Your data,yours alone.
1. Hosting
mktLegalPrivacy.s1.body
2. Data collected
Email, profile (nickname, optional club), declared bikes, service records entered, riding sessions (hours, BLE RSSI, device battery level). With a GPS tracker: your bike's positions and routes, kept for anti-theft, the map and your ride history. Depending on use: photos you add (avatar, bike) and your phone's notification token. Your phone's location is read at three moments only, always after your explicit consent and only while the app is open: when you record a ride live, when you choose to attach the place to a manually entered session, and when you set a trusted zone. It is used to place the ride on the map and to fill in the weather. No background tracking of your phone's location, no ad tracking, no browser fingerprinting.
3. Third parties
Stripe receives strictly what it needs for payment (amount, email, billing address). Our billing provider receives billing data (name, address, VAT number if a business, amounts) to issue the official invoices. Transactional email via our own SMTP or our sending provider. Google (Firebase Cloud Messaging) delivers push notifications: it sees your device token and the notification text, never your logbook. Map tiles are served by CARTO, which sees your IP address and the area displayed. No other resale, no commercial sharing.
4. Cookies
Strictly necessary: session, preferences (theme, language). No analytics or advertising cookies. No burdensome consent solution is required: we set nothing that would call for one.
5. Your GDPR rights
Access, rectification, portability, erasure. “Export my data” and “Delete my account” buttons in the app, under Settings → Privacy. Effective deletion happens 30 days after the request (cancelable grace period), then a full cascade purge.
6. Retention period
Active account: as long as you use it. Deleted account: 30-day grace period then deletion. Invoices: 10 years (legal accounting obligation, hosted at our billing provider, encrypted).
7. DPO contact
dpo@horotag.com. Reply within 30 days maximum (GDPR art. 12). If a complaint remains unresolved, you may refer the matter to the CNIL.
