BikeYa
BikeYa Legal Centre

BikeYa Privacy Notice

How BikeYa collects, uses, shares, protects, and retains personal data.

Version
1
Effective date
29 July 2026

1. Scope and roles

This Notice applies to BikeYa business accounts, websites, mobile applications, support, security, and service administration.

BikeYa acts as a data controller for business-account, staff-account, billing, usage, support, security, and legal-compliance data. For customer, renter, booking, rental, identity-document, and vehicle-use data processed for a business, the business is normally the controller and BikeYa is its processor.

2. Data and sources

BikeYa may process business and staff names, roles, emails, telephone and WhatsApp numbers, addresses, country, login records, device and network information, IP address, security events, preferences, support communications, subscription information, and service activity logs.

On a business’s instructions, BikeYa may process renter contact details, identity and driving documents, photographs, signatures, booking and rental details, locations, payments recorded by the business, vehicle use, incidents, chat messages, and attachments.

Data comes from account holders, authorised staff, customers using a business’s shop, support communications, devices, service logs, and integrations selected by users. BikeYa does not sell personal data.

3. Purposes and legal bases

BikeYa processes data to create and secure accounts; provide, localise, maintain, and support the service; deliver messages and notifications; manage plans and invoices; prevent fraud and abuse; diagnose errors; maintain audit records; comply with law; establish or defend claims; and improve reliability and usability.

Depending on the context, processing relies on contract, legal obligation, consent, vital interests, or another lawful basis recognised by applicable law.

4. Sharing and international transfers

Data is disclosed only as needed to authorised users of the relevant business, service providers and subprocessors, user-selected integrations, professional advisers, authorities where legally required, and parties to a lawful corporate transaction.

Some providers may process data outside Indonesia. BikeYa uses safeguards required by applicable law, such as adequate protection, binding contractual protection, or valid consent where required.

5. Retention

Data is kept only as long as needed for the stated purposes, the service agreement, security, backup cycles, dispute resolution, and legal, tax, or accounting requirements. Business-controlled rental data follows the business’s instructions unless retention is legally required.

Deletion from active systems may be followed by deletion from protected backups during the applicable backup cycle.

6. Individual rights

Subject to applicable law, individuals may request information, access, correction, completion, withdrawal of consent, objection, restriction, deletion, destruction, portability where applicable, and review of certain automated decisions.

Requests concerning a particular rental should normally be sent to the relevant rental business. BikeYa will assist that business where BikeYa acts as processor and may verify the requester’s identity.

7. Security, incidents, and automated tools

BikeYa applies risk-appropriate technical and organisational measures, including access controls, encryption in transit, logging, backup, monitoring, and restricted staff access.

No system is completely secure. BikeYa will investigate and mitigate confirmed personal-data incidents and provide legally required notifications or processor assistance.

BikeYa does not use solely automated decision-making to decide whether a renter may rent a vehicle. OCR and automated suggestions require human review.

8. Updates and contact

The effective date and version are displayed in the Legal Centre. Material changes will be notified where required. Privacy requests and complaints may be submitted through BikeYa’s published privacy or support contact channel.