Privacy Policy
At DRIVO Technologies, your privacy is not an afterthought — it's engineered into the core of our product. This policy explains exactly what data DRIVO collects, why we collect it, how we protect it, and the full control you have over it. We believe in radical transparency.
Overview
DRIVO Technologies ("DRIVO," "we," "us," or "our") operates the DRIVO AI car companion device, the DRIVO mobile application, and the website at drivo.ai. This Privacy Policy applies to all of these products and services (collectively, the "Services").
By purchasing, activating, or using any DRIVO Service, you agree to the collection and use of information in accordance with this policy. If you disagree with any part of this policy, please discontinue use of our Services.
Data We Collect
We collect data in three ways: data you provide directly, data collected automatically by your DRIVO device, and data collected through your use of our app and website.
| Category | Data Collected | Source |
|---|---|---|
| Account InformationName, email, password hash, billing address | You provide this during registration and checkout | DRIVO App / Website |
| Vehicle DiagnosticsOBD-II data including RPM, engine temp, fuel level, fault codes, battery voltage | Collected by DRIVO unit via OBD-II port | DRIVO Device |
| Location DataGPS coordinates during active navigation sessions (not stored continuously) | Collected only during in-app navigation with your permission | DRIVO App |
| Usage DataFeatures used, commands given, session duration, crash reports | Collected automatically to improve the service | DRIVO App / Device |
| Voice CommandsShort audio clips of voice commands (processed on-device, not stored) | Voice input is processed locally on DRIVO's neural chip | DRIVO Device |
| Device InformationDRIVO unit serial number, firmware version, hardware telemetry | Collected automatically for support and warranty purposes | DRIVO Device / App |
How We Use Data
DRIVO uses the data we collect strictly to operate, improve, and secure our Services. We do not use your data for advertising profiling, and we do not train AI models on your personal vehicle or behavioral data without your explicit opt-in consent.
- Providing core services: Operating your DRIVO device, enabling voice commands, running diagnostics, and facilitating navigation.
- Account management: Creating and maintaining your DRIVO account, processing payments, and managing your subscription.
- Personalization: Learning your driving preferences locally on-device to tailor DRIVO's responses and suggestions. This data stays on your device.
- Safety alerts: Detecting vehicle anomalies and sending push notifications for critical engine or security events.
- Product improvement: Using aggregated, anonymised usage data to improve DRIVO's features, accuracy, and reliability.
- Customer support: Diagnosing issues using device telemetry when you contact support (with your consent).
- Legal compliance: Complying with applicable laws, regulations, legal processes, or enforceable government requests.
- Security: Detecting, investigating, and preventing fraudulent transactions, abuse, and other illegal activities.
Data Sharing
DRIVO does not sell, trade, or rent your personal data. We may share data only in the limited circumstances described below:
- Service providers: Trusted third-party vendors who assist us in operating our Services — including cloud hosting (AWS), payment processing (Stripe), and analytics (anonymised data only). All vendors are bound by strict data processing agreements.
- Legal requirements: We may disclose your information if required by law, court order, or governmental authority, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
- Business transfers: If DRIVO is acquired, merged, or undergoes a significant corporate transaction, your data may be transferred as part of that transaction. We will notify you and provide opt-out options in such cases.
- With your consent: For any other purpose, we will obtain your explicit consent before sharing your data.
Vehicle Data
Vehicle diagnostic data is sensitive and we treat it accordingly. Here's exactly how it works:
Data Retention
We retain personal data only for as long as necessary to provide our Services or as required by law. Our default retention periods are:
| Data Type | Retention Period | Deletion Method |
|---|---|---|
| Account dataName, email, billing | Duration of account + 90 days after deletion request | Secure erasure on request |
| Vehicle diagnostics(cloud synced) | 12 months rolling window (Pro/Elite) | Auto-purged; instant on request |
| Trip history(local device) | Until you delete it or factory reset | Factory reset or in-app deletion |
| Security footage | 72 hours on-device (overwritten) | Automatic loop overwrite |
| Crash & error logs | 30 days | Automatic purge |
| Payment records | 7 years (legal requirement) | Compliant financial erasure |
Security
We implement industry-leading technical and organisational measures to protect your data from unauthorized access, alteration, disclosure, or destruction.
- End-to-end encryption: All data transmitted between your DRIVO device, app, and our servers is encrypted using TLS 1.3.
- At-rest encryption: Cloud-stored data is encrypted using AES-256. Local on-device storage uses hardware-level encryption.
- Zero-knowledge architecture: Voice commands and driving behavior data are processed on-device. Our servers have no access to this data.
- Penetration testing: We conduct regular independent security audits and penetration tests of our infrastructure.
- Secure OTA updates: Firmware updates are cryptographically signed and verified before installation.
- Access controls: Internal access to customer data is role-based, logged, and audited. Only authorized personnel with legitimate business need may access your data.
- Breach notification: In the event of a data breach, we will notify affected users within 72 hours as required by GDPR.
Your Rights
Depending on your location, you have various rights regarding your personal data. DRIVO honours these rights globally, not just in jurisdictions where they are legally mandated.
- Right to Access: Request a copy of all personal data we hold about you in a portable, machine-readable format.
- Right to Rectification: Correct inaccurate or incomplete personal data we hold about you at any time through the app or by contacting us.
- Right to Erasure ("Right to be Forgotten"): Request deletion of your account and all associated personal data. We will comply within 30 days.
- Right to Restrict Processing: Ask us to pause processing of your data while a dispute is resolved.
- Right to Data Portability: Receive your data in a structured, commonly used, machine-readable format (JSON or CSV) to transfer to another service.
- Right to Object: Object to processing of your data for specific purposes, including any analytical or profiling use.
- Right to Opt Out of Sale (CCPA): California residents have the right to opt out of the sale of personal information. We do not sell personal information — this right is automatically exercised.
- Right to Non-Discrimination: We will not discriminate against you for exercising any privacy rights — your service access remains unchanged.
Cookies & Tracking
Our website uses cookies and similar tracking technologies. Our mobile app does not use browser cookies but may use equivalent mobile identifiers (e.g., advertising IDs) only if you grant permission.
| Cookie Type | Purpose | Opt-Out |
|---|---|---|
| EssentialRequired for site function | Session management, security tokens, load balancing | Cannot be disabled — required for site operation |
| AnalyticsPerformance tracking | Understanding how visitors use our site (anonymised). We use self-hosted analytics — no Google Analytics. | Opt out via cookie banner or browser settings |
| FunctionalPreferences | Remembering your language preference, theme setting, and country | Opt out via cookie banner |
| MarketingRetargeting | We do not use marketing or retargeting cookies on our website | N/A — not used |
You can manage cookie preferences at any time through our cookie consent centre accessible from the footer of our website. Most browsers also allow you to refuse or delete cookies through their settings.
Children's Privacy
DRIVO is designed exclusively for adults aged 18 and over. Our Services are not directed to, and we do not knowingly collect personal data from, children under the age of 16 (or 13 in the United States).
If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately at privacy@drivo.ai. We will promptly delete such information from our systems.
Policy Changes
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Post the updated policy on this page with a revised "Last Updated" date
- Send an in-app notification to all registered DRIVO users
- Email registered users at least 14 days before material changes take effect
- For significant changes affecting data usage, obtain fresh consent where required by law
Your continued use of DRIVO after the effective date of any changes constitutes your acceptance of the updated policy. If you do not agree with a change, you may delete your account before the effective date.
Previous versions of this policy are available upon request by emailing privacy@drivo.ai.
Contact Us
For any privacy-related questions, concerns, or requests, please reach out to our Data Privacy team. We are committed to resolving all inquiries promptly and transparently.
Email: privacy@drivo.ai
Response time: Within 5 business days
Data requests: Within 30 days
For EU residents, our EU Representative can be reached at eu-privacy@drivo.ai