Esta página está disponible actualmente solo en inglés.
Privacy policy
Fecha de entrada en vigor: 5 August 2026
This Privacy Policy explains how Dedik Serhii Vitaliiovych, an individual entrepreneur registered in Ukraine under registration number 21030000000108643, with contact email support@ridekin.app ("Provider", "we", "us", "our"), collects, uses, shares, and protects personal data when you use the Ridekin mobile apps, the website at ridekin.app (including the waitlist and contact forms), and related features (together, the "Service"). We are the data controller for the processing described here.
Location and safety - the short version
Important - location and safety features. Ridekin processes precise (GPS-level) geolocation and supports real-time location sharing, group rides, messaging, and an SOS / emergency-style alert feature. Precise location is treated by many laws as sensitive. We process it only with your explicit consent, only while the relevant feature is active, and you can turn it off or revoke consent at any time. The Service is not an emergency service.
Who we are and how to contact us
Controller: Dedik Serhii Vitaliiovych, an individual entrepreneur (sole proprietor) registered in Ukraine under registration number 21030000000108643. Email: support@ridekin.app. Website: https://ridekin.app.
We have not appointed a representative in the EU/EEA or the UK under Article 27 GDPR / UK GDPR, and we have not appointed a Data Protection Officer. For any privacy matter, contact us directly by email.
Scope
This Policy applies to personal data we process about users of the Ridekin apps, visitors to this website, waitlist subscribers, and people who contact us - worldwide. Where mandatory data-protection laws of your country of residence (including the EU/EEA GDPR, the UK GDPR, the California CCPA/CPRA, and Ukraine's Law "On Protection of Personal Data") give you rights or protections beyond this Policy, those laws prevail.
Personal data we collect
Account and profile: your email address and password (stored only in hashed form), or the identifier and verified email address Google or Apple share with us if you sign in with them; plus the profile you build - display name, bio, riding style and classes, avatar, and your public handle and friend code.
Precise location (sensitive): GPS-level location when you enable presence or start a live-location share, and the route tracks you record, draw, or import. We collect precise location only after you grant the device permission and give explicit consent, only while the relevant feature is active, and only in the foreground - the current apps do not use background location. Presence expires automatically within a few hours at most and can be shared at coarse (area-level) precision instead of exact. A live-location share ends on its own schedule, and its coordinates are purged when it ends (we sweep every minute). Recorded route tracks can mask their start point.
SOS: if you trigger an SOS, we process your location at that moment, the time, your identity, and your chosen recipients in order to attempt to relay the alert. Ridekin is not an emergency service and delivery is not guaranteed. Unanswered SOS broadcasts are cleared within about an hour.
Content and social data: ride plans and RSVPs, spots and check-ins, ride clips (video), photos, posts, build threads, community memberships, reviews, and messages you exchange; and your social graph - friends, close friends, blocks, vouches, invites, referrals, and convoy participation.
Marketplace and payments: listings and business profiles you create. Paid features are bought either through the App Store or Google Play (we receive the store's receipt and transaction identifiers, never your payment-card details) or - for marketplace and event-ticket payments - through Paddle, which acts as the merchant of record and processes your payment details under its own privacy policy; we receive transaction identifiers and amounts.
Verification: if you apply for a verified badge, we process the evidence you submit; once a decision is made, the evidence is deleted and only the decision itself is retained.
Waitlist and contact: your email address and signup source when you join the waitlist, and your message, chosen category, and optional reply email when you use the contact form.
Device and technical data: device model and operating system, app version, language, time zone, push-notification tokens (where you enable notifications), your IP address (transiently, for security and abuse prevention), and crash and error reports, which go to an error-tracking service that we host on our own infrastructure.
Live-link viewers: when someone opens a live-location link you shared, we store only a salted hash derived from the link, the viewer's IP address, and coarse browser type - the raw IP address and browser details are never stored.
Beyond precise location, we do not intentionally collect special-category (sensitive) data. Please do not put sensitive information in free-text fields.
How we use personal data, and our legal bases
To provide the core Service - your account, rides, messaging, and the features you request: performance of a contract (GDPR Art. 6(1)(b)).
Presence, live-location sharing, and route recording: your explicit consent (Art. 6(1)(a)) for precise location; contract for the features you request. You can withdraw consent at any time in the app or your device settings.
SOS alerts you trigger: consent and contract, and vital interests or our legitimate interests where relevant (Art. 6(1)(d)/(f)).
To secure the Service, prevent fraud and abuse, moderate content, and enforce our Terms: legitimate interests (Art. 6(1)(f)); legal obligation where applicable.
To maintain, debug, and improve the Service: legitimate interests (Art. 6(1)(f)).
To send waitlist and product-news emails after you confirm your signup: consent (Art. 6(1)(a)); withdraw any time via the unsubscribe link.
To measure aggregate website usage with the analytics described below: legitimate interests (Art. 6(1)(f)).
To comply with legal obligations and respond to lawful requests: legal obligation (Art. 6(1)(c)).
Where we rely on consent, withdrawing it does not affect processing carried out before withdrawal.
What others can see
Location, presence, ride data, profile, and messages are shared with the audiences and recipients you select - you control with whom and at what precision you share. Recipients may retain or misuse what you share, which is outside our control; choose your audiences carefully.
Public pages: a ride, route, or spot you make public is visible to anyone with the link, showing only what you chose to publish. A live-location share link shows your moving position to anyone holding the link - but never your name, photo, or profile - and links are unguessable and stop working the moment the share ends.
Maps and navigation
Map tiles are served from our own infrastructure, and turn-by-turn guidance is computed on your device from the stored route. Your location and routes are never sent to a third-party map or routing provider.
Notifications
Push notifications are delivered through the Apple Push Notification service (iOS) or Firebase Cloud Messaging (Android); to deliver them we store a push token for your device. You can manage or disable notifications in the app and in your device settings at any time.
Waitlist emails
Joining the waitlist is double opt-in: we first send a confirmation email, and we send no marketing until you confirm. Confirmation links expire and are built so that automated email scanners cannot trigger them.
Once you are confirmed, the emails we send about the launch may include standard delivery measurement: a tiny open-tracking image and wrapped links that record when an email is opened and which links are clicked, together with the IP address and browser type of the click. Click IP addresses and browser data are deleted within 12 months. Every email contains a one-click unsubscribe link (RFC 8058); unsubscribing stops all marketing immediately.
Waitlist and contact data is processed in our own feedback service running on our own infrastructure - it is not handed to a third-party marketing platform.
Cookies and website analytics
Strictly necessary storage: your theme choice (light/dark) is kept in your browser's local storage and never leaves your device. The Cloudflare Turnstile bot check used on our forms may set its own strictly necessary cookie; it loads only where a form needs protecting.
Privacy-preserving analytics: we use PostHog (EU Cloud, hosted in the European Union) in a cookieless configuration - no cookies, no persistent identifier, no cross-site tracking - and it is disabled entirely when your browser sends the Do Not Track signal.
Google Analytics: this website also uses Google Analytics 4 (Google Ireland Ltd / Google LLC), running under Google's Consent Mode with analytics storage denied by default and never granted, so it sets no cookie and no persistent identifier on this site - only aggregate, cookieless measurement pings reach Google's servers, including in the United States. Google Signals and ads personalization stay disabled, and we use it only to measure aggregate site usage. You can opt out with Google's browser add-on at https://tools.google.com/dlpage/gaoptout or by blocking the googletagmanager.com domain.
Error monitoring on the website reports JavaScript errors to an error tracker hosted on our own infrastructure.
The mobile apps contain no third-party analytics or advertising SDKs; their crash reporting goes to the same self-hosted error tracker.
Who else sees this data (processors and recipients)
We are not in the business of selling personal data. We share it only with the recipients you choose (section 5), with service providers acting on our documented instructions under Article 28 GDPR data-processing terms, and in the limited cases below.
Our processors: DigitalOcean (cloud hosting, EU - Frankfurt); Cloudflare (DNS, CDN, DDoS and bot protection, Turnstile, and R2 object storage for uploaded media and encrypted backups); Forward Email (transactional email delivery); PostHog (EU Cloud - website analytics); Google (Google Analytics on the website; Google sign-in; Google Play and Firebase Cloud Messaging on Android); Apple (Sign in with Apple, the App Store, and the Apple Push Notification service on iOS); Paddle (merchant of record for marketplace and ticket payments). A current list of sub-processors is available on request at support@ridekin.app.
Legal and safety: we may disclose data to comply with law, legal process, or enforceable governmental requests; to enforce our Terms; to address fraud, security, or technical issues; or to protect the rights, safety, and property of any person.
Business transfer: in connection with a merger, acquisition, reorganization, or sale of assets, subject to this Policy.
We do not disclose personal data to third parties for their own independent marketing, and we do not "sell" or "share" personal information for cross-context behavioural advertising as those terms are defined under California law.
International data transfers
The Provider operates from Ukraine, and our processors store or process data in the EU/EEA, the United Kingdom, the United States, and elsewhere. When personal data of EU/EEA or UK users is transferred to a country without an adequacy decision, we rely on appropriate safeguards - principally the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum for UK data), with supplementary measures where needed. You may request details of these safeguards at support@ridekin.app.
Retention
We keep personal data only as long as needed for the purposes above, then delete or anonymise it. In particular: presence - a few hours at most; live-location coordinates - purged the moment a share ends; unanswered SOS broadcasts - about 1 hour; raw analytics events - 30 days (only aggregates that cannot identify you are kept longer); deleted messages, ride clips, and other content you delete - fully purged within 30 days; notifications - 90 days; spot check-in records - 180 days; support and feedback message content - removed from the product database within days of being relayed to our support tooling, with any residual copy deleted within 18 months; account data - for the life of your account plus up to 30 days after deletion; logs and diagnostics - up to 12 months; waitlist emails - until you unsubscribe or ask us to delete them; email open/click records - IP and browser data removed within 12 months; encrypted database backups - rotated within 30 days.
De-identified or aggregated data that can no longer reasonably identify you may be retained.
Deleting your account, and data export
You can delete your account at any time in the app or - as required by the app stores - through the web form at https://ridekin.app/delete-account (we verify the request by email). Deletion completes within 30 days: your location history, content, social graph, and push tokens are permanently removed, with location data purged first.
Some records are anonymised rather than deleted: community comments and reviews lose their link to you, moderation and safety reports are kept as an anonymous audit trail, and we retain a minimal anonymised account record to prevent abuse and keep blocks effective. Your email address is freed for future registration.
You can export your routes as GPX/KML in the app; a full copy of your account data is available on request at support@ridekin.app and will be provided within the time the law requires (generally one month).
Security
We use technical and organisational measures appropriate to the risk: encryption in transit, hashed passwords, access controls, least-privilege practices, and encrypted off-site backups. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Keep your credentials confidential and choose your sharing audiences carefully. We will notify you and/or the relevant authority of a personal-data breach where the law requires it.
Your rights
EU/EEA and UK: if you are in the EU/EEA or the UK, you have the right to access your personal data, rectify inaccurate data, obtain erasure ("right to be forgotten"), restrict processing, receive your data in a portable format, object to processing based on legitimate interests and to direct marketing, and withdraw consent at any time - including consent to precise location. We do not carry out solely automated decision-making that produces legal or similarly significant effects. To exercise any right, email support@ridekin.app; we respond within the statutory time (generally one month). You may also complain to your local Data Protection Authority or, in the UK, the Information Commissioner's Office (ICO).
California (CCPA/CPRA): we are likely not a "business" as defined by the CCPA/CPRA because we do not meet its thresholds. As a courtesy, we extend to California residents the rights to know and access, correct, and delete personal information, exercisable directly or through an authorised agent. Precise geolocation is "sensitive personal information" under California law; we use it only to provide the Service you request and for permitted purposes, and we do not use it to infer characteristics. We do not sell or share personal information as those terms are defined by the CCPA/CPRA.
Ukraine: if Ukrainian data-protection law applies, you have the rights set out in the Law of Ukraine "On Protection of Personal Data", including to know about the processing of your data, access it, demand rectification or deletion of unlawfully processed or inaccurate data, withdraw consent, object, and complain to the Ukrainian Parliament Commissioner for Human Rights (Ombudsperson) or the courts.
We will never discriminate against you for exercising your rights.
Children
The Service is intended for adults (18+) and is not directed to children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us personal data, contact support@ridekin.app and we will delete it.
Changes to this Policy
We may update this Policy from time to time. We will update the effective date above and, for material changes, give reasonable notice (for example in-app, by email, or on this page). Your continued use after changes take effect constitutes acceptance, except where the law requires fresh consent (for example, for new processing of precise location).
Contact
Privacy questions and requests: Dedik Serhii Vitaliiovych, support@ridekin.app. You may also complain to your supervisory authority (see Your rights).