Skip to content

Legal

Privacy Policy

Last updated: 10 September 2026

This policy explains how Makis ehf. (“Makis”, “we”, “us”) collects and uses your personal data when you use makis.is to book a private transfer or day tour, and the rights you have under the EU General Data Protection Regulation (GDPR) as applied in Iceland. We only collect what we need to arrange your trip — we do not sell your data or use it for advertising.

1. Who we are (data controller)

The controller responsible for your personal data is Makis ehf. (kennitala 571115-1740), a private transfer and tour operator based in Reykjavík, Iceland, registered with Samgöngustofa (the Icelandic Transport Authority).

For any privacy question or to exercise your rights, contact us at booking@makis.is.

2. The data we collect

We collect only what is needed to take and fulfil your booking:

Information you give us

  • Your name, email address and phone number.
  • Your preferred language.
  • Booking details: pickup and drop-off locations, date and time, flight number (for airport pickups), number of passengers and bags, and any notes or special requests you add (for example child-seat requests).
  • Any review or rating you choose to submit after a trip.
  • Anything else you include when you contact us by email, phone or WhatsApp.

Payment information

Card payments are processed by our payment provider, Teya. We never see or store your full card number, expiry date or security code — those go directly to Teya. We store only a payment reference and, where you choose to save a card to secure a reservation, a secure token that lets us charge the agreed amount later (for example a no-show fee). We cannot use that token for anything other than the booking it relates to.

Information collected automatically

  • Basic technical data from your device and browser (such as IP address and standard server-log information) needed to serve the site securely and prevent abuse.
  • Strictly necessary cookies — see section 8.

3. How and why we use your data (and our legal basis)

Under the GDPR we rely on the following legal bases:

  • To provide the service you booked — arranging your transfer or tour, contacting you about it, and, for airport pickups, tracking your flight so we can adjust the pickup time if it is delayed. Legal basis: performance of our contract with you.
  • To take payment and process refunds through Teya. Legal basis: performance of our contract with you.
  • To send booking confirmations, reminders and service messages by email (and, if you give a number, by phone, WhatsApp or SMS about your specific trip). Legal basis: performance of our contract with you.
  • To keep accounting, tax and audit records, including the immutable log of changes to each booking that we are required to keep as an operator registered with Samgöngustofa. Legal basis: compliance with a legal obligation.
  • To publish a review you submit, and to keep our service secure and prevent fraud. Legal basis: your consent (for publishing a review, which you can withdraw) and our legitimate interests (security and fraud prevention).

We do not use your data for advertising, and we do not build marketing profiles or sell your data to anyone.

4. Who we share your data with

We share your data only with the service providers that help us run the booking service, each acting on our instructions under a data-processing agreement, and only with the data they need:

  • Teya — card payment processing and refunds.
  • Resend and ImprovMX — sending and forwarding our booking emails.
  • AeroDataBox — flight-status lookups for airport pickups.
  • Google — address autocomplete when you type a pickup or drop-off address.
  • Vercel and our database hosting provider — hosting the website and storing booking records.

Your driver (the Makis owner-driver) sees the details needed to carry out your trip. We may also disclose data where the law requires it, or to establish or defend legal claims. Some of these providers may process data outside Iceland and the European Economic Area; where that happens it is covered by appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

5. How long we keep your data

  • Booking and payment records (including the booking audit log) — kept for 7 years, because Icelandic bookkeeping law and our audit obligations as a registered transport operator require it.
  • Enquiries and abandoned or unpaid bookings that never become a trip — deleted or anonymised once they are clearly no longer needed.
  • Published reviews — kept while displayed, and removed when you ask us to take a review down.

When a retention period ends, we securely delete or anonymise the data so it can no longer identify you.

6. Your rights

Under the GDPR you have the right to:

  • ask for a copy of the personal data we hold about you (access);
  • have inaccurate data corrected (rectification);
  • ask us to delete your data (erasure) — we will do so, except where we must keep certain records to meet the legal obligations described in section 5;
  • ask us to restrict or object to how we use your data;
  • receive your data in a portable format;
  • withdraw any consent you have given, at any time.

To exercise any of these, email booking@makis.is. We will respond within one month. There is no charge, and we may ask you to confirm your identity first so we do not disclose data to the wrong person.

If you are unhappy with how we handle your data, you can complain to the Icelandic Data Protection Authority, Persónuvernd (personuvernd.is).

7. How we protect your data

The website is served over an encrypted (HTTPS) connection. Card details never reach our own systems — they are handled directly by Teya, and we store no card numbers. Access to booking data is limited to the operator, and every change to a booking’s status is written to an immutable audit log. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your data.

8. Cookies

We use only strictly necessary cookies — for example to keep your booking session working and to keep the operator signed in to the dashboard. We do not use advertising cookies or third-party tracking. Because these cookies are essential to the service, they do not require a consent banner; you can still block cookies in your browser, though parts of the booking flow may then stop working.

9. Changes to this policy & contact

We may update this policy from time to time; the “last updated” date above shows when it last changed. For any question about this policy or your data, contact Makis ehf. at booking@makis.is.

Privacy Policy | Makis