Legal · Privacy
Privacy Policy
DRAFT — pending legal review before launch
1. Scope
This policy describes how WSI Airport Transfers handles personal information for transfer bookings and this website, consistent with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
It is written to be accurate rather than comfortable. Some of what follows — particularly section 5 — describes limits most privacy policies leave out. We would rather tell you plainly than imply we can do something we cannot.
2. What we collect when you book
- Passenger details: the name, mobile number and email address entered in the booking form. The form asks for the passenger's details — if you book for someone else, you are giving us their information, and this policy covers it.
- Trip details: pickup address, airport and terminal, date and time, passenger and luggage counts, and the number of children and infants travelling.
- Accessibility and equipment needs: whether a wheelchair or pram is coming, and child seat requirements including the ages needed to fit a restraint correctly.
- Flight number and date, if you give one, so we can track your arrival.
- Your name, mobile and email as soon as you move past the details step. The booking flow sends them to us when you continue to the review screen — before you press "Send my request" — so that we can call you back about the fare even if you close the tab. Nothing is charged at that point, and you can ask us to delete the record at any time.
- Anything you type into the notes field. It is a free-text box and we store exactly what you write. Please keep health information, door codes and anything else sensitive out of it — section 5 explains why that matters more here than on most websites.
- Payment details are handled by Stripe. Card numbers never reach our systems; we keep a payment reference and the amount.
- Correspondence — emails, SMS and enquiries you send us.
3. What Google receives while you type an address
The pickup address box uses Google Places. What you type goes straight from your browser to Google as you type it — including text you type and then delete, and including visits where you never book anything. That exchange is between your browser and Google; it does not pass through our systems and we do not keep it. Google handles it under Google's own terms.
We keep only the address you finally select.
4. How we use it
To quote and provide the transfer: pricing, dispatching a driver, tracking your flight, sending confirmations and updates, taking payment, handling refunds, and keeping the records we must keep as a NSW booking service provider. We do not sell personal information and we do not run third-party advertising.
5. Where your booking is stored — and why we cannot delete it
This is the section most policies do not have, and the one most worth reading.
Your booking record is stored on the Internet Computer, a public blockchain. The record — your name, mobile, email, pickup address, trip and flight details, and anything you typed in the notes field — is copied across many independent computers run by different operators, in more than one country.
The consequence is blunt: we cannot delete it. There is no erase function, and we are not being coy — the software has no such capability. Once a booking is written it stays. The same is true of the record of every status change on your trip and every refund, which together form an audit trail we must be able to produce.
This is deliberate. It means booking and payment records cannot be quietly altered after the fact, which protects you in a dispute. But it also means our answer to a deletion request differs from most businesses', and you should know that before you book rather than afterwards. See section 9.
6. How long we keep things
- Booking records: indefinitely, for the reason in section 5.
- Your saved quote, and the record used to show your booking reference after payment: short-lived caches — minutes to 24 hours — which expire on their own.
- Flight lookups: cached for about 90 seconds.
- Server logs held by our hosting provider, which include the IP address a request came from.
- Emails and SMS we have already sent remain with our delivery providers and in your inbox.
7. Who else receives your information
Each provider gets only what its job requires. Several are outside Australia.
- Stripe — payments. Receives your email for the receipt, plus payment data.
- Resend — sends your confirmation and update emails.
- ClickSend — sends your SMS. Receives your mobile number.
- Google — address lookup and route/distance calculation.
- AeroDataBox — flight status. Receives the flight number and date only, never your name or contact details.
- Cloudflare — runs our booking server and holds the short-lived caches and logs.
- Internet Computer node providers — hold the replicated copies described in section 5.
- Your driver — receives what they need for the pickup, passed on by our operator.
- Authorities — where the law requires, including NSW point-to-point transport regulation.
8. Your manage link
Your confirmation email contains a link that opens your booking. That link is the key — anyone holding it can view and cancel your booking, with no password. Treat it like a password and do not forward the email.
The link stops working 30 days after your trip. We cannot revoke a single link before then. If you think someone else has yours, contact us and we will cancel and rebook you under a new reference, which retires the old link.
9. Your rights, answered honestly
Access — yes. Ask and we will give you what we hold. Quote your booking reference if you have one; we compile it by hand, so allow up to 30 days.
Correction — yes for anything operational. We will correct the record and note the correction in the audit trail. The original entry stays visible beside it, because that trail only ever appends.
Deletion — this is where we differ. We can delete material held in our short-lived caches. We cannot delete your booking record, for the reason in section 5. If that is unacceptable to you, phone the booking through instead of using this website and we will keep it out of the system.
If you are unhappy with how we have handled a privacy matter, contact us first. You can also complain to the Office of the Australian Information Commissioner (OAIC).
10. If something goes wrong
If we become aware of a data breach likely to cause you serious harm, we will notify you and the OAIC as required under the Notifiable Data Breaches scheme. Given the storage described in section 5, we will tell you plainly what can and cannot be contained.
11. Drivers
We hold each driver's name and mobile number, their vehicle details, the expiry dates of their licence, insurance and driver authorisation, an authorisation reference, and operator notes about their work. Completed job counts and punctuality are recorded from real trip events. This is stored the same way as bookings, so section 5 applies to it too.
We deliberately do not hold driver licence numbers, dates of birth, home addresses or identity scans in this system.
Deletion, for drivers specifically. If you have never been assigned a job with us, we can delete your record completely on request — nothing else refers to it. Once you have driven for us we cannot: your record is referenced by booking records, the payment ledger and the audit trail we are required to keep, and section 5 applies. In that case we mark the record inactive so you are no longer dispatched, and it stops being used.
Photographs you send us are stored separately from the records above and can be deleted on request. Photos you submit are reviewed by a person before any of them are used, and any we do not keep are deleted at that point.
Not yet in place: driver self-registration, car photographs, and paying drivers through Stripe. This section will be updated before any of those go live. Today driver payments are recorded here but made outside this system, and the bank details for them sit in the operator's own payroll records.
12. Our staff
Our operators sign in with Internet Identity. Their sign-in identifier is written permanently into the audit trail beside every action they take, so it is always clear who did what. Removing someone's access does not remove them from that history.
13. Cookies, browser storage and analytics
The booking form keeps your progress in your browser so a refresh does not lose it, and clears when you close the tab. Stripe and Google set and receive information in your browser on the booking page as part of taking payment and looking up addresses. Our operator console stores a sign-in session on the operator's own device.
This site currently runs no analytics, no advertising and no cross-site tracking. We are considering adding website analytics. If we do, we will name the provider here before it goes live.
14. Security
Payment credentials are held by Stripe, not by us. Reading full booking records through our operator console requires an Internet Identity sign-in on an account we have specifically granted. Our booking server also reads booking records automatically, under its own credential, in order to send your notifications and track your flight.
Please keep sensitive details out of the free-text notes field — see sections 2 and 5.
15. Contact and changes
Reach us through the contact page for any privacy request. If we change this policy we will update it here with the date, and material changes will be described rather than slipped in.