Privacy Policy
Privacy Policy
This Privacy Policy explains how Tory Bike UK Limited (company number 17068101) ("Tory", "we", "us" or "our") collects, uses, shares and protects personal data when you use the Tory App, create or use a phone-number-based account, pay for or use a Tory sanitation unit, contact support, or otherwise interact with us.
For data protection purposes, Tory Bike UK Limited is the controller of the personal data described in this Policy unless we state otherwise.
Contact: info@tory.bike
This Policy applies to personal data collected through the App, through related web pages or payment flows, through support interactions, through the operation of the Service, and from third-party providers involved in delivering the Service, such as payment processors or mapping services.
This Policy does not govern third-party services that have their own privacy notices, except to the extent we determine the purposes and means of processing carried out through those services.
We may collect the following categories of personal data.
· Identity and contact data: mobile phone number, support contact details, and records needed to identify your account or communicate with you.
· Account data: verification status, account identifiers, device linkage, service preferences, account deletion requests and related records.
· Transaction and payment data: payment token or reference, amount, date, time, refunds, chargebacks, billing records, anti-fraud signals and records received from payment processors. We do not store full card numbers.
· Service-use data: date and time of access, duration, unit identifier, booking or unlock records, error records, and records relevant to support, misuse investigation or dispute resolution.
· Device and technical data: device model, operating system, app version, IP address, log data, crash data, diagnostics, security events and similar technical information.
· Location data: approximate or precise device location where permitted, location-related search results, and unit-location interactions used to show nearby units and help operate the Service.
· Support and communications data: the contents of emails, messages, support tickets, call notes or complaint correspondence and the records needed to manage them.
· Fraud, safety and compliance data: information used to detect misuse, enforce our terms, protect the public, respond to incidents or comply with legal obligations.
· directly from you, such as when you enter your phone number, verify your account, place an order, use the App, request support or submit a complaint;
· automatically from your device and use of the App, such as logs, diagnostics and location permissions where enabled;
· from payment processors, including Stripe, in connection with payments, fraud prevention, disputes and refunds;
· from mapping and location providers, including Google Maps services, in connection with map display, geolocation and route or place information;
· from our service providers, advisers, law enforcement or other third parties where this is lawful and necessary for safety, fraud prevention, dispute handling or compliance.
Under UK data protection law, we must have a lawful basis for each use of personal data. Depending on the context, we rely on one or more of the following lawful bases.
Purpose
Typical data used
Lawful basis
Create and operate your account, verify your phone number, allow login and identify your service history
phone number, verification records, device linkage, account records
Performance of a contract; legitimate interests in service security and account integrity
Process payments, refunds, receipts and chargebacks
payment references, transaction data, support records
Performance of a contract; legal obligation for financial recordkeeping; legitimate interests in fraud prevention
Show nearby units, operate location-based features and help you access a suitable unit
location data, device data, service-use data
Performance of a contract where location is needed to deliver the service; consent or device permission where required
Provide customer support, complaint handling and service communications
contact data, account data, transaction data, support communications
Performance of a contract; legitimate interests in service administration and customer care
Maintain security, prevent fraud, investigate misuse, recover losses and protect public safety
technical logs, transaction data, service-use data, support records, fraud signals
Legitimate interests in network and service security, fraud prevention, legal claims and public safety; legal obligation where applicable
Improve the App and Service, diagnose faults and plan operations
technical data, usage patterns, service-use data, support trends
Legitimate interests in improving and operating the Service effectively
Comply with law, regulation, court orders or lawful requests
any relevant category depending on the request
Legal obligation; legitimate interests in establishing, exercising or defending legal claims
The App may request access to your device location so it can show nearby Tory units and operate location-dependent features.
Where your device permission system requires your consent, we rely on that permission for access to location data. You can disable location access in your device settings, but some features may stop working or work less effectively.
Unless we say otherwise in the App, we do not need to keep precise location data longer than is reasonably necessary to provide the service, handle incidents, support requests, fraud checks or legal claims.
Payments are processed through third-party payment processors, including Stripe. Stripe may receive personal data such as your payment details, transaction amount, device or fraud-prevention data, and billing-related information under its own role and privacy terms.
We receive limited payment information back from Stripe, such as payment status, tokenised references, anti-fraud signals, chargeback information and records needed for support, refunds and accounting. We do not store full card numbers or card security codes.
The App uses Google Maps and related Google services to display locations, mapping content and possibly place or navigation information. Google may process device, network and location data under its own privacy terms when those services are used.
We use these services to help users find nearby units and operate map-based features in the App.
We may share personal data only where it is lawful and necessary, including with the following categories of recipients:
· payment processors and related financial service providers, including Stripe;
· cloud, hosting, software, communications, technical support and security providers;
· mapping, geolocation and infrastructure providers, including Google Maps services;
· professional advisers, insurers, auditors and prospective purchasers or investors where appropriate and lawful;
· law enforcement, regulators, courts or other authorities where disclosure is required or where we have a lawful basis to do so;
· other parties involved in dispute resolution, fraud prevention or legal claims where disclosure is necessary and proportionate.
We do not sell your personal data.
Some of our providers may process or access personal data outside the United Kingdom. Where we transfer personal data internationally, we use safeguards required or recognised by applicable law, such as adequacy regulations, contractual safeguards, or other lawful transfer mechanisms.
You can contact us if you want more information about the safeguards relevant to a particular transfer.
We keep personal data only for as long as reasonably necessary for the purposes described in this Policy, taking into account legal, accounting, tax, fraud-prevention, support and dispute-handling needs.
· Account and phone verification records: normally while your account remains active and for a reasonable period afterwards to manage reactivation, fraud prevention, support and legal claims.
· Transaction and accounting records: typically up to 7 years where required for accounting, tax, audit or legal purposes.
· Support and complaint records: typically up to 3 years after closure, and longer where needed for a dispute, investigation or legal claim.
· Technical logs and diagnostics: typically for shorter periods needed for security, stability and incident response, unless a longer retention period is justified by an investigation or legal issue.
· Location data: for the minimum period reasonably necessary to deliver the service and handle incidents, support, fraud prevention or claims; in many cases precise location is not kept long term.
· Account deletion records: as needed to record the deletion request and retain only the data we are legally required or reasonably entitled to keep.
Depending on the circumstances, you may have rights to:
· be informed about how we use your personal data;
· request access to a copy of your personal data;
· request correction of inaccurate or incomplete data;
· request deletion of personal data where there is no lawful reason for us to keep it;
· request restriction of processing in certain circumstances;
· object to processing based on legitimate interests in certain circumstances;
· receive certain data in a portable format where the law provides that right;
· withdraw consent at any time where we rely on consent, without affecting the lawfulness of processing carried out before withdrawal;
· complain to the UK Information Commissioner's Office (ICO) or, where relevant, another competent supervisory authority.
You can exercise your rights by contacting us at info@tory.bike. We may need to verify your identity before acting on a request.
If the App offers account deletion, you may use that feature or contact us to request deletion. Deleting an account does not mean we must delete data that we are legally required or otherwise lawfully entitled to keep, such as transaction, fraud-prevention, dispute or tax records.
Where data cannot be fully erased immediately, we may retain it in a restricted form only for the period required for the lawful purpose.
Some personal data is necessary for us to provide the Service, such as a verified phone number, payment-related information and certain technical or location data needed to operate the App. If you do not provide that data, you may be unable to use some or all of the Service.
Where data is optional, the App should indicate that at the point of collection where practical.
We may use automated tools for fraud screening, technical risk scoring, service integrity and basic account or payment checks. We do not currently intend to make solely automated decisions that produce legal or similarly significant effects on you without meaningful human involvement unless we clearly tell you otherwise and the law allows it.
We use technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure. These measures may include access controls, tokenisation, logging, provider due diligence and data-minimisation practices.
No app, network or storage system can be guaranteed to be completely secure, so you should also take care to keep your device and account secure.
The Service is intended for users aged 16 or older. We do not knowingly target or knowingly collect personal data from children under 16 in connection with the Service. If you believe that a child under 16 has provided personal data to us, please contact us so we can investigate and take appropriate action.
Relevant third-party privacy notices may include:
· Stripe Privacy Policy: stripe.com/privacy
· Google Privacy Policy: policies.google.com/privacy
Please contact us first if you have a privacy concern so we can try to resolve it. You also have the right to complain to the UK Information Commissioner's Office. Further information is available from the ICO website.
We may update this Privacy Policy from time to time. The latest version will be made available through the App or our website and will state its effective date. If changes are material, we may also notify you through the App, email, SMS or other reasonable means.
Tory Bike UK Limited
Email: info@tory.bike