§
Legal
Privacy policy
Notes on the actual use of data on nbnl.de · Last updated September 2026
1 · Controller
Tobias Kurig
Isarweg 1

85774 Unterföhring

Deutschland
Contact
Data protection · Access, erasure, objection
datenschutz@nbnl.de
Section 2
Scope of this policy

This privacy policy describes the data processing currently carried out on nbnl.de (front end, associated APIs and functional modules such as the catalogue, game, Tour Buddy, advisor, blog, travel, accident reports, Best Routes, “Hot or Not”, Garage as well as the community with its community stream and public member profiles).

Section 3
Hosting

This website is hosted by IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. The servers are located in Germany. A data processing agreement is in place with IONOS.

When the website is accessed, technically necessary data are processed (in particular IP address, time of access, URL requested, HTTP status code, volume of data transferred, user agent, referrer) in order to ensure secure and stable operation and to be able to fend off attacks. IP-related server logs are deleted or anonymised after 14 days at the latest.

Legal basisArt. 6(1)(f) GDPR (legitimate interest in the secure and stable operation of the website).
Section 4
User account and login

For registration and login we process in particular the biker name, e-mail address and password. Passwords are stored hashed on the server. On successful login a session cookie is set.

  • Cookie: nbnl_auth_session (HTTP-only, session management)
  • Account status (e.g. Freemium/Premium) for unlocking features
  • Password reset: on request, a time-limited token is generated and delivered by e-mail. The e-mail address is used once for delivery in this context.
  • Change of e-mail address: a confirmation token is sent to the new address; the change takes effect only after confirmation.
  • API key (MCP key): registered users can generate and manage a personal API key. It is stored hashed in the database.
  • Optional home address: in the account settings, users may voluntarily store a home address or home location (e.g. as a starting point for route planning). The entry can be changed or deleted at any time.
  • Sign-in via third parties (where offered): when signing in via Google or Apple (OAuth/Sign-In), we receive from the respective provider the data required to create the account (in particular the e-mail address and display name). A short-lived OAuth state cookie (approx. 15 minutes) is set. The privacy notices of Google or Apple apply in addition.
  • Login log: for every login we store the time, the IP address and the browser identifier (user agent) — to secure the account and to detect abusive logins.
  • Country code: from the login IP we determine the country once (only the two-letter country code, e.g. DE) and store it with the login log. It is determined exclusively on our own server using a locally held database; your IP address is not transmitted to anyone for this purpose. We use it purely internally, to see which countries NBNL is used from. It is not a nationality — we do not collect that — and the country code is neither displayed publicly nor used for personalisation, pricing or access restrictions.
Legal basisArt. 6(1)(b) GDPR (contract/user account); for the login log and the country code additionally Art. 6(1)(f) GDPR (legitimate interest in security and in rough, internal usage statistics).
Section 4a
Profile picture upload (Premium feature)

Instead of a preset avatar, Premium users can upload a photo of their own as a profile picture. The image is cropped square to 400×400 pixels on the server, converted to WebP and stored in object storage (MinIO/S3-compatible). The image delivered contains no EXIF metadata.

  • Before optimisation, the uploaded original file is read for EXIF metadata (e.g. camera model, date taken, exposure) as well as any GPS coordinates and these are stored internally in your account. These data are not displayed publicly and are not shown in the user front end; they serve exclusively internal evaluation, moderation and quality purposes.
  • Please note: many smartphones store GPS data in the image file by default. If you do not want this, deactivate location capture for the camera or remove the EXIF data before uploading (e.g. via your device’s photo settings).
  • “Delete photo” in the account settings removes the image from your profile display. The associated image file and the EXIF/GPS data read from it remain in our object storage or database until a new upload or a complete deletion of the account. You can request early, complete deletion of the EXIF/GPS data or of the image file at any time at datenschutz@nbnl.de anfordern.
  • APIs: /api/user/profile/image (POST/DELETE)
Legal basisArt. 6(1)(b) GDPR (contractual provision of the Premium feature) as well as Art. 6(1)(f) GDPR (legitimate interest in internal quality assurance and abuse prevention).
Section 5
Feature data: Tour Buddy, advisor, game, navigator

If you use the questionnaire (Tour Buddy), the advisor or the card game, the content and results you enter are processed in order to provide the feature technically (e.g. match results, recommendations, game evaluation).

  • Local identifier in the browser: localStorage nbnl_buddy_id
  • Buddy questionnaire answers: for logged-in users, the answers are stored on the server in the user account (column buddy_answers) so that they are available across devices.
  • Navigator settings: preferences for the route navigator are stored on the server in the user account.
  • APIs: /api/buddy/*, /api/berater/recommend, /api/spiel/public/*, /api/user/buddy-answers, /api/user/navigator-settings
Legal basisArt. 6(1)(b) GDPR (use of requested features) as well as Art. 6(1)(f) GDPR (operation and further development).
Section 5a
Emergency contacts

Users can optionally store up to three emergency contacts (name, telephone number, e-mail address, relationship). These data relate to third parties and are stored and processed exclusively at the user’s instigation.

  • Storage in the table user_emergency_contacts in the NBNL database
  • At the user’s request, a notification e-mail can be sent to a contact.
  • API: /api/user/notfallkontakte

Before you enter a person as an emergency contact, please obtain their consent and inform them about the storage. If, at your instigation, an emergency notification is sent to a contact, we point out to the recipient in the notification e-mail that they have been stored as an emergency contact, by whom, and about the right of access, objection and erasure vis-à-vis datenschutz@nbnl.de (Art. 14 GDPR).

Legal basisArt. 6(1)(b) GDPR (use of the feature) as well as Art. 6(1)(f) GDPR (safety feature for the benefit of the user and of the person stored).
Section 5b
Image uploads “Hot or Not”

In the community feature “Hot or Not”, logged-in users can upload photos of their own motorcycles. On upload, the image file and supplementary details (model assignment or free text, category and the confirmations given regarding the terms of use) are processed and stored under your account ID. Before being stored, the image is converted to WebP on the server, technically optimised and given an NBNL watermark.

  • EXIF metadata (e.g. camera model, date taken, GPS coordinates, where present) are read from the original and stored internally for quality and moderation purposes. GPS and EXIF data are not displayed publicly. Please note: many smartphones store GPS data in the image file by default. If you do not want this, deactivate location capture for the camera or remove the EXIF data before uploading. On request we will delete the EXIF data relating to your uploads early — send your request to datenschutz@nbnl.de.
  • Images are delivered via object storage (MinIO/S3-compatible). Delivery runs through a signed proxy; file paths contain a random component and cannot be guessed.
  • Other users can rate images that have been made public (“hot/not” swipes, favouriting). The swipe events are stored anonymously or under your account ID in order to prevent duplicate ratings and to compile leaderboards.
  • Using the “Report image” function, users can flag content for review. The reason and the account ID of the reporting person are stored in the process.
  • APIs: /api/hot-or-not/upload, /api/hot-or-not/swipe, /api/hot-or-not/report, /api/hot-or-not/favorites

You can delete your own uploads at any time via “My uploads”. In addition, the terms for image uploads.

Legal basisArt. 6(1)(b) GDPR (use of the requested feature) as well as Art. 6(1)(f) GDPR (moderation, protection against abuse).
Section 5c
GPS tracks and tour stages (Best Routes)

In the Best Routes area, logged-in users can submit routes of their own — either as an uploaded GPS file (GPX/KML/GeoJSON), as a recording from the nbnl riding mode or as a route they created themselves in the route planner. The following are processed in particular:

  • Geometry data of the route (sequence of points including elevation, movement data), calculated key figures (length, metres of ascent, difficulty) as well as descriptive texts and tags.
  • Images optionally uploaded with the route or videos linked to it (e.g. YouTube), including the associated confirmation of the image/media terms of use.
  • Account assignment of the upload, status (e.g. draft, under review, published) and moderation notes.
  • Likes, comments and track reports from other users, in each case under their account ID.
  • APIs: /api/strecken/tracks/*, /api/strecken/touren/*, /api/offroad/tracks/*

Depending on their level of detail and where they were recorded, GPS tracks may allow conclusions to be drawn about where a person has been. Submit only routes whose publication you deliberately want. Published tracks can be viewed, downloaded and exported into other applications by other users. In addition, the terms for track uploads.

Legal basisArt. 6(1)(b) GDPR.
Section 5e
Live View (optional location sharing)

The “Live View” feature is a purely voluntary, optional feature and has to be activated by the user. Once switched on, your own live location can be shared either with selected friends, a tour group (via a joining code) or through a time-limited public share link. What is transmitted in the process is in particular geo-coordinates, time stamps and optionally speed and direction. The location is recorded only while the feature is active; once it is stopped or the share token expires, live positions are deleted. Server logs relating to Live View are deleted or anonymised after a maximum of 24 hours.

  • Location is recorded only after express browser/device permission.
  • Visibility can be controlled by the user (friends, group, share link, deactivated).
  • APIs: /api/liveview/settings, /api/liveview/group/*, /api/liveview/friends, /api/liveview/share, /api/liveview/public
Legal basisArt. 6(1)(a) GDPR (consent through actively enabling the feature and granting browser location permission). Consent can be withdrawn at any time with effect for the future by switching the feature off.
Section 5f
Riding-mode recordings (optional)

In riding mode, the user can voluntarily record their own ride as a GPS track. The recording runs only if the user actively starts it. Geo-coordinates, time stamps, speed values and where applicable elevation values are captured, as well as calculated ride statistics (distance, duration, average).

  • Recordings are stored in the NBNL back end, assigned to the account.
  • Optional sharing via a time-limited share token is possible (public tracking view for passengers/family).
  • Recordings can be transferred into the personal “Best Routes” workflow or deleted at any time.
  • APIs: /api/fahrmodus/recordings/*, /api/fahrmodus/share/*, /api/fahrmodus/ride-stats

Note: GPS recordings may allow conclusions to be drawn about where a person has been — particularly if they start or end at a home or workplace. Record only what you deliberately want to store or share.

Legal basisArt. 6(1)(a) GDPR (consent through actively starting the recording and granting location permission) as well as Art. 6(1)(b) GDPR (use of the requested feature).
Section 5d
Garage (digital workshop)

In the personal Garage, logged-in users can manage their motorcycles and the associated data. The content is by default visible only to the respective user; selected bikes can optionally be marked as public or “for sale”.

  • Bike master data (model assignment, year of construction, colour, mileage, description)
  • Optional: registration number, insurance plate number, season period, purchase price, current value, sale price, roadworthiness test and insurance data
  • Bike photos (up to 3 photos in Freemium mode, up to 5 photos in Premium mode)
  • Maintenance, cost, damage and accident entries including notes, amounts and dates
  • Uploaded documents and manuals (e.g. invoices, registration documents, PDFs)
  • Results of the vehicle registration document scan as well as logged valuations including your feedback on them
  • Optional reminders (e.g. next service) including the associated notifications

Vehicle registration document scan: You can upload a photo of your vehicle registration certificate part I in order to fill the vehicle fields automatically. For this purpose the image is transmitted to our AI provider OpenAI in the USA (see section 11a); it is not stored permanently with us unless you expressly file it as a document in the record. Keeper data (name and address, fields C.1.1–C.1.3 and C.4c) are filtered out of the result and not stored. The uploaded image itself, however, is transmitted in full — cover the keeper block before taking the photo if you want to avoid this. The values read out are shown to you for confirmation before they are adopted.

Model-related evaluation: From the scan we additionally take the purely model-related details (e.g. key numbers, displacement, power, weights, tyre sizes) into our model catalogue, in order to improve the vehicle data for users of the same model. The vehicle identification number, registration number, date of first registration and keeper data do not feed into this. You can object to this evaluation at any time at datenschutz@nbnl.de widersprechen.

Manual search: If you use the search for manuals and maintenance details, we store the sources found with the respective motorcycle so that the same search does not have to be repeated. These entries are not shown to you and are not delivered to other users; they are deleted with the motorcycle or the account.

Data are recorded exclusively at the user’s instigation. Sensitive identifiers such as the registration number or the chassis number are stored only if they are actively entered. If a bike is made public or marked “for sale”, the registration number, insurance/contact details and other private notes are not displayed in the public view; only model master data, description, images and, where applicable, the sale price are published. You can edit or delete individual entries at any time.

Legal basisArt. 6(1)(b) GDPR (use of the requested feature).
Section 5j
Wallet (identity and driving licence documents)

In the Wallet, signed-in users can store copies of personal documents so they have them to hand while travelling. The contents are meant for that user alone: they are never shared, never published and at no point shown to other users.

  • Driving licence
  • Identity card or passport
  • Proof of insurance / Green Card and breakdown cover
  • Roadside assistance or club card
  • Your health insurance card, travel health cover or an emergency card
  • Vehicle documents belonging to a motorcycle in your garage
  • Other documents you choose to store
  • For each document additionally: label, type, an optional expiry date and the time it was stored

Health-related documents: A health insurance card, travel health cover or an emergency card may contain information that counts as health data (Art. 9(1) GDPR) — such as your insurer, blood group or allergies. You store such documents voluntarily and on your own initiative; we do not request them, do not evaluate them and draw no conclusions from them. The legal basis is your explicit consent under Art. 9(2)(a) GDPR, given when you store the document and revocable at any time with future effect by deleting it. The wallet works fully without these documents.

Details about other people: An emergency card usually names another person with their name and phone number. Only store such details if that person agrees. We use them solely to display them in your own wallet, match them against nothing and contact no one.

Lawfulness of the copy: Section 20(2) of the German Identity Card Act (PAuswG) expressly permits holders to make and use a copy of their own identity card. We do not request a copy of your ID, we do not verify identity with it, and we do not analyse the images.

Delivery: The files are held in a non-public storage area. A direct request without a signed-in session is refused; they are delivered solely through your own session and without intermediate caching.

Offline copy: At your explicit request, your browser stores copies of the documents on the device so they remain readable without a network connection. These copies are unencrypted on your device — this also applies to health-related documents and to details about other people. They are removed automatically when you sign out and can be deleted at any time via “Delete from device”. On a device you share with others, you should not enable the offline store.

Display lock: The Wallet locks itself after five minutes without activity. This locks the display in the interface; it is not a substitute for encrypting your files.

Wallet PIN (optional): You can additionally protect the Wallet with a four-digit PIN. The PIN is not stored in plain text but solely as a salted verification value (scrypt) combined with a server-side secret; we do not view, recover or disclose it. Once a PIN is set, the server only delivers your documents after it has been entered; after five consecutive wrong entries the Wallet is locked for 15 minutes. If you forget the PIN, we send, at your request, a single-use link valid for one hour to your account's email address, with which you set a new PIN in your signed-in session. We notify you by email whenever the PIN is set, changed or removed. Stored are the verification value, the number of failed attempts, any lock timestamp and, for reset links, their verification value, expiry and the requesting IP address; reset entries are no longer used after expiry.

You can delete each document individually. Deleting your account removes all entries and the associated files.

Legal basisArt. 6(1)(b) GDPR (use of the requested function); the offline copy additionally Art. 6(1)(a) GDPR (consent by actively switching it on); the IP address stored with a PIN reset additionally Art. 6(1)(f) GDPR (legitimate interest in preventing misuse).
Section 5g
Community: stream and posts

In the Community (/gemeinschaft) we operate a community stream in which logged-in members can publish their own posts and see the posts of others. What is processed in the process is in particular the post text (free text of up to 5,000 characters), up to four images, hashtags, an optional route reference, a repost (“share”) and, for travel posts, an embedded video link. Every post is assigned to your account ID and displayed with your displayed name and profile picture.

Automatic activities (only with your consent)

Alongside deliberately written posts, the stream can also show automatic activity notices (e.g. “has added a bike”, “has shared a route”, “has completed a tour”, “has passed the licence test”, “has received a badge”). These personal activity notices appear only if you have expressly activated the stream (feed_opt_in). Without this consent, the display of automatic activities is deactivated by default (data protection by default, Art. 25 GDPR).

Visibility and protection of names
  • You choose the visibility for each post: public, only for friends or in a group.
  • The community page is in principle accessible to visitors who are not logged in and to search engines as well. For them, however, the stream is partly accessible: Posts set to public are readable with text and images without an account and may be indexed by search engines. Posts for friends or for a group are not served. Comments and profile links remain reserved for signed-in members; they are removed server-side before delivery.
  • For visitors who are not logged in, your display name is always masked (e.g. “H***1”). The full nickname is visible only to signed-in members, and only if the owner has enabled display of their nickname in their profile settings. Masking happens server-side.
  • Certain personal system notices are — unlike the opt-in activity notices mentioned above — public by default displayed: that you have joined the community (“has joined the community”) and, exclusively in the case of public groups, that you have joined a group (“has joined the group …”). The legal basis is our legitimate interest in a visible, lively community (Art. 6(1)(f) GDPR). You can object to these notices at any time with effect for the future (system_posts_opt_out, Art. 21 GDPR) — the switch is in your profile settings. Posts in private or closed groups generate no public notice.
Images in posts
  • Post images are converted to WebP on the server and delivered via object storage (MinIO/S3-compatible, bucket community) by means of our signed image proxy. From the publicly displayed image, EXIF and GPS metadata removed.
  • Where the original file contains GPS coordinates, these are read out before cropping and separated on the server stored with the post (field image_geo). This location detail is not displayed in the stream and serve internal purposes. On request we will delete them early — send your request to datenschutz@nbnl.de.
  • Images created with AI are labelled accordingly for each post (field image_ai, EU AI Act).

To protect against spam and circumvention of contact channels, post texts are automatically pre-checked; links, domains, e-mail addresses, HTML code and social media handles are blocked in the process. Posts can be edited at any time (marked “edited”) or deleted. In addition, the community rules as well as the terms of use.

Legal basisArt. 6(1)(b) GDPR (use of the requested feature) for deliberately written posts; Art. 6(1)(a) GDPR (consent through activating the stream, feed_opt_in) for automatic activity notices; Art. 6(1)(f) GDPR (spam/abuse prevention, moderation, operation of the community).
Section 5h
Public member profile

Members can enable a public profile that is reachable at its own address (/profil/…). The profile is not public automatically — it becomes visible only once you actively make it public (profil_public). Depending on your settings, the following details may be displayed:

  • Display name (nickname), profile picture and optional header image
  • Profile text (bio) and rider characteristics/character tags (rider_traits)
  • Approximate location (city and region — not a precise address) as well as the member-since date
  • Motorcycles from the Garage that have been made public (model, year of construction, mileage, image, sale status where applicable)
  • Statistics (e.g. number of bikes, friends, tours, kilometres ridden, mountain passes, groups), image gallery from public posts, list of friends and groups as well as an activity chronicle

You control visibility in a granular way: each block (location, bike, statistics, bio, characteristics, friends, groups, activity, gallery) can be shown or hidden individually; the Garage release can be switched separately (garage_public). Visitors who are not logged in see — even where the profile is public — only a reduced basic view (masked name, profile picture, member since); bio, location, bike, statistics, gallery and contacts remain hidden from them. You change your settings under “My profile”; APIs: /api/user/profile, /api/user/share-settings, /api/user/profile/image, /api/user/profile/cover.

Legal basisArt. 6(1)(a) GDPR (consent through actively making the profile or individual blocks public) as well as Art. 6(1)(b) GDPR (provision of the requested profile).
Section 5i
Social interactions, groups and location details

Within the community, members can interact with one another. What is processed in the process is:

  • Follows (you follow other members) and Friendships (mutual confirmation) including status and time.
  • Reactions (emoji) and Comments on posts, in each case under your account ID.
  • Groups: memberships, posts created in groups as well as group events and acceptances/declines. When a new member joins, the group leadership is informed by e-mail (display name of the new member, group name; can be switched off, see section 10).
  • Blocking: You can block other members. We then store a relation “account A blocks account B” (account IDs, timestamp) in order to hide mutual content and interactions in the personal views; posts set to public are not affected. The blocked person is not notified of this.
  • In-app notifications (e.g. for a new reaction, a new comment, a shared post).

For weather and surroundings details in the community area you can voluntarily store a place name (weather_label) — either manually or through a one-off reverse geocoding call after location permission has been granted. For converting coordinates into a place name and for the associated weekend tour suggestion, we transmit the place name or the coordinates to the external service Open-Meteo (Open-Meteo, Switzerland). The place name can be changed or deleted at any time. A weekend tour suggestion generated from it is delivered exclusively privately to you.

Legal basisArt. 6(1)(b) GDPR (use of the social features) as well as Art. 6(1)(a) GDPR (consent where location is shared in order to determine the place name).
Section 5k
Notice and complaint function (Digital Services Act)

Since user-generated content is publicly disseminated via the community, we provide a notice procedure in accordance with Art. 16 of Regulation (EU) 2022/2065 (Digital Services Act, DSA). Using the “Report” function, logged-in members can flag posts, comments and activities they consider unlawful or in breach of the rules (reasons include hate speech, unauthorised advertising, harassment, spam, illegal content). What is stored in the process is the account ID of the reporting person, the element reported, the reason given and an optional note (table content_reports).

We examine incoming notices carefully, promptly and without arbitrary discrimination. The reporting person receives an acknowledgement of receipt and is informed of the outcome of the examination (Art. 16(5) DSA). If we decide on a measure (e.g. removal of a post or a block), the members concerned receive a statement of reasons (Art. 17 DSA). If we become aware of content indicating a serious criminal offence against the life or safety of persons, we inform the competent authorities (Art. 18 DSA). Further details are set out in the community rules. You will find the DSA point of contact in the legal notice.

Legal basisArt. 6(1)(c) GDPR (legal obligation under Art. 16 DSA) as well as Art. 6(1)(f) GDPR (protection of users and integrity of the platform).
Section 5l
Sharing routes and tour checklist

You can share saved routes with individual members, with all your friends or with one of your groups, publish them in the community stream or pass them on via a link. We store the route, your account ID, the target of the share (member, circle of friends or group) and the time. Recipients see the route name, its course and your display name according to the rules in section 5g. You can revoke shares and links at any time in the share window.

Sharing by e-mail: the route planner opens your own e-mail program with a prepared text and the share link. You send the message yourself from your mailbox; NBNL sends nothing and receives no recipient address.

You can create a tour checklist for a tour. For this we process the route, the motorcycle chosen from your garage (including model name, drive type, tyre pressure), a departure date you set, and the items and their status. For weather notes we request a forecast for points along the route from Open-Meteo on the server side (section 7); your browser does not contact Open-Meteo and no account data is transmitted.

Multi-day tours: You can group several of your saved routes into a private multi-day tour. For this we store a tour name you choose, optionally a description and a start date, and the order of the assigned routes of your own; the routes themselves are neither copied nor changed. A multi-day tour is visible only to you and is not shared with others. If you create a checklist for it, we request the weather per stage and travel day on the server side as described above. The multi-day tour and its checklist are deleted as soon as you remove it, at the latest with your account; your individual routes remain unaffected.

Like any other personal list, the checklist of a multi-day tour can also be made readable via “Share link”. That read-only view shows only the list’s name and its items — neither your daily stages and their order, nor a planned start time, your routes or the multi-day tour itself. Those remain private and visible to you alone.

If a route is shared with specific people, the checklist is a shared matter: all participants see the shared items, who is responsible for an item and who ticked it off — and they see each other's personal packing lists for this ride, that is the text, category and status of the items including self-added ones, each with the display name under section 5g. Not visible are your notes on individual items, your other lists and your garage. Nobody but you can change your list. A shared item is not removed by one person alone: it stays visible to everyone, struck through, until all participants have struck it. If the share is withdrawn, access ends in both directions; your personal list stays with you. Via “share link” a personal list can additionally be made readable by link: whoever has the link sees the name, the items and the reasons (e.g. the model name of your motorcycle) until you stop sharing. Such link pages are excluded from search engines.

Community templates: if you share a checklist as a template, we store a copy containing only the text, category and section of the items — without route, date, motorcycle, reasons or status. Logged-in members see the template with your display name according to section 5g and can adopt or report it (section 5k). You can withdraw the template at any time; it is deleted together with the list or the account. For notes on passes, closures, tolls and unpaved sections we analyse the route on our own servers (own routing service and own traffic data from official sources); no account data is passed on to third parties.

Legal basisArt. 6(1)(b) GDPR (provision of the sharing and checklist features you use). Data is deleted with your account or as soon as you delete the list or share; the log of pre-departure reminders 30 days after the departure date.
Section 5m
Voice link on a shared ride

When you ride a shared tour together, you can open a voice link to the other participants in riding mode. It is never on by default: you start it yourself with a button, and your browser asks for microphone access first. Without that permission no voice is transmitted.

Your voice is sent live to our own voice server (intercom.nbnl.de, same location as described in section 3) and distributed from there to the other participants of the same tour. The transmission is encrypted in transit. We do not record conversations, store no audio and do not analyse their content — the server merely forwards the voice packets and discards them immediately.

So that engine and wind noise are not transmitted continuously, your device examines the microphone signal and only passes it on when you are actually speaking. This check runs solely on your device; while it is closed, no sound leaves your phone. You can mute yourself or end the connection at any time. Meanwhile the other participants see your display name as described in section 5g and whether you are currently speaking.

To join, we issue a short-lived signed ticket containing the tour's invitation code, your account ID and your display name; it expires after ten minutes. Only someone who is a participant of the shared tour at that moment receives one. When the tour ends or you leave the connection, your session on the voice server is closed; nothing is retained.

Please remember that everyone on the tour can hear you while your microphone is open — including conversations around you that you did not intend for the group. Anyone riding with you who might be overheard should know about it.

Legal basisArt. 6(1)(a) GDPR (your consent, given by starting the voice link and granting microphone access), which you may withdraw at any time with future effect by ending the connection. No audio is stored; the session ends with the tour at the latest.
Section 6
Usage analysis
a) Our own analytics

For technical product analysis we record usage events (e.g. page views, model/article views, searches, video starts, game results). In doing so we process, among other things, the path, the time, an anonymous identifier, optionally model/article references and shortened technical metadata. The recording takes place only if you have consented to analytics cookies via the cookie banner.

If you are logged in to your NBNL account, we additionally store your account identifier (user_id) with the respective event. This makes the events attributable to your account. We evaluate this exclusively internally, in order to understand which features logged-in members actually use — there is no transfer to third parties, no profiling for advertising purposes and no automated decision-making. Without a login, the recording remains purely pseudonymous.

  • Cookie: nbnl_anon_id (anonymous assignment)
  • For logged-in members additionally: the account identifier (user_id)
  • Where the site is reached via an external link, additionally: the domain of the referring page (without path and without parameters)
  • Optional opt-out cookie: nbnl_analytics_self_exclude
  • API endpoints: /api/analytics/track and /api/analytics/track-bulk

The legal basis is your consent (Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG). You can withdraw your consent at any time via the cookie settings . When your account is deleted, the analytics events assigned to your account are deleted as well.

b) Matomo (self-hosted)

This website uses Matomo, an open source web analytics software which we host ourselves on our own server at matomo.nbnl.de . There is no transfer of the analytics data to third parties ; all data remain in Germany on our infrastructure.

  • Cookies: _pk_id.* (distinguishing unique users, storage period: 13 months), _pk_ses.* (session status, storage period: 30 minutes)
  • IP anonymisation is enabled (the last two octets of your IP address are discarded before storage)
  • The browser setting “Do Not Track” is respected; where DNT is enabled, no tracking takes place
  • Log data are deleted or aggregated after 180 days at the latest

Matomo is activated only after your express consent via the cookie banner. On withdrawal, the _pk_*cookies are removed and no further tracking takes place. Further information about Matomo: https://matomo.org/privacy/

Legal basisArt. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG (consent).
Section 7
Maps, weather and geo services

On pages with map features (including the calendar, accident pages, route planner, navigator/riding mode, Best Routes, Live View, dealer and route maps) we use third-party map and geo services. Since August 2026, map tiles, fonts and symbols are loaded exclusively via our own server — your browser does not contact the tile providers in the process, and your IP address is not transmitted to them. Since August 2026 the same applies to the conversion of coordinates into place names and to queries of map objects: these too run via our server. To the services named we transmit the geo-coordinates queried, but not your IP address. With services expressly marked “directly from the browser”, your IP address is transmitted to the respective provider. The following are used in particular:

  • OpenFreeMap (tiles.openfreemap.org) — map tiles, fonts and symbols based on OpenStreetMap; the request runs exclusively via our server, your browser does not contact OpenFreeMap
  • Federal Agency for Cartography and Geodesy (BKG) (sgx.geodatenzentrum.de, Germany) — official topographic map tiles (TopPlusOpen) in the off-road/topo view; the request runs exclusively via our server
  • AWS Open Data Terrain Tiles (s3.amazonaws.com, Amazon Web Services Inc., USA) — elevation data tiles (Terrarium DEM) for 3D terrain and hill shading; the request runs exclusively via our server, your browser does not contact AWS
  • NASA GIBS (gibs.earthdata.nasa.gov, USA) — satellite overlays (cloud imagery) in the weather view; the request runs exclusively via our server, your browser does not contact NASA
  • Esri / ArcGIS Online (Esri Inc., USA) — satellite/aerial image tiles in the satellite view; the request runs exclusively via our server, your browser does not contact Esri
  • Open-Meteo — weather data (including the DWD ICON model) for route and mountain-pass weather
  • Nominatim (OpenStreetMap Foundation) and Photon (Komoot) — address search and reverse geocoding (converting coordinates into a place name); since August 2026 the request runs exclusively via our server, your browser does not contact these services
  • Overpass API — querying map objects (e.g. POIs, road type, twisty routes); since August 2026 the request runs exclusively via our server, your browser does not contact Overpass
  • Mapillary (Meta Platforms Ireland Ltd.) — street-level photos; images are delivered via our signed image proxy
  • German Weather Service (DWD) — official weather warnings as well as radar tiles (loaded via our server)
  • EUMETNET OPERA — European rain radar composite for the radar layer in the weather view, route planner and route map; delivered via our own radar service, your browser does not contact the radar network
  • Official traffic data — closures, roadworks and traffic jams from Autobahn GmbH des Bundes (Data licence Germany – attribution 2.0), ASFINAG (Austria), ASTRA/opentransportdata.swiss (Switzerland), Fintraffic (Finland), NDW (Netherlands) as well as regional services (including BayernInfo, Straßen.NRW, MobiData BW); the request runs exclusively via our server, your browser does not contact these providers
  • Tankerkönig (creativecommons.tankerkoenig.de, provider established in Germany) — current fuel prices along the route or in the vicinity; on a query, the coordinates of the chosen location and the search radius are transmitted to the service (Art. 6(1)(b) or (f) GDPR)

If you use location features (e.g. “Events near you”, navigator, riding mode, Live View), your location is processed only after your express browser/device permission. With providers established in the USA, a transfer to the USA may take place on the basis of the EU-US Data Privacy Framework or standard contractual clauses. Services connected exclusively via our server (including all map tiles, NASA GIBS, EUMETNET OPERA, DWD, official traffic data) receive no data from your device in the process. OpenStreetMap privacy: https://wiki.osmfoundation.org/wiki/Privacy_Policy

Legal basisArt. 6(1)(b) GDPR (provision of the requested map/route feature), Art. 6(1)(f) GDPR (functioning, performant map display) as well as Art. 6(1)(a) GDPR (consent where location is shared via the browser dialogue).
Section 8
Video and social features

On the Travel, Catalogue and Community pages, videos from YouTube and Vimeo can be shown or embedded. Embedded videos are loaded only once you actively click the preview (two-click solution) — only then are data (including your IP address) transmitted to the respective provider. The preview images are fetched by our own server; your browser does not request them from the provider. When external content or social share links (e.g. WhatsApp, Facebook, Instagram) are started, the privacy provisions of the respective providers apply in addition. YouTube privacy: https://policies.google.com/privacy?hl=de

To find suitable videos (e.g. travel videos for a region or model videos in the catalogue) we additionally send search requests from our server to the YouTube Data API of Google LLC (USA). Only the search terms (e.g. region or model names) are transmitted in the process — no personal data of our users. A transfer to the USA takes place on the basis of the EU-US Data Privacy Framework or standard contractual clauses.

Legal basisArt. 6(1)(f) GDPR (user-friendly presentation) as well as Art. 6(1)(b) GDPR for actions actively triggered by the user (e.g. share click, video start).
Section 8a
Website preview images (screenshots)

Holders of a business account can have a provisional header image for their profile generated from a screenshot oftheir own website on file. For this we use the screenshot service thum.io (USA). The screenshot is created exclusively on the server and only at the express request of the respective account holder; only the address of the website to be depicted is transmitted to the provider — no personal data of our users and no IP addresses of visitors. A transfer to the USA takes place on the basis of standard contractual clauses or the EU-US Data Privacy Framework.

In event previews, no screenshots of third-party websites are used any longer; since August 2026 only our own, drawn graphics appear there.

Legal basisArt. 6(1)(b) GDPR (operation of the business account at the request of the account holder).
Section 9
Browser storage (local storage)

In addition to cookies, we store some settings in the browser’s local storage, e.g. for UI views and feature states.

  • nbnl_buddy_id (feature ID for Buddy/game/analytics)
  • nbnl.catalog.columns (catalogue view on mobile)
  • nbnl_mobile_mode (mobile display mode)
  • nbnl_last_route (the route most recently calculated in the route planner — stays in the browser only)
  • nbnl_fahrmodus_route (handover of a planned route to riding mode, session storage)
  • nbnl_premium_offline (only with an active Premium subscription: time of the last check, so that saved Premium content remains usable offline for a limited time)
  • nbnl_regmeter_v1 (only after consenting to analytics: counts sections visited without logging in for the prompt to create a free account; without consent the site counts only within the open tab)
Section 10
E-mail dispatch

For transactional e-mails (password reset, change of e-mail address, emergency contact notifications as well as the community notifications described below) we use the service Brevo (Brevo SAS, 106 boulevard Haussmann, 75008 Paris, France — formerly Sendinblue) as a processor. The recipient address and the e-mail content are transmitted to Brevo in order to carry out the dispatch technically. A data processing agreement is in place. Further information: https://www.brevo.com/de/datenschutz-und-sicherheit/

Notifications from the community

If you use the community, we send transactional notification e-mails on certain events to the verified account address concerned — never to non-members and never to the person who triggered the event:

  • when someone comments on your post or comment (notify_comment_email);
  • when you receive a friend request or a request you have sent is accepted (notify_friend_email);
  • when someone shares a route with you, with all of their friends or with one of your groups (notify_route_share_email);
  • 24 hours before the departure of a tour you are taking part in, if items on your checklist are still open (notify_tour_reminder_email);
  • to the group leadership when a new member joins their group (notify_group_owner_email); in the case of local/regional groups operated by us without their own leadership, this notice goes to an internal NBNL mailbox (gruppen@nbnl.de).

These notifications are purely transactional (no marketing, no double opt-in) and are enabled by default. You can switch off each category individually and at any time in the account menu under “Account & privacy”. In the app you additionally receive notices about reactions, comments and shared posts (see section 5i); these do not leave the platform.

We send informational e-mails about news and features (marketing) only if you have expressly consented to this in the account settings (opt-in). The time of consent is logged. You can withdraw your consent at any time in the account settings or by e-mail to datenschutz@nbnl.de widerrufen.

Transactional e-mails additionally go in copy (BCC) to our internal mailbox info@nbnl.de, so that we can handle enquiries and document the dispatch. The copies are subject to the same deletion periods as the respective matter.

Legal basisArt. 6(1)(b) GDPR (password reset, change of e-mail address), Art. 6(1)(f) GDPR (emergency contact and community notifications at the user’s request or for the operation of the social features — objection possible at any time) as well as Art. 6(1)(a) GDPR and § 7(2) no. 2 UWG (marketing e-mails only with consent).
Section 10a
Payment processing via Stripe

For paid Premium services we use the payment service provider Stripe (Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland). When you take out a paid subscription you are forwarded to the Stripe checkout page; you enter payment and invoicing data (e.g. card information, address data where applicable) directly with Stripe. From Stripe, NBNL receives exclusively the status information necessary to assign the subscription (e.g. customer/subscription IDs, payment status, term) — no complete card or account data.

A transfer of data to third countries may take place on the basis of the EU-US Data Privacy Framework or standard contractual clauses. Further information: https://stripe.com/de/privacy.

Legal basisArt. 6(1)(b) GDPR (performance of the contract).
Section 10b
Business accounts (NBNL Business)

Dealers, route operators and other businesses can create a business account (the “NBNL Business” area). In doing so we process the data provided during registration and profile maintenance (in particular company name, business e-mail address, contact person, address/location, logo or profile images, submitted content such as events, POI suggestions and test-ride offers). Verification is carried out by an e-mail confirmation link sent to the business address on file.

Our operating team is notified internally about certain business events (e.g. registration, activation, login) via the service Discord (Discord Netherlands B.V., Amsterdam, Netherlands; parent company Discord Inc., USA). The company name and, where applicable, masked contact details may be transmitted in the process.

Test-ride and booking enquiries: If you make a test-ride or booking enquiry via NBNL, we forward the details required for this (name, e-mail address, telephone number, address where applicable, licence category and your message) to the dealer or provider you have selected, so that they can process the enquiry and contact you. The recipient processes the data on their own responsibility (Art. 6(1)(b) GDPR).

Paid business packages: If a business account books a paid package, payment runs via Stripe (see section 10a). We store with the account the Stripe customer and subscription identifier, the package status, the price variant booked as well as the start and end of the billing period — no complete card or account data. Invoice records remain with Stripe and are subject to the statutory retention periods.

Legal basisArt. 6(1)(b) GDPR (provision of the business account, handling of booked packages) as well as Art. 6(1)(f) GDPR (internal operational notifications, abuse prevention).
Section 10c
Dealer directory (data from public sources)

In the “NBNL Business” area we publish a directory of motorcycle businesses in Germany, Austria and Switzerland. The entries do not predominantly come from the businesses themselves, but from publicly accessible sources: OpenStreetMap (via the Overpass API), the dealer searches of the manufacturers and importers and trade directories (in particular 1000PS). As soon as a business has taken over its entry via a business account, only its own details apply.

What is published is the name of the business, address, location coordinates, telephone number, website, brands carried and opening hours. We do not show e-mail addresses on file publicly — they serve exclusively as an invitation to take over the entry. Names of contact persons do not appear in the directory. These are company data; a personal reference exists only insofar as the business is derived from the name of a natural person (for instance in the case of sole traders).

Businesses concerned can object to the publication at any time and without giving reasons (Art. 21 GDPR) or request rectification (Art. 16 GDPR) — via the form on the respective dealer page or informally toinfo@nbnl.de. A removed entry is permanently blocked and is not reinstated even if the business continues to be listed in the original sources. Origin, purposes, recipients and rights in detail (collective information under Art. 14 GDPR) as well as the licence notice for OpenStreetMap (ODbL) can be found atnbnl.de/business/haendler/datenquellen.

Visibility counter: So that businesses can see whether their entry is being used, we count for each dealer page and day how often it was viewed and how often telephone, website or route links were clicked. What is stored is exclusively a numeric value per day, business and type of event — no IP address, no identifier, no session. Nothing is stored on your device for this and nothing is read from it (no cookie, no local storage), which is why no consent under § 25 TDDDG is required for it. Any inference about individual persons is ruled out; the daily rows are deleted after 400 days.

Legal basisArt. 6(1)(f) GDPR (legitimate interest in a complete, findable trade directory as well as in usage statistics for the listed businesses); information under Art. 14 GDPR, provided in publicly accessible form pursuant to Art. 14(5)(b) GDPR.
Section 11
Recipients and transfers

Data are transmitted to service providers and external platforms only insofar as this is necessary for the features provided (hosting, maps, video, social networks on an active click, e-mail dispatch via Brevo, payment processing via Stripe, AI services, object storage for uploaded images and documents). Web analytics with Matomo takes place on our own server in Germany; no transfer to third parties occurs in this context. There is no disclosure for other purposes.

Section 11a
Use of AI services (EU AI Act)

NBNL uses AI-supported features (motorcycle advisor, Tour Buddy, route recommendations, NBNL MCP server, the specification and manual search in the Garage, tyre pressure notes, the automatic completion of technical data when adding a motorcycle, the vehicle registration document scan, the valuation in the Garage as well as automatically created mountain-pass descriptions in the route planner). In doing so, your input and relevant context data (e.g. the motorcycle model concerned, for the valuation the year of construction and mileage, for the registration document scan the uploaded image) are transmitted to the external AI provider used, in order to provide the respective feature:

  • OpenAI API — OpenAI, L.L.C., 3180 18th Street, San Francisco, CA 94110, USA (privacy: https://openai.com/policies/privacy-policy). Under the OpenAI API terms, the content transmitted is not used to train the OpenAI models. A data processing agreement or data processing addendum is in place with OpenAI.

Only content relevant to the feature is transmitted (your search queries, filter details, vehicle preferences, vehicle data of the motorcycle concerned and — only for the vehicle registration document scan and only at your instigation — the image you uploaded). No plain data such as passwords or payment information. Personal data are transmitted only insofar as you enter or upload them yourself.

Under Regulation (EU) 2024/1689 (EU AI Act), the AI systems used are classified as minimal or limited risk . AI-generated answers are identified as such and do not replace individual professional advice. The transfer to providers in the USA takes place on the basis of the EU-US Data Privacy Framework and standard contractual clauses (Art. 46 GDPR).

Legal basisArt. 6(1)(b) GDPR (performance of the contract / use of requested features) as well as Art. 6(1)(f) GDPR (legitimate interest in providing intelligent features).
Section 12
Retention periods

We store personal data only for as long as is necessary for the respective purpose or as statutory retention obligations exist. In detail, the following benchmarks apply:

  • Account and profile data: until the account is deleted; after a deletion request, personal data are removed within 30 days, unless statutory retention obligations stand in the way.
  • Session cookie: 30 days; OAuth state cookie: 15 minutes.
  • Password reset token: approx. 1 hour; E-mail change token: approx. 24 hours.
  • Server logs (IP-related): 14 days at the latest, thereafter deletion or anonymisation.
  • Our own analytics events: 14 months (automatic daily deletion run), thereafter only in aggregated, non-personal form; entered search texts are removed after just 90 days; account-related events at the latest when the account is deleted. Anon cookie (nbnl_anon_id): 1 year; Matomo cookies (_pk_id.*): 13 months; _pk_ses.*: 30 minutes.
  • Hot-or-Not uploads: until deleted by the user; after a deletion request there is first a 30-day soft delete (for recovery in the event of a mistake), after which the image is permanently removed from object storage.
  • Community posts, comments and reactions: until deleted by the user or until the account is deleted; deleted posts are first marked as a soft delete and are subsequently removed from object storage together with their associated images. Automatic activity notices in the stream cease when the stream is deactivated or when the account is deleted.
  • Follows, friendships and group memberships: until withdrawal/dissolution by the user or until the account is deleted.
  • Weather/place detail in the community area (weather_label): until changed or deleted by the user.
  • Content reports and moderation matters: until the matter is dealt with plus 90 days of documentation, thereafter deletion of the components capable of identifying a person.
  • Best Routes / tour stages: until deleted by the user; copies already downloaded by third parties remain outside our sphere of influence.
  • Live View positions: in memory only during the active session; server-side logs relating to Live View after a maximum of 24 hours. Share tokens expire once the chosen validity period elapses.
  • Riding-mode recordings: until deleted by the user.
  • Garage data: until the entry or the account is deleted.
  • Emergency contacts: until deleted by the user; dispatch logs of notification e-mails triggered are deleted after 30 days at the latest.
  • Payment and invoicing data (Stripe reference): up to 10 years, insofar as commercial and tax law retention obligations exist (§ 257 HGB, § 147 AO).
Section 13
Your rights

You have the right at any time to access, rectification, erasure, restriction of processing and data portability. You can also object to the processing of your data insofar as it is based on Art. 6(1)(f) GDPR. Consent you have given can be withdrawn at any time with effect for the future.

Please address enquiries to datenschutz@nbnl.de. We generally deal with data protection enquiries within one month (Art. 12(3) GDPR).

If an identifiable person who has not consented to publication appears in an uploaded image, please also report this to datenschutz@nbnl.de or via the “Report image” function. We examine the matter and remove unlawful content without delay, at the latest within 30 days.

You also have the right to lodge a complaint with a supervisory authority (for Bavaria: the Bavarian State Office for Data Protection Supervision, BayLDA, Promenade 18, 91522 Ansbach).

Section 14
Currency

This policy is adapted when features and processes change. Last updated: September 2026.

Privacy policy