Motovoy
Back to homepage

PRIVACY POLICY OF THE MOTOVOY PLATFORM

Effective from: 1 June 2026

Version: 1.1

§ 1. General Provisions

  1. This Privacy Policy sets out the rules for processing the personal data of users of the Motovoy online platform available at motovoy.pl (the "Platform").

  2. The controller of personal data is MOTOVOY Sp. z o.o., with its registered office in Zielona Góra (66-001) at ul. Krępa-Sportowa 8, Poland, entered in the Register of Entrepreneurs of the National Court Register (KRS) under number 0001243665, District Court in Zielona Góra, 8th Commercial Division of the KRS, Tax ID (NIP): 9731121734, Statistical No. (REGON): 544845957, e-mail address: kontakt@motovoy.pl (the "Controller").

  3. The Controller processes personal data in accordance with: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 ("GDPR"), the Polish Act on Providing Services by Electronic Means, the Polish Electronic Communications Law, and other applicable provisions of Polish and EU law.

  4. The Controller exercises due care to ensure the protection of the privacy and security of users' personal data.

  5. Use of the Platform constitutes acknowledgement of this Privacy Policy.

§ 2. Scope of Data Processed

  1. Company account data (B2B):

  1. Company name, URL slug (required);

  2. E-mail address, password (hashed using the bcrypt algorithm - not stored in plain text);

  3. Phone number, website (optional);

  4. Address, country of registration (optional);

  5. Company logo - an image file stored on a CDN (optional);

  6. Company description in Polish, English and German (optional);

  7. Business types: transport / storage / tour / rental;

  8. Service languages: PL / EN / DE;

  9. Date and version of the accepted Terms of Service and Privacy Policy;

  10. Newsletter consent (yes/no);

  11. Declaration of holding the required licences and authorisations (yes/no), together with the date submitted;

  12. Registration IP address - recorded automatically when the account is created;

  13. Date of last login for each company user;

  14. Stripe Customer ID;

  15. Billing currency (PLN / EUR).

  1. Individual User data:

  1. Full name (required);

  2. E-mail address, password (hashed with bcrypt);

  3. Phone number (optional);

  4. Date of last login;

  5. Stripe Customer ID (if the user has a subscription).

  1. Contact-inquiry data (Companies' customers - unregistered persons) - Data collected through the contact forms on Listings:

  1. Full name (in all types of inquiries);

  2. E-mail address (in all types of inquiries);

  3. Phone number (optional - transport, tours, rentals);

  4. Motorcycle make and model (transport, storage, tour);

  5. Number of motorcycles (transport, storage);

  6. Motorcycle year of manufacture, engine capacity (cc) - tours;

  7. Years of riding experience - tours;

  8. Driving licence category and year obtained - rental;

  9. Dates (from-to) - all types;

  10. Message content (optional).

  1. Motorcycle tour participant data:

  1. Name, e-mail address, phone number;

  2. Motorcycle make, model, engine capacity;

  3. Experience level (BEGINNER / INTERMEDIATE / ADVANCED / EXPERT);

  4. Emergency contact: name, phone number, relationship - data of a third party (see § 5 para. 3);

  5. Booking and payment status (PENDING / CONFIRMED / CANCELLED / COMPLETED);

  6. Amounts: deposit paid, full price.

  1. Motorcycle storage booking data:

  1. Customer's name, e-mail address, phone number;

  2. Motorcycle make, model, registration number;

  3. Space number, dates, price.

  1. Motorcycle rental booking data:

  1. Customer's name, e-mail address, phone number;

  2. Rental dates, price, deposit;

  3. Payment status (UNPAID / DEPOSIT_PAID / PAID / REFUNDED).

  1. Transport Order data:

  1. Name, e-mail address, phone number of the party placing the order - visible only after a Company has paid for access;

  2. Motorcycle make, model, type; information on whether the motorcycle is roadworthy under its own power;

  3. Route (country and city A -> B);

  4. Budget (range);

  5. Preferred date, date flexibility;

  6. Motorcycle photographs (optional, up to 10 photos).

  1. Company fleet data (internal - visible only to the Company):

  1. Transport vehicles: make, model, year, registration plates, VIN, mileage;

  2. Drivers: name, phone number, e-mail, driving licence number, categories;

  3. Tour guides: as above, plus service languages, licence number;

  4. Service history: event type, dates, notes.

  1. Payment data:

  1. Stripe Session ID for each transaction;

  2. Amount, status (PENDING / COMPLETED / FAILED), package type;

  3. Link to the relevant Listing, storage unit, tour or rental;

  4. Payment card data is NOT stored on the Platform - it is processed solely by Stripe.

  1. Reviews of Companies:

  1. Reviewer's name, city (public);

  2. Reviewer's e-mail address (optional - visible only to the Administrator);

  3. Rating (1-5), comment content;

  4. Status: PENDING / APPROVED / REJECTED.

  1. Technical and operational data:

  1. IP address;

  2. Device and browser data;

  3. JWT session identifiers;

  4. System logs;

  5. Cookie-related data (see the Cookie Policy).

§ 3. Purposes and Legal Bases for Processing

  1. Personal data is processed for the purposes and on the legal bases indicated below:

  2. Provision of services by electronic means, and the operation and management of user accounts - Article 6(1)(b) GDPR (performance of a contract).

  3. Publication of Listings and Transport Orders, and handling of inquiries - Article 6(1)(b) GDPR.

  4. Processing of payments and management of subscriptions - Article 6(1)(b) GDPR.

  5. Verification and moderation of content - Article 6(1)(f) GDPR (the Controller's legitimate interest: security and integrity of the Platform).

  6. Ensuring the security of the Platform and preventing abuse - Article 6(1)(f) GDPR.

  7. Storage of login data and IP addresses - Article 6(1)(f) GDPR (security, detection of abuse).

  8. Establishment, pursuit or defence of claims - Article 6(1)(f) GDPR.

  9. Fulfilment of obligations arising from law (e.g. tax law) - Article 6(1)(c) GDPR.

  10. Maintaining statistics and analysing the platform's operation - Article 6(1)(f) GDPR.

  11. Sending newsletters and marketing information - Article 6(1)(a) GDPR (consent), solely once given.

  12. Storage of tour participants' emergency contact data - Article 6(1)(f) GDPR (legitimate interest: the participant's safety).

§ 4. Disclosure of Personal Data

  1. Personal data may be disclosed to entities cooperating with the Controller solely to the extent necessary to provide the services:

  2. Stripe Inc. - card payment and recurring subscription operator; Stripe stores payment card data. Stripe processes data on the basis of its own terms and privacy policy.

  3. Resend - provider of transactional e-mail delivery services (confirmations, notifications).

  4. Vercel Inc. - application hosting (Next.js) and CDN for image files.

  5. PostgreSQL database provider (Neon / Supabase / own server) - data storage.

  6. Entities providing accounting, legal or administrative services - to the extent required by law.

  7. Public authorities - where such an obligation arises from law.

  8. Where a Transport Order is published, the ordering party's contact details may be disclosed solely to Companies that have purchased a paid Contact Data Unlock. Such Companies are obliged to use the data solely for the purpose of fulfilling the relevant Order.

  9. The Controller does not sell users' personal data.

  10. Data may be transferred outside the European Economic Area solely in accordance with applicable law and subject to appropriate legal safeguards (e.g. standard contractual clauses). Stripe and Vercel are entities operating in the USA - data transferred to them is covered by mechanisms compliant with the GDPR.

§ 5. Special Categories of Data and Special Situations

  1. Transport Order data and the paid-access model:

  1. The contact details of the person publishing a Transport Order are not publicly visible. Access to them is possible solely after a Company has carried out a paid Unlock;

  2. By publishing a Transport Order, the user consents to their contact details being disclosed to Companies that carry out the Unlock, solely for the purpose of fulfilling that Order;

  3. Order data expires automatically or is closed by the Administrator.

  1. Data of Companies' customers (third parties - unregistered):

  1. Data collected through the contact forms on Listings (inquiries, bookings) relates to persons not registered on the Platform;

  2. The Controller acts as the controller of this data, and the Company is the entity to which the data is disclosed for the purpose of handling the inquiry or booking;

  3. This data is stored for the time necessary to handle the matter, and for the period resulting from law (e.g. accounting law).

  1. Tour participant's emergency contact:

  1. Emergency contact data (name, phone number, relationship) relates to a third party who is not a party to the agreement with the Platform;

  2. By providing this data, the tour participant represents that they have that person's consent to process their data for the purpose of ensuring the participant's safety;

  3. This data is available solely to the Company organising the tour and is not disclosed publicly or to other entities.

  1. Companies' internal fleet data:

  1. Data of a Company's employees and associates (drivers, guides) entered into the fleet panel is available solely to that Company;

  2. With respect to this data, the Controller acts as a processor acting on behalf of the Company.

§ 6. Data Retention Period

  1. Company account and Individual User account data - for the period the account exists, and for the time necessary to establish, pursue or defend claims after its deletion.

  2. Contact inquiry and booking data - for the time necessary to handle the matter, and for the period required by law (generally 5 years for tax purposes).

  3. Transport Order data - until the Order expires or is closed, and thereafter for the time necessary to defend claims.

  4. Payment data (Stripe Session ID, amount, status) - for the period required by tax and accounting law.

  5. Logs and IP addresses - for the time necessary to ensure the security of the Platform, no longer than 12 months, unless the law requires longer retention.

  6. Data processed on the basis of consent - until the consent is withdrawn.

  7. Upon expiry of the periods indicated, the data is deleted or anonymised.

§ 7. User Rights

  1. The data subject has the right to:

  1. access their data (Article 15 GDPR);

  2. rectify their data (Article 16 GDPR);

  3. erase their data (Article 17 GDPR);

  4. restrict processing (Article 18 GDPR);

  5. data portability (Article 20 GDPR);

  6. object to processing based on Article 6(1)(f) GDPR (Article 21 GDPR);

  7. withdraw consent at any time, without affecting the lawfulness of processing carried out before its withdrawal;

  8. lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland).

  1. To exercise the above rights, please contact the Controller by e-mail or in writing at the address indicated in § 13.

§ 8. Automated Decision-Making and Profiling

  1. The Controller does not use automated decision-making that produces legal effects or similarly significantly affects the data subject, within the meaning of Article 22 GDPR.

  2. Data may be processed in a partially automated manner (e.g. automatic expiry of Listings via cron processes, automatic activation of a Listing upon confirmation of payment via the Stripe webhook) - this does not, however, constitute profiling producing legal effects.

§ 9. Cookies and Similar Technologies

  1. The Platform uses cookies and similar technologies. The detailed rules governing their use are set out in a separate Cookie Policy available on the Platform.

  2. Cookies may be used for the purposes of: ensuring the proper functioning of the Platform, maintaining the user's session, improving security, conducting statistical analyses, and remembering user preferences.

  3. The user may manage cookie settings via their browser settings or the consent management panel available on the Platform.

§ 10. Data Security

  1. The Controller applies appropriate technical and organisational measures aimed at protecting personal data, in particular:

  1. SSL/TLS encryption of connections;

  2. password hashing using the bcrypt algorithm;

  3. JWT-based authentication with separate tokens for Companies and Administrators;

  4. access control - the contact details of Transport Orders are accessible only after the transaction has been paid for;

  5. authorisation of file-upload endpoints;

  6. protection of cron processes with a Bearer token.

  1. Despite the security measures applied, the use of the internet may involve a risk of a data security breach beyond the Controller's control.

  2. In the event of a personal data breach, the Controller will take the measures required by the GDPR, including notifying the President of the UODO within 72 hours of detecting the breach and, where appropriate, notifying the data subjects.

§ 11. Newsletter and Marketing Communications

  1. The user may consent to receiving a newsletter and commercial information.

  2. Consent may be withdrawn at any time via the unsubscribe link included in every message, or by contacting the Controller.

  3. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

§ 12. Changes to the Privacy Policy

  1. The Controller may amend this Privacy Policy in the event of: changes in law, the development of the Platform's functionality, technological or organisational changes, or the need to clarify the data processing rules.

  2. The current version of the Privacy Policy is published on the Platform together with its effective date. Registered Users will be informed of any material changes by e-mail.

  3. This Privacy Policy is available in Polish, English and German versions. In the event of a discrepancy between the language versions, the Polish-language version shall prevail.

§ 13. Contact

  1. For matters concerning personal data and this Privacy Policy, please contact the Controller:

MOTOVOY Sp. z o.o.

Address: ul. Krępa-Sportowa 8, 66-001 Zielona Góra, Poland

E-mail: kontakt@motovoy.pl

  1. Supervisory authority: President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland, e-mail: kancelaria@uodo.gov.pl