Legal Notice
This document is an English translation of the official Polish version.
It is provided for convenience and informational purposes only.
In the event of any discrepancy or inconsistency between this translation and the Polish version, the Polish version shall prevail and remain the legally binding version.
Legal Information
Spinly Privacy Policy
Last updated:
Data Controller
The controller of personal data is Yaroslav Bulba, conducting Spinly business as a sole proprietorship.
Contact: info@spinly.rent.
- Yaroslav Bulba, sole proprietor operating under the business name Spinly
- Tax ID (NIP): 8943276263
- REGON: 543567309
- correspondence address: ul. Węgliniecka 21/12, 54-106 Wrocław, Poland
- e-mail: info@spinly.rent
Scope of Collected Data
We may process data necessary for the operation of the Website, Application, and rental services, in particular:
Data is collected to the extent necessary to achieve the described purposes and in accordance with GDPR.
- account and authentication data, such as user identifier, email, sign-in method, and account status
- profile and contact data, such as first and last name, phone number, city, address, postal code, apartment number, language, and profile photo
- identification data required for rental verification, such as date of birth, PESEL, identity document number, and a photo of the identity document
- application and rental data, such as application status, selected plan, bike, battery, accessories, dates, rental history, checklists, damages, and service notes
- agreement and signature data, such as agreement number, document snapshot, signature submitted in the Application, PDF files, signed PDF files, hashes, and acceptance history
- payment, Security Deposit, and refund data, such as payment status, fee history, invoices, Stripe identifiers, limited payment method data, Recurring Subscriptions, refunds, and chargebacks
- support data, such as message content, case status, unread counters, support metadata, and attachments submitted by the User
- notification data, such as push tokens, platform, application version, and notification preferences
- technical, security, and audit data, such as logs, device or session identifiers, backend events, webhooks, administrator roles, actions in the Administrative Panel, and service records
- Website data, such as interaction events, campaign parameters stored locally in the browser, language preference, and data submitted through forms
PESEL and Identity Documents
PESEL, date of birth, identity document number, and a photo of the identity document are processed to verify the Renter’s identity, conclude and perform the Rental Agreement, protect property, prevent abuse, and pursue or defend against claims.
These data are required to provide the rental, unless Spinly indicates an alternative verification path.
Access to these data should be limited to persons and systems for which it is necessary to manage the rental, settlements, security, or claims.
Purpose of Processing
Data is used for the following purposes:
- creating and managing the account and authenticating the User
- managing the profile, rental applications, and communication with the User
- verifying the Renter’s identity, protecting property, and preventing abuse
- concluding, signing, and performing the Rental Agreement
- assigning the bike, battery, and accessories, and managing the active rental
- managing payments, the Security Deposit, Recurring Subscriptions, invoices, refunds, and overdue amounts
- handling support, complaints, returns, repairs, and service matters
- sending transactional email notifications, push notifications, and in-Application messages
- maintaining accounting records and fulfilling legal and tax obligations
- pursuing and defending against claims, preventing fraud, and ensuring system security
- administering the Website, Application, Administrative Panel, and technical infrastructure
- Website analytics, campaign performance measurement, and improving service operation
Legal Basis for Processing
The legal bases for processing are, respectively:
- Article 6(1)(b) GDPR, where processing is necessary to conclude or perform an agreement or to take steps before concluding it
- Article 6(1)(c) GDPR, where processing is necessary to comply with a legal obligation, in particular accounting, tax, or claim-related obligations
- Article 6(1)(f) GDPR, where processing is necessary for Spinly’s legitimate interests, such as security, property protection, abuse prevention, claims handling, support, audit, and service development
- Article 6(1)(a) GDPR, where processing is based on consent, for example for certain notification settings, marketing consents, or optional features, if such consent is required
Payments and Stripe
Payments are handled by Stripe. Stripe may process card data, customer, transaction, payment, subscription, invoice, refund, and chargeback identifiers, as well as data required to prevent abuse and fulfill regulatory obligations.
Spinly does not store full payment card data. Spinly stores information needed to manage payments and settlements, such as the Stripe customer identifier, payment status, fee history, subscriptions, refunds, and limited payment method data, for example brand, last digits, and expiry date.
A payment method may be saved in Stripe in order to collect recurring fees, the Security Deposit, additional fees, overdue amounts, and other amounts due in connection with the rental.
Technical Providers: Firebase, Google, Resend, and FCM
Firebase and Google services may be used for the operation of the Website, Application, and Spinly backend, including Firebase Authentication, Firestore, Firebase Storage, Firebase Functions, and Firebase Cloud Messaging.
These services may process account, profile, application, rental, document, photo, signature, payment, support, notification, technical log, audit log, and service data.
Transactional emails may be sent through the email provider Resend. Push notifications may be handled by Firebase Cloud Messaging, which processes push tokens, device platform, application version, and data necessary to deliver the notification.
Support, Attachments, and Device Permissions
As part of customer support, Spinly processes message content, case status, support metadata, contact history, unread message counters, and attachments submitted by the User, including photos.
The Application may request access to the camera or photo library to add a profile photo, submit a photo of an identity document, or add an attachment to a support case.
The Application may request consent for push notifications to provide information about the account, agreement, payments, rental, return, support, and security. The User may manage device permissions in the operating system settings.
Agreements, Signatures, Administrative Panel, and Logs
Spinly processes data needed to generate, sign, store, and make available rental documents, including document content, agreement number, snapshot of terms, signature submitted in the Application, PDF files, signed PDF files, file identifiers, document hashes, and acceptance history.
Data may also be processed in the Administrative Panel used to manage users, applications, rentals, payments, support, returns, refunds, bikes, and service.
For security, accountability, and access control purposes, Spinly may maintain technical logs, webhook logs, audit logs, administrator roles and permissions, and administrative action history.
Recipients, Processors, and Transfers Outside the EEA
Data may be entrusted or disclosed to service providers necessary for Spinly operations, in particular cloud infrastructure and database providers, Firebase/Google, the payment processor Stripe, the email provider Resend, the push notification provider Firebase Cloud Messaging, hosting providers, Website analytics tools, technical, accounting, legal, and service support, application stores, and entities authorized by law.
If data is transferred outside the European Economic Area, the Controller applies the required protection mechanisms, in particular an adequacy decision, standard contractual clauses, or other bases provided for by GDPR.
Website, localStorage, and Google Tag Manager
On the Spinly website, technical and analytics data may be processed, including interaction events, legal page views, campaign parameters stored locally in the browser, language preference, and data submitted through contact forms.
Spinly may use Google Tag Manager or similar tools to manage tags and analytics events.
Detailed rules for cookies, localStorage, and analytics tools should be described in the Privacy Policy or a separate cookie policy, if such tools are used.
Data Retention Period
Data is stored for the period necessary to achieve the purposes for which it was collected, and then for the period required by law or needed to pursue and defend against claims. In particular:
- account and profile data are stored for the duration of account use and, after account deletion, are deleted or anonymized to the extent possible
- identity documents, PESEL, and verification data are stored for the period needed to manage the rental, security, property protection, claims, and legal obligations
- agreements, signatures, PDF files, rental history, protocols, checklists, payment, refund, and Security Deposit data may be stored for the period required for settlements, accounting, taxes, chargebacks, fraud prevention, and pursuing or defending against claims
- support messages and attachments may be stored as support history, evidence of service performance, or evidence in a matter
- push tokens and notification preferences are stored as long as needed to deliver notifications or until notifications are disabled, the User logs out, the account is deleted, or the token expires
- technical logs, webhook logs, audit logs, administrator roles, and service records are stored for the period needed for security, accountability, technical support, audit, claims, and legal obligations
- backups may contain data for a limited period resulting from the backup cycle and are restored only in justified cases
Account Deletion and Effects of Deletion
The User may submit an account deletion request in the Application or through another channel indicated by Spinly.
After successful account deletion, Spinly deletes or anonymizes profile data to the extent technically and legally possible and may delete selected profile files.
Deletion may be temporarily blocked or performed to a limited extent if there is an active rental, active or unsettled application, overdue payment, unsettled Security Deposit, open support case, legal obligation, accounting obligation, tax obligation, need to prevent abuse, or need to pursue or defend against claims.
Data concerning agreements, signatures, payments, refunds, invoices, rental history, support, audit logs, claims, and legal obligations may be retained for the required period despite account deletion.
Public Description of Account Deletion
Spinly provides a public description of how to submit an account deletion request in the Application and outside the Application.
The description should indicate what data is deleted or anonymized, what data may be retained, for what period and for what reason, and when deletion may be temporarily blocked due to an active rental, active or unsettled application, payments, Security Deposit, support, legal obligations, security, abuse prevention, or claims.
Required and Optional Data
Providing data marked as required in the Website or Application is necessary to create an account, verify identity, conclude or perform a Rental Agreement, manage payments, or fulfill legal obligations.
Providing optional data, such as certain support attachments, a profile photo, or voluntary preferences, is voluntary but may facilitate handling the matter.
Refusal to provide required data may prevent use of the rental service or selected Application features.
Security and App Store Declaration Consistency
Spinly applies technical and organizational measures to protect data, in particular access control, limiting administrative permissions, audit logs, transmission security, and security mechanisms of infrastructure providers.
The scope of data described in the Privacy Policy should be consistent with Apple App Privacy and Google Play Data Safety declarations, including with respect to contact data, identifiers, financial data, payment history, photos and files, identification data, support content, diagnostic data, account data, notification data, and data collected by the SDKs and backend used.
User Rights
The User has the right to:
The User also has the right to lodge a complaint with the supervisory authority.
- access data
- rectify data
- erase data
- restrict processing
- object to processing
Contact
info@spinly.rent