Privacy

Privacy

This notice describes the information this website stores when you create an account or send a quote request. It does not describe a confirmed booking.

  • ControllerTravel 2 EventsOwner-operator Dale McCarthy.
  • AccountsName and emailPlus a mobile number and a hashed password.
  • AnalyticsG-8GBX5F4H0NLoaded only if you allow it.

Who is responsible

The controller is Travel 2 Events. The owner-operator is Dale McCarthy. This notice does not name a company registration number, because none is published for this service.

Customer accounts

Creating an account stores your first name, last name, email address and mobile number. A UK mobile number is stored in national form. An international number is stored with a leading + and its country code. The password is stored only as a scrypt hash. The account also records when it was created, when it was updated, whether the email address has been verified, the account status, and the last successful login.

The account status is active, suspended or closed. A suspended or closed account cannot sign in.

Quote requests

The quote form stores the journey details you type, including pickup, destination, date, time, passenger count, luggage and contact details. Saving that form creates a request with status received. It is not a confirmed booking.

You can send a quote without an account. If you are signed in with a verified account, the stored request can also keep a link to that account so a later booking record can belong to you. The public quote lookup does not show that link.

Bookings

A booking stored for your account can include a reference, pickup, destination, dates, passenger count, price, deposit, balance and status. It can include a separate outbound journey and return journey. Driver and vehicle names are not shown on the account page. The site does not provide live vehicle tracking.

Payment references

This website does not collect card numbers. Registration, the quote form and the account page do not ask for payment card details. A payment request can store an amount, a type (deposit, balance or full), a status and, once a provider is connected, a link to that provider's page. No payment provider is connected yet. Card data is not stored.

If a provider is added later, card data should stay with that provider and should not be copied into the account database.

Authentication and security

A signed-in browser holds an HttpOnly session cookie named t2e_session. The server stores a hash of that cookie, not the cookie value. A second HttpOnly cookie, t2e_csrf, is compared with the form header on requests that change an account. Both are required for the account service and do not depend on the analytics choice.

Session rows can store a hash of the IP address and a hash of the browser string. Those hashes use a server-side pepper. Verification and password-reset links are stored as hashes and can be used once. The audit log records events such as registration, login, logout, email verification and password reset. It does not record passwords or the raw links.

Journey communication

Quote requests are stored so Travel 2 Events can reply. Automatic email notification of a quote is not configured, so submitting the form does not by itself send a message. Account email is used for verification and password reset when email delivery is configured. No separate journey-update channel is configured on this website.

Analytics

Each page carries the Google Analytics measurement ID G-8GBX5F4H0N. The Google tag is loaded only if you allow it. Until you choose, and if you reject analytics, the tag does not run and Google cookies are not set.

The site does not add other advertising or tracking tags. Allow analytics and Reject analytics are separate from the cookies required to sign in or to request a quote.

Cookies on this site

t2e_session is required to stay signed in. It is HttpOnly, SameSite Lax and Path /. On HTTPS it is also Secure. It lasts for the browser session, or 30 days if you choose remember me. The server copy expires after 12 hours or 30 days to match that choice.

t2e_csrf is required for account forms. It is HttpOnly, SameSite Lax and Path /. It is not a tracking cookie. A signed-out browser may also receive t2e_csrf for the quote and account forms.

t2e_analytics stores the analytics choice, granted or denied, for 180 days. It is not HttpOnly, because the page has to read it. It is SameSite Lax and Path /. On HTTPS it is also Secure. It is not a Google cookie. Google Analytics cookies are set only after you allow the G-8GBX5F4H0N tag, and they are not required to request a quote or to use an account.

Retention

Account data is retained while the account remains active and as needed for operational or legal obligations. Verification links are usable for 24 hours, and password-reset links are usable for 1 hour. Each of those tokens can be used once. After that they no longer sign you in or change the password.

A session stops being accepted when it expires, when you log out, or when the password is reset. Resetting the password also invalidates sessions that were already open. Expired session rows, used tokens, quote files, audit rows and closed accounts do not have a published deletion date. Quote, booking and account records are retained only as long as reasonably necessary for the service, for accounting, for legal duties and for disputes.

Your requests

You can ask to see the account and quote information held about you, to correct it, or to close the account. You can also complain to the Information Commissioner's Office.

No public email address or phone number is published. This website does not currently offer a contact channel for privacy requests.

See also the Terms.