Legal

Privacy Policy

Draft for legal review. This policy explains exactly what we collect, why, who we pass it to, and how to get it deleted.

1. Who is responsible for your data

The data controller for this website is the operator of Rideworker. The responsible person is Jakov Dokic, contactable at jakov@rideworker.com. The registered company name and address will be added here before launch.

2. What data we collect

2.1 Contact form and emails

If you write to us we store your name, email address, the topic and the content of your message, so we can answer and keep a record of the exchange.

2.2 Technical data, cookies and analytics

  • Server logs: IP address, browser type, requested page and timestamp, generated automatically when you load a page.
  • Cookie consent choice: stored in your browser so we do not ask again on every visit.
  • Country and language preference: stored in your browser so the site opens in the version you chose.
  • Analytics: aggregated statistics about which pages are read. These are only collected if you allow analytics cookies. See our Cookie Policy.

3. Legal basis for each purpose

  • Answering your message — our legitimate interest in responding to enquiries addressed to us (Art. 6(1)(f)), or steps taken at your request before entering into a contract (Art. 6(1)(b)).
  • Non-essential cookies and analytics — your consent (Art. 6(1)(a) together with the ePrivacy rules).
  • Server logs, security and fraud prevention — our legitimate interest in operating a secure website (Art. 6(1)(f)).
  • Keeping consent records — our legal obligation to demonstrate that consent was obtained (Art. 6(1)(c)).

4. Who we share your data with

4.1 We do not pass your details to fleets or platforms

Rideworker is an information site. We do not run a sign-up or matching service, we do not collect phone numbers, and we do not pass any personal data to fleets, aggregators or delivery platforms.

4.2 Service providers (processors)

Our hosting provider, database provider and email delivery provider process data on our instructions only, under data processing agreements, and may not use it for their own purposes.

4.3 Authorities

We disclose data to public authorities only where we are legally required to do so.

5. How long we keep it

These retention periods are draft values pending legal review:

  • Contact messages: 24 months after the exchange ends, then deleted.
  • Consent records: kept for the same period as the data they relate to, plus the applicable limitation period, so we can prove consent was given.
  • Contact messages: 12 months after the exchange ends.
  • Server logs: up to 30 days.
  • Analytics: aggregated and non-identifying; retained up to 14 months.

6. Your rights

If you are in the EU or EEA, the GDPR gives you the right to:

  • Access — get a copy of the personal data we hold about you.
  • Rectification — have inaccurate data corrected.
  • Erasure — have your data deleted ("right to be forgotten").
  • Restriction — have processing paused while a dispute is resolved.
  • Portability — receive the data you gave us in a structured, commonly used, machine-readable format, or have it sent to another controller.
  • Objection — object to processing based on legitimate interests.
  • Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
  • Complain to your national data protection authority.

To exercise any of these, email jakov@rideworker.com with the phone number or email address you used, so we can find your record. We respond within one month. We do not charge for this, and we do not require a specific form of words.

7. If you are in Serbia

For users in Serbia, the applicable law is Serbia's Law on Personal Data Protection (Zakon o zaštiti podataka o ličnosti), not the EU GDPR. Serbia is not an EU member state and the GDPR does not apply directly there. However, the Serbian law is closely modelled on the GDPR, and the practical rights described in section 6 above — access, correction, deletion, restriction, portability, objection and withdrawal of consent — are substantially the same. We apply the same standards and the same procedures to Serbian users as to EU users.

The difference is where you complain: instead of an EU supervisory authority, Serbian users may lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection (Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti) in Belgrade.

8. International transfers

Our providers may process data outside the EEA. Where that happens, transfers are covered by an adequacy decision or by Standard Contractual Clauses. When we route a lead to a partner in Serbia, your data is processed in Serbia under Serbian law.

9. Security

Data is transmitted over encrypted connections and stored in access-controlled databases. Contact records are not readable from the public website — only authorised operators can access them.

10. Children

This site is intended for people old enough to work as a driver or courier. We do not knowingly collect data from children.

11. Changes to this policy

We update this policy when our processing changes. The version published here is always the current one.