Privacy Policy
Effective May 29, 2026
DRV.club ("we", "our", "us") operates the DRV.club mobile application and the drv.club website (together, the "Service"). This Privacy Policy explains what information we collect, why we collect it, who we share it with, and the rights you have over your data.
By using DRV.club you accept this Policy. If you do not agree, please uninstall the app and stop using the Service.
1. Information we collect
1.1 Information you give us
- Account profile — when you sign in with Google, Apple, or email, we receive your name, email address, and (if provided) profile photo.
- Car profile and posts — content you create in the app: car details, photos, drives, posts, comments, club membership.
- Emergency contacts — if you add SOS contacts for crash detection, we store the names and phone numbers you provide.
1.2 Information we collect automatically
- Location — precise GPS coordinates while the app is in use, and (only if you enable it) in the background. We use this for turn-by-turn navigation, convoy synchronization, hazard alerts, drive recording, and crash detection. Background location is opt-in and can be revoked at any time from your device settings.
- Motion sensors — accelerometer and gyroscope data, used to score driving (smoothness, cornering) and to detect possible crashes.
- Voice audio (when using convoy push-to-talk) — when you actively press the talk button in a convoy, your microphone audio is transmitted in real time to other convoy members via our voice partner (LiveKit). Voice is not recorded or stored by us.
- Voice search — if you use voice search for destinations, your speech is processed by your device's on-device speech recognizer or (where available) by Google Speech Services per your device settings.
- Crash and performance diagnostics — when the app crashes we collect anonymized device model, OS version, app version, and a stack trace via Sentry to fix bugs.
2. How we use your information
- Provide and operate the Service (navigation, convoy, feed, drives).
- Detect potential crashes and notify your designated SOS contacts.
- Surface community content (clubs, drives, feed) you have access to.
- Improve safety alerts based on aggregated, de-identified GPS speed signals.
- Respond to support requests, enforce our Terms, and prevent abuse.
- Send transactional notifications (drive invites, convoy starts, comments) that you can disable per-channel in app settings.
3. Third-party services
We share the minimum data required with the following processors:
- Google Firebase (Authentication, Firestore, Realtime Database, Storage, Cloud Messaging, Cloud Functions) — backend infrastructure. Google Privacy Policy.
- Mapbox — maps, geocoding, navigation tiles. Mapbox Privacy Policy.
- LiveKit — convoy push-to-talk voice (real-time, not stored). LiveKit Privacy Policy.
- Sentry — crash diagnostics. Sentry Privacy Policy.
- Apple Sign-In, Google Sign-In — identity providers when you choose them.
We do not sell your personal information. We do not show advertising in DRV.club.
4. Android permissions and why we ask
- Location (fine + background) — navigation, convoy sync, hazard alerts, drive recording, crash detection. Background access is optional and can be set to "While using the app" at any time.
- Microphone — convoy push-to-talk and voice destination search. Active only while you press the talk button or trigger voice search.
- Camera — to capture car photos and drive moments you choose to share.
- Photos and media — to attach existing photos to posts and car profiles.
- Notifications — drive invites, convoy alerts, hazard warnings, social updates.
- Foreground service — keeps location active during a drive so navigation and convoy sync stay accurate.
5. Data retention
We keep your account data while your account is active. Drive recordings, posts, and convoy history are retained for as long as you keep them in the app. Diagnostic crash reports are retained by Sentry for 90 days. Voice audio for convoy push-to-talk is transmitted in real time and is not stored.
When you delete your account (Settings → Account → Delete Account), we delete your profile, posts, drives, convoy memberships, and emergency contacts from our active systems within 30 days. Anonymous aggregated data (e.g. fleet-wide congestion samples) is retained without personal identifiers.
6. Your rights
- Access — view your profile and content in-app at any time.
- Export — Settings → Export Data generates a copy of your drives, posts, and profile.
- Delete — Settings → Account → Delete Account removes your data as described above.
- Correct — edit your profile and content in-app.
- Object / restrict / portability (GDPR jurisdictions) — email privacy@drv.club.
7. Children
DRV.club is not directed to children under 13 (or under the minimum age required in your country). If we learn we have collected data from a child without parental consent we will delete it.
8. International transfers
Our processors (Google, Mapbox, LiveKit, Sentry) operate globally. Your data may be processed outside your country, subject to the safeguards each provider publishes (standard contractual clauses where applicable).
9. Security
We use TLS in transit, encrypted storage at rest with our backend providers, and Firebase Security Rules to scope access. No system is perfectly secure; please use a strong unique password (or a federated sign-in provider) and report suspected vulnerabilities to security@drv.club.
10. Changes
We may update this Policy. Material changes will be announced in-app or by email. The "Effective" date above always reflects the current version.
11. Contact
Privacy questions, access requests, and deletion requests: privacy@drv.club.