Legal
Privacy policy
As of: 10 May 2026. We take the protection of your personal data seriously and process it solely in accordance with GDPR and the Austrian Data Protection Act (DSG).
1. Controller
GlowRide, Musterstraße 18, 4020 Linz, Austria — hallo@glowride.at.
2. Which data we process
- Account: email, name, phone (optional), invoice address, language and theme preference.
- Bookings: booked classes, bike number, attendance.
- Payments: purchases, credit balance, invoices (7-year retention per Austrian § 132 BAO).
- Marketing: consent status, send history (only after double opt-in).
- Technical: server logs (IP address, user agent), cookie preferences.
3. Purposes and legal bases
- Performance of contract (Art. 6(1)(b) GDPR): account, bookings, payments.
- Legal obligation (Art. 6(1)(c) GDPR): invoice retention.
- Legitimate interest (Art. 6(1)(f) GDPR): IT security, abuse prevention.
- Consent (Art. 6(1)(a) GDPR): marketing emails, optional cookies.
4. Recipients / processors
- Supabase Inc. — database, auth, storage (EU region).
- Vercel Inc. — hosting (EU regions).
- Stripe Payments Europe Ltd. — payment processing.
- Resend Inc. — transactional and marketing email delivery.
- Sentry — error tracking (only on active error).
GDPR-compliant data processing agreements (Art. 28 GDPR) are in place with all processors.
5. Retention periods
- Account data: until account deletion.
- Booking data: 3 years after last booking.
- Invoices: 7 years (legally required).
- Cookie consent: 12 months audit trail.
- Server logs: 30 days.
6. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability, withdrawal of consent, and objection to processing based on legitimate interests.
You may file complaints with the Austrian Data Protection Authority (dsb.gv.at).
7. Cookies
Which cookies we use is documented in our cookie inventory. You can change settings at any time via the footer link.