Privacy Policy
Last updated: 14 September 2026 · Effective: 14 September 2026
The short version: we keep the minimum needed to run your account and your rides. We never record your voice. Your location is shared only while a ride you joined is running, and only with the riders on that ride. We give nothing to third parties for advertising or analytics and we sell nothing. You can delete your account permanently from inside the app.
On this page
1. Who is responsible
Rider OS is a mobile app for group motorcycle rides. The data controller for the purposes of this policy is Rider OS. For any privacy request, write to privacy@rideros.com.tr.
Riders in Türkiye can also read our disclosure under Turkish data protection law (KVKK) on the KVKK Aydınlatma Metni page.
2. What we process
| Data | Why we process it |
|---|---|
| Email address and password | Creating your account and signing you in. We never see the password; our authentication provider stores it hashed. |
| Profile: username, display name, language and unit preference, optional avatar URL | So other riders recognise you during a ride, and so the interface and notifications use your language and units. |
| Ride records: title, join code, invite token, status, members with their join and leave times, roles | Running the ride, showing who joined and enforcing who is allowed to do what. |
| Live location: latitude, longitude, heading, speed, accuracy and timestamp | So the group can see each other on the map during a ride. See section 3. |
| Ride summary: duration, distance, a representative route line and the roster | The summary you see in your history once a ride ends. The route line is a single representative track (usually the leader's or the owner's), stored downsampled. |
| Ride events: an SOS record and the last known position at the moment it fired | So the whole group sees the call for help, and so it is clear afterwards what happened. |
| Push token | Sending notifications to your device when a ride starts, ends or somebody triggers an SOS. |
| Technical logs: IP address, request path, timestamp, app and device version | Keeping the service up, debugging, and preventing abuse and request floods. Deleted automatically after a short period. |
3. Location data
Location is the most sensitive thing Rider OS handles, so it gets its own section.
- Collected only while a ride is running. Sharing starts when a ride you joined goes live and stops when the ride ends or you leave it.
- Shared only with that ride's members. Nobody outside the ride can see where you are. There is no public map.
- It keeps flowing while the app is in the background. That is deliberate: the group needs to see you even with the phone in your pocket. Background tracking stops when the ride ends.
- Live position is not stored permanently. During a ride it lives in an in-memory store (Redis), is deleted when the ride ends, and expires on its own within 8 hours at the latest.
- What remains is a summary. After a ride we keep the duration, the distance and one downsampled route line representing the ride. Only that ride's participants can see it.
- You can withdraw the permission at any time. Turn location off in your system settings and you simply stop appearing on the map; voice keeps working.
4. Voice
Group voice is relayed in real time. Conversations are never recorded or stored. All the voice server knows is who is connected to a ride (user id and display name). Voice traffic is encrypted in transit.
We cannot, however, technically prevent other participants from recording on their own devices. Treat a group channel accordingly.
5. What we do not collect
- No advertising identifiers, tracking pixels or third-party analytics SDKs.
- No access to contacts, photo library, calendar or messages.
- No location outside a ride, and none while the app is closed.
- We never sell your data or use it for advertising.
- No tracking cookies on this website; your language choice stays in your browser.
6. App permissions
- Microphone: required for group voice.
- Location (during a ride, including in the background): for the live map and SOS. You can decline it; voice still works, you just do not appear on the map.
- Notifications: for ride-started, ride-ended and SOS alerts. On Android it is also needed for the ongoing notification shown while voice runs in the background.
- Bluetooth (Android): to route audio to your intercom.
- Camera: used only to scan a ride's QR code. No image is recorded or sent anywhere.
7. Legal bases
Under GDPR Article 6 and Turkish KVKK Article 5 we rely on:
- Performance of a contract: account, profile, ride records, the voice channel and the ride summary — the service cannot work without them.
- Consent: location data and notifications. You grant these through your operating system and can withdraw them at any time.
- Legitimate interests: technical logs, abuse prevention and the security of the service.
8. Sharing and service providers
We share nothing for marketing. To run the service we use only these providers:
| Provider | What for | Where |
|---|---|---|
| Supabase | Authentication and database (account, profile, ride records, ride summaries) | Switzerland (Zurich) |
| Our own servers | Application server, voice server and the in-memory store holding live positions | Türkiye |
| Expo Push, Apple APNs, Google FCM | Delivering notifications to your device | USA / global |
| Apple TestFlight and the App Store | Distributing the app | USA / global |
These transfers are necessary to provide the service and are covered by the providers' standard contractual clauses and security commitments. We may disclose data to authorities where a court order or legal obligation requires it.
9. Retention and deletion
- Account and profile: until you delete your account.
- Ride records and summaries: until your account is deleted.
- Live location: deleted when the ride ends, and in any case within 8 hours.
- Voice: never stored.
- Push tokens: removed when you sign out, turn notifications off or delete your account.
- Technical logs: rotate out automatically after a short period.
You can delete your account inside the app: Account → Delete account. That permanently removes your profile, the rides you created, your membership in other rides, your ride summaries and your push tokens, and deletes your authentication record at the same time. It cannot be undone and needs no support ticket.
A ride with several participants still means something to the others, so a record of it may remain in their history with your name and track removed.
10. Your rights
Under GDPR and KVKK you have the right to access your data, to be told why it is processed, to have it corrected, to have it deleted, to object to processing, to restrict it, to data portability, and to learn which third parties received it. You may also lodge a complaint with your supervisory authority.
Deletion is available in the app, immediately and by yourself. For anything else, write to privacy@rideros.com.tr; we answer within 30 days.
11. Children
Rider OS is not designed for people under 16, and we do not knowingly collect their data. If we learn we hold data about someone under 16, we delete it.
12. Changes
If this policy changes, the date above changes with it. Significant changes — such as processing a new category of data — are announced in the app before they take effect.
13. Contact
Privacy: privacy@rideros.com.tr
Anything else: support@rideros.com.tr