Privacy Policy

What Drive Dash AI collects, why, who it is shared with, how long it is kept, and what rights you have. Written against how the software actually behaves.

Last updated:

1. Introduction and scope

Drive Dash AI (Shield Driving Center LLC d/b/a Driver Ed Consultants, a Pennsylvania limited liability company, "Drive Dash AI", "we", and "us") provides a business-to-business marketing platform for driving schools. Our address is 6047 Allentown Blvd, Suite B-118, Harrisburg, PA 17112 and you can reach us at brad@driveredconsultants.com. This policy covers the drivedashai.com website and the Drive Dash AI application.

The service is sold to businesses. It is not a consumer product, not a student information system, and there is no consumer-facing account.

Our two roles

The distinction below determines which data protection duties apply to which data, so we state it up front.

Our roleWhich dataWhat that means
ControllerData about our own customer relationship: the account and login records of your staff, organization, and billing records, support conversations, demo requests, and the operational logs we need to run and secure the service.We decide why and how this data is processed, and this policy is the governing document for it.
ProcessorThe business data you put into or connect to the platform: business profile and location details, Google Business Profile content, connected social accounts and their posts and metrics, website crawl results, reviews and replies, measurement history, and generated drafts.You are the controller and we act only on your instructions. Our formal commitments are in the Data Processing Addendum, which prevails over this policy for that data.

Related documents: the Terms of Service (the contract), the Data Processing Addendum (our processor obligations), the Technology and Acceptable Use Policy (how the technology works and what you may not do with it), the Cookie Policy, and the Subprocessors page (every third party that receives data). Where one of those is the formal instrument, we cross-link rather than restate.

How we name platforms in this policy

We name the service you actually connect in the product — Google Business Profile, Google Analytics, YouTube, Facebook, Instagram, TikTok, X, LinkedIn, or Pinterest — because that is what appears on the connection screen. Where the corporate parent matters, because it is the entity that receives the data, we name the parent with its services in parentheses on first mention: Google LLC (Google Business Profile, Google Analytics, and YouTube) and Meta Platforms, Inc. (Facebook and Instagram). The Subprocessors page uses the same convention.

2. Who this policy is for

  • Customers and their staff — the people who hold accounts and use the application.
  • Visitors to the marketing site — including anyone who submits a demo request.
  • People whose data appears in customer content — most often review authors whose public display name and review text are pulled in from Google or another platform, or people named in a post or reply that a customer drafts. We process that data only to display, reply to, and report on the content, on the customer's instruction.

No student data

We do not knowingly collect data about minors or about a school's students. The platform has no field designed to hold student records, and customers are prohibited by the Technology and Acceptable Use Policy from uploading student personal data — names, dates of birth, addresses, phone numbers, permit or license numbers, lesson records, payment details, or identifiable photographs — anywhere in the product, including content drafts, notes, and support tickets.

3. What we collect

Every category the running software actually handles is listed below. If a category is not here, the application does not collect it.

CategoryWhat it includesWhere it comes from
Account and identityName, work email, avatar URL if you set one, your role in the organization, and authentication records (password credential held by our authentication provider, session and sign-in timestamps).You, at sign-up and in settings.
Organization, location, and business profileSchool name, workspace slug, plan, and location count, each location's address, city, state, phone, website, services, service areas, business hours, and instructor names and certifications you choose to enter.You, during onboarding and configuration.
Google Business Profile dataProfile fields, categories, hours, posts, review text and ratings, review replies, and profile performance metrics.Google Business Profile API, after you connect Google.
YouTube dataChannel identifier, channel metadata, video list, and video-level performance statistics. Read-only: we do not upload, edit, or delete YouTube content.YouTube Data API, after you connect a channel.
Other connected social account dataAccount, page, channel, and board identifiers, OAuth tokens, scheduled and published post content, and post-level performance metrics for Facebook, Instagram, TikTok, X, LinkedIn, and Pinterest.The platform's API, after you connect that account.
Website analytics (optional)Property identifier and aggregate traffic-by-source figures for the Google Analytics property you nominate, used to count real clicks arriving from citations.Google Analytics APIs, only if you connect Analytics and grant read access.
Website crawl dataURLs, HTML bodies, response headers, HTTP status codes, headings, titles, meta tags, and structured data from the website you nominate, stored as evidence for audit findings, plus Core Web Vitals field data.Our crawler (identifying itself as DriveDashAIBot) and the Google PageSpeed Insights API.
Measurement data from providersSearch and map result positions, competitor place records, and public review counts, domain and link metrics, geo-grid rank points, and answers returned by AI engines to visibility test prompts.SerpApi, Google Places, Moz, Local Falcon, and the AI providers listed in section 6.
Content you create or approveDrafts and approved versions of posts, review replies, page copy, schema, guides, and study assets, plus the approval and scheduling record.You and the drafting tools.
Support communicationsSupport tickets and messages you send from inside the app: subject, body, priority, status, and who raised them; plus any email you send us.You.
Billing dataSubscription, plan, location quantity, invoice, and credit-purchase records, and billing contact. Card details are entered directly on Stripe-hosted pages; we never receive or store full card numbers or CVV, and only ever see Stripe's own references and event records.You, via Stripe.
Technical, usage, and run telemetryWhich tool ran, when, for which organization, whether it succeeded, the error message if it failed, tokens and credits consumed, provider call counts and provider health, and cron job outcomes. Server request logs (IP address, user agent, request path, status) are produced by our hosting and database providers as part of serving and securing requests.Automatically, as the software runs.
Marketing and sales contactsDemo request submissions: contact name, school name, email, phone, preferred time, and our internal notes.You, from the marketing site.
Cookies and browser storageA session cookie to keep you signed in, a sidebar-state cookie, and local storage keys for interface preferences.Your browser. See the Cookie Policy for the full itemized list.

What we do not do: we run no advertising pixels, no analytics tags, and no cross-site trackers on the site or in the app; we do not buy personal data from data brokers; we do not build profiles of website visitors; and the application stores no visitor-level analytics of its own. The proof widget records only a daily hit count and referring host names — no visitor identifiers.

4. How we use it and our legal bases

Where the GDPR or UK GDPR applies, we rely on the Article 6 bases below. For data we process as a processor, the customer's own basis applies and we act on their instructions.

PurposeLegal basisWhy
Provide the service: create and secure accounts, run the tools you ask for, store results and history, and publish content you approve.Art. 6(1)(b) performance of a contract.This is the service you signed up for; without it there is nothing to deliver.
Billing, subscription management, credit accounting, invoices, and tax records.Art. 6(1)(b) contract; Art. 6(1)(c) legal obligation for retained financial records.Payment is a contractual term and record-keeping is required by tax law.
Security, abuse prevention, rate limiting, quota enforcement, and diagnosing failures.Art. 6(1)(f) legitimate interests.Balancing test: run logs, error records, and request metadata are operational rather than personal in substance, are seen only by staff who need them, and are necessary to keep every customer's data safe — an interest customers share.
Product improvement using aggregate, non-identifying figures such as which tools run, failure rates, and provider reliability.Art. 6(1)(f) legitimate interests.Balancing test: we use counts and outcomes rather than individual behavioral profiles, so the impact on any person is minimal while the benefit — fixing what breaks — is direct. Object at any time at brad@driveredconsultants.com.
Responding to a demo request or a support ticket.Art. 6(1)(b)/(f) — answering the enquiry you sent us.You contacted us and expect a reply.
Marketing email about the product to people who are not customers.Art. 6(1)(a) consent.Opt-in only, withdrawable at any time from the email or by writing to us.
Service and administrative email to account holders (confirmation, password reset, billing, and material policy changes).Art. 6(1)(b) contract.These are not marketing and cannot be unsubscribed while the account is open.
Complying with law, responding to lawful requests, enforcing our Terms, and defending legal claims.Art. 6(1)(c) legal obligation; Art. 6(1)(f) legitimate interests in enforcement.We disclose only what the request or the claim actually requires.

5. Google and YouTube API data

This section governs data we obtain from Google APIs, including YouTube. It applies in addition to the rest of this policy, and where it is more restrictive, it prevails.

Limited Use commitment

Drive Dash AI's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In practice, this means:

  • We use Google user data only to provide and improve the user-facing features described in this policy and visible in the application.
  • We do not transfer Google user data to third parties except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition, and never for serving advertisements.
  • We do not use Google user data for advertising purposes of any kind, including retargeting, personalized advertising, or interest-based advertising.
  • We do not sell Google user data.
  • We do not allow humans to read Google user data, except with the affirmative agreement of the user for specific messages, where necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and anonymized for internal operations.

What we request and why

Owners connect their own Google account. We request the following OAuth scopes, and no others:

ScopeWhat it is used for
openid and .../auth/userinfo.emailIdentifying the connected Google account so you can see which account is linked.
.../auth/business.manageReading your Business Profile — details, hours, services, verification status, reviews, and performance metrics — for the profile health dashboard, and publishing the posts, review replies, and profile updates that you approve in the application. Google publishes no read-only variant of this scope.
.../auth/analytics.readonlyReading Google Analytics traffic figures for your Citation Traffic report. Read-only; we never write to Analytics.
.../auth/youtube.readonlyReading your channel metadata, video list, and video statistics for your social dashboard. Read-only; we never upload, edit, or delete YouTube content.

Every write action is initiated by an authenticated user approving a specific change inside the application. The platform performs no background writes, never deletes content, and never accesses accounts you have not connected.

YouTube API Services

The application uses YouTube API Services. By connecting a YouTube channel you also agree to the YouTube Terms of Service, and Google's handling of your data is described in the Google Privacy Policy.

You can revoke Drive Dash AI's access to your Google and YouTube data at any time, either by disconnecting the integration inside the application or through the Google security settings page. Disconnecting inside the application deletes the stored credential immediately and, for Google, revokes it with Google first.

Storage and retention of Google data

We store only the OAuth refresh token, encrypted at rest as described in the Security section. No Google access token is stored; short-lived access tokens are requested as needed and held in memory for the duration of a request. Profile, Analytics, and YouTube data is fetched for display and reporting, and is retained under the schedule in the Retention section.

6. AI processing

Two different things happen with AI in this product, and only one of them sends your content anywhere.

  • Visibility measurement: we send fixed test prompts containing your business name, services, and locality to OpenAI, Anthropic, Google Gemini, Perplexity, and xAI (Grok) to record whether and how those engines mention you.
  • Drafting: we send business context — profile fields, services, localities, review text you are replying to, and audit findings — to a model provider to draft posts, replies, page copy, and explanations.

Prompts contain business information. They are not designed to contain, and must not be given, the personal data of students or other third parties. Please do not paste someone else's personal details into a content tool.

We do not train models on your data and we do not license your data to anyone for training. Content sent to a model provider travels over that provider's standard commercial API and is governed by that provider's API terms and retention practices, which we do not control; if a provider's position changes we will update the Subprocessors page.

Data obtained from Google APIs is not sent to third-party model providers except where necessary to produce a draft you have asked for — for example, drafting a reply to a specific review you selected — consistent with the Limited Use commitment in the Google and YouTube API data section.

Every AI output is a draft. Nothing is published to a connected platform until a person approves it, and the Technology and Acceptable Use Policy explains where the line between measured facts and generated text sits.

7. Sharing and disclosure

  • Subprocessors — hosting, database, billing, search, measurement, model, and platform APIs. Every one the code actually calls is named on the Subprocessors page, with what it receives and where it processes.
  • Platform APIs acting on your instruction — when you connect Google, YouTube, or another social platform and approve an action, the content of that action goes to that platform under its own terms.
  • Professional advisers — accountants and lawyers, bound by confidentiality, where needed to run the business.
  • Legal and regulatory disclosure — where we are legally required to, and to enforce our Terms or defend legal claims. We disclose the minimum required.
  • Business transfer — in a merger, acquisition, or sale of assets. You will be told before your data becomes subject to a different policy.

We do not sell or share personal information

We do not sell personal information and we do not share it for cross-context behavioral advertising, as those terms are defined by the CCPA as amended by the CPRA and by other US state privacy laws. There are no advertising pixels, analytics tags, tracking scripts, or data-broker relationships in the product or on the site; the only third parties that receive data are the service providers on the Subprocessors page, each acting on our instructions. We have never sold or shared personal information, including that of anyone under 16.

8. Retention

Retention is deliberate. The platform is a measurement product, so history has value and a lapsed subscription does not erase your work.

DataHow long we keep it
Account, organization, location, and business profile recordsFor the life of the account, then deleted within 30 days of a verified deletion request or account closure.
Run history, findings, audits, measurements, trends, and generated contentKept while the account exists — including through non-payment and cancellation, which is why reactivating restores your history — and for 90 days after closure or a deletion request, then deleted.
Raw crawl artifacts (stored page bodies and headers)Kept for recent scans so findings have evidence and can be diffed, superseded as newer scans replace them, and not retained beyond account closure plus 90 days.
Provider response cachesShort-lived operational caches: search results up to 24 hours, competitor review data up to 7 days.
OAuth tokens for connected platformsUntil you disconnect the integration or close the account, then deleted. Disconnecting deletes the stored token immediately, and for Google we revoke it with Google first. Google access tokens are never stored at all.
Billing, invoice, and tax recordsRetained by us and by Stripe for the period required by tax and accounting law — we apply 7 years — even after the account closes.
Support tickets and messages24 months from the ticket being closed, so we can follow up on recurring problems, then deleted.
Demo requests and sales enquiries24 months from the last contact, or sooner on request.
Server request and error logsUp to 90 days, as produced by our hosting and database providers, then rotated out.
BackupsManaged database backups expire on our provider's normal rotation, so deleted records may persist in a backup for a short period after deletion before ageing out. Backups are not used to restore individual deleted records.

9. Security

These are the measures the software applies today, described as they are rather than aspirationally. The Technology and Acceptable Use Policy explains them in more detail.

  • Encryption in transit (TLS) for all traffic.
  • Provider-managed encryption at rest applied by our managed database and storage provider to the whole database and stored files.
  • OAuth access and refresh tokens are encrypted by our application before they are written to the database, using AES-256-GCM authenticated encryption with a unique initialization vector for each value. The encryption key is held as a server-side secret, is never stored in the database, and decryption happens only in server-side code — never in the browser.
  • Google: no access token is stored. Only a refresh token is retained; short-lived access tokens are requested as needed and held in memory for the duration of the request.
  • The tables holding encrypted credentials are reachable only by the privileged server-side role. No signed-in user role and no anonymous role holds any privilege on them, so they cannot be read through the public API even with a valid session.
  • Row-level security scoped to your organization on every application table, so one school's data is not reachable from another school's session.
  • Role-based access inside the app (owner, member, and internal staff), with internal support access gated separately.
  • Least-privilege database grants, schema changes shipped as reviewed migrations, and automated scanning of schema, grants, and policies.
  • Secrets and API keys are held in a managed secret store and read only inside server-side handlers; they are never exposed to the browser.
  • Rate limits, per-organization provider quotas, and credit accounting to contain abuse.
  • Deletion on disconnect: revoking a connection deletes the stored credential.

We hold no security certification and we do not claim one. We do not operate key rotation, a key management service, or hardware security modules; if that changes, this page will change with it. Measures may evolve, but not in a way that reduces the overall level of protection, and we will notify customers of material changes.

No system is perfectly secure. If we become aware of a personal data breach affecting your data we will notify affected customers without undue delay and, where we act as processor, within 72 hours of becoming aware, with the information the customer needs to meet their own notification duties. We notify regulators and individuals where the law requires it.

10. Your rights

GDPR and UK GDPR

If you are in the EEA, UK, or Switzerland you have the right to access your personal data; to have inaccurate data rectified; to have data erased; to restrict processing; to receive your data in a portable format; to object to processing based on legitimate interests; and to withdraw consent where we rely on it, without affecting processing already carried out.

California (CCPA/CPRA)

In the last 12 months we collected these categories: identifiers (name, work email, and IP address in server logs); commercial information (subscription, invoice, and credit-purchase records); internet and network activity relating to your account (run and error logs); geolocation at business-address level only; professional information (your role at the school); and audio/visual only where you upload an image for content. We collected them from you, from the platform accounts you connect, and from public business sources.

CategoryDisclosed for a business purposeSoldShared for cross-context behavioral advertising
IdentifiersYes — to service providers on the Subprocessors page.NoneNone
Commercial informationYes — to our payment processor.NoneNone
Internet or network activityYes — to hosting and database providers.NoneNone
Geolocation (business address level)Yes — to search and measurement providers.NoneNone
Professional informationYes — to our hosting and database provider.NoneNone
Sensitive personal informationWe do not collect it for the purpose of inferring characteristics.NoneNone

You have the right to know and access a copy, to correct, to delete, to opt out of sale or sharing (we do neither), to limit the use of sensitive personal information (we do not use it for inferences), and not to be discriminated against for exercising any right — we will not deny service, charge a different price, or degrade quality. An authorized agent may submit a request with written proof of authority and we may still verify with you directly.

Shine the Light (Cal. Civ. Code § 1798.83): we have not disclosed personal information to third parties for their own direct marketing purposes in the preceding calendar year.

Other US states

Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have equivalent rights to confirm and access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and profiling with legal or similarly significant effects. We do not conduct targeted advertising, sale, or such profiling, so those opt-outs are already satisfied by default. Where a state grants an appeal right, you may appeal a refused request by replying to our decision email, and we will respond within the statutory period and tell you how to contact your attorney general if we again decline.

11. How to exercise a right

Email brad@driveredconsultants.com from the address on your account, or from the address you used to contact us, and say what you want. Verification: for account holders we verify by confirming control of the account email, and we may ask for one further matching detail such as your organization name; we ask for the minimum needed and never for sensitive documents. We never charge for a request.

Timelines: within 30 days for GDPR/UK GDPR requests, extendable by two further months for complex requests with notice; within 45 days for US state requests, extendable once by a further 45 days with notice.

If your request concerns data a driving school uploaded or connected — where we are the processor — we will route it to that customer as controller and assist them in responding, as required by the Data Processing Addendum.

12. International transfers

Drive Dash AI is operated from the United States. Our database and provider APIs are US-based and the application is served from a global edge network, so if you use the service from outside the United States your data will be transferred to and processed in the United States.

For transfers of personal data out of the EEA, UK, or Switzerland we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum and the Swiss adaptations where those apply, plus the technical measures in section 9. Copies are available on request at brad@driveredconsultants.com. Onward transfers to our providers are covered by each provider's own transfer mechanism, typically their own Standard Contractual Clauses or an approved certification.

Drive Dash AI does not currently offer the service to customers in the European Economic Area or the United Kingdom, so no Article 27 representative is presently appointed. If we begin offering the service in those regions, we will appoint a representative established in the EEA and in the UK as required, and update this policy before that offering begins.

13. Cookies and tracking

We set strictly necessary items only: a session cookie that keeps you signed in, a cookie remembering whether the sidebar is expanded, and local storage keys for interface preferences such as your selected workspace, dashboard layout, and a plan you picked before signing up. We set no analytics, advertising, or cross-site tracking cookies.

Because nothing we set is optional, EU and UK cookie rules do not require consent for it, so our notice is informational rather than a consent gate. You can reopen it at any time from the "Cookie preferences" link in the site footer. If we ever introduce a non-essential cookie we will ship a granular consent banner that is off by default and load nothing before you opt in — and update the Cookie Policy first.

Third-party content — web fonts, map tiles, Stripe's hosted checkout, and each platform's own OAuth sign-in pages — may set cookies under those providers' policies. The Cookie Policy itemizes every cookie and storage key by name.

14. Children's privacy

The service is sold to businesses and is intended solely for use by driving school staff. It is not directed to children, and we do not knowingly collect personal data from anyone under 18 through the application or the website.

We know driving schools teach teenagers. The platform is not a student information system and customers are contractually prohibited from putting student personal data into it. Publicly posted reviews may contain a reviewer's chosen display name; that content originates from the review platform and we process it only to display and reply to reviews.

If we learn that student or minor personal data has reached the platform, we will delete it, tell the customer that it happened and what was removed, and treat repeated uploads as an acceptable-use breach. To report a concern, email brad@driveredconsultants.com.

15. Automated decision-making

We do not make automated decisions that produce legal or similarly significant effects about individuals, and we do not carry out profiling of individuals. No credit, employment, insurance, pricing, or eligibility decision about a person is made by the software.

The scoring and ranking in the product is about businesses and websites: audit findings describe a web page, and visibility measurements describe how a search engine or AI engine presents a business. Any AI output is a draft for a person to review, never an automated decision about a person.

16. Changes to this policy

We will update this policy as the product changes and post the new version here with a revised "Last updated" date, which is also the effective date.

For material changes affecting your rights or how we use data, we will notify account owners by email at least 30 days before they take effect where practicable. Continuing to use the service after that date is acceptance of the updated policy; if you do not accept it, you may close your account and ask us to delete your data.

17. Contact and complaints

Privacy questions, requests, and complaints: brad@driveredconsultants.com, or write to 6047 Allentown Blvd, Suite B-118, Harrisburg, PA 17112. We have not appointed a Data Protection Officer, because our processing does not require one; privacy enquiries are handled directly by the account owner of Drive Dash AI at that address. We aim to acknowledge within 5 business days and to resolve within the timelines in section 11.

If you are not satisfied with our response, you may lodge a complaint with your data protection supervisory authority — in the UK the Information Commissioner's Office, in the EEA your national authority — or, in the United States, with your state attorney general. We would appreciate the chance to put it right first.