Skip to main content

Last updated: 28 July 2026

Privacy Policy

This draft explains the personal data processed through Drivefino’s public website and instructor-management service.

Early-access notice. Drivefino is currently in an early-access validation stage. Product features and these terms may develop as the service is tested and improved.

1. Introduction and policy details

Version: Early access 1.0

Effective date: 28 July 2026

This policy applies to website visitors, prospective and registered instructors, support contacts, and people whose information an instructor enters into Drivefino. It does not replace an instructor’s own privacy notice.

2. Contacting Drivefino

Questions about this policy or Drivefino’s handling of personal data can be sent to support@drivefino.com or submitted through the Privacy and Data Requests page.

3. When Drivefino is controller or processor

Drivefino is a controller for its own website, account administration, subscription billing, support, security and business records. An instructor is generally the controller of the student, parent, guardian, emergency-contact, lesson, note and document data they choose to manage. Drivefino generally acts as that customer’s processor for such customer-controlled data.

Students and their representatives should normally contact the relevant instructor about instructor-managed records. Drivefino will assist customers with verified requests where required. The standalone Data Processing Agreement is the intended Article 28 agreement and this summary is not a substitute for it.

4. Personal data collected and its sources

Data comes from instructors and authorised account users, people who contact Drivefino, instructors who enter information about students and related contacts, the devices used to access the service, and service providers such as Stripe.

  • Account and profile data: name, business name, email, phone, instructor/licence and optional tax identifier, country, language, locale, currency and timezone.
  • Student and related-person data: names, contact and emergency-contact details, licence details, transmission preference, status and free-form notes.
  • Lesson data: dates, locations, status, price, paid/unpaid status, skills, strengths, weaknesses, homework and goals.
  • Uploaded files, document metadata, share recipients, access tokens and sharing activity.
  • Authentication tokens, account and audit events, timestamps, and operational/security logs. The current audit model does not establish a general IP-address or user-agent ledger.
  • Support, security, legal and privacy-request correspondence.
  • Stripe customer/subscription identifiers, selected plan and currency, periods, cancellation and payment/invoice status. Drivefino does not receive full card details through its integration.
  • Consent-gated website analytics and the first-party cookie-choice record.

5. Processing purposes, legal bases and retention

Legal bases below apply when Drivefino acts as controller. When Drivefino is a processor, the customer determines its own lawful basis and gives documented instructions.

Processing activityData categoriesPurposeLegal basisRetention/criteria
Account registration and authenticationName, business, contact, credentials, country/locale, tokensCreate, authenticate and protect an accountContract; legitimate interests in securityFor the account’s life and as needed afterward for security or legal records
Customer service and operationsInstructor profile, settings, students, bookings, notes, prices and payment statusProvide the instructor-management serviceContract for customer data; customer instructions for student dataWhile the customer uses the service; longer where needed for legal obligations or disputes
Documents and sharingFiles, metadata, recipients and access/share recordsStore and share customer-selected documentsContract; customer instructionsUntil deleted or the account ends; backup copies may expire later
Subscription billingBusiness/contact details, Stripe IDs, plan, currency, invoice/payment/subscription statusCheckout, renewal, account access, accounting and disputesContract; legal obligation; legitimate interestsFor the subscription and afterward as required for accounting, tax or disputes
Transactional emailRecipient, message content, event and delivery recordsVerification, recovery and service/lesson/document noticesContract; legitimate interests; customer instructionsAs needed to deliver, troubleshoot and evidence service communications
Security and auditAccount IDs, timestamps, actions, technical logs and security eventsPrevent misuse, investigate incidents and protect tenantsLegitimate interests; legal obligation where applicableFor as long as reasonably needed for security, investigation and legal claims
Support and privacy requestsMessages, contact details, verification and case correspondenceRespond, verify, keep an audit trail and establish legal claimsContract; legal obligation; legitimate interestsFor as long as needed to resolve the request and retain an appropriate record
Optional website analyticsCookie choice, online identifier, page/session, device/browser and approximate locationMeasure and improve the marketing websiteConsentCookie choice: 180 days; analytics data follows the configured GA4 retention period

Owner approval of concrete retention periods is still required. “Legitimate interests” is used only where the operator concludes its operational or security interest is not overridden by the person’s rights.

6. Students, parents, guardians and minors

The current product is an instructor-facing business tool; students do not have self-service accounts. Instructors must provide appropriate notices and have authority to enter student, parent, guardian and emergency-contact information. A parent, guardian or authorised representative may make a request, but identity and authority may need verification.

7. Lesson notes, documents and sensitive data

Free-form notes and uploaded documents can contain information selected by a customer. Customers should not enter medical, disability, criminal-offence, biometric or other special-category/sensitive information unless it is necessary, lawful, appropriately disclosed and protected. Drivefino does not require customers to store full identity-document scans merely to operate an account.

8. Website analytics and cookie choices

The marketing website stores a necessary first-party choice record for 180 days. Google Analytics 4 loads only after Analytics is enabled. The implementation can send page/session, device/browser, approximate-location and online-identifier data; it does not intentionally send form contents, names, emails or phone numbers. Analytics consent can be withdrawn in Cookie Settings.

See the Cookie Policy. No marketing-email system or advertising tag was verified. Drivefino will update this policy before introducing either.

9. Authentication, security and service notifications

Drivefino processes credentials and tokens to register, verify, sign in and recover accounts. Passwords are stored as Argon2 hashes and refresh tokens as hashes. It records authentication and some billing/security events. Transactional emails include account verification and recovery, registration alerts, booking/reminder/cancellation notices and document-share messages. These are service communications, not verified marketing campaigns.

10. Service providers

Current service integrations are Stripe for subscription billing, Resend for transactional email, Cloudflare R2 for private document storage and Google Analytics 4 for consenting marketing-site visitors. Core application operation also relies on hosting, database and queue infrastructure.

11. International transfers

Some service providers may process data outside the person’s country, the UK, Canada or the EEA. Drivefino does not claim that data remains in the EEA. Where data-protection law restricts a transfer, Drivefino will use an available legal transfer mechanism and appropriate safeguards.

12. Security

Measures evidenced in the product include tenant-scoped access controls, private object storage, expiring signed file links, TLS at the reverse proxy, hashed passwords/tokens and signature-verified Stripe webhooks. These measures reduce risk but cannot guarantee complete security. See Security and report suspected issues to support@drivefino.com.

13. Retention, deletion and backups

Drivefino keeps data while it is needed to provide and secure the service, meet legal or accounting obligations, resolve disputes and handle requests. Archive or soft deletion is not necessarily erasure. Some records may be retained where the law permits or requires it. Deletion from active systems may not immediately remove protected backup copies, which are removed through the applicable backup cycle.

14. Individual rights, verification and response timing

Depending on applicable law, a person may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. Requests are normally free, although legally permitted limits may apply to manifestly unfounded or excessive requests. Drivefino may request proportionate information to verify identity, authority and the relevant account without asking users to email passwords, card details, medical records or unnecessary identity documents.

Drivefino intends to respond within the period required by applicable law (often one month under GDPR/UK GDPR, subject to permitted extensions), but counsel must confirm the rule for each request and jurisdiction. Use Privacy and Data Requests.

15. Complaints

You may complain to the supervisory authority where you live or work, or where an alleged infringement occurred. This may include Ireland’s Data Protection Commission, the UK Information Commissioner’s Office, an EU/EEA national authority, or the applicable Canadian federal/provincial privacy authority. The operator’s lead supervisory authority cannot be identified until establishment details are confirmed.

16. Automated decisions

No automated decision-making producing legal or similarly significant effects was found in the current product.

17. Early access, changes and contact

Drivefino is currently in an early-access validation stage. Functionality and operational procedures may develop, but the current policy will be updated before materially different processing begins.

Material changes will be dated and versioned. Where required, customers will receive notice or be asked to accept updated contractual documents. Privacy Policy acknowledgement will not be treated as consent to every processing activity.

Contact support@drivefino.com, visit Contact, or use Privacy and Data Requests.