Privacy Policy

PRIVACY POLICY

1. Introduction and Scope

Area Car Service LLC, trading as Area Car Service (“Area Car Service,” “Company,” “we,” “our,” or “us”) respects your privacy and is committed to protecting the personal information you entrust to us when you book, pay for, or use transportation arranged through our platform. This Privacy Policy explains what personal information we collect, why we collect it, how we use and share it, how long we keep it, how we protect it, and the choices and rights you have.

This Privacy Policy applies to all personal information collected through our website at https://arealimoservice.com, our mobile applications, our reservation and dispatch systems, our customer support channels, and every other channel through which we receive and coordinate transportation bookings (collectively, the “Platform”). This includes bookings and communications made by telephone, email, SMS/text message, live chat, social media messaging, third-party booking partners, travel agencies, and authorized affiliates.

Our services are directed to customers in the United States. Section 15 explains how we handle information belonging to international travelers.

This Privacy Policy should be read together with our Terms of Service, which govern the transportation reservation services we provide. Where a term is defined in the Terms of Service and used here, it carries the same meaning unless stated otherwise. In the event of any conflict between the Terms of Service and this Privacy Policy on a matter of personal information, this Privacy Policy controls.

2. Who We Are

Area Car Service is the trading name of Area Car Service LLC, a limited liability company registered in the State of Virginia 

We operate a technology-enabled reservation, dispatch, coordination, and customer support platform for ground transportation. We do not own, lease, or operate vehicles, we do not employ drivers, and we do not perform transportation services ourselves. All transportation is performed by independent, licensed transportation providers using their own vehicles, drivers, licenses, and insurance. Our role is to receive and coordinate reservations, assign trips to participating transportation providers, process payments, and provide customer support before, during, and after a trip.

Our transportation operations are focused primarily in New York, Connecticut, Massachusetts, and New Jersey. Our customers and website visitors may be located elsewhere, including outside the United States.

Who controls your information? Area Car Service LLC is the controller of, and the “business” responsible for, the personal information described in this Privacy Policy.

Transportation providers control their own information. Each transportation provider is an independent business. In respect of the personal information a provider processes for its own purposes — including its own dispatch records, in-vehicle recordings, driver communications, and regulatory record-keeping — that provider acts as an independent controller and not on our behalf. We are not responsible for a transportation provider’s handling of personal information for its own purposes, and a privacy complaint relating to that processing lies against the provider. Section 8 explains what we share with providers and why.

Our contact and registration details are set out in Section 19.

3. Information We Collect

We collect personal information in three ways: information you provide directly, information collected automatically when you use the Platform, and information we receive from third parties. What we collect depends on how you interact with us.

3.1 Information you provide directly

Identity and contact information — your name, the passenger’s name, email address, telephone number, and billing address.

Reservation and trip details — pickup date and time, pickup location, destination, flight information (airline, flight number, arrival date and scheduled arrival time), number of passengers, luggage quantity and size, child seat requirements, accessibility requests, and any special instructions.

Payment information — cardholder name, billing address, and the payment method used. Where you choose to send us card details directly, this may include the card number, expiry date, and a photograph of the card. Section 9 explains how we handle and delete that information.

Identity verification information — in the limited circumstances described in Section 5, a government-issued photo ID, so that we can confirm the name on the ID matches the name on the payment card.

Communications and support records — the content of emails, SMS/text messages, live chat sessions, and social media messages, together with complaint details, photographs, screenshots, and receipts.

Call recordings — audio recordings of telephone calls to and from our reservations and support lines. At the start of any such call, before any reservation or payment matter is discussed, we tell you that the call is recorded and ask whether you agree. Recording takes place only if you agree. If you do not agree, the call continues without being recorded, or you may instead contact us by email, SMS, or live chat, and declining will not affect the service you receive or the price you pay. Where the law of any state applicable to the call requires the consent of all parties, no recording is retained unless every party has agreed. Recordings are used for quality assurance, training, reservation accuracy, payment verification, dispute resolution, and fraud prevention. Section 9.5 explains how we handle card details spoken during a call, and Section 10 sets out how long we keep recordings.

Records of your agreement to our terms — when you accept our Terms of Service, we record the date and time, the reservation or account identifier, the channel you used (for example web, telephone, email, or messaging), your IP address where applicable, and the version of the Terms then in effect. We keep this as evidence that the agreement was formed, and we use it for no other purpose.

Feedback and reviews — suggestions, comments, ratings, and reviews you choose to share.

3.2 Information we collect automatically

Device and connection data — IP address, device type, browser type and version, operating system, language settings, and mobile device identifiers.

Usage data — pages and screens viewed, links clicked, referring and exit pages, session recordings (for example through Microsoft Clarity), and access times.

Cookies and similar technologies — identifiers set through cookies, pixels, tags, and local storage, as described in Section 6.

3.3 Location information

We collect the pickup and drop-off addresses you enter when booking, so that we can arrange your trip and provide those addresses to the transportation provider assigned to you.

We do not collect real-time GPS location data from your device, and our website and applications do not request access to your device’s location services. If we introduce live location features in the future, we will update this Privacy Policy and, where required, obtain your consent before collecting that data.

Separately, transportation providers operate their own dispatch and vehicle-tracking systems. Where a trip is disputed, or in connection with a complaint, incident, or chargeback, a transportation provider may supply us with vehicle location and dispatch records relating to your trip — for example, the time and place of arrival, waiting time, and trip completion. This is vehicle data generated by the provider’s own systems, not location data taken from your device. We receive it after the fact, we use it only to investigate and resolve the matter concerned, and we never use it for advertising or profiling.

Precise geolocation is treated as sensitive personal information under California law. Because we do not collect it, and because we use the location information we do hold only to perform the trip, investigate a complaint or incident, resolve a payment dispute, and comply with law, the protections in Section 5 apply to it in the same way.

3.4 Information we receive from third parties

Payment processors — Stripe and Square return payment tokens, authorization results, fraud-risk signals, and limited transaction details (such as the last four digits and card brand).

Transportation providers and drivers — trip status, pickup and completion information, waiting-time records, vehicle dispatch and location records relating to your trip, incident reports, and service quality, safety, damage, or lost-property details.

In-vehicle recordings — some vehicles operated by transportation providers carry audio or video recording devices. This recording is controlled by the transportation provider, not by us. We do not operate, access, or control that equipment, and the provider is responsible for its own compliance with recording and consent laws in the states where it operates. We receive such a recording only where a provider voluntarily supplies one in connection with an incident, complaint, or payment dispute, and we then use it only to investigate and resolve that matter.

Flight status providers — publicly available flight status information used to coordinate airport pickups.

Booking partners and affiliates — reservation and contact details shared when you book through a third party.

Advertising and analytics partners — platforms such as Meta and Google may provide aggregated campaign and measurement data associated with our advertising.

4. Categories of Personal Information (California Disclosure)

The table below sets out the categories of personal information, using the categories defined in the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), that we have collected in the preceding twelve (12) months, and whether we “share” each category for cross-context behavioral advertising. As explained in Section 6, we do not sell personal information, but our use of advertising and analytics tools such as the Meta Pixel and Google Ads may constitute “sharing” under California law.

Category

Examples

Collected?

Shared for advertising?

A. Identifiers

Name, email, phone, billing address, IP address, device identifiers, reservation ID, marketing consent records, and records of your acceptance of our Terms of Service (date, time, channel, IP address, and version accepted)

Yes

Online identifiers (IP address, cookie and device identifiers), and — where server-side advertising measurement applies — your email address and telephone number in irreversibly hashed form only. We do not share your name or billing address for advertising, and we never share telephone numbers or SMS consent data with third parties for their own marketing.

B. Customer records (Cal. Civ. Code §1798.80)

Name, pickup and drop-off address, phone, payment method details

Yes

No

C. Protected classification characteristics

Inferred only where an accessibility request reveals a mobility-related need; we do not intentionally collect race, religion, or similar data

Limited

No

D. Commercial information

Booking history, trip records, services purchased, transaction records

Yes

No

E. Internet or network activity

Browsing and interaction data, session recordings, analytics

Yes

Yes

F. Geolocation data

Pickup and drop-off addresses you enter, and vehicle dispatch records received from providers. We do not collect precise real-time GPS from your device.

Yes

No

G. Audio, electronic, visual information

Call recordings; in-vehicle audio or video recordings supplied to us by a transportation provider following an incident or dispute; email, chat, and SMS records; photographs or screenshots submitted with complaints

Yes

No

H. Professional or employment information

Corporate billing account, company name, and related contacts, where applicable

Yes (if applicable)

No

I. Inferences

Preferences and characteristics derived from activity, used for analytics and advertising audiences

Yes

Yes

J. Sensitive personal information

Government-issued photo ID collected for the identity-verification and fraud-prevention purposes in Section 5; an image of a payment card with all but the last four digits obscured, collected for the same purposes; a payment card number combined with a security code, in the limited case where you choose to send those details to us directly (Section 9)

Limited

No

We do not collect biometric information, education information, or precise geolocation. We do not knowingly collect personal information revealing racial or ethnic origin, religious or philosophical beliefs, union membership, genetic data, health data, sex life, or sexual orientation, other than the limited inference that may arise from an accessibility request, as described in Section 5.

Sources and recipients. The sources from which we collect each category are described in Section 3, and the categories of third parties to whom we disclose each category are described in Section 8.

5. Sensitive Personal Information

We collect sensitive personal information only for identity verification and fraud prevention, and only in the following limited circumstances:

  • where our payment processor flags a transaction as carrying an elevated fraud risk;
  • where the payment card used for a booking belongs to someone who is not the customer or the passenger, and we need to confirm that the cardholder authorized the transaction; or
  • where we otherwise have a reasonable, specific concern that a booking or payment may be fraudulent, unauthorized, or unlawful.

In those circumstances we may ask you, or the cardholder, to provide a government-issued photo ID so that we can confirm that the name on the ID matches the name on the payment card. We may also ask for an image of the payment card showing only the cardholder name, expiry date, and last four digits, with all other digits and the security code obscured by you, together with confirmation of the billing address or a signed card authorization form. We request these materials only through a secure upload link. We will never ask for them by text message, or messaging app.

When we do so:

  • We use the ID and the card image only to verify that the name and card match, and for no other purpose.
  • We never use them to infer characteristics about you, and we never disclose them to advertising or analytics partners.
  • We store them in encrypted form, both in transit and at rest, on systems separate from your general customer record. Access is limited to the small number of authorized personnel who need it to complete a verification or to respond to a fraud investigation, chargeback, or legal claim, and every access is logged.
  • We retain them for the period set out in Section 10, because a verification record is the evidence we rely on to defend a chargeback, a claim of unauthorized use, or an allegation that we processed a payment we should not have. Those disputes can arise long after the trip.
  • Early deletion at your request. You may at any time request deletion of a government-issued identification document or payment card image held under this Section by contacting us using the details in Section 19. We will delete the requested document within thirty (30) days of receipt of the request and confirm the deletion in writing. Following deletion, we retain only the outcome of the verification (verified or not verified), the date on which it was performed, and the type of document verified.

This right does not apply where the document is material to a chargeback, fraud investigation, insurance claim, legal claim, or law-enforcement or regulatory request that is active at the date of the request. In that event, we will notify you that the request is suspended and the reason for the suspension, delete the document within thirty (30) days of the conclusion of that matter, and confirm the deletion in writing.

We use sensitive personal information solely for purposes that are permitted under the CCPA without the need to offer a right to limit — namely verifying identity, preventing and investigating fraud and other unlawful conduct, and complying with law. Because we do not use or disclose sensitive personal information for any other purpose, we are not required to provide, and do not provide, a separate “Limit the Use of My Sensitive Personal Information” mechanism. If this changes, we will update this Privacy Policy and provide that mechanism.

Accessibility requests. Separately, where you make an accessibility request that reveals information about a mobility-related need, we use that information only to arrange a suitable vehicle and to inform the assigned transportation provider so that the trip can be performed. We share it with that provider only to the extent necessary, we never use it for advertising, profiling, or pricing, and we delete it twelve months after the trip. You are never required to disclose a medical condition or diagnosis to us — only the practical requirement, such as a wheelchair-accessible vehicle or space for a folding wheelchair.

6. Cookies, Analytics, and Advertising Technologies

We use cookies and similar technologies to operate the Platform, remember your preferences, measure and improve performance, and support our advertising. Some are provided by third parties who may set their own identifiers and receive information about your activity.

Strictly necessary — required to load pages, secure the site, and complete a booking. These do not require consent.

Performance and analytics — Google Analytics and Microsoft Clarity, used to understand how visitors use the Platform, including session recordings.

Advertising and measurement — the Meta (Facebook and Instagram) Pixel and Google Ads, used to measure advertising and reach relevant audiences.

Session recording limitations. Where session recording is used, we configure it to mask all text entered into form fields, and we exclude payment pages, identity-verification pages, and any page containing accessibility fields from recording entirely.

Because the Meta Pixel and Google advertising tools may disclose identifiers and activity data to those platforms for cross-context behavioral advertising, this activity is treated as “sharing” of personal information under California law, even though we receive no payment for it. You can opt out as described in Section 11, including recognized opt-out preference signals such as Global Privacy Control (GPC).

You can also manage cookies through your browser settings and through our cookie preference tool, which is available on every page. Blocking some cookies may affect how the Platform functions.

Server-side advertising measurement. In addition to the browser-based Meta Pixel, we send certain conversion events to Meta directly from our servers using Meta’s Conversions API. These events cover actions such as submitting a booking request or completing a payment, and they include the event type, timestamp, and value, together with identifiers such as your email address, telephone number, and IP address, which are irreversibly hashed before transmission so that Meta receives them only in encoded form. We use this only to measure the performance of our advertising and to reach relevant audiences. Because this transmission happens on our servers rather than in your browser, blocking cookies does not prevent it. Where you opt out under Section 11, or send us a Global Privacy Control signal, we apply Meta’s Limited Data Use flag to your events, and we do not send server-side conversion events for you.

7. How We Use Your Information

We use personal information for the following business and commercial purposes:

  • To receive, confirm, coordinate, and fulfill transportation reservations, including assigning trips to transportation providers and drivers.
  • To process payments, apply authorizations, issue refunds and credits, and maintain accurate billing and transaction records.
  • To verify identity where a payment is flagged as high-risk or where a third-party cardholder is involved, and to detect, investigate, and prevent fraud, chargeback abuse, and other unlawful activity.
  • To communicate with you about reservations, confirmations, receipts, driver and dispatch information, trip updates, operational notices, and customer support.
  • To coordinate airport pickups using flight information and publicly available flight status.
  • To provide customer support and to review, investigate, and resolve complaints, disputes, damage claims, and lost-property matters.
  • To operate, secure, maintain, analyze, and improve the Platform and our services.
  • To conduct marketing and advertising, measure campaign performance, and reach relevant audiences, subject to your choices and applicable law.
  • To comply with legal, tax, accounting, insurance, regulatory, and law-enforcement obligations, and to establish, exercise, or defend legal claims.

8. How We Share and Disclose Information

We share personal information only as described below. We do not sell your personal information, as that term is defined under the CCPA. We do share personal information for cross-context behavioral advertising, as described in Section 6.

Transportation providers and drivers — the information needed to perform your trip, such as passenger name, contact number, pickup and drop-off locations, flight details, and special instructions. Transportation providers are independent businesses that determine for themselves how they handle personal information in the course of operating their own services. They act as independent controllers, not on our behalf, and their own privacy practices govern their use of your information.

Payment processors and financial institutions — Stripe and Square, and the banks and card networks involved in your transaction.

Card networks and issuing banks in a payment dispute — where you or a cardholder initiates a chargeback or payment dispute, we may submit to the card network, issuing bank, or payment processor the evidence needed to respond to it. That evidence may include the reservation record, the booking confirmation, our communications with you, call recordings, and dispatch or vehicle location records supplied by the transportation provider. We submit only what is relevant to the disputed transaction.

Analytics and advertising partners — online identifiers and activity data shared with Google, Meta, and Microsoft, as described in Section 6.

Service providers and vendors — vendors who host our systems, send communications, provide customer-support tooling, and perform similar functions on our behalf, under written contracts that restrict their use of the information to the services they provide to us and require them to protect it.

Insurers and professional advisers — insurers, auditors, accountants, and legal advisers in connection with claims, audits, and legal matters.

Provider details disclosed to you after an incident — where you request it in writing following an incident, we will give you the identity and contact details of the transportation provider assigned to your reservation, and the insurance carrier and policy details we hold for that provider, so that you can pursue a claim directly.

Law enforcement and authorities — where permitted or required by law, or to protect the rights, safety, and property of customers, drivers, the public, or the Company.

Business transfers — personal information may be transferred as part of a merger, acquisition, financing, reorganization, or sale of assets, subject to this Privacy Policy.

With your direction or consent — shared with other parties when you ask us to.

A current list of our key service providers is available on request using the details in Section 19.

9. Payment Information and Card Data

9.1 How we prefer to take payment

Our standard method is a secure payment link, or secure payment fields hosted by our payment processors, Stripe and Square. When you pay this way, your card details go directly to the processor and never reach our systems at all. We ask every customer to use this method, including customers booking by telephone.

9.2 Card details you choose to send us directly

Some customers ask us to process a payment on their behalf and choose to send card details to us directly — by telephone, email, text message, or messaging app, sometimes including a photograph of the card. We do not require this and we discourage it, because these channels are not secure and we cannot control copies held on your own device or by your messaging or email provider.

Where you do send card details to us, we handle them as follows:

  • We use them only to enter the payment into our payment processor and complete the transaction you have asked for.
  • We delete the original message, image, or note as soon as the payment has been authorized, and in any event within 24 hours — including from the receiving mailbox or chat, from deleted and archived folders, and from any device on which it was viewed or downloaded.
  • We never retain the card security code (CVV/CVC/CID) after authorization, in any form.
  • We keep a dated record that the deletion was carried out, so that we can demonstrate it if asked.
  • We do not transfer card details to any other system, and we do not store them in your customer profile.

9.3 What we keep afterwards

Once a payment is authorized, the only card information retained on our systems is a secure token supplied by our payment processor, together with the card brand, the last four digits, and the expiry date. The token — never your full card number — is what allows us to identify a card for repeat bookings, refunds, dispute resolution, and fraud prevention.

9.4 Access and processors

Access to payment-related information is limited to authorized personnel who need it for a legitimate business purpose, and is protected by role-based access controls, authentication requirements, and audit logging. Card transactions are processed by Stripe and Square, who handle your card information under their own terms and privacy policies.

Please note: we will never ask you to send card details by email, text message, or messaging app. If you receive such a request appearing to come from us, do not respond to it, and contact us using the details in Section 19.

9.5 Card details spoken during a recorded call

Where you choose to give card details to us by telephone on a recorded line, we either suppress recording during the part of the call in which you read out the card details, or we remove the card number and security code from the stored recording or the complete recording. We do this as soon as the payment has been authorized, and in any event within 24 hours. What remains in the recording is the part that evidences your authorization — that you agreed to the amount and to the charges described — and not the card number or security code themselves. We keep a dated record confirming this was carried out.

10. Data Retention

We keep personal information only for as long as necessary for the purposes described in this Privacy Policy. The periods below reflect our standard retention schedule. Where a legal claim, investigation, audit, or regulatory request is active, we retain the relevant records until it is concluded, even if the standard period has expired.

Information

Retention period

Reason

Booking and trip records

7 years from the date of travel

Tax record-keeping, insurance, and claims

Payment tokens and transaction records

7 years from the transaction

Tax, accounting, chargeback, and dispute resolution

Card details sent to us directly by a customer

Deleted once payment is authorized, and within 24 hours at the latest

Not needed after the transaction; minimizing exposure

Card security codes (CVV/CVC/CID)

Never retained after authorization

Prohibited by payment card security standards

Government-issued ID used for fraud checks

Seven (7) years from the date of verification, or until deletion is requested under Section 5, whichever occurs first. Such documents are held in encrypted form, in storage separate from general customer records, with access restricted to authorized personnel and logged. Where deletion is requested, only the verification outcome, the date of verification, and the document type are retained, for seven (7) years from the date of verification

Evidence in chargebacks, claims of unauthorized card use, insurance matters, and legal claims, which may arise several years after the date of travel

Customer support and complaint records

3 years, or 6 years where linked to a claim or dispute

Limitation periods for contractual claims

Call recordings

7 years from the date of the call

Payment authorization evidence, tax and accounting record-keeping, chargeback and dispute resolution, and defense of legal claims

Incident, injury, and vehicle damage reports

7 years, or longer where a minor was involved, until the applicable limitation period expires

Personal injury limitation periods

Accessibility request details

12 months after the trip

Shortest period consistent with repeat-booking service

Marketing contact details

Until you opt out, or after 24 months of inactivity

Consent must remain current

Records of consent and opt-out

6 years after consent is withdrawn

Evidence that processing was lawful

In-vehicle audio or video recordings supplied by a transportation provider

Until the conclusion of the incident, complaint, dispute, or claim to which the recording relates, and deleted from Company systems thereafter. Retention of the original recording by the transportation provider is governed by that provider’s own policies and is outside the Company’s control

Investigation and resolution of the incident, complaint, dispute, or claim concerned

SMS marketing consent records (opt-in timestamp, method, IP address, disclosure text shown, opt-out date)

6 years from the date consent is withdrawn or last relied on

Telephone Consumer Protection Act claims carry a 4-year limitation period; these records are the primary defense

Website analytics data

2 to 3 Years

Platform maximum retention setting

Session recordings

12 months

Limited-term usability analysis only

Server and security logs

12 months, extended to 24 months where a log relates to an active or investigated security incident

Security monitoring and incident investigation

When personal information reaches the end of its retention period, we delete it, or irreversibly anonymize it so that it can no longer be associated with you.

11. Your Privacy Rights

We extend the following rights to all customers in the United States as a matter of policy. Where a right exists only under a particular state law, that law governs its precise scope.

Right to know and access — request the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties to whom we disclose it.

Right to delete — request deletion of personal information we have collected, subject to legal exceptions (for example, completing a transaction, meeting tax or accounting obligations, preventing fraud, or defending legal claims).

Right to correct — request correction of inaccurate personal information.

Right to opt out of sale or sharing — opt out of sharing for cross-context behavioral advertising. We do not sell personal information.

Right to data portability — receive a copy of your personal information in a portable, readily usable format.

Right to non-discrimination — we will not deny service, charge different prices, or provide a different quality of service because you exercised a privacy right.

How to exercise these rights. Contact us using the details in Section 19. We will verify your identity before acting on a request, using information already held in your account or booking record. You may use an authorized agent, who must provide written proof of authority. We honor the Global Privacy Control (GPC) as a valid opt-out signal for the browser and device from which it is sent.

Timing and appeals. We acknowledge requests within 10 business days and respond within 45 days, extendable once by a further 45 days where reasonably necessary, and we will tell you if an extension applies. If we decline your request, we will explain why. You may appeal that decision within 60 days by emailing [privacy@arealimoservice.com] with the subject line “Privacy Request Appeal”. We will respond to an appeal within 45 days, explaining the outcome in writing. If your appeal is denied, you may contact your state Attorney General.

California “Shine the Light.” California Civil Code §1798.83 permits California residents to request certain information about disclosure of personal information to third parties for those third parties’ own direct marketing purposes. We do not disclose personal information to third parties for their own direct marketing.

Consumers under 16. We do not sell or share the personal information of consumers we know to be under 16 years of age.

12. Marketing Communications

We distinguish between two kinds of messages.

Transactional messages — booking confirmations, receipts, driver and vehicle details, pickup updates, changes and cancellations, and responses to your enquiries — are part of the service you have asked us to provide. We send these by email and SMS, and you cannot opt out of them while you have an active booking, because we need them to deliver your transportation.

Marketing messages — promotions, offers, newsletters, and service announcements not tied to a specific booking. We send these by email, and by SMS/text message where you have separately opted in to receive them.

Marketing email. We send marketing email in accordance with the CAN-SPAM Act. Every marketing email carries a clear unsubscribe link, which we action within ten business days.

Marketing SMS. We send marketing or promotional text messages, automated calls, or prerecorded messages only where you have given prior express written consent through a separate, unchecked opt-in, as the Telephone Consumer Protection Act requires. That consent is:

  • separate — it is its own checkbox or keyword confirmation, not bundled into your acceptance of our Terms of Service or Privacy Policy;
  • not a condition of purchase — you can book with us, and receive every transactional message about your booking, without ever agreeing to marketing SMS; and
  • recorded — we keep a record of when and how you opted in, and the disclosure language shown to you at the time.

At the point of opt-in you will be shown substantially the following:

By checking this box you agree to receive recurring automated marketing text messages from Area Car Service at the mobile number provided. Consent is not a condition of purchase. Message frequency varies. Message and data rates may apply. Reply STOP to unsubscribe or HELP for help. See our Privacy Policy and Terms of Service.

Opting out. You can opt out of marketing at any time by replying STOP to any marketing text, using the unsubscribe link in any marketing email, or contacting us using the details in Section 19. We action SMS opt-outs immediately and automatically. Opting out of marketing does not stop transactional messages about bookings you have made, and does not affect the service you receive or the price you pay.

We do not sell, rent, or share your telephone number with third parties for their own marketing purposes, and we do not share SMS consent data with any third party other than the messaging vendor that delivers the messages on our behalf.

13. Automated Decision-Making and Profiling

We do not use fully automated decision-making that produces legal effects concerning you or similarly significantly affects you. Where our payment processor flags a transaction as high-risk, that flag is reviewed by a member of our team before any action is taken, and you can always contact us to discuss the outcome.

Where we use analytics or advertising tools to build audience segments, these are used for marketing purposes only and do not determine your access to our services or the price you pay. If this changes, we will update this Privacy Policy.

14. How We Protect Your Information

We implement administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, disclosure, alteration, misuse, and loss. These include role-based access controls, authentication requirements, restricted internal access, audit logging, encryption of data in transit, and reliance on established third-party processors for all card transactions.

Staff who handle payments are trained on the deletion procedure described in Section 9.2, and deletions are logged so that compliance can be demonstrated.

If a security breach affecting your personal information occurs, we will notify affected individuals and regulators as required by applicable state breach notification laws, without unreasonable delay.

No method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security. You also play a part: use the secure payment links we provide, avoid sending card details or other sensitive information through unsecured channels, and contact us promptly if you believe your information or account has been compromised.

15. International Visitors

We are based in the United States, our services are directed to customers in the United States, and all transportation we arrange is performed in the United States. We do not target or market our services to residents of the European Union, the European Economic Area, or the United Kingdom, and we do not offer services in those regions. Comprehensive EU or UK data protection law does not therefore apply to us merely because a traveler visiting the United States books a trip through the Platform.

If you are an international visitor, your personal information will be processed and stored in the United States, where privacy laws differ from those in your home country. As a matter of policy, we handle all personal information in line with core data-protection principles regardless of where you are located: we collect only what we need, use it for the purposes described in this Privacy Policy, keep it only as long as necessary, and apply reasonable security. Where you have rights under the law of your own jurisdiction, we will make reasonable efforts to honor a comparable request. Contact us using the details in Section 19.

16. Children’s Privacy

Our Platform and services are intended for adults. Consistent with our Terms of Service, you must be at least eighteen (18) years of age, or have the legal authority to enter into a binding contract, to make a reservation.

We do not knowingly collect personal information directly from children under 16, and we do not direct our services to children. Minors may of course travel as passengers when an adult makes the booking; in that case the adult customer provides any passenger information and is responsible for supervising minors during the trip. If you believe we have inadvertently collected personal information directly from a child, please contact us and we will take reasonable steps to delete it.

17. Third-Party Links and Services

The Platform may link to, or integrate with, third-party websites, applications, and services — including payment processors, mapping and flight-status providers, social media platforms, and booking partners. This Privacy Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review the privacy policy of any third-party service you use in connection with our Platform.

18. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. When we do, we will revise the “Last Updated” date above and, where a change is material, provide additional notice by posting on our website or through another reasonable method. We review this Privacy Policy at least once every twelve months, as required under California law.

19. How to Contact Us

If you have questions about this Privacy Policy, wish to exercise your privacy rights, or want to raise a privacy concern, you may contact us:

Contact point

Details

Company

Area Car Service, a trading name of Area Car Service LLC

State of registration

Virginia 

Operations

New York, Connecticut, Massachusetts, and New Jersey

Privacy email

privacy@areacarservice.com

General email

info@areacarservice.com

Telephone

(888) 999-8679

Website

https://areacarservice.com

For questions about our Terms of Service, please refer to that document. For matters relating to drivers and transportation providers, please refer to the applicable Transportation Provider Agreement.