-
Privacy Policy for the Yomoko App
As of: September 2026
We are pleased that you are using the Yomoko app. Below, we inform you about how we process personal data when you use our app, our website, and associated digital services.
Personal data is any information relating to an identified or identifiable natural person.
This privacy policy applies to the Yomoko app, our website, and associated digital services, unless expressly stated otherwise below.
1. Controller
The controller responsible for data processing in connection with the Yomoko app is:
Yomoko UG (haftungsbeschränkt)
Straße der Jugend 18
14974 Ludwigsfelde
Germany
General contact: office@yomoko.app
Support and privacy: support@yomoko.app
Phone: +49 (0)176 98 60 71 58
2. General Use of the App and Technical Data
When downloading the app from an app store, certain data may be processed by the respective app store provider, for example, username, email address, customer number, time of download, device identifier, or payment information. We generally have no influence on this processing. The privacy policies of the respective app store provider apply.
When using our app, we process technical data required to provide the app, operate it securely, and improve it technically. This may include, in particular:
Date and time of access
Time zone information
Content, destination, and type of request
Access status / HTTP status code
Volume of data transferred
Referrer / source of access, if technically transmitted
IP address, shortened or anonymized if applicable
Device information, device identifiers, and technical device parameters
Operating system, app version, and system interface
Language settings
Browser or webview information, if such features are used
Usage and log data
Technical request, connection, and server data
Error, diagnostic, and crash data
The processing is carried out on the basis of Art. 6 para. 1 lit. b GDPR, insofar as it is necessary for the provision of the app and its features. Insofar as the processing serves the security, stability, error analysis, abuse prevention, or technical improvement of our app, it is carried out on the basis of our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR.
In the event of indications of unlawful, abusive, or security-related use, we may retrospectively review log data, insofar as this is necessary for clarification, securing our systems, abuse prevention, or enforcing our rights.
Insofar as necessary for security, authentication, abuse prevention, technical provision, or the operation of individual app features, technical identifiers may also be processed. These may include, in particular, device identifiers, installation IDs, push tokens, app instance IDs, session IDs, and comparable technical identifiers.
3. Age Restriction and Youth Protection
The Yomoko app is directed at users aged 16 and over. Use by persons under 16 is not intended and is not permitted under our Terms of Use.
As part of the registration process, we ask for the date of birth and may technically restrict registration below the age limit. Secure age verification does not take place; users are obligated to provide accurate information.
For individual features, in particular ride recording, location-based game and community features, crews, chats, public leaderboards, or prize winning features, additional age-related restrictions, safety instructions, or terms and conditions of participation may apply.
If we become aware that personal data is being processed contrary to the applicable age requirements, we may take appropriate measures, in particular restricting or deleting the user account and the associated data, unless legal obligations or overriding legitimate interests prevent this.
4. Registration and User Account
Registration is required to use certain features of the app.
For new user accounts, registration and login are currently done via a Google account ("Sign in with Google") or an Apple account ("Sign in with Apple").
In connection with the registration, login, and use of a user account, the following data in particular may be processed:
Email address
Unique user, account, or authentication identifier provided by the respective authentication provider
Name, profile picture, or other basic account information, insofar as provided by the authentication provider
Phone number for existing user accounts originally registered with a phone number, during the transition phase
Username
Date of birth
Profile information
Profile picture
Gender or voluntary profile details
Login and authentication data
Voluntarily provided content and settings
When using "Sign in with Apple," users can choose not to disclose their personal email address. In this case, Apple may provide Yomoko with a private relay email address instead of the personal email address.
Existing user accounts originally registered with a phone number may temporarily continue to use SMS-based authentication during a transition phase to access the existing account and link it to a Google or Apple account supported by Yomoko. During this process, the phone number, one-time authentication codes, and associated technical authentication data may continue to be processed.
The processing is carried out to create, manage, authenticate, and provide the user account, as well as to use the app features, on the basis of Art. 6 para. 1 lit. b GDPR.
Insofar as authentication takes place via Google or Apple, the respective authentication provider may process personal data additionally in accordance with its own privacy policy.
Voluntary details can generally be adjusted or deleted by the user at any time, provided the app offers this option and no legal obligations or legitimate reasons stand in the way.
5. User-Generated Content
Users can provide their own content within the app, for example, text, images, videos, profile information, messages, tours, routes, comments, reviews, community content, or other information.
This content is processed to provide the respective app features, display user profiles, enable communication, operate community features, and make content available within the app.
The processing is carried out on the basis of Art. 6 para. 1 lit. b GDPR. Insofar as content is processed for security, moderation, abuse prevention, or the enforcement of our Terms of Use, this is done on the basis of our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR.
Please note that certain content may be visible to other users depending on the app feature and settings, for example, profile information, published tours, community posts, crew information, or leaderboard details.
If users intentionally publish or share tours, routes, ride content, or comparable content, the information contained therein may be visible to other users depending on the feature and settings. This may also include location-based information such as starting points, destinations, route paths, map areas, timestamps, or associated content.
6. Communication, Chat, and Notifications
The app may provide features for communication between users. In this context, message content, sender and recipient information, timestamps, read status, technical delivery data, and notification settings may be processed.
The processing is carried out to provide the communication features on the basis of Art. 6 para. 1 lit. b GDPR. Insofar as we process data for abuse prevention, security, or technical error analysis, this is done on the basis of Art. 6 para. 1 lit. f GDPR.
If you activate push notifications, we process the technical data required for this, in particular device or installation identifiers, push tokens, and notification settings. The processing is generally based on your consent pursuant to Art. 6 para. 1 lit. a GDPR. You can deactivate push notifications at any time in the app or system settings.
Depending on the operating system, the Apple Push Notification service (APNs) from Apple and Firebase Cloud Messaging (FCM) from Google may be used to send push notifications. In this context, push tokens, device or installation identifiers, technical delivery data, notification settings, and message content may be processed.
Push notifications may be used, in particular, to deliver technical notices, communication notifications, security information, and, if activated, feature-related notices regarding tours, crews, group rides, game rounds, territory statuses, results, or comparable app features.
Insofar as push notifications are required for a feature actively used by you, the processing may additionally be carried out on the basis of Art. 6 para. 1 lit. b GDPR. Insofar as it serves technical security, delivery, or abuse prevention, it is carried out on the basis of Art. 6 para. 1 lit. f GDPR.
7. App Permissions and Consents
For individual features, the app may require access to certain device functions or content. This may include location, camera, photos or media, notifications, or comparable permissions.
Access only takes place if it is necessary for the respective feature and the corresponding permission has been granted. You can revoke granted permissions at any time in the app or system settings. If a permission is deactivated, the affected features cannot be used or can only be used with limitations.
For location-based features, precise location data, background location, or comparable permissions may be required depending on the operating system and feature. This applies in particular to features where a ride is to be recorded while the app is running in the background or the screen is locked.
Insofar as processing is based on your consent, you can revoke this at any time with effect for the future. The lawfulness of the processing carried out up to the revocation remains unaffected.
8. Location Data, Map Features, and Ride Recording
Our app uses location data to provide location-based features. This may include, in particular:
Displaying your own location on a map
Finding users, crews, tours, events, or content in the surrounding area
Planning and displaying tours and routes
Recording rides
Displaying, saving, and subsequently showing recorded routes
Providing a ride history
Map-based community, crew, or game features
Calculating distances, areas, points, statistics, or leaderboards
Security, error analysis, abuse and manipulation prevention for ride, crew, and game features
Depending on the feature used, precise GPS location data, approximate location data, timestamps, start and end times of a ride, distance traveled, map areas, user ID, crew affiliation, movement information, points, statistics, and leaderboard information may be processed.
The app may process location data selectively, for instance, to display users, crews, tours, events, or content in your vicinity or to provide location-based map features.
On the other hand, continuous recording of location data for ride recording, group rides, or location-based game and community features only takes place if you actively start a corresponding feature. During an actively started recording, location processing may continue even if the app is running in the background or the screen is locked. This is necessary so that a ride can still be recorded if the app does not remain open in the foreground continuously during the ride.
Continuous location processing for ride recording or location-based game and community features outside of actively started features does not take place.
You can end an active recording at any time and revoke the location permission at any time in the app or system settings. Without location permission, certain features of the app cannot be used or can only be used with limitations.
The processing of precise location data is generally based on your consent pursuant to Art. 6 para. 1 lit. a GDPR. The processing of ride, route, score, and result data is carried out to provide the respectively used app feature on the basis of Art. 6 para. 1 lit. b GDPR. Insofar as data is processed for security, error analysis, fraud, abuse, or manipulation prevention, this is done on the basis of our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR.
Insofar as information is stored on or read from your terminal device in connection with the respective feature and consent is required for this, this is done in accordance with the applicable requirements of the German Telecommunications-Telemedia Data Protection Act (TDDDG).
9. Location-Based Game and Community Features
Our app may provide location-based game and community features.
Location-based game and community features can link real motorcycle rides with a digital map. Users or crews can conquer or defend virtual areas on a map through real rides, or collect points for these areas. From this use, points, scores, crew results, territory data, leaderboards, or comparable community results can be calculated and displayed.
If you actively use such a feature or start a group ride or a ride recording, location data may be processed continuously during the active ride. Continuous location processing begins when you actively start the ride, the ride recording, the group ride, or the game round, and ends when you stop recording or withdraw the required permission.
This may include, in particular, precise GPS coordinates, timestamps, movement data derived from location data, speed if technically available, start and end times of the ride, distance traveled, map areas, user ID, crew affiliation, as well as game and result data derived from these.
During an active ride, location data is processed and saved at regular technical intervals. This processing serves to record the route driven, provide a ride history, calculate virtual areas or points, update scores, make results verifiable, prevent manipulation, prevent abuse, and ensure technical functionality.
If a feature requires continuous recording, location processing may continue even if the app is running in the background or the screen is locked. This only occurs if the ride, the ride recording, or the location-based game round has been actively started by you or is required for the feature you have activated.
To prevent abuse and manipulation, location and movement data may also be used to check the plausibility of a ride or the physical proximity of participants within a recording.
Permanent location processing outside of actively used or actively started features for ride recording or location-based game and community features does not take place.
You can stop an active recording at any time in the app and revoke the location permission at any time via the app or system settings. If the location permission is deactivated, features such as ride recording or location-based game and community features cannot be used or can only be used with limitations.
The crew, territory, ranking, and result data derived from the use of location-based game and community features may be displayed within the app as well as on the Yomoko website. This may include, in particular, crew names, crew size, scores, rankings, controlled, ridden, or won territories, as well as cartographic territory displays. A regional allocation or rough location specification of a crew may be displayed, insofar as this is necessary to display the crew, territory, or ranking feature.
Precise GPS raw data of individual users, complete individual route paths, and permanent live locations of individual users are generally not displayed publicly on the website for this purpose.
The exact design may vary depending on the feature, round, season, or game mode. Processing only takes place to the extent necessary for the respectively active feature used.
10. Visibility of Location, Ride, Crew, and Result Data
Other users do not automatically see your precise live location. Live locations are not shared with other users as a dedicated live-sharing feature.
Depending on the feature and your settings, however, certain location, ride, crew, or result data may be visible. This may include, in particular, published or shared rides, route information, controlled map areas, points, crew results, leaderboard rankings, completed rides, aggregated statistics, or comparable game and community results.
Leaderboards, territory results, crew results, points, rankings, or comparable result data may be visible publicly within the app depending on the feature.
In addition, certain crew-related game and result data may also be regularly published on our Yomoko website. This may include, in particular, crew name, ranking, score, crew size, regional allocation or rough location specification of the crew, controlled, ridden, or won territories, and a map view. This map view can show at the territory or regional level which crews have ridden, controlled, or won which territories and what score those crews have achieved.
Publication on the website serves to display community, crew, and game features, to visualize scores, leaderboards, and results of location-based game and community features, and to inform the community about current crew and territory results.
Other crews, public leaderboards, and the website generally show only the crew, territory, ranking, or result data intended for the respective feature, not automatically precise GPS raw data, complete individual route paths, or a permanent live location of individual users.
Within a crew, certain activity, route, post, or result data may be visible depending on the feature. Which data crew members or crew administrators can see in detail depends on the respective feature, role, and setting.
If you intentionally publish or share rides, routes, or ride content, location-based information contained therein, such as starting points, destinations, route paths, map areas, or timestamps, may become visible to other users.
Whether and which information is visible depends on the respective app feature, the available settings, and the type of participation.
11. Storage of Location, Ride, and Game Information
Location, movement, route, and ride data are stored to the extent necessary for the respective feature, ongoing recording, displaying ridden routes, providing a ride history, calculating and displaying territories, points, or scores, displaying results, technical error analysis, security, or the prevention of abuse and manipulation.
In the case of ride recordings, group rides, or location-based game and community features, precise location data and route information may remain stored even after a ride or game round is completed. This may be necessary, in particular, to show the route driven at a later date, provide a ride or route history, make scores and territory results verifiable, display territory histories, prevent abuse or manipulation, analyze technical errors, or provide the respective feature.
Precise location and route data are therefore not automatically deleted immediately after a points calculation, insofar as they are still required to display the route driven, for the ride or route history, the verifiability of scores, the allocation or display of territories, the community feature, or the prevention of abuse and manipulation.
Location, route, recording, and movement data may be stored for the duration of the user account and, insofar as they are allocated to crew results, territory histories, leaderboards, scores, abuse prevention, or the verifiability of results, also beyond that.
Derived result data, for example points, territory statuses, crew results, leaderboards, statistics, territory histories, or season results, can be created from location, movement, and route data. This derived data may be stored and displayed for longer, insofar as this is necessary to display ongoing or completed rounds, ensure the verifiability of results, for the community feature, territory history, abuse prevention, or the enforcement of our Terms of Use.
Crew-related result data, territory data, leaderboards, scores, crew size, crew name, regional allocation or rough location specification of the crew, and cartographic displays of ridden, controlled, or won territories may also be stored after the completion of individual rides, rounds, or seasons and displayed within the app or on the Yomoko website, insofar as this is required for the community, ranking, game, territory, or territory history.
Deletion of individual rides or routes within the app may currently not be provided in all cases. However, users can request the deletion of personal data via our support. Insofar as data continues to be required for crew results, leaderboards, territory histories, abuse prevention, or legal purposes, it may be kept in a shortened, aggregated, anonymized, or non-directly user-related form if necessary.
After deletion of a user account, personal profile data is deleted or anonymized, unless legal obligations or overriding legitimate interests stand in the way. Crew-related routes, scores, territory results, leaderboards, scores, crew sizes, website displays, territory histories, or game scores may still be retained, insofar as they are part of the crew, game, community, ranking, or territory history. In this case, the direct link to the deleted user account will be removed or reduced where possible.
If a user is the last member of a crew and the crew is deleted, the data allocated to the crew may also be deleted, unless legal obligations or legitimate interests stand in the way.
Backups are deleted in a timely manner within the framework of regular technical rotation and overwriting cycles.
12. Data Minimization and Protection Measures for Location Features
We design location-based features so that only the data required for the respective feature is processed.
As far as possible and sufficient for the respective purpose, we use derived, shortened, aggregated, or feature-related data instead of precise location data. However, precise location and route data may be required if a feature involves subsequently displaying a ridden route, providing a ride history, the verifiability of a ride, calculating or displaying scores, territories, or points, territory history, or the prevention of abuse and manipulation.
Access to location, ride, and game information is only given to individuals or service providers to the extent necessary for operation, security, error analysis, abuse prevention, manipulation prevention, or the provision of the respective feature.
13. Map, Route, and Geodata Services
To display maps, routes, territories, and location-based features, we use map, route, and geodata services. In particular, services from Mapbox, OpenStreetMap, Google Maps, Scenic, or comparable services may be used.
When using map, route, or geo-features, technical data and location data may be processed, in particular IP address, device information, app and usage data, map sections, zoom levels, timestamps, search queries, route information, location data, or interactions with the map.
The processing is carried out to provide the map, route, and location-based app features on the basis of Art. 6 para. 1 lit. b GDPR. Insofar as precise location data is processed, this is generally based on your consent pursuant to Art. 6 para. 1 lit. a GDPR. Insofar as processing serves the security, error analysis, or improvement of map features, it is carried out on the basis of Art. 6 para. 1 lit. f GDPR.
Depending on the technical integration, recipients of the data may in particular be:
Mapbox, Inc., 740 15th Street NW, 5th Floor, Washington, DC 20005, USA
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, D04 E5W5, Ireland
OpenStreetMap Foundation, St John’s Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom, if directly integrated
Scenic or providers affiliated with Scenic, insofar as corresponding route or map services are integrated
companies and sub-processors affiliated with the aforementioned providers
Processing may also take place outside the European Union or the European Economic Area. Insofar as necessary, such transfer takes place on the basis of suitable safeguards within the meaning of the GDPR, in particular adequacy decisions, the EU-US Data Privacy Framework, standard contractual clauses, or other permissible transfer mechanisms.
An adequacy decision of the European Commission may exist for transfers to the United Kingdom.
14. Hosting, Backend, Databases, and Infrastructure
To operate the app, deliver content, and technically provide our services, we use hosting, storage, backend, database, security, and content delivery services.
These services enable, in particular, the provision of the app infrastructure, the storage and delivery of content, images, files, map and app data, data synchronization, as well as the secure and performant use of the app.
Depending on usage, IP address, device information, technical request and connection data, log data, user account and profile data, content, communication data, location data, ride and crew data, scores, leaderboard information, and other app data in particular may be processed.
The processing is carried out to provide and securely operate the app on the basis of Art. 6 para. 1 lit. b GDPR. Insofar as processing serves technical security, stability, error analysis, abuse prevention, manipulation prevention, performance optimization, or improvement of the app, it is carried out on the basis of our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR. Insofar as precise location data is affected, its processing is generally based on your consent pursuant to Art. 6 para. 1 lit. a GDPR.
Recipients of the data may, in particular, be hosting, backend, database, storage, security, and content delivery providers, as well as their sub-processors.
Where necessary, we conclude contracts with processors pursuant to Art. 28 GDPR.
Processing may also take place outside the European Union or the European Economic Area. Insofar as necessary, such transfer takes place on the basis of suitable safeguards within the meaning of the GDPR, in particular adequacy decisions, the EU-US Data Privacy Framework, standard contractual clauses, or other permissible transfer mechanisms.
15. Backend and Database Services: Supabase
To provide our app infrastructure, user management, and the secure storage and synchronization of app data, we use the backend and database service Supabase.
The provider is SUPABASE PTE. LTD., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513, Singapore.
Depending on usage, user account, profile, content, communication, crew, ride, location, route, score, leaderboard, log, and technical usage data in particular may be processed via this infrastructure. This may include, in particular, IP address, login data, authentication data, saved routes, ride histories, app activities, location data, scores, territory statuses, and technical log data.
The processing is carried out to provide the app and its features, in particular user management, storage, synchronization, ride history, game features, and secure app infrastructure, on the basis of Art. 6 para. 1 lit. b GDPR. Insofar as the processing serves technical security, high availability, performance, error analysis, abuse prevention, manipulation prevention, or improvement of the app, it is carried out on the basis of our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR. Insofar as precise location data is affected, its processing is generally based on your consent pursuant to Art. 6 para. 1 lit. a GDPR.
Recipients of the data may, in particular, be Supabase, companies affiliated with Supabase, and their sub-processors.
We have concluded a data processing agreement with Supabase pursuant to Art. 28 GDPR.
Primary data storage takes place, according to our current technical configuration, in a region within the European Union. Processing by Supabase or its sub-processors outside the European Union or the European Economic Area may nevertheless take place, provided that this is necessary for operation, support, security, or provision of the service and is permissible under data protection law.
Since Supabase is based in Singapore and data transfers may take place to countries outside the European Union or the European Economic Area for which no adequacy decision of the European Commission exists, such transfers only take place on the basis of suitable safeguards pursuant to Art. 44 et seq. GDPR, in particular on the basis of standard contractual clauses of the European Commission pursuant to Art. 46 GDPR and, where necessary, additional protection measures.
16. Firebase, Google, and Apple Services
We use Firebase and Google services, in particular for authentication, cloud storage, database features, server features, push notifications, error analysis, usage analysis, map features, or individual app features. For authentication via an Apple account, "Sign in with Apple" may also be used.
The provider of the Google and Firebase services is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, D04 E5W5, Ireland.
For "Sign in with Apple," services from Apple are additionally used. For users in the European Economic Area, the United Kingdom, and Switzerland, Apple Distribution International Limited, Hollyhill Industrial Estate, Hollyhill, Cork, Ireland, may be responsible for this.
Depending on the service used, user, device, usage, content, communication, location, route, error, and technical data in particular may be processed.
Depending on the service and purpose, the processing is carried out on the basis of Art. 6 para. 1 lit. b GDPR, Art. 6 para. 1 lit. f GDPR, and, insofar as consent is required, Art. 6 para. 1 lit. a GDPR.
Depending on the service used, recipients of the data may in particular be Google Ireland Limited, Google LLC, Alphabet Inc., Apple Distribution International Limited, Apple Inc., and sub-processors.
Where necessary, we have concluded data processing agreements with Google.
Processing may also take place outside the European Union or the European Economic Area, in particular in the USA. Insofar as necessary, such transfer takes place on the basis of suitable safeguards within the meaning of the GDPR, in particular adequacy decisions, the EU-US Data Privacy Framework, standard contractual clauses, or other permissible transfer mechanisms.
The Firebase, Google, and Apple services used may include, in particular:
Firebase Authentication
Firebase Authentication serves the technical registration, login, and authentication of users within the app. New user accounts can use Google or Apple as identity providers for authentication. Existing accounts originally registered with a phone number can temporarily continue to use SMS-based authentication during the transition phase and link the existing account to a supported identity provider.
Depending on the authentication method, email address, the phone number during the transition phase, unique Firebase or provider user IDs, authentication tokens or authentication information, basic account information provided by the authentication provider, user agent, IP address, device information, technical identifiers, and login data in particular may be processed.
The processing is carried out on the basis of Art. 6 para. 1 lit. b GDPR and Art. 6 para. 1 lit. f GDPR.
Sign in with Apple
"Sign in with Apple" is used to authenticate users via an Apple account. Depending on the user's settings and the data provided by Apple, Yomoko may in particular receive a unique Apple user ID, email address, and, if provided, the name or associated authentication information.
If the user selects the Apple feature to hide their email address, Yomoko can receive and process a private relay email address provided by Apple instead of the personal email address.
The processing is carried out for the registration, login, and authentication of the user account on the basis of Art. 6 para. 1 lit. b GDPR.
Firebase Firestore
Firebase Firestore serves as a database to store, synchronize, and provide app data.
IP address, user agent, usage data, technical data and, depending on usage, user account, profile, content, communication, location, route, ride, crew, score, and leaderboard data in particular may be processed.
The processing is carried out on the basis of Art. 6 para. 1 lit. b GDPR, Art. 6 para. 1 lit. f GDPR and, insofar as precise location data or data requiring consent is affected, Art. 6 para. 1 lit. a GDPR.
Firebase Cloud Functions
Firebase Cloud Functions serves the server-side execution of functions required for the operation of individual app features.
IP address, technical request and connection data, log data and, depending on the feature, user, content, communication, location, route, ride, crew, score, or leaderboard data in particular may be processed.
The processing is carried out on the basis of Art. 6 para. 1 lit. b GDPR, Art. 6 para. 1 lit. f GDPR and, insofar as data requiring consent is affected, Art. 6 para. 1 lit. a GDPR.
Firebase Cloud Storage
Firebase Cloud Storage serves the storage and provision of app content, images, files, media, or other user-generated content.
Accessed content, uploaded content, files, images, videos, technical access data, IP address, device information, access method, timestamps, and usage data in particular may be processed.
The processing is carried out on the basis of Art. 6 para. 1 lit. b GDPR, Art. 6 para. 1 lit. f GDPR and, insofar as consent is required, Art. 6 para. 1 lit. a GDPR.
Firebase Cloud Messaging
Firebase Cloud Messaging serves the dispatch and delivery of push notifications and technical messages.
Push tokens, installation ID, device information, technical identifiers, notification settings, message content, delivery, and usage data in particular may be processed.
The processing is carried out on the basis of Art. 6 para. 1 lit. a GDPR, insofar as push notifications are based on your consent, Art. 6 para. 1 lit. b GDPR, insofar as notifications are required for a feature used by you, and Art. 6 para. 1 lit. f GDPR for security, technical delivery, and abuse prevention.
Firebase Crashlytics
Firebase Crashlytics serves the recording and analysis of crash and error reports.
Error data, crash data, unique identifiers, device information, operating system, app version, IP address, and technical usage data in particular may be processed.
The processing is carried out on the basis of our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR in security, stability, troubleshooting, and improvement of the app. Insofar as consent is required, processing is carried out on the basis of Art. 6 para. 1 lit. a GDPR.
Google Analytics for Firebase
Google Analytics for Firebase serves the analysis of app usage, the improvement of features, and the measurement of reach or interactions.
Identifiers, usage data, session duration, IP address, geographic location, operating system, device information, app updates, time of first visit, viewed content, interactions, and technical event data in particular may be processed.
The processing is carried out on the basis of Art. 6 para. 1 lit. a GDPR, insofar as consent is required, and Art. 6 para. 1 lit. f GDPR, insofar as a consent-free, privacy-compliant reach measurement or technical analysis is permissible.
Google Maps
Google Maps can be used to display maps, locations, routes, or location-based information.
Date and time of access, location data, IP address, URL, usage data, search terms, geographic location, device information, and technical access data in particular may be processed.
The processing is carried out on the basis of Art. 6 para. 1 lit. b GDPR, insofar as map features are required to provide the app, Art. 6 para. 1 lit. a GDPR, insofar as precise location data or map services requiring consent are affected, and Art. 6 para. 1 lit. f GDPR for security, stability, and improvement of map features.
Google Gemini
Google Gemini can be used to provide AI-powered features for generating images for motorcycle tours within the app. Prompts actively provided by the user, tour details, or other contextual information required for image generation, as well as the generated images, may be processed. Processing is carried out on the basis of Art. 6 para. 1 lit. b GDPR to provide the respective feature, and Art. 6 para. 1 lit. f GDPR for security and abuse prevention.
17. Cloudflare
We may use Cloudflare to provide our website, interfaces, content, or technical infrastructure securely and with high performance.
The provider is Cloudflare, Inc., USA.
Cloudflare can be used in particular for content delivery, DNS, security features, protection against abuse and attacks, performance optimization, and technical provisioning.
IP address, technical request and connection data, header information, device and browser information, timestamps, security events, and log data in particular may be processed.
The processing is carried out on the basis of Art. 6 para. 1 lit. f GDPR based on our legitimate interest in the security, stability, and high-performance provision of our services, as well as Art. 6 para. 1 lit. b GDPR, insofar as the processing is necessary for the provision of our services.
Processing outside the EU/EEA, in particular in the USA, may take place provided the requirements of Art. 44 et seq. GDPR are met.
18. RevenueCat, App Stores, Payments, and In-App Purchases
Insofar as paid features, in-app purchases, subscriptions, CrewCoins, premium features, or other digital services are offered in the app, payment processing is regularly carried out via the respective app store provider or payment service provider.
To manage in-app purchases, subscriptions, digital permissions, purchase status, entitlements, transaction information, and technical purchase validation, we use RevenueCat.
The provider is RevenueCat, Inc., USA.
Depending on usage, app user ID, device or installation identifiers, product ID, transaction information, purchase and subscription status, entitlement information, technical usage data, and store-related information in particular may be processed.
We generally do not receive complete payment data such as credit card numbers. Processing by the respective app store provider or payment service provider is carried out in accordance with their own privacy policies.
The processing is carried out on the basis of Art. 6 para. 1 lit. b GDPR to provide, manage, and bill paid features, as well as Art. 6 para. 1 lit. f GDPR for security, fraud prevention, technical verification, and abuse prevention. Insofar as legal retention obligations exist, processing is carried out on the basis of Art. 6 para. 1 lit. c GDPR.
Processing outside the EU/EEA, in particular in the USA, may take place provided the requirements of Art. 44 et seq. GDPR are met.
19. Consent Management
We use a consent management tool to manage, store, and document consents and privacy settings.
The provider is Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, Germany.
Consent status, opt-in/opt-out data, timestamp, consent ID, consent type, template version, banner language, user agent, device and browser information, technical IDs, IP address, geographic location, and user settings in particular may be processed.
The processing is carried out on the basis of Art. 6 para. 1 lit. c GDPR, insofar as processing is necessary to fulfill legal obligations, and Art. 6 para. 1 lit. f GDPR, insofar as processing serves our legitimate interest in legally secure documentation of consents.
Insofar as information is stored on or read from your terminal device for this purpose, this is done in accordance with the provisions of the TDDDG.
20. AI-Powered Features
The app may provide AI-powered features, for example, to generate images for motorcycle tours. If you actively use such a feature, the inputs (prompts) you provide, as well as contextual information, may be processed. Processing is carried out to provide the respective AI feature on the basis of Art. 6 para. 1 lit. b GDPR. Insofar as data is processed for security, error analysis, and improvement of the feature, this is done on the basis of Art. 6 para. 1 lit. f GDPR.
21. Scores, Points, Leaderboards, and Potential Prizes
The app can automatically calculate points, scores, leaderboards, territory statuses, or comparable results based on the use of certain features. These calculations serve to provide gamified community features.
Insofar as leaderboards, winners, rankings, or comparable results are determined as part of gamified features, this is done on the basis of the respective terms and conditions of participation and the results achieved within the feature.
Automatically calculated points, leaderboards, or territory statuses can form the basis for displaying scores or determining winners.
Crew-related results, rankings, scores, crew sizes, regional allocations or rough location specifications of crews, territory results, and cartographic territory displays may be published within the app and on the Yomoko website, insofar as this is necessary to display location-based game and community features, community results, the ranking feature, territory history, or game history. The display is generally at the crew, territory, or regional level and not as a publication of precise GPS raw data of individual users.
Insofar as prizes, digital rewards, CrewCoins, boosters, vouchers, or comparable benefits are provided, scores, leaderboards, participation information, user account, and contact data may be processed to determine winners, provide prizes, prevent abuse, and process the respective action.
As far as legally or actually necessary, we reserve the right to perform a manual check, in particular to prevent abuse, manipulation, or fraud.
Details can be found in separate terms and conditions of participation.
22. Analysis, Advertising, Advertising Identifiers, and Partner Offers
We may process usage data to analyze, improve, troubleshoot, measure the reach of, optimize features of, and provide offers within the app.
Insofar as partner offers, vouchers, benefit areas, advertising, or similar content are displayed, technical usage data, interaction data, and, if applicable, pseudonymized or aggregated evaluations may be processed for this purpose.
Personal data will only be passed on to partners if this is necessary to provide the respective offer, if you have given your express consent, or if another legal basis exists.
23. Cookies, Local Storage, and Similar Technologies
To make our app and website user-friendly, operate them securely from a technical standpoint, and provide certain features, we may use cookies, local storage, device identifiers, app instance IDs, session IDs, or comparable technologies.
Some of the cookies or comparable technologies we use are automatically deleted after usage ends. Others remain on your device for a certain period to recognize settings, logins, consents, or other features when you use the app or website again.
If cookies or comparable technologies are used, certain information may be processed depending on the feature, in particular IP address, device information, browser or webview data, language settings, usage data, location data, technical identifiers, consent settings, and timestamps.
Cookies and comparable technologies can serve in particular to store settings, document consents, enable logins, ensure security, provide app features, analyze errors, measure usage, or improve the usability of the app.
Insofar as information is stored in or read from the terminal device, this is done in accordance with the respectively applicable legal requirements, in particular the TDDDG, insofar as this is applicable. Technically necessary storage or access may be permissible without consent. Storage or access that is not necessary only occurs if consent is required and has been granted.
Depending on the purpose, the processing of personal data is carried out on the basis of Art. 6 para. 1 lit. b GDPR, Art. 6 para. 1 lit. c GDPR, Art. 6 para. 1 lit. f GDPR, or on the basis of your consent pursuant to Art. 6 para. 1 lit. a GDPR.
You can change corresponding settings in the app, operating system, or browser. Please note that this may lead to restrictions in the use of individual features.
24. Contact and Support
When you contact us, for example by email, contact form, or via an app feature, we process the data you provide to handle your request. This may include, in particular, name, email address, message, technical metadata, and other information provided by you.
This also applies if you assert information, deletion, data export, or other data protection rights. For support requests and all privacy-related concerns, please use support@yomoko.app.
The processing is carried out on the basis of Art. 6 para. 1 lit. f GDPR. If your request is directed towards entering into or performing a contract or is required to process a user account, processing is additionally carried out on the basis of Art. 6 para. 1 lit. b GDPR. Insofar as we are legally obligated to process the request, processing is carried out on the basis of Art. 6 para. 1 lit. c GDPR.
25. Recipients of Data
Personal data may be transferred to the following categories of recipients, insofar as necessary for the respective purposes:
technical service providers for hosting, content delivery, backend, databases, and storage
providers of map, location, route, and geodata services
authentication, communication, and push service providers
analysis, diagnostics, and security service providers
consent management service providers
payment, app store, and in-app purchase service providers
partners or providers of benefit offers, insofar as necessary for an offer or if you have consented
authorities, courts, or other bodies, insofar as we are legally obligated to do so or must protect our rights
Where necessary, we conclude contracts with processors pursuant to Art. 28 GDPR.
26. Third Country Transfers
Some of the service providers we use may also process personal data outside the European Union or the European Economic Area, in particular in the USA, Singapore, the United Kingdom, or other third countries.
Such transfer only takes place if the requirements of Art. 44 et seq. GDPR are met, for example on the basis of an adequacy decision, the EU-US Data Privacy Framework, standard contractual clauses of the European Commission, additional protection measures, or another permissible legal basis.
27. Retention Period
We store personal data only as long as necessary for the respective purposes or as long as legal retention obligations exist.
Account data is generally stored for the duration of the user account. Content and app data are stored as long as they are required for the respective feature, display within the app, or management of the user account.
Location, recording, route, and movement data are stored as long as necessary for the respective feature, evaluation, display, provision of a ride history, security, abuse prevention, manipulation prevention, or verifiability.
Precise location and route data may remain stored even after a ride or game round is completed, insofar as this is necessary to display the route driven later, provide ride or route histories, make scores verifiable, or prevent abuse and manipulation.
Derived functional data, for example points, crew results, leaderboards, territory statuses, territory histories, statistics, or season results, may be stored and displayed for longer, insofar as this is required for the respective feature, the verifiability of ongoing or completed results, the community display, the ranking feature, or the territory history.
Crew-related result data, rankings, scores, crew sizes, regional allocations or rough location specifications of crews, territory results, and cartographic territory displays may be published and stored within the app and on the Yomoko website, as long as this is required to display the community, crew, ranking, game, territory, or territory history. The display is generally at the crew, territory, or regional level and not as a publication of precise GPS raw data of individual users.
Security, error, and abuse logs may be stored as long as necessary for technical security, error analysis, fraud or manipulation prevention, or to assert, exercise, or defend legal claims.
When personal data is no longer required for the respective purposes, it is deleted, anonymized, aggregated, or further processed in a form that no longer allows direct personal reference, provided that no legal retention obligations, legitimate interests, or technical reasons prevent this.
After deletion of a user account, personal data is deleted or anonymized, unless legal retention obligations, legitimate interests, or technical reasons stand in the way of immediate deletion.
Publicly provided content or already completed community, crew, game, or leaderboard results may, if necessary, continue to be displayed, but where possible without direct allocation to the deleted user account.
Backups are deleted in a timely manner within the framework of regular technical rotation and overwriting cycles.
28. Data Security
We take appropriate technical and organizational measures to protect personal data against loss, misuse, unauthorized access, disclosure, alteration, or destruction.
This includes in particular access restrictions, technical security measures, authorization concepts, and ongoing review of the systems used.
29. Rights of the Data Subject
You have the following rights in accordance with statutory provisions:
Right of access pursuant to Art. 15 GDPR
Right to rectification pursuant to Art. 16 GDPR
Right to erasure pursuant to Art. 17 GDPR
Right to restriction of processing pursuant to Art. 18 GDPR
Right to notification pursuant to Art. 19 GDPR
Right to data portability pursuant to Art. 20 GDPR
Right to withdraw consent granted pursuant to Art. 7 para. 3 GDPR
Right to object pursuant to Art. 21 GDPR
Right to lodge a complaint with a data protection supervisory authority pursuant to Art. 77 GDPR
If you have given consent, you can withdraw it at any time with effect for the future. The lawfulness of the processing carried out up to the withdrawal remains unaffected.
To exercise your data protection rights, please contact us at support@yomoko.app.
30. Right to Object
If we process personal data on the basis of Art. 6 para. 1 lit. f GDPR, you have the right to object to this processing at any time for reasons arising from your particular situation.
We will then no longer process the affected data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing serves to assert, exercise, or defend legal claims.
If we process personal data for the purpose of direct marketing, you can object to this processing at any time. In this case, we will no longer use the data for direct marketing.
31. Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates the GDPR.
The competent authority may in particular be the data protection supervisory authority of your place of residence, your place of work, the place of the alleged violation, or our place of business.
32. Changes to This Privacy Policy
We may adapt this privacy policy if our app, features, services used, or legal requirements change.
The current version is available in the app or on our website.
33. Additional Information for Users in Switzerland and the United Kingdom
Applicable Data Protection Law
For users in Switzerland, the Swiss Federal Act on Data Protection (FADP) and the associated Data Protection Ordinance apply additionally or to the extent applicable. Insofar as this privacy policy refers to the GDPR, the processing of personal data of persons in Switzerland is simultaneously carried out in accordance with Swiss data protection law.
For users in the United Kingdom, the UK GDPR applies together with the Data Protection Act 2018, provided the spatial scope is opened. Insofar as provisions of the GDPR are referred to in this privacy policy, the corresponding provisions of the UK GDPR apply to users in the United Kingdom, to the extent applicable.
Storage on and Access to Terminal Devices
Insofar as the German Telecommunications-Telemedia Data Protection Act (TDDDG) is mentioned in this privacy policy, this only applies within its scope of application in Germany. For users outside Germany, the respective applicable national regulations on the storage of or access to information on terminal devices apply. In the United Kingdom, this includes in particular the Privacy and Electronic Communications Regulations (PECR), to the extent applicable.
International Data Transfers
For users in Switzerland, disclosures of personal data abroad are made in accordance with Art. 16 et seq. FADP. Insofar as the recipient country does not guarantee an adequate level of data protection, we use – where necessary – suitable safeguards, in particular recognized standard data protection clauses and, where necessary, additional protection measures. For correspondingly certified recipients in the USA, the Swiss-U.S. Data Privacy Framework can be used.
For users in the United Kingdom, international data transfers are made in accordance with the UK GDPR and the Data Protection Act 2018. Depending on the recipient and destination country, in particular UK adequacy regulations, the UK Extension to the EU-U.S. Data Privacy Framework, the International Data Transfer Agreement (IDTA), or the UK International Data Transfer Addendum to the EU standard contractual clauses, as well as required additional protection measures, may be used.
Rights and Complaints
Users in Switzerland can assert their rights under the Swiss FADP. Privacy inquiries and complaints can be directed to support@yomoko.app or via the official support channel in the app. The competent independent supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC).
Users in the United Kingdom can exercise their rights under the UK GDPR and the Data Protection Act 2018. Privacy inquiries and complaints can be directed to support@yomoko.app or via the official support channel in the app. Independently of this, there is a right to complain to the Information Commissioner's Office (ICO).
