FORTY5°

Légal

Politique de confidentialité

En vigueur : 12 July 2026

Le présent document est fourni en langue anglaise ; seule la version anglaise fait foi.

This Privacy Policy explains what data Forty5° collects when you use our app, website, and workshop services, what we do with it, and the rights you have over your data. Forty5° is operated by Clubstyle Casa - F.Z.E, a Free Zone Establishment registered in the United Arab Emirates, which is the data controller for your personal data and processes it in accordance with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL). For any privacy question, or to exercise your rights below, contact us at contact@forty5d.com.

1. Data we collect

Account data

  • Phone number and email address (used for sign-in).
  • First and last name (you provide these).
  • Profile photo if you choose to upload one.
  • Preferred language and notification preferences.

Bike + service data

  • Make, model, year, colour, mileage, stage build, and replacement history of motorcycles you register.
  • Bookings, jobs, and service notes associated with your bikes.
  • Photos of your bikes that you upload.
  • Odometer photos. When you tap "Update odometer" in the app, your dashboard photo is sent to Claude Haiku (Anthropic) for optical character recognition, then stored in our private object storage. We keep the photo as part of the audit trail for your bike's mileage history so that disputes (drop-off mileage at the workshop, etc.) can be resolved against the source image. Each photo is associated with your account and only visible to you and Forty5° staff with explicit audit-permission.
  • Rides. When you create or RSVP to a ride, the title, planned time, expected distance, optional meeting-point label and coordinates, and any logged km after the ride are stored. RSVPs and km logs are visible to other riders who can see the ride.

Chat history

  • Messages you send to the AI Mechanic and the model's responses, retained so chat sessions remain readable on return.
  • Daily message counts, used to enforce rate limits per tier.

Subscription + commerce data

  • Subscription state (active, in trial, expired) — synced from Apple / Google via RevenueCat. We never see your payment-card details.
  • A link between your Forty5° account and your Shopify customer record (matched by email) so we can show your order history in-app.

Location data

  • Coarse location when you set a pickup, delivery, or ride meeting point, or when you ask the AI Mechanic to find a garage near you.
  • Precise location in the background, but only while you are recording a ride. When you start a ride recording we track your route by GPS and keep tracking with the screen off or the app in the background — that is the feature. Recording never starts on its own: it begins when you press record and stops when you press stop. Your phone shows a location indicator the whole time it is running. If you also switch on live broadcast, your position is shared with your followers until you end the ride.
  • We do not track your location when you are not recording a ride, and we do not use location for advertising or sell it to anyone.

Direct messages

  • Messages you send to another rider, plus any photo or document you attach to them. Attachments can include things like registration papers or an invoice, so treat a DM the way you would treat handing someone a copy of a document.
  • Direct messages on Forty5° are not a social inbox. They exist so a buyer and a seller can talk about a specific thing — a bike listing or a used-parts post — and they can only be opened from one. They are not meant to replace WhatsApp, Instagram or any other messaging app, and we deliberately do not build them into one.
  • They are deleted after 30 days. Once a conversation has had no new message for 30 days, the messages and their attachments are permanently deleted from our systems — not archived, not hidden. A deal that is done is data we have no reason to keep. The one exception is a conversation involved in a report of harassment, fraud or abuse: we hold that one for up to 12 months so it can be investigated and appealed, then delete it too.
  • Because of this, DMs are not a place to keep something you will need later. If a seller sends you an address or an agreed price you want to keep, save it somewhere else.

Diagnostic + crash data

  • Crash reports and basic device-model / OS-version metadata via Firebase Crashlytics, used to diagnose bugs.
  • Push-notification delivery receipts, used to confirm critical messages (booking confirmations, etc.) reached your device.

2. Why we collect it

We use the data above to:

  • Run the app and the workshop (the core service you signed up for).
  • Personalise the AI Mechanic — it can only give useful answers when it knows what bike you ride and your service history.
  • Process subscriptions, apply member pricing, and enforce rate limits fairly across tiers.
  • Communicate booking confirmations, reminders, and shop announcements.
  • Improve the app by analysing crashes and usage patterns.
  • Comply with UAE legal record-keeping obligations.

3. Third parties we share data with

We use a small set of trusted vendors to operate the Service. Each receives only the data they need to do their job:

  • Supabase — database hosting, authentication, file storage. Data is stored in Supabase's EU region.
  • Anthropic — powers the AI Mechanic + odometer OCR + image moderation. Your chat messages, attached photos, dashboard photos (when you update your odometer), and the bike context for each request are sent to Anthropic's API. Anthropic's enterprise terms mean they don't train on user inputs. We send only what the specific feature needs — odometer OCR does not see your chat history, the AI Mechanic does not see your odometer photos unless you attach one yourself.
  • Voyage AI — embeds your AI Mechanic queries (member tier only) so we can retrieve relevant service-manual excerpts. Embeddings are derived data, not the raw query, but the query text itself is sent to Voyage to generate them.
  • RevenueCat — manages our subscription lifecycle. Receives your Forty5° user ID and the receipt data Apple/Google send when you subscribe, renew, or cancel.
  • Shopify — runs our parts catalogue. When your email matches a Shopify customer, we link the records and your member status is propagated as a customer tag for automatic discount eligibility.
  • Apple + Google — process subscription payments and deliver the app via the App Store / Play Store. They receive only what their platform requires; we never see your payment card.
  • Firebase (Google) — receives crash reports and push notification metadata.
  • Railway — hosts our API server. No user data is stored on Railway permanently — it's the transit layer between the app and Supabase.
  • Google Analytics + Microsoft Clarity — website audience measurement, and only on the forty5d.com website if you accept analytics cookies (see section 6). They never receive your account data, your bikes, your bookings or your chats.

We do not sell your personal data to anyone. We don't use it for advertising. We don't share it with other riders.

4. Data retention

  • Account + bike data: retained while your account is active, deleted within 30 days of account deletion.
  • Booking / service records: retained for 5 years after the service date, as required by UAE consumer-protection law.
  • Chat history: retained while your account is active. Deleted when you delete the chat session or your account.
  • Odometer photos + readings: the photo blob is retained for 2 years (audit window for service-mileage disputes). The numeric reading on your bike record is retained for the life of the bike. Both are deleted within 30 days of account deletion (or sooner if you remove the bike).
  • Direct messages + their attachments: permanently deleted 30 days after the last message in the conversation, whether or not you delete your account. A conversation that is the subject of an open report of harassment, fraud or abuse is held for up to 12 months so it can be investigated and appealed, then deleted.
  • Ride content + RSVPs: retained while the ride exists in your history. Cancelled rides are soft-deleted after 90 days; attended rides are kept until you delete your account so your km log + badges remain accurate.
  • Reports of harmful content: retained for 1 year so we can identify repeat violators, then anonymised.
  • Subscription records: retained for 7 years after the last transaction, as required by UAE tax law.
  • Crash logs: auto-deleted by Firebase after 90 days.

5. Your rights

You have the right to:

  • Access the personal data we hold about you. Most of it is visible in the app under Profile and Garage; for anything else, email us.
  • Correct data that's wrong. You can edit your profile and bikes directly in the app.
  • Delete your account from Profile → Settings → Delete account. Some data may be retained for legal record-keeping (see retention).
  • Export your data in a portable format. Email us and we'll send a JSON export within 30 days.
  • Object to specific processing — for example, opting out of non-essential push notifications. Adjust these in Profile → Notifications.

6. Cookies + analytics

The forty5d.com website uses essential cookies for session management and to remember your language choice. These carry no tracking and are always on. The app does not use cookies; it uses local secure storage for the session token.

The website also uses analytics cookies — but only if you accept them. On your first visit a banner asks for your choice, and nothing analytics-related loads until you accept. If you accept, we use:

  • Google Analytics 4 (Google) — how many people visit, which pages they read, which country and language they browse in, which site or search brought them, and which device they use. Where Google is able to infer them, this includes aggregated age range, gender and interest categories. We see these only as group statistics, never as a named individual, and we never use them to advertise to you.
  • Microsoft Clarity (Microsoft) — anonymised heatmaps and session replays of how visitors scroll and click, so we can find confusing layouts. Clarity masks text input by default, so anything you type in a form is not recorded.

If you reject, neither tool loads and neither sets a cookie. You can change your decision at any time via Cookie settings in the site footer. We do not use advertising cookies, and we do not sell or share this data with data brokers.

7. Children

Forty5° is intended for riders aged 18 and over. We do not knowingly collect data from anyone under 18.

8. International transfers

Some of our vendors process data outside the UAE (Supabase EU, Anthropic US, Apple/Google US). When data leaves the UAE, we rely on the vendor's compliance with international data-protection frameworks (GDPR for EU vendors; SCCs for US vendors). You consent to these transfers when you use the Service.

9. Security

All data in transit uses TLS. Data at rest in Supabase is encrypted at the storage layer. We follow row-level-security best practices so riders can only see their own data — even our backend can't show one rider another rider's bikes or chat history without an explicit admin-tier credential.

10. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we'll update the "Effective" date at the top of this page and notify you in-app for material changes. Continuing to use the Service after a change means you accept the updated policy.

11. Contact

Questions about your data? Reach us at contact@forty5d.com or visit the workshop in Dubai.