Note: This translation is provided to you for ease of understanding. The German original version is authoritative; in the event of discrepancies it will be used for interpretation. Your rights under the GDPR are not restricted by this.
Privacy Policy
For the BikeMates App
1. Data protection at a glance
General information
The following information provides a simple overview of what happens to your personal data when you use the BikeMates App. Personal data is any data by which you can be personally identified. For detailed information on the subject of data protection, please refer to our privacy policy set out below this text.
Data collection in this app
Who is responsible for the data processing in this app?
Data processing in this app is carried out by the app operator. You can find their contact details in the section “Information on the controller” in this privacy policy.
How do we collect your data?
Your data is collected firstly by you providing it to us. This may, for example, be data that you enter during registration, in your profile or in chat messages.
Other data is collected automatically or with your consent when you use the app, by your device sensors and our IT systems. This is primarily technical data (e.g. smartphone operating system, GPS location, sensor data such as lean angle and acceleration) as well as usage data. This data is collected automatically as soon as you use certain functions of the app (e.g. ride recording, navigation).
What do we use your data for?
Part of the data is collected in order to ensure that the app is provided without errors. Other data may be used to analyse your riding behaviour (lean angle, speed, curve rating) as well as for community functions, navigation, crash detection and the integrated shop.
What rights do you have regarding your data?
You have the right at any time to receive information about the origin, recipients and purpose of your stored personal data free of charge. You also have a right to request the rectification or erasure of this data. If you have given consent to data processing, you can withdraw this consent at any time with effect for the future. In addition, you have the right to request the restriction of the processing of your personal data under certain circumstances. Furthermore, you have a right to lodge a complaint with the competent supervisory authority.
You can contact us at any time regarding this and any further questions on the subject of data protection.
2. Hosting and backend infrastructure
The content and backend services of our app are hosted by the following provider:
Hetzner
The provider is Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen (hereinafter Hetzner).
When you use our app, your usage data, ride recordings, profile information and location data, among other things, are processed and stored on Hetzner’s servers. For details, please refer to Hetzner’s privacy policy: https://www.hetzner.com/de/rechtliches/datenschutz.
Hetzner is used on the basis of Art. 6(1)(f) GDPR. We have a legitimate interest in providing our app and the associated backend services as reliably as possible.
Processing on behalf of a controller
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract required under data protection law which ensures that the provider processes the personal data of our app users only in accordance with our instructions and in compliance with the GDPR.
3. General information and mandatory information
Data protection
The operators of this app take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection provisions and this privacy policy.
When you use this app, various personal data is collected. Personal data is data by which you can be personally identified. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.
We would like to point out that data transmission over the internet (e.g. when communicating by e-mail) may have security vulnerabilities. Complete protection of data against access by third parties is not possible.
Information on the controller
The controller responsible for data processing in this app is:
Manuel Spielberger
LuMa Medien
Rechte Brandstr. 31
86167 Augsburg
Phone: +49 (0)821 567 338 31
E-mail: datenschutz@bikemates.eu
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data (e.g. names, e-mail addresses or similar).
Storage period
Unless a more specific storage period is stated within this privacy policy, your personal data will remain with us until the purpose for the data processing no longer applies. If you assert a justified request for erasure or withdraw consent to data processing, your data will be erased unless we have other legally permissible grounds for storing your personal data (e.g. retention periods under tax or commercial law); in the latter case, erasure takes place once these grounds no longer apply.
In detail, the following periods apply:
- Closed tickets – six months after closure; cases that have been put on hold to preserve evidence are retained beyond this
- Prize draw entries – six months after the end of the prize draw
- Media in one-time view – after they have been opened by all recipients, at the latest after 30 days
- Earlier versions of ride drafts – 30 days
- Membership of the chat of a ride – seven days after the ride has ended; the chat history itself is retained
- Attribution identifiers of the referral programme – 48 hours
- Last reported live position – overwritten by every new report, no longer delivered after two hours and erased together with the account
- Ride recordings, curve passes and explored areas – no fixed period; they exist for as long as your account exists
- Orders and invoices – ten years (§ 147 AO)
If a different period is stated for an individual function in this policy, that period applies.
General information on the legal bases for data processing in this app
Insofar as you have consented to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR, where special categories of data pursuant to Art. 9(1) GDPR are processed. If your data is required for the performance of a contract or for the implementation of pre-contractual measures, we process your data on the basis of Art. 6(1)(b) GDPR. Furthermore, we process your data where this is necessary for compliance with a legal obligation, on the basis of Art. 6(1)(c) GDPR. Data processing may also be carried out on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR. Information on the legal bases applicable in each individual case is provided in the following paragraphs of this privacy policy.
Withdrawal of your consent to data processing
Many data processing operations are only possible with your explicit consent. You can withdraw consent you have already given at any time. The lawfulness of the data processing carried out up to the point of withdrawal remains unaffected by the withdrawal.
Right to object to the collection of data in special cases and to direct marketing (Art. 21 GDPR)
If data processing is carried out on the basis of Art. 6(1)(e) or (f) GDPR, you have the right at any time to object, on grounds relating to your particular situation, to the processing of your personal data; this also applies to profiling based on these provisions. If you object, we will no longer process the personal data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims (objection pursuant to Art. 21(1) GDPR).
If your personal data is processed for the purposes of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purposes of such marketing; this also applies to profiling insofar as it is related to such direct marketing. If you object, your personal data will subsequently no longer be used for the purposes of direct marketing (objection pursuant to Art. 21(2) GDPR).
Right to lodge a complaint with the competent supervisory authority
In the event of infringements of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or the place of the alleged infringement. This right to lodge a complaint is without prejudice to any other administrative or judicial remedy.
Right to data portability
You have the right to have data that we process automatically on the basis of your consent or in performance of a contract handed over to you or to a third party in a commonly used, machine-readable format. If you request the direct transfer of the data to another controller, this will only take place insofar as it is technically feasible.
Information, rectification and erasure
Within the framework of the applicable statutory provisions, you have the right at any time to obtain free information about your stored personal data, its origin and recipients and the purpose of the data processing and, where applicable, a right to rectification or erasure of this data. You can contact us at any time regarding this and any further questions on the subject of personal data.
Right to restriction of processing
You have the right to request the restriction of the processing of your personal data. You can contact us at any time for this purpose. The right to restriction of processing exists in the following cases:
- If you contest the accuracy of your personal data stored by us, we generally need time to verify this. For the duration of the verification, you have the right to request the restriction of the processing of your personal data.
- If the processing of your personal data took place/is taking place unlawfully, you can request the restriction of the data processing instead of erasure.
- If we no longer need your personal data but you need it for the exercise, defence or establishment of legal claims, you have the right to request the restriction of the processing of your personal data instead of erasure.
- If you have lodged an objection pursuant to Art. 21(1) GDPR, a balancing of your interests and ours must be carried out. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.
If you have restricted the processing of your personal data, this data may – apart from being stored – only be processed with your consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or a Member State.
SSL/TLS encryption
For security reasons and to protect the transmission of confidential content, this app uses SSL/TLS encryption for all communication between the app and our servers. This means that the data transmitted between your device and our servers cannot be read by third parties.
Objection to advertising e-mails
We hereby object to the use of contact data published in the context of the legal notice obligation for the purpose of sending advertising and information material that has not been expressly requested. The operators of the app expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, for example by spam e-mails.
4. Registration and user account
Registration via Google or Apple (Firebase Authentication)
To use the app, registration or sign-in via your Google account or your Apple account is required. Authentication takes place via the Firebase Authentication service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter “Google”).
When signing in via Google, the following data is transmitted to us and stored:
- E-mail address
- Display name
- Profile picture URL
- Firebase user ID (unique identifier)
When signing in via Apple, the following data is transmitted to us and stored:
- E-mail address (may be provided by Apple as a relay address)
- Name (insofar as released by you)
- Firebase user ID (unique identifier)
This data is strictly necessary for the creation and administration of your user account. The legal basis is Art. 6(1)(b) GDPR (performance of a contract).
After you first sign in, a server-side authentication hash is generated which is stored on your device and authenticates you automatically in subsequent sessions. Further information on data protection at Google can be found at: https://policies.google.com/privacy. Information on data protection at Apple can be found at: https://www.apple.com/de/privacy/.
Profile data
After registration, you can optionally provide further profile data:
- User name
- Display name
- Profile picture (photo upload)
- Profile biography
- Social media links (Instagram, TikTok)
- Motorcycle information (make, model, year of construction; optionally the details from the vehicle registration document, see section 12)
- Home location (coordinates)
- Privacy settings (visibility of your profile and your statistics)
Providing this data is voluntary. The processing is carried out on the basis of your consent (Art. 6(1)(a) GDPR). You can change or delete this data at any time in the app settings.
Session data: For every sign-in we store a session identifier, the time of last use as well as the platform (Android/iOS) and the app version. This serves session management, troubleshooting and the decision as to which functions can be delivered to a given app version (Art. 6(1)(f) GDPR). Sessions are terminated and deleted upon sign-out, a suspension or the deletion of the account.
Language setting
The app is available in nine languages. On first launch, the system language of your device is adopted; if it is not among them, English is used. Your choice of language is stored in your account and additionally for each signed-in device, so that push notifications, e-mails, invoices and the accident report can be created in your language. It is not derived from your IP address or the country you are in.
The translations come from dictionaries that are stored permanently in the app and on our server; texts of communities, shop products and ticket categories are maintained by us manually. No external translation service is used, and no content is transmitted to third parties for this purpose.
The legal basis is Art. 6(1)(b) GDPR (performance of a contract).
Account deletion
You can request the deletion of your user account at any time — in the app via a ticket to the BikeMates team or by e-mail to datenschutz@bikemates.eu. The deletion takes place in two steps:
- Scheduling with a 14-day period. During this time your account remains fully usable and is not suspended. At every sign-in you will see a notice about the scheduled deletion and can revoke it with a single tap. If you request accelerated deletion, the period is shortened to 48 hours.
- Execution once the period has expired. After that, the deletion can no longer be reversed.
What is deleted: your identity data (sign-in identifier, user name, e-mail address), profile and profile picture, all ride recordings and position data, explored areas, saved places, motorcycles including vehicle registration data and images, emergency contacts, accident data and detection logs, location shares, friendships, community memberships, applications and invitations, your chat memberships, reactions and read markers, all uploaded files (chat attachments, post images, ticket attachments, diagnostic logs), push registrations, sessions, shopping basket and address book, prize draw entries, your corner passes including best times, your BikePoints trail and trophies awarded to you, your votes in polls, messages marked with a star and pinned by you, the records of opened one-time views, notes that community administrators have created about you, as well as your own referral links.
What remains in anonymised form: your chat messages, posts and comments remain in place as content so that the conversations and posts of other users are not torn apart; the sender is then shown only as “Unknown”, and a profile can no longer be opened. Rides and group rides created by you are retained for the other participants, likewise without any personal reference. If you have founded a community, the founder role passes to the BikeMates system account so that the community can continue to exist.
What remains for legal reasons: orders and invoices from the shop (retention obligation under § 147 AO, ten years — Art. 17(3)(b) GDPR), cases that the BikeMates team has put on hold to preserve evidence (see “Tickets and reports”), as well as the log of the interventions of the operator team.
Ride tracks archived on our file server and accident reports that have been generated are removed as part of the same process.
The legal basis is Art. 17 GDPR.
5. Location data and sensor data
GPS location collection
The app collects your precise GPS location for the following purposes:
- Ride recording (route capture, speed, elevation profile)
- Navigation and route calculation
- Display of your position on the map
- Crash detection and emergency notification
- Location sharing with friends and communities
- Petrol station and POI search in your vicinity
Location collection runs continuously only while a ride recording or navigation is active or the map is open. In all other views, the app determines only a single position at startup (for example for “Communities near you” or the location details on a post) and then ends the request. Background location collection is necessary so that rides can be recorded in full even when the screen is switched off. The motion sensors of the device are read out exclusively during a recording.
The legal basis is your consent pursuant to Art. 6(1)(a) GDPR, which you give expressly by granting the location permission on your device. You can withdraw the location permission at any time in the system settings of your device.
Background location
The app uses the background location permission (ACCESS_BACKGROUND_LOCATION) in order to continue the ride recording and navigation even when the app is not in the foreground. This permission is requested from you expressly and is necessary for the core functionality of the motorcycle telemetry. Without this permission the app cannot record rides reliably in the background.
The background location data is processed exclusively for the purposes stated above and is not used for advertising purposes or for the creation of movement profiles.
Smartphone sensor data (internal IMU)
During ride recording, the app accesses the internal sensors of your smartphone:
- Accelerometer – to measure acceleration forces (G-forces)
- Gyroscope – to measure rotational movements and lean angles
- Gravity sensor – to calibrate the attitude in space
From this raw data the app calculates, among other things, the lean angle of your motorcycle. These calculations are carried out locally on your device. When a ride recording is uploaded, the calculated lean angles and speed values are transmitted to our server.
The legal basis is your consent (Art. 6(1)(a) GDPR), which you give by starting the ride recording.
External Bluetooth sensor (PerformanceTracker)
Optionally, the app can be connected to an external PerformanceTracker sensor via Bluetooth Low Energy (BLE). This sensor supplies more precise IMU data (acceleration, gyroscope, orientation) than the internal smartphone sensors.
When this sensor is used, the following data is processed:
- Bluetooth device address of the sensor
- Raw sensor data (acceleration, gyroscope, orientation)
- Lean angles and G-forces calculated from it
The connection is established actively by you and the data processing initially takes place locally on your device. The Bluetooth permissions (BLUETOOTH_SCAN, BLUETOOTH_CONNECT) are requested expressly.
The legal basis is your consent (Art. 6(1)(a) GDPR).
Tyre pressure sensors (TPMS)
The app can optionally receive tyre pressure data from Bluetooth TPMS sensors. In doing so, tyre pressure, temperature and the Bluetooth device addresses of the sensors are processed and displayed locally on your device. This data is not transmitted to our servers.
The legal basis is your consent (Art. 6(1)(a) GDPR).
Ambient light sensor
If you select the “Automatic” mode in the map settings, the app evaluates the ambient light sensor of your device in order to switch between the light and dark map display. The brightness values are processed exclusively locally on your device, are not stored and are not transmitted to our servers. The sensor is evaluated only for as long as the app is visible and the “Automatic” mode is active.
The legal basis is your consent (Art. 6(1)(a) GDPR), which you give by selecting the “Automatic” mode.
6. Ride recording and analysis
Recorded ride data
When you start the ride recording, the following data is collected and transmitted to our server once the ride has ended:
- GPS coordinates (latitude, longitude) along the route ridden
- Speed and speed accuracy
- Altitude
- Lean angles per time segment
- Acceleration values (G-forces)
- Start and end time of the ride
- Total distance
- Maximum lean angles and top speeds
- IP address at the time of upload
- App version
- Assigned motorcycle (if selected)
The storage of the IP address serves the detection of misuse and is processed on the basis of Art. 6(1)(f) GDPR (legitimate interest). The remaining ride data is stored on the basis of the performance of a contract (Art. 6(1)(b) GDPR).
Curves, best times and records
The curve map matches your ride recordings against a catalogue of surveyed curves. For every curve ridden through, we store the reference to the curve and to the ride, the beginning and end of the pass, the time taken as well as average and maximum values of lean angle and speed. A pass is only counted as such if you ride through the curve with a significant lean angle of around 20 degrees.
What others see of this: In the curve view, the fastest pass is displayed as a record. Other users see the user name, display name, profile picture and the time ridden by the record holder. Speed and lean angle are not displayed to other users; you can see these values only yourself, for your own passes.
Controlling visibility: Using the privacy setting “Leaderboards” in your profile, you determine whether you appear in leaderboards and curve records. The setting is set to visible by default and can be changed at any time. Irrespective of this, the map marks a curve as already ridden as soon as anyone has recorded a time there. This indication is anonymous, contains neither names nor values and does not allow any conclusions to be drawn about a specific person.
Storage period: Curve passes are not deleted after a period of time; they exist for as long as your account exists and are removed when the account is deleted. If a ride is matched again, the new values replace the previous ones.
The legal basis is Art. 6(1)(b) GDPR (performance of a contract); you control the visibility to other users yourself.
Explored areas (Explorer map)
From every ride recording it is determined which areas you have ridden through. For this purpose the world is divided into grid cells of approximately 5 × 5 kilometres; for each cell we store only the fact that you have ridden through it and the date of the first pass — not the exact route within the cell. This list is visible exclusively to you yourself on the Explorer map; only the number of newly explored areas is included in community leaderboards.
The legal basis is Art. 6(1)(b) GDPR (performance of a contract).
Community leaderboards
Community administrators can enable leaderboards for their community (e.g. kilometres ridden, number of riding days, longest ride, explored areas, curves, post activity) for the periods week, year and all time. The values are calculated hourly from your ride recordings and cached; visible to the members of the community are the user name or display name, the profile picture and the respective value. There are deliberately no leaderboards by speed or lean angle; to be distinguished from these are the curve records, where only the time ridden is published (see “Curves, best times and records”).
Using the privacy setting “Leaderboards” in your profile, you determine whether you appear in leaderboards for all members, only for friends or not at all.
The legal basis is Art. 6(1)(b) GDPR; you control the visibility yourself.
BikePoints and trophies
BikePoints from kilometres ridden: When a ride is uploaded, BikePoints are credited to the community of which you are a member. For this purpose we keep a trail per community, member and day, with the kilometres ridden, the points calculated from them and the number of rides. Community administrators see from this only daily totals without names; the individual entries can be viewed solely by us as the operator.
Granting of memberships: If a community administrator uses BikePoints to gift a GoldBiker or SilberBiker membership to a member, this transaction is recorded with the recipient’s user name, tier, term, points used and time, and can be viewed by the administrators of the community.
Trophies: Community administrators can award trophies to members. What is stored is the trophy, the member honoured, the awarding person, a possible end of validity as well as an internal note of up to 255 characters. The trophy itself appears in your profile; the note is intended for the administration of the community and is not displayed to you in the app. Upon a request for information pursuant to Art. 15 GDPR we will also disclose this note to you. Using the privacy setting “Communities” you can switch off the display of your trophies.
Trophies in the shop: A trophy can open up access to certain products or a discount. If you redeem such a discount, the link between the trophy and the order is stored; it is then subject to the ten-year retention period for order documents.
The legal basis is Art. 6(1)(b) GDPR, and for the logging of awards within a community Art. 6(1)(f) GDPR (legitimate interest in a traceable administration).
Sharing of rides
You can share individual rides or daily reports with third parties via an individual link. When a shared ride history is accessed, the IP address of the visitor is stored for the purpose of access statistics and the detection of misuse.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in tracking the use of shared content).
Video export (time-lapse)
You can have a time-lapse video created from a recorded ride. The creation takes place entirely on your device: route, speed and lean angles are combined locally into a video. No ride or position data is transmitted to us or to third parties in the process.
For the map display in the video, the app loads map tiles from our server — the same ones that are also used for the normal map view. No conclusions about the specific ride can be drawn from this, since the tiles are delivered across the whole area and independently of your route.
The finished video is stored in the media library of your device (folder “Movies/BikeMates”) and is thus also visible to other apps to which you have granted access to your media. Whether and with whom you share the video is decided solely by you.
The legal basis is your consent (Art. 6(1)(a) GDPR), which you give by starting the export.
7. Crash detection and emergency contacts
Automatic crash detection
The app has an automatic crash detection (Crash Detection) which is active during ride recording. This function analyses the sensor data (acceleration, gyroscope) locally on your device in order to detect a possible accident.
If an accident is detected, the following happens:
- The current GPS location (accident site) is transmitted to our server
- A countdown is displayed which you can cancel (false alarm)
- Once the countdown has expired, the emergency contacts you have stored are notified automatically by SMS
- The SMS contains an individual link to the accident site and your most recent ride history that can only be retrieved with a secret key (valid for 24 hours). If there is no network connection at the moment of the accident and this key can therefore not be generated, the SMS instead contains your position as a map link.
- BikeMates users who are stored as emergency contacts additionally receive a push notification
The legal basis is your explicit consent (Art. 6(1)(a) GDPR) as well as Art. 6(1)(d) GDPR (vital interests of the data subject).
Emergency contacts
You can store emergency contacts in two ways:
- BikeMates users – by linking to another user account
- Telephone numbers – by entering them manually or selecting them from your device contacts
For the selection from the device contacts, the READ_CONTACTS permission is requested. The contact data is read out exclusively locally and only the telephone number selected by you is stored on the server as an emergency contact. Your address book is not uploaded in full. Please make sure that the persons you store as emergency contacts agree to the storage and use of their telephone number for this purpose. The processing of this contact data is carried out on the basis of Art. 6(1)(f) GDPR (legitimate interest in providing a functioning emergency notification system).
The SEND_SMS permission is required for sending the SMS. It is sent directly from your device.
Detection log (Crash Diagnostics)
To improve crash detection, the app offers a voluntary detection log. For every detection event (including automatically discarded false alarms), the following data is stored locally on your device:
- Raw sensor data (acceleration, gyroscope) from a time window around the event
- GPS position history immediately before and after the event (post-event window approx. 30 seconds)
- Speed and lean angle at the time of the event
- Device information (manufacturer, model, Android version, app version)
- Tyre pressure sensor status (TPMS), if connected
- Threshold values of the detection algorithms
- Battery level and Bluetooth status
This data is stored exclusively locally and is not transmitted automatically. Transmission to our server takes place only if you actively tap “Submit” in the detection log. During transmission, the data is gzip-compressed and linked to your user ID.
You can additionally add a classification (false alarm, minor or serious accident) and an optional comment.
Locally stored events are deleted automatically after 14 days or after successful transmission. A maximum of 5 discarded and 15 confirmed events are kept locally.
The legal basis is your consent (Art. 6(1)(a) GDPR), which you give by actively submitting the data.
Accident report (PDF)
For a submitted detection event, you can have an accident report generated as a PDF in the app — for example to submit to an insurance company or authorities, or for your own records. It is created exclusively upon your express request; no report is generated without your involvement.
The report is compiled from the data we already hold on this event (see “Detection log”) and contains, depending on its scope:
- Time and place of the event, including a map display and the associated address
- Speed, lean angle and acceleration curve before, during and after the event
- a graphical representation of the calculated attitude of the vehicle
- if a ride recording was running at the time of the event: the associated telemetry data of that ride
- if connected: tyre pressure and sensor data
To determine the address, the event coordinate is passed to our own geocoding service; no disclosure to third parties takes place in the process. The result is cached so that the same request does not have to be made several times.
The finished PDF is stored on our file server and made available to you for retrieval via a time-limited, signed link. If you request the same report again, the version already generated is delivered. The stored reports are retained permanently so that they remain available to you even after a longer period of time — for example if an insurance claim is only processed later. You can request the deletion of a report at any time; when your user account is deleted, the associated reports are removed as well.
The scope of the report differs depending on the membership (basic and full version). The number of reports that can be generated per day is technically limited.
The legal basis is your consent (Art. 6(1)(a) GDPR), which you give by requesting the report.
Temporarily pausing crash detection
You can pause crash detection in the settings for a limited period of time (up to 28 days). While it is paused, no accident alarm is triggered and no accident-related notification or data transmission (accident site, SMS to emergency contacts) takes place; the other functions such as ride recording continue unchanged. The app reminds you of the paused state with a permanent notification and reactivates the detection automatically once the period has expired. The time of the pause is stored exclusively locally on your device.
8. Navigation and map services
Route calculation (GraphHopper)
For the navigation and route calculation function, the app uses a self-hosted GraphHopper routing server. When you start navigation, your start and destination location (GPS coordinates) are transmitted to this server (route.bikemates.eu) in order to calculate the route.
The data processing takes place on our own servers at Hetzner. No disclosure to third parties takes place. The legal basis is Art. 6(1)(b) GDPR (performance of a contract).
Map display (OpenStreetMap / PMTiles)
The map display is based on OpenStreetMap data, which is provided in PMTiles format on our own server (maps.bikemates.eu). When map tiles are loaded, your current map view (coordinates and zoom level) is transmitted to our server.
The map rendering library MapLibre GL JS is executed locally in the app. No data is passed on to external map services. The legal basis is Art. 6(1)(b) GDPR (performance of a contract).
Location sharing with friends and communities
You can share your current location with selected friends, within your communities or for the duration of a group ride or a ride. The data transmitted comprises coordinate, speed, direction of travel and time.
Who sees your position: A position is delivered only to recipients for whom you have expressly granted the release and with whom there is at the same time a confirmed friendship, as well as to the participants of a group ride or ride in progress. If you have set up an event with location sharing, the position released there can also be retrieved via the event link without signing in.
Home area: An area around your place of residence defined by you is hidden before delivery.
Storage: We store only the most recently reported position per account; every new report overwrites the previous one, so no movement history arises. If the stored position is older than two hours, it is no longer delivered. It is erased when your account is deleted.
Transmission path: The distribution runs via a messaging service (MQTT) which we operate ourselves on our own server infrastructure; the connection is encrypted with TLS. No third party is involved in this. The access token of your device contains only your account identifier, your user name and the permissions, is valid for one hour and is not stored. If this path is not available, the app falls back to the ordinary query via our app server.
Live view: If an authorised person opens your live position, we record for the duration of the view who is viewing whom; this serves solely to increase the reporting rate of your device for a short time. The entry expires after two minutes and is deleted no later than one day afterwards.
Location sharing is switched off by default and has to be switched on by you. You can end it at any time. The legal basis is your consent (Art. 6(1)(a) GDPR).
Saved places
You can save places (e.g. your home location, favourite routes) with GPS coordinates, a name and optionally an emoji in the app. This data is stored on our server and is visible only to you (unless set otherwise).
The legal basis is Art. 6(1)(b) GDPR (performance of a contract).
9. Community functions and chat
Communities
The app offers community functions (motorcycle clubs, groups). When you use them, the following data is processed:
- Community membership and time of joining
- Posts and comments (incl. location at the time of posting, if released)
- Community applications (with the mandatory fields defined by the community operator)
- Location sharing within the community
- Assigned ranks and permissions
- Votes cast in polls in posts
Polls: Posts can contain a poll. The vote you cast is stored on the server. Whether other members can see how you voted is determined by the creator of the poll (“Voters visible”): if this option is active, your user name or display name is displayed together with your choice for other members; otherwise your vote is included in the overall result only anonymously. You can change or withdraw your vote at any time while the poll is running.
Automatic channel assignment: If a community organises regional sub-areas (channels) by postcode, the postcode and country you provided in the community application may be used to assign you automatically to the matching regional channel once your application has been accepted. For countries without postcode boundaries, the postcode is assigned to a region via our own geocoding service; it is not transmitted to third parties. The territorial division of a community (Squad map) can be viewed by prospective members so that they can find the area responsible for them.
Invitations and welcome: Community administrators can invite you to a community; the invitation (who, whom, when, response) is stored. If you join a community chat, the community can have you greeted with an automatic welcome message; for this purpose we remember the time of joining so that nobody is greeted more than once.
Rides and drafts: For rides we store the creator, participants, route, date and your participation. Rides can be edited as a draft together with invited co-planners before publication; co-planners see the draft and the names of the other co-planners. The members of the area concerned receive a push notification about new rides, which you can switch off in the settings.
Links and social media accounts of communities: Community administrators can store link collections as well as Instagram/TikTok accounts of their community. This is information provided by the community, not your personal data. When you open such links you leave the app; the privacy provisions of the respective provider then apply. The app points this out before opening.
The legal basis is Art. 6(1)(b) GDPR (performance of a contract) for the basic membership administration and Art. 6(1)(a) GDPR (consent) for the optional location sharing.
Chat and messages
The app offers a chat function for private messages and group chats (also within communities). The following data is processed:
- Text messages
- Voice messages (audio recordings)
- File attachments (images and other files)
- Time stamps of the messages
- Delivery and read markers per chat (up to which message you have received or read, with the time) — they are stored on our server so that your reading position is the same on all your devices
- Emoji reactions to messages (stored with your user identifier; visible to all chat participants)
- Reply references (when replying to a message, the identifier and a short excerpt of the original message are linked to your reply)
- Markings with a star (visible only to you) as well as muting and pinning of chats (your setting per chat, on all your devices)
- Pinned messages in group and community chats (who pinned them, until when; visible to all members)
- For group chats: group name, description, optional group picture, creator, creation date and member list
Read receipts: Other chat participants see on their messages whether you have received them (grey double tick) and read them (blue double tick); in groups only once all members have read them, and in the message info also with names and times. You can switch off read receipts in the settings — then neither do others see your reading position nor you theirs. The delivery confirmation remains unaffected by this.
One-time view: Images and videos can be sent in such a way that the recipient can open them only once. We store who opened such a file and when, and do not deliver it again afterwards; once it has been opened by all recipients, or at the latest after 30 days, the file is deleted. The app prevents screenshots in this view insofar as the operating system permits it; it cannot prevent the content being photographed with another device.
Polls: Polls can be created in group and community chats. What is stored is the question, the answer options, the creating person, the end of the poll as well as your vote with the time. Whether the names of the participants are visible to the other members or the poll runs anonymously is determined by the creating person when setting it up; in an anonymous poll, other members see only the number of votes. For us as the operator, the attribution of your vote remains identifiable in the database even then.
Mentions: You can mention other members with @username and, in groups, all members with @all. Those mentioned receive a notification even if they have muted the chat.
Shared posts: If a community post is shared into a chat, only the identifier of the post travels with it; the preview is built up at the recipient’s end with the recipient’s own permissions. Content of a community that the recipient would not be allowed to see is not displayed to them in this way either.
Stickers: Stickers come exclusively from collections provided by us; your own stickers cannot be uploaded. Which stickers you last used is stored only on your device.
Blocking: If you block a user, they can no longer write to you even in private chats that already exist.
Notifications: Push notifications about new messages carry the name of the chat or of the sender and an excerpt of the message. In muted chats your device receives only an invisible notification which retrieves the message in the background.
Display of the sender: If a member leaves a chat or their account is deleted, they are displayed as “Unknown” on their previous messages.
Group chats can be created by any user. Whether you can be added to groups by other users is controlled by you via the privacy setting “Group invitations” in your profile. If the creator leaves a group, the administration automatically passes to the member who has been involved the longest.
The microphone permission (RECORD_AUDIO) is required for voice messages. Recording takes place exclusively upon your express action (holding down the record button). No automatic or background audio recording takes place.
Chat messages are stored on our server and additionally cached locally on your device in an encrypted database (Room/SQLite).
The legal basis is Art. 6(1)(b) GDPR (performance of a contract).
Tickets and reports
Via the ticket system you can address matters to your community or to the BikeMates team and report users or content. For each ticket we store: category and subject, your messages including attachments (images, videos, documents, voice messages), the reference (e.g. the reported post, user or the order) as a snapshot of text and metadata — never a copy of images or videos —, the parties involved, the handler and the history (status changes, forwardings) with time stamps.
Who sees what: A ticket addressed to a community is seen by its authorised administrators; in the case of reports, your identity remains hidden from the community (pseudonymous). If a case is forwarded to the BikeMates team or is addressed to it, the staff of the operator team see it. Internal notes made by the handlers are not visible to you. Reports relating to child protection always go to the BikeMates team.
Diagnostic logs: You can voluntarily attach technical logs from your app to a ticket addressed to the BikeMates team (e.g. calibration data of the lean angle measurement or a measurement recording which contains the position trail of the ride concerned). Before attaching, the app shows what a log contains; nothing is sent along automatically. These logs can be downloaded exclusively by staff of the operator team; they are not passed on to communities.
Retention: Closed tickets are deleted six months after closure, including attachments. The BikeMates team can put a case on hold to preserve evidence (for example in the case of criminal content or to safeguard legal claims); cases put on hold are retained with a snapshot of the identities involved until the reason no longer applies, and are excluded from the deletion of the account.
The legal basis is Art. 6(1)(b) GDPR for your own matters and Art. 6(1)(f) GDPR (legitimate interest in maintaining the security of the platform) for reports and the preservation of evidence.
User suspension and blocking
You can block other users. In addition, community administrators can remove or suspend members from their community, and the BikeMates team can suspend an account temporarily or permanently. The suspension information (reason, duration, who imposed the suspension) is stored on the server; in the case of an account suspension, all sessions are terminated and push notifications are discontinued, and the next time you sign in you will see the reason and the end of the period.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the security of the platform).
10. Shop and payment processing
Integrated shop
The app contains an integrated shop through which both we (as the app operator) and community operators (as independent third-party sellers) can offer products. When you use the shop, the following data is processed:
- Delivery address (name, street, postcode, town, country, optionally: telephone number, company, address supplement)
- Invoice address (if different)
- Order history and order details
- Shopping basket data
- IP address at the time of the order (for the detection of misuse and the statutory documentation obligation)
- Acceptance of the general terms and conditions and the cancellation policy (incl. version status)
This data is necessary for the performance of the contract. The legal basis is Art. 6(1)(b) GDPR.
Payment processing via Stripe
Payment processing in the shop is carried out via the payment service provider Stripe Inc., 510 Townsend Street, San Francisco, CA 94103, USA (hereinafter “Stripe”).
In the case of a purchase, the following data is transmitted to Stripe:
- Payment amount and currency
- Payment method (credit card, Google Pay, etc.)
- Metadata (order number, user ID)
Your complete payment data (e.g. credit card number) is processed exclusively by Stripe and is never stored on our servers. From Stripe we receive merely a confirmation ID (Payment Intent ID).
Stripe processes data in the USA, among other places. The data transfer is carried out on the basis of standard contractual clauses (Art. 46(2)(c) GDPR). Further information on data protection at Stripe can be found at: https://stripe.com/de/privacy.
The legal basis is Art. 6(1)(b) GDPR (performance of a contract).
Invoicing
For completed orders, invoices are created which contain your invoice address, order details and payment information. These invoices are stored as PDF files on our server and can be downloaded via the app.
The storage is carried out on the basis of statutory retention obligations (Art. 6(1)(c) GDPR, in particular § 257 HGB, § 147 AO) for a period of 10 years.
Disclosure of data to the seller (community operator)
Since the shop is a marketplace in which various community operators can act as independent sellers, we transmit your order data (in particular your name, your delivery and invoice address as well as the details of the products ordered) to the respective community operator from whom you purchase the product. This is strictly necessary so that the seller can process your order, pack the goods and dispatch them to you. If you purchase a product directly from us (the app operator), this disclosure to a third-party seller does not apply.
The legal basis for this transfer is Art. 6(1)(b) GDPR (performance of the purchase contract).
Disclosure of data to shipping service providers
For the purpose of delivering the goods ordered, we (or the respective seller) pass on your delivery address and your name to the transport company commissioned with the delivery (e.g. DHL, DPD, UPS, GLS or Hermes). Insofar as this is necessary for the announcement of the delivery, we also pass on your e-mail address and/or telephone number, provided that you have consented to this or that it is necessary for the performance of the contract.
The legal basis for this disclosure is Art. 6(1)(b) GDPR (performance of a contract).
Payout and partner connection via Stripe Connect (for sellers)
For community operators who offer products in the shop, we use the Stripe Connect service of Stripe Inc. (or Stripe Payments Europe Ltd.) for the processing of payouts and the connection of the seller accounts. In this process your Stripe account ID, payout and identification data are transmitted to Stripe and processed there.
The legal basis for this is Art. 6(1)(b) GDPR (performance of a contract).
11. Push notifications and in-app purchases
Firebase Cloud Messaging (FCM)
The app uses Firebase Cloud Messaging (FCM) of Google Ireland Limited for sending push notifications. When you register for push notifications, a device-specific FCM token is generated and stored on our server. Via this token we can send you notifications, e.g.:
- New chat messages
- Community notifications (new posts, applications)
- Friend requests and location updates
- Notifications in the event of accidents involving your emergency contacts
- System and status notifications
The FCM token is renewed with every app update. No message content is transmitted via Google servers – the push message contains merely a signal, whereupon the app retrieves the actual data directly from our server.
Further information on data protection at Firebase: https://firebase.google.com/support/privacy.
The legal basis is your consent (Art. 6(1)(a) GDPR), which you give by granting the notification permission.
Firebase Crashlytics
The app can optionally use Firebase Crashlytics of Google Ireland Limited in order to collect crash reports and error logs. This function is deactivated by default and is used only after you have expressly activated it.
When activated, the following data is transmitted to Google servers:
- Device type and operating system version
- App version
- Crash stack traces and error messages
- Time stamp of the crash
No personal data such as name, e-mail or location is transmitted to Crashlytics. The legal basis is your consent (Art. 6(1)(a) GDPR).
In-app purchases (Google Play Billing)
Via Google Play Billing, the app offers the possibility of purchasing a GoldBiker membership as an in-app purchase. The purchase is processed entirely via Google Play. From Google we receive merely:
- Product ID of the item purchased
- Purchase token (unique purchase identifier)
- Purchase status
The purchase token is stored on our server in order to prevent multiple use and to activate the membership. Your payment information (credit card, PayPal, etc.) is processed exclusively by Google and is not transmitted to us.
The legal basis is Art. 6(1)(b) GDPR (performance of a contract). Further information: https://policies.google.com/privacy.
12. Photo upload, documents and vehicle registration document
The app makes it possible to upload photos and videos for your profile picture, your motorcycles, community posts, chat attachments and tickets, as well as documents (e.g. PDF) in chats and tickets. Images are selected via the photo picker of your device, cropped or reduced in size on the device and then transmitted to our file server; there they are checked for malware and stored in several sizes. The app does not take any photos itself.
Uploaded files can be retrieved via signed addresses which only the recipients of the respective message or the authorised viewers of a post receive. If you delete a message, a post or your account, the associated files are removed; files that are also used in further messages (forwarding to several chats) are retained for as long as one of these messages exists.
The legal basis is your consent (Art. 6(1)(a) GDPR), which you give by selecting and uploading.
Vehicle registration document (Zulassungsbescheinigung Teil I)
You can create a motorcycle from your vehicle registration document or add the details from the vehicle registration document to an existing motorcycle. The procedure:
- The document is captured with the document scanner of Google ML Kit, which is part of the Google Play services on your device; it detects the edges of the sheet, rectifies the image and passes it to the app. The processing by this scanner takes place on your device.
- The rectified image is transmitted to our file server and evaluated there with our own text recognition (Tesseract) — no external AI service, no disclosure to third parties. If the server-side recognition is not available, the app recognises the text on the device instead (Google ML Kit text recognition, model from the Google Play services, processing on the device).
- What is evaluated and stored is exclusively vehicle data: key numbers (HSN/TSN), registration number, vehicle identification number, date of first registration, manufacturer, type and trade designation, vehicle class, cubic capacity, power output and rated engine speed, top speed, masses, seats, axles, fuel, emission class, tyres as well as remarks and tyre approvals from field 22. The name and address of the keeper are neither recognised nor stored. We match key numbers against our vehicle catalogue in order to determine the manufacturer and model reliably. All recognised details are displayed to you for checking before they are saved and can be changed or deleted at any time.
- The image of the vehicle registration document is retained on our file server and assigned to your motorcycle — as evidence and in order to be able to trace recognition errors. It lies outside the normal media area: there is no retrievable address for it, no preview images and no delivery to other users. It can be viewed exclusively by administrators of the BikeMates team; every access is logged. By its nature, the image also contains the keeper’s data printed on the document.
- The images are deleted when your account is deleted. You can also request the deletion of an image separately at any time (datenschutz@bikemates.eu).
The legal basis is your consent (Art. 6(1)(a) GDPR), which you give by starting the scan; for the retention of the image, our legitimate interest in the traceability of the vehicle details (Art. 6(1)(f) GDPR). Information on Google ML Kit: https://developers.google.com/ml-kit/terms.
13. Group rides (tours)
The app offers a group ride function in which a Ride Leader creates a route and other participants can follow this route. During a group ride, the location data of all participants is transmitted to our server in real time and displayed to the other participants of the tour.
Participation in a group ride is voluntary. The legal basis is your consent (Art. 6(1)(a) GDPR).
14. Data transfer to third countries
When certain services are used, personal data is transferred to countries outside the European Union (EU) or the European Economic Area (EEA), in particular to the USA. This concerns the following services:
- Firebase Authentication, Firebase Cloud Messaging, Firebase Crashlytics, Firebase Analytics – Google Ireland Limited (data processing also in the USA by Google LLC)
- Google Play Billing – Google LLC, USA
- Apple Sign-In – Apple Inc., USA (when using the Apple sign-in)
- Stripe – Stripe Inc., USA (when using the shop)
The transfer of data to the USA is carried out on the basis of standard contractual clauses pursuant to Art. 46(2)(c) GDPR and/or on the basis of the EU-US Data Privacy Framework (adequacy decision pursuant to Art. 45 GDPR), insofar as the respective recipient is certified.
For Google services the following additionally applies: https://policies.google.com/privacy
For Stripe the following applies: https://stripe.com/de/privacy
For Apple the following applies: https://www.apple.com/de/privacy/
15. Summary of the app permissions
The app requests the following permissions, in each case only when needed:
- Location (precise, also in the background) – ride recording, navigation, location sharing, crash detection
- Bluetooth (scan, connection) – connection to the PerformanceTracker sensor, TPMS sensors and Bluetooth accessories
- Camera – capture of your vehicle registration document with the document scanner; beyond that the app does not access the camera
- Microphone – recording of voice messages in the chat
- Contacts (read) – selection of emergency contacts from the address book
- SMS (send) – automatic sending of an SMS when an accident is detected
- Notifications – receipt of push notifications
- Foreground service – ride recording, navigation and video export in the background
- Battery optimisation exception (optional) – so that the recording is not interrupted when power saving mode is active; can be declined
- Detect screen capture – notice in the one-time view when a screenshot is attempted; nothing is stored in the process and nobody is notified
- Screen overlay – display of the accident alert on top of other apps
- Media library (write) – saving exported time-lapse videos in the folder “Movies/BikeMates”
All permissions are requested individually and with an explanation. You can withdraw each permission at any time in the system settings of your device. Please note that some functions of the app are not available, or only available to a limited extent, without the corresponding permissions.
16. Local data storage on the device
The app stores certain data locally on your device:
- Authentication hash – in the SharedPreferences for automatic sign-in
- Chat messages – in a local Room/SQLite database for offline availability
- Petrol station and POI data – in a local database for offline display
- Map data cache – PMTiles blocks for faster map loading
- Sensor calibration data – IMU calibration values for precise measurements
- App settings – your personal settings (e.g. dark mode, units), kept separately per account
- Recording queue – ride segments not yet transmitted (until the upload succeeds), assigned to the respective account
- Detection and calibration logs – accident events and diagnostic files of the lean angle measurement, which are transmitted only upon your action (see sections 7 and 9)
- Exported videos – in the folder “Movies/BikeMates” of your device
When the account is changed on the same device, account-related caches (chat database, emergency contacts, profile data) are deleted or are kept only for the respective account. Data from the device-to-device transfer and cloud backups of Android are excluded for this app.
This local data is deleted automatically when the app is uninstalled. The data stored on the server remains unaffected by this and can be removed by means of a deletion request.
17. Friendship system and social functions
Adding friends
You can send friend requests to other users. In the case of a friendship, the user IDs of both users are linked on the server. Friends can see your profile, follow your location (if released) and send you messages.
The legal basis is Art. 6(1)(b) GDPR (performance of a contract).
Profile visitors
If another user views your profile, this is stored together with the user ID of the visitor and the time of the visit. You can see who has visited your profile. This function serves social interaction and can be restricted via the privacy settings in your profile.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in promoting social interaction).
Motorcycle sharing
You can share a motorcycle stored in the app with other users. In doing so, a link is created between your motorcycle and the user account of the recipient. The recipient can display the shared motorcycle in their profile and use it for ride recordings.
The legal basis is your consent (Art. 6(1)(a) GDPR).
Ride start notifications
GoldBiker members can have themselves notified when a friend starts a ride. For this purpose, an assignment (subscription) between your account and the friend’s account is stored on the server. When you start a ride, a push notification is sent to subscribed friends.
The activation of this function is voluntary. The legal basis is your consent (Art. 6(1)(a) GDPR).
Events
The app supports live events in which the organiser shares their location in real time with participants. Participants can see the live position of the organiser on a map via an event link. In doing so, the location of the organiser is retrieved from the server and displayed.
The legal basis is the consent of the organiser (Art. 6(1)(a) GDPR).
18. Firebase Analytics
The app integrates Firebase Analytics of Google Ireland Limited. Firebase Analytics is deactivated by default and in this state does not collect any data. A future, optional activation would collect anonymised usage statistics in order to improve the quality of the app.
In the event of activation, the following data would be transmitted to Google servers:
- App usage events (e.g. screen views, feature use)
- Device type and operating system version
- App version
- Anonymised user identifiers
The advertising ID (AD_ID) is expressly NOT collected by the app (the permission com.google.android.gms.permission.AD_ID has been removed). No tracking for advertising purposes takes place.
The legal basis is your consent (Art. 6(1)(a) GDPR). Further information: https://firebase.google.com/support/privacy.
19. Prize draws
Time-limited prize draws may be offered in the app. Participation is voluntary and takes place exclusively through your active registration (“Take part”) in the app; without registering you do not take part and no prize-draw-related data relating to you is stored.
If you take part, the following data is processed:
- Participation status and time of registration or deregistration
- The kilometres ridden during the promotional period with an active ride recording and the chances of winning calculated from them (“tickets”)
- Bonus status (e.g. membership of a participating community, insofar as the respective prize draw provides for a bonus)
- In the event of a win: the contact details required to process the prize
To prevent misuse, ride recordings are checked automatically for plausibility (e.g. speed and route characteristics). Conspicuous recordings can be excluded from the allocation of tickets; your ride recording itself remains unaffected by this. The legal basis for this is Art. 6(1)(f) GDPR (legitimate interest in a fair execution).
At the start of a prize draw, a notice may be sent as a push notification to all users of the app — that is, also if you are not (yet) taking part. You can deactivate these notices in the app settings (“No prize draw notifications”); irrespective of this, push notifications can be switched off at any time in the system settings of your device (see the section “Push notifications”). You can end your participation in the app at any time.
Once a prize draw has been concluded, the prize-draw-related data is deleted or anonymised as soon as it is no longer required for the processing and no statutory retention obligations stand in the way.
The legal basis of the processing is the execution of the prize draw upon your registration (Art. 6(1)(b) GDPR). For individual prize draws, separate conditions of participation and privacy information apply in addition, which are published on the respective prize draw page.
20. Referral programme – refer a friend
Referral links and attribution of a registration
You can share a personal referral link. If someone registers via this link, the registration is attributed to you and both sides receive a reward. The attribution takes place exclusively upon the initial registration and is not changed subsequently.
The following is stored in the process: the referral code used, the time of the attribution as well as the identifier of the referring account. For the calculation of the rewards, the kilometres covered by the referred account are additionally taken into account.
The legal basis is the execution of the referral programme at your instigation (Art. 6(1)(b) GDPR).
Technical attribution of the click (first-party matching)
On Android, the referral code is passed on via the installation reference provided by the app store; separate processing by us is not required for this.
On iOS, this route is not available. So that a referral can nevertheless be attributed, when a referral link is clicked we briefly store a pseudonymised identifier: from technical details of your device request, an irreversible checksum (HMAC) is formed using a secret key that is not stored in the database. The underlying details themselves — in particular the complete IP address — are not stored in the process; with IPv6, moreover, only the network portion (the first 64 bits) is included, not the complete address.
When the app is first launched, the same checksum is formed again and compared with those stored. If they match, the referral code is adopted. No conclusions about your person or your IP address can be drawn from the stored checksum.
These checksums are deleted automatically after 48 hours at the latest. They are not combined with other data, passed on to third parties or used for advertising or analysis purposes.
The legal basis is our legitimate interest in the reliable settlement of the referral programme and in preventing abusive claims to rewards (Art. 6(1)(f) GDPR).
21. User administration by the operator team
Staff of the BikeMates team (administrators and moderators) have access to a user administration area in order to safeguard the security of the platform and to process requests. The following can be viewed there: account data (user name, display name, rank, registration date, membership status, suspensions, scheduled deletions; the e-mail address only for administrators), community memberships and ranks, your motorcycles including the details from the vehicle registration document as well as an overview of the files you have uploaded. Images of vehicle registration documents can be opened only by administrators.
Interventions by the team — suspending and unsuspending, scheduling or revoking an account deletion, granting or withdrawing the GoldBiker membership, community assignments, changes to motorcycle data, the opening of an image of a vehicle registration document — are recorded in a log with the time, the acting person and the person concerned. This log serves traceability and is retained with a snapshot of the name even after an account has been deleted.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a secure and traceable operation of the platform).
Last updated: 21 September 2026