1. Who we are
sidestep is operated by Neill Lima ("we", "us", "our"), an individual based in Berlin, Germany. sidestep is a service that monitors public disruptions in your city and sends you personalised alerts when one is likely to affect your saved commute or cycling route.
Data controller:
Neill Lima
Berlin, Germany
privacy@sidestep.fyi
2. What data we collect and why
2.1 Account data
When you sign up, we collect your email address. This is used to identify your account and send you disruption alerts.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
2.2 Route data
You provide one or more commute or cycling routes by entering a start point and an end point. We compute a road-network path between those points and store it as a geometric line. A route can be marked as one-way or as a return trip.
Privacy sphere: Before storing your route, we trim the geometry by a privacy radius you choose (any value between 150 m and 500 m, 300 m by default) from both the start and end points. The exact addresses you enter are never persisted. Only the road segment between the trimmed endpoints is stored — never the true start or end.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
2.3 Alert preferences
We store your persona (commuter, sports, or both) and, if you provide one, an alternative alert email address. These are used to filter relevant disruptions and route alerts to the right channel.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
2.4 Telegram chat ID
If you connect your Telegram account via our bot (@sidestep_bot), we store your Telegram chat ID to send you disruption alerts via Telegram. This is optional. You can disconnect Telegram at any time from your profile settings.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
2.5 Alert delivery records
We keep a record of which alerts have been sent, keyed on a one-way SHA-256 hash of the disruption and route identifiers. This record is used solely to prevent duplicate alerts. Because the key is a one-way hash, this record cannot be linked back to the specific disruption, and therefore does not reveal the content or political nature of any demonstration you were alerted about.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest (preventing duplicate notifications).
2.6 Disruption data
Disruptions (demonstrations, road closures, events) are scraped from public sources, primarily official police and city authority websites. This data is not linked to you. We store the type (procession or standing demonstration), location, and time of each disruption. We do not persist the political theme, organiser, or reason for a demonstration.
3. What we do not collect
- Payment data — sidestep is currently free to use; we do not collect or process any payment or card details.
- Precise home or workplace addresses — the privacy sphere on your route ensures these are not stored.
- The political content of demonstrations you are alerted about.
- Location tracking or real-time movement data.
- Browsing behaviour or advertising/tracking analytics.
4. Sub-processors
We share personal data with the following processors, each bound by a Data Processing Agreement (DPA):
| Processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Clerk (clerk.com) | Authentication, session management | United States | EU Standard Contractual Clauses |
| Resend (resend.com) | Email alert delivery | United States | EU Standard Contractual Clauses |
| Railway (railway.app) | Application hosting and database | United States | EU Standard Contractual Clauses |
| Telegram (telegram.org) | Telegram alert delivery (optional) | UAE / global | Adequacy assessment + SCCs |
Anthropic (anthropic.com) is used to parse publicly available disruption text into structured data (location, type, time). This parsing uses no personal data — only public text from police and city authority websites.
Google is used only if you choose to sign in with your Google account, to authenticate you. We receive your email address and basic profile information from Google for that purpose.
We do not sell your data to any third party.
5. Cookies
sidestep uses only strictly necessary cookies set by Clerk for authentication session management, plus a cookie that remembers your chosen language. These cookies do not track you across sites and do not require your consent. No advertising or cross-site tracking cookies are used.
6. Retention
| Data | Retention period |
|---|---|
| Account data (email, persona, preferences) | Until you delete your account |
| Route geometry | Until you delete the route or your account |
| Telegram chat ID | Until you disconnect Telegram or delete your account |
| Alert delivery records | 90 days |
| Disruption data | 30 days after the disruption date, then removed |
7. Your rights under GDPR
As a data subject, you have the following rights:
Art. 15 — Right of access: You can request a copy of all personal data we hold about you. Use the "Export my data" option in your profile settings.
Art. 16 — Right to rectification: You can update your email, alert preferences, and route data directly in the app at any time.
Art. 17 — Right to erasure: You can delete your account from your profile settings. This permanently removes your account, all saved routes, and all alert records, and deletes your authentication record from our identity provider.
Art. 18 — Right to restriction: You can request that we restrict processing of your data while a dispute is being resolved.
Art. 20 — Right to data portability: You can export your data in machine-readable format (JSON) from your profile settings.
Art. 21 — Right to object: You can object to processing based on legitimate interest. In practice, you can stop all alert processing by deleting your routes.
To exercise any right or ask a question, contact: privacy@sidestep.fyi
You also have the right to lodge a complaint with the supervisory authority:
Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI)
Friedrichstr. 219, 10969 Berlin
mailbox@datenschutz-berlin.de
8. Security
Your route geometry is stored in a PostgreSQL database hosted on Railway. Access to the database is restricted to the service operator. We apply transport-layer encryption (TLS) on all connections.
9. Changes to this policy
We will notify you by email at least 14 days before any material changes to this policy. The date at the top of this page reflects the most recent update.
10. Contact
privacy@sidestep.fyi