Version 1.6, effective 30.09.2026. The Polish version prevails.
1. Who processes data
The controller is Sendormeco Holding sp. z o.o., ul. Złota 75A/7, 00-819 Warsaw, Poland, KRS 0000906110, NIP 5252866457, REGON 389194801. Contact for data matters: office@hovera.app, phone +48 791 301 019. We have not appointed a data protection officer — we are not required to.
2. Two roles — the key point
| Data | Our role | Who decides |
|---|---|---|
| panel and app accounts (people on the Customer’s side: stable, transport company, horse owner) | controller | us |
| rider and horse owner account in the mobile app: email, name, password, verification codes, phones registered for push notifications and the list of stables the account is linked to | controller | us |
| data of horse owners, riders and stable clients kept by the stable: client record with contact details, passes, bookings, horse data, messages, billing and invoices — also when you view them in the app | processor | the Customer (stable) |
| transport company drivers’ data, including the phone’s location during a trip (trip tracking) | processor | the transport company |
| logs, cookies, technical data | controller | us |
| contact, demo and transport inquiry forms | controller | us |
Data entered by the Customer — a stable or a transport company — is processed only on its documented instructions, under the data processing agreement (Art. 28 GDPR) at app.hovera.app/dpa.
A rider account is not the same as a client record at the stable. You create the app account yourself — the stable does not — and one account can be linked to several stables. That is why we are the controller of the account itself. Each stable remains the controller of what it keeps about you: the client record, bookings, passes, invoices and messages. The app only shows you that data on the stable’s behalf. Details in section 7.
For data kept by your stable or transport company (client record, bookings, invoices, driver data), contact it — it is the controller of that data. We will pass your request on but cannot decide it ourselves. For the app account itself (access, correction, deletion), write to us.
3. Data we process as a controller
Accounts: name, email, phone, role, login data (password hash), login history and, in the mobile app, a device identifier for push notifications. Rider and horse owner app account: email (login), name, password hash, preferred language, email confirmation date, linked stables (client record ID, its name and link date), records of issued verification codes (code hash, purpose, channel, the phone number an SMS went to, attempts, validity), login tokens and phones registered for push (platform, app version, device model). Billing: company name and address, tax ID, plan, payment and invoice history — we never see the full card number. Technical: IP address, browser and device type, request time, referrer, cookie identifiers. Visit statistics (only with consent): if you accept analytics cookies, Google Analytics collects a cookie identifier, pages visited, visit time, approximate location derived from the IP address and browser and device data. Without consent the Google script is not even loaded. Correspondence: support requests, contact forms and transport inquiries.
4. Purposes and legal bases
| Purpose | Legal basis | Retention |
|---|---|---|
| providing the Service and the Account | Art. 6(1)(b) GDPR | term of the agreement + 30 days for export |
| billing and accounting | Art. 6(1)(c) GDPR | 5 years from the end of the tax year |
| transactional notifications (invoice, payment, outage, trip) | Art. 6(1)(b) GDPR | term of the agreement |
| rider and horse owner app account: registration, login, linking stables, password reset | Art. 6(1)(b) GDPR — agreement for use of the app (§ 15 of the Terms) | until the account is deleted |
| verification codes and attempt limits (protection against account takeover) | Art. 6(1)(b) and (f) GDPR | code valid 15 minutes; the code record is deleted after 30 days |
| push notifications in the app | Art. 6(1)(b) GDPR | until logout, uninstalling the app or deleting the account |
| visit statistics (Google Analytics) on hovera.app and app.hovera.app | Art. 6(1)(a) GDPR — consent given in the banner | until consent is withdrawn; cookies up to 24 months, data in Google Analytics at most 14 months |
| own marketing | Art. 6(1)(a) GDPR — separate consent | until consent is withdrawn |
| security, logs, abuse prevention | Art. 6(1)(f) GDPR | 12 months |
| establishing and defending claims | Art. 6(1)(f) GDPR | until time-barred |
| public transport request board (app.hovera.app/gielda) — showing the request to carriers who can make an offer and showing that the platform works | Art. 6(1)(f) GDPR — legitimate interest; notice at the form, right to object | until an offer is accepted or the request expires; accepted requests — another 30 days in the “Booked” section |
5. Recipients and processors
| Provider | Role | Scope | Where |
|---|---|---|---|
| Hetzner Online GmbH | hosting and backups | all Service data | Germany (EEA) |
| PayU S.A. | payment operator | transaction and card data (we don’t see it) | Poland |
| Revolut Bank UAB | payment operator (Revolut Pay and card) | transaction data, payer’s email address; we don’t see card data | Lithuania (EEA) |
| Mailgun Technologies, Inc. | transactional email, including account verification codes | email address, message content | EU servers |
| SMSAPI (ComVision sp. z o.o.) | SMS, including account verification codes | phone number, message content | Poland |
| HeiGIT gGmbH (OpenRouteService) | route calculation | pickup and drop-off addresses and coordinates | Germany (EEA) |
| Mapbox, Inc. | fallback routing, address suggestions | addresses and coordinates | USA — standard contractual clauses |
| Google Ireland Ltd (Firebase Cloud Messaging) | push notifications in the mobile app | device identifier, notification content | possible transfer to the USA — EU-US Data Privacy Framework and standard contractual clauses |
| OpenStreetMap Foundation | map tiles in the panel, the customer portal and the fleet map in the Android app | IP address of the browser or phone loading the map | United Kingdom — adequacy decision |
| Google Ireland Ltd (Google Analytics) | visit statistics for hovera.app and app.hovera.app — only after consent in the banner | IP address, cookie identifier, pages visited, browser and device data | possible transfer to the USA — EU-US Data Privacy Framework and standard contractual clauses |
| BunnyWay d.o.o. (Bunny Fonts) | fonts on hovera.app and the app’s login pages | IP address of the browser loading the font; no cookies | Slovenia (EEA) |
Panel and app data is stored in the EEA and leaves it only as described above, always under an adequacy decision or standard contractual clauses. We do not sell data.
Transport inquiries (transport marketplace). A transport inquiry sent to all carriers is visible in the panel to all verified marketplace carriers with an active subscription or trial — the route with pickup and drop-off addresses, the date and notes straight away, and contact details (full name, email, phone) once they take the inquiry — so they can prepare an offer. Notifications about a new inquiry go to carriers serving the area. An inquiry addressed to chosen carriers goes only to them. Once an offer is accepted, the chosen transporter becomes a separate controller of that data for the transport contract — requests about the transport go to them (contact details are on their profile and invoice). We remain the controller of the inquiry history and data needed to run the platform. Details: transport marketplace terms.
Public request board. A transport request sent to all carriers (rather than to one chosen carrier) is shown publicly at app.hovera.app/gielda with: the requester’s first name only, the town and voivodeship of pickup and drop-off, the date, the number of horses, the number of offers made and when it was added. We do not show publicly the surname, email address, phone number, exact addresses or notes: addresses and notes are visible only to a logged-in, verified carrier with an active subscription or trial, and contact details only to a carrier who has taken the request in the panel. Purpose: reaching carriers who can make an offer and showing that the platform works. Legal basis: Art. 6(1)(f) GDPR; we say so at the form. You have the right to object (Art. 21 GDPR): tick “Do not show my first name on the board” in the form or write to office@hovera.app — we then show “Client” instead of your name. The request leaves the list once an offer is accepted or it expires; accepted requests stay for another 30 days in the “Booked” section. Requests sent before 26.09.2026 are shown without a name.
We notify Customers of any change of processors of entrusted data 30 days in advance.
6. Trip tracking in the transport module
A transport company can enable trip tracking. The Hovera app on the driver’s phone then records the phone’s location — coordinates, accuracy and time of fix — about every 15 minutes, from saving “Start trip” (loading) to “Finish trip” (unloading).
- No location outside a trip. While tracking runs, the driver sees a persistent notification.
- The transport company is the controller — it decides to enable tracking and informs its drivers beforehand. We act as a processor.
- Who sees what: the company office sees the route; a customer who ordered through Hovera sees only the last point in the inquiry portal, and only until the trip ends.
- Text with a link: on “On my way to pickup” the carrier’s customer may receive a text (sent via SMSAPI) with a link to a tracking page — the trip stage and, if the company tracks trips, the vehicle’s last position. The link shows data only during the transport and for one day after; the carrier can switch this text off in its settings.
- How long: trails are deleted after 30 days; the position in the customer portal disappears when the trip ends or is cancelled, at the latest after 24 hours without a new point.
7. Rider and horse owner account in the mobile app
How a rider account is created. A stable client creates the account themselves in the Hovera app. They enter an email address; we check whether stables using Hovera have a client record with that address. If so, we send a one-time code: by SMS to the phone number on the client record (via SMSAPI) or — if the record has no number — by email (via Mailgun). After entering the code and setting a password, the account is linked to the records the code confirmed. A code sent by SMS confirms only records with that phone number; you choose which stables to link. Further stables are linked the same way from within the account. You can unlink a stable at any time in the app; the stable can also unlink it in its panel — the account stays, only its connection to the client record at that stable is removed.
- Where the record data comes from. We take the phone number and name from the client record kept by the stable, solely to send the code and show which stable you are linking. We do not change the record other than marking that it has a linked account.
- The SMS with a code is transactional. We send it only at your request (registration, password reset, linking a stable, account deletion); it contains no advertising and needs no marketing consent. The code is valid for 15 minutes, can be entered at most five times, and we store only its hash. The record of an issued code (hash, channel, number, attempts) is deleted after 30 days; abuse-prevention attempt counters expire within an hour.
- Password reset works the same way — a code by SMS to the number on a record the account has already confirmed, or by email. A new password logs out all phones.
- Push notifications (lessons, invoices, messages from the stable) are sent via Firebase Cloud Messaging to phones registered on the account. We delete a phone’s identifier on logout, when Firebase reports it invalid, and when the account is deleted. You can also switch notifications off in your phone settings.
- A horse owner logs into the app with the same account as in the owner panel. What the stable keeps about their horses (livery, invoices, messages) remains the stable’s data, as above.
- Who sees your account. The stable sees that its client record has a linked account; it does not see your password or the other stables your account is linked to.
- How long. We keep the account until it is deleted. An account unused for 24 months may be deleted after prior notice sent to the account’s email address.
- Deleting a rider account — yourself, immediately. In the app (More → Delete account) or at app.hovera.app/delete-account. You confirm with your password or a one-time code sent by SMS to the number on a client record the account has already confirmed, or by email if there is none. We then immediately delete the stable links (the client record no longer points to the account), verification codes, push phone identifiers, login tokens and sessions. The account itself is first anonymised (email, name, password, second login factor) and then deleted; if a technical link in the database prevents that, only an anonymised row marked as deleted remains. The event log keeps only the account identifier. The email address is free straight away. As a fallback you can write to office@hovera.app from the account’s address — we then delete within 30 days.
- A horse owner (account with an owner panel, transport orders and invoices) deletes the account via office@hovera.app — part of that data must be retained. A staff account at a stable or transport company is removed by that company in its panel.
- What stays with the stable. Deleting the account does not delete the client record or the bookings, passes, invoices, messages and documents kept by the stable: that is the stable’s data as controller, and it must keep invoices for the period required by tax law. Ask the stable to delete it.
8. Your rights
You have the right of access, rectification, erasure, restriction, portability, objection to processing based on legitimate interest and to withdraw consent at any time. Write to office@hovera.app — we reply within one month (extendable by two months for complex cases). You may also lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw.
9. Security
TLS encryption, encrypted credentials and keys, a separate database per Customer, role-based access control, one-time verification codes stored only as a hash with attempt limits, event logging, daily backups stored outside the production server and availability monitoring. Only people who need it have access to production data.
10. Automated decisions
We do not make decisions based solely on automated processing, including profiling, that produce legal effects.
11. Cookies and visit statistics
On hovera.app and app.hovera.app we use cookies necessary for the service to work. Google Analytics is loaded only after consent given in the banner — until then the browser does not connect to Google at all. We store the consent together with the cookie policy version number; if the version changes, we ask again. You can withdraw consent with the “Cookie settings” link; we then delete stored Google Analytics cookies. Details in the separate cookie policy.
12. Changes
We announce material changes 30 days in advance by email and in the panel. The current version is always at hovera.app/en/polityka-prywatnosci. Version 1.5 is effective from 26.09.2026.