Last updated: 28 July 2026
Privacy Policy
This draft explains the personal data processed through Drivefino’s public website and instructor-management service.
1. Introduction and policy details
Version: Early access 1.0
Effective date: 28 July 2026
This policy applies to website visitors, prospective and registered instructors, support contacts, and people whose information an instructor enters into Drivefino. It does not replace an instructor’s own privacy notice.
2. Contacting Drivefino
Questions about this policy or Drivefino’s handling of personal data can be sent to support@drivefino.com or submitted through the Privacy and Data Requests page.
3. When Drivefino is controller or processor
Drivefino is a controller for its own website, account administration, subscription billing, support, security and business records. An instructor is generally the controller of the student, parent, guardian, emergency-contact, lesson, note and document data they choose to manage. Drivefino generally acts as that customer’s processor for such customer-controlled data.
Students and their representatives should normally contact the relevant instructor about instructor-managed records. Drivefino will assist customers with verified requests where required. The standalone Data Processing Agreement is the intended Article 28 agreement and this summary is not a substitute for it.
4. Personal data collected and its sources
Data comes from instructors and authorised account users, people who contact Drivefino, instructors who enter information about students and related contacts, the devices used to access the service, and service providers such as Stripe.
- Account and profile data: name, business name, email, phone, instructor/licence and optional tax identifier, country, language, locale, currency and timezone.
- Student and related-person data: names, contact and emergency-contact details, licence details, transmission preference, status and free-form notes.
- Lesson data: dates, locations, status, price, paid/unpaid status, skills, strengths, weaknesses, homework and goals.
- Uploaded files, document metadata, share recipients, access tokens and sharing activity.
- Authentication tokens, account and audit events, timestamps, and operational/security logs. The current audit model does not establish a general IP-address or user-agent ledger.
- Support, security, legal and privacy-request correspondence.
- Stripe customer/subscription identifiers, selected plan and currency, periods, cancellation and payment/invoice status. Drivefino does not receive full card details through its integration.
- Consent-gated website analytics and the first-party cookie-choice record.
5. Processing purposes, legal bases and retention
Legal bases below apply when Drivefino acts as controller. When Drivefino is a processor, the customer determines its own lawful basis and gives documented instructions.
| Processing activity | Data categories | Purpose | Legal basis | Retention/criteria |
|---|---|---|---|---|
| Account registration and authentication | Name, business, contact, credentials, country/locale, tokens | Create, authenticate and protect an account | Contract; legitimate interests in security | For the account’s life and as needed afterward for security or legal records |
| Customer service and operations | Instructor profile, settings, students, bookings, notes, prices and payment status | Provide the instructor-management service | Contract for customer data; customer instructions for student data | While the customer uses the service; longer where needed for legal obligations or disputes |
| Documents and sharing | Files, metadata, recipients and access/share records | Store and share customer-selected documents | Contract; customer instructions | Until deleted or the account ends; backup copies may expire later |
| Subscription billing | Business/contact details, Stripe IDs, plan, currency, invoice/payment/subscription status | Checkout, renewal, account access, accounting and disputes | Contract; legal obligation; legitimate interests | For the subscription and afterward as required for accounting, tax or disputes |
| Transactional email | Recipient, message content, event and delivery records | Verification, recovery and service/lesson/document notices | Contract; legitimate interests; customer instructions | As needed to deliver, troubleshoot and evidence service communications |
| Security and audit | Account IDs, timestamps, actions, technical logs and security events | Prevent misuse, investigate incidents and protect tenants | Legitimate interests; legal obligation where applicable | For as long as reasonably needed for security, investigation and legal claims |
| Support and privacy requests | Messages, contact details, verification and case correspondence | Respond, verify, keep an audit trail and establish legal claims | Contract; legal obligation; legitimate interests | For as long as needed to resolve the request and retain an appropriate record |
| Optional website analytics | Cookie choice, online identifier, page/session, device/browser and approximate location | Measure and improve the marketing website | Consent | Cookie choice: 180 days; analytics data follows the configured GA4 retention period |
Owner approval of concrete retention periods is still required. “Legitimate interests” is used only where the operator concludes its operational or security interest is not overridden by the person’s rights.
6. Students, parents, guardians and minors
The current product is an instructor-facing business tool; students do not have self-service accounts. Instructors must provide appropriate notices and have authority to enter student, parent, guardian and emergency-contact information. A parent, guardian or authorised representative may make a request, but identity and authority may need verification.
7. Lesson notes, documents and sensitive data
Free-form notes and uploaded documents can contain information selected by a customer. Customers should not enter medical, disability, criminal-offence, biometric or other special-category/sensitive information unless it is necessary, lawful, appropriately disclosed and protected. Drivefino does not require customers to store full identity-document scans merely to operate an account.
8. Website analytics and cookie choices
The marketing website stores a necessary first-party choice record for 180 days. Google Analytics 4 loads only after Analytics is enabled. The implementation can send page/session, device/browser, approximate-location and online-identifier data; it does not intentionally send form contents, names, emails or phone numbers. Analytics consent can be withdrawn in Cookie Settings.
See the Cookie Policy. No marketing-email system or advertising tag was verified. Drivefino will update this policy before introducing either.
9. Authentication, security and service notifications
Drivefino processes credentials and tokens to register, verify, sign in and recover accounts. Passwords are stored as Argon2 hashes and refresh tokens as hashes. It records authentication and some billing/security events. Transactional emails include account verification and recovery, registration alerts, booking/reminder/cancellation notices and document-share messages. These are service communications, not verified marketing campaigns.
10. Service providers
Current service integrations are Stripe for subscription billing, Resend for transactional email, Cloudflare R2 for private document storage and Google Analytics 4 for consenting marketing-site visitors. Core application operation also relies on hosting, database and queue infrastructure.
11. International transfers
Some service providers may process data outside the person’s country, the UK, Canada or the EEA. Drivefino does not claim that data remains in the EEA. Where data-protection law restricts a transfer, Drivefino will use an available legal transfer mechanism and appropriate safeguards.
12. Security
Measures evidenced in the product include tenant-scoped access controls, private object storage, expiring signed file links, TLS at the reverse proxy, hashed passwords/tokens and signature-verified Stripe webhooks. These measures reduce risk but cannot guarantee complete security. See Security and report suspected issues to support@drivefino.com.
13. Retention, deletion and backups
Drivefino keeps data while it is needed to provide and secure the service, meet legal or accounting obligations, resolve disputes and handle requests. Archive or soft deletion is not necessarily erasure. Some records may be retained where the law permits or requires it. Deletion from active systems may not immediately remove protected backup copies, which are removed through the applicable backup cycle.
14. Individual rights, verification and response timing
Depending on applicable law, a person may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. Requests are normally free, although legally permitted limits may apply to manifestly unfounded or excessive requests. Drivefino may request proportionate information to verify identity, authority and the relevant account without asking users to email passwords, card details, medical records or unnecessary identity documents.
Drivefino intends to respond within the period required by applicable law (often one month under GDPR/UK GDPR, subject to permitted extensions), but counsel must confirm the rule for each request and jurisdiction. Use Privacy and Data Requests.
15. Complaints
You may complain to the supervisory authority where you live or work, or where an alleged infringement occurred. This may include Ireland’s Data Protection Commission, the UK Information Commissioner’s Office, an EU/EEA national authority, or the applicable Canadian federal/provincial privacy authority. The operator’s lead supervisory authority cannot be identified until establishment details are confirmed.
16. Automated decisions
No automated decision-making producing legal or similarly significant effects was found in the current product.
17. Early access, changes and contact
Drivefino is currently in an early-access validation stage. Functionality and operational procedures may develop, but the current policy will be updated before materially different processing begins.
Material changes will be dated and versioned. Where required, customers will receive notice or be asked to accept updated contractual documents. Privacy Policy acknowledgement will not be treated as consent to every processing activity.
Contact support@drivefino.com, visit Contact, or use Privacy and Data Requests.