Your privacy — in plain language
DriveWaypoints is built by a GDPR consultant, and you can tell from the architecture — not just from a policy text. Here is exactly what we do:
- Positions are deleted automatically after 48 hours. Not "can be deleted" — are deleted. Two independent mechanisms in the database take care of it, every hour, every day.
- We never store a GPS track. Only your most recent position exists — a single point, overwritten every 5 minutes. Your route on the drive cannot be reconstructed, not even by us.
- Data minimisation: A position data point consists of user id, latitude, longitude and time. Nothing else. No speed, no heading, no device information.
- You control the GPS. "Always" / "While in use" / "Off" — the setting lives in your profile, and the app only asks for location once you turn sharing on.
- Anonymity with one tap. Turn on "Anonymous on this drive" and your name and picture are hidden from other participants — you appear as a neutral dot on the map.
- Emergency information is encrypted. If you enter next of kin or medication, it is stored AES-encrypted and can only be opened by the organiser in an emergency.
- Deletion means deletion. If you delete your profile, positions, check-ins, registrations and devices are removed immediately and the account is anonymised. No "retention for analytics purposes".
Who sees what?
| Data |
Other participants |
The organiser |
| Name & profile picture | Yes — unless you are anonymous | Yes |
| Your live position | Only if the organiser chose "the whole group" — and never if you are anonymous | Yes, if position sharing is on |
| Your check-in times | Only on the leaderboard (can be anonymous) | Yes (live dashboard) |
| Emergency information | Never | Only in an emergency |
| Email | Never | Yes (participant list) |
Questions?
Write to privatliv@drivewaypoints.com — you will get an answer from a human who has actually read the GDPR.