In plain English: We collect the data we need to make DriveSidekick work — your drives, your scores, your progress. We never sell it, and we never share it with insurance companies, insurance brokers, price-comparison services, or advertisers — permanently, not just for now. Analytics on this website only run if you click "Accept" on the cookie banner. You can see, export, or delete everything we hold about you, any time.
DriveSidekick is run by a sole trader based in the United Kingdom, trading as DriveSidekick. Under data protection law, DriveSidekick is the "data controller" for the personal data described in this policy. That means we are responsible for looking after it.
Questions? Email us at [email protected]. A real person reads it.
This policy covers the DriveSidekick website (drivesidekick.uk) and the DriveSidekick mobile app. It is written to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
We will never sell your driving data, and we will never share your location traces, driving scores, or other driving data with insurance companies, insurance brokers, price-comparison services, or advertisers. Your driving data is used to give you feedback on your driving — nothing else. This is a permanent commitment, not a description of our current practice that we might change later. We are not, and will not become, funded by selling or sharing your driving data.
Your Driving Score is a post-drive performance metric we calculate from the location and sensor data recorded during a session you start. To be radically clear about it:
What your driving data IS used for:
All of this is processed for your account, to give you feedback — nothing else.
What your driving data is NEVER used for:
UK GDPR says we need a lawful reason for everything we do with your data. Here they are:
| What we do | Lawful basis |
|---|---|
| Record and score your practice drives, track your syllabus progress, and show your history — the core features you signed up for | Contract (we can't provide the service without it) |
| Collect location and sensor data during a session | Consent (you start each session yourself, and you can stop it or turn off permissions at any time) |
| Website and in-app analytics | Consent (the website asks via the cookie banner; nothing runs if you say no) |
| Crash and error reporting, so we can fix bugs | Legitimate interests (you can object — just email us) |
| Process payments and keep purchase records | Contract, plus a legal obligation to keep tax records |
| Form submissions (waitlist, feedback) | Consent (you choose to send the form) |
| Security logging on the website | Legitimate interests (keeping the site safe) |
We don't sell, rent, or trade your personal data — see our promise above. We do use trusted companies ("processors") to run the service. Each one only gets the data it needs, and each one is under a data processing agreement. Here is the full list:
| Company | What it does | Where |
|---|---|---|
| Supabase | Stores your account and driving data | US company (see transfer note below) |
| Mixpanel | Analytics (app, and website only after consent) | US company — we use its EU servers, so analytics data stays in the EU |
| Sentry | Crash and error reports | US company (see transfer note below) |
| Mapbox | Maps and routes inside the app | US company (see transfer note below) |
| RevenueCat | Manages in-app purchases | US company (see transfer note below) |
| Stripe | Payment processing for website purchases | US company with UK/EU entities |
| Cloudflare | Hosts this website | US company with UK/EU infrastructure |
| Tally | Forms (waitlist, feedback) | Belgium (EU — covered by UK adequacy rules) |
Transfer note: some of these companies are based outside the UK, mainly in the US. Where data leaves the UK, it is protected by legally approved safeguards — the UK Extension to the EU-US Data Privacy Framework, or the UK's International Data Transfer Agreement / standard contractual clauses. In short: UK-level protection travels with your data.
We will only share data beyond this list if the law requires it (for example, a court order), and we will tell you if we ever change this policy to add a new processor.
No insurers, ever: no insurance company, insurance broker, price-comparison service, or advertiser appears on this list, and none ever will. We will not add one, and we will not share your driving data with one — this is a permanent commitment.
| Data | Kept for |
|---|---|
| Account, drives, scores, and syllabus progress | Until you delete them or close your account, then removed from backups within 30 days |
| Analytics data (Mixpanel) | 24 months, then deleted |
| Crash reports (Sentry) | 90 days, then deleted |
| Form submissions (Tally) | 12 months, then deleted |
| Purchase records (Stripe) | 6 years — UK tax law requires this |
| Website security logs (Cloudflare) | A few days, handled automatically by Cloudflare |
You control your data. You can:
The fastest route: in the app, go to Settings → Account, where you can export your data or delete your account directly. Or email [email protected] — we respond within one month, usually much faster.
If you think we've handled your data badly, you can complain to the UK regulator, the Information Commissioner's Office (ICO). We'd appreciate the chance to fix it first.
Most of our users are 17 — that's who the app is for. Because many of you are legally children under UK data protection law, we hold ourselves to a higher standard: no advertising profiles, no selling data, no sharing with marketers, plain-English policies, and analytics that are off by default on this website. You don't need a parent's permission to use DriveSidekick, but you (or a parent) can exercise any of the rights above at any time. You must be at least 17 to use the app, which matches the minimum age for a UK provisional licence.
This website sets no optional cookies or tracking storage unless you accept them. Full details of what we store and for how long are in our Cookie Policy. You can change your mind any time using the "Cookie settings" link in the footer of every page.
Your data is encrypted on its way to and from our servers and while stored. Access is limited to the one person who runs DriveSidekick, and only when needed to operate the service or help you. No internet service can promise perfect security, but if a breach ever put your data at risk, we would tell you and the ICO promptly, as the law requires.
If we change this policy, we update the date at the top. For significant changes — like a new processor or a new type of data — we will tell app users directly before the change takes effect. We will never weaken the driving-data promise above.
Anything unclear, or anything you want to ask, see, or delete: [email protected]