Reykjavik Express
ReykjavikExpress

Privacy Policy

Last updated: 27 June 2026

Who We Are (Data Controller)

Reykjavik Express is a private airport-transfer brand operated by Guðmundur Tyrfingsson ehf. ("GTS", "we", "us", "our"), a transport operator registered in Iceland at Fossnes C, 800 Selfoss. GTS is the data controller responsible for the personal data described in this policy. You can reach us about any privacy matter by email at info@reykjavikexpress.is or by phone at +354 894 2115.

About This Policy

This Privacy Policy explains what personal data we collect when you visit our website or book a transfer, how and why we use it, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR) as implemented in Iceland by the Act on Data Protection and the Processing of Personal Data (No. 90/2018). It applies to our website and to the door-to-door airport-transfer services we provide between Keflavík Airport (KEF) and the Reykjavík capital area (and the Blue Lagoon). It does not cover third-party websites we may link to.

What Data We Collect

When you make a booking we collect the details needed to arrange and deliver your transfer: your name, email address, phone number, pickup and drop-off address, flight number, and passenger or group information (such as the number of travellers and any luggage or accessibility notes you provide). When you pay, your card payment is processed by our payment provider, Stripe; we do not see or store your full card number. When you use our website, we also collect limited technical and usage data such as your IP address, device and browser type, and pages viewed, as described in our Cookie Policy.

How We Use Your Data and Our Legal Bases

We use your data to perform our contract with you — confirming and managing your booking, arranging pickup, tracking your flight, contacting you about your transfer, and processing payments and refunds, including free cancellation up to 24 hours before the scheduled pickup. We rely on our legitimate interests to keep our website and services secure, prevent fraud, respond to enquiries, and improve our service. We rely on legal obligations to keep accounting and tax records. Where required, we rely on your consent for marketing communications and for non-essential cookies and analytics, which you can withdraw at any time.

Payments (Stripe)

Card payments on our website are handled by Stripe, a third-party payment processor. When you enter your card details, they are sent directly to Stripe over an encrypted connection; we receive only a confirmation of payment and limited information such as the result of the transaction and the last digits and type of card. Stripe processes this data under its own privacy terms and uses it for payment processing, fraud prevention, and compliance with financial regulations.

Cookies and Analytics

Our website uses cookies and similar technologies to make the site work, remember your preferences, and understand how the site is used. Strictly necessary cookies are always active. Analytics and other non-essential technologies — including Google Analytics 4 — load only after you give consent through our cookie banner, and you can change or withdraw your choice at any time. For full details, please see our Cookie Policy.

Who We Share Your Data With

We share personal data only as needed to run our service. This includes: Stripe, which processes card payments; Resend, which delivers our booking confirmations and other transactional emails; Vercel, which hosts our website; and our drivers and operations staff, who receive the booking details needed to carry out your transfer. We may also share data with professional advisers, or with public authorities where we are legally required to do so. We do not sell your personal data.

International Transfers

Some of the service providers we use are based outside Iceland and the European Economic Area (EEA), or may process data in other countries. Where personal data is transferred outside the EEA, we rely on appropriate safeguards — such as the European Commission's adequacy decisions or Standard Contractual Clauses — to ensure your data receives a level of protection consistent with European and Icelandic data protection law.

How Long We Keep Your Data

We keep your booking and contact data for as long as needed to provide your transfer and to handle any follow-up, questions, or refunds. We retain transaction and accounting records for the period required by applicable Icelandic accounting and tax legislation. Where we process data based on your consent, such as marketing, we keep it until you withdraw consent or it is no longer needed. When data is no longer required, we delete or anonymise it.

Your Rights

Under the GDPR you have the right to access the personal data we hold about you, to have inaccurate data corrected, and to have your data erased in certain circumstances. You may also ask us to restrict or object to certain processing, request a copy of the data you provided in a portable format, and withdraw any consent you have given. We will respond to requests in line with applicable law, and in most cases exercising these rights is free.

Complaints and Supervisory Authority

If you have concerns about how we handle your personal data, please contact us first so we can try to resolve them. You also have the right to lodge a complaint with the Icelandic Data Protection Authority, Persónuvernd (www.personuvernd.is), which supervises compliance with data protection law in Iceland.

Contact and Changes to This Policy

To exercise your rights or ask any question about this policy, contact us at info@reykjavikexpress.is or +354 894 2115, Guðmundur Tyrfingsson ehf., Fossnes C, 800 Selfoss, Iceland. We may update this Privacy Policy from time to time; the current version will always be available on our website, and we will indicate when it was last updated. This policy is governed by Icelandic law.

Questions about a booking or these policies? Contact us at info@reykjavikexpress.is / +354 894 2115.