Security & Data Protection

Last updated: 1 July 2026

This Security & Data Protection Protocol provides a high-level overview of the measures and principles HubRide applies when operating its booking platform and related services.

It is intended for hotels, venue groups, taxi operators, dispatch partners, IT teams and other business partners assessing HubRide’s approach to data protection and information security.

This document should be read together with our Privacy Policy and Platform Privacy Notice.

Purpose and scope

HubRide provides browser-based booking interfaces, guest self-service links, QR-based booking flows, operational messaging and related integrations for hospitality venues, taxi operators and dispatch platforms.

This protocol describes the principles applied to protect personal data, booking information and the systems used to deliver HubRide services. It covers standard HubRide web booking flows, guest links, venue-facing booking interfaces and approved integrations.

This public document is not a security certification, penetration-test report or substitute for contractual security documentation agreed with a specific partner.

Security governance

HubRide maintains technical and organisational measures designed to protect personal data and service information against unauthorised access, accidental loss, misuse, alteration or disclosure.

Security measures are reviewed and developed as the platform, integrations and applicable legal requirements evolve. HubRide may update this protocol when material changes are made to relevant practices or services.

Access management

Access to HubRide administration tools and operational systems is intended to be limited to authorised users with a legitimate business need.

Access rights are assigned according to the user’s role and responsibilities. HubRide seeks to limit access to the information and functionality necessary for the relevant task.

Partners remain responsible for managing access to their own devices, staff accounts, networks and internal systems.

Secure communication and platform access

HubRide’s web-based booking interfaces are delivered through encrypted HTTPS/TLS connections between the user’s browser and HubRide’s services.

Where supported, booking interfaces and guest self-service links are designed to display only the information necessary for the relevant booking journey or service action.

HubRide booking services are browser-based. Standard booking links do not by themselves provide access to a hotel’s, venue’s or partner’s internal network, PMS, POS, door systems, local databases or other internal systems.

Any integration with a PMS, payment provider, dispatch platform or other third-party system is subject to the relevant technical configuration, documentation and commercial agreement.

Guest self-service links and QR flows

HubRide may provide guests with individual booking or service links through SMS, email, QR code or other approved channels.

These links may allow the guest to view relevant booking information, receive status updates, track a vehicle where enabled, modify a booking, arrange a return journey or use payment-related features where available.

Guest links are designed to be unique to the relevant booking or guest journey. Where appropriate, links may be limited in duration, invalidated or reissued to reduce the risk of misuse.

Guests and venue staff should not share personal booking links publicly or with unauthorised individuals.

Application and operational security

HubRide applies measures intended to reduce common security risks in the operation and development of its services. Depending on the relevant component, these may include:

  • secure software-development practices;
  • input validation and controls intended to reduce common web-application risks;
  • security updates and maintenance of relevant systems and dependencies;
  • logging and monitoring of relevant operational and security events;
  • controls intended to reduce automated misuse, unauthorised bookings or abnormal activity; and
  • procedures for access management, incident handling and service continuity.

Data protection and confidentiality

HubRide processes personal data in accordance with applicable data-protection requirements and the relevant contractual arrangements with its customers and partners.

Depending on the specific service setup, HubRide, a hotel, a venue, a taxi company or a dispatch partner may act as an independent data controller for its own processing activities. In some cases, HubRide may process data on behalf of a partner under a data processing agreement.

Further information about the categories of personal data processed, relevant purposes, recipients, retention periods and individual rights is available in the Platform Privacy Notice.

Third-party suppliers and integrations

HubRide may use third-party providers to support hosting, messaging, analytics, monitoring, customer support, payment-related services or other operational functions.

Where suppliers process personal data on behalf of HubRide, HubRide seeks to ensure that appropriate contractual and data-protection safeguards are in place.

HubRide does not control the security practices of independent taxi companies, hotels, venues, dispatch platforms or other third parties. Each organisation remains responsible for its own systems, staff, policies and legal obligations.

Incident management

If HubRide becomes aware of a suspected security incident involving the platform or personal data, it will assess the incident and take appropriate steps to contain, investigate and remediate it.

Where an incident qualifies as a personal-data breach under applicable law, HubRide will assess relevant notification obligations and cooperate with affected partners where appropriate.

Partners who suspect misuse of a HubRide booking link, abnormal booking activity or a security issue should contact HubRide as soon as possible and provide relevant details, including the affected venue, date, time and observed behaviour.

Partner responsibilities

Hotels, venues, taxi operators, dispatch partners and other organisations using HubRide are responsible for protecting their own environment, including:

  • keeping reception devices, browsers and operating systems updated;
  • using appropriate device, network and account-security controls;
  • ensuring only authorised personnel can access venue-facing booking interfaces;
  • training relevant staff to recognise phishing, suspicious links and abnormal booking activity; and
  • reporting suspected security incidents without unnecessary delay.

Security documentation for enterprise partners

Partners with specific IT-security, procurement or compliance requirements may contact HubRide for additional information relevant to a particular implementation, including information about booking-link usage, integrations, data-processing arrangements and operational responsibilities.

Changes to this protocol

HubRide may update this Security & Data Protection Protocol to reflect changes in services, security practices, technology, contractual arrangements or applicable legal requirements. The latest version will always be published on this page.

Contact

HubRide ApS
CVR no. 42177253
Sct. Mathias Gade 38, 2.
8800 Viborg
Denmark
support@hub-ride.com
+45 40 500 720