Data controller/operator: Bon Aleksei Michailovich.
Data-subject contact: support@motohub.app.
This Policy applies to Motohub and explains what data is processed, why, on what basis, with whom it is shared, how long it is retained, and how Users can exercise their rights.
1. Scope and principles
This Policy covers the mobile app, website, APIs, support, social features and related Motohub services. Personal data is processed lawfully, fairly, for specified purposes, with data minimisation, accuracy, retention limits and appropriate security.
2. Data categories
Account data: email, login, nickname, password hash, date of birth or age category, optionally provided gender, preferences, language, country and account status.
Profile and social data: avatar, photos, motorcycle details, friends, follows, blocks, reactions, comments, posts, reports, achievements and ranking information.
Routes and location: coordinates, timestamps, accuracy, speed, heading, distance, elevation, route points, start/finish information, related photos and visibility choices. While the User has started a trip, location may be collected in the background when the app is minimized or the screen is off.
Trip and sensor data: duration, average and maximum speed, elevation, lean angles, jumps and other derived metrics where supported.
Health data: only User-authorised heart-rate records read from Google Health Connect for the selected trip period, plus derived minimum, average and maximum values. Motohub does not write data back unless expressly disclosed.
Communications: message text, attachments, sender/recipient, timestamps, delivery state, conversation identifiers, reports and blocks.
Technical data: IP address, device and OS, app version, language, timezone, installation/push identifiers, network events, diagnostics, crash and security logs.
Support and purchase data: support data and, for purchases, transaction identifiers, plan, subscription status and expiry; normally not full payment-card details.
3. Sources
Data comes from the User, automatically from the device/app, from Health Connect with permission, app stores, infrastructure providers, and other Users when they interact, mention or report the User.
4. Purposes and legal bases
Contract performance: accounts, route recording, statistics, social features, chats, rankings, support, purchases and syncing.
Consent: background location, photo/camera access, heart-rate reading, optional marketing and other processing where consent is required. An OS permission is not always the same as legal consent.
Legitimate interests where available: security, fraud prevention, diagnostics, improvement, defence of rights and aggregated analytics, subject to balancing.
Legal obligations: regulatory requests, accounting, retention, restriction and deletion duties. Explicit consent or another permitted basis is used for special-category health data.
5. Background location
Background access is used only during a trip recording initiated by the User so that the route continues while the app is minimized or the screen is off. Permission can be withheld or revoked, which may disable or limit background recording. Sharing precise location with others depends on publication and visibility choices.
6. Health Connect
Heart-rate data is read only after the feature is enabled and permission is granted. It is used for trip statistics and not for advertising, credit, insurance, employment decisions or sale to data brokers. Revocation stops new access but does not necessarily delete previously saved trip statistics; those can be deleted with the trip or Account.
7. Public and social Content
Information posted publicly or to friends is visible to the selected audience. Other Users may capture or redistribute it outside the Service. The Operator continues to treat public Content as personal data where applicable.
8. Chats and moderation
Messages are stored for delivery, sync, history, abuse prevention and complaint handling. Staff access is limited to support requests, reports, safety, technical diagnosis or lawful demands. Automated systems may detect spam, malicious links and abuse.
9. Recipients and processors
Data may be accessed by authorised personnel and vendors for hosting, backup, email and push delivery, crash monitoring, maps, geocoding, weather, support, security and app-store operations, only as necessary.
The list to verify before publication may include Motohub infrastructure in Russia; nic.ru; Yandex Cloud or other Yandex services; Firebase Cloud Messaging and/or Crashlytics only if actually used; Google Health Connect; Google Play; and Apple App Store.
The Operator does not sell personal data and does not provide health data to advertising networks.
10. International transfers
Foreign providers may process limited technical data outside a User’s country. Transfers occur only with a lawful basis, required filings or permissions, and appropriate safeguards.
For Russian citizens, collection and core database operations are organised in Russia where required by Russian law, and legally required procedures are followed before cross-border transfers. For EEA data, adequacy decisions, Standard Contractual Clauses or another Chapter V GDPR mechanism are used where required.
11. Retention
Account/profile: while active and normally up to 30 days to complete deletion, unless longer retention is required.
Routes, photos and trip statistics: until the item or Account is deleted; backups normally expire within 90 days.
Messages: while available to participants or until deletion under Service functionality; complaint evidence may be retained for up to three years or the applicable limitation period.
Technical logs: normally up to 12 months; security and abuse evidence up to three years where necessary.
Transaction records are retained for statutory accounting and consumer-law periods.
12. Deletion
Users can delete individual items and request Account deletion in-app or by email. Identity verification may be required. Active data is normally deleted or anonymised within 30 days and backups within a cycle of up to 90 days, subject to legal, security, dispute and accounting exceptions.
Deleting a sender’s copy may not delete a recipient’s copy unless a delete-for-everyone feature is available. Third-party screenshots and redistributions are outside the Operator’s control.
13. User rights
Depending on applicable law, Users may request information, access, correction, restriction, deletion, objection, withdrawal of consent and data portability, and may complain to a supervisory authority or court. Requests should be sent to the contact email with enough information to verify identity. The target response period is 30 days unless applicable law provides otherwise. Withdrawal does not affect earlier lawful processing or processing based on another legal ground.
14. Automated processing
Rankings and recommendations may be generated automatically but are not intended to produce legal or similarly significant effects. Users may challenge a moderation action or obvious ranking error.
15. Security and incidents
Measures include access controls, encryption in transit, password hashing, logging, backups, patching, network protection and incident response. No system is completely secure. Required notifications to individuals and authorities will be made following a qualifying incident.
16. Children
The Service is for adults aged 18+. The Operator does not knowingly seek children’s data. An underage Account may be suspended and data deleted unless another lawful basis applies.
18. Changes
Material updates will be communicated in-app, on the website or by email. The revised Policy applies from the stated date unless fresh consent is required.
19. Contact and complaints
Data requests: support@motohub.app.
Controller/operator: Bon Aleksei Michailovich.
Users may also complain to Roskomnadzor, their local data protection authority or a competent court.