Legal Information
Privacy Policy
1. Data Controller & General Information
The protection of your personal data is highly important to us. Below, we inform you about the processing of personal data when using the DriveBase App and website in accordance with the General Data Protection Regulation (GDPR).
2. Your Rights as a Data Subject
Under the GDPR, you have the following rights at any time regarding your processed personal data:
- Right of access (Art. 15 GDPR) to your stored data.
- Right to rectification (Art. 16 GDPR) of inaccurate data.
- Right to erasure / Right to be forgotten (Art. 17 GDPR), provided there are no legal storage retention duties.
- Right to restriction of processing (Art. 18 GDPR).
- Right to data portability (Art. 20 GDPR) in a structured format.
- Right to object (Art. 21 GDPR) to future processing.
- Right to withdraw consent (Art. 7 para. 3 GDPR) at any time.
- Right to lodge a complaint with a competent supervisory authority (Art. 77 GDPR).
You can exercise these rights directly yourself: delete your account in the app settings or via the “Delete Account” page on this website. As a logged-in user, you can download an export of the account data we store about you (Art. 15/20 GDPR) via the app. For any other requests, an informal email to support@drivebase-app.de is sufficient.
3. Hosting, Server Log Files & Web Fonts
Our website and app assets are hosted on web servers located in Germany. When you load the app, the web server automatically saves temporary connection data (server log files, e.g., IP address, date/time, requested page, browser type). This is processed for IT security and system stability purposes based on Art. 6 para. 1 lit. f GDPR.
For a consistent appearance, we serve the 'Inter' typeface as part of the DriveBase application from our own servers. Loading the font does not connect to Google Fonts or another font provider.
Optional DriveBase emails
Only with your express consent will you receive learning tips, product news and Pro offers from Samuel Hoffleit (Hoffleit Digital). Profile signup is optional, available from age 16 and independent of your account or a purchase. It becomes active only after an additional email confirmation (double opt-in). The legal basis is Article 6(1)(a) GDPR. To select relevant emails we use your email address, account association, language, Free/Pro status and last app activity. At most one marketing email is sent every seven days. We use no opening pixels or individual click tracking.
You can withdraw consent at any time in your profile or through the unsubscribe link in every marketing email without signing in. Processing before withdrawal remains lawful. Emails are sent through our hosting and email provider STRATO, which processes the address and message for delivery. We record the consent wording, version, request and confirmation as evidence. Unconfirmed subscriptions are deleted after 30 days. Delivery details are removed after 90 days; minimal delivery identifiers remain to prevent repeated automations until the contact is deleted. After withdrawal, consent evidence is kept for at most three years to defend potential legal claims (Article 6(1)(f) GDPR). Deleting an account deletes associated contact data and evidence. A hash of an unsubscribed or permanently undeliverable address remains solely to prevent further marketing. This hash is also personal data. The suppression list is reviewed annually for continued necessity.
4. Cookies & LocalStorage
To provide the app features you use, we store technically necessary preferences in LocalStorage, SessionStorage or cookies (section 25(2) no. 2 TDDDG; Art. 6(1)(b) or (f) GDPR). Optional analytics information is stored only after your explicit consent (section 25(1) TDDDG; Art. 6(1)(a) GDPR). This includes:
Language preferences:Stores the chosen language setting to display the app correctly (DE/EN).Learning progress and status information:locally stored results and information indicating whether onboarding is complete or an app session is active.Analytics consent:your decision, policy version and timestamp so that your choice can be respected and documented.Only after consent:a random pseudonymous analytics ID, a short-lived session ID, and normalized campaign information or the referring website's domain.
5. Custom Analytics Tracking
On the website and in the iOS and Android apps, internal pseudonymous usage analytics takes place only after your explicit consent (Art. 6(1)(a) GDPR). Session starts, scroll depth, feature areas used, learning and purchase-funnel events, and technically redacted error data may be sent to our own application backend. Each event uses a random pseudonymous analytics ID, a session ID renewed after 30 minutes of inactivity, the platform, language, and page path without query parameters. Campaign parameters are normalized; for external referrals, we store at most the domain rather than the full URL. We do not collect email addresses, names, free text, push tokens, or complete user-agent or stack-trace data for usage analytics. Raw product-event data is deleted after 90 days and redacted technical error details after 30 days. On public web pages, Cloudflare Web Analytics may additionally be loaded after the same consent. Advertising measurement is separate and requires additional consent. You can withdraw consent at any time under “Pseudonymous usage analytics” in the app settings; optional analytics identifiers are then removed from your device.
Google Analytics
With your additional consent to usage analytics including Google Analytics, we use Google Analytics 4 for traffic sources, page views, scroll depth, product views, checkout starts registrations, trials and confirmed purchases. In Android and iOS, with the same separate consent, we use Firebase Analytics for app launches, screen views and these actions; this may involve a pseudonymous app instance identifier. Advertising-ID collection and personalized ads are disabled. This processes cookies, technical browser data, sanitized page addresses and purchase data (pseudonymous transaction identifier, value, currency and product). We do not pass names, email addresses, form entries or login tokens. Google may process data in the US. The property is linked to Google Ads for campaign reporting; our website configuration disables personalized ads and Google Signals. You can change your consent here at any time.
Optional ad measurement
With separate consent we load Google Ads and the OpenAI Measurement Pixel. Providers process technical browser data, ad click identifiers, purchase identifier, amount and currency to measure ad performance. Processing in the US is possible. Your choice is stored with a timestamp. Without consent these pixels are not loaded. For signed-in users we store advertising consent and an available OpenAI ad click identifier for up to 30 days to link website and app actions. With consent, confirmed native purchases and other app actions are sent to OpenAI through our server without email addresses. Queued events have a seven-day retention period; older events are no longer used for attribution.
On the website, with your advertising consent, we also use the Meta Pixel (Meta Platforms Ireland Limited) to measure page views, Pro views, checkout starts, registrations, trials and confirmed purchases. This may process cookies (in particular _fbp and _fbc), IP address, browser and device information, page addresses, event and purchase data (amount, currency and pseudonymous transaction identifier), and link this information to a Meta account. We do not pass names or email addresses or enable automatic advanced matching. Meta cookies may be stored for up to 90 days. Processing in the US is possible. The legal basis is your consent under Article 6(1)(a) GDPR and, for access to your device, Section 25(1) TDDDG. After withdrawal we send no further Meta events. Previous consent without Meta is not carried over. The website pixel does not measure native app installations. Meta Privacy Policy.
6. User Account & Sign-In (Email, Google & Apple)
You can optionally register and sign in via Single Sign-On (Google Sign-In and Apple Sign-In) or email. If you use these services, the following data will be processed to create your user account and authenticate you (Art. 6 para. 1 lit. b GDPR):
- Unique identification number of the provider (OAuth ID).
- E-mail address (for account creation and contact).
- First and last name (for a personalized user profile).
- Profile picture URL (if enabled by you in your Google settings).
We use the backend service Supabase to manage user accounts and synchronize your learning progress. For technical account administration, we also store whether your signed-in account has used the website, iOS app or Android app, including the first and most recent access per platform, as well as the currently selected learning language (DE/EN) and its most recent synchronization time. This information is not used for advertising. Your account data and learning progress are stored on the basis of a data processing agreement (Art. 28 GDPR). After you delete your account, the associated data is erased unless statutory retention obligations apply.
7. Payment Processing (DriveBase Pro)
When you purchase DriveBase Pro, we and our payment providers process the data required to complete the purchase (Art. 6 para. 1 lit. b GDPR). On the website, payment is processed by Stripe (Stripe Payments Europe, Ltd., Ireland): your payment details (e.g., card data) are collected and processed directly by Stripe — we ourselves never receive full payment details, only a transaction reference, your email address, and the purchase status. In the mobile apps, purchases are processed by the Apple App Store or Google Play in accordance with their privacy policies. To validate purchases and assign your Pro status across platforms, we also use the service RevenueCat (RevenueCat, Inc., USA); pseudonymous user IDs and transaction data are processed in this context. Transfers to third countries are based on appropriate safeguards (e.g., EU Standard Contractual Clauses or the EU-US Data Privacy Framework).
8. Push Notifications (Mobile Apps)
In the mobile apps, you can optionally enable push notifications (e.g. learning or streak reminders). For this purpose, we process a pseudonymous device token, platform, app language and time zone through the Apple Push Notification Service or Firebase Cloud Messaging (Google). If you enable dynamic learning or streak reminders, we also use your selected reminder time, the time of your last learning activity, the most recently started topic and its progress to schedule a relevant reminder (Art. 6 para. 1 lit. a GDPR). Learning reminders, streak reminders and product updates can each be controlled separately. Technical delivery logs are deleted after 90 days at the latest and do not contain device tokens. You can withdraw your consent at any time in the app settings or block notifications in your device settings.
9. E-Mail Communication & Contact
When you contact us via email, your details (name, e-mail address, and message) are stored in our systems to process the request and in case of follow-up questions, based on Art. 6 para. 1 lit. b or f GDPR. We do not share this data without your explicit consent. As a registered user, you will also receive transactional emails (e.g., purchase confirmations) and occasional information about DriveBase features and offers (Art. 6 para. 1 lit. f GDPR). You can object to receiving promotional emails at any time — an informal message to support@drivebase-app.de is sufficient.