Політика конфіденційності
Останнє оновлення: березень 2026
Ronda зобов'язується захищати вашу конфіденційність та дотримуватися GDPR. Ця політика пояснює, як ми збираємо, використовуємо та захищаємо ваші персональні дані.
1. Data Controller
The data controller responsible for your personal data is: Provare Ltd. Email: dpo@ronda.community Website: https://ronda.zone If you have any questions about how we handle your data, please contact us at the email address above.
Дані, які ми збираємо
We collect the following categories of personal data when you use Ronda:
Account Data
Your name, email address, and profile picture. If you sign in with Google OAuth, we receive your name, email, and profile photo from Google. If you register with email and password, we store a securely hashed version of your password.
Incident Report Data
When you submit a theft report, we collect the incident location (latitude/longitude), description, date and time, theft type (bicycle, motorbike, phone, car, or GPS cool-down spot), and any optional details you provide. Your identity as the reporter is stored but never displayed publicly.
Technical Data
We collect hashed IP addresses (never stored in raw form), browser type and version, device type, operating system, and referring website. This data is used for security, rate limiting, and abuse prevention.
Consent Records
We maintain an immutable log of all consent actions you take (e.g. cookie preferences, account creation), including timestamps, to comply with our record-keeping obligations under UK GDPR.
Location Data
If you enable push notifications for nearby safety alerts, we process your approximate location to deliver relevant notifications. We also use location data from incident reports to generate safety heatmaps. We use the Nominatim geocoding service (operated by OpenStreetMap) to convert addresses to coordinates.
Правова основа (GDPR Стаття 6)
Under UK GDPR Article 6, we process your personal data on the following legal bases:
Як ми використовуємо ваші дані
Відображення повідомлень про інциденти на карті. Створення оцінок безпеки та теплових карт. Надсилання сповіщень безпеки (за згодою). Покращення платформи. Запобігання зловживанням.
Передача даних
Ми не продаємо персональні дані. Місцезнаходження інцидентів є публічними (без ідентифікації автора повідомлення). Анонімізовані дані можуть передаватися правоохоронним органам або дослідникам. Провайдери авторизації отримують лише дані, необхідні для входу.
6. Third-Party Services
We use the following third-party services to operate Ronda. Each processes data as described below:
Google (OAuth & AdSense)
Google OAuth is used for account sign-in. When you sign in with Google, we receive your name, email, and profile picture. Google AdSense is used to display advertisements on the platform. AdSense may set cookies and collect browsing data to serve personalised ads. You can manage ad personalisation at Google's Ad Settings. Google's privacy policy: https://policies.google.com/privacy
OpenStreetMap / Nominatim
We use OpenStreetMap tiles to render our interactive maps and the Nominatim geocoding service to convert addresses to geographic coordinates. These requests may include location queries and your IP address. OpenStreetMap's privacy policy: https://wiki.osmfoundation.org/wiki/Privacy_Policy
Supabase (Database Hosting)
Our database is hosted on Supabase (PostgreSQL with PostGIS for geographic data). All incident and account data is stored in Supabase's infrastructure. Supabase applies row-level security (RLS) to restrict data access. Supabase's privacy policy: https://supabase.com/privacy
Vercel (Application Hosting)
The Ronda web application is hosted on Vercel. Vercel processes HTTP requests including IP addresses and request metadata. Vercel's privacy policy: https://vercel.com/legal/privacy-policy
Зберігання даних
Дані акаунту зберігаються, поки акаунт активний. Персональні дані видаляються протягом 30 днів після запиту на видалення. Анонімізовані повідомлення зберігаються для громадської безпеки. Журнали згоди зберігаються 5 років для відповідності.
Файли cookie
Cookies are small text files stored on your device. We use the following types of cookies:
Essential Cookies
Required for the website to function. These include session cookies for authentication (NextAuth session token), locale preference, cookie consent preferences, and CSRF protection tokens. These cannot be disabled.
Analytics Cookies
Help us understand how visitors use the site, including page views and navigation patterns. These are only set if you consent via the cookie banner.
Marketing / Advertising Cookies
Set by Google AdSense to serve relevant advertisements. These cookies may track your browsing activity across websites. You can opt out via the cookie banner or through Google's Ad Settings.
You can manage your cookie preferences at any time using the cookie banner, which is accessible from the bottom of any page. You can also clear cookies through your browser settings. Rejecting non-essential cookies will not affect the core functionality of Ronda.
Ваші права згідно з GDPR
Under the UK General Data Protection Regulation, you have the following rights regarding your personal data. These rights apply to all personal data we hold about you.
- Право на доступ — Завантажте всі свої дані з Налаштувань акаунту.
- Право на виправлення — Оновлюйте інформацію свого профілю в будь-який час.
- Право на видалення — Видаліть свій акаунт та всі персональні дані з Налаштувань акаунту.
- Портативність даних — Експортуйте свої дані у машинозчитуваному форматі JSON.
- Обмеження обробки — Відкликайте згоду на конкретну обробку даних.
- Право на заперечення — Заперечте проти обробки на основі законного інтересу.
- Відкликання згоди — Відкликайте згоду в будь-який час без впливу на попередню обробку.
To exercise any of these rights, visit your Account Settings page at /account, or contact us at dpo@ronda.community. We will respond to your request within 30 days. If we need more time, we will inform you within the initial 30-day period.
10. Data Security
We take the security of your data seriously and implement the following measures: • All data in transit is encrypted using TLS/HTTPS. • IP addresses are cryptographically hashed before storage — we never store raw IP addresses. • Passwords (for email/password accounts) are securely hashed using industry-standard algorithms. • Our database uses row-level security (RLS) policies to ensure users can only access data they are authorised to see. • We apply rate limiting and flood protection to prevent abuse of the reporting system. • Content filtering automatically flags reports containing discriminatory language. • Security headers (Content Security Policy, HSTS, X-Frame-Options) protect against common web attacks. While no system can guarantee absolute security, we regularly review our security practices and respond promptly to any identified vulnerabilities.
11. International Data Transfers
Ronda is operated by Provare Ltd., a UK company. Our hosting providers Supabase and Vercel may process data in data centres located outside the United Kingdom, including in the United States and the European Economic Area. Where personal data is transferred outside the UK, we ensure that appropriate safeguards are in place, including: • Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner. • Adequacy decisions where the UK government has determined that a country provides an adequate level of data protection. • Contractual commitments from our service providers to protect your data to UK GDPR standards.
12. Children's Data
Ronda is not intended for use by anyone under the age of 13. We do not knowingly collect personal data from children under 13. If you are between 13 and 18, you should review this privacy policy with a parent or guardian. If we become aware that we have collected personal data from a child under 13, we will take steps to delete that data as soon as possible. If you believe a child under 13 has provided us with personal data, please contact us at dpo@ronda.community.
13. Anonymised Data Licence
By submitting incident reports to Ronda, you grant Provare Ltd. a non-exclusive, worldwide, royalty-free licence to use, display, and distribute the anonymised incident data (with all personal identifiers removed) as part of the community safety dataset. This is a licence, not a transfer of ownership. You retain all rights over your personal data under UK GDPR, including the right to request deletion at any time. Anonymised data that can no longer be linked to you is not considered personal data and may be retained after account deletion. We do not claim ownership of your personal data. We do not sell personal data to third parties.
Відповідальний за захист даних
Зверніться до нашого DPO за адресою dpo@ronda.community з питань захисту даних.
Наглядовий орган
Ви маєте право подати скаргу до місцевого органу захисту даних.
16. Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. For material changes, we will notify registered users by email before the changes take effect. The updated policy will be posted on this page with a new effective date. We encourage you to review this page periodically. Your continued use of Ronda after changes are published constitutes acceptance of the updated policy.