JuiceGO · Effective: 11 August 2026
Privacy Policy
This Privacy Policy describes how we process personal data of users of the JuiceGO service and mobile app. We process your data only to the extent necessary to provide the powerbank rental service and to fulfill our legal obligations.
§1.Data Controller
The controller of your personal data is L3ST Borys Skrzypek, Tax ID (NIP) 5482775586, based in Skoczów, Poland (the “Controller”).
For data-related matters please contact: hello@juicego.pl.
The Controller has not appointed a Data Protection Officer, as none of the conditions in Article 37 GDPR apply. For any matter concerning personal data, write directly to the contact address above.
§2.Scope of data processed
We process data you provide when creating an account (name, email, phone number), payment data (passed directly to the payment processor), rental history, location of rental stations, and technical data (IP address, device identifier, browser data).
We do not continuously track your device location — location is only used when you actively open the station map.
We also process the content of support requests together with any attachments, and a record of the consents you have given (date, wording of the consent and a shortened connection identifier) — the latter solely so that we can demonstrate the consent was granted.
Providing an email address and phone number is voluntary but necessary to enter into the contract — without them you cannot create an Account or rent a Powerbank. Consent to analytics is entirely voluntary and withholding it has no effect on your use of the service.
§3.Purposes and legal basis
We process your data for the following purposes:
a) providing the powerbank rental service — Article 6(1)(b) GDPR (performance of a contract);
b) processing transactions and issuing accounting documents — Article 6(1)(c) GDPR (legal obligation);
c) handling complaints and user communication — Article 6(1)(f) GDPR (legitimate interest);
d) marketing our own services, based solely on explicit consent — Article 6(1)(a) GDPR.
§4.Data recipients
Your data may be shared with: the payment processor PayU (PayU S.A., seated in Poznań, Poland), which processes and stores your card data as a secure token (the Operator does not store the full card number), hosting and cloud infrastructure providers, customer support tooling providers, and government authorities entitled by law.
You enter card details directly on the payment processor's secured page; the Operator receives only a token plus the last four digits and card brand, needed for deposit charges.
In addition: we share your phone number with our SMS gateway provider (Vonage) if you enable two-step login or SMS notifications, and usage data with Google Ireland Limited — only if you consent to analytics.
Data may leave the European Economic Area only within Google's services (analytics) and the SMS gateway, under standard contractual clauses approved by the European Commission. If you do not consent to analytics, no data is sent to Google.
§5.Automated decision-making
Some decisions about your Account are made without human involvement, based on fixed rules set out in the Terms. These are:
a) blocking the ability to rent when your Account carries an outstanding debt that could not be charged to your card — the block is lifted automatically once the amount is settled;
b) refusing a further rental once the limit of simultaneously rented Powerbanks is reached;
c) charging a fee for a rental returned within the free period when the daily allowance of free returns has already been used.
These rules are the same for everyone. We do not build a user profile or a creditworthiness score from them, and we do not carry out profiling for marketing or advertising purposes.
If you believe a decision was made in error, you have the right to obtain human review, express your point of view and contest the decision (Article 22(3) GDPR). A message to our contact address is enough — the case is handled by a person, not by the system.
§6.Partner and counterparty data
Separately from user data, we process data of the people running the venues that host our Stations and of those representing them: name, company details, tax identification number, address, phone number, email address, bank account number, correspondence and service requests, and partner portal login credentials.
The legal basis is performance of the cooperation agreement (Article 6(1)(b) GDPR), tax and accounting obligations (Article 6(1)(c) GDPR), and our legitimate interest in day-to-day contact and defence against claims (Article 6(1)(f) GDPR).
Data of people who expressed interest in cooperating but with whom no agreement was ultimately concluded is deleted within 12 months of the last contact.
Data of partners we did contract with is kept for the term of the agreement and for the limitation period of mutual claims; accounting documents for 5 years from the end of the year in which they were issued.
§7.Retention period
We keep account data for as long as the account is active and for 3 years after closure in order to defend against potential claims.
Billing data — for the period required by tax law (5 years from the end of the year in which the document was issued).
Technical logs — up to 12 months.
Records of consents given — for the duration of the consent and 3 years after its withdrawal, solely to demonstrate that it was granted.
§8.Data security
Passwords are stored only as irreversible hashes — nobody, ourselves included, can read your password.
Your login session lives in a cookie that scripts in the browser cannot read, and all communication with the site and the app is encrypted over HTTPS. You can additionally enable two-factor login with an SMS code.
Only authorised staff can access the admin panel, and only within the scope of their assigned role; login attempts are logged and rate-limited.
We never receive or store your full card number — you enter card details directly with the payment processor and we only receive a token, the last four digits and the card brand.
We take regular backups and periodically verify that data can actually be restored from them.
§9.Your rights
You have the right to: access your data, rectify it, erase it, restrict processing, data portability, object to processing, and withdraw consent at any time (without affecting the lawfulness of processing carried out earlier).
You also have the right to lodge a complaint with the President of the Polish Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw).
§10.Cookies
Strictly necessary cookies — required to run the service, no consent needed: the session cookie (keeps you signed in, removed on logout) and the NEXT_LOCALE language cookie (written only once you change the language yourself, valid 12 months).
Browser local storage — your app login token and a record of dismissed "what's new" notices. Cleared on logout or when you clear browser data.
Consent cookie (juicego_consent) — remembers your choice so we don't ask on every visit. Valid 12 months.
Analytics — Google Analytics (Google Ireland Limited), ONLY with your consent. Purpose: identifying traffic sources (where visitors come from) and the number of visits, so we can respond to real demand — including deciding where to place new stations. It stores _ga and _ga_* cookies for up to 2 years. Until you consent, the Google script is not loaded at all. The IP address is anonymised and Google's advertising features stay disabled; data may be transferred outside the EEA under standard contractual clauses.
You can withdraw analytics consent at any time — the "Cookie settings" link in the footer reopens the same choice, and on refusal we delete stored Google cookies. We do not use advertising or profiling.
You can also delete stored data or block cookies in your browser settings — note that blocking strictly necessary cookies will prevent you from logging in.
§11.Contact
For any data protection matters please contact the Controller in writing at the registered address or by email at hello@juicego.pl.
We respond within 30 days of receiving a request.