Last updated: June 2026
Privacy Policy
1. Who we are
Ryma is an electric vehicle charging platform operated in Albania. We act as the data controller for personal data collected through the Ryma mobile app and web dashboard. Contact us at [email protected].
2. What data we collect
- Account data: email address, account type, and a password we store only as a one-way hash — never the password itself.
- Vehicle data: make, model, battery level, and range you enter manually.
- Charging sessions: station used, start/end time, energy delivered, and cost per session.
- Payment data: wallet balance and transaction records. Card details are handled by our payment provider (POK) and never stored on Ryma servers.
- Location: your device's GPS coordinates when you open the map, used only to show nearby stations. We do not store or share your location history.
- Push notification tokens: a device token used to send you session alerts. You can opt out in your device settings at any time.
3. Why we use your data
- To operate your account and process charging sessions (contract performance).
- To send you booking confirmations and session completion alerts (legitimate interest).
- To calculate your environmental impact stats (CO₂ saved, green km) (legitimate interest).
- To comply with financial record-keeping obligations (legal obligation).
We do not use your data for advertising or sell it to third parties.
4. Data sharing
We share your data only with:
- POK — Albanian payment processor for wallet top-ups and session payments.
- Resend — email delivery service for transactional emails only.
- Expo — push notification delivery for session alerts.
- Railway — cloud infrastructure provider where the API and database are hosted.
All processors are bound by data processing agreements consistent with GDPR requirements.
5. Data retention
We retain your account and session data for 5 years after your last activity to meet financial record-keeping obligations. After account deletion, personal identifiers (email address, push token) are immediately anonymised. Billing records are retained in anonymised form.
6. Your rights
Under GDPR you have the right to:
- Access — request a copy of all data we hold about you.
- Rectification — correct inaccurate data.
- Erasure — delete your account and anonymise personal identifiers. You can do this directly in the app under Settings → Delete Account, or by emailing us.
- Portability — receive your data in a machine-readable format.
- Object — object to processing based on legitimate interest.
To exercise any of these rights, email [email protected]. We will respond within 30 days.
7. Cookies
The Ryma web app uses only strictly necessary cookies for authentication. The session cookie is httpOnly, so no script on the page can read it. We do not use analytics or advertising cookies.
8. Security
All data is transmitted over HTTPS. Database access is restricted to the Ryma API service. Payment data is never stored on our servers. Passwords are hashed with bcrypt and never stored in readable form. Sign-in is rate limited and repeated failures lock the account temporarily, and sessions use short-lived access tokens with refresh tokens that are rotated on every use and revoked if one is ever replayed.
9. Changes to this policy
We may update this policy to reflect changes in our practices or legal requirements. We will notify you by email before any material changes take effect.
10. Contact
For privacy questions or to exercise your rights: [email protected]