Version 1.1 · Effective 11 September 2026
Privacy Policy
This policy covers the RideCommit website, waitlist and current iPhone service. The app is not yet publicly available in app stores. We will update this policy before releasing features with different data handling, including Android.
1. Who is responsible
Konstantine Khomeriki (კონსტანტინე ხომერიკი), Tbilisi, Georgia, is responsible for RideCommit’s processing of personal data. Contact khomeriki.dev@gmail.com for privacy questions or requests.
2. Information the app handles
- Account information: email address, account identifier, profile name and username, authentication credentials and session information. Passwords are stored as password hashes. Where Sign in with Apple is available and used, we process the identifier and account information Apple supplies and authentication tokens needed for that service.
- Bike and profile details: motorcycle model, year, mileage, maintenance information and optional weight in riding gear.
- Ride information: precise GPS coordinates, timestamps, distance, speed, accelerometer and gyroscope measurements, recording diagnostics, derived corner events, estimated lean, scores, ride names and feedback you give on the analysis. Routes may reveal sensitive places such as your home or workplace.
- Photos: images you select or take for your profile or bike. Photos are stored on your device. Enabling cloud uploads also uploads your profile and motorcycle photos to your private account. Photos are resized and re-encoded, and embedded metadata such as EXIF location is removed from the server copy. Other devices signed into the same account can download and cache these photos even when uploads are off.
- Support communications: your email and any information or attachments you choose to send us. Please do not send passwords or unnecessary location recordings.
3. Local processing and optional cloud uploads
Recording and ride analysis run on the phone. Cloud uploads are off by default for each account on each device. Enabling cloud uploads requires a separate confirmation. After you enable them, supported profile and motorcycle details, photos, rides, precise routes and analysis results can upload automatically as data changes or the app returns to the foreground, including pending rides recorded before you opted in. The server also supports storage and retrieval of raw GPS and inertial recordings; the current mobile app uploads supported account and ride information and analysis results, rather than every raw sensor file.
Synchronised information is associated with your account. You can turn cloud uploads off in Profile. This stops new uploads from this device and attempts to cancel in-flight transfers. A transfer already received by the server may remain stored. Disabling uploads does not delete existing cloud copies or change the setting on other devices. Account authentication, automatic cloud photo restoration and explicit ride downloads or deletion requests still use the server. With uploads enabled, turning off connectivity only delays transmission. Device-level backups may include local photos and other app data according to your device settings. Signing out does not delete information already synchronised.
4. Why we use information
We use information to authenticate your account; record, analyse and replay your rides; synchronise supported data between your devices; remember profile preferences; process deletion and support requests; and maintain service security and reliability. Rider feedback is stored with the relevant ride. It does not automatically change the corner’s score.
Where data-protection law requires a legal basis, we rely on performance of the service agreement for account and requested service functions, consent where required for optional processing, legitimate interests for proportionate security and service administration where permitted, and legal obligations where applicable. Device permission is a technical control and does not replace any separate legal consent that is required.
We do not sell personal ride data or use private routes for targeted advertising. The current app and website do not use advertising or third-party analytics integrations. We will update this policy before changing that.
5. Website and waitlist
If you choose “Notify me”, we store your email address, registration time and expiry date to contact you about RideCommit availability, based on your request and consent. Joining does not create an app account. We store the list in our private PostgreSQL database on DigitalOcean in New York, United States. Entries expire after 365 days and are removed by a daily cleanup when the service is running. Repeated submissions do not extend that period. You can withdraw consent or request earlier removal at khomeriki.dev@gmail.com. We do not send an automatic confirmation email; any availability message will provide a way to opt out. We do not use the list for unrelated marketing.
The website loads its Inter font from Google Fonts. Your browser therefore connects to Google and sends connection information such as your IP address and browser request headers. See Google Fonts privacy information. The website does not use analytics scripts or advertising cookies. DigitalOcean hosts the website. Our web server is configured without routine request access logs. The API temporarily holds IP addresses in memory for rate limiting; it does not store them with waitlist entries. Infrastructure and security logs may still contain connection information needed to operate and protect the service.
6. Service providers and disclosures
The website and app backend run on a DigitalOcean server in New York, United States. DigitalOcean processes hosted information to run our service. See its Data Processing Agreement. Apple processes information when you use its sign-in or distribution services. Google processes website font requests. Email communications pass through the email services used by you and us, including Gmail for the support address.
We may disclose information when reasonably necessary to comply with a legal obligation, address a valid legal request, protect rights or service security, or carry out your instructions. We do not publish your private rides by default. Our United States hosting and other providers may process information outside your country. Where applicable law requires safeguards for an international transfer, we use the applicable contractual arrangements and you may contact us for further information.
7. Storage and deletion
Local recordings remain on the device until removed through available app controls or local app data is removed. Synchronised account data remains in the active service until deleted. You can delete individual rides through the ride list and request account deletion through Profile → Delete account. Server deletion requires connectivity.
Account deletion removes the account and its associated active database records, including synchronised profile and motorcycle photos, ride analysis and supported recordings. It also initiates local account cleanup on the requesting device. Offline copies on another device cannot be remotely erased while that device remains offline; remove app data there when necessary.
Server backups are scheduled daily. The configured cleanup removes backups older than seven days after a successful new backup. If backups or cleanup fail, older copies can remain longer. Deletion from the active database is therefore not immediate erasure from every backup. This backup schedule also applies to waitlist entries. Following a restore, deletion requests must be reapplied before using the restored list to send messages.
Where Apple sign-in is used, an encrypted provider token may remain in a restricted retry queue until revocation succeeds. Support messages are kept as needed to resolve your request and document our response; contact us to request their deletion. Security and operational records are kept only as needed for investigation and service administration. We will retain information required by law only for the applicable purpose and period.
8. Your choices and rights
You can stop a recording and change location, motion, camera or photo permissions in your device settings. Revoking permission affects the related functionality but does not delete existing recordings or server copies.
Depending on the law that applies to you, you may have rights to access, correct, delete or receive a copy of your information, restrict processing, object to certain processing or withdraw consent. Contact us to exercise these rights. We may request proportionate information to verify ownership; never send your password. You may also complain to the competent data-protection authority.
See Account and data deletion for the current in-app route and contact instructions. The app does not currently offer a complete self-service export; contact us for an access or portability request.
9. Security, children and updates
We use authenticated account access and HTTPS for the configured API, along with password hashing and protected credential storage. No method of storage or transmission is completely secure; these controls are not a claim of end-to-end encryption.
RideCommit is designed for motorcycle riders, not as a service directed to children. Contact us if you believe a child’s information has been submitted without legally required authorisation so we can investigate and take appropriate action.
We will update this policy when data handling changes, show its effective date and give any notice or obtain any consent required by applicable law. For privacy enquiries, contact khomeriki.dev@gmail.com.