Privacy Policy
Last updated: 2026-09-28
Draft prepared for launch review. Legal requirements depend on where the operator is established and where users live. This text must be reviewed by a qualified lawyer before the service goes live.
We collect as little personal data as the service needs to work. We don't sell personal data, and we don't use advertising or analytics trackers.
1. Who is responsible
The controller responsible for your personal data is [not configured — set in environment before launch], [not configured — set in environment before launch]. Contact: [not configured — set in environment before launch]. See the imprint for full details.
2. What we process, why, and on what legal basis
| Data | Purpose | Legal basis (GDPR) | Kept for |
|---|---|---|---|
| Email address, username, password hash | Creating and securing your account | Contract, Art. 6(1)(b) | Until you delete your account. Accounts whose email is never confirmed are deleted after 7 days. |
| Session record (hashed session ID, browser user-agent, created/last-seen time) | Keeping you signed in; letting you see and end sessions | Contract, Art. 6(1)(b) | Up to 30 days of inactivity, or until you sign out |
| Builds, comments, likes, saved builds, reports you file | Providing the builder and community features | Contract, Art. 6(1)(b) | Until you delete them or your account |
| IP address and email (as a one-way hash in rate-limit counters) | Rate limiting to prevent abuse and brute-force attacks | Legitimate interest in security, Art. 6(1)(f) | Up to 1 hour (length of the limit window), then deleted |
| Single-use email tokens (stored hashed) | Verifying your email, resetting your password | Contract, Art. 6(1)(b) | 24 hours (verification, email change) or 1 hour (reset), then invalid |
| Two-step verification (encrypted authenticator secret, hashed recovery codes), if you turn it on | Protecting your account | Contract, Art. 6(1)(b) | Until you turn it off or delete your account |
| Moderation records (reports, removal decisions, moderation log) | Keeping the community safe; handling complaints | Legitimate interest, Art. 6(1)(f) | 12 months after the case is closed |
| Builder drafts and preferences in your browser's local storage | Remembering your work on your own device | Strictly necessary for a feature you use | Until you clear your browser data |
We don't ask for your real name, date of birth, address or payment details. Please don't put personal information in public build descriptions or comments.
3. Children
Accounts are for people aged 16 or older (or the minimum age of digital consent in your country, if lower and permitted). The kids-bike builder is meant for parents and guardians; children should not create accounts.
4. The build assistant
The build assistant runs on our own servers using rules and catalog data. Your messages are not sent to any external AI provider and are not stored. If we add an external AI provider in future, we will update this policy first and only send what the feature needs — never your email or account details. See the AI disclaimer.
5. Processors and recipients
We use these service providers (processors) under data-processing agreements. The list below must be completed with the providers actually chosen for launch:
- Hosting provider — runs the website and stores server logs: [not configured — set in environment before launch]
- Database provider — stores account and build data: [not configured — set in environment before launch]
- Email provider — sends verification, password-reset and email-change emails only: [not configured — set in environment before launch]
- Have I Been Pwned (breached-password check) — when you choose a password, we send only the first 5 characters of its SHA-1 hash to check whether it appeared in a known data breach. Your password, the full hash, your email and your IP address are not sent.
Product photos are fetched and optimised by our own server; your browser does not contact the photo host. Fonts are served from our own domain. Links to retailers open the retailer's website, which then has its own privacy policy.
6. International transfers
We aim to store data within the EU/EEA. If a provider processes data outside the EU/EEA, we rely on an adequacy decision or Standard Contractual Clauses. Details depend on the providers chosen for launch and will be listed here.
7. Your rights
- Access and portability: download all your data as a JSON file from your account page.
- Correction: change your username and email address in your account settings.
- Erasure: delete your account at any time — see Deleting your account.
- Objection and restriction: contact us at the address above.
- Complaint: you can lodge a complaint with your local data-protection authority.
We answer requests within one month.
8. Security
Passwords are stored only as Argon2id hashes. Session and email tokens are stored hashed. All traffic uses HTTPS, cookies are HttpOnly and SameSite, and sign-in and other sensitive actions are rate limited. Access to production data is limited to people who need it.
9. Data breaches
If a personal-data breach is likely to put your rights at risk, we notify the competent supervisory authority within 72 hours of becoming aware of it and inform affected users without undue delay, as required by Articles 33–34 GDPR.
10. Changes
We will announce material changes to this policy on the website before they take effect.