Privacy policy

Version: 2026-08-09 Effective date: 2026-08-09 Last updated: 2026-08-09 Controller: E. zona, MB (trading as "FabiRide"), Tvirtovės al. 88, Kaunas, Lithuania · contact info@fabiride.com

This policy explains what data FabiRide ("we") collects when you use the FabiRide mobile app, the FabiRide display, the FabiRide smart battery, and the cloud services that connect them, and what your rights are under the EU General Data Protection Regulation (GDPR).

In short: we collect the minimum data needed to run your account, your bike and your warranty. We never sell your data. EU customer data is stored in EU data centres. You can export or delete everything at any time.

1. Data we collect

Category Examples Why we need it Legal basis
Account Email, first and last name, password hash (or Apple sign-in identifier), phone, country (optional) Identify you, contact you, sign you in Contract (Art. 6(1)(b))
Terms acceptance Which version of the Terms and Privacy Policy you accepted, and when Prove lawful consent and contract formation Legal obligation + legitimate interest
Sign-in provider Apple account identifier (sub) and the email Apple relays, when you use "Sign in with Apple" Let you log in without a password Contract
Display registration Display serial number, purchase shop, invoice scan, claim date Warranty + theft chain-of-custody Contract + legal obligation (10 yr invoice retention, LT Accounting Law)
Location & maps GPS trail (only while you record a trip or share live location), and the map area you view. Maps are rendered by Apple Maps (iOS) / Google Maps (Android). Show your rides, your route, your bike's live location on a map Consent (Art. 6(1)(a)) for GPS
Bike telemetry Speed, distance, odometer, battery state, motor/controller temperature, power and current, ride and session statistics Show you your rides, your range, your bike's health Contract
Bike configuration Controller make and settings, limits and caps, calibration values, riding modes, rider-access caps Sync your setup across devices, restore it after a display swap, support you Contract
Voice chat Live microphone audio during a crew voice session (streamed, not recorded by us), your display name in the room Push-to-talk group voice with riders you invite Consent (Art. 6(1)(a))
Now-playing The title + artist text of the track your phone is playing (from any music app, e.g. Spotify / Apple Music) Look up cover art to show on the display Consent / legitimate interest
Emergency contacts Names, phone numbers and emails of the contacts you choose to add for crash SOS Alert them by SMS if a crash is detected Consent, and vital interests (Art. 6(1)(d)) when sending a crash alert
Camera A QR code you scan (rider invites, display serial numbers). Images are processed on-device and not stored. Scan invites and serials Contract
Firmware & updates Firmware version, hardware revision, last-seen time, IP for over-the-air (OTA) updates Push updates, support tickets Legitimate interest
Email & push notifications Your email, and (if enabled) push token Verification, password reset, ownership transfers, optional alerts Contract + consent for marketing
Diagnostics & logs App and firmware logs, BLE link quality, firmware fault and crash reports captured on the display and uploaded by your phone, administrative audit log Fix bugs, support, security Legitimate interest
Support messages What you write to us, plus — only if you tick the box — your bike name, model, serial, firmware version, protocol and recent activity log Answer your support request Contract + consent for the attached details
Security events Tamper and source-code-extraction detections on a display, failed-auth patterns, ownership-dispute records Anti-theft, protecting our hardware and other riders Legitimate interest

We do not knowingly collect data from children under 16. If we learn we have, we delete it.

2. What we do with the data

We do not carry out automated decision-making that produces legal effects for you, within the meaning of Art. 22 GDPR. Automated limits — such as rate limiting or a tamper lock-out — are technical protections, and you can always reach a human at info@fabiride.com.

3. Shared bikes: what the owner can see

This is the part most people miss, so it gets its own section.

If you ride a bike that someone else owns in FabiRide — you were invited as a shared rider or shared admin — then the owner of that bike can see the data that bike produces while you ride it, including its GPS trail, its live location, ride history, speed, and telemetry. The owner also sets the limits your account rides under.

4. Sharing & third parties

We share data only with the parties below, each under a GDPR-compliant Data Processing Agreement where applicable. The full, current list is at https://my.fabiride.com/legal/subprocessors.

We will never share your location, ride history, voice, or telemetry with insurers, employers, or advertisers without your explicit opt-in.

5. Retention

Data How long
Account profile Until you delete it (right to erasure, see §7)
Terms-acceptance record 10 years after account closure (evidence of consent)
Invoice + sales-chain rows 10 years from sale (Lithuanian Accounting Law)
Telemetry / ride & GPS history While the device is registered to you, or 30 days after you remove it
Voice chat audio Not retained — relayed live only
Emergency contacts Until you remove them or delete your account
Diagnostics + firmware fault logs 90 days, then aggregated
Security / tamper event records 7 years (anti-theft, legal claims)
Administrative audit log 7 years (compliance)
Email-server logs 30 days

6. Cookies & similar

The mobile app uses local storage only (on your phone) — no third-party tracking or advertising SDKs. The web portal sets a single session cookie holding your refresh token (HttpOnly, Secure, SameSite=Strict). We use no advertising or analytics cookies, which is why you are not asked for cookie consent.

7. Your rights under GDPR

You have the right to:

Requests are handled within 30 days (extendable to 90 for complex ones).

8. Security

9. International transfers

All primary data is processed within the EU/EEA. Limited US transfers — app-store telemetry, push-notification routing, cover-art lookup (Apple/Deezer) and Google Maps tiles on Android — are covered by the EU–US Data Privacy Framework and/or Standard Contractual Clauses.

10. Changes to this policy

We reserve the right to update this policy at any time, for example when we add features, change providers, or the law changes. The current version always lives at https://my.fabiride.com/legal/privacy and in the App under More ▸ Help & support ▸ Legal, and carries a version date at the top.

For material changes — a new purpose, a new category of data, a new recipient — we will notify you in-app or by email at least 30 days before they take effect, and where the law requires it we will ask for fresh consent. Clarifications and minor corrections take effect when published. If you do not accept a change, you can delete your account before it takes effect.

11. Contact

info@fabiride.com · E. zona, MB (FabiRide) · Tvirtovės al. 88, Kaunas, Lithuania

Related documents: Terms & conditions · GDPR statement · Sub-processors · Delete your account