Privacy & Cookie Policy
This policy explains how Rideful processes personal data, uses cookies and local storage, and protects your privacy.
Privacy at a glance
Rideful uses account and project data to provide the service, Stripe to process subscriptions, and Google services for authentication, database functions and hosting.
Google Analytics is optional. No Analytics data is sent and no Analytics cookies are stored before you actively consent.
Rideful does not send project content, route names, notes, email addresses or account IDs to Google Analytics.
1. Controller
The controller responsible for processing personal data in connection with Rideful is:
Endersky UG (haftungsbeschränkt)
Full company and contact details are available in our Legal Notice.
Questions or requests concerning privacy can be submitted through the contact details stated in the Legal Notice or through Rideful support.
2. Scope of this policy
This Privacy & Cookie Policy applies to the Rideful website, the Rideful web application, account functions, subscriptions, customer support and associated online services operated by Endersky UG (haftungsbeschränkt).
Third-party websites or services linked from Rideful are governed by their own privacy policies.
3. Data we process
Depending on how you use Rideful, we may process the following categories of data:
- Account data: email address, authentication identifiers, account status and subscription tier.
- Project data: projects, routes, settings, notes and other content that you create or save in Rideful.
- Payment and subscription data: Stripe customer and subscription identifiers, selected plan, payment status, invoices and related transaction information. Complete card details are processed by Stripe and are not stored by Rideful.
- Technical data: IP address, browser, operating system, device information, request time, error information and server log data.
- Optional Analytics data: page views, feature events, project and route counts, export format, tutorial progress, subscription tier, approximate location, device information and session information.
- Local device data: preferences and app settings stored in your browser's local storage.
- Communication data: information you provide when contacting support or otherwise communicating with us.
4. Legal bases
We process personal data only where a legal basis applies. Depending on the context, processing is based on:
- Article 6(1)(b) GDPR: processing necessary to provide Rideful, manage your account, save projects and administer subscriptions.
- Article 6(1)(c) GDPR: processing necessary to meet legal obligations, including tax, accounting and record-keeping obligations.
- Article 6(1)(f) GDPR: legitimate interests in operating, securing, maintaining and improving the service, preventing abuse and resolving technical problems.
- Article 6(1)(a) GDPR and Section 25(1) TDDDG: your consent to optional Analytics processing and the storage of Analytics cookies or similar identifiers on your device.
Where storage or access on your device is strictly necessary to provide a feature you requested, it is based on Section 25(2) TDDDG.
5. Accounts and Firebase
Rideful uses services provided by Google, including Firebase Authentication, Cloud Firestore and Cloud Functions.
- Firebase Authentication is used to register users, sign them in and securely manage authentication sessions.
- Cloud Firestore is used to store and retrieve account information, projects, routes, settings and other app data.
- Cloud Functions is used to execute backend operations, process application events and securely connect Rideful functions with other services.
The processing is necessary to create and operate your Rideful account and to provide the app under Article 6(1)(b) GDPR. Security-related processing may also be based on our legitimate interests under Article 6(1)(f) GDPR.
Google may process technical identifiers, IP addresses, authentication information and the data stored or transmitted through these services. Additional information is available in Google's privacy documentation.
6. Projects and app content
Rideful processes the projects, routes, notes, settings and other content you create so that the application can save, display, edit, export and synchronise that content.
This content is processed to provide the service under Article 6(1)(b) GDPR. It is not used for advertising and is not sent to Google Analytics.
You are responsible for ensuring that content you upload or enter into Rideful does not unlawfully contain personal data belonging to other people.
7. Payments and subscriptions with Stripe
Rideful uses Stripe for subscription checkout and the Stripe Customer Portal. Depending on your payment method, Stripe may process your name, email address, billing address, payment details, transaction data, device information and fraud-prevention information.
Payment details such as complete credit card numbers are entered directly into Stripe's systems and are not stored by Rideful. Rideful receives the information necessary to manage your subscription, such as your Stripe customer ID, subscription status, selected plan and payment status.
This processing is necessary to enter into and perform the subscription contract under Article 6(1)(b) GDPR. Processing required for invoices, bookkeeping and tax obligations is based on Article 6(1)(c) GDPR. Fraud prevention and payment security may additionally be based on legitimate interests under Article 6(1)(f) GDPR.
Stripe acts as an independent controller for parts of its payment processing. Its own privacy policy applies to data processed directly by Stripe.
8. Google Analytics
With your permission, Rideful uses Google Analytics 4 to understand how the website and application are used, which features are helpful, where users encounter problems and how Rideful can be improved.
Google Analytics is disabled by default. Analytics data is not transmitted and Analytics cookies are not stored until you select “Allow analytics” in the consent banner or Privacy Settings.
Where consent is granted, Rideful may send:
- page views and session information;
- feature usage events;
- counts of projects or routes, without their content or names;
- export format and tutorial progress;
- subscription tier, such as Free, Standard or Pro;
- browser, operating system, device category and approximate geographic region.
Rideful does not send project content, route content, project names, route names, notes, email addresses or Rideful account IDs to Google Analytics.
Google Analytics may use cookies such as _ga and _ga_<container-id> to distinguish browsers and measure sessions. The information generated through Analytics may be processed by Google Ireland Limited and other Google group companies.
Rideful uses Google Consent Mode v2 to communicate your consent choice. Optional Analytics storage and collection remain denied until consent is granted.
The legal basis is your consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG. You may withdraw consent at any time with effect for the future. Withdrawal does not affect processing that occurred before consent was withdrawn.
9. Cookies and local storage
Cookies are small text files stored by your browser. Local storage is a browser feature that allows a website or web application to save information locally on your device.
Strictly necessary storage
Rideful may use technically necessary browser storage for authentication, security, consent status, application operation and features you request. This storage is necessary to provide the service and does not require consent where the statutory requirements of Section 25(2) TDDDG are met.
Preferences in local storage
Rideful stores certain preferences locally, for example interface settings or other application choices. These values generally remain on the device until Rideful removes them, the application replaces them, or you clear the website data in your browser.
Analytics cookies
After consent, Google Analytics may store cookies including _ga and a property-specific _ga_* cookie. These cookies help distinguish browsers and maintain Analytics session information. Their actual lifetime may be shortened by browser settings, Google configuration, consent withdrawal or manual deletion.
Blocking or deleting strictly necessary storage may prevent login, saved preferences or parts of Rideful from working correctly. Declining optional Analytics does not restrict Rideful's core functionality.
10. Hosting and server logs
Rideful is hosted using Google Cloud Run. When you access the service, hosting systems may automatically process technical request and log data, including IP address, date and time, requested resource, response status, browser information and information required to detect errors or attacks.
This processing is necessary to deliver Rideful and is based on Article 6(1)(b) GDPR. Security, stability, abuse prevention and troubleshooting are also based on our legitimate interests under Article 6(1)(f) GDPR.
Rideful uses encrypted HTTPS connections to protect data in transit.
11. International data transfers
Google and Stripe are international service providers. Depending on service configuration, support access and technical processing, personal data may be processed outside the European Economic Area, including in the United States.
Where required, transfers are protected through an adequacy decision, the EU–US Data Privacy Framework for certified recipients, the European Commission's Standard Contractual Clauses or other safeguards recognised under Chapter V GDPR.
No transfer mechanism can eliminate every risk associated with processing in another jurisdiction. We select established providers and use available contractual and technical safeguards appropriate to the relevant processing.
12. Retention
We retain personal data only for as long as necessary for the relevant purpose or as required by law.
- Account and project data: generally retained while your account is active and for a limited period afterwards where necessary for deletion processing, security, dispute resolution or legal obligations.
- Payment and invoice data: retained for the periods required under applicable commercial and tax law.
- Support communications: retained for as long as necessary to handle the request and establish or defend legal claims.
- Server logs: retained only as long as needed for security, diagnostics and abuse prevention, unless an incident requires longer retention.
- Analytics data: retained according to the retention period configured in the relevant Google Analytics property and may also be aggregated.
- Local storage: remains on your device until it expires, is overwritten, is removed by Rideful or is deleted through your browser.
Where data must be retained for legal reasons, its use is restricted to those purposes.
13. Security
We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures include encrypted transmission, access controls and the use of established infrastructure providers.
No online service can guarantee absolute security. Please use a strong, unique password and protect access to your email account and devices.
14. Your data protection rights
Subject to the applicable legal requirements, you may have the right to:
- request access to your personal data under Article 15 GDPR;
- request correction of inaccurate data under Article 16 GDPR;
- request deletion under Article 17 GDPR;
- request restriction of processing under Article 18 GDPR;
- receive certain data in a portable format under Article 20 GDPR;
- object to processing based on legitimate interests under Article 21 GDPR;
- withdraw consent at any time under Article 7(3) GDPR; and
- lodge a complaint with a data protection supervisory authority under Article 77 GDPR.
Where processing is based on legitimate interests, you may object on grounds relating to your particular situation. We will stop the relevant processing unless compelling legitimate grounds override your interests, rights and freedoms, or the processing is required for legal claims.
You may lodge a complaint with the supervisory authority responsible for your place of residence, workplace or the location of the alleged infringement. Endersky UG is based in Saxony, Germany, so the Saxon Data Protection and Transparency Commissioner may also be a competent authority.
15. Managing your consent and browser data
You can change or withdraw your Google Analytics choice at any time in Rideful under Settings → Privacy Settings. Disabling Analytics prevents future Analytics collection and Rideful attempts to remove accessible Analytics cookies.
You can also delete cookies and local storage through your browser settings. Browser menus vary, but the relevant option is commonly called “Cookies and site data”, “Website data”, “Privacy”, or “Clear browsing data”.
Deleting all Rideful browser data may sign you out and reset locally saved preferences. Your projects stored in your Rideful account are not deleted merely by clearing your browser storage.
Open Privacy Settings16. Changes to this policy
We may update this policy when Rideful's functions, providers or legal obligations change. The current version is published on this page with its effective date.
Where a change materially affects how we process personal data, we will provide an appropriate notice within Rideful or by another suitable method.
17. Contact
For privacy questions, requests or concerns, please contact Endersky UG (haftungsbeschränkt) using the details in our Legal Notice or through Rideful support.
To help us handle a data protection request securely, we may need to verify your identity before disclosing, changing or deleting account data.
This policy is intended to transparently describe Rideful's current data practices. It does not replace individual legal advice.
