Skip to content
Home

Your data. Your choices.

Privacy at DrivR

What the closed beta processes, who can see it and how to exercise your rights. Planned services are identified separately.

Updated 14 September 2026

Location sharing
You choose when to become visible.
Current hosting
Our own server in Málaga, Spain. Email has separate processing locations.
Need help?
Contact Silvester directly about your data.

On this page

  1. Who is responsible
  2. Your account, profile and garage
  3. Free Roam, convoy and location choices
  4. Recording, planning and navigation
  5. Clubs, events, messages and photos
  6. Profile photos, reports and moderation
  7. Where data goes
  8. How long data remains
  9. Download a copy of your account data
  10. Erase your account: scope and confirmation
  11. Cookies, local storage and device access
  12. Protection built into the service
  13. Your rights and how to ask
  14. Automated features and your choices
  15. Planned services — not active processing
  16. Changes and further information
On this page
  1. Who is responsible
  2. Your account, profile and garage
  3. Free Roam, convoy and location choices
  4. Recording, planning and navigation
  5. Clubs, events, messages and photos
  6. Profile photos, reports and moderation
  7. Where data goes
  8. How long data remains
  9. Download a copy of your account data
  10. Erase your account: scope and confirmation
  11. Cookies, local storage and device access
  12. Protection built into the service
  13. Your rights and how to ask
  14. Automated features and your choices
  15. Planned services — not active processing
  16. Changes and further information
01

Who is responsible

Silvester M. Wehmer, sole trader (autónomo) trading as JGSW Studio, is the controller for the DrivR website, portal, admin service and mobile apps. He is DrivR’s founder, developer and operator of its current hosting infrastructure.

Calle Actriz Rosario Pino 12, 29014 Málaga, Spain. Tax identification number: ESY5003488J.

Silvester is also your personal privacy contact, professionally certified as a data protection officer by TÜV Rheinland Akademie. This qualification is distinct from an independent statutory DPO appointment; he also acts as DrivR’s controller.

silvester@driv-r.com ↗Full legal notice ↗
02

Your account, profile and garage

We use your email, username, password hash, sign-in and session records to provide and protect your account. Passwords are stored as salted scrypt hashes. Email, username and a password are needed for an account; optional biography, city, Instagram username, vehicle details and photos are not. If you add Instagram, we store its username and show a profile link only to signed-in drivers who can view your DrivR profile. You can edit or remove it in your profile settings.

To limit abusive sign-in attempts, we use counters keyed by HMAC values derived from IP addresses and login identifiers. These are pseudonymous identifiers, not anonymous data. The counters are kept in Redis with expiry renewed when used: normally 10 minutes for IP counters and 15 minutes for login identifiers, with a configured maximum of 24 hours.

Profile and vehicle visibility settings control access by other signed-in users. Blocking is taken into account. Photos you select are resized into new JPEGs without the original EXIF/GPS metadata. The visible image itself may still reveal a number plate, person or place.

These account and community functions process data to provide the service you request (Article 6(1)(b) GDPR). Security checks serve our legitimate interest in protecting accounts and preventing abuse (Article 6(1)(f)).

03

Free Roam, convoy and location choices

Device location permission, private recording and sharing with other drivers are separate choices. Free Roam visibility must be started explicitly. Going visible also enables short-lived greetings from other visible drivers; it does not send a greeting or a contact request for you. You can mute or block unwanted contact. You can stop sharing or withdraw device permission; features that need your location then stop working or become limited.

The Free Roam visibility control shows precise location on a roughly 10-metre grid before you choose Go visible. Existing sessions that agreed to a 100-metre grid are not silently upgraded. The server receives your location sample and reduces it to the precision agreed for that sharing session before placing it in the live store. GPS and network conditions can make the actual location less accurate or less recent than the grid size. The app remembers your choice within the current signed-in runtime session; the web portal remembers it while this map page stays open. Sharing pauses in the background and resumes with a fresh location when you return. Leaving Free Roam pauses sharing in the app and ends it on the web. Go invisible cancels the remembered choice.

Other eligible signed-in map viewers can see your driver identity and recent shared position within the area they view, even if they are not visible themselves. Active maps request updates about once per second; moving drivers send new available location samples at about that rate. A smooth animation between received positions does not mean a new GPS measurement was received for every animation frame. This is location sharing, not anonymous tracking.

Rally convoy sharing is limited to eligible event participants and uses your event-specific sharing choice. Live positions expire after at most 45 seconds unless a new sample is sent; short control leases can last 60 seconds. Stopping or losing authorization invalidates live visibility. These limits do not apply to routes you deliberately record and save.

The event_live_consent record stores your event sharing choice, chosen precision and when that choice changed. These records persist beyond the 45/60-second live limits; they are not a history of your positions.

Nearby Cars & Coffee suggestions are calculated from short-lived visible positions; they do not automatically create a saved event. Optional sharing relies on your consent (Article 6(1)(a)), which you can withdraw for the future.

04

Recording, planning and navigation

Recording stores exact GPS points, timestamps, accuracy, stops and your route description in an account-specific file on your device. Uploading a recording is a separate action that saves a private copy on our server. Recording does not automatically publish it to your club.

Our route engine processes waypoints or recorded traces to calculate your requested route. Publishing or sharing a resulting route exposes its geometry and stops to the selected audience. Starting, pausing, discarding and correcting a recording are part of the requested service (Article 6(1)(b)). Screen-off recording uses a separate explicit mode and a local Android recording notification.

Screen-off rally navigation is another explicit GPS option in the mobile app. It keeps a private navigation checkpoint on the device so guidance can continue with the screen off. Pausing or finishing the drive, leaving the drive screen or signing out stops this mode. Enabling it does not start live sharing with other drivers. Operating-system permission and device restrictions still apply.

You can explicitly delete your uploaded recording and its private navigation-review candidates using the recording’s cloud-deletion control. A minimal deletion record without GPS points prevents an old save from restoring it. Routes already published as shared rally snapshots remain available to their audience. Deleting a local copy and deleting the cloud copy are separate actions; saved exports, copies on other devices and offline route packages are not remotely erased.

silvester@driv-r.com ↗
05

Clubs, events, messages and photos

We store memberships, club roles, invitations, event participation, schedules, waypoints, published route versions and your contributions to operate community features. Organizers and other members receive information according to the object’s visibility and their current rights. An organizer or admin may supply your invitation address or membership information; contacts and other participants supply the messages and interactions addressed to you.

Only the original club founder appoints additional founders. That role grants club management, not platform administration. A club logo belongs to the club and can remain when its uploader leaves. Revoking management access does not necessarily revoke otherwise permitted member access.

Direct messages are available between accepted contacts. We store the text and delivery/read-related records on our server. They are not end-to-end encrypted. Deleting your message removes its text and content hash, while a deletion marker and basic record can remain. These features use Article 6(1)(b). Recipients can keep copies they have already received.

06

Profile photos, reports and moderation

You can choose a separate personal profile photo, a garage photo or initials. Uploads are optional; providing your chosen profile identity is part of the requested service (Article 6(1)(b)). Other signed-in drivers can report the currently visible profile picture or story. We receive their account ID, the reported account, category, reason, optional explanation, time and a snapshot of the reported avatar or description.

Authorized moderators review reports to protect users and enforce community standards. We rely on our legitimate interest in preventing abuse and maintaining a safe service (Article 6(1)(f)). Reporting is not an automatic finding of a violation. Removal decisions are made by a moderator; we do not use automated AI image classification in this workflow. The reported driver is not shown the reporter’s identity. You can contact us about a decision or object to this processing using the rights described below.

Reports and their image/text evidence expire 90 days after creation and are then unavailable to moderation tools. A scheduled cleanup removes expired records in bounded batches, so physical deletion can follow expiry. Confirmed account erasure also removes reports involving that account. A separate administration audit retains the action, moderator, target account reference, decision reason and time under the security-audit rules below; it does not copy the reported image or story. Deployment recovery copies are subject to the backup limitations below.

silvester@driv-r.com ↗Community guidelines ↗
07

Where data goes

The current main application, databases, live store, routing and map tiles run on our own server in Málaga, Spain (EU). Our stack includes Next.js/React, React Native/Expo, NestJS, PostgreSQL/PostGIS, Redis, Valhalla, MapLibre and Docker. Software names do not imply that those projects receive your account or route data.

Map data is based on OpenStreetMap and regional source extracts. The deployed map and route services are self-hosted; your route requests are processed by DrivR’s services.

When you submit an address or place search, DrivR processes the text through its own search service. Your browser does not send that query directly to a third-party geocoder. Search results may be cached in server memory for up to 10 minutes under a hashed query key; we do not keep a persistent address-search history or log query text. A place you explicitly add to a saved route becomes part of that route.

Account recovery email is delivered through Resend (Plus Five Five, Inc.). It receives the destination address, email content and delivery metadata. Resend states that stored message content and delivery data are processed in the United States, including when an EU sending region is selected. Its data processing agreement incorporates EU Standard Contractual Clauses. See the linked safeguards or contact us for a copy. Your own email provider also processes delivered messages.

Authorized infrastructure administration can involve access to stored data where necessary for support, security or recovery. Dedicated platform admins have restricted application permissions and audited actions. Authorities or advisers may receive information where legally required or necessary to establish or defend claims (Articles 6(1)(c) or 6(1)(f), as applicable).

Resend: storage locations and retention ↗Resend data processing agreement and safeguards ↗
08

How long data remains

Different features have different retention rules. An expired login or an archived event is not the same as erasing its stored record. We assess deletion requests against the continuing service purpose, other participants’ rights, security needs and any applicable legal obligation; we explain a restriction when one applies.

Account export and erasure controls are described below. Records outside the confirmed erasure scope, including shared content and security audit records, have no universal automatic deletion period. Their continued retention needs a specific purpose and applicable basis; the presence of a record in the system does not itself justify keeping it indefinitely. Contact us for review of a particular retained record.

Configured container logs rotate by size rather than a fixed number of days. Retention for other host, proxy and database logs is not yet fully defined and verified. Deployment recovery copies and database backups are separate from active data; there is not yet a uniform, verified backup deletion interval. Immediate removal from every recovery copy is not promised. Please contact us about a particular record or deletion request.

  • Live positions and greetings: up to 45 seconds without renewal; short control leases: up to 60 seconds.
  • Normal sign-in sessions: usually valid for 14 days; admin sessions: up to 8 hours, with a 20-minute inactivity limit. Revocation may end access earlier.
  • Password reset links: valid for 30 minutes. Queued encrypted recovery content is removed after confirmed delivery, use or terminal failure.
  • Account exports: access lasts 15 minutes in the requesting session. Erasure previews: valid for 10 minutes. Erasure status receipts: usable for 30 days. These are technical access and recovery limits, not legal retention periods or promises that every metadata row is deleted at expiry. Expired grant, preview and receipt metadata is cleaned up opportunistically.
  • Current personal profile and vehicle photos are replaced or removed when you replace/delete them. A reported image may remain separately as restricted evidence for the report retention period. Club logos remain with their club until replaced, removed or the club is deleted.
  • Resend publishes 30-day email/log retention for its standard plans; enterprise terms can differ. Its own backup and termination periods are described in its linked notice.
  • Local drafts, preferences, downloaded maps and recordings remain until removed by their feature, device settings or app-data removal. Logging out does not erase every saved draft.
silvester@driv-r.com ↗
09

Download a copy of your account data

Account → Privacy and data offers a download after you confirm your current password. It includes account details, private routes and uploaded GPS recordings, stored photo derivatives and messages you sent. Protect the saved copy: it can contain precise locations and private content. If the control is unavailable, you can still contact us to request your data.

The export covers 39 fixed sections of accessible stored account data. It excludes incoming private message text, authentication and MFA secrets, tokens and provider payloads. Club content is included only while you have permission to read it. Current live positions held in Redis are not exported; the last_location and location_history sections have no stored SQL location history. Uploaded GPS recordings are a separate, persistent dataset and are included.

Where present, notification preferences are included in the profile section and your own registration and delivery metadata in security_activity. Expo tokens, provider ticket identifiers and internal delivery claim identifiers are excluded.

The file uses NDJSON: a manifest, data entries and a final completion record. Large records can span numbered chunks. Data is read page by page during the download (page_time capture), not as one atomic snapshot of the whole account. A detected change within a record being exported, loss of access, cancellation or an exceeded size limit stops the export; a partial file is not reported as complete. There is no server-side downloadable archive.

This self-service file has the scope above; it is not a complete response to every GDPR access or portability request. Contact us for additional records, processing information or review of an excluded category. The tool does not replace your rights or restrict how you may exercise them.

Privacy and data controls ↗silvester@driv-r.com ↗
10

Erase your account: scope and confirmation

The account privacy screen first shows what will be removed, what remains and any blockers. You then confirm your current password and explicitly approve erasure. The automatic process is blocked while you are the original owner of an active club, host a rally or meet that has not ended and is not cancelled, have any platform-admin record (even inactive), or have a billing-customer record requiring manual provider review. These are limits of the automatic tool, not a refusal of a legal request; contact us to resolve them or request an individual assessment.

Confirmed erasure removes the private profile, personal profile photos, reports and evidence involving your account, vehicles and vehicle photos, uploaded GPS recordings and private review candidates, unpublished personal routes, sign-in sessions and your sent message rows. The account becomes an inactive pseudonymous identifier for retained shared references; this is not full anonymization. Other senders’ messages and minimal shared conversation references remain, with your read timestamps removed.

Club-owned logos remain with their club after their uploader link is removed. Shared published route and rally snapshots, club-bound content and past or cancelled collaborative event records can remain. The preview also identifies retained financial records, security audits, the erasure receipt and backup copies where relevant. This describes the automatic deletion boundary, not an unlimited retention entitlement; you can ask us to review remaining personal data.

Only an explicit deleted confirmation establishes completion. A request can remain unknown even after the database change while invalidation of live access is being confirmed. Signing out, a failed login or an expired status receipt does not prove deletion. The device keeps a private recovery record so you can explicitly check the same request without signing in; do not share its secret. If the result remains unknown or that record is lost, contact us. Leaving the screen cannot undo a committed deletion.

Account-specific local cleanup does not remotely remove files you exported or shared, copies on other devices, or every older browser/app draft. Database backups and deployment recovery copies are not immediately rewritten; no uniform verified backup deletion interval is claimed. The retention and device-storage sections explain these remaining limits.

Privacy and data controls ↗Check a pending erasure on this device ↗silvester@driv-r.com ↗
11

Cookies, local storage and device access

The current beta uses storage for sign-in, security, your chosen preferences and recovering work. We do not use advertising cookies or audience analytics in this beta. The social links, including optional Instagram profile links, are ordinary external links; no embedded social SDK, feed or player is loaded. DrivR does not contact Instagram to display a profile link. Opening it takes you to Instagram, where its own privacy terms apply.

The website uses __Host-ltw_session and __Host-ltw_csrf for login and request protection (normally up to 14 days), and __Host-drivr_admin for admin authentication (up to 8 hours). The ltw_locale cookie remembers your selected language for one year. The ltw:web:theme preference is stored in localStorage until cleared.

The separate downloads page saves its language and appearance choices in localStorage as drivr.downloads.locale.v1 and drivr.downloads.appearance.v1. They remain until cleared; they do not use the website’s one-year language cookie.

The optional Getting started guide saves only review and dismissal choices in localStorage under drivr:onboarding:v1:<userId>, separately for each account in that browser, until cleared. It does not store profile details, positions or a server-side completion status. Confirmed account erasure clears the matching account’s guide key; other accounts’ choices remain. If browser storage is unavailable, the guide remains usable without saving these choices beyond the page.

Prepared mobile notification registration uses a random installation UUID in the operating system’s SecureStore, retained until app data is removed. This local installation identifier is not the push token. A requested Expo push token is held separately for registration; requesting one sends an identifier to Expo. Registration and delivery are not currently activated, as explained under planned services.

Route drafts and pending club/event operations use account-specific localStorage; some navigation retries use sessionStorage. Clearing browser data can remove unsaved work. The mobile app stores its session token in the operating system’s secure store. Recordings, offline maps and recovery drafts are app-private files, not all additionally encrypted by DrivR.

An erasure recovery record contains an operation identifier and a secret status token, not your password. The Web stores it in localStorage and the mobile app in secure storage so an uncertain request can be checked after sign-out or restart. The local record can outlast the server’s 30-day status-access limit; removing device/site data can destroy that recovery option. Export preparation uses temporary local storage or bounded browser memory. Copies you finish saving or sharing are under your control and must be removed separately.

The photo picker accesses the images you choose. The app does not request microphone access to record audio. Optional ambient-light and battery readings support local display/preflight behavior; navigation uses operating-system speech output. Device and operating-system services have their own settings and privacy terms.

12

Protection built into the service

We use HTTPS, password hashing, revocable sessions, origin and request-forgery checks, rate limits and object-level access checks. Admin access runs through a separate service with password plus TOTP and additional checks for sensitive actions. Database roles restrict application access; private image responses are authenticated and marked not to be cached.

These controls reduce risk. They are not a guarantee against every incident, an assertion of full disk encryption or a certification of GDPR compliance. The operator can technically access infrastructure data; messages and uploaded content are not end-to-end encrypted. Copies already saved by a recipient cannot be remotely recalled.

13

Your rights and how to ask

Contact Silvester by email or post for access, correction, erasure, restriction or portability where applicable. You may object to processing based on legitimate interests. You can withdraw optional sharing consent without affecting earlier lawful processing. You do not need an in-app button to make a request.

Tell us which account and request are involved. We only ask for additional identity evidence where necessary; do not send a password, sign-in token or identity document unless a proportionate verification method has been agreed.

We respond without undue delay, normally within one month. If a legally permitted extension is needed, we explain it within that month. Requests are generally free. You can complain to the Spanish Data Protection Agency (AEPD) or the authority in your habitual residence, place of work or place of the alleged infringement.

silvester@driv-r.com ↗AEPD: exercise your data protection rights ↗
14

Automated features and your choices

Route calculation, local driver discovery and Cars & Coffee suggestions process location or route inputs to return relevant results. The current beta does not use them to make solely automated decisions with legal or similarly significant effects about you. We do not sell personal data or use the beta for advertising profiling.

You can use account and planning features without making yourself visible on the live map. Without the data needed for a requested feature, that feature may be unavailable. Avoid placing sensitive personal information about yourself or others in a profile, message, photograph or route description.

15

Planned services — not active processing

The roadmap includes additional services. This notice is not blanket consent to activate them. Their data flows, providers, legal basis, retention and relevant controls will be explained before they start processing your data.

  • Paid membership and approved referral partners: planned web payments through Stripe, with payment status unlocking app access and referral attribution supporting commission accounting. Payment and referral processing are currently disabled. Provider notices and financial retention rules will be supplied before activation.
  • Push notifications: the mobile registration controls are prepared, but require an explicit button press, an EAS project configuration and an enabled server flag. An EAS project identifier alone does not activate delivery: native Apple/Google credentials and a separate provider worker are also required. Registration and delivery are disabled by default. The foreground inbox reads unread chats and incoming contact requests from DrivR while the app or portal is open, without sending their contents to a push provider. Chat and contact-request push preferences are separate from rally notices and start disabled. If push is enabled later, requesting an Expo push token shares an identifier with Expo; DrivR stores the registered token, notification preferences and expiry. Registration is valid for at most 30 days; this is a technical limit, not a promise of deletion on day 30. Removing the registration, revoking its bound session, deactivating the account or erasing it deletes its tokens and pending delivery rows. Expired rows require an explicit maintenance run; no scheduled worker is active. Push delivery through Expo, Apple or Google is not activated or qualified. Existing Android recording and navigation notices are local notifications, not evidence of live push delivery.
  • CarPlay, Android Auto and a wider community feed: planned interfaces and sharing surfaces; availability and permissions will be explained when introduced.
  • Azure and wider rollout: after public release, a move to Microsoft Azure datacentres with global reach is planned. Azure is not the current application host. Selected regions, replication, support access and any international-transfer safeguards must be set out before migration. Worldwide availability does not by itself require worldwide storage.
Microsoft: data location and privacy ↗
16

Changes and further information

This notice describes the current closed beta and clearly identified plans. Material changes to purposes, recipients or location sharing will be communicated before the new processing starts. You can ask for information about a particular processing activity or a copy of relevant transfer safeguards using the contact above.

General Data Protection Regulation ↗Legal notice ↗
Legal noticePrivacy
Back to top ↑