comments left by our customer service or by you as part of your use of our Services, telephone conversations with our customer service, conversations with other Drivers, your acceptance rate of Rides, your supporting documents in case of suspected fraud, as well as your status related to the use of our Services (active, suspended or dormant).
We may also collect data mentioning the incidents encountered during the use of our Services (unpaid, bad behavior, etc.).
For Fleet Managers:
- Identification data: your first name, last name, email address, telephone number, photograph.
- Data relating to your professional life: legal name and form of your company, intra-community VAT number, registered office, information relating to the vehicle fleet (vehicle photography, vehicle brand and model, vehicle registration number, vehicle registration number, vehicle registration certificate, driving license, driver's license, driver's license, VTC registration certificates, VTC registration certificates, VTC license card and date of obtaining, declination and motorization, green cards, digital buttons with QR code), proof of professional insurance, cities or regions in which the corresponding fleet performs Rides.
- Economic and financial data: IBAN, BIC, turnover achieved through our Services.
This data may be collected when you download the Application, when you use our Site, or when you use our Services. Mandatory data is indicated when you provide us with your data. They are reported by all means.
3. On what legal bases, for what purposes and for how long do we keep your personal data?
Objectives
This collection is necessary in order to perform the contract concluded when you use our Services on our Application and/or our Site.
Perform operations relating to the management of our customers concerning contracts, orders, unpaid invoices and ensure the monitoring of the contractual relationship with our Users
Improving our services
Manage your opinions on our products, services, courses or content
Create a file of customers and prospects
Send newsletters, solicitations and promotional messages by email
Respond to your requests for information
Comply with legal obligations applicable to our business
Develop statistics (navigation, the audience of the Site/Application, etc.) and improve the functionalities of the Site/Application through the deposit of audience measurement cookies
Broadcast personalized advertising through the deposit of advertising cookies
Allow you to simulate your income
Locate you in order to allow you to find a Driver or a User more easily
Manage incidents
Fighting fraud
Detect excessive or abusive cancellations by Users
Manage requests to exercise rights
Legal bases
When the processing of your data is necessary for compliance with a legal obligation to which we are subject.
Execution of the contract that you or your company has entered into with Us
Our legitimate interest in improving our services
Our legitimate interest in collecting your opinion on our products, services, courses or content
Our legitimate interest in developing and promoting our business
If you are a consumer:
For customers: our legitimate interest in retaining and informing our customers of our latest news
For prospects:
your consent
If you are a professional:
Our legitimate interest in retaining and informing our customers and prospects of our latest news
If you are a consumer:
For customers: our legitimate interest in retaining and informing our customers of our latest news
For prospects:
your consent
If you are a professional:
Our legitimate interest in retaining and informing our customers and prospects of our latest news
Comply with our legal and regulatory obligations
Your consent
or
Our legitimate interest in analysing the composition of our customers and improving our services
Your consent
Pre-contractual measures taken at your request
Your consent via your phone settings
Passengers can use our Application without activating the collection of location data from their portable devices. However, this may have an impact on some of the features of our Application. For example, a Passenger who has not activated accurate location data will have to manually enter their pick-up address.
In addition, accurate location data collected from the Driver's device during a trip is linked to the Passenger's account, even if the Passenger has not activated the collection of accurate location data from their device. This data is used for purposes such as receipting, customer service, fraud detection, insurance, and litigation.
Our legitimate interest in managing incidents
Our legitimate interest in preventing fraud and in dealing with it where appropriate
Our legitimate interest in fighting abuse
Our legitimate interest in responding to your requests and keeping track of them
Retention periods
With regard to the collection and storage of your personal data through the cookies used on our Application and/or our Site.
Your connection logs are kept for 1 year.
In the event of an account that is inactive for 2 years, your personal data will be deleted in the absence of a response from you to our reactivation email.
In addition, your data can be archived for evidentiary purposes for a period of 5 years.
Personal data is kept for the duration of the contractual relationship.
In addition, your data (with the exception of your bank details) are archived for evidentiary purposes for a period of 5 years.
Regarding the data relating to your bank card, they are kept by our payment service provider Stripe.
Data relating to the visual cryptogram or CVV2, written on your bank card, is not stored.
Data relating to your bank cards may be kept, for the purpose of proof in the event of a possible dispute with the transaction, in intermediate archives for a period of thirteen (13) months following the debit date. This period may be extended to fifteen (15) months in order to take into account the possibility of using deferred debit payment cards.
Telephone call records are kept for 6 months) from when collected. Telephone call content analysis documents are kept for 6 months from the time of recording.
Regarding reviews on Heetch, the data is kept for 2 years from the publication of the review
Regarding reviews on your trips, the data is kept for the duration of your account
For customers: the data is kept for the duration of the contractual relationship.
For prospects: the data is kept for a period of 3 years from your last contact.
The data is kept for 3 years from the date of your last contact with Us or until the withdrawal of your consent.
The data is kept for 3 years from the date of your last contact with Us or until the withdrawal of your consent.
For invoices: invoices are archived for a period of 10 years. Data relating to your transactions (except bank data) are kept for 5 years.
The data is kept for 18 months.
The data is kept for 18 months.
The data is kept for 7 days.
The data is kept for a period of 5 years from the end of the commercial relationship and up to 6 years for the most serious cases.
In addition, your data can be archived for evidentiary purposes for a period of 5 years.
The data is kept for a period of 5 years from the end of the commercial relationship and up to 6 years for the most serious cases.
In addition, your data can be archived for evidentiary purposes for a period of 5 years.
The data is kept for a period of 5 years from the end of the commercial relationship.
In addition, your data may be
archived for evidentiary purposes for a period of 5 years.
If we ask you for proof of identity: we only keep it for the time necessary for identity verification. Once the verification has been carried out, the receipt is deleted.
If you exercise your right to object to receiving prospecting: we keep this information for 3 years.
The information allowing the management of your requests to exercise rights under the RGPD will be kept for 3 years from the request.
4. Who are the recipients of your data?
Will have access to your personal data:
1. Our team,
2. The services in charge of control (auditor in particular),
3. Our subcontractors: tools for carrying out statistical and marketing studies; audience measurement and analysis providers; audience measurement and analysis providers; hosting providers; online communication providers; administration, collaboration and management tools; back office management tools; online payment service provider; online payment service provider; online payment service provider; online payment service provider; online payment service provider; online payment service provider; online payment service provider; identity verification and fraud prevention tools; cookie management provider; IP voice telephony tool.
4. Our partners (VTC training centers in particular) or your employer (for employed Drivers) with whom we are likely to work to perform our Services, with your agreement,
5. Our partners provided that you have accepted the partnership with them and/or that you are registered with them, in order to facilitate the provision of their Services.
Not to mention (less fun) public organizations, court officials (bailiffs, notaries, etc.), ministerial officers and organizations responsible for debt collection.
Your personal data may be transferred, rented or exchanged for the benefit of third parties, only if you give us your prior and express consent for this purpose.
Your personal data may be transferred, rented or exchanged for the benefit of third parties, only if you give us your prior and express consent for this purpose.
5. Is your data likely to be transferred outside the European Union?
Your data is retained and stored for the duration of processing on the servers of the company Amazon Web Services, located in the European Union.
As part of the tools we use (see article on recipients concerning our subcontractors), your data is likely to be transferred outside the European Union. The transfer of your data in this context is secured using the following tools:
- or the data is transferred to a country that has been the subject of an adequacy decision by the European Commission, in accordance with article 45 of the RGPD: in this case, this country ensures a level of protection considered sufficient and adequate to the provisions of the RGPD;
- or the data is transferred to a country whose level of data protection has not been recognized as adequate under the RGPD: in this case these transfers are based on appropriate guarantees indicated in article 46 of the RGPD, adapted to each service provider, in particular in particular in a non-exhaustive manner, the conclusion of standard contractual clauses approved by the European Commission, the application of binding corporate rules or under an approved certification mechanism.
- or the data is transferred on the basis of one of the appropriate guarantees described in Chapter V of the GDPR.
You can obtain a copy of the tools allowing the transfer of your data outside the European Union by contacting us at the following address: dpo@heetch.com.
6. What are your rights to your data?
You have the following rights with respect to your personal data:
Right to information : that's exactly why we wrote this policy. This right is provided for in articles 13 and 14 of the GDPR.
Right of access : you have the right to access all of your personal data at any time, under article 15 of the RGPD.
Right to rectification : you have the right to rectify your inaccurate, incomplete or outdated personal data at any time in accordance with Article 16 of the GDPR
Right to limitation : you have the right to obtain the limitation of the processing of your personal data in certain cases defined in article 18 of the RGPD.
Right to erasure : you have the right to demand that your personal data be erased, and to prohibit any future collection of it for the reasons set out in article 17 of the GDPR.
Right to file a complaint with a competent supervisory authority (in France, the CNIL), if you consider that the processing of your personal data constitutes a violation of applicable texts, in accordance with article 77 of the RGPD.
Right to define guidelines for the storage, deletion and communication of your personal data after your death.
Right to withdraw your consent at any time : for purposes based on consent, Article 7 of the GDPR states that you can withdraw your consent at any time. This withdrawal will not call into question the legality of the processing carried out prior to the withdrawal.
Right to portability : under certain conditions specified in Article 20 of the GDPR, you have the right to receive the personal data you have provided to us in a standard machine-readable format and to require their transfer to the recipient of your choice.
Right to object : under article 21 of the GDPR, you have the right to object to the processing of your personal data.
You can exercise these rights by writing to us using the contact details below. On this occasion, we may ask you to provide us with additional information or documents to justify your identity.
7. What cookies do we use?
To find out more about the management of cookies we invite you to consult our Cookies Policy.
8. Point of contact to exercise your rights
Contact email: dpo@heetch.com
Contact address: 198 bis rue Lafayette, 75010, Paris
9. Changes
We may modify this policy at any time, in particular in order to comply with any regulatory, jurisprudential, editorial or technical changes. These changes will apply as of the effective date of the amended version. You are therefore invited to regularly consult the latest version of this policy. However, we will keep you informed of any significant changes to this privacy policy.
Entry into force: November 20, 2024