Legal Information
Privacy Policy
1. Data Controller & General Information
The protection of your personal data is highly important to us. Below, we inform you about the processing of personal data when using the DriveBase App and website in accordance with the General Data Protection Regulation (GDPR).
2. Your Rights as a Data Subject
Under the GDPR, you have the following rights at any time regarding your processed personal data:
- Right of access (Art. 15 GDPR) to your stored data.
- Right to rectification (Art. 16 GDPR) of inaccurate data.
- Right to erasure / Right to be forgotten (Art. 17 GDPR), provided there are no legal storage retention duties.
- Right to restriction of processing (Art. 18 GDPR).
- Right to data portability (Art. 20 GDPR) in a structured format.
- Right to object (Art. 21 GDPR) to future processing.
- Right to withdraw consent (Art. 7 para. 3 GDPR) at any time.
- Right to lodge a complaint with a competent supervisory authority (Art. 77 GDPR).
You can exercise these rights directly yourself: delete your account in the app settings or via the “Delete Account” page on this website. As a logged-in user, you can download an export of the account data we store about you (Art. 15/20 GDPR) via the app. For any other requests, an informal email to support@drivebase-app.de is sufficient.
3. Hosting, Server Log Files & Web Fonts
Our website and app assets are hosted on web servers located in Germany. When you load the app, the web server automatically saves temporary connection data (server log files, e.g., IP address, date/time, requested page, browser type). This is processed for IT security and system stability purposes based on Art. 6 para. 1 lit. f GDPR.
For a consistent appearance, our website embeds the 'Inter' typeface via Google Fonts (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). When you load the page, your browser retrieves the font files from Google servers; for technical reasons, your IP address is transmitted to Google in the process (Art. 6 para. 1 lit. f GDPR — our interest in a consistent, performant presentation). For further details, please refer to Google's privacy policy.
4. Cookies & LocalStorage
To provide the app features you use, we store technically necessary preferences in LocalStorage, SessionStorage or cookies (section 25(2) no. 2 TDDDG; Art. 6(1)(b) or (f) GDPR). Optional analytics information is stored only after your explicit consent (section 25(1) TDDDG; Art. 6(1)(a) GDPR). This includes:
Language preferences:Stores the chosen language setting to display the app correctly (DE/EN).Learning progress and status information:locally stored results and information indicating whether onboarding is complete or an app session is active.Analytics consent:your decision, policy version and timestamp so that your choice can be respected and documented.Only after consent:a random pseudonymous analytics ID, a short-lived session ID, and normalized campaign information or the referring website's domain.
5. Custom Analytics Tracking
On the website and in the iOS and Android apps, internal pseudonymous usage analytics takes place only after your explicit consent (Art. 6(1)(a) GDPR). Session starts, scroll depth, feature areas used, learning and purchase-funnel events, and technically redacted error data may be sent to our own application backend. Each event uses a random pseudonymous analytics ID, a session ID renewed after 30 minutes of inactivity, the platform, language, and page path without query parameters. Campaign parameters are normalized; for external referrals, we store at most the domain rather than the full URL. We do not collect email addresses, names, free text, push tokens, or complete user-agent or stack-trace data for usage analytics. Raw product-event data is deleted after 90 days and redacted technical error details after 30 days. On public web pages, Cloudflare Web Analytics may additionally be loaded after the same consent. We do not perform cross-site advertising tracking. You can withdraw consent at any time under “Pseudonymous usage analytics” in the app settings; optional analytics identifiers are then removed from your device.
6. User Account & Sign-In (Email, Google & Apple)
You can optionally register and sign in via Single Sign-On (Google Sign-In and Apple Sign-In) or email. If you use these services, the following data will be processed to create your user account and authenticate you (Art. 6 para. 1 lit. b GDPR):
- Unique identification number of the provider (OAuth ID).
- E-mail address (for account creation and contact).
- First and last name (for a personalized user profile).
- Profile picture URL (if enabled by you in your Google settings).
We use the backend service Supabase to manage user accounts and synchronize your learning progress. For technical account administration, we also store whether your signed-in account has used the website, iOS app or Android app, including the first and most recent access per platform, as well as the currently selected learning language (DE/EN) and its most recent synchronization time. This information is not used for advertising. Your account data and learning progress are stored on the basis of a data processing agreement (Art. 28 GDPR). After you delete your account, the associated data is erased unless statutory retention obligations apply.
7. Payment Processing (DriveBase Pro)
When you purchase DriveBase Pro, we and our payment providers process the data required to complete the purchase (Art. 6 para. 1 lit. b GDPR). On the website, payment is processed by Stripe (Stripe Payments Europe, Ltd., Ireland): your payment details (e.g., card data) are collected and processed directly by Stripe — we ourselves never receive full payment details, only a transaction reference, your email address, and the purchase status. In the mobile apps, purchases are processed by the Apple App Store or Google Play in accordance with their privacy policies. To validate purchases and assign your Pro status across platforms, we also use the service RevenueCat (RevenueCat, Inc., USA); pseudonymous user IDs and transaction data are processed in this context. Transfers to third countries are based on appropriate safeguards (e.g., EU Standard Contractual Clauses or the EU-US Data Privacy Framework).
8. Push Notifications (Mobile Apps)
In the mobile apps, you can optionally enable push notifications (e.g. learning or streak reminders). For this purpose, we process a pseudonymous device token, platform, app language and time zone through the Apple Push Notification Service or Firebase Cloud Messaging (Google). If you enable dynamic learning or streak reminders, we also use your selected reminder time, the time of your last learning activity, the most recently started topic and its progress to schedule a relevant reminder (Art. 6 para. 1 lit. a GDPR). Learning reminders, streak reminders and product updates can each be controlled separately. Technical delivery logs are deleted after 90 days at the latest and do not contain device tokens. You can withdraw your consent at any time in the app settings or block notifications in your device settings.
9. E-Mail Communication & Contact
When you contact us via email, your details (name, e-mail address, and message) are stored in our systems to process the request and in case of follow-up questions, based on Art. 6 para. 1 lit. b or f GDPR. We do not share this data without your explicit consent. As a registered user, you will also receive transactional emails (e.g., purchase confirmations) and occasional information about DriveBase features and offers (Art. 6 para. 1 lit. f GDPR). You can object to receiving promotional emails at any time — an informal message to support@drivebase-app.de is sufficient.