Privacy Policy
2026.2 ·
I. About this Policy
The personal data controller is „Demo Trans” S.R.L., IDNO 1000000000000, with its registered office at str. Demo 1, MD-2000 Chișinău, Republica Moldova (hereinafter — "the Controller", "we").
Requests concerning personal data are sent to date@demo.local or, in writing, to str. Demo 1, MD-2000 Chișinău, Republica Moldova.
This Policy explains what personal data Demo Transport processes in connection with the website, the mobile app and related services, for what purpose and on what basis.
It applies to:
- the website, the mobile app and the passenger account;
- trip search, booking, purchase and issuing of tickets, changes, cancellations and refunds;
- user accounts and sign-in;
- support requests, chat and phone calls;
- initiating payments, receiving their status and preventing fraud;
- email, SMS, push notifications and service messages;
- security, monitoring and improvement of the services.
The journey is operated by Demo Transport or by the carrier named on the ticket. Where another carrier operates the journey, its own rules and notices apply to the processing it carries out independently.
The version of this Policy in force is 2026.2, applicable from 01/10/2026. The current version is always available on this page.
This Policy is drafted in Romanian and translated into other languages for your convenience. In case of discrepancy between language versions, the Romanian version prevails.
II. What data we process
Depending on what you use, the following categories of data are processed.
Passenger data: first and last name; date of birth, age, citizenship and country of residence where required for the journey, the fare or by law; passenger category and discount entitlement; details of an accompanying person; type, number, country and validity of the identity or travel document; visa details where required.
Contact data: phone number, email address, billing address, preferred language and channel of communication, correspondence with us.
Account data: account identifier, securely hashed password, one-time codes, access tokens and session data, sign-in history and security events, records of acceptance of terms and of consents.
Booking and trip data: departure and destination points, route, stops, date and time, trip, vehicle, boarding and drop-off points, order, booking and ticket numbers, seat, luggage, fare, discount, booking, boarding, change, cancellation and refund statuses, other passengers in the same booking, and details of complaints, incidents and lost property.
Payment data: amount, currency, time, method and status of the payment, transaction identifier, masked digits and card scheme, fraud-check results, details of invoices, refunds and chargebacks.
Support data: questions, requests, complaints, feedback, correspondence, case notes, status and outcome, files attached voluntarily.
Technical data: IP address, device identifiers, device model, operating system, app and browser version, language, time zone, approximate location derived from the IP address, cookies and session identifiers, page views and events, error and security logs.
Location data: where the feature is enabled and you have given permission, the app may use your location to show the nearest boarding points and the progress of the trip. Precise location is collected only after your permission.
Approximate location from the IP address: on our server, the IP address is looked up in a local database that returns only the country and the town, so that a search starts from the town you are in and the routes from there come first. The IP address is not passed to anyone for this, and the result stays in your browser for at most one day. Database: IP Geolocation by DB-IP, CC BY 4.0 licence.
https://db-ip.comIII. Special categories of data
Data concerning health or disability, as well as biometric, genetic, religious and other special category data, is deliberately not requested. It is processed only where strictly necessary for the assistance you requested for the journey, for accessibility, safety, an emergency, or where the law expressly provides for it, and only where an additional legal condition applies, such as explicit consent.
Do not send full card details, images of identity documents, health information or other irrelevant sensitive data through free-text fields, chat or by phone unless it has been specifically requested and is necessary.
IV. Purposes of processing and legal bases
We process personal data on the basis of Law No. 195/2024 on the protection of personal data. For each purpose described below, the applicable legal basis is indicated.
Trip search and fare display — to show routes, dates, seat availability and prices at your request. Basis: steps taken at your request before entering into a contract, and the legitimate interest in a working and secure service.
Booking, issuing tickets, changes and refunds — to enter into and perform the contract of carriage. Basis: performance of the contract, steps taken at your request before entering into it, and obligations that apply to the carrier.
User account — to create, protect and administer the account. Basis: performance of the account service contract and the legitimate interest in security and prevention of abuse.
Passenger support — to receive, review and resolve a question or complaint and to keep a record of the case. Basis: the contract or steps taken at your request, the legitimate interest in effective support, and the obligation to review a complaint where the law requires it.
Payments, reconciliation and fraud prevention — to take payment, confirm its status, process a refund and prevent abuse. Basis: the contract, legal obligations and the legitimate interest in preventing fraud.
Security and logs — to authenticate users, detect attacks, investigate abuse and restore the service. Basis: the legitimate interest in protecting users, systems and information.
Essential website and app technologies — authentication, session continuity, security, language and currency preferences. Basis: providing the service you requested.
Optional analytics — to measure audience and use of the service. Basis: your prior consent where it is required.
Marketing messages — to send offers and news. Basis: your prior consent, which can be withdrawn at any time.
Legal compliance — to meet mandatory obligations, respond to lawful requests and defend our rights. Basis: legal obligation and legitimate interests in legal claims.
V. How we obtain data
Personal data may come:
- directly from you, when you create an account, search for trips, book, pay, contact support, call or write in chat;
- from the person who makes a booking or gets in touch on your behalf;
- from the carrier, ticket seller, dispatcher, driver or sales agent;
- from payment providers and fraud-prevention providers;
- automatically from browsers, devices, the app, cookies and logs, subject to the necessary permissions and consents;
- from competent authorities or lawful public sources where necessary.
If you provide another person's data — another passenger, a child or a colleague — you must be authorised to do so and give them the privacy information required. Provide only accurate and necessary data.
VI. Mandatory and optional data
Some data is required by the carrier, the payment provider, the law or the contract. Mandatory fields are marked in the interface or are evident from the service you requested.
Without mandatory data it may be impossible to create an account, issue a valid ticket, process a payment or refund, meet passenger list or border-crossing requirements, authenticate a user or open a support request.
Optional data can be withheld without affecting the core services — only the corresponding additional feature will be unavailable.
VII. Tickets, boarding and the journey
The necessary data is shared with the carrier operating the trip, its authorised agents, ticket offices and operational partners, so that boarding, the passenger list check and the route can be carried out.
For international journeys the law may require limited passport, identity document, visa, citizenship or date of birth details. Such data is passed to border, customs, immigration, police, transport or other competent authorities only where the law provides for it or where it is necessary to operate the journey you requested.
The carrier may contact you about boarding, delays, cancellations, document requirements and safety.
VIII. Booking for other passengers
A person making a booking for others must provide only the information necessary for the journey, make sure it is accurate, and inform the other passengers about that processing and about this Policy.
A minor's data is provided by a parent, guardian or another authorised person, unless the law and the carrier's rules allow the minor to act independently.
IX. Identity documents
The number and main details of an identity or travel document are processed where required for international travel, the passenger list, compliance with border requirements, confirmation of a discount entitlement, or another lawful and specifically defined purpose.
An image or copy of a document is requested only where applicable law expressly requires or permits it — operational convenience alone is not enough. Unnecessary fields must be masked, the image is stored encrypted and access to it is restricted.
Document images are deleted immediately after the check or the permitted transfer is complete and, as a rule, no later than 30 days after the relevant journey, unless a longer period is required by law or by a documented dispute.
X. Payments
Payments are handled by third-party processors, banks, payment systems and digital wallets. Information entered in the payment field or in the provider's interface is collected directly by that provider under its own privacy notice.
Full card numbers and card verification codes are processed by authorised payment providers and are not passed to us. We receive limited information: the transaction identifier, masked card details, status, amount, currency, fraud-check results and refund data. This information is used to complete the booking, for reconciliation, fraud prevention, support and accounting.
XI. Support, chat and phone calls
Authorised staff may combine your request with information about the account, booking, trip, payment status and previous interactions, so that you are not asked for the same thing twice and support stays consistent. Access is limited by role and business need, and staff actions are logged.
When you call, the phone number, date, time and duration of the call, menu choices, transfers and the outcome of the call may be processed. A call is recorded only where recording is enabled and lawful: you will receive a clear notice before recording starts, and where recording relies on consent, a reasonably accessible channel without recording will be offered.
Feedback may be used to reply to you, improve support and prepare aggregated reports. Identifiable feedback is not published without your permission.
XII. Cookies and similar technologies
The website and the app may use cookies, local storage, pixels, mobile SDKs and similar technologies for essential operation, authentication, session management, security, storing preferences, performance measurement and analytics.
Strictly necessary technologies are used only to provide or protect the service you requested. Optional analytics technologies are not loaded before valid consent is obtained, where the law requires consent.
Refusing optional technologies must be as easy as accepting them. Consent can be withdrawn at any time; withdrawal does not affect the lawfulness of earlier processing.
XIII. Service and marketing messages
Service messages — authentication codes, tickets, receipts, payment status, schedule changes, boarding details, security warnings and notices required by law. They are sent only to the extent necessary for your account, booking, request or security purposes, and contain no hidden advertising.
Marketing messages by email, SMS, push notification or phone are sent only after prior consent has been obtained. Marketing consent is given separately from acceptance of the terms and the contract of carriage, relates to a specific channel and purpose, is not a condition of buying a ticket or receiving support, and can be withdrawn free of charge and as easily as it was given.
Unsubscribe requests are acted on without delay. Minimal details may be kept on a suppression list so that messages do not resume by mistake.
XIV. Automated processing
Automated rules may validate the form and seat availability, display the fares provided, route support requests, detect duplicates and suspicious activity, prioritise operational alerts and remember your preferences.
We do not make decisions producing legal effects, or similarly significant effects, based solely on automated processing. A fraud or security alert may temporarily delay a transaction or trigger a review; human review is available where the law requires it.
XV. Anonymised and aggregated information
Statistical, aggregated or anonymous information may be created for capacity planning, service improvement, reporting and commercial planning.
Information counts as anonymous only where a person cannot reasonably be identified, taking into account the data reasonably available to us. Pseudonymised data remains personal data and is protected as such.
XVI. Who receives the data
Personal data is disclosed only where necessary and on lawful grounds:
- to the carrier, ticket seller, ticket office, sales agent or travel partner;
- to authorised dispatchers, drivers and support staff;
- to payment processors, banks, payment systems, digital wallets and fraud-prevention providers;
- to email, SMS and push notification providers;
- to hosting, database, storage, backup, CDN, cybersecurity and monitoring providers;
- to analytics providers, where the necessary consent has been given;
- to auditors, lawyers, insurers and accountants;
- to border, customs, immigration, transport, tax, law-enforcement, judicial and other competent authorities where the law provides for it;
- to another recipient at your direction or with your valid consent.
Processors acting on our behalf are bound by a written contract covering instructions, confidentiality, security, assistance, deletion of data and audit rights.
We do not sell personal data and do not rent it out for money. Disclosure necessary to issue the ticket, operate the journey, take payment or provide support is not a sale.
XVII. Processing outside the country
We may use infrastructure and providers located in different countries, so personal data may be processed outside the country in which it was collected.
In such cases the transfer mechanisms provided by law apply, together with additional safeguards: encryption, strict access control, data minimisation and pseudonymisation. International travel may require the carrier to send the necessary passenger details to the country of destination or to a competent authority.
XVIII. Retention periods
Personal data is kept only for as long as necessary for the stated purpose and to meet legal, accounting and tax, transport, payment, security and limitation-period requirements.
Baseline periods:
- account and profile — for the life of the account and up to three years after it is closed;
- booking, ticket, invoice and payment status — the period required by accounting and transport rules;
- passenger list and document details — the period required by law for the particular route, and otherwise the minimum period necessary for the journey;
- document images — as a rule no later than 30 days after the journey;
- support cases and correspondence — usually up to three years after the case is closed;
- call metadata — usually up to 12 months;
- call recordings for quality assurance — no more than 90 days;
- technical and security logs — usually up to 12 months;
- marketing data — until consent is withdrawn, an objection is made or the purpose ends;
- deleted data in backups — until it is overwritten in the backup cycle, usually no more than 90 days.
A record may be kept longer only because of a documented legal obligation, an unresolved complaint, a fraud or security incident investigation, or a legal claim. During any extended period access is restricted, and retention ends when the ground for it falls away.
XIX. Data security
Technical and organisational measures appropriate to the risk are applied to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access:
- encryption in transit and, where appropriate, at rest;
- role-based access and the least-privilege principle;
- multi-factor authentication for privileged access;
- logging of access, changes and security events;
- backup, restore and service continuity measures;
- secure development, code review and vulnerability management;
- vetting of processors and contractual security terms;
- confidentiality obligations and staff training;
- incident response procedures and periodic reviews.
No online service is completely secure. Protect your credentials, use secure devices and tell us immediately if you suspect your account has been compromised.
XX. Personal data breaches
We maintain procedures to detect, assess, contain, document and remedy personal data security breaches.
The supervisory authority indicated in Chapter XXVI is notified within the period set by applicable law, including within 72 hours where that period applies. Where a breach presents a high risk to the people affected, they will also be informed without undue delay, unless a lawful exception applies.
XXI. Your rights
Subject to applicable law and lawful limitations, you may:
- receive clear information about the processing;
- obtain confirmation that your data is being processed;
- obtain access to the personal data and a copy of it;
- have inaccurate data corrected and incomplete data completed;
- request erasure where there is no longer a lawful ground for keeping it;
- request restriction of processing;
- receive the relevant data in a machine-readable format and transmit it to another controller;
- object to processing based on legitimate interests;
- object to direct marketing at any time;
- withdraw consent at any time where the processing is based on consent;
- request human intervention in relation to relevant automated decisions;
- lodge a complaint with the supervisory authority indicated in Chapter XXVI.
Rights are not absolute. Data may be kept where the law requires it or where it is necessary for accounting, transport obligations, security, fraud prevention, protection of another person's rights or legal claims. Information relating to another person may be withheld.
XXII. How to exercise your rights
A request can be sent using the contact details in the "Contacts" section of the website. In your request, state the account, booking, phone number or other details that help us locate your data.
Reasonably necessary information may be requested to verify identity and authority — it is used only to handle the request. A representative may be asked to prove their authority.
A response is provided within the period set by applicable law, as a rule within one month, allowing for any extension the law permits. Where an extension or a refusal is permitted by law, you will receive an explanation and information about your right to lodge a complaint and to seek a judicial remedy.
Where the processing is carried out by another carrier named on the ticket, the request may be forwarded to it, and we will provide the necessary assistance.
XXIII. Children and minors
The service is not intended for a child to enter into a contract independently where they lack the necessary capacity. A booking is made and supervised by a parent, guardian or another authorised adult, unless the law and the carrier's rules allow otherwise.
Name, age, date of birth, route, required travel document details, guardian details and necessary assistance information may be processed to operate the journey, comply with the law and protect the child. Only the necessary data is collected. Children's data is not used for advertising.
XXIV. Third-party services and links
The service may link to, or interact with, carrier websites, payment pages, maps, social networks, app stores and other third-party services. Such third parties may process personal data independently under their own notices and terms.
This Policy does not govern processing carried out by an independent third party. Please read the relevant notice of that service.
XXV. Changes to this Policy
This Policy may be updated because of changes to the services, the processing, providers, security or the law. The current version is published on this page.
Where a change materially affects your rights or the use of personal data, additional notice will be given through the website, the app, your account, email or another suitable channel. Where consent is required for a new purpose, it will be requested. Continued use of the service is not treated as consent where the law requires valid consent.
XXVI. Supervisory authority
The supervisory authority is National Center for Personal Data Protection, with its headquarters at str. Serghei Lazo 48, MD-2004 Chișinău, Republica Moldova, telephone +37322820801.
You have the right to lodge a complaint with the supervisory authority if you consider that the processing of your data violates Law No. 195/2024 on the protection of personal data.