Privacy policy
Last updated: July 30, 2026
Table of Contents
I. Preamble — Scope of this Privacy Policy
II. Data Controller
III. Data Subjects
IV. Categories of Personal Data Processed
V. Collection of Personal Data
VI. Purposes of Processing, Legal Bases, and Retention Periods
VII. Recipients of Your Personal Data
VIII. Transfers Outside the European Union
IX. Your Rights
X. How to Exercise Your Rights — DPO Contact
XI. Security of Personal Data
I. Preamble - Scope of this Privacy Policy
In the course of its activities, Tootbus (hereinafter the “Company” or “We”) processes personal data concerning you (hereinafter “Personal Data”). This privacy policy (hereinafter the “Policy”) specifies the conditions under which we collect and process your Personal Data, acting as the data controller, and informs you of your rights and how to exercise them.
The Policy applies to customers and users of the Company’s services, as well as to visitors of its website and mobile applications, and more generally to any person concerned by the processing of Personal Data carried out in the context of the Company’s activities (hereinafter “You”).
We process your Personal Data in compliance with the applicable legislation and regulations on personal data protection, in particular Regulation (EU) No. 2016/679 of April 27, 2016 (hereinafter the “GDPR”) and the amended French Data Protection Act No. 78-17 of January 6, 1978 (hereinafter together the “Regulations”).
This Policy does not constitute a contract and does not create any contractual obligation. The Policy may be modified at any time, in particular to take into account legal, regulatory, or operational developments.
II. Data Controller
Your Personal Data is processed by RATP Développement, a public limited company (société anonyme) with a capital of 517,301,072.70 euros, registered in the Paris Trade and Companies Register under number RCS 389 795 006, whose registered office is located at 9 Rue Brahms, 75012 Paris, France.
III. Data Subjects
The Policy applies to the following categories of persons:
- Customers, their beneficiaries, and users of the services;
- Prospects;
- Visitors and users of the website, mobile applications, and other digital services offered by the Company;
- Persons contacting the Company’s internal departments;
- Job applicants;
- And, more generally, any person concerned by the processing of Personal Data carried out in the context of the Company’s activities as described in this Policy.
IV. Categories of Personal Data Processed
In accordance with the Regulations, “Personal Data” means any information relating to an identified or identifiable natural person. In the course of its activities, the Company may collect and process the following categories of Personal Data:
- Identification data (e.g., last name, first name, date of birth, customer number);
- Contact data (e.g., email address);
- Service usage data (e.g., ticket type, validation data, pass number, usage history);
- Payment data (e.g., payment method, order amount, credit card number and expiry date, payment incident);
- Navigation and connection data (e.g., IP address, connection logs, cookies, and trackers);
- Location data (e.g., geolocation of the person or device associated with a person);
- Images and sound recordings (e.g., via video surveillance systems).
During collection, you are informed of the mandatory or optional nature of the requested Personal Data. If you refuse to provide mandatory Personal Data, we will not be able to provide the requested services (such as processing your order on the website or registering for an on-demand transport service). We commit to collecting and processing only Personal Data that is relevant and necessary for the intended purpose.
V. Collection of Personal Data
Your Personal Data is collected:
- Directly from you, for example, when purchasing a service, using the application, visiting the website, or interacting with our Company;
- Indirectly, from legitimate sources, such as partners, authorized third parties, or publicly available sources.
When your Personal Data is not collected directly from you, you are informed of its origin in accordance with GDPR requirements.
VI. Purposes of Processing, Legal Bases, and Retention Periods
Your Personal Data is collected and processed for specific, explicit, and legitimate purposes, as detailed in the table below, based on the following legal bases:
- Performance of a contract or pre-contractual measures;
- Compliance with our legal obligations;
- Our legitimate interest, provided it prevails over your interests or fundamental rights and freedoms;
- Your consent.
In accordance with the Regulations, your Personal Data is stored in active databases for the duration necessary to achieve the purposes for which it was collected, as specified in the table below. At the end of this period, it may be archived for the duration of the applicable legal statute of limitations if it has administrative interest (e.g., litigation management) or to satisfy a legal obligation. At the end of these periods, your Personal Data is deleted or anonymized.
Customer Relations, Tickets, and Services:
| Purposes | Legal Bases | Retention Period |
| Contract management: orders, service execution, subscriptions, ticket issuance, registrations, and mobility service bookings. | Performance of a contract or pre-contractual measures | Duration of the contractual relationship, then archived for the applicable statute of limitations (5 years in case of litigation). |
| Customer complaints and after-sales service. | Performance of a contract or pre-contractual measures | Duration of the contractual relationship, then archived for a maximum of 5 years from the closure of the complaint. |
| Customer relationship monitoring: satisfaction surveys. | Legitimate interest or consent | Duration necessary to complete the survey or until opposition or withdrawal of consent. |
| Bank transactions: payment for services (including open payment, online payment), transaction evidence, and refunds. | Performance of a contract or pre-contractual measures | Duration of the transaction (single payment) or until the last payment installment. Credit card data is archived for 13 months from the debit date (15 months for deferred debit cards) for dispute purposes. CVV is deleted immediately after payment. |
| Lost & Found management: handling requests, contacting owners, returning items. | Legitimate interest or consent | 1 month after loss declaration or owner identification, or immediately upon consent withdrawal. If owner is identified, until restitution + legal statute of limitations (5 years). |
Communication and Commercial Prospecting:
| Purposes | Legal Bases | Retention Period |
| Commercial prospecting via electronic means (email): ads, promotions, newsletters, contests, etc. | Consent of the customer/prospect, or legitimate interest for similar goods/services purchased by the customer | 3 years from the end of the commercial relationship or last contact from the customer/prospect, or until consent withdrawal. Up to 24 months after contest completion and prize distribution. |
| Inquiries via online contact forms or email (excluding complaints/after-sales). | Legitimate interest | 3 years after the last contact. |
| Social media interactions: responding to inquiries. | Legitimate interest | In accordance with the social network’s policy. |
Statistics, Surveys, and Service Improvement:
| Purposes | Legal Bases | Retention Period |
| Analyses and statistical studies of service usage. | Legitimate interest | Anonymization process immediately after the survey ends. |
Fight Against Fraud:
| Purposes | Legal Bases | Retention Period |
| Detection and management of ticket and system fraud: counterfeiting, technological fraud, abnormal application behavior, access control to accounts, website, and apps. | Legitimate interest | Applicable legal statute of limitations or during the dispute until all remedies are exhausted. Validation data for tech fraud detection is kept for a maximum of 48 hours. |
Security of Persons and Property:
| Purposes | Legal Bases | Retention Period |
| Security alerts and accidents management: incident monitoring, victim assistance, insurance and compensation files. | Legitimate interest | Duration of incident processing + 3 years, and where applicable, during the insurance file processing + 5 years. |
Offenses and Litigation Management:
| Purposes | Legal Bases | Retention Period |
| Judicial and administrative procedures management. | Legitimate interest | Kept for the duration of the litigation until all remedies are exhausted. |
Compliance with Legal and Regulatory Obligations:
| Purposes | Legal Bases | Retention Period |
| Rights requests management. | Legal obligation | 5 years from the closure of the request. |
| Accounting and tax obligations. | Legal obligation | Archived for the legal retention period (10 years for accounting). |
| Mediation requests via the RATP Ombudsperson online form. | Legal obligation | 3 years from the referral to the RATP Ombudsperson. |
| Responding to authorized third-party legal requests (judicial requisitions, court orders). | Legal obligation | Applicable statute of limitations as evidence. |
Website and Mobile App Management:
| Purposes | Legal Bases | Retention Period |
| Ensuring technical website/app functionality, audience measurement. | Legitimate interest | See our cookie policy. |
Geolocation:
| Purposes | Legal Bases | Retention Period |
| Geolocation (when service is activated). | Legitimate interest or performance of contract | Until the end of the contract or service subscription. |
Recruitment:
| Purposes | Legal Bases | Retention Period |
| Managing applications: screening, organizing interviews. | Performance of a contract or pre-contractual measures | Recruitment process duration + 5 years from when the position is filled, for evidence purposes. |
| CV database creation. | Legitimate interest or consent | Up to 2 years from the last contact with the applicant, or until opposition/withdrawal of consent. |
VII. Recipients of Your Personal Data
Your Personal Data may be transmitted to:
- Authorized internal departments of the Company (customer service, marketing, security personnel);
- RATP Développement and its subsidiaries;
- Processors and subcontractors (IT, hosting, payment service providers, communication agencies);
- Competent administrative or judicial authorities.
VIII. Transfers Outside the European Union
We host your data within the European Economic Area (EEA). If transferred outside the EEA, we ensure standard contractual clauses or equivalent legal mechanisms are in place to guarantee an adequate level of protection.
IX. Your Rights
In accordance with the Regulations, you have the following rights:
- Access: Get a copy of your Personal Data.
- Rectification: Correct inaccurate/incomplete data.
- Erasure (Right to be forgotten): Delete data, except where legal or contractual obligations require storage.
- Restriction of processing: Temporarily freeze data processing.
- Objection: Object to processing based on legitimate interest (does not apply to CCTV).
- Portability: Receive your data in a structured, electronic format.
- Consent withdrawal: Withdraw consent at any time.
- Post-mortem instructions: Define directives for after your death.
X. How to Exercise Your Rights - DPO Contact
Contact our Data Protection Officer (DPO):
- By mail: Tootbus – Filiale de RATP Développement, Délégué à la protection des données, 9 rue Brahms, 75012 Paris, France.
- By email: [email protected]
A copy of your ID may be requested in case of reasonable doubt. We will reply within 1 month (extendable by 2 months for complex requests). You can file a complaint with the CNIL (https://www.cnil.fr).
XI. Security of Personal Data
We implement appropriate technical and organizational measures (encryption, pseudonymization) to protect your data. Subcontractors are bound by contract to enforce appropriate security. The website may contain links to third-party sites which operate under their own policies. In case of a high-risk data breach, you will be notified in accordance with the Regulations.