This policy explains, in detail, what data the Velaris Bike app collects, why, how we use it, who we disclose it to, how long we keep it, and what rights you have, including your rights under Regulation (EU) 2016/679 (GDPR), Romanian law (Law 190/2018), and, for users in the United States, the California Consumer Privacy Act / CPRA, as well as Google Play's Data Safety requirements.
Privacy Policy
Last updated: September 7, 2026 - Version 2.1
1. Who is the data controller
The data controller for the Velaris Bike app and website is Păcurar Narcisa-Ancuța, a natural person, the developer and operator of the platform, based in Târgu Mureș, Romania (referred to hereinafter as "we" or "the controller"). For any request regarding your data, you can contact us at: privacy@velarisbike.online. We do not have a formally appointed Data Protection Officer (DPO), as our processing does not fall within the criteria requiring one under Art. 37 GDPR, but all requests are handled directly by the controller.
2. What data we collect
a) Account data: email address, password (stored exclusively as a bcrypt hash, never in plain text), display name, profile picture (optional). b) Google authentication data (if this sign-in method is available and you choose to use it): email address, name and public profile photo provided by Google during the sign-in process. This information is used exclusively to create and manage your account in the app. We do not request or receive access to Gmail, Google Drive, Contacts or other Google services. c) Ride data (physical activity): GPS route (latitude/longitude coordinates with timestamps), distance, speed (average/maximum), altitude/elevation, duration, estimated calories, start/end date and time. d) Bike data: name, type, mileage, maintenance log entered by you. e) Progress data: level, experience points (XP), unlocked challenges/achievements. f) App preferences: language, units of measurement (metric/imperial), theme (light/dark). g) Technical and session data: authentication token (JWT), IP address and standard server information (user agent, access timestamp), collected automatically by the hosting infrastructure solely for security, fraud prevention and debugging purposes, not for profiling. h) Photos / camera: if you choose to upload a profile picture, the app requests access to the gallery or camera only at that moment, with your explicit permission granted through the operating system (Android).
3. Legal basis for processing (GDPR Art. 6)
• Performance of a contract (Art. 6(1)(b)), for creating your account, operating the app, and saving rides and bikes. • Consent (Art. 6(1)(a)), for access to GPS location and camera/photo gallery; you may withdraw this consent at any time from your phone settings or by deleting your account. • Legitimate interest (Art. 6(1)(f)), for the security of the service (fraud prevention, minimal technical logs), within limits that do not prejudice your fundamental rights.
4. GPS location data
Location is collected only during an active ride that you start manually. On Android, if you explicitly enable screen-locked recording, the active ride may continue while the screen is locked through an Android foreground service with a persistent notification. Tracking stops when the ride ends, is discarded, or you stop the feature. We do not collect location outside an active ride and we do not use location for advertising or profiling. You can revoke location, background location, or notification permission at any time from Android settings. Revoking a required permission stops the affected tracking capability and the app does not silently request it again.
5. Who we disclose data to (subprocessors and third-party services)
We do not sell or rent your data to any third party. We use the following strictly technical providers, necessary for the app to function, each acting as a processor or as a separate controller, as applicable: • MongoDB database, for storage of account, ride and bike data (strictly isolated per user_id). • Backend hosting service (API server), which runs the app code and processes requests. • SMTP provider, currently Gmail using the account teamswody@gmail.com, used to send password reset codes and account-deletion verification codes when you request those operations. The email address you provide is used to deliver the requested message. • OpenStreetMap / Leaflet, for displaying maps; when a map loads, the tile servers may receive your device's IP address, as is standard for any online mapping service. • Sentry (crash and error reporting), which receives a technical error report when the app crashes or hits an unexpected error, including the error message, a stack trace, basic device information (model, OS version), and an internal, non-identifying user ID. Sentry never receives your email, name, password, or GPS route data. Data is processed in the EU. These services may be hosted in the EU, the US, or other jurisdictions. We do not use advertising networks, tracking pixels, or behavioral analytics tools (Google Analytics, Meta Pixel, Firebase Analytics, etc.).
6. International data transfers
If a technical provider (e.g. hosting server or Google) processes data outside the European Economic Area, we ensure the transfer relies on a mechanism recognized by the GDPR: an adequacy decision of the European Commission, Standard Contractual Clauses (SCCs), or an equivalent certification framework (e.g. the EU-US Data Privacy Framework, where the provider is certified).
7. How long we keep data
• Account and ride data: for as long as your account is active. • After account deletion: data is permanently and irreversibly deleted from the production database, usually instantly, and from backups within a maximum of 30 days. • Password reset and account-deletion verification codes: expire automatically after 10 minutes and are not retained afterward. • Technical server logs (IP, timestamp): kept for a maximum of 90 days, exclusively for security/debugging purposes.
8. What we do NOT do
• We do not sell your data. • We do not "share" it within the meaning of the CCPA (we do not use it for cross-context behavioral advertising on other sites/apps). • We do not use tracking analytics or behavioral profiling. • We do not display ads in the app. • We do not make automated decisions with legal effects on you (no automated profiling within the meaning of Art. 22 GDPR).
9. Data security
Passwords are hashed with bcrypt (an irreversible algorithm with salt); we never store your password in plain text. Session tokens (JWT) are stored encrypted locally on your device, in Android EncryptedSharedPreferences/Keystore. All communication between the app and the server is encrypted via HTTPS/TLS. Access to the database is restricted, and each user can only access their own data, isolated by a unique identifier (user_id). While we apply reasonable technical and organizational measures, no method of electronic transmission or storage is 100% secure; we cannot guarantee absolute security. If you discover a security vulnerability, please report it responsibly to security@velarisbike.online instead of disclosing it publicly, so we can investigate and fix it before it can be exploited.
10. Your rights under GDPR (users in the EU/EEA and the UK)
You have the right to: (a) obtain confirmation and access to your data (Art. 15); (b) request the rectification of inaccurate data (Art. 16); (c) request the erasure of your data (the "right to be forgotten", Art. 17), available directly from the app: Profile → Settings → Delete account, permanent and immediate deletion; (d) request restriction of processing (Art. 18); (e) receive your data in a structured, commonly used, machine-readable format (portability, Art. 20), available from Settings → Export data; (f) object to processing based on legitimate interest (Art. 21); (g) withdraw your consent at any time, without affecting the lawfulness of processing carried out before its withdrawal; (h) lodge a complaint with a supervisory authority. For Romania: the National Supervisory Authority for Personal Data Processing (ANSPDCP), www.dataprotection.ro, B-dul G-ral. Gheorghe Magheru nr. 28-30, Bucharest. Users in other EU member states may contact the supervisory authority of their state of residence. To exercise any of these rights, use the app's features (Settings) or write to us at privacy@velarisbike.online. We respond within a maximum of 30 days.
11. Rights of California, USA residents (CCPA/CPRA)
If you are a California resident, under the California Consumer Privacy Act as amended by the CPRA, you have the right to: (a) know what categories of personal information we collect, their sources, and the purpose of collection (see section 2 above; we have not collected, in the past 12 months, categories beyond those described); (b) request deletion of your personal information; (c) correct inaccurate information; (d) know whether we "sell" or "share" your data. We do NOT sell and do NOT share your personal information within the meaning of the CCPA/CPRA (there is no "Do Not Sell or Share My Personal Information" link because we do not engage in these practices); (e) limit the use of sensitive personal information. We do not collect categories of information considered "sensitive" under the CPRA other than precise geolocation data during an active ride, used exclusively for the app's core functionality; (f) not be discriminated against for exercising these rights. You can exercise these rights from the app's Settings or by writing to us at privacy@velarisbike.online. We may ask you to verify your identity before processing your request, in order to protect your data against unauthorized access. You may designate an authorized agent to act on your behalf, as permitted by law.
12. Other international users (Canada, Switzerland, other jurisdictions)
For users in Canada, we apply the principles of PIPEDA (Personal Information Protection and Electronic Documents Act): we only collect data necessary for the stated purpose, and you may withdraw your consent at any time. For users in Switzerland and other jurisdictions with similar data protection laws, we offer the same rights of access, rectification and erasure described above, regardless of your location.
13. Children and minimum age
Velaris Bike is not intended for children under 16 (the minimum age of digital consent under GDPR for Romania) and, for users in the United States, is not intended for children under 13, in accordance with the Children's Online Privacy Protection Act (COPPA). We do not knowingly collect data from children under these ages. If you become aware that a child has provided us with personal data without parental/guardian consent, please contact us at privacy@velarisbike.online so we can immediately delete the account and associated data.
14. Account deletion
You can permanently delete your account and associated data directly from the app: Profile → Settings → Delete account. You can also use the public account-deletion page at https://www.velarisbike.online/delete-account. The web flow sends a six-digit verification code to the email address associated with the account before deletion is completed. After the code is verified, the account and associated production data are permanently deleted. The deletion cannot be reversed. If you cannot use the web flow or the app, you can contact us at privacy@velarisbike.online.
15. Cookies and local storage
Velaris Bike is a native mobile app, not a website, so it does not use cross-site tracking cookies. We use encrypted local storage on the device (Android Keystore) exclusively to keep the authentication token and your preferences (language, units, theme), so that you don't have to sign in again every time you open the app.
16. Changes to this policy
We may periodically update this policy to reflect legal or functional changes to the app. In the event of significant changes, we will notify you directly within the app before the new version takes effect. The date of the last update is shown at the top of this document.
17. Contact
For any question about privacy, exercising your rights, or this policy, you can write to us at any time at: privacy@velarisbike.online