Privacy Policy

Last updated: 21 August 2026

1. Data Controller

The data controller responsible for the processing of personal data on this platform within the meaning of Art. 4 (7) of the General Data Protection Regulation (GDPR) is:

EP betteride Technologies UG

Rheinsberger Straße 76/77

10115 Berlin, Germany

Managing Director: Emmanuel Plattard

Commercial Register: Amtsgericht Charlottenburg, HRB 269229 B

Tax / Supervisory Authority: Finanzamt Charlottenburg

Email: [email protected]

Website: https://betteride.eu

Phone: +352621625922

2. Overview & Scope of Processing

2.1 Purpose of this Privacy Policy

This Privacy Policy informs you about the type, scope, and purpose concerning the processing of personal data within our online marketplace platform, associated websites, APIs, and mobile/web applications (collectively referred to as the "Platform" or "Services").

2.2 Scope and Target Audience

  • Riders / Customers: Individuals searching for repair workshops, booking bike services, managing bicycle maintenance profiles, or communicating with mechanics.
  • Workshops & Mechanics: Businesses and authorised representatives listing their services, managing repair schedules, issuing customer invoices, and processing repair orders.
  • Platform Visitors & Prospective Users: Unregistered visitors browsing workshop directories, marketing pages, or contacting our support team.

2.3 Definitions under Art. 4 GDPR

  • Personal Data (Art. 4 (1) GDPR): Any information relating to an identified or identifiable natural person ('data subject').
  • Processing (Art. 4 (2) GDPR): Any operation performed on personal data, such as collection, recording, structuring, storage, retrieval, disclosure, or erasure.
  • Controller (Art. 4 (7) GDPR): The legal entity that determines the purposes and means of personal data processing (EP betteride Technologies UG).
  • Processor (Art. 4 (8) GDPR): A natural or legal person that processes personal data on behalf of the controller.

3. General Principles & Legal Bases for Processing

We process personal data under the following legal grounds of Art. 6 (1) GDPR:

  • Performance of a Contract (Art. 6 (1)(b) GDPR): To operate the marketplace, register accounts, schedule bike repair bookings, generate invoices, and send service status updates.
  • Compliance with Legal Obligations (Art. 6 (1)(c) GDPR): Statutory retention of commercial/tax records (German HGB and AO).
  • Legitimate Interests (Art. 6 (1)(f) GDPR): Ensuring platform availability, rate-limiting, malware scanning, abuse prevention, and network security.
  • Consent (Art. 6 (1)(a) GDPR & § 25 (1) TDDDG): Optional analytics tracking and social login authorizations.

4. Categories of Personal Data Collected & Processed

A. User & Account Data

First name, last name, email address, phone number, encrypted password hash, authentication tokens, and social provider IDs (Google, Facebook, Apple).

B. Workshop & Mechanic Profile Data

Workshop name, legal entity name, business address, geocoordinates, VAT ID, business phone number, business email, service catalog, and accepted bike categories.

C. Booking, Bike & Service Records

Booking identifiers, time slot selection, bicycle make/model/specifications, service history, and repair notes.

D. Financial & Invoicing Data

PDF invoices, invoice numbers, billing addresses, VAT breakdowns, and transaction amounts.

E. Media & Uploaded Files

Bicycle photos, repair documentation images, workshop assets, and logos.

5. Third-Party Integrations & Sub-Processors

All sub-processors operate under Data Processing Agreements (DPA) pursuant to Art. 28 GDPR:

  • Product Analytics – PostHog (EU Cloud: eu.i.posthog.com): Analyzes user interactions for UX optimization under explicit consent (Art. 6 (1)(a) GDPR). Cookieless mode is active until explicit consent is given.
  • Maps & Geolocation – Mapbox: Geolocation and map display for workshop discovery (Art. 6 (1)(b) & (f) GDPR).
  • Bicycle Specifications – 99Spokes (api.99spokes.com): Querying bicycle technical data (no direct personal identifiable data transferred).
  • Cloud Infrastructure – Amazon Web Services (AWS): Object storage for media/invoices and transactional SMS dispatch.
  • Email Delivery – IONOS: Transactional email notifications (verification codes, booking confirmations, pickup notices).
  • Social Login – Google LLC, Meta Platforms Ireland Ltd., Apple Inc.: Simplified user authentication upon user request.

6. Cookies and Local Storage

Name / MechanismTypePurposeRetentionLegal Basis
Session & AuthEssentialMaintains secure login session and access authorizationActive session durationArt. 6(1)(b) GDPR / § 25(2) TDDDG
User PreferencesEssentialStores interface language and display preferencesPersistent local storageArt. 6(1)(f) GDPR / § 25(2) TDDDG
Privacy PreferencesEssentialRemembers user consent choicesPersistent local storageArt. 6(1)(c) GDPR / § 25(2) TDDDG
PostHog AnalyticsAnalytics (Optional)Session analysis to improve platform usability (only with consent)Up to 1 yearArt. 6(1)(a) GDPR / § 25(1) TDDDG

7. Data Retention and Erasure

  • User Accounts: Retained while active. Accounts and personal data can be deleted upon request within 30 days under Art. 12 (3) GDPR by emailing [email protected].
  • Temporary Tokens & Codes: Expire automatically and are purged regularly.
  • Invoices & Receipts: Retained for 6 to 10 years pursuant to statutory commercial/fiscal requirements (HGB § 257, AO § 147).

8. Rights of the Data Subject

Under the GDPR, you have the following rights:

  • Right of Access (Art. 15 GDPR)
  • Right to Rectification (Art. 16 GDPR)
  • Right to Erasure (Art. 17 GDPR)
  • Right to Restriction of Processing (Art. 18 GDPR)
  • Right to Data Portability (Art. 20 GDPR)
  • Right to Object (Art. 21 GDPR)
  • Right to Withdraw Consent (Art. 7 (3) GDPR)

To exercise your rights, contact us at [email protected].

9. Data Security Measures

  • TLS 1.3 / SSL encryption for data in transit; encrypted storage at rest.
  • Role-based access control (RBAC) and strict credential isolation.
  • Rate limiting, Web Application Firewall (WAF) filtering, and automated malware scanning on uploads.

10. Supervisory Authority & Complaints

You have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR):

Berliner Beauftragte für Datenschutz und Informationsfreiheit

Alt-Moabit 59-61, 10555 Berlin, Germany

Website: https://www.datenschutz-berlin.de

11. Updates and Versioning

  • Current Version: 1.0.0
  • Effective Date: 21 August 2026
  • Material changes will be communicated via email or in-app notices. Consent-based features will request renewed consent upon material changes.