Skip to content

Privacy Policy

Version in force: 1 October 2026 · Scaling.pt Unipessoal Lda · NIF 516184610

This policy explains how Scaling.pt Unipessoal Lda processes personal data when you use DriveAlert, whether as a vehicle owner with an account or as someone alerting an owner through a sticker. We collect only what is needed, we don't sell data and we don't run ads.

1. Data controller

The controller of your personal data is Scaling.pt Unipessoal Lda, tax number (NIF) 516184610, registered in Portugal, which operates the DriveAlert service (drivealert.pt).

For privacy questions or to exercise your rights, contact [email protected]. For support, use [email protected].

We have not appointed a data protection officer, as we are not required to (Article 37 GDPR). The contact above is our point of contact for all data protection matters.

2. Who this applies to

  • Owners: people who create an account to receive alerts about their vehicles.
  • Reporters: people who scan a sticker's QR code and send an alert, without an account.
  • Visitors: anyone browsing our website.

3. What data we process

We collect only what the service needs. We don't ask for your address, date of birth or identity documents, except where stated.

Category
Account
Data
Mobile number, email, first name (optional), language, notification preferences, date and version of the accepted terms.
Source
The owner
Category
PIN
Data
Stored only as an irreversible cryptographic hash (argon2id). Nobody, including us, can read it.
Source
The owner
Category
Vehicles
Data
Registration plate and, optionally, make, model, name and a photo of the vehicle.
Source
The owner
Category
Vehicle verification
Data
Photo of the vehicle registration document, which may contain the holder's name and address.
Source
The owner, only if they request verification
Category
Stickers and orders
Data
Sticker code and activation history; delivery name and address for orders.
Source
The owner
Category
Alerts received
Data
Type of problem, optional message and photo, date and time, and status (new, seen, resolved).
Source
Reporters
Category
Notifications
Data
Technical identifier of the browser's notification subscription and the delivery status of each alert.
Source
The owner's device, when notifications are enabled
Category
Account security
Data
Signed-in sessions (browser type and last use), failed PIN attempts, recovery requests and a cryptographic hash of the IP address linked to security events.
Source
Use of the service
Category
Reporters
Data
Type of problem, optional message and photo, time taken to send and a pseudonymous technical identifier (section 5).
Source
Reporters
Category
Statistics
Data
Aggregated event counts (for example “sticker scanned” or “alert sent”), without cookies and without identifiers of people or devices.
Source
Use of the service
Category
Technical logs
Data
IP address, date and request made to the server, in the web server logs.
Source
Use of the service

4. Purposes and legal bases

Purpose
Creating and managing the account, registering vehicles, generating the QR and activating stickers.
Legal basis (GDPR)
Performance of a contract — Art. 6(1)(b)
Purpose
Delivering alerts to you (device notification and email copy).
Legal basis (GDPR)
Performance of a contract — Art. 6(1)(b)
Purpose
Receiving and passing on alerts sent by reporters.
Legal basis (GDPR)
Legitimate interest of the owner in being alerted and of the reporter in helping — Art. 6(1)(f)
Purpose
Protecting accounts: PIN, lockout after failed attempts, recovery by email and security notices.
Legal basis (GDPR)
Performance of a contract and legitimate interest in security — Art. 6(1)(b) and (f)
Purpose
Preventing abuse, spam and fraud in alerts: limits, repeat detection and temporary blocks.
Legal basis (GDPR)
Legitimate interest in network and information security (Recital 49) — Art. 6(1)(f)
Purpose
Verifying vehicle ownership and resolving plate disputes.
Legal basis (GDPR)
Legitimate interest in preventing misuse of other people's plates — Art. 6(1)(f)
Purpose
Shipping ordered stickers.
Legal basis (GDPR)
Performance of a contract — Art. 6(1)(b)
Purpose
Invoicing and accounting obligations, once payments exist.
Legal basis (GDPR)
Legal obligation — Art. 6(1)(c)
Purpose
Aggregated statistics to improve the service.
Legal basis (GDPR)
Legitimate interest — Art. 6(1)(f). Statistics don't identify anyone
Purpose
Logging administrative actions.
Legal basis (GDPR)
Legitimate interest and accountability — Arts. 5(2) and 6(1)(f)
Purpose
Responding to authorities and defending legal claims.
Legal basis (GDPR)
Legal obligation and legitimate interest — Art. 6(1)(c) and (f)

Where we rely on legitimate interest, we have assessed that the processing is necessary, kept to a minimum and expected by people using the service. You can object at any time (section 12).

We don't use your data for advertising, we don't build marketing profiles and we don't sell or rent data. If we ever want to send marketing communications, we will only do so with your prior consent.

5. If you alerted an owner through a sticker

  • You don't need an account or to identify yourself. We don't ask for your name, phone or email.
  • The owner only receives the type of problem, the message and photo you choose to send, and the time of the alert. They never receive your IP address or anything that identifies you.
  • To prevent abuse, we compute a technical identifier from the IP address and browser type, using a secret key that changes every day. We don't store the IP address. This identifier only tells us whether the same device sent several alerts on the same day.
  • If the owner marks an alert as abusive, alerts with the same identifier are blocked for 24 hours.
  • We automatically remove hidden metadata from photos, including GPS location and device model.
  • Please don't include personal data in the message and avoid photographing people or other vehicles' plates.
  • Because we don't know who you are, we may be unable to link a rights request to your alerts (Article 11 GDPR). If you contact us with the sticker code and the approximate date and time, we will do our best to help.

6. What people who scan your sticker see

  • The QR code only contains a web address with a random code. It contains no plate, name or contact details.
  • The sticker page doesn't show your number, email, plate or address.
  • Your first name only appears if you allow it in your account settings.
  • There is no plate search and no way to find an owner from a plate.

7. Who we share data with

We only share data with providers that help us run the service, acting on our behalf, following our instructions and under a contract meeting Article 28 GDPR (processors):

Provider
Hosting provider (server and database)
Purpose
Hosting the application, database and files.
Data
All service data, encrypted in transit.
Provider
Email delivery provider
Purpose
Sending verification codes, security notices and alert copies.
Data
Email address and message content.
Provider
Your browser's push service: Google (Chrome and Android), Apple (Safari and iPhone), Mozilla (Firefox) or Microsoft (Edge)
Purpose
Delivering notifications to your device.
Data
End-to-end encrypted notification content, which the service cannot read, and the subscription's technical identifier.
Provider
Courier or postal service
Purpose
Delivering ordered stickers.
Data
Delivery name and address.
Provider
Payment provider, once payments exist
Purpose
Processing payments.
Data
Data needed for the payment, handled by the provider itself.

We may also disclose data to judicial, police or administrative authorities where the law requires it. Otherwise, we don't share data with third parties. An up-to-date list of processors is available on request at [email protected].

8. Transfers outside the European Economic Area

Browser push services may process data outside the European Economic Area (EEA), notably in the United States. These transfers rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework, where the provider is certified, or on the standard contractual clauses approved by the Commission (Implementing Decision (EU) 2021/914). Notification content travels encrypted and can only be read on your device.

If another processor ever handles data outside the EEA, we will apply the same safeguards and update this policy.

9. How long we keep data

Data
Account, vehicles and stickers
Period
For as long as the account exists. Deleted immediately when you delete the account.
Data
Alerts received, including messages and photos
Period
12 months after receipt, or earlier if you delete the vehicle or account.
Data
Test alerts
Period
7 days.
Data
Reporter technical identifier
Period
Kept with the alert, for the same period. Blocks last 24 hours.
Data
Vehicle verification documents
Period
Deleted 30 days after the decision. Requests without a decision expire after 90 days and the document is deleted.
Data
Order delivery name and address
Period
3 years after delivery (legal guarantee period) and deleted immediately if you delete the account. Invoices, once they exist, are kept for the legal period of 10 years.
Data
Verification codes sent by email
Period
1 hour.
Data
Signed-in sessions
Period
Until you sign out, or 90 days without use on a trusted device (12 hours otherwise).
Data
Security events
Period
90 days.
Data
Notification delivery records
Period
90 days.
Data
Administrative action logs
Period
2 years.
Data
Web server technical logs
Period
Up to 30 days.
Data
Backups
Period
Overwritten within a maximum 30-day cycle.
Data
Aggregated statistics
Period
Contain no personal data.

When the period ends, data is deleted or irreversibly anonymised.

10. Cookies and storage on your device

We don't use advertising, analytics or third-party cookies, nor social media trackers. We only use what is strictly necessary to provide the service you ask for, so we don't need your consent (Article 5(2) of Portuguese Law 41/2004 and Article 5(3) of Directive 2002/58/EC).

Name
da_rt
Type
Essential cookie, not accessible to scripts
Purpose
Keeping you signed in.
Duration
Up to 90 days, or until you close the browser if you don't choose to stay signed in.
Name
da_lang
Type
Local storage
Purpose
Remembering your language.
Duration
Until you delete it.
Name
da_push_later
Type
Local storage
Purpose
Remembering that you postponed the notification request.
Duration
3 days.
Name
da_install_later
Type
Local storage
Purpose
Remembering that you postponed the app install instructions.
Duration
7 days.
Name
App cache
Type
Service worker
Purpose
Working offline and updating the app.
Duration
Until the next version or until you clear site data.
Name
Notification subscription
Type
Browser
Purpose
Receiving alerts on your device, only if you enable them.
Duration
Until you disable them.

You can delete this data at any time in your browser settings. If you do, you will need to sign in again.

11. How we protect data

  • All connections use HTTPS (TLS).
  • The PIN is stored with argon2id and never in readable form. After 5 wrong attempts, access is temporarily locked.
  • Sessions use a cookie inaccessible to scripts, renewed on each use, and can be ended on any device.
  • Photos and documents are not public: they are only reachable through signed links that expire.
  • Photo metadata, including location, is removed on upload.
  • Administrative access is restricted and every action is logged.
  • We make regular backups and apply security updates.

No system is infallible. If a personal data breach occurs, we will notify the CNPD within 72 hours where required and inform affected people without undue delay if there is a high risk to their rights (Articles 33 and 34 GDPR).

12. Your rights

  • Access and portability: in Account › Privacy, use “Download my data” to get a complete copy in a structured file (JSON).
  • Rectification: you can correct your data in your account at any time.
  • Erasure: in Account › Delete account. Deletion is immediate and permanent, except for data the law requires us to keep.
  • Restriction and objection, in particular to processing based on legitimate interest.
  • Not being subject to solely automated decisions with legal effects (section 13).
  • Lodging a complaint with the Portuguese data protection authority, Comissão Nacional de Proteção de Dados (CNPD), Av. D. Carlos I, 134, 1.º, 1200-651 Lisboa, www.cnpd.pt.

To exercise rights not available in your account, write to [email protected]. We reply within one month, extendable by two further months for complex requests, in which case we will let you know. Exercising your rights is free. To protect your account, we may ask you to confirm the request from the email linked to it.

13. Automated decisions

To prevent abuse, the system may automatically limit alerts sent from a device (for example, after many alerts in a short time) and temporarily lock an account after several wrong PIN attempts. These measures are temporary, have no legal effects and can be reviewed by a person on request at [email protected]. We make no other automated decisions and do no profiling.

14. Minors

Accounts are for people aged 18 or over. We don't knowingly collect data from minors through accounts. If we learn that a minor created an account, we will delete it.

15. Changes to this policy

We may update this policy to reflect legal or service changes. If changes are significant, we will notify account holders by email or in the app at least 15 days in advance. The version in force is always shown at the top of this page.

Questions about this document? [email protected]

Terms and Conditions