Greekaway
  • explore
  • categories
  • Bookings
  • Wishlist
  • Profile
Greekaway

Move through Greece like a local.

Phone · +30 6985700007
Email · info@greekaway.com
Explore
  • All destinations
Company
  • About
  • Terms of Use
  • Privacy Policy
Connect
  • Instagram
  • facebook
  • tiktok
© 2026 Greekaway · Made in Athens
v2.0.1714
  • explore
  • categories
  • Bookings
  • Wishlist
  • Profile

Save to wishlist

Choose how you want to save this trip.

— Legal

Privacy Policy

Privacy Policy & GDPR

  • Effective date: 23 August 2026
  • Last updated: 23 August 2026
  • Version: 1.0

1. Introduction

This Privacy Policy explains how Greekaway collects, uses, stores and protects personal data when you visit our website, request or book a service, use PROFILE or MY BOOKINGS, communicate with us, or otherwise interact with Greekaway.

Greekaway processes personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation or “GDPR”), Greek Law 4624/2019 and, where applicable, Greek Law 3471/2006 concerning electronic communications.

This Policy is intended to provide information. It does not constitute consent to every form of processing described below. Where consent is required, for example for optional advertising technologies, marketing communications or certain special-category data, it will be requested separately through an appropriate affirmative action.

2. Who is responsible for your data

The data controller is:

  • Legal entity: AWAY SYSTEMS O.E.
  • Trading name: Greekaway
  • VAT number: 802723119
  • GEMI number: 181583603000
  • Registered office: 18 Mitropoliti Grigoriou Kydonion Street, Nea Smyrni, Athens 17123, Greece
  • Email: info@greekaway.com
  • Telephone and WhatsApp: +30 693 7184 551
  • Website: www.greekaway.com

AWAY SYSTEMS O.E. determines the purposes and means of processing personal data through Greekaway, except where another service provider acts as a separate data controller for its own processing activities.

3. Scope of this Policy

This Policy applies to personal data processed through:

  • the Greekaway website;
  • booking requests and confirmed bookings;
  • transfers, day tours and other travel or transport services offered by Greekaway;
  • PROFILE, MY BOOKINGS and passwordless access;
  • customer support and communications;
  • payment authorisations, captures, cancellations and refunds;
  • cookies, browser storage and similar technologies;
  • any future Greekaway feature that refers to this Policy.

Third-party websites, platforms and services are governed by their own privacy policies.

4. Data protection principles

We process personal data in accordance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality.

We seek to collect only the information reasonably required for the requested service, our legal obligations, security and the proper operation of Greekaway.

We do not sell, rent or trade our customers’ personal data.

5. Personal data we may collect

Depending on how you interact with Greekaway, we may process the following categories of data.

5.1 Identity and contact information

  • full name;
  • email address;
  • telephone or mobile number;
  • country or preferred language, where provided;
  • billing or invoicing information, where requested;
  • company name and tax information, where an invoice is required.

5.2 Booking and travel information

  • type of service requested;
  • pickup and drop-off locations;
  • addresses, place names and geographical coordinates;
  • intermediate stops and requested itinerary;
  • date and time of service;
  • number of passengers;
  • luggage and vehicle requirements;
  • flight, ferry, train or other arrival information, where relevant;
  • accommodation or meeting-point information;
  • selected tour, transfer, vehicle or service options;
  • price, currency and booking status;
  • requests concerning accessibility or special assistance;
  • comments, instructions and other information you choose to provide.

Please avoid including unnecessary confidential or medical information in free-text fields.

5.3 Payment and transaction information

We may process:

  • selected payment method;
  • transaction amount and currency;
  • payment authorisation, capture, cancellation or refund status;
  • payment and booking identifiers;
  • limited card information made available by Stripe, such as card type, card brand and the last four digits;
  • information required for accounting, invoicing, fraud prevention and dispute handling.

Greekaway does not receive or store the complete card number, card security code or full card credentials.

Where cash payment is available, we may record that cash was selected and whether payment was completed. Cash payments do not involve a Stripe card refund.

5.4 PROFILE and MY BOOKINGS information

Greekaway provides passwordless access through a secure magic link sent to the email address associated with a booking.

We may process:

  • the email address used to request access;
  • secure access tokens and session information;
  • login and access timestamps;
  • profile information;
  • booking history;
  • saved or wishlisted services;
  • initials used for the profile avatar;
  • security and authentication logs.

Where profile information is incomplete, Greekaway may use the name and telephone number already provided in existing bookings associated with the same verified email address to complete the customer profile.

Magic links are short-lived and may be used only for their intended purpose. You should not forward or share them with another person.

5.5 Communications

We may retain information contained in:

  • emails;
  • telephone or support requests;
  • WhatsApp communications;
  • booking-related messages;
  • complaints, feedback and refund requests;
  • communications with an assigned driver or service provider.

Telephone conversations are not recorded unless you are informed in advance and a lawful basis exists.

5.6 Technical and security information

When you use the website, our systems and infrastructure providers may process:

  • IP address;
  • browser type and version;
  • device type and operating system;
  • language and display settings;
  • referring page;
  • requested pages and timestamps;
  • session and security identifiers;
  • server, application and error logs;
  • approximate location derived from an IP address;
  • information used to detect abuse, fraud or unauthorised access.

5.7 Preferences and browser storage

The website may store information such as:

  • wishlist selections;
  • recent searches;
  • theme preference;
  • dismissed notices;
  • cookie choices and consent records;
  • secure session information.

Some of this information may remain only on your device, while other information may be synchronised with a verified Greekaway profile.

Further details are available in our Cookie Policy.

5.8 Analytics and advertising information

Where optional analytics or advertising tools are activated and you have provided valid consent, we may process information such as:

  • pages, destinations and tours viewed;
  • searches and interactions with the website;
  • booking initiation and completion events;
  • campaign and referral information;
  • cookie or advertising identifiers;
  • browser, device and approximate location information;
  • advertising attribution and conversion data.

Where supported by the selected advertising service and permitted by your consent, contact information such as an email address or telephone number may be transmitted in a securely hashed form for conversion measurement or audience matching.

We do not use payment-card information, private booking notes or special-category data for advertising.

6. How we obtain personal data

We may obtain personal data:

  • directly from you when you search, submit a booking, contact us or use a Greekaway feature;
  • from the person making a booking on behalf of other passengers;
  • from previous bookings associated with your verified email address;
  • from an assigned driver or transport provider concerning the status and performance of a service;
  • from Stripe concerning the status of a payment;
  • through Google Maps when you select locations or routes;
  • automatically from browsers, devices, servers and security systems;
  • from advertising or analytics platforms, only where the relevant technology is active and valid consent has been provided;
  • from public authorities or professional advisers where permitted or required by law.

7. Purposes and legal bases of processing

We process personal data only where a lawful basis applies.

7.1 Steps before entering into a contract and performance of a contract

Under Article 6(1)(b) GDPR, we process data to:

  • calculate and display services and prices;
  • receive and assess booking requests;
  • search for and assign an available driver or service provider;
  • confirm and perform a booking;
  • arrange pickup, transportation, tours and related services;
  • communicate booking instructions and updates;
  • provide PROFILE and MY BOOKINGS access;
  • process payments, cancellations and refunds;
  • provide customer support;
  • handle requested booking changes.

7.2 Compliance with legal obligations

Under Article 6(1)(c) GDPR, we process data where necessary to:

  • comply with tax, accounting and invoicing requirements;
  • respond to lawful requests from courts, tax authorities, supervisory authorities or law-enforcement bodies;
  • maintain legally required transaction and business records;
  • comply with consumer protection, transport and other applicable legislation;
  • manage personal-data breaches and regulatory obligations.

7.3 Legitimate interests

Under Article 6(1)(f) GDPR, we may process data where necessary for legitimate interests such as:

  • protecting customers, drivers, Greekaway and its systems;
  • preventing fraud, abuse and unauthorised access;
  • maintaining technical logs and service availability;
  • investigating errors, complaints and disputed transactions;
  • managing and improving our operations and customer service;
  • establishing, exercising or defending legal claims;
  • producing aggregated or anonymised business statistics.

Before relying on legitimate interests, we consider whether the processing is necessary and whether your rights and interests override those interests.

7.4 Consent

Under Article 6(1)(a) GDPR, we rely on consent for activities such as:

  • optional analytics and advertising technologies;
  • personalised advertising and campaign attribution;
  • non-essential cookies and similar technologies;
  • marketing communications where consent is required;
  • processing special-category information where explicit consent is required.

You may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

7.5 Vital interests

In a genuine emergency, information may be processed where necessary to protect the vital interests of a passenger or another person, in accordance with Article 6(1)(d) GDPR and, where special-category data are involved, the applicable provisions of Article 9 GDPR.

8. Information required to provide a service

Certain information, including valid contact details, pickup and destination information, service date and time, passenger requirements and payment information where applicable, is necessary to assess and perform a booking.

If required information is not supplied or is materially inaccurate, Greekaway may be unable to provide, confirm or properly perform the requested service.

Optional notes, marketing consent and non-essential cookie consent are not conditions for making a standard booking.

9. Bookings made for other passengers

If you make a booking for another person or a group, you confirm that:

  • you are authorised to provide the necessary information;
  • the information is accurate;
  • the passengers have been informed that Greekaway will process their data in accordance with this Policy;
  • you will not provide unnecessary or excessively sensitive information about them.

The person making the booking is responsible for communicating relevant booking information and applicable terms to the other passengers.

10. Drivers and transport providers

Greekaway may perform a service using a vehicle operated by AWAY SYSTEMS O.E. or assign it to a suitably authorised independent driver or transport provider.

To perform the service, we may share only the information reasonably necessary, such as:

  • passenger name;
  • telephone number;
  • pickup and drop-off details;
  • service date and time;
  • number of passengers;
  • luggage or vehicle requirements;
  • flight or arrival details;
  • necessary accessibility or assistance instructions.

The assigned driver or provider must use this information for performing the service, communicating with the passenger and complying with applicable legal obligations.

A driver or transport provider may act as a separate controller for processing required by their own legal, tax, insurance or transport obligations. Their independent processing is subject to their own legal responsibilities.

11. Payment processing

Online card payments are processed through Stripe. Depending on the booking flow, Stripe may:

  • request an authorisation on the selected card;
  • hold the authorised amount;
  • capture the payment after the booking is confirmed;
  • cancel or release the authorisation if the booking cannot be confirmed;
  • process a full or partial refund after capture.

Stripe processes transaction, device, authentication and fraud-prevention information in accordance with its own legal obligations and privacy practices.

For further information, see the Stripe Privacy Policy.

12. Passwordless access and account security

Greekaway does not require a traditional password for PROFILE and MY BOOKINGS. Access is provided through a secure magic link sent to the verified booking email address.

The link is currently valid for a limited period and is designed for one authorised recipient. A secure session may remain active until it expires or you sign out.

We process authentication and security information to:

  • verify access to the correct customer records;
  • prevent unauthorised access;
  • investigate suspicious access attempts;
  • maintain the security of booking and profile information.

If you believe that another person has accessed your email account or Greekaway session, contact us immediately.

13. Maps, routes and location information

Greekaway uses Google Maps Platform services to display maps, identify addresses, calculate routes and assist with pickup and destination selection.

Location information entered or selected by you, including addresses, place names and coordinates, may be transmitted to Google for these purposes.

Greekaway does not use the public website to continuously track your movements. Precise device location will be accessed only if an available feature requests it and you actively grant permission through your browser or device. Such permission can be withdrawn through your device or browser settings.

Use of Google Maps is subject to the Google Privacy Policy and the applicable Google Maps terms.

14. Accessibility and special-category data

Information concerning accessibility, disability, health or other assistance requirements may constitute special-category personal data under Article 9 GDPR.

Please provide only information genuinely necessary for the safe and appropriate performance of the requested service.

Where such information is required, Greekaway will process it:

  • with your explicit consent;
  • to arrange the assistance you requested;
  • to communicate necessary instructions to the assigned driver or provider;
  • where necessary to protect vital interests in a genuine emergency;
  • where otherwise permitted by applicable law.

We do not use accessibility or health-related information for advertising or unrelated profiling.

15. Cookies, analytics and advertising

Greekaway uses cookies, local storage, session storage and similar technologies.

Strictly necessary technologies may be used without consent where they are required for security, booking functionality, session management or remembering privacy choices.

Optional analytics and advertising technologies are used only after valid consent, where required. Depending on the tools subsequently activated, these may include services provided by Google, Meta Platforms or TikTok for:

  • website and campaign measurement;
  • conversion attribution;
  • advertising performance;
  • audience creation;
  • personalised or retargeted advertising.

Rejecting optional technologies will not prevent access to the essential booking functions of Greekaway, although some optional features may be unavailable.

You can change or withdraw your choices through Cookie Settings, available in the website footer and on the Legal page. Full details are provided in our Cookie Policy.

16. Marketing communications

Booking confirmations, payment updates, security messages and service communications are transactional communications and may be sent where necessary to perform a booking or comply with legal obligations.

Promotional emails, messages or similar direct marketing will be sent only where a lawful basis exists and, where required, after your consent.

You may unsubscribe from promotional communications at any time by:

  • using the unsubscribe option contained in the message;
  • contacting info@greekaway.com.

Unsubscribing from marketing does not prevent Greekaway from sending necessary booking, payment, security or legal communications.

Cookie consent and consent to direct marketing are separate choices.

If you choose to communicate through WhatsApp, WhatsApp and Meta may independently process your telephone number, device information and communication metadata under their own privacy policies. You may use email instead if you do not wish to communicate through WhatsApp.

17. Recipients and service providers

Personal data may be disclosed, where necessary, to the following categories of recipients:

  • assigned drivers and authorised transport or tour providers;
  • Stripe for payment processing, authentication and fraud prevention;
  • Google Maps Platform for maps, addresses and routes;
  • Vercel for frontend hosting, website delivery and related infrastructure;
  • Render for backend hosting, databases and operational systems;
  • Cloudflare R2 for storage of files and service-related materials where applicable;
  • email and transactional communication providers;
  • technical support, security and software service providers;
  • analytics or advertising providers, only if activated and valid consent has been provided;
  • accountants, legal advisers, insurers and other professional advisers;
  • competent courts, regulatory, tax, law-enforcement or public authorities where legally required.

Service providers acting on our behalf receive only the information required for their assigned purpose and are subject to contractual, confidentiality and data-protection obligations where required by law.

18. Independent processing by third parties

Certain providers, including Stripe, Google, WhatsApp, advertising platforms and independent transport providers, may act as separate data controllers for some of their activities.

Their processing may include compliance with their own legal obligations, fraud prevention, platform security, payment-network requirements, transport records or the operation of their services.

Where a third party acts as an independent controller, its own privacy policy also applies. Greekaway does not control processing performed independently by that provider.

19. International data transfers

Some service providers may process personal data outside Greece or the European Economic Area.

Where personal data are transferred to a country outside the EEA, we rely on an appropriate transfer mechanism where required, such as:

  • an adequacy decision adopted by the European Commission;
  • the EU–US Data Privacy Framework, where applicable to a certified recipient;
  • Standard Contractual Clauses approved by the European Commission;
  • supplementary technical and organisational safeguards;
  • another lawful mechanism available under the GDPR.

You may contact us for information concerning the safeguards applicable to a particular transfer.

20. Data retention

We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including contractual, tax, accounting, security and legal-claim requirements.

Our general retention criteria are:

  • incomplete, expired or unconfirmed booking requests are normally retained for up to 12 months after the last relevant activity;
  • confirmed, completed, cancelled or refunded booking records are retained for the period required to provide support and comply with applicable tax, accounting and legal obligations;
  • invoices, transaction records and legally required financial information are retained for the period prescribed by Greek law and longer only where required by an audit, dispute or legal claim;
  • customer-support communications are normally retained for up to 24 months after the matter is closed, unless they form part of a booking record or legal dispute;
  • profile information is retained while the profile remains in use or until deletion is requested, subject to records that must be preserved independently for legal reasons;
  • magic links and authentication tokens are retained only until they expire, are used or are invalidated;
  • technical and security logs are normally retained for up to 12 months, unless a longer period is necessary to investigate an incident, fraud or legal claim;
  • marketing data are retained until consent is withdrawn or the information is no longer required for the stated marketing purpose;
  • consent and objection records may be retained for as long as necessary to demonstrate compliance;
  • information stored on your device remains according to the periods described in the Cookie Policy or until you delete it.

When information is no longer required, it is deleted, anonymised or placed beyond normal use pending secure deletion from backup cycles. Properly anonymised statistical information may be retained without identifying an individual.

21. Data security

Greekaway applies appropriate technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, accidental loss or unlawful destruction.

These measures may include:

  • encrypted network communications;
  • secure payment processing through Stripe;
  • passwordless and time-limited access mechanisms;
  • access controls and restricted administrative permissions;
  • system, security and error logging;
  • backups and recovery procedures;
  • confidentiality obligations;
  • data minimisation and limited disclosure to drivers and providers;
  • logical separation of Greekaway customer data from unrelated services operated within the wider technical environment;
  • procedures for responding to suspected security incidents.

No internet service can guarantee absolute security. If a personal-data breach occurs, Greekaway will assess it and notify the Hellenic Data Protection Authority and affected individuals where required by the GDPR.

22. Automated processing and profiling

Greekaway does not make decisions producing legal or similarly significant effects concerning customers solely through automated processing.

Stripe and other payment providers may use automated systems to detect fraud, authenticate transactions or assess payment risk.

Where optional advertising technologies are enabled with consent, advertising providers may create audiences or profiles based on website interactions. Such advertising processing is not used by Greekaway to make decisions producing legal or similarly significant effects concerning you.

You may withdraw advertising consent through Cookie Settings.

23. Children

Greekaway services are not intended to be booked independently by persons under 18 years of age.

An adult may make a booking that includes children and provide the limited information necessary for their transportation, safety or participation in a service.

We do not knowingly create advertising profiles directed at children or request unnecessary information about them. If we learn that a minor has submitted personal data without appropriate authority, we may suspend the relevant request and take reasonable steps to delete the information.

24. Your rights

Subject to the conditions and limitations of the GDPR, you may have the right to:

  • receive clear information about the processing of your data;
  • obtain confirmation that we process your data and receive a copy;
  • correct inaccurate or incomplete information;
  • request deletion of your data;
  • request restriction of processing;
  • receive data you provided in a structured, commonly used and machine-readable format;
  • request direct transfer of eligible data to another controller where technically feasible;
  • object to processing based on legitimate interests;
  • object at any time to direct marketing;
  • withdraw consent at any time;
  • request human intervention where a decision is based solely on automated processing and significantly affects you;
  • lodge a complaint with a competent supervisory authority.

These rights are not absolute. For example, certain data may need to be retained for tax obligations, payment disputes, fraud prevention, the protection of other persons or the establishment and defence of legal claims.

25. Exercising your rights

To exercise a data-protection right, contact:

  • Email: info@greekaway.com
  • Postal address: AWAY SYSTEMS O.E., 18 Mitropoliti Grigoriou Kydonion Street, Nea Smyrni, Athens 17123, Greece

Please describe your request clearly and identify the booking or email address concerned.

We may request information reasonably necessary to verify your identity and prevent disclosure of data to an unauthorised person. We will not request more verification information than necessary.

Requests are normally handled without charge and within one month. Where a request is particularly complex or numerous requests are received, this period may be extended by up to two additional months. We will inform you of any extension and the reasons for it.

Manifestly unfounded or excessive requests may be refused or subject to a reasonable fee where permitted by law.

26. Complaints

You have the right to lodge a complaint with the Hellenic Data Protection Authority.

Hellenic Data Protection Authority

1–3 Kifisias Avenue 115 23 Athens Greece

  • Telephone: +30 210 6475600
  • Email: contact@dpa.gr
  • Website: www.dpa.gr
  • Complaints: submitted through the Authority’s website, www.dpa.gr

For complaints concerning the exercise of GDPR rights, the Authority will generally expect you first to have submitted the relevant request to Greekaway and allowed the applicable response period to expire.

You may also seek judicial remedies where available under applicable law.

27. Third-party links, changes and contact

The website may contain links to social networks, mapping services or other third-party websites. Following such a link may allow the third party to process data under its own privacy policy. Greekaway is not responsible for the independent privacy practices of third-party websites.

We may update this Policy where our services, providers, technology or legal obligations change. The effective date, last-updated date and version number will be amended accordingly.

Material changes will be communicated in an appropriate and visible manner. Where a new purpose requires consent, the relevant processing will not begin until valid consent has been obtained.

For any question concerning this Policy or the processing of personal data by Greekaway, contact:

AWAY SYSTEMS O.E. — Greekaway

  • Email: info@greekaway.com
  • Telephone and WhatsApp: +30 693 7184 551
  • Address: 18 Mitropoliti Grigoriou Kydonion Street, Nea Smyrni, Athens 17123, Greece