Skip to main content

Privacybeleid

Laatst bijgewerkt: maart 2026

Ronda zet zich in voor de bescherming van je privacy en naleving van de AVG. Dit beleid legt uit hoe we je persoonlijke gegevens verzamelen, gebruiken en beschermen.

1. Data Controller

The data controller responsible for your personal data is: Provare Ltd. Email: dpo@ronda.community Website: https://ronda.zone If you have any questions about how we handle your data, please contact us at the email address above.

Gegevens die we verzamelen

We collect the following categories of personal data when you use Ronda:

Account Data

Your name, email address, and profile picture. If you sign in with Google OAuth, we receive your name, email, and profile photo from Google. If you register with email and password, we store a securely hashed version of your password.

Incident Report Data

When you submit a theft report, we collect the incident location (latitude/longitude), description, date and time, theft type (bicycle, motorbike, phone, car, or GPS cool-down spot), and any optional details you provide. Your identity as the reporter is stored but never displayed publicly.

Technical Data

We collect hashed IP addresses (never stored in raw form), browser type and version, device type, operating system, and referring website. This data is used for security, rate limiting, and abuse prevention.

Consent Records

We maintain an immutable log of all consent actions you take (e.g. cookie preferences, account creation), including timestamps, to comply with our record-keeping obligations under UK GDPR.

Location Data

If you enable push notifications for nearby safety alerts, we process your approximate location to deliver relevant notifications. We also use location data from incident reports to generate safety heatmaps. We use the Nominatim geocoding service (operated by OpenStreetMap) to convert addresses to coordinates.

Rechtsgrondslag (AVG Artikel 6)

Under UK GDPR Article 6, we process your personal data on the following legal bases:

Consent (Article 6(1)(a)) — When you create an account, opt in to push notifications, or accept non-essential cookies. You may withdraw consent at any time.
Performance of a Contract (Article 6(1)(b)) — Processing necessary to provide the Ronda service to you, including displaying your reports on the map and managing your account.
Legitimate Interest (Article 6(1)(f)) — Processing anonymised and aggregated incident data to generate community safety heatmaps and risk scores, content moderation to prevent abuse, and platform security measures such as rate limiting and duplicate detection.
Legal Obligation (Article 6(1)(c)) — Maintaining consent records, responding to valid law enforcement requests, and retaining data required by applicable law.

Hoe we je gegevens gebruiken

Incidentmeldingen weergeven op de kaart. Veiligheidsscores en heatmaps genereren. Veiligheidswaarschuwingen verzenden (indien aangemeld). Het platform verbeteren. Misbruik voorkomen.

Gegevens delen

We verkopen geen persoonlijke gegevens. Incidentlocaties zijn openbaar (zonder identiteit van de melder). Geanonimiseerde gegevens kunnen worden gedeeld met wetshandhaving of onderzoekers. Auth-providers ontvangen alleen login-noodzakelijke gegevens.

6. Third-Party Services

We use the following third-party services to operate Ronda. Each processes data as described below:

Google (OAuth & AdSense)

Google OAuth is used for account sign-in. When you sign in with Google, we receive your name, email, and profile picture. Google AdSense is used to display advertisements on the platform. AdSense may set cookies and collect browsing data to serve personalised ads. You can manage ad personalisation at Google's Ad Settings. Google's privacy policy: https://policies.google.com/privacy

OpenStreetMap / Nominatim

We use OpenStreetMap tiles to render our interactive maps and the Nominatim geocoding service to convert addresses to geographic coordinates. These requests may include location queries and your IP address. OpenStreetMap's privacy policy: https://wiki.osmfoundation.org/wiki/Privacy_Policy

Supabase (Database Hosting)

Our database is hosted on Supabase (PostgreSQL with PostGIS for geographic data). All incident and account data is stored in Supabase's infrastructure. Supabase applies row-level security (RLS) to restrict data access. Supabase's privacy policy: https://supabase.com/privacy

Vercel (Application Hosting)

The Ronda web application is hosted on Vercel. Vercel processes HTTP requests including IP addresses and request metadata. Vercel's privacy policy: https://vercel.com/legal/privacy-policy

Gegevensbewaring

Accountgegevens bewaard zolang actief. Persoonlijke gegevens gewist binnen 30 dagen na verwijderingsverzoek. Geanonimiseerde meldingen bewaard voor openbare veiligheid. Toestemmingslogboeken bewaard 5 jaar voor naleving.

Cookies

Cookies are small text files stored on your device. We use the following types of cookies:

Essential Cookies

Required for the website to function. These include session cookies for authentication (NextAuth session token), locale preference, cookie consent preferences, and CSRF protection tokens. These cannot be disabled.

Analytics Cookies

Help us understand how visitors use the site, including page views and navigation patterns. These are only set if you consent via the cookie banner.

Marketing / Advertising Cookies

Set by Google AdSense to serve relevant advertisements. These cookies may track your browsing activity across websites. You can opt out via the cookie banner or through Google's Ad Settings.

You can manage your cookie preferences at any time using the cookie banner, which is accessible from the bottom of any page. You can also clear cookies through your browser settings. Rejecting non-essential cookies will not affect the core functionality of Ronda.

Je rechten onder de AVG

Under the UK General Data Protection Regulation, you have the following rights regarding your personal data. These rights apply to all personal data we hold about you.

  • Recht op inzage — Download al je gegevens vanuit Accountinstellingen.
  • Recht op rectificatie — Werk je profielinformatie op elk moment bij.
  • Recht op vergetelheid — Verwijder je account en alle persoonlijke gegevens vanuit Accountinstellingen.
  • Gegevensoverdraagbaarheid — Exporteer je gegevens in machineleesbaar JSON-formaat.
  • Beperking van verwerking — Trek toestemming in voor specifieke gegevensverwerking.
  • Recht van bezwaar — Maak bezwaar tegen verwerking op basis van gerechtvaardigd belang.
  • Toestemming intrekken — Trek toestemming op elk moment in zonder eerdere verwerking te beïnvloeden.

To exercise any of these rights, visit your Account Settings page at /account, or contact us at dpo@ronda.community. We will respond to your request within 30 days. If we need more time, we will inform you within the initial 30-day period.

10. Data Security

We take the security of your data seriously and implement the following measures: • All data in transit is encrypted using TLS/HTTPS. • IP addresses are cryptographically hashed before storage — we never store raw IP addresses. • Passwords (for email/password accounts) are securely hashed using industry-standard algorithms. • Our database uses row-level security (RLS) policies to ensure users can only access data they are authorised to see. • We apply rate limiting and flood protection to prevent abuse of the reporting system. • Content filtering automatically flags reports containing discriminatory language. • Security headers (Content Security Policy, HSTS, X-Frame-Options) protect against common web attacks. While no system can guarantee absolute security, we regularly review our security practices and respond promptly to any identified vulnerabilities.

11. International Data Transfers

Ronda is operated by Provare Ltd., a UK company. Our hosting providers Supabase and Vercel may process data in data centres located outside the United Kingdom, including in the United States and the European Economic Area. Where personal data is transferred outside the UK, we ensure that appropriate safeguards are in place, including: • Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner. • Adequacy decisions where the UK government has determined that a country provides an adequate level of data protection. • Contractual commitments from our service providers to protect your data to UK GDPR standards.

12. Children's Data

Ronda is not intended for use by anyone under the age of 13. We do not knowingly collect personal data from children under 13. If you are between 13 and 18, you should review this privacy policy with a parent or guardian. If we become aware that we have collected personal data from a child under 13, we will take steps to delete that data as soon as possible. If you believe a child under 13 has provided us with personal data, please contact us at dpo@ronda.community.

13. Anonymised Data Licence

By submitting incident reports to Ronda, you grant Provare Ltd. a non-exclusive, worldwide, royalty-free licence to use, display, and distribute the anonymised incident data (with all personal identifiers removed) as part of the community safety dataset. This is a licence, not a transfer of ownership. You retain all rights over your personal data under UK GDPR, including the right to request deletion at any time. Anonymised data that can no longer be linked to you is not considered personal data and may be retained after account deletion. We do not claim ownership of your personal data. We do not sell personal data to third parties.

Functionaris voor gegevensbescherming

Neem contact op met onze FG via dpo@ronda.community voor vragen over gegevensbescherming.

Toezichthoudende autoriteit

Je hebt het recht een klacht in te dienen bij je lokale gegevensbeschermingsautoriteit.

16. Changes to This Policy

We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. For material changes, we will notify registered users by email before the changes take effect. The updated policy will be posted on this page with a new effective date. We encourage you to review this page periodically. Your continued use of Ronda after changes are published constitutes acceptance of the updated policy.