Privacy policy

Last updated: 2026-06-20

Jorge Donet Alberola processes your personal data in accordance with Regulation (EU) 2016/679 (GDPR). For users in the United Kingdom, processing is also governed by the UK GDPR (United Kingdom General Data Protection Regulation) and the Data Protection Act 2018.

1. Data controller

  • Controller: Jorge Donet Alberola
  • Tax ID (DNI): 20025823E
  • Address: Avda. de la Valldigna, 9, 46750 Simat de la Valldigna, Valencia (España)
  • Email: kidstoride@gmail.com
  • Privacy contact: privacidad@kidstoride.com

2. Data we process

  • Identification data: first and last name, ID document where applicable.
  • Contact data: email address, phone number.
  • Children's data: first and last name and date of birth, provided by the parent or legal guardian.
  • Payment data: handled entirely by Stripe Payments Europe Ltd. We never store card numbers.
  • Platform usage data: rides published, bookings, ratings.
  • Real-time location data during an active ride, with your explicit consent. Stored in Redis with a maximum TTL of 1 hour and never persisted in relational databases.

3. Purposes and legal bases

  • Performance of contract: providing the platform service, registration, ride management, billing and operational communications.
  • Compliance with legal obligations: invoicing, taxation, attending administrative or judicial requests.
  • Legitimate interest: fraud prevention, platform security and service improvement.
  • Consent: marketing communications, real-time location, analytics and marketing cookies.

4. Data retention

We retain data while the contractual relationship lasts and, once finished, for the legally required periods to address potential liabilities (generally up to six years for tax purposes).

GPS positions are only retained during the active trip and automatically removed after 1 hour.

5. Recipients and processors

We do not transfer your data to third parties unless legally required. To provide the service we engage the following data processors:

  • Stripe Payments Europe Ltd. (payment gateway, Merchant of Record).
  • Cloudflare Inc. — R2 (file storage: user-uploaded avatars, documents and images).
  • Fly.io Inc. (API hosting and backend services).
  • Vercel Inc. (web application hosting and CDN).
  • Upstash Inc. (managed Redis for ephemeral session and GPS data, and QStash async task queue).
  • Resend Inc. (transactional email delivery).
  • MapTiler AG (map tiles, geocoding and routing — EU).
  • Google LLC — Firebase Cloud Messaging (push notifications), Google Analytics (web analytics) and Google OAuth (social authentication).
  • Apple Inc. (social authentication — Sign in with Apple).
  • Mistral AI S.A.S. (artificial intelligence features — France, EU).
  • PostHog Inc. (product analytics, EU-hosted server).
  • LiveKit Inc. (real-time voice and video communication).

6. International transfers

Some processors may handle data outside the European Economic Area. In such cases, transfers are protected by Standard Contractual Clauses approved by the European Commission or other safeguards recognised by GDPR.

7. Your rights

You may exercise your rights of access, rectification, erasure, objection, restriction of processing, portability and withdrawal of consent by emailing kidstoride@gmail.com or writing to the postal address above, attaching a copy of an identity document.

If you believe processing does not comply with the regulation, you may file a complaint with the relevant supervisory authority. For EU users, this is the supervisory authority in your country of residence. For users in the United Kingdom, the supervisory authority is the Information Commissioner's Office (ICO), ico.org.uk.

8. Children's data

Data of children under 14 is provided exclusively by their parent or legal guardian, who assumes responsibility for its accuracy and for the legitimacy of providing it. The platform does not allow self-registration for users under 14.

Children's data includes height (`heightCm`) and weight (`weightKg`), used exclusively to determine the approved child restraint system required for the child's road safety during trips. These data are processed on the basis of the legal guardian's consent (Art. 6.1.a GDPR) and, given their potential relation to health, also with explicit consent under Art. 9.2.a GDPR. They are not used for any other purpose and are not shared with third parties.

9. Security

We apply the technical and organisational measures necessary to guarantee data confidentiality, integrity and availability: encryption in transit (TLS 1.2+), encryption at rest, access controls, JWT-based strong authentication with refresh tokens, activity logging and regular reviews.

10. Automated decisions and fraud-risk profiling

The platform uses an automated risk-scoring system (`riskScore`) to prevent fraud and protect user safety. This system analyses behavioural patterns on the platform (cancellations, disputes, anomalous activity) and may set an account to `creditBlocked` status, which prevents new bookings.

This decision has significant effects on the user and is subject to Art. 22 GDPR. You have the right not to be subject to a decision based solely on automated processing, to obtain human intervention, to express your point of view and to contest the decision. To exercise this right, contact us at privacidad@kidstoride.com with the subject line "Contest automated decision".

Questions? Email us at kidstoride@gmail.com
Privacy policy | Kidstoride