PRIVACY
In force 24 August 2026
This site does two things with data. It takes an email address for a waitlist, and it counts visits if you let it. That is the whole of it. The rest of this page is the detail.
Who holds it
Ride Sideways is a sole trader registered in Poland: dotCode Michał Mańko, NIP 5372405173, ul. Kasprowicza 15, 21-500 Biała Podlaska. That business is the data controller for this site, which is the formal way of saying it decides what gets collected here and why.
Write to hello@ride-sideways.com about anything on this page. The postal address above works too, and is slower.
There is no data protection officer. Nothing here runs at the scale that requires one.
What is collected
An email address, if you type one into the waitlist field. That field is the whole form. No name, no country, no phone number, and nothing inferred from the address itself.
Analytics about your visit, but only after you press ALLOW. That covers which pages loaded and for how long, the device and browser, an approximate location worked out from the IP address, and whether you arrived from a link, a search or the address bar.
An access log, which happens either way. Every web server keeps one. The hosting platform records the IP address, the time, the file requested and the browser string, because that is what serving a page involves. It is not joined to the waitlist or to the analytics.
The form also carries a hidden field named company, there to catch bots. If anything fills it, the submission is dropped in the browser and never sent. Nothing typed into it is stored anywhere.
Why, and what makes it lawful
The email address is there for one thing: a message when the first run goes on sale. Not a newsletter. Not a schedule of updates. One email, when there is one to send. The confirmation described below is the only other thing that ever arrives.
The basis for that is your consent, article 6(1)(a) of the GDPR. Polish law asks for the same thing from the other direction, since the Electronic Communications Law of 2024 requires consent before marketing reaches an address (art. 398). The list is double opt-in: typing the address in only starts it, Klaviyo sends a confirmation email, and the address joins the list when the link in that email is clicked. An address that is never confirmed never joins. Nothing on the site is withheld if you skip the form.
Analytics answers a narrower question: how many people opened the page, and how far down they got. Consent again, and the same law requires consent before anything is written to or read from your device (art. 399).
The access log is the exception. Its basis is legitimate interest, article 6(1)(f), and the interest is keeping the site up and dealing with abuse. A server that keeps no log cannot be debugged and cannot be defended.
Who else it reaches
Three companies, each doing one job.
- Klaviyo Inc., in the United States. Holds the waitlist and sends the email. The signup posts from your browser straight to Klaviyo, so what arrives there is the address, a label reading Ride Sideways waitlist, and the IP address and browser string that any direct request carries.
- Google LLC, in the United States. Runs the analytics, and only after ALLOW.
- Microsoft Corporation. Azure hosts the site, serves the page and keeps the access log.
All three are processors. They act on instruction and are not free to use any of it for their own ends. Nothing is sold, rented or traded, and no advertising network runs on this site.
Where it goes
Klaviyo, Google and Microsoft are all American companies, so all three can hold data outside the EU.
The cover for that is the EU-US Data Privacy Framework, the adequacy decision the European Commission adopted in July 2023. All three are certified under it, and an adequacy decision is what makes the transfer lawful without anything bolted on top. Klaviyo and Microsoft sign the Standard Contractual Clauses as well, so a second mechanism sits underneath the first.
The framework was challenged and survived: the General Court dismissed the case in September 2025, and an appeal is pending at the Court of Justice. Its two predecessors were both struck down. If this one goes the same way, this section changes, and so does the arrangement it describes.
Cookies, and what sits in your browser
Nothing is stored until you choose. The analytics tag is not in the page markup at all. A script injects it after ALLOW and never otherwise, so DENY is not a request that something stops. There is nothing to stop.
After ALLOW, Google Analytics sets two cookies.
- _ga
- A random identifier for the browser. Expires after two years.
- _ga_PCVG4ZQKN7
- Session state for this analytics property. Expires after two years.
Press DENY and both are deleted if they were ever set, and Google's own opt-out flag is switched on for this browser.
Your choice is kept separately, in local storage under rs-consent. That is not a cookie, it is never sent anywhere, and it stays on the machine you chose on. If the set of trackers ever changes, that record stops counting and the banner asks again, because consent given for one thing does not cover something that did not exist when you gave it.
Change your mind from Cookies at the bottom of any page.
How long it is kept
The email address stays on the list until you take it off. There is no timer on it and no automatic clear-out. Every email carries an unsubscribe link, and asking by email works just as well.
Analytics is set to two months. After that, Google deletes the visit-level and user-level records. Aggregate counts survive, with nobody identifiable left in them.
The access log belongs to the hosting platform rather than to Ride Sideways, so no fixed period can honestly be quoted for it. The GDPR allows the criteria instead of a number where that is the case, and the criteria are these: it lives as long as Azure keeps it to run and protect the service, it is not exported, and it is not read here for anything beyond faults and abuse.
What you can ask for
The GDPR gives you the following, and using any of them is free.
- A copy of what is held about you.
- Correction of anything wrong.
- Deletion.
- Restriction, which parks the processing while something is disputed.
- A portable copy, in a format you can take elsewhere.
- Objection to the access log, the one thing here running on legitimate interest rather than consent.
Ask at hello@ride-sideways.com. The GDPR allows a month to answer. A list this small will not need one.
No decision here is made automatically about you, and nobody is profiled or scored. There is a list, and a visit counter.
Changing your mind
Consent can be withdrawn whenever you want, and withdrawing has to be as easy as giving it was. Unsubscribe from any email, or press Cookies at the foot of the page and choose DENY.
Withdrawal works forwards. It stops the processing from that point. It does not make what happened before it unlawful.
Complaining
If something here is wrong and the answer you get is not good enough, the Polish supervisory authority takes complaints.
Prezes Urzędu Ochrony Danych Osobowych ul. Stanisława Moniuszki 1A 00-014 Warszawa uodo.gov.pl
You do not have to raise it here first. If you live in another EU country, your own national authority will take the complaint too.
Changes to this page
This page changes when what it describes changes, and not otherwise. The date at the top is the version. If a change affects something you consented to, the banner comes back and asks again rather than treating the old answer as still good.