Privacy Policy
How we handle your personal data – transparently and limited to what is necessary.
Only the German version is legally binding. This translation is provided for convenience only.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Jonas Chyba
Mittelstraße 1, 01445 Radebeul, Deutschland
Email: business@motomotors.de
2. Overview
MotoMotors is a non-commercial, private community project for motorcyclists with no intention of making a profit. We only process the data required to operate the Platform. We do not use any marketing, tracking or analytics tools and no advertising networks. Your data is not sold to third parties.
3. What data we process
a) Account and profile data
During registration and profile maintenance, we process:
- Display name and username (you sign in with the username)
- Email address – required for registration and its confirmation; we use it to verify your account, for password recovery and for important notifications (see “Sending of emails”)
- Password – exclusively as a cryptographic hash (bcrypt), never in plain text
- Date of birth (to verify the minimum age of 16 years)
- Account status (e. g. “under review”, “active”), role and the time of your email confirmation – for administration and security
- your preferred language for emails and the time of your consent to our legal documents (respective version)
- optional: federal state and city
- optional: motorcycle make and model, riding styles, profile description (bio)
- optional: a profile picture (avatar) uploaded by you
b) Usage data
Relationships you establish yourself (e. g. who you follow) as well as timestamps for the creation and update of your profile.
c) Direct messages
The content and timestamps of the messages you send and receive, including sender/recipient as well as edit/deletion markers. Messages are only visible to the respective conversation partners. If you report a message, the affected conversation is transmitted in excerpts to moderation/support in order to be able to review the incident.
d) Community vote “Picture of the Month”
Voting images uploaded by you, including an optional caption, the respective month and your vote. The winning entry of a month is published – with your consent given upon participation – on the homepage as well as on our Instagram channel (see the section “Publication on Instagram”).
e) Crews & rideouts
Crew memberships and roles, content created by you/the crew (name, description, image) as well as rideout details (title, description, meeting point, time, visibility). Publicly posted rideouts and crew profiles are visible to everyone.
f) Notifications & push
In-app notifications (e. g. new followers, messages, voting result). Only if you enable push do we store the push subscription of your device required for this (endpoint URL and cryptographic keys of your browser). Delivery takes place via the push service of your browser/operating system (e. g. Google, Mozilla, Apple/Microsoft).
g) Server log files
When the pages are accessed, technically necessary access data is processed by the hosting provider (e. g. IP address, date/time, requested resource, browser type). This data is required for the delivery, stability and security of the service.
h) Sending of emails
We send emails exclusively for important matters: confirmation of your email address upon registration, password recovery, account deletion, account changes made by the administration (e. g. role or status) as well as updates to our legal documents. We do not send advertising, newsletter or tracking emails. They are sent via our own mail server at the hosting provider; no external email marketing service is used. In the settings you can choose the language of these emails.
i) Reviews
When you submit a review, we process your star rating and your text. By default, reviews serve only as internal feedback. Only if you explicitly consent may your review – after selection by our team – appear publicly on the homepage, then together with your display name, username and profile picture. You can withdraw this consent for the future at any time; the review is then no longer shown publicly.
j) Invitations & badges
Via your personal invite link (?ref=…) we store on the invited account that you referred it (referral). From this we derive your ambassador status and award visible badges (e. g. for milestones or invitations) shown on your public profile. For attribution we set a technically necessary cookie when an invite link is opened (see cookie table).
k) Two-factor authentication (2FA)
If you enable 2FA, depending on the method we store an encrypted authenticator secret or send one-time codes by email, plus single-use recovery codes (only as a hash) and – if you choose – devices marked as “trusted” (via a secure cookie). This data serves solely to secure your sign-in.
4. Purposes and legal bases
- Provision of the account and the community features – Art. 6 (1) (b) GDPR (contract / pre-contractual measures).
- Email confirmation, account security, two-factor authentication, password recovery and important service emails – Art. 6 (1) (b) GDPR (contract) or (f) GDPR (legitimate interest in a secure, verified account).
- Publishing reviews on the homepage – Art. 6 (1) (a) GDPR (your consent, revocable at any time); the internal evaluation as feedback – Art. 6 (1) (f) GDPR.
- Invitation/referral feature and badges – Art. 6 (1) (f) GDPR (legitimate interest in growing the community) or (b) GDPR.
- Security, abuse and spam prevention, stability (e. g. log files, CSRF protection, moderation) – Art. 6 (1) (f) GDPR (legitimate interest in secure operation).
- Push notifications and the publication of the voting winner on Instagram – Art. 6 (1) (a) GDPR (your consent, revocable at any time).
- Compliance with legal obligations, where applicable – Art. 6 (1) (c) GDPR.
5. Public visibility
MotoMotors is an open community. Your profile is publicly accessible – that is, visible even without signing in – and includes the profile data you provide (e. g. display name, username, region, motorcycle, riding styles, bio, avatar), your badges, winning “Picture of the Month” entries, and reviews you have released for publication. Crews (name, description, number of members, region) and public rideouts are also visible to everyone. Not public are your date of birth, your password, your email address, your direct messages, and rideouts marked “crew only”. In the settings you can also determine whether your follower/following lists, your region and your motorcycle are displayed publicly. In public fields, only provide data whose publication you want.
5a. Publication on Instagram
We publish the monthly winning entry of the “Picture of the Month” vote – with the consent you gave upon participation (Art. 6 (1) (a) GDPR) – on our Instagram channel @motomotorsde, naming your profile name. In doing so, the image is transmitted to Meta Platforms Ireland Ltd. and is subject to their privacy policy. You can revoke this consent at any time with effect for the future (business@motomotors.de).
6. Cookies & local storage
We use exclusively technically necessary (functional) cookies or local storage. No marketing, tracking or third-party cookies are used. Necessary cookies are exempt from consent pursuant to Section 25 (2) TDDDG.
| Name | Purpose | Storage duration | Type |
|---|---|---|---|
motomotors_sess |
Keeps your session/login active (you stay signed in) | Until logout, max. 30 days | Necessary (cookie) |
| CSRF token | Protection against cross-site request forgery (within the session) | Session | Necessary |
mm_cookie_consent |
Stores your cookie decision so the notice does not appear again | Permanent (locally in the browser) | Necessary (localStorage) |
mm_remember |
Keeps you signed in (automatic re-login) | 60 days | Necessary (cookie) |
mm_lang |
Remembers your language choice (German/English) | 1 year | Necessary (cookie) |
mm_ref |
Attributes a registration to the referring account (invitation) | 60 days | Necessary (cookie) |
mm_2fa_trust |
Remembers a device marked as “trusted” for two-factor authentication | 30 days | Necessary (cookie) |
7. Hosting
The Platform is operated by a hosting provider that processes the data on our behalf and in accordance with our instructions (processing on behalf pursuant to Art. 28 GDPR). The processing takes place to provide the service securely and reliably.
8. Embedded fonts
For a consistent presentation, we use web fonts that are loaded from external providers: Google Fonts (Google Ireland Limited) as well as Fontshare (Indian Type Foundry). When the font files are loaded, your IP address is, for technical reasons, transmitted to the respective servers. The legal basis is our legitimate interest in an appealing and consistent presentation (Art. 6 (1) (f) GDPR).
9. Storage duration
We store your account and profile data for as long as your account exists. If you delete your account or ask us to delete it, we remove the data, provided no statutory retention obligations prevent this. Server log files are only kept for a short time for security purposes.
10. Recipients
As a rule, no data is passed on to third parties, with the following exceptions:
- the hosting provider named above (processing on behalf pursuant to Art. 28 GDPR);
- the push service of your browser/operating system (e. g. Google, Mozilla, Apple/Microsoft) – only if you enable push;
- Meta Platforms Ireland Ltd. – only for the voting winner published on Instagram and only with your consent;
- as well as insofar as we are legally obliged to do so.
11. Your rights
Under the GDPR, you have the right at any time to:
- Information about the data stored about you (Art. 15)
- Rectification of inaccurate data (Art. 16)
- Erasure (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Objection to processing based on legitimate interests (Art. 21)
To exercise these rights, a message to business@motomotors.de. is sufficient. In addition, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).
12. Data security
Transmission is encrypted via HTTPS/TLS. Passwords are stored exclusively as a bcrypt hash. Write actions are protected by CSRF tokens.
13. No automated decision-making
Automated decision-making or profiling within the meaning of Art. 22 GDPR does not take place.
14. Minimum age
MotoMotors is aimed at persons aged 16 and over. By registering, you confirm that you are at least 16 years old.
15. Changes to this policy
We adapt this Privacy Policy if the service or the legal situation changes. The version published here applies in each case.