Privacy Policy
Ušen Horses app for riders (iOS) · Last updated: 6 September 2026
This Privacy Policy explains what personal data we process through the Ušen Horses mobile application for riders (the “App”), for what purposes, on what legal basis, and what your rights are under the General Data Protection Regulation (GDPR) and applicable local law.
The Ušen Horses Admin app, used by club staff, has a separate privacy policy.
1. Data controller
Ušen Horses
Privacy contact: podpora@horsesbooking.app
The App is intended for riders — the customers of an equestrian centre. In it you see your own sessions, sign-ups, hour balance and badges. You do not process data about other customers of the centre.
2. What data we process
2.1 Account and identity data
- Username, first and last name
- Contact details you can edit yourself: email address and phone number
- A profile photo, if you upload one (optional; you can remove it at any time)
- Data about your training kept by the club: session sign-ups, assigned horse, hour and package ledger, badges you earned and the trainer's notes attached to them
- A message to the trainer, when you write one while cancelling a session
2.2 Device and authentication data
- A randomly generated unique device identifier (created by the App on first use; it is not the hardware UDID), the activation key and a one-time login token (OTP)
- Device manufacturer, model and name
- This data is stored securely in the system Keychain and is used solely for device registration and secure sign-in
2.3 Biometrics
- You may use Face ID / Touch ID for quick sign-in. Biometric processing happens entirely on the device through Apple's system framework; we never receive, store or transmit biometric data.
2.4 Camera and photos
- Camera access is used only to scan the QR code during activation. We do not store camera images.
- A profile photo is chosen through the system photo picker; the App only accesses the image you select. An uploaded photo is stored with our hosting provider and is visible to you and to club staff.
2.5 Weather for sessions
- A session may show a weather forecast. For that, the coordinates of the club location are sent to Apple WeatherKit. The App does not access your device location and does not track you.
2.6 Usage, diagnostics and notification data
- Analytics (Firebase Analytics): anonymised usage events (e.g. screen views, signing up for a session), together with technical device data (model, OS version) and an app instance identifier. These events are not used for advertising and we do not track you across apps.
- Crash diagnostics (Firebase Crashlytics): error and crash reports used to improve stability.
- Push notifications (Firebase Cloud Messaging): a device token used to deliver notifications. You choose which types you receive in the App under Profile → Settings → Notifications.
- Remote configuration (Firebase Remote Config): app behaviour settings.
3. Purposes and legal bases
| Purpose | Legal basis (GDPR) |
| Running the App, sign-in and device registration | Performance of a contract / provision of the service (Art. 6(1)(b)) |
| Session sign-ups, hour ledger and badges | Performance of the contract between you and the club (Art. 6(1)(b)) |
| Security, abuse prevention, crash diagnostics | Legitimate interest (Art. 6(1)(f)) |
| Usage analytics for improvements | Legitimate interest (Art. 6(1)(f)) |
| Push notifications | Provision of the service / system-level consent (Art. 6(1)(a), (b)) |
4. Processors and third parties
We do not sell personal data. We use the following processors:
- Google Ireland Ltd. / Google LLC – Firebase (analytics, crash diagnostics, push notifications, remote configuration).
- Apple Inc. – push notification delivery (APNs), weather forecasts (WeatherKit) and app distribution.
- Oracle Corporation – Oracle Cloud Infrastructure (OCI): hosting of the backend service and database holding business data. Servers are located in the Frankfurt data centre (Germany, EU).
5. International transfers
Some processors (e.g. Google) may process data outside the EU/EEA. Such transfers rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses.
6. Retention
We keep personal data only as long as necessary for the purposes for which it was collected, for the duration of your membership with the club, and in line with statutory retention periods. Device and sign-in data is kept until the device activation is revoked or you sign out.
7. Your rights
Under the GDPR you have the right to: access, rectification, erasure (“right to be forgotten”), restriction of processing, data portability, objection to processing, and withdrawal of consent (where processing is based on consent). To exercise your rights, contact us at podpora@horsesbooking.app.
If you believe the processing infringes the law, you have the right to lodge a complaint with the supervisory authority — the Information Commissioner of the Republic of Slovenia (www.ip-rs.si).
8. Children
The App is not intended for independent use by children. Where a rider is a minor, the account and data are managed by the club within its business relationship with the legal guardian.
9. Security
We use appropriate technical and organisational measures: encrypted connections (HTTPS/TLS), secure storage of sensitive keys in the system Keychain, and device authentication mechanisms.
10. Changes to this policy
We may update this policy from time to time. The latest version is always published on this page; the date of the last update is shown at the top.
11. Contact
For questions about this policy or about the processing of personal data, contact us at podpora@horsesbooking.app.