Privacy Policy
How we handle personal data, and what you can ask us to do with it
Version 2.0 · In effect from 20 August 2026
This policy explains what personal data the Horsika platform collects, why, and what you can require us to do about it. It is written to be read, not filed: where a legal term is unavoidable we say what it means in practice.
1. Who we are
The platform at https://horsika.com is operated by , , registered at (“Horsika”, “we”, “us”).
2. Our two roles: controller and processor
Horsika handles personal data in two different capacities, and which one applies changes who you should talk to.
We are the controller when
- you create an account with us, as a club owner, an administrator, a trainer or a rider;
- you contact us, request early access, or use our marketing website;
- we bill a club for its subscription.
Here we decide what is collected and why, and this policy governs it.
We are a processor when
An equestrian club uses Horsika to run its business. The client records, appointments, notes, memberships and payment history it keeps in our system belong to the club: the club decides what to record and why, and we only act on its instructions. In data protection terms the club is the controller and we are the processor.
If you are a client of a club and want your record corrected or deleted, the club is the right place to ask. Write to us instead and we will pass the request on, but we cannot decide it ourselves. The terms of that relationship are set out in our Data Processing Agreement, which every club accepts.
3. What we collect
3.1 Account data
Name, email address, password (stored only as a bcrypt hash, never in readable form), phone number and whether it has been verified, profile photo, a short biography if you write one, the identifier issued by Google or Apple if you sign in that way, and the time of your last sign-in.
3.2 Club client records
Where a club keeps records about its riders: first and last name, phone number, email address, date of birth, any note the club's staff writes about the client, any discount applied, and whether the club has flagged the client as barred from online booking. We hold this for the club, under section 2 above.
3.3 Bookings
The date and time of a lesson, the service and trainer chosen, the number of participants, the price, the payment status, the comment left when booking, and any internal note the club's staff adds afterwards. A booking also stores a copy of the client's name, phone and email as they were at the time.
3.4 Horses and stabling
Where a horse is owned by a private individual, the record links to that person. Veterinary details kept against a horse — allergies, chronic conditions, current medication, the practice or vet's contact details — may amount to personal data about the vet as well as information about the animal.
3.5 Messages we send
For every SMS we log the recipient's number, the full text of the message, and whether it was delivered. Phone verification stores the number, the one-time code, the IP address the request came from, and how many attempts have been made. Push notifications store the device token, the platform and the device name.
3.6 Technical and usage data
IP address, browser user agent, and the pages you visit. Early access requests store the IP and user agent to catch automated submissions. Administrative actions are written to an audit log so a club can see who changed what.
3.7 Payment data
We never see or store card numbers. Payment is handled by , and we keep only the amount, the currency, the status, and the reference the provider returns.
3.8 Cookies
Set out separately in our Cookie Policy. Only strictly necessary cookies are set unless you tell us otherwise; you can change your mind at any time through .
4. Why we use it, and on what legal basis
| What for | Which data | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Running your account and providing the service | Account data, bookings, club records | Performance of a contract, Art. 6(1)(b) |
| Confirming a phone number so booking notifications reach the right person | Phone number, one-time code, IP | Performance of a contract, Art. 6(1)(b) |
| Booking reminders and confirmations by SMS or push | Phone number, device token, booking details | Performance of a contract, Art. 6(1)(b) |
| Billing clubs and collecting payment | Account data, subscription and payment records | Performance of a contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c) |
| Keeping the service secure — rate limiting, abuse and fraud prevention, audit logs | IP, user agent, sign-in times, audit records | Legitimate interests, Art. 6(1)(f): running a service that is not abused |
| Understanding how the product is used so we can improve it | Usage data, analytics cookies | Consent, Art. 6(1)(a) — nothing is collected until you agree |
| Measuring our advertising | Marketing cookies, hashed identifiers | Consent, Art. 6(1)(a) |
| Answering support requests | Whatever you include in your message | Legitimate interests, Art. 6(1)(f): responding to people who contact us |
| Meeting accounting and tax obligations | Invoices and payment records | Legal obligation, Art. 6(1)(c) |
Where we rely on legitimate interests, we have weighed those interests against your rights and concluded they do not override them. You can ask us to explain that assessment, and you can object to the processing — see section 8.
We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you, and we do not profile you.
5. Who else sees it
We do not sell personal data and we do not share it for anyone else's marketing. We do use service providers who process data on our behalf, under contract and only on our instructions. They are listed, with what each one receives, on our sub-processors page, which we keep current.
Beyond those providers, we disclose personal data only:
- to the club whose service you booked, so it can deliver that service;
- where the law requires it, or to establish, exercise or defend legal claims;
- to a buyer or successor if the business is sold or reorganised — you would be told first.
6. Sending data outside the EEA
We are established in , and some of our providers operate outside the European Economic Area. That means personal data is transferred to a third country.
Where the European Commission has not decided that the destination country offers adequate protection, we rely on Standard Contractual Clauses adopted by the Commission (Implementing Decision (EU) 2021/914), together with an assessment of whether local law in that country would undermine them and any additional safeguards needed. You may request a copy of the clauses that apply to a particular transfer by writing to privacy@horsika.com.
7. How long we keep it
These periods are enforced by an automated cleanup process, not applied by hand:
| What | Kept for |
|---|---|
| Account data | While the account is open, then 3 years of inactivity before deletion |
| Club client records and bookings | For as long as the club instructs; deleted or returned when its contract with us ends |
| SMS logs, including message text | 90 days |
| Phone verification records | 30 days |
| Early access requests | 365 days |
| Audit and activity logs | 730 days |
| Records marked deleted but not yet purged | 90 days, then permanently erased |
| Invoices and payment records | As long as tax and accounting law requires |
8. Your rights
Under the GDPR you may ask us to:
- Give you a copy of the personal data we hold about you (Art. 15).
- Correct anything inaccurate or incomplete (Art. 16).
- Delete it where we no longer have grounds to keep it (Art. 17).
- Pause processing while a dispute about accuracy or grounds is resolved (Art. 18).
- Hand it over in a machine-readable format, to you or another provider (Art. 20).
- Stop processing based on legitimate interests, by objecting (Art. 21).
- Withdraw consent at any time, without affecting what was lawful beforehand (Art. 7(3)).
Write to privacy@horsika.com. We answer within one month; if a request is complex we may take up to two months more and will tell you why within the first month. There is no charge unless a request is manifestly unfounded or excessive.
For cookies specifically, the fastest route is — changes take effect immediately.
Complaints. You have the right to complain to a data protection supervisory authority, in the EU member state where you live, where you work, or where you think the problem happened. You do not need to contact us first, though we would rather have the chance to put it right.
9. How we protect it
- All traffic is encrypted in transit with TLS.
- Passwords are stored as bcrypt hashes and are never recoverable, by us or anyone else.
- Access is scoped by role and by organisation: a trainer sees their own sessions, a club sees only its own data.
- Administrative actions are recorded in an audit log.
- Our providers are bound by contract to equivalent standards.
No system is perfectly secure, and we would rather say so than imply otherwise. If you spot a vulnerability, please tell us at privacy@horsika.com.
10. If something goes wrong
If personal data is breached and it is likely to put people's rights at risk, we notify the competent supervisory authority within 72 hours of becoming aware of it (Art. 33). Where the risk is high, we tell the people affected directly and without undue delay (Art. 34). Where we act as a processor for a club, we notify the club without undue delay so it can meet its own obligations.
11. Children
Accounts are for people aged 16 and over. Riding lessons are often booked for children — in that case the account belongs to the parent or guardian, who provides the child's details and is responsible for them. If you believe a child has created an account directly, tell us and we will remove it.
12. Changes to this policy
When we change this policy we publish the new version here with a new version number and effective date. For changes that materially affect you we give notice by email or in the application before they take effect. We do not treat silence as agreement: where a change requires consent, we ask for it.
13. How to reach us
Privacy: privacy@horsika.com
Support: support@horsika.com
Questions about this document: privacy@horsika.com. Our other legal documents: Terms of Use, Privacy Policy, Cookie Policy, Data Processing Agreement, Sub-processors, Refunds & Withdrawal, Imprint.