Политика за поверителност
Последна актуализация: март 2026
Ronda е ангажирана да защитава вашата поверителност и да спазва GDPR. Тази политика обяснява как събираме, използваме и защитаваме вашите лични данни.
1. Data Controller
The data controller responsible for your personal data is: Provare Ltd. Email: dpo@ronda.community Website: https://ronda.zone If you have any questions about how we handle your data, please contact us at the email address above.
Данни, които събираме
We collect the following categories of personal data when you use Ronda:
Account Data
Your name, email address, and profile picture. If you sign in with Google OAuth, we receive your name, email, and profile photo from Google. If you register with email and password, we store a securely hashed version of your password.
Incident Report Data
When you submit a theft report, we collect the incident location (latitude/longitude), description, date and time, theft type (bicycle, motorbike, phone, car, or GPS cool-down spot), and any optional details you provide. Your identity as the reporter is stored but never displayed publicly.
Technical Data
We collect hashed IP addresses (never stored in raw form), browser type and version, device type, operating system, and referring website. This data is used for security, rate limiting, and abuse prevention.
Consent Records
We maintain an immutable log of all consent actions you take (e.g. cookie preferences, account creation), including timestamps, to comply with our record-keeping obligations under UK GDPR.
Location Data
If you enable push notifications for nearby safety alerts, we process your approximate location to deliver relevant notifications. We also use location data from incident reports to generate safety heatmaps. We use the Nominatim geocoding service (operated by OpenStreetMap) to convert addresses to coordinates.
Правно основание (GDPR Член 6)
Under UK GDPR Article 6, we process your personal data on the following legal bases:
Как използваме вашите данни
Показване на сигнали за инциденти на картата. Генериране на оценки за безопасност и топлинни карти. Изпращане на сигнали за безопасност (при съгласие). Подобряване на платформата. Предотвратяване на злоупотреби.
Споделяне на данни
Не продаваме лични данни. Местоположенията на инциденти са публични (без идентичност на докладващия). Анонимизирани данни могат да бъдат споделени с правоприлагащи органи или изследователи. Доставчиците на удостоверяване получават само данни, необходими за вход.
6. Third-Party Services
We use the following third-party services to operate Ronda. Each processes data as described below:
Google (OAuth & AdSense)
Google OAuth is used for account sign-in. When you sign in with Google, we receive your name, email, and profile picture. Google AdSense is used to display advertisements on the platform. AdSense may set cookies and collect browsing data to serve personalised ads. You can manage ad personalisation at Google's Ad Settings. Google's privacy policy: https://policies.google.com/privacy
OpenStreetMap / Nominatim
We use OpenStreetMap tiles to render our interactive maps and the Nominatim geocoding service to convert addresses to geographic coordinates. These requests may include location queries and your IP address. OpenStreetMap's privacy policy: https://wiki.osmfoundation.org/wiki/Privacy_Policy
Supabase (Database Hosting)
Our database is hosted on Supabase (PostgreSQL with PostGIS for geographic data). All incident and account data is stored in Supabase's infrastructure. Supabase applies row-level security (RLS) to restrict data access. Supabase's privacy policy: https://supabase.com/privacy
Vercel (Application Hosting)
The Ronda web application is hosted on Vercel. Vercel processes HTTP requests including IP addresses and request metadata. Vercel's privacy policy: https://vercel.com/legal/privacy-policy
Съхранение на данни
Данните за акаунта се съхраняват, докато е активен. Личните данни се изтриват в рамките на 30 дни от искане за изтриване. Анонимизираните сигнали се запазват за обществена безопасност. Дневниците за съгласие се съхраняват 5 години за съответствие.
Бисквитки
Cookies are small text files stored on your device. We use the following types of cookies:
Essential Cookies
Required for the website to function. These include session cookies for authentication (NextAuth session token), locale preference, cookie consent preferences, and CSRF protection tokens. These cannot be disabled.
Analytics Cookies
Help us understand how visitors use the site, including page views and navigation patterns. These are only set if you consent via the cookie banner.
Marketing / Advertising Cookies
Set by Google AdSense to serve relevant advertisements. These cookies may track your browsing activity across websites. You can opt out via the cookie banner or through Google's Ad Settings.
You can manage your cookie preferences at any time using the cookie banner, which is accessible from the bottom of any page. You can also clear cookies through your browser settings. Rejecting non-essential cookies will not affect the core functionality of Ronda.
Вашите права съгласно GDPR
Under the UK General Data Protection Regulation, you have the following rights regarding your personal data. These rights apply to all personal data we hold about you.
- Право на достъп — Изтеглете всичките си данни от Настройки на акаунта.
- Право на коригиране — Актуализирайте информацията в профила си по всяко време.
- Право на изтриване — Изтрийте акаунта си и всички лични данни от Настройки на акаунта.
- Преносимост на данните — Експортирайте данните си в машинно четим формат JSON.
- Ограничаване на обработката — Оттеглете съгласието за конкретна обработка на данни.
- Право на възражение — Възразете срещу обработка, основана на легитимен интерес.
- Оттегляне на съгласие — Оттеглете съгласието си по всяко време, без това да засяга предишната обработка.
To exercise any of these rights, visit your Account Settings page at /account, or contact us at dpo@ronda.community. We will respond to your request within 30 days. If we need more time, we will inform you within the initial 30-day period.
10. Data Security
We take the security of your data seriously and implement the following measures: • All data in transit is encrypted using TLS/HTTPS. • IP addresses are cryptographically hashed before storage — we never store raw IP addresses. • Passwords (for email/password accounts) are securely hashed using industry-standard algorithms. • Our database uses row-level security (RLS) policies to ensure users can only access data they are authorised to see. • We apply rate limiting and flood protection to prevent abuse of the reporting system. • Content filtering automatically flags reports containing discriminatory language. • Security headers (Content Security Policy, HSTS, X-Frame-Options) protect against common web attacks. While no system can guarantee absolute security, we regularly review our security practices and respond promptly to any identified vulnerabilities.
11. International Data Transfers
Ronda is operated by Provare Ltd., a UK company. Our hosting providers Supabase and Vercel may process data in data centres located outside the United Kingdom, including in the United States and the European Economic Area. Where personal data is transferred outside the UK, we ensure that appropriate safeguards are in place, including: • Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner. • Adequacy decisions where the UK government has determined that a country provides an adequate level of data protection. • Contractual commitments from our service providers to protect your data to UK GDPR standards.
12. Children's Data
Ronda is not intended for use by anyone under the age of 13. We do not knowingly collect personal data from children under 13. If you are between 13 and 18, you should review this privacy policy with a parent or guardian. If we become aware that we have collected personal data from a child under 13, we will take steps to delete that data as soon as possible. If you believe a child under 13 has provided us with personal data, please contact us at dpo@ronda.community.
13. Anonymised Data Licence
By submitting incident reports to Ronda, you grant Provare Ltd. a non-exclusive, worldwide, royalty-free licence to use, display, and distribute the anonymised incident data (with all personal identifiers removed) as part of the community safety dataset. This is a licence, not a transfer of ownership. You retain all rights over your personal data under UK GDPR, including the right to request deletion at any time. Anonymised data that can no longer be linked to you is not considered personal data and may be retained after account deletion. We do not claim ownership of your personal data. We do not sell personal data to third parties.
Длъжностно лице по защита на данните
Свържете се с нашето DPO на dpo@ronda.community за запитвания относно защитата на данните.
Надзорен орган
Имате право да подадете жалба до местния орган за защита на данните.
16. Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. For material changes, we will notify registered users by email before the changes take effect. The updated policy will be posted on this page with a new effective date. We encourage you to review this page periodically. Your continued use of Ronda after changes are published constitutes acceptance of the updated policy.