DrivenToCollect
Data Retention
Last updated: July 10, 2026
Purpose
This page defines how DrivenToCollect keeps, exports, anonymizes, and deletes service data. It is intended to support account management, GDPR rights handling, security, backup operations, and legal recordkeeping.
Account Data
Account profile data, including name, email address, phone number, password credentials, roles, login status, and account timestamps, is kept while the account is active. When an account deletion request is completed through the profile page, DrivenToCollect anonymizes account profile fields, disables login, clears active sessions, and records the erasure request.
Collection and Vehicle Records
Collection records, vehicle records, checklist data, service records, notes, VINs, license plates, valuation fields, sale marketplace details, and activity history are retained while needed to provide the service, preserve collection history, support shared collection access, resolve disputes, or meet legal obligations. If these records contain personal data, users may request review, correction, export, restriction, or deletion by contacting us.
Uploaded Files and Object Storage
Uploaded vehicle images, checklist attachments, service documents, generated optimized images, and related object metadata are stored to provide vehicle and checklist features. When a vehicle, attachment, or service document is removed through the application, the associated database record and storage object should be removed or made inaccessible as part of the deletion workflow. If an account is anonymized but shared collection records remain, uploaded files associated with those records may remain unless deletion is required by law or approved after review.
Imports and Temporary Processing
Vehicle import batches and import row details are retained long enough to confirm import results, troubleshoot failures, prevent duplicate work, and audit changes. Import records that are no longer needed should be deleted or anonymized during periodic maintenance.
Privacy Requests
Privacy request records are retained to document access, export, correction, erasure, restriction, or objection requests and our response. These records may include the email address used at the time of the request, request type, status, timestamps, and internal handling notes.
Cookies and Sessions
Authentication sessions are short-lived and expire automatically. Cookie consent choices are retained for up to 180 days. Theme preferences may be retained for up to one year when a signed-in user chooses a theme.
Backups and Logs
Backups, infrastructure logs, application logs, and security logs may retain copies of service data for a limited period needed for recovery, reliability, abuse prevention, and security investigation. Data removed from the live service may persist in backups until those backups expire or are overwritten. Restoration from backup should not re-enable a deleted account without reapplying completed erasure records.
Review
Retention rules should be reviewed when new vendors, analytics, storage systems, payment features, or user-facing workflows are added.
Contact
Questions or requests about retention can be sent to info@driventocollect.com.