Privacy Policy
1. Introduction
1.1. We are Gobao Electronic Technology GmbH(the “GOBAO”). We respect your privacy and private life, but sometimes we need your Personal Data. In this privacy policy, we explain which data we use and how we save, protect and process these data. This privacy policy applies to the use of:
- Our website www.gobao-ebike.com (the “Website”)
- The services that we offer (the “Services”), for example, the diagnosing of bikes
- Our service tool
- Website, Services, APP and Service tool collectively referred to as our “Platform”
1.2. We comply with the EU General Data Protection Regulation and other national data protection laws of the member states as well as any other relevant legislation.
2. Responsible party
Gobao Electronic Technology GmbH
Emil-von-Behring-Straße 6, 63128 Dietzenbach
Email: info@gobao-ebike.com
Tel: +49 (0) 8142 / 654 5492
You can reach the data protection officer as follows:
DataCo GmbH (www.dataguard.com)
Sandstraße 33, 80335 München, Germany
Email: privacy@dataguard.com
3. The Limitation of Age
3.1. If you are younger than sixteen years old, you cannot use our Website, Services and App without the permission of your parents or legal guardian.
4. Type and scope of the data
4.1. To offer our Website, Services and App we process Personal Data and Non Personal Data. “Personal Data” means any information relating to an identified or identifiable natural person as defined in the relevant legislation. “Non- Personal Data” is information that is anonymous, aggregate, de-identified, or otherwise does not reveal your identity.
5. Lawful basis
5.1. We can collect and process your data at various times. For example, when you visit our Web site, create an account via our Web site, use our Services, install and use our App, Rides feature, or when you contact us. The lawful basis for our processing can be:
- The necessity for the performance of the contract between you and us
- Compliance with legal obligations
- Your consent
- Our legitimate interests or the legitimate interests of a third party
- A legal requirement to share Personal Data
6. What data do we collect, and process and how do we use your data?
6.1. When you use our Platform, we need the following contact data. We need these data for your interactions with GOBAO via digital/electronic tools such as email or telephone; for example, to process your order efficiently and correctly, to connect you to your bike, for pre and post-sale services, for the use of your account, to improve our services, for marketing purposes, and for any other business/commercial purposes:
- Your name
- Your phone number
- Your e-mail address
- Your IP-address
- Your username and password
- Your reference number
6.2. For some orders (for example, for our B2B partners) we also need:
- Company name
- Date of birth
- IBAN number
- Your shipping address
6.3. We may also collect and process the following Non-Personal Data if you use our Platform:
- The type of your browser
- The operating system that you use
- The internet service provider
- Website behaviour
6.4 Website Technology Stack and Processing Tools
Our official website is built on the open-source content management system WordPress, with all core data processing operations conducted on our self-hosted servers. The following technical components and plugins process visitor data as part of normal website operation:
6.4.1. Core Infrastructure
- Server-side technology: PHP server-side scripting, MySQL (MariaDB) relational database for data storage, Nginx/Apache web server for access delivery
- Transmission security: Full-site SSL/TLS encryption (HTTPS) is enabled to encrypt all data transmitted between your browser and our servers, including form submissions, cookie data and session information
- Front-end technology: HTML5, CSS3 and JavaScript (including jQuery and React libraries) are used for page rendering and interactive functionality
6.4.2. Core WordPress System
- Session handling: Temporary session IDs are stored in your browser to maintain form filling status and page interaction state. These session records are automatically destroyed when you close your browser
- Data storage: All website content, form submission records, cookie consent logs and privacy preference selections are stored in our internal MySQL database. No personal data is shared with third parties through the WordPress core system
6.4.3. Contact Form 7 (Form Collection Tool)
- We use the Contact Form 7 plugin to operate our website inquiry forms. The following personal data is collected when you submit a form: first name, last name, email address, phone number, company name and message content
- Mandatory consent mechanism: All forms include a mandatory privacy policy acknowledgement checkbox. No form can be submitted until you explicitly confirm your consent to data processing. Your consent status is permanently stored in our compliance log
- Submission records: Each form submission is logged with your IP address, submission timestamp, all submitted content and privacy consent status. Logs are retained for business correspondence and compliance audit purposes and can be exported in CSV format for data subject request handling
- Data usage: Submitted form data is used exclusively for business inquiry response, customer follow-up and product quotation purposes. We do not share, sell or disclose form data to any unauthorized third party
6.4.4. Speed Optimizer (Performance & Security Tool)
- Caching functionality: We use Nginx Dynamic Caching and browser local caching to store static page content, images, CSS and JavaScript files to improve page loading speed and reduce database queries. Cached content does not contain personally identifiable information and is automatically cleared when page content is updated or a form is submitted
- Web application firewall: The built-in firewall feature blocks malicious crawlers, attack traffic and unauthorized access attempts. Malicious IP addresses are logged exclusively for security protection purposes and are never used for marketing or user profiling
6.4.5. Real Cookie Banner (Cookie Consent Management)
- We use the Real Cookie Banner plugin to manage cookie consent in compliance with EU ePrivacy requirements. The tool records your cookie preference selection (acceptance/rejection of analytical/functional cookies) and stores the consent status as a necessary cookie for 12 months
- The tool enables granular cookie category controls, allowing you to adjust your cookie preferences at any time through the website consent banner
6.4.6. Polylang (Multilingual Functionality)
- The Polylang plugin provides multi-language switching functionality. A necessary cookie is stored to record your selected language preference to maintain consistent language display across your visit
6.4.7. Additional Operational Plugins
The following plugins support normal website operation and may access stored website data as part of their functionality, but do not independently collect or share personal data with external parties:
- All-in-One WP Migration: Used for website backup, migration and full data export. The tool reads full database, media file and user information exclusively for internal backup and disaster recovery purposes
- Code Snippets: Used to deploy custom PHP/JS code for website functionality customization. No personal data is collected or shared by this tool
- Easy WP SMTP: Used to deliver form submission notifications and service emails via SMTP protocol. The tool stores only email service configuration and send/receive logs for email delivery troubleshooting
- Yoast SEO: Used for search engine optimization and sitemap generation. The tool sets SEO-related cookies to support page indexing optimization and does not collect personal user identification data
- Unlimited Elements: Used as a front-end page builder component library. The tool stores page layout preferences in local browser storage to improve your browsing experience
- WP-Optimize: Used for database cleanup and cache optimization. The tool processes existing visitor data tables in our database exclusively for performance optimization and does not collect additional personal data
7. B2B Customer Contact Privacy Notice
7.1. Scope and Application. This section applies to the personal data of individuals who act as authorized contacts for our business-to-business (“B2B”) customers, partners, suppliers, distributors, and other corporate entities (collectively, “B2B Contacts”). B2B Contacts may include, without limitation, procurement managers, technical liaisons, account managers, authorized administrators, engineering contacts, and other personnel designated by a B2B customer to communicate or interact with GOBAO.
7.2. Categories of Personal Data We Collect. In connection with our B2B relationships, we may collect and process the following personal data of B2B Contacts:
- Full name and job title or position
- Business email address and business telephone number
- Company name, company address, and other company identification details
- Account credentials (username and password) for any GOBAO portal, platform, or service to which the B2B Contact has been granted access
- Communication records, including emails, meeting notes, telephone logs, and correspondence between the B2B Contact and GOBAO personnel
- Order and transaction data associated with the B2B Contact’s company, including purchase order references, shipping details, and billing contact information
- IP address and device information when the B2B Contact accesses our Website, APP, or Service tool
- Any other personal data voluntarily provided by the B2B Contact in the course of the business relationship
7.3. Purposes of Processing. We process B2B Contact personal data for the following purposes:
- To perform and administer contracts between GOBAO and the B2B Contact’s company, including order processing, delivery, invoicing, and customer support
- To communicate with the B2B Contact regarding business inquiries, product information, quotations, technical support, and after-sales service
- To create and manage user accounts for GOBAO platforms, including the Gobao APP Admin Portal where access has been authorized
- To maintain business relationship records and account management
- To comply with legal obligations, including tax, accounting, and record-keeping requirements
- To protect our legitimate interests, including fraud prevention, security, and the enforcement of our legal rights
- With the B2B Contact’s consent, to send marketing communications about GOBAO products, services, and events
7.4. Lawful Basis. The lawful bases for processing B2B Contact personal data are:
- Performance of a contract (Article 6(1)(b) GDPR), where processing is necessary for the performance of a contract to which the B2B Contact’s company is a party, or for the taking of steps at the request of the B2B Contact’s company prior to entering into a contract
- Compliance with a legal obligation (Article 6(1)(c) GDPR), where processing is necessary for compliance with legal obligations to which GOBAO is subject
- Legitimate interests (Article 6(1)(f) GDPR), where processing is necessary for the purposes of the legitimate interests pursued by GOBAO or a third party, provided that such interests are not overridden by the B2B Contact’s rights and freedoms
- Consent (Article 6(1)(a) GDPR), where the B2B Contact has given explicit consent for specific processing activities, such as marketing communications
7.5. Recipients of Personal Data. B2B Contact personal data may be shared with:
- GOBAO affiliates and subsidiaries within our corporate group, where necessary for the administration of the business relationship
- Service providers and processors who assist us in operating our business, including IT service providers, cloud hosting providers, payment processors, and customer relationship management (CRM) platforms
- Professional advisors, including lawyers, accountants, and auditors, where necessary for the provision of their services
- Competent authorities, where required by law or in connection with legal proceedings
- Any other recipient with the B2B Contact’s explicit consent
7.6. Data Retention. We retain B2B Contact personal data for as long as necessary to fulfil the purposes for which it was collected, including:
- The duration of the business relationship with the B2B Contact’s company
- Any statutory retention periods applicable to tax, accounting, and commercial records
- Such additional period as may be necessary to establish, exercise, or defend legal claims
- Upon expiry of the applicable retention period, personal data is securely deleted or anonymised
7.7. B2B Contact Rights. B2B Contacts have the rights set out in Section 17 (Your rights under GDPR) of this privacy policy, including the right to access, correct, erase, restrict processing, data portability, object to processing, and withdraw consent. To exercise these rights, B2B Contacts may contact us using the details in Section 20 (Contact information).
7.8. Note on the B2B Customer’s Role. B2B Contacts should note that their employer or company may also act as an independent data controller for the personal data it provides to GOBAO. Questions about the company’s internal data handling practices should be directed to the company’s own data protection officer or appropriate representative.
8. Gobao APP Admin Portal Privacy Policy
8.1. Scope. This section applies to the personal data processed through the Gobao APP Admin Portal (the “Admin Portal”), a web-based management interface to which certain authorized B2B customers and their designated personnel are granted access. The Admin Portal enables authorized users to manage user accounts, view device and diagnostic data, monitor orders, configure settings, and perform other administrative functions related to their company’s use of GOBAO products and services.
8.2. Eligibility and Authorization. Access to the Admin Portal is limited to:
- Personnel of B2B customers who have been explicitly granted access by GOBAO
- Each authorized user must be designated by the B2B customer’s authorized representative and must register an individual account
- GOBAO reserves the right to grant, restrict, or revoke Admin Portal access at any time, with or without cause
8.3. Categories of Personal Data Processed. Through the Admin Portal, we process the following categories of personal data:
- Account Information: full name, business email address, job title, company name, username, password (stored in encrypted form), and account role or permissions
- Authentication and Access Data: login timestamps, IP addresses, device identifiers, browser type, session duration, and failed login attempts
- Activity Logs: records of actions performed within the Admin Portal, including pages visited, functions accessed, data viewed or exported, configuration changes made, and timestamps of such activities
- Device and Operational Data: information about electric bikes and devices associated with the B2B customer’s account, including device identifiers, serial numbers, firmware versions, diagnostic data, battery status, and location data (where applicable and enabled)
- User-Generated Content: any data, notes, configurations, or other content that the authorized user inputs or uploads through the Admin Portal
- Communication Data: records of support requests, messages, or notifications exchanged through the Admin Portal
8.4. Purposes of Processing. We process personal data through the Admin Portal for the following purposes:
- To provide, operate, and maintain the Admin Portal and its features
- To authenticate authorized users and manage access control, including role-based permissions
- To enable B2B customers to manage their accounts, devices, orders, and related administrative functions
- To ensure the security and integrity of the Admin Portal, including fraud detection, unauthorized access prevention, and security incident response
- To maintain audit logs for compliance, accountability, and troubleshooting purposes
- To improve and optimize the Admin Portal’s functionality, performance, and user experience
- To provide customer support and technical assistance related to the Admin Portal
- To comply with applicable legal obligations, including record-keeping and audit requirements
8.5. Lawful Basis. The lawful bases for processing personal data through the Admin Portal are:
- Performance of a contract (Article 6(1)(b) GDPR), where processing is necessary to provide the Admin Portal as part of the contractual relationship with the B2B customer
- Legitimate interests (Article 6(1)(f) GDPR), including ensuring the security of the Admin Portal, maintaining audit trails, and improving our services
- Compliance with a legal obligation (Article 6(1)(c) GDPR), where processing is necessary to meet legal or regulatory requirements
- Consent (Article 6(1)(a) GDPR), where specific processing activities require the individual’s explicit consent
8.6. Data Security. We implement appropriate technical and organizational measures to protect personal data processed through the Admin Portal, including:
- Encryption of data in transit (TLS/SSL) and at rest
- Secure password storage using industry-standard hashing algorithms
- Role-based access control (RBAC) to ensure users only access data and functions appropriate to their authorized role
- Multi-factor authentication (MFA) where available and enabled
- Comprehensive activity logging and monitoring for security and audit purposes
- Regular security assessments, vulnerability scanning, and penetration testing
- Strict internal access controls, with access limited to authorized GOBAO personnel on a need-to-know basis
8.7. Data Retention.
- Account information is retained for the duration of the authorized user’s Admin Portal access and for a reasonable period thereafter to handle any outstanding matters
- Authentication and access logs are retained for a minimum of 12 months for security monitoring and incident investigation purposes
- Activity logs are retained for a minimum of 24 months for audit, compliance, and troubleshooting purposes
- Device and operational data is retained in accordance with the applicable agreement with the B2B customer and applicable legal requirements
- Upon expiry of the applicable retention period, personal data is securely deleted or anonymised, unless further retention is required by law
8.8. User Responsibilities. Authorized users of the Admin Portal are responsible for:
- Maintaining the confidentiality of their account credentials and not sharing them with any third party
- Immediately notifying GOBAO of any suspected unauthorized use of their account or any other security breach
- Ensuring that all personal data they input or manage through the Admin Portal is accurate, up-to-date, and processed in compliance with applicable data protection laws
- Using the Admin Portal only for authorized business purposes and in accordance with the applicable terms of use
8.9. Data Subject Rights. Authorized users and other data subjects whose personal data is processed through the Admin Portal have the rights set out in Section 17 (Your rights under GDPR) of this privacy policy. To exercise these rights, please contact us using the details in Section 20 (Contact information). Please note that certain data processed through the Admin Portal may be the responsibility of the B2B customer as a separate data controller; in such cases, we will direct the request to the appropriate controller where required by law.
8.10. Changes to Admin Portal. GOBAO may modify, suspend, or discontinue the Admin Portal or any of its features at any time. We will provide reasonable advance notice of material changes where practicable. Continued use of the Admin Portal after changes constitutes acceptance of the updated terms.
9. Market research
9.1. We may invite you to participate in market research. In that case, we shall use your data for that market research. We use that statistical data pseudonymised for GOBAO. We do not sell, trade or share your answers with others or make them publicly available. In addition, your answers are not connected to your e-mail address.
10. Third Party Features
We may allow you to connect our Services to a third party service or offer our Services through a third party service (“Third Party Features”). If you use a Third Party Feature, both we and the applicable third party may have access to and use information associated with your use of the Third Party Feature, and you should carefully review the third party’s privacy policy and terms of use. Some examples of Third Party Features include the following:
10.1. Logging-In. You may choose to log in, create an account or enhance your profile on the Services through the Third Parties (eg. Facebook, Twitter, Instagram, etc.) Connect feature. By doing this, you are asking Facebook to send us certain information from your Facebook profile, and you authorize us to collect, store, and use in accordance with this Privacy Policy any and all information available to us through the Facebook interface.
10.2. Brand Pages. We offer our content on social networks such as a Facebook, Twitter, and Instagram. Any information you provide to us when you engage with our content (such as through our brand page) is treated in accordance with this Privacy Policy. Also, if you publicly reference our Services on a third party service (e.g., by using a hashtag associated with us in a tweet or post), we may use your reference on or in connection with our Service.
10.3. YouTube. We use YouTube API Services in relation to certain content that we offer. By using the Services, you agree to be bound by the by YouTube’s Terms of Service, YouTube API Services Terms of Service, and Google’s Privacy Policy. You can modify your Google privacy and security settings at https://myaccount.google.com.
We take no responsibility for the content or privacy practices of any third parties. We encourage you to carefully review the privacy policies of any third-party services you access.
11. Security
11.1. We follow reasonable procedures to protect personal data from unauthorized access and misuse.
11.2. We use appropriate business systems and procedures to protect and safeguard the Personal Data you give us. We also use security procedures, technical and physical restrictions, for accessing and using Personal Data on our servers. Only authorized personnel are permitted to access Personal Data in the course of their work.
12. Storage duration
We will not retain your Personal Data longer than is legally allowed, and only as long as is necessary to enable you to use our Platform, including maintaining the online user account if created, to comply with applicable laws, resolve disputes with any parties and otherwise as necessary to allow us to conduct our business, including to detect and prevent fraud or other illegal activities.
13. Processors and other business partners
13.1. We may share your Personal Data with Processors, within the meaning of the Relevant Legislation. We may also share Personal Data with third parties who are not processors, as per contractual obligation, for example, other Controllers who provide services connected to the use of our Platform. With these parties, we make clear agreements about the use and protection of Personal Data. We may share your Personal Data for example, with IT service providers, marketing analytics, advertising platforms, payment platforms, cloud based data warehousing, lease companies and consumer review platforms. They will, for example, store and visualize data, process transactions, and perform marketing activities.
13.2. Others, for legal reasons
We may also share data with GOBAO affiliates, subsidiaries, and partners, for legal reasons or in connection with claims or disputes. We may also share Personal Data if we believe it is required by applicable law, regulation, operating license or agreement, legal process or governmental request, or where the disclosure is otherwise appropriate due to safety or similar concerns.
13.3. Others, with your consent
We may ask for your voluntary participation in online or offline communication about GOBAO, for marketing or informational purposes.
14. Transfer
In principle, the Personal Data that we collect from you is stored within the European Economic Area (“EEA”). However, In some cases, your personal data may be processed outside your country of residence when remote access from China is involved during maintenance and operation. Regardless of where your personal data is processed, we apply the same protections as described in this Policy. We transfer your personal data in accordance with the legal frameworks required by different jurisdictions. Recipients of your personal data are required to adhere to the same level of privacy safeguards as mandated by applicable data protection laws. These include, but are not limited to:
a. Adequacy decisions, such as:
- European Commission adequacy decisions
- UK adequacy regulations
b. Agreements, such as:
- EEA Standard Contractual Clauses (SCCs)
- UK International Data Transfer Agreement (IDTA)
15. Hyperlinks
On our website, there are hyperlinks to websites of other suppliers. Upon clicking on these hyperlinks, you are passed from our website directly onto the website of the other suppliers. You recognise this, among other things, by the change of the URL. We can assume no responsibility for the confidential treatment of your data on these websites of third parties, since we have no influence over whether these companies adhere to data protection provisions. Please learn about the treatment of your personal data by these companies directly on these websites.
16. Use of cookies and Local Storage
16.1. General Information
Our website uses cookies and similar local storage technologies (including browser local storage, session storage and cached assets) to ensure basic website functionality, improve your browsing experience and analyze website performance. In this policy, all such client-side storage technologies are collectively referred to as “Cookies”. Cookies are small text files stored on your device or browser when you visit a website. On your subsequent visits, this data is sent back to our server to recognize your device and retain your preferences. We classify cookies into three categories based on their purpose and necessity. You can manage your cookie preferences at any time through the cookie consent banner on our website, or adjust your browser settings to block or delete cookies. Please note that blocking necessary cookies may cause some core website functions to fail.
16.2. Strictly Necessary Cookies
These cookies are essential for the basic operation of the website and cannot be disabled. They are set in response to actions you take on the site, such as submitting a form or setting your privacy preferences. You can set your browser to block or alert you about these cookies, but some parts of the site will not work properly if you do so. These cookies do not store any personally identifiable information used for marketing or analytics. Strictly necessary cookies used on this website include:
- Cookie consent preference cookie: Stores your selection of cookie preferences (acceptance/rejection of optional cookie categories). Retention period: 12 months
16.3. Functional Cookies (Opt-in)
These cookies enable enhanced functionality and personalized website experience. They are set only if you explicitly grant consent through the cookie banner. If you do not allow these cookies, some or all of these additional functions may not operate properly. Functional cookies and local storage items include:
- Language preference cookie (Polylang): Polylang is a multilingual system for WordPress websites. The cookies store the language of the user and can redirect the user to the version of the website that matches with the language of the browser of the user. Retention period: 1 year
- Google Maps: Google Maps displays maps on the website as iframe or via JavaScript directly embedded as part of the website. No cookies in the technical sense are set on the client of the user, but technical and personal data such as the IP address will be transmitted from the client to the server of the service provider to make the use of the service possible
16.4. Cookie Management You can change or withdraw your cookie consent at any time by clicking the cookie settings icon at the bottom of the website. You may also configure your browser to block cookies, delete existing cookies or notify you when cookies are being set. Please refer to your browser’s help documentation for specific operation instructions. Please note that disabling certain cookies may affect the normal use of some website functions
17. Your rights under GDPR
17.1. You have the following rights:
- According to Article 15 GDPR, you can request information about your personal data processed by us. In particular, you can request information about the processing purposes, the categories of the personal data, the categories of recipients, to whom your data were or are being disclosed, the planned storage duration, the existence of a right to correction, erasure, limitation of the processing, or objection, the existence of a right of complaint, the origin of your data, if the latter were not collected by us, concerning the transmission to third countries or to international organisations as well as concerning the existence of an automated decision-making including profiling and possibly meaningful information concerning the details thereof
- According to Article 16 GDPR, you can immediately request the correction of your incorrect personal data or completion of your personal data stored with us
- According to Article 17 GDPR, you can request the erasure of your personal data stored with us, if the processing is not necessary for the exercise of the right to free expression of opinion and information, for fulfilling a legal obligation, for reasons of public interest, or for assertions, exercise, or defense of legal claims
- According to Article 18 GDPR, you can request the limitation of the processing of your personal data, if you contest the correctness of the data, the processing is illegal, we no longer need the data, and you deny the erasure thereof because you need these for assertion, exercise, or defense of legal claims. The right pursuant to Article 18 GDPR is also available to you if you have lodged an objection to the processing according to Article 21 GDPR
- According to Article 20 GDPR, you can request to obtain your personal data, which you have provided to us, in a structured, regular, and machine-readable format or you can request the transmission to another controller
- According to Article 7 paragraph 3 GDPR, you can revoke the consent that you once granted to us at any time. The result of this is that, in the future, we may no longer continue the data processing based on such consent
- According to Article 77 GDPR, you have the right to lodge a complaint with a supervisory authority. As a rule, you can contact the supervisory authority of your usual place of residence, your workplace, or your company headquarters for this
18. Right to object
In the case of the processing of your personal data on the basis of justified interests, according to Article 6, paragraph 1, sentence 1, (f) GDPR you have the right, according to Article 21 GDPR, to lodge an objection against the processing of your personal data, if there are grounds for this, which result from your particular situation or the objection is directed against direct advertising. In the case of direct advertising, you have a general right to object, which shall be implemented by us without indication of a particular situation.
19. Update to this notice
19.1. This privacy policy is currently valid in the version of: July 2026.
19.2. Since changes in laws or changes in our internal company procedures may make amendments to this privacy policy necessary, we ask you to read through this privacy policy on a regular basis. The privacy policy can be called upon the data protection navigation area of our website and app, and it can be stored and printed out at any time.
19.3. After such notice, the use of our services by users in countries outside the European Union will be understood as consent to the updates to the extent permitted by law.
20. Contact information
If you have further questions regarding this privacy policy, please contact us via Email to: service@gobao-ebike.com.