MinDriveTime privacy policy

This document is a starting template. Have a licensed attorney review it before launch.

[Last updated: DATE]

This policy describes how [Company legal name] ("MinDriveTime", "we", "us") handles your information when you use mindrivetime.com and our mobile, watch, and desktop apps (together, the "Service").

1. The short version

The rest of this policy spells out the details.

2. What we collect

Account information. Your email address, display name if you set one, subscription tier, and account settings.

Location. With your permission, the app uses approximate and precise device location to detect when you are at a saved place, to time your drives, and to position hazard alerts. Precise location is processed on your device as described in section 3. If you deny location permission, departure predictions still work for routes you enter manually.

Saved places and routes. The places you save (such as home and work), the routes between them, and your schedule preferences. These sync encrypted between your own devices through your account.

Device and usage telemetry. Device model, operating system version, app version, crash reports, feature usage events, and performance metrics. We use this to fix bugs and improve the Service.

Payment information. Stripe processes web payments. We receive your subscription status, the last four digits of your card, and the card brand so we can show you your billing state. We never receive or store your full card number. App store purchases are processed by Apple or Google under their policies.

Support communications. Emails you send to support@mindrivetime.com or privacy@mindrivetime.com.

3. On-device learning

The app learns your recurring places, typical departure windows, and drive patterns using a model that runs on your device. This precise place-learning data does not leave the device. It is not uploaded to our servers, not included in telemetry, and not recoverable by us. If you delete the app, that learned model is deleted with it.

4. What leaves the device

To improve predictions for everyone, the app contributes corridor timing samples to a shared cache. Each sample records how long a section of road took to traverse, keyed only by:

Samples are anonymized and aggregated before use. They contain no account identifier, no device identifier, no trip origin or destination, and no full trajectory. We cannot link a sample back to you, and we design the pipeline so no one else can either. You can turn off contribution in settings; predictions still work using the shared cache built from other contributions.

5. Third-party processors

We share data only with processors that help us run the Service, under contracts that limit what they can do with it:

ProcessorPurposeWhat they receive
StripeBilling for web purchasesEmail, payment details you enter with Stripe, subscription status
Traffic, weather, and toll data providersLive conditions and hazard dataAnonymized road-section queries; never your identity or account
Microsoft AzureHosting and storageAccount data and synced routes, encrypted
Analytics providerAggregate usage statistics and crash reportingPseudonymous telemetry described in section 2

Apple and Google process purchases made through their stores under their own policies. We do not send your saved places or routes to traffic or weather providers with your identity attached.

6. No sale of personal data

We do not sell your personal data. We do not sell or share your location data with anyone, including data brokers and advertisers, and we do not use it for targeted advertising. "Share" here includes the CPRA meaning of cross-context behavioral advertising.

7. Data retention

8. Your rights

Depending on where you live, including under the GDPR (EU/UK) and the CCPA/CPRA (California), you have the right to:

To exercise any right, email privacy@mindrivetime.com from your account email, or use the in-app account tools for access and deletion. We respond within the time the applicable law requires (generally 30 days under GDPR, 45 days under CCPA). We may ask you to verify your identity first. You may use an authorized agent where the law allows. If we refuse a request, we will explain why, and you may appeal by replying to our decision or complain to your local supervisory authority or the California Attorney General.

Our GDPR lawful bases: contract performance (running the Service you signed up for), consent (location permission, optional telemetry), legitimate interests (security, fraud prevention, service improvement), and legal obligation (tax and accounting records).

9. Children

The Service is not directed to children. We do not knowingly collect personal data from children under 13, or under 16 where that is the applicable threshold. Our terms require users to be 18 or older. If you believe a child has given us personal data, email privacy@mindrivetime.com and we will delete it.

10. Cookies on the website

mindrivetime.com uses:

We do not use advertising cookies. We honor Global Privacy Control signals as an opt-out where the law gives them effect.

11. International transfers

We host the Service on Microsoft Azure. If you use the Service from outside the hosting region, your data crosses borders. For transfers out of the EU, UK, or Switzerland, we rely on standard contractual clauses and equivalent safeguards with our processors.

12. Security

We protect your data with encryption in transit (TLS) and at rest, access controls that limit staff access to what their role requires, and logging and monitoring of our systems. No system is perfectly secure, but we design for the principle that the most sensitive data, your precise places and patterns, never reaches our servers at all.

13. If a breach happens

If a breach affects your personal data, we will notify you and the relevant authorities as the applicable law requires (for GDPR, authority notification within 72 hours of our becoming aware where required). Our notice will describe what happened, what data was involved, and what we and you can do about it.

14. Changes to this policy

We may update this policy. For material changes we will notify you by email or in the app before the change takes effect, and we will update the date at the top. Earlier versions are available on request.

15. Contact

Privacy questions and rights requests: privacy@mindrivetime.com General support: support@mindrivetime.com

EU/UK residents may also contact their local data protection authority.