Schedule a free consultation
Electric scooters and personal data — what should we know?

Electric Scooters and Personal Data
You are standing in the city center, running late for a meeting, and a few meters away you spot an available electric scooter. You open the corresponding service app on your phone, scan the code, and set off. From a user's perspective, it is a simple process: find the scooter, unlock it, ride, and park. From the perspective of a digital system, however, significant information about you is generated during these few minutes.
Riding an electric scooter is no longer just about moving down the street. It is a service that integrates a mobile application, a map, phone location tracking, bank payments, sensors embedded in the scooter, and customer support. Each of these components generates data. Therefore, it is important to understand what happens from the moment the app is downloaded until the ride is completed, and even thereafter.
Initial Data Collected Prior to Registration
The processing of personal data may begin even before an account is created. Upon opening the app, the system may collect details regarding the phone model, operating system, app version, language settings, IP address, and technical errors. This information is utilized to ensure the proper functionality, security, and technical troubleshooting of the application.
An IP address, unique device identifiers, and other technical markers—particularly when cross-referenced—can point to a specific user. Georgian legislation also defines personal data as any information that enables the direct or indirect identification of an individual, including geolocation and electronic communication identifiers.
Registration
To build an account, the application typically requests a phone number or an email address. It may also require entering a name, password, date of birth, or other details. A one-time verification code sent to the phone confirms that you indeed have access to the number, thereby mitigating the risk of fraudulent accounts and unauthorized profile use.
Occasionally, companies may require age or identity verification. This process might involve uploading an identification document or a photograph. The core principle here is data minimization: only necessary information should be collected. If a date of birth or another simple method suffices to verify age, permanently retaining a full copy of an ID card may be excessive.
One of the fundamental principles of personal data protection is proportionality: a company should not collect information merely because it is technically feasible to do so. Only data that is strictly necessary for a specific, predetermined purpose should be processed.
What Are We Agreeing To?
During registration, we often check a small box indicating: "I agree to the Terms and Conditions and Privacy Policy." Many accept these without reading in order to start their ride quickly. However, a company cannot shield itself from accountability behind a single consent button.
Users must easily understand who is processing their data, what is collected, why it is needed, who it might be shared with, whether the information is transferred internationally, how long it is retained, and how they can exercise their rights. Georgian law requires this information to be provided prior to or at the start of data collection. The text must be clear, particularly when services may be utilized by minors.
Not all data processing relies on consent. Processing a phone number, payment details, and basic trip records is necessary to perform the service itself: otherwise, the company cannot unlock the scooter, calculate the fare, or process the transaction. Separate opt-ins should be provided for marketing communications, additional tracking, or personalization features.
Consequently, "I agree to all" should not grant a company the right to use any data for any arbitrary purpose. Users must be able to utilize the core service without having to opt into non-essential auxiliary features.
Payment Data
After creating an account, the user adds a payment method. While card numbers, expiration dates, and security codes are entered, this does not mean all this sensitive information is stored directly by the scooter company. Payments are often processed through secure third-party banks or specialized payment gateway providers, leaving only a technical token in the app for future transactions.
Users should be explicitly informed about who processes their financial data and who is responsible for its security. The company must not retain comprehensive financial records beyond what is strictly necessary. Post-trip transaction records may be kept to handle refunds, disputes, accounting, or tax compliance requirements.
Payment history constitutes personal data because it is linked to a specific user, time, and service. Therefore, protection must extend not only to the card number itself but also to records indicating when, how much, and for which specific rides the user paid.
Location
To locate a scooter, the app requires access to our location. A point on the map shows our current position, while icons indicate where available scooters are parked. Without location services, users cannot search for transport, and companies cannot determine if a ride can be initiated or terminated within a designated zone.
However, location data is highly revealing. While a single route might merely show a commute to work, an extensive trip history can establish a detailed portrait of an individual's daily life: where they live, where they work, what establishments they visit, and what time they return home.
Using location data to locate scooters and manage active trips is a legitimate purpose. Using the same history to build detailed user profiles or serve targeted advertising constitutes a separate purpose and requires independent justification.
The app should not mandate continuous background location access if the service performs adequately with permissions granted only while using the application. Users should be able to select within their phone settings whether to share location constantly, only while using the app, or not at all.
QR Codes
When scanning a QR code, the system associates our account with a specific physical scooter. The start time, scooter ID, location, active tariff, and often the battery level are recorded. From this moment, the company knows that a specific user is operating a designated vehicle at a specific time.
This association is essential for service delivery and establishing liability. If a scooter is damaged, parked in a restricted area, or incorrectly billed, these records assist in resolving the issue.
However, the justification "we might need this in the future" is not sufficient grounds for indefinite data retention. Companies must define beforehand which information is kept for a few hours, a few months, or longer, and justify why.
What Does the System Learn During a Ride?
Data collection is not limited to mobile devices. Scooters may feature integrated GPS, speedometers, accelerometers, and other sensors. With these, the system logs the route, speed, hard braking, sudden acceleration, or entry into prohibited zones.
This information serves safety, maintenance, and compliance enforcement. For instance, publicly available micromobility policies describe using sensors to detect tandem riding, harsh braking, skidding, speeding, collisions, and improper parking. While technology suites vary by company, this example highlights how granular trip data can become.
The fundamental question remains: is each data point strictly necessary for a specified purpose? Detecting a hard impact to identify an accident may be justified, but retaining all user movements indefinitely under the banner of safety is not.
The golden rule of data protection states: collect only what is necessary, use it solely for the disclosed purpose, retain it only for the required duration, and secure it diligently.
When the Software Deems You a "Bad Driver"
Based on sensor data, the system may generate a user safety rating. Frequent harsh braking, rapid acceleration, riding in restricted zones, or illegal parking can trigger warnings, supplementary penalties, or temporary account suspensions.
Issues arise when such decisions are fully automated without providing explanations to the user. Sensors can malfunction, GPS accuracy can drift, another person may have moved the scooter, or the software might misinterpret an event.
If an automated decision carries significant consequences for a user, they must have the right to understand the underlying reasoning, present their side of the story, and request human review. Georgian legislation provides special protections regarding fully automated decisions that carry material consequences, including those based on behavioral profiling.
Ending a Ride and Parking Photos
At your destination, you tap "End Ride" in the app, but you are typically prompted to ensure the scooter is in a permitted zone, parked correctly, and to submit a photo. This photo verifies that the scooter is not blocking sidewalks, building entrances, ramps, or emergency exits.
The camera frame may inadvertently capture the faces of pedestrians, vehicle license plates, private yards, or other details extraneous to verifying parking compliance. Users should aim to photograph only the scooter and its immediate surroundings, and companies must safeguard these photos from being used for facial recognition or unrelated profiling.
Some systems use staff to review these photos, while others employ artificial intelligence. Public micromobility policies describe automated image analysis that rejects ride termination if incorrect parking is detected. While such automated checks assist in maintaining municipal order, users must be provided with a streamlined path to appeal errors.
Interactions with Customer Support Are Also Data
If a scooter failing to unlock, a double charge, or an incomplete trip cancellation occurs, the user contacts support. In chats, emails, or phone calls, we share names, numbers, routes, payment details, and issue descriptions. Occasionally, photos or redacted bank statements are also submitted.
The company must only request information necessary to resolve the support ticket. Support agents should not have access to complete user histories if viewing a single trip is sufficient. Users should also be informed if conversations are recorded, how long correspondence is retained, and whether it is analyzed for quality assurance.
With Whom Is This Information Shared?
Behind a single application, there are often multiple auxiliary service organizations. Maps may be provided by one provider, payments processed by a bank, notifications pushed by a communication platform, data hosted on cloud storage, and physical maintenance handled by a local operating partner.
While users do not need to read every technical service agreement, they should be informed of the general categories of data recipients and the reasons for transfer. Partners must not receive more information than is strictly necessary to perform their specific tasks.
If data is transferred or stored internationally, users must be notified, and appropriate transfer safeguards must be implemented. International mobility providers may share data with group corporate affiliates, technology partners, and infrastructure providers operating across various jurisdictions.
What Remains After the Ride?
Locking a scooter does not automatically erase your data. The system may retain trip durations, route segments, pricing, the scooter ID used, payment statuses, incident logs, parking photos, and support interactions.
Retaining certain records is necessary for processing refunds, resolving disputes, detecting fraud, tax accounting, or compliance with legal mandates. However, not all data categories should share the same retention schedules.
Financial records may be kept longer than technical logs or parking photographs. Under Georgian legislation, once the specified processing purpose is fulfilled, data must be deleted, destroyed, or fully anonymized, unless alternative legal retention requirements apply.
Deleting an account also does not always guarantee instantaneous, complete data erasure. Records necessary for ongoing disputes or financial liabilities may be retained, but companies must define which data is retained, why, and for how long. Simply deleting the app from your mobile device does not equate to deleting your account and associated records from the service provider's systems.
How Should Companies Protect This Data?
Scooter services compile account, location, financial, and behavioral records. A data breach could lead to account takeovers, financial fraud, or the exposure of an individual's historic physical movements.
Companies must implement secure data transmission and storage protocols, restrict internal employee access, log system activities, monitor for suspicious logins, and establish incident response frameworks. Security measures must correspond to the volume, categories, and potential risks associated with the processed data.
For particularly high-risk and large-scale analytical processing, companies should perform prior impact assessments to identify risks to user rights and establish mitigation strategies. When technology compiles systematic movement profiles or automates highly consequential user decisions, data security cannot be treated as a minor developer task.
User diligence is equally vital; users should adopt unique passwords, avoid sharing one-time verification codes, secure mobile devices with screen locks, and periodically review location, camera, and background app permissions.
What Are Your Rights as a User?
Users have the right to ask companies: What data do you hold about me? How was it collected? For what purpose is it processed? With whom has it been shared? How long will it be retained?
You have the right to request copies of your data, correct inaccuracies, object to processing under certain conditions, and request data erasure or restriction. You can also opt out of direct marketing and contest significant automated decisions.
An easily accessible privacy contact channel should be available in the app or on the corporate website. Users should not have to navigate complex support chat trees merely to exercise their privacy rights.
If a company fails to address a legitimate rights request, or if a user believes their data has been processed unlawfully, they have the right to lodge a complaint with the Personal Data Protection Service of Georgia or seek judicial remedy.
Before We Tap "Start Ride"
Forgoing electric scooters entirely is not the only way to safeguard your privacy. Several practical habits can help: review which fields are mandatory during registration; restrict location services to "While Using the App" unless constant access is strictly necessary; opt out of optional marketing preferences; avoid capturing bystanders in parking photos; verify that your ride session is fully terminated in-app upon parking; and check the account deletion process if you decide to stop using the service.
An electric scooter is more than just wheels, a battery, and an app. Every trip constructs a narrative—who unlocked the vehicle, where the trip began, the path taken, riding behaviors, where it was parked, and how payment was completed.
While this data can render services more efficient, safe, and convenient, it can also map out an incredibly detailed view of an individual's private life.
An exemplary service is one that provides safe transport while demonstrating deep respect for personal privacy. Physical tire tracks on a city street disappear quickly, but digital footprints can endure. Therefore, their collection, use, and retention must always be transparent, justified, and secure.
Author: Kakhaber Goshadze — Data Protection Trainer
Change of language
