Privacy Policy

Last updated:

This Privacy Policy explains how Ridewize GmbH processes personal data when you use the Ridewize iOS app (the App), visit ridewize.io (the Website), join a waitlist or newsletter, or contact us. The App and Website are intended for use in Switzerland. This Policy covers only the service Ridewize offers in Switzerland.

The related contractual terms are available in our Terms of Service.

1. Who is responsible for your data

Ridewize GmbH is responsible for how your personal data is used:

Ridewize GmbH
c/o Matthias Grob
Alpenblickstrasse 9b
8733 Eschenbach SG
Switzerland

UID: CHE-262.556.537
Commercial-register number: CH-320.4.103.608-0

For App support, privacy questions, or to exercise your data-protection rights, email support@ridewize.io. For general Website enquiries, email hello@ridewize.io.

2. Data we process

Here is an overview of the personal data we use. Sections 3 to 6 explain the most important parts in more detail.

DataWhy we use itWho may receive itHow long we keep it
Account details: phone number, user ID, and information needed to keep you signed in and protect your account.To create your account, let you sign in, recover access, prevent misuse, and connect your Ridewize records.Supabase provides our account system. Bird/MessageBird receives your phone number and the one-time code needed to send you a login SMS.Usually for as long as you have an account. Some security records may be kept for as long as reasonably needed to protect the service.
Profile details: email address, name, username, birthdate, country, language, time zone, marketing choice, and information about completing onboarding.To complete your profile, confirm that you are at least 13, communicate with you, provide support, and check whether you qualify for an offer.Supabase and, where needed, authorised Ridewize support staff.Usually for as long as you have an account, unless you correct or delete them earlier.
Location and commute information: precise location points collected with your iOS permission, possible and confirmed trips, times, start and end points or nearby public-transport stops, distance, route, and information about how a trip was assessed.To detect and verify public-transport commutes, calculate points and reward eligibility, show your commute history, fix tracking problems, and avoid processing a trip twice.Most detailed location data stays on your phone. Limited commute information is sent to Supabase and Google Routes Platform as explained in Section 3. Apple provides the phone's location features.Detailed location points on your phone are normally deleted after 7 days. Other local tracking information is kept for 30 days. Records needed to provide and protect the service are usually kept for the life of your account, unless deleted earlier.
Temporary information on your phone: location points waiting to be processed or sent, timestamps, processing status, and limited information about the App and your device.To let tracking continue reliably in the background, recover after interruptions, manage phone storage, and diagnose problems.This normally stays on your phone. It is shared with Ridewize only if you choose to send a support package.It is removed by the App's automatic cleanup. The 7-day and 30-day periods above apply to the related information.
Trips, points, rewards, and wallet activity: trip summaries, points, offers you view or choose, wallet items, vouchers, redemptions, and expiry dates.To provide the rewards service, show your balance and history, issue and redeem rewards, apply offer rules, and prevent the same claim or voucher from being used twice.Supabase. A reward partner may receive or see only the voucher or redemption information needed to accept it.Usually for the life of your account and for as long as needed to manage a reward, redemption, or related dispute.
Service, security, and support records: information showing whether a trip was accepted or rejected, records used to prevent duplicate actions, support references, and records of sensitive support access.To keep the service reliable and secure, investigate problems, document support access, and resolve disputes.Supabase and authorised Ridewize staff or support providers.Only for as long as needed for the relevant service, security, support, or dispute purpose.
A commute support package you choose to send: selected detailed location points for one commute, route or stop information, the reason a trip was accepted or rejected, tracking information, and limited App or device details.To investigate a specific problem with tracking, a commute, points, or a reward.Stored privately through Supabase. Only authorised support administrators can access it, and their access is recorded.30 days after we receive it, or earlier where appropriate.
Website use: IP address, requested page, request time, response information, browser or device details, and analytics identifiers or cookies.To deliver, secure, monitor, and improve the Website and understand how it is used.Vercel hosts the Website. Google Analytics and Microsoft Clarity provide Website analytics.Website logs are kept only as long as reasonably needed. Analytics information follows our configured controls and the applicable provider's retention and deletion processes.
Waitlist and newsletter details: your email address and your separate choices about joining the waitlist and receiving the newsletter.To manage the waitlist, send communications you requested, and respect your choices.Ridewize and the providers needed to operate the Website and send the requested communications.Until the relevant list or communication ends, you unsubscribe, or we honour an applicable deletion request.
Messages you send us: your email address, message, attachments, and delivery information.To reply, provide support, handle privacy requests, and keep an appropriate record of the conversation.Ridewize's email or support providers and your email provider.Only for as long as needed to handle and document the request, unless the law or an unresolved claim requires longer.

The App Store privacy information lists precise location, name, email address, phone number, user ID, use of App features, customer support information, diagnostics, and other commute or reward information. These data are linked to your account where applicable. Ridewize does not use them to track you across other companies' apps or websites, or for third-party advertising.

Ridewize does not currently charge users through the App, and the current service does not process payment-card or bank-account data.

3. Location and background tracking

Ridewize uses public-transit travel to determine eligible commutes and rewards. For automatic detection, the App asks for Always location access and Precise Location. When enabled, iOS can deliver precise location to the App while it is open and in the background. This is why the permission is requested and why reduced or foreground-only permission limits automatic commute detection.

Most location processing starts on your phone:

  • detailed location points are normally deleted from your phone after 7 days;
  • information about possible commutes and tracking problems is kept on your phone for 30 days;
  • some location points and processing information may remain temporarily on your phone while the App finishes its work or recovers after an interruption; and
  • the App uses the location points to identify a possible trip, nearby public-transport stops, times, distance, and route.

During normal verification, Ridewize does not upload the complete record of all location points collected along your journey. The App sends only the start and end points or nearby public-transport stops, times, distance, route, and other limited information needed to check the commute. Ridewize uses Google Routes Platform to check whether the route is plausible. We then record the trip result and the related points, reward, and security information in our systems.

An exception applies when you deliberately submit a commute support package as described in Section 5. That package may contain selected detailed location points for the one commute you ask us to investigate.

4. Rewards, wallet, and product interactions

Ridewize processes verified trip summaries and claims to calculate points and determine whether you qualify for an offer or reward. Eligibility may depend on commute results, available points, offer availability, your birthdate, and other stated offer rules.

We record interactions needed to operate the catalogue and wallet, including viewing or selecting an offer, moving a reward into the wallet, issuing a voucher, redemption, expiry, and attempts that must be rejected or de-duplicated. A participating partner may need to see a voucher code or its redemption status. Partners do not receive the detailed location points from your journey merely because you redeem an offer. A partner's own website, venue, or service may have a separate privacy policy.

5. Commute support packages

If a commute is missing, rejected, or otherwise incorrect, the App may let you prepare a private support package for that commute. Before upload, the App presents the package for your consent. Depending on what is available for that commute, the package may include selected detailed location points, route or stop information, why the commute was accepted or rejected, information about tracking problems, and limited details about the App or your device.

You may cancel before submitting the package. Once submitted, only authorised support administrators can access it, and their access is recorded. The package and its private files are kept for 30 days. To withdraw consent or request earlier deletion after submission, contact support@ridewize.io. Withdrawal does not undo processing that already occurred, and we may keep a limited support or audit record where necessary to document the outcome or comply with law.

6. Website, waitlist, newsletter, and analytics

Vercel hosts the Website and processes requests and technical logs so the Website can work securely. You can also submit your email address through a Ridewize Website form. The waitlist and newsletter are separate choices: joining one does not automatically sign you up for the other.

The Website uses Google Analytics and Microsoft Clarity to measure visits and interactions. Analytics can use cookies or similar browser identifiers and receive technical information such as browser/device details, IP information, visited pages, referral information, and event timing. You can limit this processing through available Website choices, browser cookie controls, or content-blocking settings. Google's available analytics opt-out controls apply specifically to Google Analytics. Blocking analytics does not prevent essential requests needed to deliver and secure the Website.

Microsoft Clarity

Microsoft Clarity is a web analytics service provided by Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. It helps us understand how visitors use the Website by recording interactions such as clicks, scrolling, and mouse movements. Depending on configuration and consent, Clarity may use cookies and other browser technologies to collect information including IP addresses, browser type, operating system, pages visited, visit duration, and similar technical information.

We use this information to understand usage trends and improve the Website's user experience. Ridewize does not use Clarity to try to identify visitors by name. Microsoft states that it uses security measures intended to help protect the data against unauthorised access.

You can unsubscribe from newsletter emails using the link in the message or by contacting support@ridewize.io.

7. Why we process personal data

Swiss data-protection law is based on principles such as transparency, proportionality, purpose limitation, and security. It does not require this policy to assign every activity to the European Union's GDPR lawful-basis labels.

In practical terms, Ridewize processes data:

  • to provide the App, Website, account, commute detection, points, rewards, wallet, and support that you request;
  • with your choice or consent where appropriate, including iOS location permission, newsletter subscription, Website analytics choices where offered, and commute support package submission;
  • to pursue legitimate operational interests, such as service reliability, security, fraud and duplicate prevention, troubleshooting, product improvement, and defending legal claims, while respecting your interests and rights; and
  • to comply with duties imposed by Swiss law or a binding authority.

Where processing depends on consent, you may withdraw it for the future using the controls in Section 10. Withdrawal does not affect processing that was lawful before withdrawal. If data are necessary to provide a feature, withdrawing the relevant permission can make that feature unavailable.

8. Service providers, disclosures, and international processing

Ridewize uses the following providers for the stated purposes:

Provider or recipientRole
SupabaseApp accounts and sign-in, storage of App records and private support files, and services that run Ridewize features.
Bird/MessageBirdDelivery of SMS one-time passwords.
Google Routes PlatformChecking possible public-transport routes using the limited location and trip information described above.
AppleiOS, device-level location permissions and capabilities, and App Store platform services. Ridewize does not send Apple your Ridewize account profile merely because you use these device capabilities.
VercelWebsite hosting and delivery.
Google AnalyticsWebsite audience and usage measurement.
Microsoft Clarity (Microsoft Corporation)Website interaction and usage analytics to understand trends and improve the user experience.
Ridewize mailbox/support services and your email providerDelivery and handling of messages you send to us.
Reward partnersValidation of a relevant voucher or redemption where necessary.

Ridewize may also disclose data when required by Swiss law, a binding order, or to establish, exercise, or defend legal claims. We do not sell personal data and do not disclose App data for third-party advertising or cross-app tracking.

Some providers are based in, or use infrastructure and subprocessors in, Switzerland, the European Economic Area, the United States, or other countries. This means personal data may be processed outside Switzerland. Before making a material international disclosure, Ridewize must assess whether the destination provides adequate protection under Swiss law. Where it does not, Ridewize uses an applicable safeguard, such as recognised contractual data-protection clauses, unless a specific legal exception permits the disclosure.

Ridewize requires service providers and other third parties that process App user data for Ridewize to protect it to the same or an equivalent standard as described in this Policy, through contract or applicable law. We limit disclosures to data reasonably needed for the provider's task. Provider-specific infrastructure and subprocessors can change; contact us if you want current information relevant to your data.

9. Retention and account deletion

We keep personal data only while it serves the purposes described in this Policy. The fixed periods are:

  • detailed location points on your phone: normally 7 days;
  • other commute and tracking information on your phone: 30 days; and
  • a commute support package you choose to send, including its private files: 30 days from receipt.

For other records, retention depends on the account lifetime and the operational need to provide the service, administer rewards or redemptions, prevent duplicates and abuse, secure systems, handle support, or resolve disputes. Website logs and communications are kept only as long as reasonably needed for their stated purposes. Website analytics information follows our configured controls and the applicable provider's retention and deletion processes. Specific records may be retained longer only where Ridewize must keep them under law or for an unresolved legal claim.

You can delete your account from within the App. This permanently deletes your Ridewize sign-in account and Ridewize-held profile, trip, points, reward, wallet, voucher, support, and related account information. It also deletes stored commute support files. The App clears tracking information and pending trip or redemption activity from your phone. We may keep specific records only where the law requires it or they are needed for an unresolved legal claim.

You may also request deletion or ask a question at support@ridewize.io.

10. Your choices

You can control processing in the following ways:

  • Location: in iOS Settings, change Ridewize's location access, turn off Precise Location, or disable background location. Doing so can prevent or reduce automatic public-transit detection and may result in missing trips, points, or rewards.
  • Support package: cancel before upload. After upload, contact us to withdraw consent for future processing or request early deletion.
  • Newsletter: use the unsubscribe link in an email or contact us.
  • Website analytics: use available Website or browser controls, block or clear analytics cookies or other browser storage, or use Google's available opt-out controls specifically for Google Analytics.
  • Account deletion: use the deletion control inside the App or contact us.
  • Other consent: where we rely on your consent, withdraw it through the same available setting or by emailing us.

11. Your rights under Swiss law

Subject to the conditions and exceptions in the Swiss Federal Act on Data Protection (FADP), you may:

  • ask whether Ridewize processes personal data about you and receive the information required by law;
  • receive access to your personal data;
  • ask us to correct inaccurate or incomplete data;
  • request deletion or destruction of data;
  • request that unlawful processing stop, or object to or ask us to restrict processing where applicable; and
  • request delivery or transfer of personal data in a commonly used electronic format where the statutory portability conditions apply.

Email support@ridewize.io to exercise a right. Describe your request and the account or interaction it concerns. We may take proportionate steps to verify your identity before disclosing or changing data, so that another person cannot obtain your information. A right may be limited where Swiss law permits or requires it; if so, we will explain the applicable limitation where required.

You may raise a data-protection concern with the Swiss Federal Data Protection and Information Commissioner (FDPIC). The FDPIC recommends contacting the controller first and explains that its ability to intervene depends on the circumstances; it does not exercise individual rights on your behalf or decide every private dispute.

FDPIC
Feldeggweg 1
3003 Bern
Switzerland
www.edoeb.admin.ch

12. Automated verification and reward eligibility

Ridewize uses software rules and route checks to decide whether a possible commute is plausible, calculate distance and points, prevent the same trip from being counted twice, and decide whether the App can issue a reward or voucher under the applicable rules. The checks may use travel times, start and end points or nearby stops, distance, route results, relevant profile information, available points, and whether an offer is still available.

These processes can affect what appears in your commute history, points balance, or wallet. They are operational parts of the service; this Policy does not state that every such result is an automated individual decision with a legal effect under the FADP. If you believe a commute or reward result is wrong, contact support@ridewize.io. Ridewize can investigate the result and provide human support or review where appropriate.

13. Security

Ridewize uses technical and organisational measures appropriate to the nature of the data and the risks of processing. These include authenticated access, access controls, private storage for support packages, limited provider disclosures, retention controls, and audit records for sensitive support access. No internet-connected service is completely secure, so we cannot guarantee absolute security.

You should protect your phone and login messages and should not share a one-time login code with anyone. If you suspect unauthorised access, contact us promptly.

14. Children

The App is not available to children under 13. A birthdate is required to complete a profile, and Ridewize uses it to enforce the minimum age and, where relevant, offer eligibility. We do not knowingly provide App accounts to children under 13. If you believe a child under 13 has supplied personal data, contact support@ridewize.io so we can investigate and delete it where appropriate.

15. Third-party links and partner offers

The App and Website may link to third-party websites, App Store pages, partner offers, or venues. Those third parties act under their own terms and privacy notices when you interact directly with them. Ridewize is not responsible for their independent data processing. Review the relevant notice before providing personal data.

16. Changes to this Policy

Ridewize may update this Policy when the service, providers, or legal requirements change. A published update will identify when the revised policy takes effect. Where a change materially affects processing that requires your consent, Ridewize will request a new choice before relying on that consent. A repository version is not effective merely because it appears in this repository.

17. Contact

For privacy questions, rights requests, consent withdrawal, or deletion requests: support@ridewize.io.

For general Website enquiries: hello@ridewize.io.

Postal enquiries may be sent to the company address in Section 1.