Privacy Policy
Last updated: 22 June 2026
This Privacy Policy explains how Luca Matysik exaDev (“exaDev”, “we”, “us”, or “our”) processes personal data and personal information when you use RIDEit.
RIDEit is a mobile app for designing, organizing, sharing, animating, and exporting equestrian courses and related training content. This policy applies to users of the app, including anonymous users, registered users, and people who contact us. It is written with the GDPR, the German Federal Data Protection Act (BDSG), German ePrivacy rules such as the TDDDG, and California privacy laws such as the CCPA/CPRA in mind where they apply.
For California residents, the California-specific sections below provide additional disclosures for transparency. Providing these disclosures does not mean that every CCPA/CPRA obligation or threshold applies to exaDev in every situation.
1. Controller and Contact
The controller responsible for processing personal data is:
Luca Matysik exaDev
Blockgasse 1
74523 Schwäbisch Hall
Germany
Email: [email protected]
We have not appointed a data protection officer because we are not currently legally required to do so. You can contact us about privacy matters at the email address above.
Further legal provider information is available in the Legal Notice / Imprint.
2. Personal Data We Process
Depending on how you use RIDEit, we may process the following categories of personal data.
Account and Authentication Data
- email address;
- authentication identifiers, user ID, and session data;
- username;
- selected app language;
- anonymous account identifiers and data needed to migrate an anonymous account to a registered account.
Authentication is provided through Supabase Auth. Passwords are handled by the authentication provider and are not stored by us in plain text.
Profile and Social Data
- public profile settings;
- profile visibility and force-follow settings;
- follow relationships;
- profile links and username-based public URLs;
- notification preferences related to profiles or followed users.
Depending on your settings and actions, parts of your profile or shared content may be visible to other users or to people who receive a public link.
Course, Content, and App Data
- courses you create, edit, save, like, share, or open;
- course metadata, instructions, movements, distances, gait variations, horses, riders, obstacles, and related settings;
- exported images or videos, where created through app functionality;
- course slots, library-course access, shared links, posts, and app navigation data needed to provide those features;
- app preferences such as grid, horse/rider, notification, privacy, and language settings.
You should not include unnecessary personal data about other people in courses, instructions, notes, profile details, support requests, or other app content.
Technical, Device, and Usage Data
We may process technical data needed to run, secure, analyze, and troubleshoot the app, such as:
- device type, operating system, platform, app version, and similar diagnostic information;
- app events such as app opening, login, course opening, sharing, export, paywall, notification, and error events;
- crash or error details, stack traces, and optional user descriptions when an error report is submitted;
- push notification tokens and delivery-related metadata where notifications are enabled.
Payment and Subscription Data
Payments are handled by the Apple App Store, Google Play, or another applicable app store or payment provider. We do not receive or store full payment card details.
We may process subscription status, entitlement information, product/package identifiers, purchase status, and related metadata through RevenueCat and the relevant app store so that we can provide paid features.
Communication Data
If you contact us, we process the information you provide, such as your email address, message content, attachments, request type, and metadata needed to respond.
CCPA / CPRA Category Mapping
For California privacy purposes, the data described above may fall into the following categories of personal information:
- identifiers, such as email address, username, user ID, authentication identifiers, device identifiers, push notification tokens, and advertising identifiers where applicable;
- customer records or account information, such as subscription status, entitlement data, app store purchase metadata, and support request information;
- commercial information, such as subscription status, product identifiers, purchase status, entitlement status, and purchase restoration information;
- internet, electronic network, or app activity information, such as app events, course interactions, paywall events, export events, notification interactions, analytics events, error events, and ad interactions;
- user-generated content, such as courses, course metadata, profile details, shared links, exports, support messages, and other content you choose to create or share;
- approximate location or technical region information, where inferred by providers from device, network, app store, or service usage data. RIDEit does not currently require precise location data for normal app use;
- inferences, where generated from app usage, preferences, analytics, or subscription status to understand product performance or provide app functionality.
RIDEit does not require sensitive personal information for normal app use, and we do not use or disclose sensitive personal information to infer characteristics about you.
3. Purposes and Legal Bases
We process personal data only where we have a legal basis under the GDPR.
Providing the App
We process account, profile, course, content, settings, and subscription data to provide RIDEit, sync your data, authenticate you, manage accounts, enable sharing, and make app features available.
Legal basis: Article 6(1)(b) GDPR, performance of a contract or pre-contractual steps.
Cloud Sync, Hosting, and Security
We use Supabase to provide authentication, database storage, and cloud sync. The primary Supabase project region is eu-central-1 (Frankfurt).
We process technical and security-related data to keep the app available, protect accounts, prevent abuse, diagnose issues, and maintain service integrity.
Legal basis: Article 6(1)(b) GDPR for providing the app, and Article 6(1)(f) GDPR for our legitimate interest in security, reliability, and abuse prevention.
Profiles, Sharing, and Public Links
If you make a profile public, follow other users, share courses, or create public links, we process the related data to provide those features and make the selected content available according to app functionality and your settings.
Legal basis: Article 6(1)(b) GDPR for requested sharing features, and Article 6(1)(f) GDPR for our legitimate interest in operating public and social app features.
Push Notifications
If you allow notifications, we process notification preferences, device push tokens, and delivery metadata to send push notifications through Firebase Cloud Messaging.
Legal basis: Article 6(1)(a) GDPR for device notification permission and consent where required, and Article 6(1)(b) GDPR where notifications are part of app features you enabled.
You can manage notification permissions in your device settings and notification preferences in the app.
Analytics
We use PostHog EU for product analytics. Analytics may include events such as app openings, authentication events, course interactions, paywall events, export events, notification interactions, and reliability events.
Analytics tracking is consent-based. It is used only when analytics consent is granted. You can change analytics tracking in the app preferences.
Legal basis: Article 6(1)(a) GDPR, consent. You may withdraw consent at any time with effect for the future.
Error Reporting and Support
If an error is reported, we may process the error message, stack trace, optional user description, app version, platform, device information, additional diagnostic data, and your user ID if you are logged in.
We use this information to diagnose problems, improve app reliability, and respond to support needs.
Legal basis: Article 6(1)(f) GDPR, our legitimate interest in maintaining a stable and secure app. Where error reporting is based on an optional user action or preference, Article 6(1)(a) GDPR may also apply.
Subscriptions and Entitlements
We process subscription and entitlement information to unlock paid features, verify access, restore purchases, and handle subscription-related app behavior. Billing, refunds, and payment methods are handled by the relevant app store or payment provider.
Legal basis: Article 6(1)(b) GDPR, performance of a contract.
Advertising
RIDEit may display ads through Google AdMob or similar advertising services. Advertising may involve device information, advertising identifiers, interaction data, and information needed to display, limit, secure, or measure ads.
RIDEit currently requests non-personalized ads by default. We do not sell personal information, and we do not knowingly share personal information for cross-context behavioral advertising. If we later introduce personalized advertising or other processing that qualifies as a sale or sharing under California privacy law, we will update this policy and provide appropriate choices before enabling it.
Where required by law, ads and related access to device identifiers or storage are based on your consent. You may also have controls in your device operating system, Google settings, Apple settings, or app store account.
More details about tracking technologies and SDKs are provided in the Cookie Policy.
Legal Compliance and Rights Requests
We process personal data where necessary to comply with legal obligations, respond to privacy requests, enforce our Terms, or protect legal rights.
Legal basis: Article 6(1)(c) GDPR for legal obligations and Article 6(1)(f) GDPR for legitimate interests in legal defense and enforcement.
4. Third-Party Providers and Recipients
We use service providers to operate RIDEit. Depending on your use of the app, personal data may be processed by:
- Supabase: authentication, database, cloud storage, and backend services; primary region eu-central-1 (Frankfurt);
- PostHog: consent-based analytics, hosted in the EU;
- Firebase / Google: push notifications, app infrastructure, ads, and related device services;
- RevenueCat: subscription and entitlement management;
- Apple App Store and Google Play: app distribution, purchases, billing, refunds, and store account services;
- technical service providers used for app operation, diagnostics, communication, security, or support.
Some providers act as processors on our behalf. Others, especially app stores and payment providers, may act as independent controllers for their own processing.
5. International Data Transfers
Our primary backend storage is hosted in the EU through Supabase in Frankfurt, and analytics are configured for PostHog EU.
Some providers, especially globally operating companies such as Google, Apple, RevenueCat, or related subprocessors, may process data outside the European Economic Area. Where this happens, transfers are handled using safeguards required by applicable data protection law, such as EU adequacy decisions, standard contractual clauses, contractual protections, or comparable lawful transfer mechanisms.
6. Retention
We keep personal data only for as long as necessary for the purposes described in this policy or as required by law. Retention periods depend on the category of data, the purpose for which it is processed, whether the account or feature is still active, and whether legal, security, fraud prevention, accounting, or dispute-resolution obligations apply.
In general:
- account and course data are kept while your account exists or while needed to provide the app;
- shared content and public links may remain available while the relevant feature, account, or content exists;
- subscription and entitlement data are kept as long as needed to provide paid features, restore purchases, and meet legal or accounting requirements;
- error reports and diagnostic data are typically reviewed and deleted or anonymized within 180 days, unless they are still needed for security, support, legal claims, or resolving an ongoing issue;
- analytics data is retained according to our analytics configuration and provider settings and is generally not kept longer than 24 months in identifiable form unless a shorter provider setting applies;
- legal, tax, accounting, or dispute-related records may be retained for statutory retention periods.
If you delete your account or request deletion, we will delete or anonymize personal data where required, unless retention is necessary for legal obligations, security, fraud prevention, dispute resolution, or legitimate business records.
7. Security
We use technical and organizational measures intended to protect personal data, including authenticated backend access, access controls, secure transport, service provider safeguards, and operational security practices.
No app or online service can be guaranteed to be completely secure. You are responsible for keeping your account credentials secure and for using the app responsibly.
8. Children and Minors
RIDEit is intended for a broad audience. If you are under the age of legal majority in your country, you may use RIDEit only with permission from a parent or legal guardian.
Parents and guardians are responsible for a minor’s use of the app. If you believe personal data of a minor has been processed without required consent, contact us at [email protected].
9. Special Categories of Data
RIDEit does not require special categories of personal data, such as health data, biometric data, political opinions, religious beliefs, or similar sensitive data, for normal app use.
Please do not include unnecessary sensitive data in courses, instructions, profile details, support messages, or error reports.
10. Automated Decision-Making
RIDEit does not make decisions based solely on automated processing that produce legal effects or similarly significant effects for you.
Third-party providers may use automated systems for security, analytics, advertising, billing, or fraud prevention according to their own policies.
11. Your Privacy Rights
Subject to the conditions and limits of applicable law, you may have the rights described below.
GDPR / EEA / UK-Style Rights
Where the GDPR or similar data protection laws apply, you may have the right to:
- request access to your personal data;
- request correction of inaccurate data;
- request deletion of your data;
- request restriction of processing;
- receive data portability where applicable;
- object to processing based on legitimate interests;
- withdraw consent at any time with effect for the future;
- lodge a complaint with a data protection supervisory authority.
You can withdraw consent at any time with effect for the future. Withdrawal does not affect processing that happened before consent was withdrawn.
Because exaDev is located in Baden-Württemberg, Germany, the relevant supervisory authority may be:
Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI Baden-Württemberg)
You may also contact another competent supervisory authority in your country or region.
California Privacy Rights
If you are a California resident, you may have the right to:
- request information about the categories and specific pieces of personal information we have collected about you;
- request information about the categories of sources, purposes, and recipients of personal information;
- request correction of inaccurate personal information;
- request deletion of personal information;
- opt out of the sale or sharing of personal information, if applicable;
- limit the use or disclosure of sensitive personal information, if applicable;
- use an authorized agent to submit a request where permitted by law;
- not receive discriminatory treatment for exercising privacy rights.
RIDEit does not sell personal information and does not knowingly share personal information for cross-context behavioral advertising. RIDEit also does not knowingly sell or share personal information of users under 16.
We do not offer financial incentives, price differences, or service differences in exchange for personal information.
How to Exercise Rights
You can contact us at [email protected] to exercise your rights. Please include enough information for us to understand and verify your request, such as the email address or username connected to your account and the right you want to exercise.
Where available, you can also manage some choices directly in the app, including analytics consent, notification preferences, language, profile visibility, and account-related settings.
We may ask for additional information if needed to verify your identity, verify an authorized agent’s authority, or understand your request. We will respond within the time required by applicable law. If we cannot fulfill a request fully, for example because legal retention duties, security needs, fraud prevention, app store or payment-provider rules, or independent-controller processing by third-party providers apply, we will explain this where required.
12. California Privacy Notice
This section provides additional information for California residents.
Categories Collected
The categories of personal information we may collect are described in Section 2, including identifiers, account and customer records, app activity information, user-generated content, approximate technical region information, commercial or subscription information, and limited inferences from app usage or preferences.
Sources
We collect personal information from:
- you, when you create an account, use app features, create or share content, configure settings, subscribe, or contact us;
- your device and app usage, including SDKs used in the app;
- service providers that help operate the app;
- app stores, payment providers, and RevenueCat for purchase and entitlement information;
- other users or recipients where they interact with shared content, public links, profiles, or social features.
Purposes
We use personal information for the purposes described in Section 3, including providing the app, authentication, cloud sync, subscriptions, sharing features, notifications, security, support, analytics where consented, advertising delivery, legal compliance, and rights handling.
Disclosures to Recipients
We may disclose categories of personal information to the recipients described in Section 4 for business purposes, including providing the app, maintaining security, processing subscriptions, sending notifications, analyzing app performance where consented, showing ads, diagnosing issues, and handling support or legal requests.
During the 12 months before the date of this policy, the categories disclosed for business purposes may have included identifiers, account and customer records, commercial or subscription information, app activity information, user-generated content where needed to provide app features, approximate technical region information, and limited inferences from app usage or preferences.
Sale, Sharing, and Sensitive Personal Information
We do not sell personal information. We do not knowingly share personal information for cross-context behavioral advertising. During the 12 months before the date of this policy, we have not knowingly sold personal information or knowingly shared personal information for cross-context behavioral advertising. RIDEit currently requests non-personalized ads by default.
RIDEit does not require sensitive personal information for normal app use, and we do not use or disclose sensitive personal information to infer characteristics about you. If personalized advertising, qualifying sharing, or new sensitive-data processing is introduced later, we will update this policy and provide any required choices before enabling it.
13. Account Deletion
You may stop using RIDEit at any time. Where the app provides account deletion functionality, you can use it to request deletion of your account and associated synced app data.
Deleting an account may remove access to saved courses, profiles, settings, and shared app content. Some data may be retained where required by law, for security, for dispute resolution, or by independent providers such as app stores or payment providers.
Deleting the app from your device does not automatically cancel subscriptions. Subscription cancellation is handled through the app store or payment provider where the purchase was made.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time, for example when the app changes, legal requirements change, or providers change.
The latest version will be available in the app. The date at the top shows when this policy was last updated.
