1. Introduction and scope
Drive Dash AI (Shield Driving Center LLC d/b/a Driver Ed Consultants, a Pennsylvania limited liability company, "Drive Dash AI", "we", and "us") provides a business-to-business marketing platform for driving schools. Our address is 6047 Allentown Blvd, Suite B-118, Harrisburg, PA 17112 and you can reach us at brad@driveredconsultants.com. This policy covers the drivedashai.com website and the Drive Dash AI application.
The service is sold to businesses. It is not a consumer product, not a student information system, and there is no consumer-facing account.
Our two roles
The distinction below determines which data protection duties apply to which data, so we state it up front.
| Our role | Which data | What that means |
|---|---|---|
| Controller | Data about our own customer relationship: the account and login records of your staff, organization, and billing records, support conversations, demo requests, and the operational logs we need to run and secure the service. | We decide why and how this data is processed, and this policy is the governing document for it. |
| Processor | The business data you put into or connect to the platform: business profile and location details, Google Business Profile content, connected social accounts and their posts and metrics, website crawl results, reviews and replies, measurement history, and generated drafts. | You are the controller and we act only on your instructions. Our formal commitments are in the Data Processing Addendum, which prevails over this policy for that data. |
Related documents: the Terms of Service (the contract), the Data Processing Addendum (our processor obligations), the Technology and Acceptable Use Policy (how the technology works and what you may not do with it), the Cookie Policy, and the Subprocessors page (every third party that receives data). Where one of those is the formal instrument, we cross-link rather than restate.
How we name platforms in this policy
We name the service you actually connect in the product — Google Business Profile, Google Analytics, YouTube, Facebook, Instagram, TikTok, X, LinkedIn, or Pinterest — because that is what appears on the connection screen. Where the corporate parent matters, because it is the entity that receives the data, we name the parent with its services in parentheses on first mention: Google LLC (Google Business Profile, Google Analytics, and YouTube) and Meta Platforms, Inc. (Facebook and Instagram). The Subprocessors page uses the same convention.
2. Who this policy is for
- Customers and their staff — the people who hold accounts and use the application.
- Visitors to the marketing site — including anyone who submits a demo request.
- People whose data appears in customer content — most often review authors whose public display name and review text are pulled in from Google or another platform, or people named in a post or reply that a customer drafts. We process that data only to display, reply to, and report on the content, on the customer's instruction.
No student data
We do not knowingly collect data about minors or about a school's students. The platform has no field designed to hold student records, and customers are prohibited by the Technology and Acceptable Use Policy from uploading student personal data — names, dates of birth, addresses, phone numbers, permit or license numbers, lesson records, payment details, or identifiable photographs — anywhere in the product, including content drafts, notes, and support tickets.
3. What we collect
Every category the running software actually handles is listed below. If a category is not here, the application does not collect it.
| Category | What it includes | Where it comes from |
|---|---|---|
| Account and identity | Name, work email, avatar URL if you set one, your role in the organization, and authentication records (password credential held by our authentication provider, session and sign-in timestamps). | You, at sign-up and in settings. |
| Organization, location, and business profile | School name, workspace slug, plan, and location count, each location's address, city, state, phone, website, services, service areas, business hours, and instructor names and certifications you choose to enter. | You, during onboarding and configuration. |
| Google Business Profile data | Profile fields, categories, hours, posts, review text and ratings, review replies, and profile performance metrics. | Google Business Profile API, after you connect Google. |
| YouTube data | Channel identifier, channel metadata, video list, and video-level performance statistics. Read-only: we do not upload, edit, or delete YouTube content. | YouTube Data API, after you connect a channel. |
| Other connected social account data | Account, page, channel, and board identifiers, OAuth tokens, scheduled and published post content, and post-level performance metrics for Facebook, Instagram, TikTok, X, LinkedIn, and Pinterest. | The platform's API, after you connect that account. |
| Website analytics (optional) | Property identifier and aggregate traffic-by-source figures for the Google Analytics property you nominate, used to count real clicks arriving from citations. | Google Analytics APIs, only if you connect Analytics and grant read access. |
| Website crawl data | URLs, HTML bodies, response headers, HTTP status codes, headings, titles, meta tags, and structured data from the website you nominate, stored as evidence for audit findings, plus Core Web Vitals field data. | Our crawler (identifying itself as DriveDashAIBot) and the Google PageSpeed Insights API. |
| Measurement data from providers | Search and map result positions, competitor place records, and public review counts, domain and link metrics, geo-grid rank points, and answers returned by AI engines to visibility test prompts. | SerpApi, Google Places, Moz, Local Falcon, and the AI providers listed in section 6. |
| Content you create or approve | Drafts and approved versions of posts, review replies, page copy, schema, guides, and study assets, plus the approval and scheduling record. | You and the drafting tools. |
| Support communications | Support tickets and messages you send from inside the app: subject, body, priority, status, and who raised them; plus any email you send us. | You. |
| Billing data | Subscription, plan, location quantity, invoice, and credit-purchase records, and billing contact. Card details are entered directly on Stripe-hosted pages; we never receive or store full card numbers or CVV, and only ever see Stripe's own references and event records. | You, via Stripe. |
| Technical, usage, and run telemetry | Which tool ran, when, for which organization, whether it succeeded, the error message if it failed, tokens and credits consumed, provider call counts and provider health, and cron job outcomes. Server request logs (IP address, user agent, request path, status) are produced by our hosting and database providers as part of serving and securing requests. | Automatically, as the software runs. |
| Marketing and sales contacts | Demo request submissions: contact name, school name, email, phone, preferred time, and our internal notes. | You, from the marketing site. |
| Cookies and browser storage | A session cookie to keep you signed in, a sidebar-state cookie, and local storage keys for interface preferences. | Your browser. See the Cookie Policy for the full itemized list. |
What we do not do: we run no advertising pixels, no analytics tags, and no cross-site trackers on the site or in the app; we do not buy personal data from data brokers; we do not build profiles of website visitors; and the application stores no visitor-level analytics of its own. The proof widget records only a daily hit count and referring host names — no visitor identifiers.
4. How we use it and our legal bases
Where the GDPR or UK GDPR applies, we rely on the Article 6 bases below. For data we process as a processor, the customer's own basis applies and we act on their instructions.
| Purpose | Legal basis | Why |
|---|---|---|
| Provide the service: create and secure accounts, run the tools you ask for, store results and history, and publish content you approve. | Art. 6(1)(b) performance of a contract. | This is the service you signed up for; without it there is nothing to deliver. |
| Billing, subscription management, credit accounting, invoices, and tax records. | Art. 6(1)(b) contract; Art. 6(1)(c) legal obligation for retained financial records. | Payment is a contractual term and record-keeping is required by tax law. |
| Security, abuse prevention, rate limiting, quota enforcement, and diagnosing failures. | Art. 6(1)(f) legitimate interests. | Balancing test: run logs, error records, and request metadata are operational rather than personal in substance, are seen only by staff who need them, and are necessary to keep every customer's data safe — an interest customers share. |
| Product improvement using aggregate, non-identifying figures such as which tools run, failure rates, and provider reliability. | Art. 6(1)(f) legitimate interests. | Balancing test: we use counts and outcomes rather than individual behavioral profiles, so the impact on any person is minimal while the benefit — fixing what breaks — is direct. Object at any time at brad@driveredconsultants.com. |
| Responding to a demo request or a support ticket. | Art. 6(1)(b)/(f) — answering the enquiry you sent us. | You contacted us and expect a reply. |
| Marketing email about the product to people who are not customers. | Art. 6(1)(a) consent. | Opt-in only, withdrawable at any time from the email or by writing to us. |
| Service and administrative email to account holders (confirmation, password reset, billing, and material policy changes). | Art. 6(1)(b) contract. | These are not marketing and cannot be unsubscribed while the account is open. |
| Complying with law, responding to lawful requests, enforcing our Terms, and defending legal claims. | Art. 6(1)(c) legal obligation; Art. 6(1)(f) legitimate interests in enforcement. | We disclose only what the request or the claim actually requires. |
5. Google and YouTube API data
This section governs data we obtain from Google APIs, including YouTube. It applies in addition to the rest of this policy, and where it is more restrictive, it prevails.
Limited Use commitment
Drive Dash AI's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice, this means:
- We use Google user data only to provide and improve the user-facing features described in this policy and visible in the application.
- We do not transfer Google user data to third parties except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition, and never for serving advertisements.
- We do not use Google user data for advertising purposes of any kind, including retargeting, personalized advertising, or interest-based advertising.
- We do not sell Google user data.
- We do not allow humans to read Google user data, except with the affirmative agreement of the user for specific messages, where necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and anonymized for internal operations.
What we request and why
Owners connect their own Google account. We request the following OAuth scopes, and no others:
| Scope | What it is used for |
|---|---|
| openid and .../auth/userinfo.email | Identifying the connected Google account so you can see which account is linked. |
| .../auth/business.manage | Reading your Business Profile — details, hours, services, verification status, reviews, and performance metrics — for the profile health dashboard, and publishing the posts, review replies, and profile updates that you approve in the application. Google publishes no read-only variant of this scope. |
| .../auth/analytics.readonly | Reading Google Analytics traffic figures for your Citation Traffic report. Read-only; we never write to Analytics. |
| .../auth/youtube.readonly | Reading your channel metadata, video list, and video statistics for your social dashboard. Read-only; we never upload, edit, or delete YouTube content. |
Every write action is initiated by an authenticated user approving a specific change inside the application. The platform performs no background writes, never deletes content, and never accesses accounts you have not connected.
YouTube API Services
The application uses YouTube API Services. By connecting a YouTube channel you also agree to the YouTube Terms of Service, and Google's handling of your data is described in the Google Privacy Policy.
You can revoke Drive Dash AI's access to your Google and YouTube data at any time, either by disconnecting the integration inside the application or through the Google security settings page. Disconnecting inside the application deletes the stored credential immediately and, for Google, revokes it with Google first.
Storage and retention of Google data
We store only the OAuth refresh token, encrypted at rest as described in the Security section. No Google access token is stored; short-lived access tokens are requested as needed and held in memory for the duration of a request. Profile, Analytics, and YouTube data is fetched for display and reporting, and is retained under the schedule in the Retention section.
6. AI processing
Two different things happen with AI in this product, and only one of them sends your content anywhere.
- Visibility measurement: we send fixed test prompts containing your business name, services, and locality to OpenAI, Anthropic, Google Gemini, Perplexity, and xAI (Grok) to record whether and how those engines mention you.
- Drafting: we send business context — profile fields, services, localities, review text you are replying to, and audit findings — to a model provider to draft posts, replies, page copy, and explanations.
Prompts contain business information. They are not designed to contain, and must not be given, the personal data of students or other third parties. Please do not paste someone else's personal details into a content tool.
We do not train models on your data and we do not license your data to anyone for training. Content sent to a model provider travels over that provider's standard commercial API and is governed by that provider's API terms and retention practices, which we do not control; if a provider's position changes we will update the Subprocessors page.
Data obtained from Google APIs is not sent to third-party model providers except where necessary to produce a draft you have asked for — for example, drafting a reply to a specific review you selected — consistent with the Limited Use commitment in the Google and YouTube API data section.
Every AI output is a draft. Nothing is published to a connected platform until a person approves it, and the Technology and Acceptable Use Policy explains where the line between measured facts and generated text sits.
8. Retention
Retention is deliberate. The platform is a measurement product, so history has value and a lapsed subscription does not erase your work.
| Data | How long we keep it |
|---|---|
| Account, organization, location, and business profile records | For the life of the account, then deleted within 30 days of a verified deletion request or account closure. |
| Run history, findings, audits, measurements, trends, and generated content | Kept while the account exists — including through non-payment and cancellation, which is why reactivating restores your history — and for 90 days after closure or a deletion request, then deleted. |
| Raw crawl artifacts (stored page bodies and headers) | Kept for recent scans so findings have evidence and can be diffed, superseded as newer scans replace them, and not retained beyond account closure plus 90 days. |
| Provider response caches | Short-lived operational caches: search results up to 24 hours, competitor review data up to 7 days. |
| OAuth tokens for connected platforms | Until you disconnect the integration or close the account, then deleted. Disconnecting deletes the stored token immediately, and for Google we revoke it with Google first. Google access tokens are never stored at all. |
| Billing, invoice, and tax records | Retained by us and by Stripe for the period required by tax and accounting law — we apply 7 years — even after the account closes. |
| Support tickets and messages | 24 months from the ticket being closed, so we can follow up on recurring problems, then deleted. |
| Demo requests and sales enquiries | 24 months from the last contact, or sooner on request. |
| Server request and error logs | Up to 90 days, as produced by our hosting and database providers, then rotated out. |
| Backups | Managed database backups expire on our provider's normal rotation, so deleted records may persist in a backup for a short period after deletion before ageing out. Backups are not used to restore individual deleted records. |
9. Security
These are the measures the software applies today, described as they are rather than aspirationally. The Technology and Acceptable Use Policy explains them in more detail.
- Encryption in transit (TLS) for all traffic.
- Provider-managed encryption at rest applied by our managed database and storage provider to the whole database and stored files.
- OAuth access and refresh tokens are encrypted by our application before they are written to the database, using AES-256-GCM authenticated encryption with a unique initialization vector for each value. The encryption key is held as a server-side secret, is never stored in the database, and decryption happens only in server-side code — never in the browser.
- Google: no access token is stored. Only a refresh token is retained; short-lived access tokens are requested as needed and held in memory for the duration of the request.
- The tables holding encrypted credentials are reachable only by the privileged server-side role. No signed-in user role and no anonymous role holds any privilege on them, so they cannot be read through the public API even with a valid session.
- Row-level security scoped to your organization on every application table, so one school's data is not reachable from another school's session.
- Role-based access inside the app (owner, member, and internal staff), with internal support access gated separately.
- Least-privilege database grants, schema changes shipped as reviewed migrations, and automated scanning of schema, grants, and policies.
- Secrets and API keys are held in a managed secret store and read only inside server-side handlers; they are never exposed to the browser.
- Rate limits, per-organization provider quotas, and credit accounting to contain abuse.
- Deletion on disconnect: revoking a connection deletes the stored credential.
We hold no security certification and we do not claim one. We do not operate key rotation, a key management service, or hardware security modules; if that changes, this page will change with it. Measures may evolve, but not in a way that reduces the overall level of protection, and we will notify customers of material changes.
No system is perfectly secure. If we become aware of a personal data breach affecting your data we will notify affected customers without undue delay and, where we act as processor, within 72 hours of becoming aware, with the information the customer needs to meet their own notification duties. We notify regulators and individuals where the law requires it.
10. Your rights
GDPR and UK GDPR
If you are in the EEA, UK, or Switzerland you have the right to access your personal data; to have inaccurate data rectified; to have data erased; to restrict processing; to receive your data in a portable format; to object to processing based on legitimate interests; and to withdraw consent where we rely on it, without affecting processing already carried out.
California (CCPA/CPRA)
In the last 12 months we collected these categories: identifiers (name, work email, and IP address in server logs); commercial information (subscription, invoice, and credit-purchase records); internet and network activity relating to your account (run and error logs); geolocation at business-address level only; professional information (your role at the school); and audio/visual only where you upload an image for content. We collected them from you, from the platform accounts you connect, and from public business sources.
| Category | Disclosed for a business purpose | Sold | Shared for cross-context behavioral advertising |
|---|---|---|---|
| Identifiers | Yes — to service providers on the Subprocessors page. | None | None |
| Commercial information | Yes — to our payment processor. | None | None |
| Internet or network activity | Yes — to hosting and database providers. | None | None |
| Geolocation (business address level) | Yes — to search and measurement providers. | None | None |
| Professional information | Yes — to our hosting and database provider. | None | None |
| Sensitive personal information | We do not collect it for the purpose of inferring characteristics. | None | None |
You have the right to know and access a copy, to correct, to delete, to opt out of sale or sharing (we do neither), to limit the use of sensitive personal information (we do not use it for inferences), and not to be discriminated against for exercising any right — we will not deny service, charge a different price, or degrade quality. An authorized agent may submit a request with written proof of authority and we may still verify with you directly.
Shine the Light (Cal. Civ. Code § 1798.83): we have not disclosed personal information to third parties for their own direct marketing purposes in the preceding calendar year.
Other US states
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have equivalent rights to confirm and access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and profiling with legal or similarly significant effects. We do not conduct targeted advertising, sale, or such profiling, so those opt-outs are already satisfied by default. Where a state grants an appeal right, you may appeal a refused request by replying to our decision email, and we will respond within the statutory period and tell you how to contact your attorney general if we again decline.
11. How to exercise a right
Email brad@driveredconsultants.com from the address on your account, or from the address you used to contact us, and say what you want. Verification: for account holders we verify by confirming control of the account email, and we may ask for one further matching detail such as your organization name; we ask for the minimum needed and never for sensitive documents. We never charge for a request.
Timelines: within 30 days for GDPR/UK GDPR requests, extendable by two further months for complex requests with notice; within 45 days for US state requests, extendable once by a further 45 days with notice.
If your request concerns data a driving school uploaded or connected — where we are the processor — we will route it to that customer as controller and assist them in responding, as required by the Data Processing Addendum.
12. International transfers
Drive Dash AI is operated from the United States. Our database and provider APIs are US-based and the application is served from a global edge network, so if you use the service from outside the United States your data will be transferred to and processed in the United States.
For transfers of personal data out of the EEA, UK, or Switzerland we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum and the Swiss adaptations where those apply, plus the technical measures in section 9. Copies are available on request at brad@driveredconsultants.com. Onward transfers to our providers are covered by each provider's own transfer mechanism, typically their own Standard Contractual Clauses or an approved certification.
Drive Dash AI does not currently offer the service to customers in the European Economic Area or the United Kingdom, so no Article 27 representative is presently appointed. If we begin offering the service in those regions, we will appoint a representative established in the EEA and in the UK as required, and update this policy before that offering begins.
14. Children's privacy
The service is sold to businesses and is intended solely for use by driving school staff. It is not directed to children, and we do not knowingly collect personal data from anyone under 18 through the application or the website.
We know driving schools teach teenagers. The platform is not a student information system and customers are contractually prohibited from putting student personal data into it. Publicly posted reviews may contain a reviewer's chosen display name; that content originates from the review platform and we process it only to display and reply to reviews.
If we learn that student or minor personal data has reached the platform, we will delete it, tell the customer that it happened and what was removed, and treat repeated uploads as an acceptable-use breach. To report a concern, email brad@driveredconsultants.com.
15. Automated decision-making
We do not make automated decisions that produce legal or similarly significant effects about individuals, and we do not carry out profiling of individuals. No credit, employment, insurance, pricing, or eligibility decision about a person is made by the software.
The scoring and ranking in the product is about businesses and websites: audit findings describe a web page, and visibility measurements describe how a search engine or AI engine presents a business. Any AI output is a draft for a person to review, never an automated decision about a person.
16. Changes to this policy
We will update this policy as the product changes and post the new version here with a revised "Last updated" date, which is also the effective date.
For material changes affecting your rights or how we use data, we will notify account owners by email at least 30 days before they take effect where practicable. Continuing to use the service after that date is acceptance of the updated policy; if you do not accept it, you may close your account and ask us to delete your data.
17. Contact and complaints
Privacy questions, requests, and complaints: brad@driveredconsultants.com, or write to 6047 Allentown Blvd, Suite B-118, Harrisburg, PA 17112. We have not appointed a Data Protection Officer, because our processing does not require one; privacy enquiries are handled directly by the account owner of Drive Dash AI at that address. We aim to acknowledge within 5 business days and to resolve within the timelines in section 11.
If you are not satisfied with our response, you may lodge a complaint with your data protection supervisory authority — in the UK the Information Commissioner's Office, in the EEA your national authority — or, in the United States, with your state attorney general. We would appreciate the chance to put it right first.