Privacy Policy
Version in force: 1 October 2026 · Scaling.pt Unipessoal Lda · NIF 516184610
This policy explains how Scaling.pt Unipessoal Lda processes personal data when you use DriveAlert, whether as a vehicle owner with an account or as someone alerting an owner through a sticker. We collect only what is needed, we don't sell data and we don't run ads.
1. Data controller
The controller of your personal data is Scaling.pt Unipessoal Lda, tax number (NIF) 516184610, registered in Portugal, which operates the DriveAlert service (drivealert.pt).
For privacy questions or to exercise your rights, contact [email protected]. For support, use [email protected].
We have not appointed a data protection officer, as we are not required to (Article 37 GDPR). The contact above is our point of contact for all data protection matters.
2. Who this applies to
- Owners: people who create an account to receive alerts about their vehicles.
- Reporters: people who scan a sticker's QR code and send an alert, without an account.
- Visitors: anyone browsing our website.
3. What data we process
We collect only what the service needs. We don't ask for your address, date of birth or identity documents, except where stated.
- Category
- Account
- Data
- Mobile number, email, first name (optional), language, notification preferences, date and version of the accepted terms.
- Source
- The owner
- Category
- PIN
- Data
- Stored only as an irreversible cryptographic hash (argon2id). Nobody, including us, can read it.
- Source
- The owner
- Category
- Vehicles
- Data
- Registration plate and, optionally, make, model, name and a photo of the vehicle.
- Source
- The owner
- Category
- Vehicle verification
- Data
- Photo of the vehicle registration document, which may contain the holder's name and address.
- Source
- The owner, only if they request verification
- Category
- Stickers and orders
- Data
- Sticker code and activation history; delivery name and address for orders.
- Source
- The owner
- Category
- Alerts received
- Data
- Type of problem, optional message and photo, date and time, and status (new, seen, resolved).
- Source
- Reporters
- Category
- Notifications
- Data
- Technical identifier of the browser's notification subscription and the delivery status of each alert.
- Source
- The owner's device, when notifications are enabled
- Category
- Account security
- Data
- Signed-in sessions (browser type and last use), failed PIN attempts, recovery requests and a cryptographic hash of the IP address linked to security events.
- Source
- Use of the service
- Category
- Reporters
- Data
- Type of problem, optional message and photo, time taken to send and a pseudonymous technical identifier (section 5).
- Source
- Reporters
- Category
- Statistics
- Data
- Aggregated event counts (for example “sticker scanned” or “alert sent”), without cookies and without identifiers of people or devices.
- Source
- Use of the service
- Category
- Technical logs
- Data
- IP address, date and request made to the server, in the web server logs.
- Source
- Use of the service
| Category | Data | Source |
|---|---|---|
| Account | Mobile number, email, first name (optional), language, notification preferences, date and version of the accepted terms. | The owner |
| PIN | Stored only as an irreversible cryptographic hash (argon2id). Nobody, including us, can read it. | The owner |
| Vehicles | Registration plate and, optionally, make, model, name and a photo of the vehicle. | The owner |
| Vehicle verification | Photo of the vehicle registration document, which may contain the holder's name and address. | The owner, only if they request verification |
| Stickers and orders | Sticker code and activation history; delivery name and address for orders. | The owner |
| Alerts received | Type of problem, optional message and photo, date and time, and status (new, seen, resolved). | Reporters |
| Notifications | Technical identifier of the browser's notification subscription and the delivery status of each alert. | The owner's device, when notifications are enabled |
| Account security | Signed-in sessions (browser type and last use), failed PIN attempts, recovery requests and a cryptographic hash of the IP address linked to security events. | Use of the service |
| Reporters | Type of problem, optional message and photo, time taken to send and a pseudonymous technical identifier (section 5). | Reporters |
| Statistics | Aggregated event counts (for example “sticker scanned” or “alert sent”), without cookies and without identifiers of people or devices. | Use of the service |
| Technical logs | IP address, date and request made to the server, in the web server logs. | Use of the service |
4. Purposes and legal bases
- Purpose
- Creating and managing the account, registering vehicles, generating the QR and activating stickers.
- Legal basis (GDPR)
- Performance of a contract — Art. 6(1)(b)
- Purpose
- Delivering alerts to you (device notification and email copy).
- Legal basis (GDPR)
- Performance of a contract — Art. 6(1)(b)
- Purpose
- Receiving and passing on alerts sent by reporters.
- Legal basis (GDPR)
- Legitimate interest of the owner in being alerted and of the reporter in helping — Art. 6(1)(f)
- Purpose
- Protecting accounts: PIN, lockout after failed attempts, recovery by email and security notices.
- Legal basis (GDPR)
- Performance of a contract and legitimate interest in security — Art. 6(1)(b) and (f)
- Purpose
- Preventing abuse, spam and fraud in alerts: limits, repeat detection and temporary blocks.
- Legal basis (GDPR)
- Legitimate interest in network and information security (Recital 49) — Art. 6(1)(f)
- Purpose
- Verifying vehicle ownership and resolving plate disputes.
- Legal basis (GDPR)
- Legitimate interest in preventing misuse of other people's plates — Art. 6(1)(f)
- Purpose
- Shipping ordered stickers.
- Legal basis (GDPR)
- Performance of a contract — Art. 6(1)(b)
- Purpose
- Invoicing and accounting obligations, once payments exist.
- Legal basis (GDPR)
- Legal obligation — Art. 6(1)(c)
- Purpose
- Aggregated statistics to improve the service.
- Legal basis (GDPR)
- Legitimate interest — Art. 6(1)(f). Statistics don't identify anyone
- Purpose
- Logging administrative actions.
- Legal basis (GDPR)
- Legitimate interest and accountability — Arts. 5(2) and 6(1)(f)
- Purpose
- Responding to authorities and defending legal claims.
- Legal basis (GDPR)
- Legal obligation and legitimate interest — Art. 6(1)(c) and (f)
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating and managing the account, registering vehicles, generating the QR and activating stickers. | Performance of a contract — Art. 6(1)(b) |
| Delivering alerts to you (device notification and email copy). | Performance of a contract — Art. 6(1)(b) |
| Receiving and passing on alerts sent by reporters. | Legitimate interest of the owner in being alerted and of the reporter in helping — Art. 6(1)(f) |
| Protecting accounts: PIN, lockout after failed attempts, recovery by email and security notices. | Performance of a contract and legitimate interest in security — Art. 6(1)(b) and (f) |
| Preventing abuse, spam and fraud in alerts: limits, repeat detection and temporary blocks. | Legitimate interest in network and information security (Recital 49) — Art. 6(1)(f) |
| Verifying vehicle ownership and resolving plate disputes. | Legitimate interest in preventing misuse of other people's plates — Art. 6(1)(f) |
| Shipping ordered stickers. | Performance of a contract — Art. 6(1)(b) |
| Invoicing and accounting obligations, once payments exist. | Legal obligation — Art. 6(1)(c) |
| Aggregated statistics to improve the service. | Legitimate interest — Art. 6(1)(f). Statistics don't identify anyone |
| Logging administrative actions. | Legitimate interest and accountability — Arts. 5(2) and 6(1)(f) |
| Responding to authorities and defending legal claims. | Legal obligation and legitimate interest — Art. 6(1)(c) and (f) |
Where we rely on legitimate interest, we have assessed that the processing is necessary, kept to a minimum and expected by people using the service. You can object at any time (section 12).
We don't use your data for advertising, we don't build marketing profiles and we don't sell or rent data. If we ever want to send marketing communications, we will only do so with your prior consent.
5. If you alerted an owner through a sticker
- You don't need an account or to identify yourself. We don't ask for your name, phone or email.
- The owner only receives the type of problem, the message and photo you choose to send, and the time of the alert. They never receive your IP address or anything that identifies you.
- To prevent abuse, we compute a technical identifier from the IP address and browser type, using a secret key that changes every day. We don't store the IP address. This identifier only tells us whether the same device sent several alerts on the same day.
- If the owner marks an alert as abusive, alerts with the same identifier are blocked for 24 hours.
- We automatically remove hidden metadata from photos, including GPS location and device model.
- Please don't include personal data in the message and avoid photographing people or other vehicles' plates.
- Because we don't know who you are, we may be unable to link a rights request to your alerts (Article 11 GDPR). If you contact us with the sticker code and the approximate date and time, we will do our best to help.
6. What people who scan your sticker see
- The QR code only contains a web address with a random code. It contains no plate, name or contact details.
- The sticker page doesn't show your number, email, plate or address.
- Your first name only appears if you allow it in your account settings.
- There is no plate search and no way to find an owner from a plate.
7. Who we share data with
We only share data with providers that help us run the service, acting on our behalf, following our instructions and under a contract meeting Article 28 GDPR (processors):
- Provider
- Hosting provider (server and database)
- Purpose
- Hosting the application, database and files.
- Data
- All service data, encrypted in transit.
- Provider
- Email delivery provider
- Purpose
- Sending verification codes, security notices and alert copies.
- Data
- Email address and message content.
- Provider
- Your browser's push service: Google (Chrome and Android), Apple (Safari and iPhone), Mozilla (Firefox) or Microsoft (Edge)
- Purpose
- Delivering notifications to your device.
- Data
- End-to-end encrypted notification content, which the service cannot read, and the subscription's technical identifier.
- Provider
- Courier or postal service
- Purpose
- Delivering ordered stickers.
- Data
- Delivery name and address.
- Provider
- Payment provider, once payments exist
- Purpose
- Processing payments.
- Data
- Data needed for the payment, handled by the provider itself.
| Provider | Purpose | Data |
|---|---|---|
| Hosting provider (server and database) | Hosting the application, database and files. | All service data, encrypted in transit. |
| Email delivery provider | Sending verification codes, security notices and alert copies. | Email address and message content. |
| Your browser's push service: Google (Chrome and Android), Apple (Safari and iPhone), Mozilla (Firefox) or Microsoft (Edge) | Delivering notifications to your device. | End-to-end encrypted notification content, which the service cannot read, and the subscription's technical identifier. |
| Courier or postal service | Delivering ordered stickers. | Delivery name and address. |
| Payment provider, once payments exist | Processing payments. | Data needed for the payment, handled by the provider itself. |
We may also disclose data to judicial, police or administrative authorities where the law requires it. Otherwise, we don't share data with third parties. An up-to-date list of processors is available on request at [email protected].
8. Transfers outside the European Economic Area
Browser push services may process data outside the European Economic Area (EEA), notably in the United States. These transfers rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework, where the provider is certified, or on the standard contractual clauses approved by the Commission (Implementing Decision (EU) 2021/914). Notification content travels encrypted and can only be read on your device.
If another processor ever handles data outside the EEA, we will apply the same safeguards and update this policy.
9. How long we keep data
- Data
- Account, vehicles and stickers
- Period
- For as long as the account exists. Deleted immediately when you delete the account.
- Data
- Alerts received, including messages and photos
- Period
- 12 months after receipt, or earlier if you delete the vehicle or account.
- Data
- Test alerts
- Period
- 7 days.
- Data
- Reporter technical identifier
- Period
- Kept with the alert, for the same period. Blocks last 24 hours.
- Data
- Vehicle verification documents
- Period
- Deleted 30 days after the decision. Requests without a decision expire after 90 days and the document is deleted.
- Data
- Order delivery name and address
- Period
- 3 years after delivery (legal guarantee period) and deleted immediately if you delete the account. Invoices, once they exist, are kept for the legal period of 10 years.
- Data
- Verification codes sent by email
- Period
- 1 hour.
- Data
- Signed-in sessions
- Period
- Until you sign out, or 90 days without use on a trusted device (12 hours otherwise).
- Data
- Security events
- Period
- 90 days.
- Data
- Notification delivery records
- Period
- 90 days.
- Data
- Administrative action logs
- Period
- 2 years.
- Data
- Web server technical logs
- Period
- Up to 30 days.
- Data
- Backups
- Period
- Overwritten within a maximum 30-day cycle.
- Data
- Aggregated statistics
- Period
- Contain no personal data.
| Data | Period |
|---|---|
| Account, vehicles and stickers | For as long as the account exists. Deleted immediately when you delete the account. |
| Alerts received, including messages and photos | 12 months after receipt, or earlier if you delete the vehicle or account. |
| Test alerts | 7 days. |
| Reporter technical identifier | Kept with the alert, for the same period. Blocks last 24 hours. |
| Vehicle verification documents | Deleted 30 days after the decision. Requests without a decision expire after 90 days and the document is deleted. |
| Order delivery name and address | 3 years after delivery (legal guarantee period) and deleted immediately if you delete the account. Invoices, once they exist, are kept for the legal period of 10 years. |
| Verification codes sent by email | 1 hour. |
| Signed-in sessions | Until you sign out, or 90 days without use on a trusted device (12 hours otherwise). |
| Security events | 90 days. |
| Notification delivery records | 90 days. |
| Administrative action logs | 2 years. |
| Web server technical logs | Up to 30 days. |
| Backups | Overwritten within a maximum 30-day cycle. |
| Aggregated statistics | Contain no personal data. |
When the period ends, data is deleted or irreversibly anonymised.
11. How we protect data
- All connections use HTTPS (TLS).
- The PIN is stored with argon2id and never in readable form. After 5 wrong attempts, access is temporarily locked.
- Sessions use a cookie inaccessible to scripts, renewed on each use, and can be ended on any device.
- Photos and documents are not public: they are only reachable through signed links that expire.
- Photo metadata, including location, is removed on upload.
- Administrative access is restricted and every action is logged.
- We make regular backups and apply security updates.
No system is infallible. If a personal data breach occurs, we will notify the CNPD within 72 hours where required and inform affected people without undue delay if there is a high risk to their rights (Articles 33 and 34 GDPR).
12. Your rights
- Access and portability: in Account › Privacy, use “Download my data” to get a complete copy in a structured file (JSON).
- Rectification: you can correct your data in your account at any time.
- Erasure: in Account › Delete account. Deletion is immediate and permanent, except for data the law requires us to keep.
- Restriction and objection, in particular to processing based on legitimate interest.
- Not being subject to solely automated decisions with legal effects (section 13).
- Lodging a complaint with the Portuguese data protection authority, Comissão Nacional de Proteção de Dados (CNPD), Av. D. Carlos I, 134, 1.º, 1200-651 Lisboa, www.cnpd.pt.
To exercise rights not available in your account, write to [email protected]. We reply within one month, extendable by two further months for complex requests, in which case we will let you know. Exercising your rights is free. To protect your account, we may ask you to confirm the request from the email linked to it.
13. Automated decisions
To prevent abuse, the system may automatically limit alerts sent from a device (for example, after many alerts in a short time) and temporarily lock an account after several wrong PIN attempts. These measures are temporary, have no legal effects and can be reviewed by a person on request at [email protected]. We make no other automated decisions and do no profiling.
14. Minors
Accounts are for people aged 18 or over. We don't knowingly collect data from minors through accounts. If we learn that a minor created an account, we will delete it.
15. Changes to this policy
We may update this policy to reflect legal or service changes. If changes are significant, we will notify account holders by email or in the app at least 15 days in advance. The version in force is always shown at the top of this page.
Questions about this document? [email protected]
Terms and Conditions