Privacy Policy

This privacy policy explains how Cycle Shield processes personal data when you use the website, contact the workshop, request bicycle servicing, or interact with our booking and service process.

Effective Date
As stated in this policy
Scope
All users of our services
Questions?

Privacy Contact

Privacy email
Privacy phone
+46 70 904 69 36
Postal address
Tjärhovsgatan 56, 11628 Stockholm City
Privacy contact

Use the contact details below for privacy questions or requests relating to your personal data.

Purposes of Processing

We use personal data to respond to inquiries, manage bookings, receive bicycles for service, carry out inspections, prepare and confirm quotes, perform repairs and adjustments, record approvals, complete quality checks, issue service summaries, handle payments, maintain business records, support website operation, and meet legal or accounting requirements. We may also use limited contact information to send seasonal maintenance reminders where appropriate.

Processing is limited to workshop operations and related legal obligations.

Service Providers and Partners

We may share personal data with operational partners that support website hosting, communication tools, booking handling, payment processing, or similar administrative functions. These parties act on our instructions or under their own legal responsibilities and are expected to use the data only for the relevant service or legal purpose.

Service providers receive only the information needed to perform their assigned tasks.

Legal Disclosure

We may share personal data with authorities or other parties where disclosure is required by law, necessary to establish or defend legal claims, or needed to comply with lawful requests. We may also disclose information to protect our rights, customers, staff, or property where permitted by law.

Disclosure may occur when the law, a court order, or a public authority requires it.
01 · Collection

Data We Collect

We may process contact details, communication content, booking information, bicycle intake details, inspection findings, service notes, quote approvals, payment-related records, and limited technical data from website use. Where a bicycle is brought in for service, we may also record information needed to assess condition, confirm requested work, and document the service summary.

The data collected depends on the service inquiry, booking, or workshop visit.
02 · Sources

How We Collect Data

We receive data when you contact us, submit a form, book an appointment, bring in a bicycle, approve work, make payment, or communicate with the workshop. We may also generate internal records from inspection, repair, quality check, and collection activities, and we may receive limited technical data from the website and connected systems.

Most information comes directly from the customer or is created during the service process.
03 · Cookies

Cookie Types

We may use essential cookies to support security, page delivery, and form operation. Preference cookies may remember basic settings, and analytics cookies may help us understand how the site is used. Cookies may be session-based or persistent depending on their purpose and lifespan.

Cookie use is limited to standard website functions and basic measurement where enabled.
04 · Controls

Cookie Controls

Where cookies or similar technologies are used, you can manage them through browser settings and, where available, site controls. Essential cookies may be needed for basic operation, while preference or analytics cookies can usually be limited or disabled. Blocking certain cookies may reduce the functionality of forms or other website features.

Cookie choices can be adjusted in the browser, and some settings may affect site functions.
User Rights

Your Rights

Depending on your location and the applicable law, you may have rights to know what data we hold, correct inaccurate information, request deletion, object to certain processing, or ask for a copy of your data. Some requests may not be granted if we must keep the information for legal compliance or to document the service provided.

Available rights depend on the legal basis and the type of information involved.
Requests

How to Make a Request

To exercise a privacy right, we may ask for information needed to verify your identity and understand the request. We will assess the request, respond within the applicable legal timeframe, and explain any refusal or limitation where the law allows us to do so.

Requests are reviewed before action is taken to protect confidentiality and accuracy.
Data Retention

Data Retention

We retain personal data for the period needed to handle the inquiry, complete the service, document approvals and collection, and meet applicable legal or accounting obligations. When data is no longer needed, we delete it or anonymize it where feasible, subject to any required retention period.

Records are kept only for as long as needed for service, legal, or accounting purposes.
Policy Updates

Policy Updates

If we make material changes, we will update the policy text and may provide additional notice where appropriate. The version in effect is the one published on the website at the time of review, unless a different effective date is stated.

We may revise this policy when our processing practices or legal obligations change.
GDPR

GDPR Overview

Where GDPR applies, we process personal data on a lawful basis such as performance of a contract, compliance with legal obligations, legitimate interests, or consent where required. We limit processing to what is relevant for workshop operations, customer communication, recordkeeping, and website administration.

For individuals in the European Economic Area, the General Data Protection Regulation may apply to our processing of personal data.

This section is intended for users whose data is protected by GDPR rules.
GDPR aware

Your GDPR Rights

Where applicable, you may request access, rectification, erasure, restriction, objection, or data portability. You may also withdraw consent where processing relies on consent. We may need to keep certain information where required for legal, accounting, or service documentation purposes.

GDPR rights are handled through a verified request process and may be limited by law.