Sekretesspolicy
Gäller från: oktober 2026
Party Onbici Pty Ltd (formerly Bike Party) (ABN 77 684 853 594) ("we", "us" or "Party Onbici") is committed to privacy protection. At Party Onbici ("this site"), we understand the importance of keeping personal information private and secure.
This privacy policy ("Privacy Policy") describes generally how we manage personal information and safeguard privacy. If you would like more information, please don't hesitate to contact us.
This Privacy Policy forms part of, and is subject to the provisions of, our Website Terms of Use (https://www.partyonbici.com/policies/website-terms-and-conditions/).
We care about your privacy:
We will never rent, trade or sell your email address to anyone.
We will never publicly display your email address or other personal details that identify you.
1. The Australian Privacy Principles
We will treat all personal information in accordance with any and all obligations that are binding upon us under the Privacy Act 1988 (Cth) (“Privacy Act”).
The Privacy Act lays down 13 key principles in relation to the collection and treatment of personal information, which are called the “Australian Privacy Principles”.
2. What is "personal information"?
Personal information held by Party Onbici may include your:
- name, date of birth and gender;
- residential and business postal addresses, telephone/mobile/fax numbers and email addresses;
- bank account and/or credit card details for agreed billing purposes;
- any information that you provided to us by you during your account creation process or added to your user profile;
- preferences and password for using this site and your computer and connection information;
- an identifier the mobile app creates for each installation (a random value on Android; Apple's identifier for vendor on iOS). The app sends it with ride synchronization, push notification registration, live ride sharing and app diagnostics, and when you are signed in it is linked to your account. It is never used for advertising; and
- any information that you otherwise share with us.
Information provided to Stripe
All purchases that are made through this site are processed securely and externally by Stripe.
Unless you expressly consent otherwise, we do not see or have access to any personal information that you may provide to Stripe, other than information that is required in order to process your order and deliver your purchased items to you (eg, your name, email address and billing address).
Information provided to Digital iD
Some bike parties may require you to provide verification of your identity. We use Digital iD to verify your identity.
2A. Children and young riders
Party Onbici is not directed at children. You must be at least 16 years old to create an account, to join or organise a group ride, or to share a live ride link, and the app asks you to confirm your age before any of those. You can use the map, plan routes and record rides on your own device without an account.
We do not knowingly collect personal information from anyone under 16. If you believe someone under 16 has given us personal information, contact our Data Protection Officer at dpo@partyonbici.com and we will delete it. A parent or guardian may make that request on their child's behalf.
Your age or year of birth. When you create an account we ask for your age or your year of birth. We use it to apply the minimum age and the age limits that ride organisers set on their rides, and we count riders by age band in aggregate to understand who uses Party Onbici; those counts never identify you. It is never shown to other riders, it is not used for advertising or profiling, and it is deleted with your account. The age check the app shows to someone without an account keeps only the outcome on that device, not the year you entered.
Rides that include younger children. Group rides that include children under 16, such as a school bike bus, are led by adults using the app. Children taking part do not need, and should not be given, an account.
3. How we may collect your personal information
At this site, we only collect personal information that is necessary for us to conduct our business as an online community to meet cyclists travelling to a shared destination.
Information that you provide to us
We may collect personal information that you provide to us about yourself when you:
- use this site, including (without limitation) when you:
- create a user account;
- create a party/route/incident report;
- join a party
- add information to your user profile;
- purchase any services through this site;
- add reviews, forum or chat room messages or comments in any elements of this site that permit user-generated content;
- register for access to premium content or request certain premium features; or
- complete an online contact form to contact us or any third party supplier;
- provide information to us by telephone or through marketing or competition application forms; or
- send us an email or other communication.
IP addresses
This site may also collect Internet Protocol (IP) addresses. IP addresses are assigned to computers on the internet to uniquely identify them within the global network.
Party Onbici collects and manages IP addresses as part of the service of providing internet session management and for security purposes.
Party Onbici may also collect and use web log, computer and connection information for security and analytical purposes to help guide feature development and retirement, prevent and detect any misuse of, or fraudulent activities involving, this site.
Third-Party Services
When you use certain features on this site, data may be shared with third-party service providers to deliver the functionality you requested:
- Stadia Maps (Geocoding): When you use the address search or location autocomplete feature (e.g., when creating a party, reporting an incident, or saving a location on your profile), your search query text is sent to Stadia Maps for geocoding. Stadia Maps processes your search text and returns matching addresses and coordinates. Party Onbici caches the results for up to 24 hours under a one-way hash of the search text, so repeated searches are faster.
- Stadia Maps (Map Tiles): When you view a map on this site, map tile coordinates indicating the area you are viewing are shared with Stadia Maps to render the map. These coordinates do not precisely identify your location.
- Stadia Maps (Routing): When you create a cycling route, waypoint coordinates are sent to Stadia Maps for route calculation.
For more information about Stadia Maps' privacy practices, visit stadiamaps.com/privacy.
3A. Mobile App Data Collection
In addition to the website, Party Onbici offers a mobile application for cycling navigation. The following describes data collection specific to the mobile app.
Ride Data Synchronization
With your consent, the Party Onbici mobile app may synchronize your cycling ride data to our servers. This feature is optional and can be controlled at any time in the app's Privacy Center.
Data that may be synchronized includes:
- Ride timestamps (start and end times)
- GPS coordinates and route trajectory
- Speed, distance, and elevation statistics
- Accelerometer data (used for road quality assessment and crash detection)
- Device information (app version, device model, operating system version)
- The app's installation identifier described in section 2, linked to your account
Heart rate is never synchronized. If you use the optional heart-rate feature (see the Heart Rate section below), your heart-rate readings are excluded from ride synchronization and are never uploaded to our servers.
Purposes of synchronization:
- Enable backup and restoration of your ride history
- Allow access to your rides if you change devices
- Provide aggregated statistics for route planning and cycling infrastructure analysis (e.g., popular routes, road quality insights). City partners see only totals for areas crossed by at least 3 different riders; individual ride tracks are visible only to authorised Party Onbici staff.
- Improve app features based on usage patterns
Your control:
- You can enable or disable ride sync at any time via Settings > Privacy Center in the app
- You can request deletion of all synchronized data at any time
- Data synchronized to our servers is encrypted in transit (TLS 1.3) and at rest
Server location: Your data is processed and stored in the region your account belongs to: Australia (Sydney) or the European Union (Milan, Italy). For information about cross-border data transfers, see the GDPR section below.
Retention: Synchronized ride data is retained for 10 years, so that your long-term ride history and year-over-year statistics remain available to you. Deleting a ride in the app removes it from your account and stops it syncing; its stored points are deleted 10 years after they were recorded. When you delete your account, your synchronized rides are separated from it (the ride name, start and end addresses and device name are removed) and kept for aggregate statistics until that 10-year limit. To have them erased instead, contact our Data Protection Officer before you delete your account; see how to delete your account.
Location Data
When using the Party Onbici mobile app:
- Precise location (GPS coordinates) is collected during ride recording to track your cycling route. This data is stored locally on your device and, with your consent, may be synchronized to our servers for backup purposes.
- Weather: your location is sent through our servers to Azure Maps to provide weather where you are. It is usually rounded to about 11 metres, and for some checks (such as the weather when a ride starts) it is sent at full precision. Riders in the European Union use Azure's EU service.
- Group rides and live ride links: during a group ride your live position is sent through our servers to the other riders in that ride, at the precision you choose in the ride's privacy setting. If you share a live ride link, anyone with the link can see your position until you stop sharing.
- Bike-path statistics and ride addresses: when you finish a ride recorded without a planned route, the app sends the recorded track through our servers to Stadia Maps to work out how much of it was on bike paths, and sends the start and end points to look up their street addresses. This happens whether or not ride synchronization is on. Our servers cache these answers for up to 24 hours (addresses for up to 7 days).
- Map tile coordinates are shared with Stadia Maps to display the map. These coordinates indicate the area of the map you are viewing but do not precisely identify your location.
- Address search queries are sent to Stadia Maps when you use the location search or address autocomplete features on the website or in the mobile app. Stadia Maps processes your search text to return matching addresses and coordinates.
Your location data is never sold to third parties or used for advertising purposes.
Apple Health and Health Connect (Optional)
You can choose to have your completed rides saved to Apple Health (iOS) or Health Connect (Android) on your device. This feature is off by default and is turned on in the app via Settings > Integrations.
When enabled, each completed ride is written to your device's health store as a cycling workout. The exact data types written are:
- Exercise session / workout - the ride recorded as a cycling workout with its start and end time
- Distance - the total distance you cycled
- Total calories burned - an estimate of the active energy you used, calculated from your ride's speed, elevation, and your weight setting (a typical rider weight is assumed if you haven't set one)
- Exercise route - the GPS route of the ride
No other data types are written. You can also export your previously recorded rides in one step.
This ride export is write-only: Party Onbici never reads your workouts or any other data from Apple Health or Health Connect through this feature. The only health data the app can read is your heart rate, and only if you separately turn on the optional heart-rate feature described in the next section. The exported data is written only on your device - it is never sent to our servers, never shared with third parties, and never used for advertising, marketing, or data mining. We do not store or retain any copy of the data written to Apple Health or Health Connect; the only copy outside your health app is the ride itself, which is governed by the ride data practices described above.
Your control:
- To stop future exports, turn the toggle off in Settings > Integrations, or revoke Party Onbici's access in the Health app (iOS) or Health Connect settings (Android)
- Workouts already written remain in your health app under your control; you can delete them there at any time
- Disabling the feature or deleting Party Onbici does not automatically remove workouts you previously saved
Heart Rate (Optional)
Party Onbici can show your live heart rate during a ride and save it with that ride's record on your device. This feature is off by default: it only works if you turn it on in the app's Settings and grant the relevant permission. Your heart rate can come from:
- A Bluetooth heart-rate sensor (such as a chest strap or armband) that you choose to pair in the app
- Your Apple Watch (iOS) - with your permission, the app reads your heart rate from Apple Health during a ride
- Your Wear OS watch (Android) - with your permission, the watch reads its heart-rate sensor while you record a ride and relays the reading to your own paired phone
Your heart rate stays on your devices. It is displayed during the ride, stored in the encrypted ride database on your phone, and shown in your ride history. It is never sent to our servers - even if you enable ride synchronization, heart rate is excluded from the data that is uploaded. It is never shared with third parties, never visible to other riders in group rides or shared rides, and never used for advertising, marketing, or data mining. The only ways heart-rate data leaves your devices are actions you take yourself, such as exporting a ride as a FIT or TCX file.
Your control:
- Turn the heart-rate feature off at any time in the app's Settings
- On iOS, you can also revoke heart-rate access at any time in the Health app; on Android, you can revoke the sensor permission in your watch or phone system settings
- Deleting a ride also deletes the heart-rate data recorded with it
4. Cookies
This site uses "cookies" to help personalise your online experience.
A cookie is a text file or a packet of information that is placed on your hard disk by a web page server to identify and interact more effectively with your computer.
There are two types of cookies that may be used at this site: a persistent cookie and a session cookie.
A persistent cookie is entered by your web browser into the "Cookies" folder on your computer and remains in that folder after you close your browser, and may be used by your browser on subsequent visits to this site.
A session cookie is held temporarily in your computer’s memory and disappears after you close your browser or shut down your computer.
Cookies cannot be used to run programs. Cookies are uniquely assigned to you, and can only be read by a web server in the domain that issued the cookie to you.
In some cases, cookies may collect and store personal information about you. Party Onbici extends the same privacy protection to your personal information, whether gathered via cookies or from other sources.
You can configure your internet browser to accept all cookies, reject all cookies or notify you when a cookie is sent.
Please refer to your internet browser’s instructions to learn more about these functions. Most web browsers automatically accept cookies, but you can usually modify your browser settings to decline cookies if you prefer.
If you choose to decline cookies, you may not be able to fully experience the interactive features of this site.
Why we use cookies
This site uses cookies in order to:
- remember your preferences for using this site;
- manage the signup process when you create an account with us;
- recognise you as logged in while you remain so. This avoids your having to log in again every time you visit a new page;
- facilitate e-commerce transactions, to ensure that your order is remembered between pages during the checkout process;
- show relevant notifications to you (eg, notifications that are relevant only to users who have, or have not, created an account or subscribed to newsletters or email or other subscription services); and
- remember details of data that you choose to submit to us (eg, through online contact forms or by way of comments, forum posts, chat room messages, reviews, ratings, etc).
Many of these cookies are removed or cleared when you log out but some may remain so that your preferences are remembered for future sessions.
Third party cookies
In some cases, third parties may place cookies through this site. For example:
- Datadog and Sentry to assess app and site performance, feature usage, and error tracking, and Datadog to make session recordings of some website visits (see "Website monitoring and session recordings" in section 6);
- Stadia Maps and Azure Maps to provide location and weather information;
- Front Chat to provide customer support chat functionality;
- Firebase Cloud Messaging (Google) and Apple Push Notification Services to deliver push notifications about ride alerts and app updates;
- third party social media applications (eg, Facebook, Twitter, LinkedIn, Pinterest, YouTube, Instagram, etc) may use cookies in order to facilitate various social media buttons and/or plugins in this site.
5. How we may use your personal information
Your personal information may be used in order to:
- verify your identity;
- assist you to make purchases through this site;
- process any purchases of services that you may make through this site, including charging, billing and collecting debts;
- make changes to your account;
- respond to any queries or feedback that you may have;
- conduct appropriate checks for credit-worthiness and for fraud;
- prevent and detect any misuse of, or fraudulent activities involving, this site;
- conduct research and development in respect of our services;
- collect data in an anonymised form to better understand and provide for user needs or provide information to third parties e.g. popular routes, suburbs, usage times or urban planning;
- gain an understanding of your information and communication needs or obtain your feedback or views about our services in order for us to improve them; and/or
- maintain and develop our business systems and infrastructure, including testing and upgrading of these systems,
and for any other purpose reasonably considered necessary or desirable by Party Onbici in relation to the operation of our business.
From time to time we may email our customers with news, information and offers relating to our own services. We do not share your contact details with third parties for their own marketing.
Your personal information may also be collected so that Party Onbici can promote and market products and services to you. This is to keep you informed of products, services, and special offers we believe you will find valuable and may continue after you cease acquiring products and services from us. If you would prefer not to receive promotional or other material from us, please let us know and we will respect your request.
You can unsubscribe from such communications at any time if you choose.
6. When we may disclose your personal information
Information provided to suppliers
When you acquire or access any other goods or services from a third party supplier through this site, we will provide to that supplier such information as is necessary to enable it to process and administer your order.
Such information will include personal information about you, including (without limitation) your name and contact details.
Information provided to other organisations
In order to deliver the services you require or for the purposes set out above, Party Onbici may disclose your personal information to organisations outside Party Onbici. Your personal information may be disclosed to these organisations only in relation to this site, and Party Onbici takes reasonable steps to ensure that these organisations are bound by confidentiality and privacy obligations in relation to the protection of your personal information. These organisations may carry out or provide:
- authentication and authorisation services;
- customer enquiries;
- mailing systems;
- billing and debt-recovery functions;
- information technology services;
- marketing, telemarketing and sales services;
- market research; and
- website usage analysis.
In addition, we may disclose your personal information to:
- your authorised representatives or legal advisers (when requested by you to do so);
- credit-reporting and fraud-checking agencies;
- credit providers (for credit-related purposes such as creditworthiness, credit rating, credit provision and financing);
- our professional advisers, including our accountants, auditors and lawyers;
- government and regulatory authorities and other organisations, as required or authorised by law;
- organisations who manage our business strategies, including those involved in a transfer/sale of all or part of our assets or business (including accounts and trade receivables) and those involved in managing our business risk and funding functions; and
- the police or other appropriate persons where your communication suggests possible illegal activity or harm to others.
Mobile App Service Providers
The Party Onbici mobile app shares data with the following third-party service providers who process data on our behalf:
- Sentry (USA, EU) - Crash and error reporting, on by default; you can turn it off in the app's Privacy Center. Receives crash and error reports, performance timings, device information and app state, tagged with a pseudonymous identifier for your installation rather than your account. Any location it receives is rounded to about 1 km.
- Datadog (USA) - Usage analytics and performance monitoring. In the EU, UK, EEA and Switzerland it runs only after you allow it; elsewhere it is on by default and you can turn it off in the app's Privacy Center. Receives app performance metrics, screen views and interactions, device information and the app's installation identifier. The app does not make session recordings (our website does for some visitors; see "Website monitoring and session recordings" below). Any location it receives is rounded to about 1 km.
- Stadia Maps (USA, EU) - Map display, geocoding, and route calculation. Receives map tile coordinates, address search queries, route waypoints, the tracks of rides recorded without a planned route (for bike-path statistics) and the start and end points of rides (for street addresses).
- Azure Maps (USA, EU) - Weather information. Receives your location, usually rounded to about 11 metres; requests for riders in the European Union go to Azure's EU service.
- Front Chat (USA, EU) - Customer support. Receives the information you choose to share in support conversations, plus the app version, platform and language of the app you write from.
- Clicky (USA) - Website analytics. Receives anonymized page view data, browser type, and coarse location. We have disabled cookie-based tracking; Clicky processes IP addresses only for session attribution and does not build user profiles.
- Firebase Cloud Messaging/Apple Push Notification Services (USA) - Push notifications. Receives device tokens; does not receive your location or ride data.
- Firebase App Check (USA) - Checks at launch that requests come from a genuine copy of the app. Receives an identifier for the app installation and a device attestation; does not receive your location or ride data.
- Amazon Rekognition (Amazon Web Services: Sydney for Australian accounts, Frankfurt for European Union accounts) - Screens photos and videos you upload to incident reports and group rides for content that breaks our rules. Receives the photo or video only; photos are processed in memory and videos are deleted after the check.
- Google, Apple and Microsoft sign-in - When you choose to sign in with one of them, the provider confirms your identity to us and shares your name and email address (or an Apple relay address).
Website monitoring and session recordings
Our website uses Datadog (USA) to measure how quickly pages load, find errors and understand how the site is used. For a sample of visits, Datadog also makes a session recording. A session recording is a reconstruction of the web page and how you moved through it: the pages you viewed, the layout of each page, and your clicks, scrolling and mouse movements. It is not a video of your screen, and it captures nothing outside our website.
- What is masked: Your browser masks the content of the page before anything is sent. Text and images are replaced with placeholders, and everything you type into forms (including passwords, messages and searches) is hidden. So a recording does not show your name, your ride details or anything you type.
- Who is recorded: We make session recordings only on the website we run from Australia. We do not record visitors in the EU, UK, EEA, Switzerland or Brazil, or anyone using our European Union website, even if they allow performance cookies. The mobile app does not make session recordings.
- Link to your account: If you are signed in, a recording is tagged with a random account identifier, not your name or email address. This lets us look into problems you report to us.
- Why we do it: To find and fix bugs and problems that make the site hard to use. Our legal basis is our legitimate interest in running a reliable service.
- How long we keep it: Datadog keeps recordings for up to 30 days and then deletes them.
- How to opt out: Turn off performance cookies under "Manage cookies" at the bottom of any page. If your browser sends a Do Not Track or Global Privacy Control signal, we do not load Datadog at all.
All service providers are bound by Data Processing Agreements (DPAs) that require them to:
- Process data only for the specified purposes
- Implement appropriate security measures
- Delete data upon our request
- Notify us of any data breaches within 72 hours
- Comply with applicable data protection regulations (GDPR, LGPD, APP)
For users in the EU, transfers to providers outside the EU are protected by Standard Contractual Clauses (SCCs) or equivalent legal safeguards. To request a copy of our Data Processing Agreements, please contact privacy@partyonbici.com.
7. Contacting us about privacy
If you would like more information about the way we manage personal information that we hold about you, or are concerned that we may have breached your privacy, please contact us by email to privacy@partyonbici.com or by post.
Access to your personal information
In most cases, you may have access to personal information that we hold about you. We will handle requests for access to your personal information in accordance with the Australian Privacy Principles.
All requests for access to your personal information must be directed to the Privacy Officer by email using the email address provided above or by writing to us at our postal address.
We will deal with all requests for access to personal information as quickly as possible. Requests for a large amount of information, or information that is not currently in use, may require further time before a response can be given. We may charge you a fee for access if a cost is incurred by us in order to retrieve your information, but in no case will we charge you a fee for your application for access.
In some cases, we may refuse to give you access to personal information that we hold about you. This may include circumstances where giving you access would:
- be unlawful (eg, where a record that contains personal information about you is subject to a claim for legal professional privilege by one of our contractual counterparties);
- have an unreasonable impact on another person’s privacy; or
- prejudice an investigation of unlawful activity.
We may also refuse access where the personal information relates to existing or anticipated legal proceedings, and the information would not be accessible by the process of discovery in those proceedings.
If we refuse to give you access, we will provide you with reasons for our refusal.
Correcting your personal information
We will amend any personal information about you that is held by us and that is inaccurate, incomplete or out of date if you request us to do so. If we disagree with your view about the accuracy, completeness or currency of a record of your personal information that is held by us, and you ask us to associate with that record a statement that you have a contrary view, we will take reasonable steps to do so.
8. Storage and security of your personal information
We are committed to maintaining the confidentiality of the information that you provide us and we will take all reasonable precautions to protect your personal information from unauthorised use or alteration.
In our business, personal information may be stored both electronically (on our computer systems and with our website hosting provider) and in hard-copy form. Firewalls, anti-virus software and email filters, as well as passwords, protect all of our electronic information. Likewise, we take all reasonable measures to ensure the security of hard-copy information.
9. Third party websites
You may click-through to third party websites from this site, in which case we recommend that you refer to the privacy statement of the websites you visit. This Privacy Policy applies to this site only and Party Onbici assumes no responsibility for the content of any third party websites.
Re-marketing
Party Onbici does not use re-marketing or behavioural advertising services (such as Google Ads or Facebook/Meta pixels), and we do not place advertising cookies or pixel tags on this site. If this ever changes, we will update this policy and ask for your consent before any such tracking is enabled.
10. GDPR
Party Onbici welcomes the General Data Protection Regulation (“GDPR”) of the European Union (“EU”) as an important step forward in streamlining data protection globally. We intend to comply with the data handling regime laid out in the GDPR in respect of any personal information of data subjects in the EU that we may obtain.
GDPR rights
The requirements of the GDPR are broadly similar to those set out in the Privacy Act and include the following rights:
- you are entitled to request details of the information that we hold about you and how we process it. For EU residents, we will provide this information for no fee;
- you may also have a right to:
- have that information rectified or deleted;
- restrict our processing of that information;
- stop unauthorised transfers of your personal information to a third party;
- in some circumstances, have that information transferred to another organisation; and
- lodge a complaint in relation to our processing of your personal information with a local supervisory authority; and
- where we rely upon your consent as our legal basis for collecting and processing your data, you may withdraw that consent at any time.
If you object to the processing of your personal information, or if you have provided your consent to processing and you later choose to withdraw it, we will respect that choice in accordance with our legal obligations. However, please be aware that:
- such objection or withdrawal of consent could mean that we are unable to provide our services to you, and could unduly prevent us from legitimately providing our services to other clients subject to appropriate confidentiality protections; and
- even after you have chosen to withdraw your consent, we may be able to continue to keep and process your personal information to the extent required or otherwise permitted by law, in particular:
- to pursue our legitimate interests in a way that might reasonably be expected as part of running our business and which does not materially impact on your rights, freedoms or interests; and
- in exercising and defending our legal rights and meeting our legal and regulatory obligations.
Storage and processing by third parties
Data that we collect about you may be stored or otherwise processed by third party services with data centres based outside the EU, such as Amazon Web Services, Microsoft Azure, Apple, and the service providers listed in section 6 (eg, Sentry, Datadog, Stadia Maps, Clicky).
We consider that the collection and such processing of this information is necessary to pursue our legitimate interests in a way that might reasonably be expected (eg, to analyse how our clients use our services, develop our services and grow our business) and which does not materially impact your rights, freedom or interests.
Party Onbici requires that all third parties that act as “data processors” for us provide sufficient guarantees and implement appropriate technical and organisational measures to secure your data, only process personal data for specified purposes and have committed themselves to confidentiality.
Duration of retention of your data
We will only keep your data for as long as is necessary for the purpose for which it was collected, subject to satisfying any legal, accounting or reporting requirements.
At the end of any retention period, your data will either be deleted completely or anonymised (for example, by aggregation with other data so that it can be used in a non-identifiable way for statistical analysis and business planning). In some circumstances, you can ask us to delete your data.
Keeping your information up-to-date
To ensure that your personal information is accurate and up to date, please promptly advise us of any changes to your information by contacting our data protection officer by email at privacy@partyonbici.com or by post.
11. California Consumer Privacy Act (CCPA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) regarding your personal information:
Your CCPA Rights
- Right to Know: You can request disclosure of the categories and specific pieces of personal information we have collected about you, the categories of sources, our business purposes for collecting the information, and the categories of third parties with whom we share it.
- Right to Delete: You can request deletion of your personal information, subject to certain exceptions.
- Right to Opt-Out of Sale: You have the right to opt out of the "sale" of your personal information. Party Onbici does not sell personal information in the traditional sense, but we respect your right to opt out of any data sharing that could be considered a "sale" under CCPA's broad definition.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
Categories of Personal Information Collected (Preceding 12 Months)
In the preceding 12 months we have collected the following categories of personal information, from the sources, for the business purposes, and with disclosure to the categories of third parties shown below. We have not sold or shared (for cross-context behavioural advertising) personal information in the preceding 12 months.
| Category | Examples | Sources | Business purpose | Disclosed to |
|---|---|---|---|---|
| Identifiers | Name, email address, account identifiers, app installation identifiers, push notification tokens | Directly from you; automatically from your device | Account creation, authentication, communication, ride synchronization, diagnostics | Hosting and email service providers, crash reporting and analytics providers (Sentry, Datadog), push notification providers (see section 6) |
| Internet or other electronic network activity | Pages viewed, app interactions, browser and device type, anonymised analytics, session recordings of some website visits | Automatically from your device | Analytics, security, debugging, service improvement | Analytics and monitoring providers (Clicky, Datadog, Sentry) |
| Geolocation data | GPS ride routes (when you synchronize rides), live positions during group rides and shared rides, locations for weather and search | Your device | Ride recording and backup, group rides, weather, mapping and routing, aggregated infrastructure statistics | Mapping and weather providers (Stadia Maps, Azure Maps); other riders in your group ride; people you share a live ride link with |
| Audio or visual information | Profile photos, incident report photos, and group ride photos and videos you upload | Directly from you | Profile display, incident reports, group ride galleries, content moderation | Hosting providers; content moderation (Amazon Rekognition) |
| Characteristics of protected classifications | Age or year of birth; gender, if you provide it | Directly from you | Minimum age and ride age limits; aggregate statistics | Hosting providers |
| Inferences | Not collected — we do not build behavioural profiles | — | — | — |
Retention periods for each category are set out in the data retention table in this policy.
Do Not Sell My Personal Information
Party Onbici does not sell your personal information to third parties. We may share information with service providers who help us operate our business, but these relationships are not "sales" under CCPA. If you wish to opt out of any sharing that could be considered a sale, please contact us at privacy@partyonbici.com or use the cookie management preferences on our website.
Exercising Your Rights
To exercise your CCPA rights, you may:
- Email us at privacy@partyonbici.com
- Export your data through your account settings
- Delete your account through the account deletion feature
We will verify your identity before processing your request. We aim to respond within 45 days, as required by CCPA.
12. Lei Geral de Proteção de Dados (LGPD) - Brazil
If you are a resident of Brazil, you have specific rights under the Lei Geral de Proteção de Dados (LGPD):
Your LGPD Rights
- Confirmation and Access: You have the right to confirm whether we process your personal data and to access such data.
- Correction: You can request correction of incomplete, inaccurate, or outdated data.
- Anonymization, Blocking, or Deletion: You can request anonymization, blocking, or deletion of unnecessary or excessive data, or data processed in non-compliance with LGPD.
- Data Portability: You can request portability of your data to another service provider.
- Deletion: You can request deletion of personal data processed with your consent.
- Information about Sharing: You have the right to information about public and private entities with which we share your data.
- Information about Consent: You have the right to information about the possibility of not providing consent and the consequences of such refusal.
- Revocation of Consent: You can revoke your consent at any time.
Legal Basis for Processing
We process your personal data under the following legal bases as defined by LGPD:
- Your consent, where applicable
- Performance of a contract with you
- Compliance with legal obligations
- Legitimate interests, balanced with your rights and freedoms
International Transfers
Your data may be transferred to and processed in Australia and other countries. We ensure appropriate safeguards are in place, including contractual protections that meet LGPD requirements.
13. Data Protection Officer
Party Onbici has appointed a Data Protection Officer (DPO) / Encarregado to oversee our compliance with data protection regulations including GDPR, LGPD, and CCPA.
DPO Contact Information
- Email: dpo@partyonbici.com
- General Privacy Inquiries: privacy@partyonbici.com
DPO Responsibilities
Our Data Protection Officer is responsible for:
- Monitoring compliance with data protection laws and policies
- Advising on data protection impact assessments
- Acting as the point of contact for data subjects and supervisory authorities
- Handling data subject requests (access, deletion, portability)
- Coordinating breach notification procedures
Response Times
We aim to respond to all data protection inquiries within:
- GDPR requests: Within 30 days
- CCPA requests: Within 45 days
- LGPD requests: Within 15 days
14. Data Breach Notification Procedure
Party Onbici upprätthåller en omfattande dataintrångsprocedur för att följa GDPR, LGPD och andra föreskrifter.
72-timmars meddelandeåtagande
GDPR & LGPD-efterlevnad: I händelse av ett personuppgiftsbrott som innebär en risk för dina rättigheter och friheter kommer vi att meddela relevant tillsynsmyndighet inom 72 timmar.
Vad utgör ett dataintrång?
Ett personuppgiftsbrott är en säkerhetsincident som leder till:
- Förstöring av personuppgifter
- Förlust av personuppgifter
- Ändring av personuppgifter
- Obehörigt utlämnande av personuppgifter
- Obehörig åtkomst till personuppgifter
Vår intrångshanteringsprocess
| Tidslinje | Åtgärd |
|---|---|
| 0-24 timmar | Intrångsdetektering, begränsning och initial bedömning av omfattning och allvar |
| 24-48 timmar | Riskbedömning, bevisbevarande och förberedelse av anmälan |
| 48-72 timmar | Anmälan till tillsynsmyndigheter (GDPR: relevant EU-dataskyddsmyndighet, LGPD: ANPD) |
| Så snart som möjligt | Direkt underrättelse till berörda individer vid hög risk för rättigheter och friheter |
Meddelandeinnehåll
Våra meddelanden om intrång kommer att innehålla:
- Intrångets art och kategorier av berörda uppgifter
- Ungefärligt antal berörda individer
- Namn och kontaktuppgifter för vårt dataskyddsombud
- Troliga konsekvenser av intrånget
- Vidtagna eller föreslagna åtgärder för att hantera intrånget
- Rekommendationer för berörda individer att skydda sig
Regionala tillsynsmyndigheter
| Region | Myndighet | Meddelandedeadline |
|---|---|---|
| 🇪🇺 EU (GDPR) | Ledande tillsynsmyndighet (Italien: Garante per la protezione dei dati personali) | 72 timmar |
| 🇧🇷 Brasilien (LGPD) | ANPD - Autoridade Nacional de Proteção de Dados | 72 timmar (rimlig tidsram) |
| 🇦🇺 Australien (Integritetslag) | OAIC - Australiens informationskommissionärs kontor | Så snart som möjligt (inom 30 dagar) |
| 🇺🇸 Kalifornien (CCPA/CPRA) | Kaliforniens riksåklagare | Snabb underrättelse till berörda konsumenter |
Hur vi skyddar mot intrång
- Kryptering av alla personuppgifter i vila och under överföring
- Regelbundna säkerhetsrevisioner och penetrationstester
- Flerfaktorsautentisering för all personalåtkomst
- Automatiserad hotdetektering och övervakning (Datadog, AWS GuardDuty)
- Regelbunden säkerhetsutbildning för alla anställda
- Dataminimering - vi samlar endast in det vi behöver
Rapportera ett säkerhetsproblem
Om du tror att du har upptäckt en säkerhetsbrist eller potentiellt dataintrång, vänligen rapportera det omedelbart.
- Säkerhetsteam: security@partyonbici.com
- Dataskyddsombud: dpo@partyonbici.com
15. Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements.
Retention Periods
| Datatyp | Lagringsperiod |
|---|---|
| Kontodata (namn, e-post, profil) | Tills du raderar ditt konto |
| Reshistorik och rutter | Skiljs från ditt konto när du raderar det och sparas sedan för sammanställd statistik i upp till 10 år efter inspelningen |
| Synkroniserad turdata (mobilapp) | 10 år, eller tills du begär radering |
| Enhetslokal identifierare för synkronisering | Sparas med de synkade turer de skickades med |
| Push-aviseringar aktiverade | Inaktiveras efter 30 dagar utan användning; raderas med ditt konto |
| Turdeltaganderegister | Bevaras i 2 år efter festdatumet |
| Serverloggfiler (IP-adresser, förfrågningar) | 1 år |
| Felloggar och kraschrapporter | 90 dagar |
| Säkerhetskopior | 30 dagar efter radering |
| Samtyckesregister (för efterlevnad) | 7 år |
| Betalnings-/transaktionsregister | 7 år (lagkrav) |
After Retention Period
När lagringsperioden löper ut kommer dina uppgifter att:
- Permanent raderade, eller
- Anonymiserade (aggregerade med andra data så att de inte kan användas för att identifiera dig)
Early Deletion
Du kan när som helst begära tidig radering av dina uppgifter på följande sätt:
- Genom att använda funktionen för kontoradering i dina profilinställningar
- Genom att kontakta vårt dataskyddsombud på dpo@partyonbici.com
Obs: Vissa uppgifter kan behållas längre om det krävs enligt lag eller för legitima affärsändamål.
16. Changes to this Privacy Policy
From time to time, it may be necessary for us to revise this Privacy Policy. Any changes will be in accordance with any applicable requirements under the Privacy Act and the Australian Privacy Principles.
We may notify you about changes to this Privacy Policy by posting an updated version on this site.
If you require any further information about the Privacy Act and the Australian Privacy Principles, you can visit the Federal Privacy Commissioner's website (see www.privacy.gov.au).