Version: 2026-08-09 Effective date: 2026-08-09 Last updated: 2026-08-09 Controller: E. zona, MB (trading as "FabiRide"), Tvirtovės al. 88, Kaunas, Lithuania · contact info@fabiride.com
This policy explains what data FabiRide ("we") collects when you use the FabiRide mobile app, the FabiRide display, the FabiRide smart battery, and the cloud services that connect them, and what your rights are under the EU General Data Protection Regulation (GDPR).
In short: we collect the minimum data needed to run your account, your bike and your warranty. We never sell your data. EU customer data is stored in EU data centres. You can export or delete everything at any time.
| Category | Examples | Why we need it | Legal basis |
|---|---|---|---|
| Account | Email, first and last name, password hash (or Apple sign-in identifier), phone, country (optional) | Identify you, contact you, sign you in | Contract (Art. 6(1)(b)) |
| Terms acceptance | Which version of the Terms and Privacy Policy you accepted, and when | Prove lawful consent and contract formation | Legal obligation + legitimate interest |
| Sign-in provider | Apple account identifier (sub) and the email Apple relays, when you use "Sign in with Apple" |
Let you log in without a password | Contract |
| Display registration | Display serial number, purchase shop, invoice scan, claim date | Warranty + theft chain-of-custody | Contract + legal obligation (10 yr invoice retention, LT Accounting Law) |
| Location & maps | GPS trail (only while you record a trip or share live location), and the map area you view. Maps are rendered by Apple Maps (iOS) / Google Maps (Android). | Show your rides, your route, your bike's live location on a map | Consent (Art. 6(1)(a)) for GPS |
| Bike telemetry | Speed, distance, odometer, battery state, motor/controller temperature, power and current, ride and session statistics | Show you your rides, your range, your bike's health | Contract |
| Bike configuration | Controller make and settings, limits and caps, calibration values, riding modes, rider-access caps | Sync your setup across devices, restore it after a display swap, support you | Contract |
| Voice chat | Live microphone audio during a crew voice session (streamed, not recorded by us), your display name in the room | Push-to-talk group voice with riders you invite | Consent (Art. 6(1)(a)) |
| Now-playing | The title + artist text of the track your phone is playing (from any music app, e.g. Spotify / Apple Music) | Look up cover art to show on the display | Consent / legitimate interest |
| Emergency contacts | Names, phone numbers and emails of the contacts you choose to add for crash SOS | Alert them by SMS if a crash is detected | Consent, and vital interests (Art. 6(1)(d)) when sending a crash alert |
| Camera | A QR code you scan (rider invites, display serial numbers). Images are processed on-device and not stored. | Scan invites and serials | Contract |
| Firmware & updates | Firmware version, hardware revision, last-seen time, IP for over-the-air (OTA) updates | Push updates, support tickets | Legitimate interest |
| Email & push notifications | Your email, and (if enabled) push token | Verification, password reset, ownership transfers, optional alerts | Contract + consent for marketing |
| Diagnostics & logs | App and firmware logs, BLE link quality, firmware fault and crash reports captured on the display and uploaded by your phone, administrative audit log | Fix bugs, support, security | Legitimate interest |
| Support messages | What you write to us, plus — only if you tick the box — your bike name, model, serial, firmware version, protocol and recent activity log | Answer your support request | Contract + consent for the attached details |
| Security events | Tamper and source-code-extraction detections on a display, failed-auth patterns, ownership-dispute records | Anti-theft, protecting our hardware and other riders | Legitimate interest |
We do not knowingly collect data from children under 16. If we learn we have, we delete it.
We do not carry out automated decision-making that produces legal effects for you, within the meaning of Art. 22 GDPR. Automated limits — such as rate limiting or a tamper lock-out — are technical protections, and you can always reach a human at info@fabiride.com.
This is the part most people miss, so it gets its own section.
If you ride a bike that someone else owns in FabiRide — you were invited as a shared rider or shared admin — then the owner of that bike can see the data that bike produces while you ride it, including its GPS trail, its live location, ride history, speed, and telemetry. The owner also sets the limits your account rides under.
We share data only with the parties below, each under a GDPR-compliant Data Processing Agreement where applicable. The full, current list is at https://my.fabiride.com/legal/subprocessors.
We will never share your location, ride history, voice, or telemetry with insurers, employers, or advertisers without your explicit opt-in.
| Data | How long |
|---|---|
| Account profile | Until you delete it (right to erasure, see §7) |
| Terms-acceptance record | 10 years after account closure (evidence of consent) |
| Invoice + sales-chain rows | 10 years from sale (Lithuanian Accounting Law) |
| Telemetry / ride & GPS history | While the device is registered to you, or 30 days after you remove it |
| Voice chat audio | Not retained — relayed live only |
| Emergency contacts | Until you remove them or delete your account |
| Diagnostics + firmware fault logs | 90 days, then aggregated |
| Security / tamper event records | 7 years (anti-theft, legal claims) |
| Administrative audit log | 7 years (compliance) |
| Email-server logs | 30 days |
The mobile app uses local storage only (on your phone) — no third-party tracking or advertising SDKs. The web portal sets a single session cookie holding your refresh token (HttpOnly, Secure, SameSite=Strict). We use no advertising or analytics cookies, which is why you are not asked for cookie consent.
You have the right to:
info@fabiride.com, or in-app: Settings → My account → Export my data).Requests are handled within 30 days (extendable to 90 for complex ones).
firmware.bin cannot be reflashed onto another device, and a source-code-extraction attempt permanently disables the display (see the Terms).info@fabiride.com if you suspect a problem.All primary data is processed within the EU/EEA. Limited US transfers — app-store telemetry, push-notification routing, cover-art lookup (Apple/Deezer) and Google Maps tiles on Android — are covered by the EU–US Data Privacy Framework and/or Standard Contractual Clauses.
We reserve the right to update this policy at any time, for example when we add features, change providers, or the law changes. The current version always lives at https://my.fabiride.com/legal/privacy and in the App under More ▸ Help & support ▸ Legal, and carries a version date at the top.
For material changes — a new purpose, a new category of data, a new recipient — we will notify you in-app or by email at least 30 days before they take effect, and where the law requires it we will ask for fresh consent. Clarifications and minor corrections take effect when published. If you do not accept a change, you can delete your account before it takes effect.
info@fabiride.com · E. zona, MB (FabiRide) · Tvirtovės al. 88, Kaunas, Lithuania
Related documents: Terms & conditions · GDPR statement · Sub-processors · Delete your account