RiderAdda helps delivery riders decide where to wait, by showing how busy a spot is relative to how many orders it actually produces. Riders never pay for RiderAdda. This policy explains exactly what we collect, what we deliberately do not collect, and what you can do about it.
Quick links: Your rights (GDPR) · Your Privacy Choices (California/CCPA)
RiderAdda is operated by [FILL: legal entity name], [FILL: registered address], commercial registration [FILL].
RiderAdda is available to riders internationally. We are the data controller for the personal data described here under whichever data-protection law applies to you. Rather than promise a different standard in each country, we apply one standard everywhere: the strongest protection any of those laws would require. The specific rights this gives you are set out in Section 10.
RiderAdda is a tool for delivery riders. We are not a delivery platform, we do not employ riders, and we are not affiliated with, endorsed by, or acting on behalf of any delivery platform or delivery company, anywhere. Platform names shown in the app are there only so you can record which apps you ride for; they are trademarks of their owners and imply no relationship with us.
It also covers staff users of our internal console (Section 12).
k ≥ 5),
so a number can never be traced back to one person.| Data | Why | Notes |
|---|---|---|
| Email address | To send a one-time login code (your verification method) | Used transiently to deliver the code. Stored only as a salted hash — we cannot read your email back out of our database. Never displayed, never shared. |
| Password | To sign you in | Stored only as an argon2 hash — a one-way function with a per-account random salt. We cannot read your password, and no member of staff can recover or reset it. If you forget it, we send a one-time code to your email so you can choose a new one. |
| Mobile number | Bound to your account to stop a banned user re-registering | Used transiently. Stored only as a salted hash — we cannot read your number back out of our database. We also keep the last two digits as a masked hint (e.g. "…ending ••47"); the full number cannot be reconstructed from it. |
| Display name / handle | So riders can be referred to without being identified | The only identity any rider or staff member can ever see. Auto-generated (e.g. Rider-7F3A) unless you change it. |
| Real name (optional) | Only if you choose to provide it | Encrypted at rest (AES-256-GCM). Never displayed to other riders, never displayed to our staff, never returned by any part of our system. |
| Referral code | To credit a rider who invited you |
We do not collect: photographs of you, government ID or national identity number, date of birth, gender, address, payment details, or bank details.
Session activity (check-in, waiting, order received, picked up, break, shift end), the spot involved, timestamps, your XP and trust level, alerts sent to you, favourited spots, appeals you filed, and any cooldowns applied. This is the raw material for the spot scores every rider sees.
A hashed device identifier, a Google Play Integrity verdict, whether reported location appears mocked, and abuse-signal and violation history. False data harms every other rider, so we check for it. Penalties require corroborating signals of different kinds — a single anomaly is never enough.
There is currently no way to upload a photo in RiderAdda, and no photograph of any kind leaves your device. The commitments below describe how photos will be handled if that feature is added. They are recorded in advance, and are not a description of something the app does today.
A Firebase Cloud Messaging token, so we can send spot alerts. Alerts are rationed, never broadcast (Section 6).
RiderAdda is free and always will be; advertising funds it. Ads are served by Google AdMob. By default we request non-personalised ads. Personalised advertising is opt-in — off unless you switch it on.
Crash reports contain technical diagnostics only. Usage analytics collection stays off until you consent. Both share one "Diagnostics & crash reports" opt-in.
What we send, and what the SDK collects on its own, are different things — so we state both. We attach no identity to either tool: no user identifier, no custom keys, no location parameters. Your handle, email, phone and precise GPS coordinates are never sent to Google by us. But any SDK that makes a network request necessarily reveals your IP address, and Google derives an approximate location (country, region, often city) from it, plus its own per-install pseudonymous identifiers and basic device details. We cannot switch that off while using the tool at all — which is exactly why these tools are off until you opt in, and why we describe the boundary instead of claiming a cleanliness we do not control. See §7.1.
Firebase Performance Monitoring is a separate opt-in from the diagnostics setting above and stays off by default. When you turn it on we first show a dialog explaining what it collects, and it only starts after you acknowledge and agree. It records the timing and web addresses of the network requests the app makes, app startup and screen-render times, and basic device/network attributes — to help us diagnose slowness. We attach no handle, email, phone or GPS coordinates to it; as in §4.8, Google still sees your IP address and derives an approximate location from it. You can turn it off at any time.
This section is about our website, not the app. The two are configured separately, and consenting to one does not consent to the other.
On the public pages of rideradda.com we use Google Analytics 4 to count page visits — which pages people read, and which site referred them. Nothing loads until you press "Allow" on the notice at the bottom of the page. Until then no Google script is fetched, no request is made to Google and no cookie is set. If you decline, or simply ignore the notice, that stays true permanently.
If you do allow it:
_ga, _ga_*) holding a random identifier for your
browser, so returning visits count as one visitor rather than several. It is not linked to
any RiderAdda account — the website has no way to know who you are.You can change your mind at any time using "Cookie settings" in the site footer.
Withdrawing deletes the _ga cookies from your browser immediately.
The admin console is excluded entirely. Nothing under /admin is measured, for
any visitor, in any configuration.
We keep operational logs for security and debugging. Our logging strips location coordinates and phone numbers before anything is written, and automated tests fail our build if a coordinate or phone number can reach a log file.
| Purpose | Legal basis (GDPR / PDPL / equivalent) |
|---|---|
| Creating and securing your account; sending login codes | Performance of a contract |
| Showing spot scores, presence and the map | Performance of a contract |
| Detecting fraud, fake data and ban evasion | Legitimate interests — protecting a shared dataset every rider relies on |
| Aggregate statistics and service improvement | Legitimate interests |
| Optional real name; personalised ads; analytics | Consent — withdrawable at any time |
| Responding to lawful requests from authorities | Legal obligation |
We deliberately do not broadcast "this spot is good" to everyone — that would send a crowd to the same place and destroy the advantage it reported.
If our system sees signals suggesting a report was not genuine — for example location data that does not match a check-in, or a pattern consistent with other confirmed abuse — it can, without a staff member reviewing it first:
This is an automated decision that can affect your account. We use it because the volume of check-ins makes person-by-person review of every one impossible, and because acting quickly limits how much a bad report can distort the map for other riders before it is caught.
You always have the right to ask a person to review it. Every cooldown and every Trust XP reduction can be appealed from the app, and an appeal is read and decided by a member of our team, not by the same system that made the original call. Appealing never costs you anything and is never held against you. The reasoning behind each cooldown decision considers corroborating signals from your recent activity (such as location consistency and device signals) weighed against your account's history — we do not use this to profile you for any purpose beyond that check.
A Trust XP reduction is shown in your XP history in plain language, stating what did not match rather than accusing you of anything, and it is never a full reset — only trust is affected, never the Contribution XP you have already earned for work you did.
We do not sell your personal data, and we do not share device-level location data with anyone.
| Provider | What they receive | Purpose |
|---|---|---|
| Hetzner (Falkenstein, Germany) | All service data (hosted) | Running the service |
| Resend (EU region, Ireland) | Your email address, and the login code itself, inside the message. Retained in Resend’s delivery log for a limited period after sending — not only in transit | Delivering your login code |
| Google — Play Integrity | Device attestation token | Anti-fraud |
| Google — AdMob | Advertising identifier; non-personalised by default | Advertising |
| Google — Firebase | Push token; crash diagnostics; usage events after consent | Notifications, stability, analytics |
| Google — Places API | Queries about restaurants, not about you | Building the initial spot list |
About the login code and your email address. We store your email address only as a salted hash — we cannot read it back or search by it. Sending you a code, however, requires the real address, so our email provider necessarily receives it, and their delivery log records that a message was sent and what it contained. That log is theirs, not ours, and is kept for a limited period under their own retention policy. This is unavoidable for any service that emails you anything; we state it plainly rather than let “stored only as a hash” imply more than it means. We deliberately keep the code out of the subject line so it is not exposed in list views, notification previews or logs any wider than necessary.
Planned, but not in use today. Verification is currently by email only. Your phone number is bound to your account and stored as a salted hash, but it is not sent to any SMS or WhatsApp provider, because we do not use one — there is no such processor to list. We expect to add phone verification by SMS or WhatsApp in a future release. When we do, that provider will be added to the table above and the change will be published as a policy update before it takes effect, so you see it and accept it first. We name it here so a later addition is not a surprise; it is not a description of anything happening now.
We may disclose data where legally required — under a valid legal or regulatory order from a competent authority in a jurisdiction that applies to us. Any such disclosure by our staff is recorded in an append-only audit log.
In a merger, acquisition or sale of assets, personal data may transfer to the acquirer, who would remain bound by this policy until you are notified of any change.
Some code in the app is Google's, not ours. Those SDKs talk to Google directly, so it is not enough to tell you what we store — you should know what runs on your device and what it sends.
| SDK | On by default? | What it sends to Google |
|---|---|---|
| Play Integrity | Yes | A device-attestation token, your IP. No rider identity. Required to keep fake accounts out. |
| Firebase Cloud Messaging (push) | Yes, if you allow notifications | A push token tied to this install, your IP. |
| Firebase Crashlytics | No — diagnostics opt-in | Stack traces, device state, an install UUID, your IP. |
| Firebase Analytics | No — diagnostics opt-in | Screen/feature events, App Instance ID, device model/OS/language, your IP. |
| Firebase Performance | No — separate opt-in with its own dialog | Request URLs and timings, startup/render traces, your IP. |
| Google AdMob (ads) | Yes, if ads ship — non-personalised unless you opt in | Advertising identifier, your IP, ad-request context. |
In every row, "your IP" means Google can derive an approximate location (typically country and city). That is unavoidable for any network call to any provider and is not unique to us — but it means "we send no location" would be a misleading half-truth, so we do not say it. What we do say, and what is true: we never send your precise GPS coordinates, your handle, your email or your phone number to any of them.
We do not control Google's own use of the data these SDKs collect; for that, see Google's privacy policy and the Firebase/AdMob data-disclosure documentation. You can switch off everything in the "No" rows, and turn personalised ads off, from Settings at any time.
Aggregate, non-identifying statistics — how busy a spot is, how many pickups per hour it produces — are a product of the service and may be used commercially, including in a future business product.
To be explicit about the boundary: this never includes device-level location data, and
never includes anything that identifies you. The k ≥ 5 floor applies before
any figure is shown or shared.
We may work with restaurants and other businesses to offer riders occasional perks — a drink, a light meal, or a discount. This is not switched on today; it is described here so that if it is, you have already been told how it works rather than finding out afterwards.
Where we do this:
k ≥ 5 minimum-group-size floor that applies everywhere else in this policy.
They receive nothing about any other business.| Data | Retention |
|---|---|
| Precise coordinates | 30 days, then automatically deleted |
| Live presence (that you are at a spot right now) | Minutes — held in memory with a short expiry |
| Account, XP, session history | While your account exists |
| Aggregate spot statistics | Indefinitely — no individual is identifiable |
| Abuse signals, bans | As long as needed to keep a ban effective |
| Staff audit log | Retained as an integrity record (append-only) |
Deleting your account is a genuine erasure — your telemetry, sessions, XP and related records are removed at the database level. Two narrow, purpose-limited exceptions remain, each disclosed here:
Lawful requests from authorities. We do not proactively share your data with anyone. We disclose data to a law-enforcement or government body only when compelled by a valid legal instrument (court order, warrant, or an equivalent lawful request from a competent authority), and only the specific data it covers. Because your email and phone are stored only as one-way salted hashes, and location older than 30 days is already deleted, in most cases there is little readable personal data we are technically able to produce.
Legal hold. Where we are legally required to preserve a specific account's data for an active matter (for example, an ongoing investigation or legal claim), we may place that single account under a legal hold. A hold is placed only by a senior administrator, tied to a documented case reference, and every placement and release is audit-logged. While a hold is in force, a deletion request for that account is lawfully deferred rather than refused — the account is locked and the data retained only for that matter — and the erasure completes automatically once the hold is released. We do not apply blanket "just in case" retention to any other account.
RiderAdda records what you tell the app: your check-ins, your taps, and where your phone was while a shift was running. We have no connection to any delivery platform's systems. We cannot see, confirm or contradict what you were actually assigned, paid, rated or penalised.
Because of that, our records are supporting information, not an official record:
We do not profile you for anyone else. We do not build behavioural profiles about you for third parties, do not rate, score or rank riders on behalf of delivery platforms, employers, insurers or lenders, and do not sell or share your data with them. The trust score exists solely to keep the service fair and abuse-resistant inside the app.
Your own data remains yours. You may export it and use it however you wish — including to support your own position in a dispute with a platform. We simply do not present it as proof and cannot vouch for it.
Our position on evidence. It is our position that RiderAdda records are not proof of anything and should not be relied on as proof — neither of your work, nor against you. We do not produce records for evidentiary use. We do not certify, authenticate or attest to the accuracy of any record for any legal, disciplinary or contractual purpose, and we will not act as a witness, certifier or expert about them for any party, including a delivery platform, employer or insurer. Any use of RiderAdda data in a proceeding is at the using party's own risk.
Compelled disclosure is not endorsement. Where a valid legal instrument compels us, we are obliged to produce what it covers and we will do so — that is a legal obligation we cannot refuse, not a choice. It is not a representation that the data is accurate, complete or reliable. Everything above applies equally to anything produced under compulsion.
What we cannot claim. We cannot state that our records are inadmissible or that they may not be used in a court of law. Admissibility and weight are decided by a court, tribunal or regulator, and no policy written by us binds them. Stating otherwise would be telling you something untrue. What is genuinely ours to state — and what we do state — is everything above: unverified, incomplete by design, uncertified, not produced for evidentiary use, and in our view not proof.
Nothing in this section limits our obligation to respond to valid legal process above, or your rights below.
What we ARE responsible for, and do not attempt to disclaim. RiderAdda is the controller of your personal data and is accountable under the applicable data-protection law wherever you ride — GDPR, PDPL, CCPA/CPRA or the local equivalent — for how we collect, secure, use, share and delete it. That responsibility is not waivable by contract, we do not try to waive it, and nothing in this section should be read as attempting to. If we mishandle your data, that is our failure and your statutory remedies against us are unaffected.
What we are not responsible for. RiderAdda, and equally its owner, developers, publisher and administrators, are not responsible for:
Limitation. To the fullest extent permitted by applicable law, we are not liable for indirect, incidental or consequential loss, including lost earnings, lost work, lost opportunity or reputational harm. Nothing in this section limits liability that cannot lawfully be limited — including for fraud, gross negligence or wilful misconduct, for death or personal injury caused by negligence where that cannot be excluded, or for your statutory data-protection and consumer-law rights, all of which remain fully intact.
Wherever you ride, and whatever data-protection law applies where you live, you may access, correct, delete, object to or restrict processing, withdraw consent, and request portability.
Two are built into the app, so you do not have to ask us:
What survives deletion, and why: records needed to keep an active ban effective, and entries in our append-only staff audit log. Aggregate statistics already computed remain, because they identify no one and cannot be reversed to you.
For any other right, contact [email protected]. We respond within 30 days (California requests: see Section 10a for that timeline).
Complaints. If you believe we have handled your data wrongly, tell us first at [email protected] and we will investigate. You also have the right to complain to the data-protection authority responsible for the country or region where you live. You do not need our permission and you do not have to contact us first. Each authority publishes its own contact details; if you write to us and tell us where you are, we will point you to the right one.
Where the law of a particular country requires us to appoint a local representative or contact point, that appointment is named in Section 1 once it exists.
We do not sell or share your personal information, as those terms are defined by California law — not for money, and not for cross-context behavioural advertising.
If you are a California resident, you additionally have the right to:
Notice at collection. Section 4 lists every category of personal information we collect and why, before or at the point we collect it. We do not use personal information for any purpose materially different from what is disclosed there without providing updated notice.
How to exercise these rights. Use Export my data / Delete my account in Settings, or contact [email protected]. We will verify your request using your account's verified email and respond within 45 days (extendable once by a further 45 days for complex requests, as California law permits).
Email addresses and phone numbers are stored only as salted hashes. An optional real name is encrypted with AES-256-GCM. Traffic is encrypted in transit (HTTPS/TLS). Sessions use signed tokens that can be revoked immediately. Staff access is least-privilege — our content moderators structurally cannot access rider data — and every sensitive staff action is written to an append-only audit log.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authority as required by law.
For staff we process work email, role and a password hash, plus an audit record of actions taken. Roles are least-privilege: Managers see photos and spot names only; Admins see rider handles and signals; Super-admins additionally manage configuration and roles. No role displays a rider's phone number.
RiderAdda is for working delivery riders and is not directed at anyone under 18. We do not knowingly collect data from children. If you believe a minor has an account, contact us and we will delete it.
Our infrastructure is hosted in [FILL: region]. Some processors (e.g. Google) may process data outside the Kingdom. Where that occurs we rely on the transfer mechanisms permitted under PDPL and, where relevant, GDPR safeguards such as Standard Contractual Clauses.
RiderAdda is not offered in mainland China.
We may update this policy at any time. Minor changes (for example, wording or contact details) take effect as soon as they are posted here, and the "Last updated" date above always reflects the current version. For any material change — such as collecting new data or using it for a new purpose — we will notify you in the app before it takes effect, and where the law requires your consent we will ask for it. Continued use after a change takes effect means you accept the updated policy.
[FILL: legal entity name]
[FILL: address]
Privacy: [email protected]