GDPR NOTICE - Effective Date: May 7, 2025

This GDPR privacy notice (“Notice”)—is part of FareObuddy’s Privacy Policy and applies specifically to the processing of ‘personal data,’ as defined in the General Data Protection Regulation (“GDPR”), of individuals located in the European Economic Area (“EEA”) or the United Kingdom (“UK”) by FareObuddy LLC (referred to herein as “EEA Individuals,” “you,” or “your”). Any capitalized terms not defined in this Notice shall have the meanings ascribed to them in the Privacy Policy or, if not defined there, the GDPR. In case of any conflict between this Notice and other sections of our Privacy Policy, this Notice will govern for EEA Individuals and their personal data. If you are located outside of the EEA or UK, please refer to our general Privacy Policy

Controller Details

FareObuddy is the controller of personal data collected from EEA Individuals via its websites, customer service centers, and other related travel services (collectively, the “Services”).

Data Storage

FareObuddy stores EEA Individuals’ personal data on servers located in the United States.

Data Transfers

FareObuddy is self-certified under:

• The EU-U.S. Data Privacy Framework (EU-U.S. DPF),

• The UK Extension to the EU-U.S. DPF, and

• The Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF).

Should these frameworks become invalid as a data transfer mechanism, FareObuddy will rely on the European Commission’s Standard Contractual Clauses (SCCs) to safeguard international transfers of personal data to the United States.

Transfers to non-EEA/UK travel suppliers (e.g., airlines, hotels) for the purpose of booking and fulfilling your services may be based on derogations under GDPR Article 49(1)(b) and/or 49(1)(c), as necessary for performance of a contract or at your request.

Retention

We retain your personal data for as long as necessary, based on:

• Your transaction frequency, account activity, and loyalty rewards usage;

• The need to analyze historical travel trends to improve offerings;

• Your marketing subscription status and engagement;

• Requirements for fraud detection, security, and legal compliance;

• The resolution of disputes and customer support activities;

• Legal retention mandates and statutes of limitations;

• Potential legal claims or regulatory obligations.

Information Security

FareObuddy implements robust technical and organizational security measures. This includes compliance with PCI-DSS and adherence to industry standards like ISO 27001. Data such as your credit card information is encrypted using SSL.

We log IP addresses, browser details, timestamps, referrer URLs, and other diagnostic information to secure our platforms and detect cyber threats.

Government Access Requests

We may disclose your data to public authorities if legally required for national security, law enforcement, or other regulatory reasons.

Corporate Restructuring

In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the new entity, subject to our existing privacy commitments.

Your GDPR Rights

As an EEA Individual, you have the right to:

1. Access, correct, or delete your personal data;

2. Restrict or object to its processing;

3. Request data portability;

4. Withdraw consent (if processing is based on consent).

To exercise these rights, email: support@fareobuddy.com with the subject line “GDPR Notice.”

Objections to Legitimate Interest / Direct Marketing

You may object to processing based on FareObuddy’s legitimate interests. If so, FareObuddy will stop processing unless there are compelling legal reasons. You can also object to direct marketing anytime – either via unsubscribe links or by emailing support@fareobuddy.com

Please note that administrative communications (e.g., booking confirmations) are not subject to opt-out.

Right to Lodge a Complaint

You may file a complaint with your local data protection authority in the EEA or UK. A full list is available at:

https://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.htm

You may also assert your rights under any applicable Standard Contractual Clauses executed by FareObuddy.

Minors

Our Services are not directed at individuals under the age of 18. We do not knowingly collect data from minors.

Updates to This Notice

Should we use your data for purposes not previously disclosed, we will provide prior notice and update this Notice accordingly. The “Effective Date” will reflect the latest update.

Data Privacy Framework

FareObuddy complies with the DPF, as set by the U.S. Department of Commerce. We have certified adherence to the:

• EU-U.S. DPF Principles for EU personal data;

• UK Extension to the EU-U.S. DPF for UK personal data;

• Swiss-U.S. DPF Principles for Swiss personal data.

In case of conflicts, DPF Principles take precedence. Learn more and view our certification: https://www.dataprivacyframework.gov/

We are subject to oversight by the U.S. Federal Trade Commission.

DPF Complaints

For unresolved DPF complaints, we’ve committed to cooperate with the BBB National Programs Data Privacy Framework Services. File complaints at:

https://bbbprograms.org/programs/all-programs/dpf-consumers/ProcessForConsumers

Binding arbitration may also be available for certain unresolved issues.

Onward Transfers to Third Parties

FareObuddy may transfer personal data to service providers acting on our behalf (e.g., hosting, analytics, marketing). These vendors must provide equivalent privacy protections and notify us of any non-compliance.

We may also share data with affiliates to support services and business operations.

Opt-In/Opt-Out for Onward Transfers

You may opt-out of data sharing with third parties (not acting as agents) by emailing support@fareobuddy.com. We will not share sensitive personal data without opt-in consent.

Your DPF Rights

You may request access to, correction of, or deletion of your DPF-covered data by contacting support@fareobuddy.com. Please allow reasonable time for processing.

Retention under DPF

We retain DPF-related personal data only for as long as necessary to meet our business or legal needs, after which it may be anonymized or deleted.

Security of Your Data

We implement appropriate measures to prevent loss, misuse, or unauthorized access to DPF-related data.

Contact Us

If you have any questions or wish to exercise your GDPR rights, contact us at:

Email: support@fareobuddy.com (Subject: “GDPR Notice”)

Or write to us at:

FAREOBUDDY

371 Hoes Lane, Suite 200

Piscataway, New Jersey 08854

Note: Do not include sensitive data such as payment information in your emails.