Data Protection Declaration for affiliated products
(Applicable to MAPFOUR connectivity e-bikes and associated App services))
Version: V1.0
I. Applicability
This Data Notice applies to MAPFOUR connected electric bicycles, the MAPFOUR App, and supporting services directly related to the functions of these products.
When you purchase, connect, use, manage, or interact with a MAPFOUR electric bicycle through the App, the product and its associated services may generate, collect, store, or process data related to vehicle operation, device connection, ride data, customer service, and other functions you actively use.
This Data Notice aims to inform potential purchasers, users, and actual administrators of connected devices about the following:
1. What data is generated by this product and its associated services?
2. The sources, main purposes, and processing limits of the data concerned;
3. What data users can directly access;
4. What data can be exported;
5. What data can be transferred to third parties upon user request;
6. What data can be deleted and under what restrictions;
7. What data is not externally disclosed, or only to a limited extent, due to cybersecurity, business secrets, system integrity, or the protection of third-party rights and interests.
This Data Notice, along with the MAPFOUR Privacy Policy, the MAPFOUR Data Access, Export, Sharing, and Deletion Rules, and related policy documents such as the Customer Service Policy, constitute the framework for MAPFOUR's external disclosure of data related to connected products and related services. Where personal data is processed, the processing concerned is also subject to applicable data protection laws. This Data Notice does not supersede the General Data Protection Regulation (GDPR).
II. Scope of Networked Products and Associated Services
-
Connected Products
The connected electric bicycles of the MAPFOUR brand include integrated or external IoT communication modules, sensors, control systems, and vehicle functionalities related to vehicle status, diagnosis, and ride data.
- Related Services
Digital services directly related to the functions of the aforementioned connected products include, but are not limited to:
• App account registration and login;
• Vehicle binding and unbinding;
• Vehicle status display and settings;
• Ride data, route, and history retrieval;
• Fault diagnosis and feedback;
• Community contributions, comments, and image uploads;
• Backend processing directly related to customer service, system operation and maintenance, authorization management, and security.
III. Data Categories
-
Vehicle Operational and Status Data
During vehicle operation, parking, charging, or when connected, the product may collect data on vehicle operation, riding statistics, vehicle status, operational performance, vehicle control and settings, device status and logs, device diagnostics, connection status, location support, and riding behavior.
Main Purposes:
To display vehicle status to users, enable ride data and history inquiries, provide fault diagnosis and customer service, support safety and performance-related maintenance, and, upon user request, allow data access, export, or transfer to third parties to a certain extent.
-
Device Identification and Connection Data
As part of connectivity, connection, identification, and vehicle management, the relevant services may collect and process device identification and connection data.
Main Purposes:
For device identification, establishing or maintaining binding relationships, displaying compatibility and version information, supporting diagnostics and customer service, and ensuring the security of device and service connections.
-
Location and Route Data
When users activate location services, navigation features, ride recording, or similar map functionalities, the associated services may collect and process the following data:
• Mobile device location data;
• the precise location of the vehicle;
• the vehicle's travel routes and the route itself.Main Purposes:
To enable location services, navigation, ride recording, historical ride viewing, location-related features, and sharing functionalities actively selected by users.
This data category is extremely sensitive, encompassing personal movement patterns and travel habits. We implement stringent security measures, including encryption, in its collection and processing. User access to, export, deletion, and transfer to third parties of this data are subject to even stricter controls.
-
Account and Basic Profile Data
During MAPFOUR App registration, login, and account settings, the relevant services may collect and process the following data:
• Email address;
• Password;
• Country/Region;
• Nickname;
• Avatar or profile picture.Main Purposes:
For creating and maintaining user accounts, supporting identity verification, enabling account management, and providing related services.
Passwords are used solely for authentication and security verification and are not considered data elements that users can view, export, or share.
-
Feedback, Customer Service, and Support Data
When users provide problem feedback, repair requests, inquiries, or customer service requests, the relevant services may collect and process the following data:
• User's email address or other contact information;
• Device name;
• User's country;
• Type of issue;
• Text of the feedback;
• Photos for feedback;
• Logs or diagnostic data to identify the issue.Main Purposes:
For troubleshooting, providing customer service, performing fault analysis, and handling the service process.
Free text content, attachments, and log files may contain additional personal data or third-party information. Therefore, the disclosure of such data to third parties is generally subject to stricter restrictions. -
Community and User-Generated Content
When users engage in image editing, community posts, comments, or sharing functions, the associated services may collect and process the following data:
• Photos uploaded to the community;
• Content of comments;
• other content actively published by users.Main Purposes:
To enable community interaction, including content display, commenting, and communication features for users.
This data category typically involves user-generated content and may also involve settings related to public visibility, deletion requests, and the protection of third-party rights and interests.
- Usage Logs and System Data
During the operation of the App and backend services, MAPFOUR may process log data related to service operation, troubleshooting, and security maintenance.
Main Purposes:
Ensuring normal operation, troubleshooting failures, handling security incidents, optimizing stability, and maintaining system integrity.
Raw logs are generally not fully shared. If necessary, users may receive summaries or explanations of results directly related to their requests.
IV. How Users Access This Data
Depending on the data type, risk level, and system availability, MAPFOUR provides users with the following access methods:
-
Direct Online Display
The data that users can directly view within the MAPFOUR App includes, but is not limited to:
• Real-time vehicle status data;
• basic riding statistics;
• Device identification data such as device name, model, and version;
• basic display content in historical ride logs;
• basic account profile data;
• Basic information of submitted feedback;
• Community contributions. -
Export Upon Request
For data that is structurally stored and can be appropriately extracted, users can export the relevant data from the corresponding module through the associated function in the MAPFOUR App.
Exportable data typically includes, but is not limited to:
• Vehicle operational data;
• Riding statistics;
• Vehicle status data;
• basic account profile data;
• User-submitted community content and feedback.The exported data is provided in a structured, commonly used, and machine-readable format. For data that can be provided in real-time or continuously, MAPFOUR decides whether to grant continuous access based on technical feasibility.
- Disclosure to Third Parties only with Prior Consent.
Provided that legal requirements are met, identity and authorization verification are completed, and the user has properly submitted the request, MAPFOUR may transfer the relevant data to a third party designated by the user.
Typical use scenarios include, but are not limited to:
• Repair, maintenance, and fault diagnosis;
• Support for insurance matters or claims;
• Fleet management;
• other data services selected by the user.
The extent to which information is provided to third parties is limited by the following factors:
• the scope of user authorization;
• the type and sensitivity of the data;
• system security and the protection of business secrets;
• whether third-party information is affected;
• verification of the recipient's identity and security conditions.
V. Data generally not fully disclosed or only to a limited extent.
To protect network and product security, business secrets, third-party rights and interests, and system integrity, the following data is generally not fully shared as raw data with users or third parties, or is only made available to a limited extent:
- Passwords, login credentials, key material, and other authentication data;
- Underlying control parameters related to device or platform security mechanisms;
- Raw data that could reveal system vulnerabilities, interface strategies, abuse protection logic, or internal security monitoring rules;
- Complete raw log files, debug logs, and internal risk control indicators;
- Data containing personal data of third parties, protected business information, or internal information. & information included;
- Portions of the complete raw sensor data that exceed the reasonable purpose for user access and whose disclosure could compromise security or reveal business secrets.
Alternatively, MAPFOUR may provide the following:
• Summaries that users can easily understand;
• necessary extracts directly related to customer service, repairs, or the user's request;
• Versions that are anonymized, aggregated, shortened, or limited in scope.
VI. Deletion and Retention Rules
Users can directly delete certain data within the MAPFOUR App or submit deletion requests to MAPFOUR. Data that can be deleted includes, but is not limited to:
• Community contributions;
• specific route and location data;
• Profile picture, nickname, and other profile data;
• Attachments to reviews;
• the deletion of the account and the subsequent processing of data associated with the account.
However, under the following circumstances, MAPFOUR may postpone deletion, partially retain data, or substitute deletion with anonymization or restriction:
- to the extent necessary for customer service, dispute resolution, fulfillment of warranty obligations, or fault detection;
- to the extent necessary to comply with applicable legal obligations, as well as financial and audit requirements;
- to the extent necessary to ensure network and product security, detect abuse, and maintain service integrity;
- to the extent necessary to protect the legitimate rights and interests of third parties.
If immediate deletion is not carried out or is only partially performed, MAPFOUR will explain the reasons in the relevant user interface or in the processing result.
VII. User Requests and Identity Verification
To prevent unauthorized data access, disclosure, or deletion, MAPFOUR implements various levels of identity and access authorization verification, depending on the type of request.
For high-risk requests, such as:
• exporting precise location or route data;
• authorizing a third party to continuously receive device data;
• deleting data closely linked to device pairing;
• requiring access to data that allows a high degree of identifiability, such as the full display of serial numbers or MAC addresses,
MAPFOUR may require users to perform additional checks, including but not limited to:
• Confirmation of registration status;
• secondary review;
• Verification of device pairing;
• Additional confirmation of current control rights, purchase agreement, or usage agreement.
VIII. Updates to this Data Notice
If product functions, App-related services, data structures, export functions, or third-party access mechanisms change, MAPFOUR may update this Data Notice accordingly and make the latest version available to users through the official website, the App, or other appropriate means.
IX. Contact and Further Information
Users can obtain more information on the following topics through the "EU Data Protection Law" section in the MAPFOUR App, customer service, the feedback page, or the relevant article on the official MAPFOUR website:
• Data access;
• Data export;
• Consent for disclosure to third parties;
• Deletion requests;
• Processing of personal data.