MinVolt — Privacy Policy
Effective date: 2026-05-09
This Privacy Policy explains how MinVolt (“MinVolt”, “we”, “us”, or “our”) processes personal data in connection with:
- the MinVolt Courier web application and installable Progressive Web App (“Courier App”),
- the operator/admin management system (“CMS”),
- related APIs,
- and associated operational services
(collectively, the “Services”).
By using the Services, you acknowledge the practices described in this Policy.
1. Scope and Roles
This Policy applies to:
- courier users,
- operators,
- administrators,
- contractors,
- and authorized personnel using the Services.
This Policy does not apply to third-party services, websites, or platforms accessed through external links.
2. Categories of Data We Process
2.1 Account and Identity Data
We may process:
- phone numbers,
- names,
- courier identifiers,
- account status,
- language preferences,
- access roles,
- and operational authorization data.
2.2 Authentication and Security Data
We may process:
- OTP verification records,
- SMS verification events,
- anti-abuse and fraud-prevention signals,
- reCAPTCHA validation data,
- login timestamps,
- device/browser session identifiers,
- IP-related security metadata,
- and security logs.
2.3 Operational Data
Depending on your role, we may process:
- assigned bike and battery information,
- asset identifiers,
- operational statuses,
- debt and tariff information,
- payment-related operational records,
- support interactions,
- restrictions and operational actions,
- and inventory/workflow records.
2.4 Notifications and Communications
We may process:
- notification delivery status,
- push notification subscriptions,
- message content metadata,
- support communications,
- and operational alert preferences.
2.5 Device and Technical Data
We may process limited technical information such as:
- browser type,
- User-Agent data,
- device metadata,
- request logs,
- session tokens,
- local storage/session storage identifiers,
- API request metadata,
- and diagnostic logs.
2.6 Location Data
If permission is granted, we may process approximate or precise geolocation data for:
- operational functionality,
- map-related features,
- station discovery,
- operational visibility,
- and related workflows.
Location permissions may be withdrawn at any time through browser or device settings.
2.7 Camera and Microphone Data
If enabled by the user, camera or microphone access may be used for:
- profile photo capture,
- QR/barcode scanning,
- operational verification,
- audio-code scanning,
- or other approved operational functionality.
Certain audio-processing features may process data locally in the browser where technically feasible.
2.8 Media and Uploaded Content
We may process:
- profile photos,
- uploaded documents,
- operational attachments,
- and associated metadata.
3. Purposes of Processing
We process personal data to:
- provide and operate the Services,
- authenticate users,
- maintain account security,
- prevent fraud and abuse,
- manage operational workflows,
- administer assets and inventory,
- support courier operations,
- deliver notifications,
- provide customer and operational support,
- maintain audit and security records,
- improve reliability and functionality,
- comply with legal obligations,
- and protect MinVolt systems, users, and operations.
4. Legal Bases
Depending on jurisdiction and operational context, processing may rely on:
- contractual necessity,
- legitimate interests,
- operational necessity,
- compliance with legal obligations,
- and user consent for specific permissions or features.
Permissions such as:
- notifications,
- push notifications,
- geolocation,
- camera,
- and microphone access
may rely on browser or device-level consent mechanisms.
5. Third-Party Providers and Data Sharing
We may share data with infrastructure and service providers necessary to operate the Services.
These may include providers related to:
- cloud hosting,
- database infrastructure,
- storage,
- messaging,
- authentication,
- push notifications,
- mapping services,
- anti-abuse systems,
- analytics,
- and operational communications.
Examples may include:
- Hetzner,
- Supabase,
- Twilio,
- Google reCAPTCHA,
- Google Maps,
- browser push infrastructure providers,
- WhatsApp,
- Telegram,
- and related operational platforms.
Third-party providers may process data according to their own privacy policies and legal obligations.
We may also disclose information:
- when required by law,
- to respond to lawful requests,
- to investigate abuse or fraud,
- to protect safety or security,
- or to enforce operational and legal rights.
6. International Data Transfers
Infrastructure and providers used by MinVolt may process data in multiple jurisdictions.
Primary hosting infrastructure may be located in Germany or other operational regions.
Some providers may process data internationally depending on their systems and infrastructure.
Where required, MinVolt will implement appropriate safeguards for cross-border transfers.
7. Data Retention
We retain data only for as long as reasonably necessary for:
- operational purposes,
- security,
- auditing,
- legal compliance,
- dispute resolution,
- fraud prevention,
- and service reliability.
Retention periods may vary depending on:
- operational requirements,
- legal obligations,
- security needs,
- and technical constraints.
Examples may include:
- temporary verification records,
- notification delivery data,
- audit logs,
- push subscriptions,
- and operational activity records.
8. Security Measures
We implement administrative, technical, and organizational safeguards designed to protect personal data.
Security measures may include:
- access controls,
- authentication systems,
- logging and monitoring,
- infrastructure isolation,
- rate limiting,
- and abuse-prevention mechanisms.
No platform or transmission method is completely secure, and users are responsible for protecting their devices and credentials.
9. User Controls and Permissions
Users may:
- manage browser permissions,
- disable notifications,
- revoke push permissions,
- control geolocation access,
- and manage certain profile information where functionality is available.
Disabling permissions may affect Service functionality.
10. Children
The Services are intended for operational and workforce-related use and are not directed toward children.
11. Changes to This Privacy Policy
MinVolt may update this Privacy Policy periodically.
Updated versions may be published:
- within the Services,
- through official MinVolt channels,
- or through operational communication methods.
Continued use of the Services after updates become effective constitutes acknowledgment of the updated Policy.
12. Contact
Privacy and operational inquiries may be submitted through official support or communication channels provided within the Services.