Privacy Policy
FifaBus2026 / WC26 Fan Planner β fifabus2026.com
Effective: 1 January 2026 β’ Last updated: 6 April 2026
This Privacy Policy explains how FifaBus2026 LLC ("FifaBus2026", "we", "us") collects, uses, stores, and shares personal data when you use the WC26 Fan Planner at fifabus2026.com. It is written in plain language to comply with Articles 13 and 14 of the General Data Protection Regulation (GDPR) and the EU Digital Services Act (DSA).
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights described in Section 7 below.
1. Data Controller
The data controller responsible for your personal data is:
FifaBus2026 LLC
New Jersey, United States of America
Website: fifabus2026.com
Data Protection Officer (DPO): privacy@fifabus2026.com
For EEA users, FifaBus2026 acts as data controller under Article 4(7) GDPR. We process personal data in accordance with GDPR, the ePrivacy Directive, and applicable EU member state laws.
2. Data We Collect & Why
We collect only the data we need to provide our services. The table below shows what we collect, why, and the legal basis under GDPR Article 6.
| Data | Purpose | Legal Basis |
|---|---|---|
| Name, email address | Send booking confirmation and transactional emails | Art. 6(1)(b) β contract performance |
| Payment data (card number, billing details) | Process bus ticket payments via Stripe | Art. 6(1)(b) β contract performance |
| Journey details (route, date, passenger count) | Fulfil your bus booking | Art. 6(1)(b) β contract performance |
| Discount / promo codes | Apply fan discounts and referral rewards | Art. 6(1)(b) β contract performance |
| Referral code & usage | Track referral credits and issue rewards | Art. 6(1)(f) β legitimate interest |
| IP address, browser type, device info | Security, fraud prevention, server logs | Art. 6(1)(f) β legitimate interest |
| Cookie preferences (consent record) | Record your consent decision for auditing | Art. 6(1)(c) β legal obligation (ePrivacy) |
| Analytics data (page views, session length) β opt-in only | Improve site performance and user experience | Art. 6(1)(a) β consent |
| Marketing interaction data β opt-in only | Show relevant ads on external platforms | Art. 6(1)(a) β consent |
We never sell your personal data to third parties. Analytics and marketing cookies are only activated after you give explicit consent via our Cookie Banner.
3. Special Category Data
We do not intentionally collect or process special category data (Article 9 GDPR) such as health data, racial or ethnic origin, political opinions, religious beliefs, biometric data, or sexual orientation. If you believe we have inadvertently collected such data, please contact privacy@fifabus2026.com.
We do not profile users based on special category data for any purpose, including targeted advertising, in line with Article 9 GDPR and the DSA's prohibition on ads targeting minors using profiling.
4. Cookies & Tracking Technologies
We use cookies and similar technologies. Under the ePrivacy Directive (as implemented in EU member states) and GDPR, we obtain your consent before setting any non-essential cookies.
Essential cookies (always on)
Session management, security tokens, language preference. These are strictly necessary and do not require consent.
Analytics cookies (consent required)
Google Analytics 4 (GA4) β used to measure page views and user journeys. Only activated after your consent. IP addresses are anonymised. GA4 data is subject to Google's privacy policy.
Marketing cookies (consent required)
Google Ads and Meta Pixel β used to show personalised advertisements on other platforms. Only activated after your consent. No marketing cookies are used for minors.
You can change your cookie preferences at any time using the Cookie Preferences button in the footer or by clearing your browser cookies. Withdrawing consent does not affect the lawfulness of processing before withdrawal (Article 7(3) GDPR).
5. How We Share Personal Data
We share personal data only where necessary and with appropriate contractual protections:
Stripe, Inc.
β Payment processorContract performanceProcesses card payments. Subject to Stripe's privacy policy and PCI-DSS compliance. Data may be processed in the USA under Standard Contractual Clauses (SCCs).
Resend, Inc.
β Transactional email providerContract performanceSends booking confirmations and transactional emails. Data processed under a Data Processing Agreement (DPA).
Google LLC (Analytics / Ads)
β Analytics & advertisingConsent onlyOnly if you consent. Data transferred to USA under SCCs. You can opt out of Google Analytics at analytics.google.com/analytics/optout.
Meta Platforms Ireland Ltd
β AdvertisingConsent onlyOnly if you consent. Meta acts as a separate controller for ad targeting. Subject to Meta's privacy policy.
Replit, Inc.
β Cloud hosting providerLegitimate interestInfrastructure and server hosting. Data processed in the USA under a DPA.
We do not sell personal data. We do not share data with law enforcement unless legally compelled to do so, in which case we will attempt to notify you where permitted by law.
6. International Data Transfers
FifaBus2026 is based in the United States. When personal data is transferred from the EEA, UK, or Switzerland to the USA or other third countries, we rely on one or more of the following safeguards under Chapter V GDPR:
- Standard Contractual Clauses (SCCs) β approved by the European Commission under Decision 2021/914
- EUβUS Data Privacy Framework β where the recipient is certified
- Adequacy decisions β where the European Commission has recognised equivalent protection
You may request a copy of our SCCs or transfer impact assessments by contacting privacy@fifabus2026.com.
7. Your Data Protection Rights
If you are in the EEA, UK, or Switzerland, you have the following rights under GDPR (Articles 15β22). You can exercise any right by contacting privacy@fifabus2026.com. We will respond within 30 days (extendable to 90 days for complex requests).
- Right of Access (Art. 15): Request a copy of the personal data we hold about you.
- Right to Rectification (Art. 16): Ask us to correct inaccurate or incomplete data.
- Right to Erasure / 'Right to be Forgotten' (Art. 17): Request deletion of your personal data where there is no compelling reason to continue processing.
- Right to Restriction (Art. 18): Ask us to pause processing your data in certain circumstances.
- Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format (applies to consent-based or contract-based processing).
- Right to Object (Art. 21): Object to processing based on legitimate interests, including profiling. We will stop unless we demonstrate compelling legitimate grounds.
- Right to Withdraw Consent (Art. 7(3)): Withdraw any previously given consent at any time without affecting lawfulness of prior processing.
- Right not to be subject to automated decision-making (Art. 22): We do not make solely automated decisions with legal or similarly significant effects. Discount calculations are rule-based, not AI/ML profiling.
To exercise any of these rights, send an email to privacy@fifabus2026.com with the subject line "GDPR Data Subject Request" and describe the right you wish to exercise. We may need to verify your identity before acting.
8. Data Retention
We retain personal data only as long as necessary for the purpose it was collected or as required by law (Article 5(1)(e) GDPR β storage limitation).
| Data Type | Retention Period | Reason |
|---|---|---|
| Booking records (name, email, journey) | 7 years | Tax / accounting obligations |
| Payment records | 7 years | Legal / regulatory obligation |
| Server access logs (IP, timestamps) | 90 days | Security & fraud prevention |
| Cookie consent records | 3 years | Audit trail for consent compliance |
| Analytics data (aggregated) | 26 months (GA4 default) | Product improvement |
| Marketing data (if consented) | Until consent withdrawn | Consent-based processing |
| Referral records | 2 years after last activity | Reward fulfilment |
9. Children's Data
Our services are not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has provided us with personal data, please contact privacy@fifabus2026.com and we will delete it promptly. We do not show targeted advertising to minors in line with DSA Article 26(3) and GDPR Recital 38.
10. Security Measures
We implement appropriate technical and organisational measures (TOMs) as required by Article 32 GDPR to protect your personal data against accidental or unlawful destruction, loss, alteration, or unauthorised access:
- TLS 1.2+ encryption for all data in transit
- Encrypted storage of sensitive fields (payment data handled entirely by Stripe, never stored on our servers)
- HTTP security headers: Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, Referrer-Policy, Permissions-Policy
- Access controls β staff have least-privilege access to production systems
- Regular security scans and dependency auditing
- Incident response plan β we will notify affected users and relevant supervisory authorities within 72 hours of a data breach where required by Article 33 GDPR
11. Digital Services Act (DSA) β Your Rights
The EU Digital Services Act (Regulation 2022/2065) applies to our platform. As a user in the European Union, you have the following additional rights:
- Transparent advertising: We clearly label any advertising content and disclose the advertiser identity and targeting parameters used.
- No profiling-based ads for minors: We never show targeted ads to users we know to be under 18 (DSA Art. 26(3)).
- Recommender system transparency: If we use recommendation algorithms, we inform you of the main parameters and offer a non-profiled alternative view (DSA Art. 27).
- Illegal content reporting: You can report illegal content or behaviour by emailing dsa@fifabus2026.com with the subject "DSA Illegal Content Report". We act promptly under our Notice-and-Action policy.
- Complaints and appeals: If you disagree with a decision we made about your account or content, you may submit a complaint to dsa@fifabus2026.com. We will respond within 14 days.
FifaBus2026 is not a Very Large Online Platform (VLOP) as defined by DSA Article 33. Annual active user counts are reviewed quarterly and reported in our transparency reports if the 45-million-user threshold is reached.
12. Right to Lodge a Complaint
If you believe we have processed your personal data in violation of GDPR, you have the right to lodge a complaint with a supervisory authority (Article 77 GDPR). You may contact the supervisory authority in your EU member state of residence, place of work, or the location of the alleged infringement. Key supervisory authorities include:
- Germany: Bundesbeauftragter fΓΌr den Datenschutz und die Informationsfreiheit (BfDI)
- France: Commission Nationale de l'Informatique et des LibertΓ©s (CNIL)
- Spain: Agencia EspaΓ±ola de ProtecciΓ³n de Datos (AEPD)
- Ireland: Data Protection Commission (DPC)
- Netherlands: Autoriteit Persoonsgegevens (AP)
For online dispute resolution (including cross-border disputes), you may also use the EU ODR platform:
ec.europa.eu/consumers/odrWe always encourage you to contact us first at privacy@fifabus2026.com β we aim to resolve all concerns promptly and fairly.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will notify you of material changes by posting a notice on our homepage or, where feasible, by email at least 30 days before the change takes effect. The "Last updated" date at the top of this page always shows the most recent revision. Continued use of our services after an update constitutes acceptance of the revised policy, except where additional consent is required under GDPR.
14. Contact Us
For any privacy-related enquiries, data subject requests, or to exercise your rights, please use the relevant contact below:
Data Protection Officer (DPO)
privacy@fifabus2026.comGeneral Support
support@fifabus2026.comLegal / Contracts
legal@fifabus2026.comDSA β Illegal Content / Abuse
dsa@fifabus2026.comFifaBus2026 LLC β’ New Jersey, USA β’ fifabus2026.com
This Privacy Policy was last updated on 6 April 2026 and is effective from 1 January 2026.
Not affiliated with FIFA, any national football federation, or any host city authority.