Official documents
Privacy Policy
1. Who is the controller
CONNECTBASE SRL, IDNO/tax code 1023600007753, registered office: MD-2089, Republic of Moldova, mun. Chișinău, s. Ciorescu, str. Ștefan cel Mare, no. 9, operates autocare.md, autobuse.md, autobuze.md, the Autocare mobile app and pay.autocare.md.
For questions and exercising rights: [email protected], phone +373 60 003 377.
2. To whom the policy applies
The policy applies to users of the websites and app, account holders, passengers included in requests, people who contact support, use MAIB payment, or explicitly subscribe to price alerts. A person entering the data of another passenger must have the right to provide it and must communicate this policy and the relevant booking terms to them.
We collect contact details only for the person making the booking. We do not request the separate phone number or e-mail of the other passengers, and Autocare communications about the request and the trip are sent to the booking person, who must pass them on to the people for whom they booked.
3. What data we process
| Category | Examples | Usual source |
|---|---|---|
| Identity and contact | The first and last names of passengers; the booking person's phone number, e-mail, preferred language and account identifier. | The user, the adult making the booking, or account authentication. |
| Booking and trip data | Route, date/time, carrier, boarding/disembarking points, passengers, seat, baggage/options, necessary comments. | The user, the selected offer, the carrier and connected systems. |
| Additional data required by the trip | Date of birth, document type/number or other information only if the offer/carrier explicitly requests it for the selected trip. | The user, after notice in the form. |
| Payment | Amount, currency, provider, transaction identifier, status, deadline, refund. Autocare does not request storage of the full card number or CVV. | The user, MAIB and Autocare records. |
| Communications and support | E-mails, SMS, push notifications, requests, complaints, responses and the necessary operational history. | The user, Autocare and the carrier. |
| Technical and security data | IP address, timestamps, device/browser, logs, session identifiers, authentication/push tokens, error and anti-fraud events. | The device, servers and technical providers. |
| Preferences and analytics | Language, theme, favorite/recent routes, cookie consent and Google Analytics events only according to consent options. | The user and use of the platform. |
| Price alerts | The tracked route and the subscription status. | Explicit user subscription; we do not use the booking for a general newsletter. |
4. Why we use the data and what is the legal basis
| Purpose | Basis used, as applicable |
|---|---|
| Searching, transmitting the request, confirming, managing the booking and communicating with the passenger. | Steps taken at the user's request and performance of the service/contractual relationship. |
| Transmitting the data to the carrier for acceptance, the passenger list and performance of the trip. | Necessity for the requested booking/transport and applicable obligations. |
| MAIB payment, reconciliation, refund, fraud prevention and financial-accounting records. | Performance of the payment/contract, legal obligations and legitimate security interests. |
| Account, authentication, OTP, security, abuse prevention and incident investigation. | Performance of the service, security obligations and proportionate legitimate interests. |
| Support, complaints, defense of rights and dispute resolution. | Legal obligations, performance of the service and legitimate interests. |
| Price alerts for selected routes. | Explicit request/subscription; they can be stopped at any time. |
| Google Analytics and the associated optional storage. | Consent from the cookie banner. |
| Fulfilling requests from competent authorities. | Legal obligation or defense of a right. |
5. Data transmitted to the carrier
In the standard flow we transmit to the carrier the name of each passenger, the booking person's phone number, the route, the date/time and the boarding/disembarking points. If a trip legitimately requires additional data, they are indicated in the form before collection.
The carrier uses the data to verify availability, accept/refuse the request, prepare the passenger list, operational contact, issue the transport document and provide the trip. The carrier is independently responsible for its own processing and must be contacted for rights relating to its own records.
For an offer from a carrier without a commercial contract with Autocare, before transmission an infobox is displayed that identifies the carrier, indicates its available contact details and lists the categories of data that will be transmitted to it. Pressing the "Send request" button represents the user's request to transmit these data to the named recipient for booking and transport steps. This processing is necessary for the user's request; it is not presented as an optional consent for marketing or other unrelated purposes.
6. To whom else we may disclose data
- MAIB, for the payment hosted at pay.autocare.md, transaction authentication and refund;
- hosting, database, storage, CDN, security and technical support providers;
- e-mail, SMS and notification providers; for mobile we use, depending on the platform, Firebase Cloud Messaging and Apple Push Notification service;
- Google Analytics, if you have allowed the analytics category; Google reCAPTCHA for protecting OTP requests; Google Maps when you open map-based functions;
- Sentry for server-side diagnostics of production errors;
- the communication infrastructure used for transmission to the carrier, including Telegram integration;
- professional advisers and authorities, when disclosure is necessary and lawful;
- a business successor, with respect for continuity of protection and the notice required by law.
We do not sell personal data. Analytics, advertising or communication tools not listed in this policy are not part of the active service set described by this version.
7. International transfers
Carriers may be established in the Republic of Moldova, Ukraine or European Union states. Some technical providers may process data in other countries. When data are transferred abroad, we use the basis and safeguards required by the applicable law, limit the data to the purpose and impose contractual obligations where these are necessary.
You may request information about the destination and the relevant safeguards at [email protected]. The foreign carrier remains responsible for the data it receives and uses for transport purposes.
8. How long we keep data
| Category | Retention rule |
|---|---|
| Bookings and identifiable passengers | In the normal flow, a maximum of 5 years from the travel date, unless a legal term or a justified dispute requires otherwise. |
| Valid request for deletion | Eligible data are deleted or anonymized without undue delay, within a maximum of one month. Data strictly necessary for a future trip or required by law are isolated and re-evaluated after the reason ceases. |
| Payments and financial-accounting documents | For the period required by tax, accounting, payment and dispute prevention/resolution legislation. |
| Complaints and proof of acceptance | As long as necessary for resolution and for the duration of the applicable limitation/rights-defense periods. |
| Price alerts | Until unsubscribing/deleting the alert or until the feature is no longer available. |
| Security logs and errors | For the minimum period justified by security, investigation and service stability; the period may vary depending on the log type. |
| Cookies and local storage | According to the Cookie Policy and the user's choices. |
| Backups | Until backup rotation/expiration; deleted data are not brought back into current use if technical restoration becomes necessary. |
9. Your rights
Under the conditions of the applicable law, you may request:
- confirmation of processing and access to data;
- rectification of inaccurate data or completion of data;
- deletion or anonymization of eligible data;
- restriction of processing;
- objection to processing based on legitimate interest;
- data portability, where applicable;
- withdrawal of consent, without affecting processing carried out before withdrawal;
- information about recipients and transfers;
- filing a complaint with the National Center for Personal Data Protection or seizing the competent court.
10. How to submit a data request
Write to [email protected] and describe the right requested. We may ask for information strictly necessary to verify identity and protect the account/passengers. We respond without undue delay and, normally, within a maximum of one month. If the law allows an extension for a complex request, we inform you within the initial term about the reason and the estimated duration.
If the request concerns data kept by the carrier in its systems, also contact the carrier using the details in the confirmation. Autocare may forward the request, but cannot delete in place of the independent controller the data that are exclusively under its control.
11. Minors
The account and the request are created by a person aged at least 18. The adult may provide the data of a minor passenger only if they have the right to do so and are responsible for its accuracy. We do not intentionally use the minor's data for newsletters or advertising profiling.
12. Automated decisions
The carrier, not an Autocare algorithm, decides whether to accept the request. The system may automatically update statuses, calculate the payment deadline and calculate/execute refunds according to configured rules. We do not use profiling to make decisions exclusively by automated means with a significant legal effect on the person. If such a function is introduced, we will inform the person and provide the safeguards required by law.
13. Security
We apply proportionate technical and organizational measures, including access control, authentication, logging, encryption of communications where available, data minimization, backups and incident monitoring. No transmission is without risk; please protect OTP codes, passwords and the device.
14. Changes to the policy
We publish the version and the effective date. Material changes are communicated by appropriate means and, if they are based on consent or affect the accepted terms, we request a new choice where the law requires it. The versions accepted for a booking must be kept as historical proof.
CONNECTBASE SRL · IDNO/tax code 1023600007753
[email protected] · +373 60 003 377



