DriveDocket

DRIVEDOCKET SOLUTIONS LLC
PRIVACY POLICY
Consumer-Facing Mobile & Web Application

Effective Date:  April 2026

Version:  1.0 — MVP Release

Platform:  DriveDocket Mobile Application (iOS & Android) and Web Application

1. Introduction

DriveDocket Solutions LLC (“DriveDocket,” “we,” “us,” or “our”) is committed to protecting the privacy of our users. This Privacy Policy explains what information we collect, how we use it, how we store and protect it, and your rights with respect to your personal information when you use the DriveDocket mobile application (the “Application”).

By creating an account and using the Application, you agree to the collection and use of your information as described in this Privacy Policy. If you do not agree, please do not use the Application.

This Privacy Policy applies to the DriveDocket mobile application for iOS and Android and the DriveDocket web application (collectively, the “Application”). It does not apply to any third-party websites, services, or applications that may be linked from within the Application.

2. Information We Collect
2.1 Information You Provide Directly

When you create an account and use the Application, you provide us with the following information:

• Account registration information: first name, last name, middle name (optional), date of birth (optional), phone number, and email address.
• Uploaded documents: driver’s license (front required; back optional), vehicle registration, insurance card, traffic tickets and citations, excise tax    documents, and vehicle inspection documents.
• Vehicle information: vehicle identification number (VIN), make, model, and year.

2.2 Information Extracted from Your Documents

When you upload documents to the Application, we use optical character recognition (OCR) technology powered by AWS Textract to extract information from those documents. This may include:

• Driver’s license: name, license number, date of birth, address, expiration date, and license class.
• Vehicle registration: vehicle details, registration expiration date, and plate number.
• Insurance card: insurance provider name and policy expiration date.
• Traffic tickets and citations: violation type, violation date, due date, and fine amount.
• Excise tax documents: vehicle details and payment due dates

OCR extraction is used solely to populate your compliance dashboard and generate reminders. You remain responsible for verifying the accuracy of extracted information.

2.3 Information from Public Sources

The Application retrieves certain information from publicly available sources and APIs that do not involve the transmission of your personal information. This includes:

  • • Vehicle recall data from the National Highway Traffic Safety Administration (NHTSA) public recall database, accessed using your vehicle VIN.
    • Municipal street cleaning schedules, where publicly available.
    • Google Civic API data for voting and civic alerts, where applicable.
2.4 Device and Session Data

We collect limited technical information necessary to operate the Application, including:

  • • Authentication tokens (JSON Web Tokens and refresh tokens) for session management. Tokens expire automatically and are revoked upon logout.
    • Push notification tokens to deliver compliance reminders and alerts to your device.
    • A biometric preference flag (enabled or disabled) stored on our servers. No biometric data itself — including fingerprints or facial scans — is collected or stored by DriveDocket. All biometric authentication is handled entirely by your device operating system using Face ID, Touch ID, or fingerprint recognition.

We do not collect GPS or device location data. We do not use any third-party analytics, error tracking, or advertising SDKs. We do not track user behavior within the Application.

3. How We Use Your Information

We use the information we collect solely to provide and improve the DriveDocket service. Specifically, we use your information to:

  • • Create and manage your account.
    • Process and store uploaded documents securely.
    • Extract compliance-relevant data from your documents using OCR.
    • Generate your Driver Compliance Dashboard, compliance status indicators, and Driver Compliance Score.
    • Send you reminders and alerts about document expirations, ticket due dates, vehicle recalls, and other compliance deadlines.
    • Authenticate your identity using one-time passcodes (OTP) sent to your registered email or phone number.
    • Maintain session security and application performance.

We do not use your information for advertising, profiling, credit decisions, insurance underwriting, employment decisions, or any purpose other than providing you with the DriveDocket service.

4. Driver Compliance Score — Important Disclaimer

The Driver Compliance Score generated by the Application is an internal, informational indicator based solely on data you have uploaded. It reflects document validity, expiration timelines, and unresolved violations as tracked within the Application. The Driver Compliance Score is:

  • • Not a credit score, insurance score, or risk score of any kind.
    • Not shared with any third party, including insurers, employers, or government agencies.
    • Not used or intended for any eligibility, underwriting, or employment determination.
    • Informational only and intended solely for your personal awareness and compliance management.

DriveDocket does not operate as a consumer reporting agency as defined under the Fair Credit Reporting Act (FCRA). The Application does not furnish consumer reports and does not access official motor vehicle records (MVRs) from state DMV systems.

5. How We Share Your Information

DriveDocket does not sell your personal information. We do not share your personal information with advertisers or data brokers. We do not share your driving records, violation data, or compliance information with insurers, employers, law enforcement, or government agencies.

We share limited information with the following service providers solely to operate the Application:

  • • Amazon Web Services (AWS): cloud infrastructure for encrypted document storage (AWS S3) and OCR processing (AWS Textract). AWS processes data on our behalf under a data processing agreement and does not have independent rights to use your information.

We may disclose your information if required to do so by law, court order, or valid legal process, or to protect the rights, safety, or property of DriveDocket or its users.

6. Data Storage and Security

Your documents and account data are stored on servers operated by Amazon Web Services (AWS) in the United States. We implement the following security controls:

    • • Encrypted storage for all documents and personal data.
      • Secure API communications using industry-standard encryption protocols.
      • Access controls limiting data access to authorized personnel.
      • Passwordless authentication using one-time passcodes (OTP) delivered via email or SMS. We do not store passwords.
      • Automatic session timeout after five minutes of inactivity.
      • Authentication tokens with automatic expiry; refresh tokens are revoked upon logout.

No security system is impenetrable. While we use commercially reasonable measures to protect your information, we cannot guarantee absolute security. In the event of a data breach that affects your personal information, we will notify you in accordance with applicable law.

7. Data Retention

We retain your account information and documents for as long as your account remains active. You may delete individual documents at any time through the Application.

When you delete your account, the following data is permanently and irreversibly deleted from our systems:

    • • Your account record and all profile information.
      • All uploaded documents, including all copies stored in AWS S3.
      • All vehicle records, infraction records, and notification history.
      • All authentication tokens and push notification tokens.

Certain technical records, such as server logs generated during the development phase, may be retained for a limited period for operational and security purposes. These records do not contain your personal document data.

We may retain information for a longer period where required by applicable law or to fulfill a legal obligation. We will notify you of any such retention requirements to the extent permitted by law.

8. Your Rights and Choices

You have the following rights with respect to your personal information:

    • • Access: you may access and review the information stored in your account at any time through the Application.
      • Correction: you may update or correct inaccurate information in your account profile.
      • Deletion: you may delete individual documents or delete your entire account at any time through the Application Settings. Account deletion results in permanent and irreversible deletion of all your data.
      • Deactivation: if you wish to temporarily suspend access to your account without deleting your data, please contact us at the address below.
      • Portability: you may request a copy of your personal data by contacting us.

To exercise any of these rights or to make a privacy-related inquiry, please contact us at privacy@drivedocket.com.

9. Driver's Privacy Protection Act (DPPA)

The federal Driver’s Privacy Protection Act (DPPA) restricts the disclosure of personal information obtained from state motor vehicle records. DriveDocket does not access, retrieve, or use information from any state DMV database or official motor vehicle record system. All information processed by DriveDocket is provided directly by you, the user, through voluntary document upload. DriveDocket is not a motor vehicle record provider and does not operate within the scope of DPPA-regulated activities.

10. Children's Privacy

The Application is intended for use by individuals who hold or are applying for a driver’s license and are at least 16 years of age. We do not knowingly collect personal information from children under the age of 13. If we become aware that we have collected personal information from a child under 13, we will delete that information promptly. If you believe a child under 13 has created an account, please contact us at privacy@drivedocket.com.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or applicable law. When we make material changes, we will notify you through the Application or by email to your registered address at least 14 days before the changes take effect. Your continued use of the Application after the effective date of the updated Privacy Policy constitutes your acceptance of the changes.

12. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

DriveDocket Solutions LLC
Attn: Privacy
privacy@drivedocket.com
www.drivedocket.com

DriveDocket Solutions LLC — Privacy Policy — Version 1.0 — Effective April 2026 — For incorporation into the DriveDocket Mobile Application, Web Application, and Corporate Website