driveweekend

Privacy policy

The short version: driveweekend has no accounts, no cookies and no tracking, and your plan never touches our servers. The long version below covers the little that is processed, why, and your rights wherever you live.

Effective 19 July 2026 · applies to driveweekend.com

Who is responsible

driveweekend.com is an independent project operated from within the European Union, as part of the drivenerve family of driving tools — the "controller", where data-protection law uses that term (for example under the EU/UK GDPR). The way to reach the operator, for anything in this policy including a legal request, is email: hello@drivenerve.com. Full legal identity and postal details are provided on request and will be published here when the site's commercial features switch on.

The design principle

The planner runs entirely in your browser. Your trip briefing, your points on the map, your edits and your packing ticks are yours: they live in the page URL and in your device's storage, not in any database of ours. We built it this way on purpose, and this policy is mostly a list of the few places where any data leaves your device at all.

What is processed, and why

1. Your plan — processed only on your device

Everything you enter into the planner (days, car, crew, budget, fuel numbers, your start label, custom stop names, notes, point labels) is encoded into the page URL after the #! symbol. URL fragments are not sent to web servers, so we never receive them. Sharing the link shares the plan; deleting the link deletes the plan. Choose what you type into a plan you intend to share — anyone holding the link can read everything in it.

2. Your browser's local storage

Two conveniences use local storage on your device: your last briefing (so the form remembers your settings) and your packing-list ticks. This storage is strictly functional — it is never read for advertising, analytics or profiling, and it never leaves your device. Clear it any time via your browser's "clear site data". Because we use no cookies and no tracking technologies, this site shows no cookie banner — there is nothing to consent to.

3. The map, search and routing — opt-in by action

Nothing on the map loads until you act (search a place, press "Start from my location", tap the map poster, or open a shared link that has points). When you do, the minimum needed to answer that request is transmitted:

Legal basis where the GDPR applies: performance of the service you are actively requesting (Art. 6(1)(b)) and our legitimate interest in serving those requests efficiently and abuse-free (Art. 6(1)(f)).

4. Email dispatches — only if you sign up

When the sign-up form is offered and you use it, we store your email address for exactly one purpose: sending you occasional driveweekend/drivenerve dispatches. The sign-up is double opt-in — nothing is stored as active until you click the confirmation link we email you. We record the address, the time you signed up and the time you confirmed, and nothing else. Every email contains a one-click unsubscribe link; unsubscribing removes your address from the active list. The list is stored on our own server, is never sold, shared or enriched, and is not used for any other purpose. Legal basis: your consent (GDPR Art. 6(1)(a)), withdrawable at any time via the unsubscribe link or by emailing hello@drivenerve.com. This feature is intended for people aged 16 or over.

5. Hosting logs

The site is served by our hosting provider (Hostinger International Ltd., EU). Like any web host, its servers process IP addresses and request lines transiently in standard server logs, for delivery, security and abuse prevention, with short routine retention. Legal basis: legitimate interest in operating a secure website.

6. Email you send us

If you email hello@drivenerve.com, we keep the correspondence as long as needed to deal with it, then routinely delete it.

What we do not do

Recipients and international transfers

The only recipients of any data are the service providers named above: our hosting provider (EU), the OpenStreetMap Foundation (UK — covered by EU adequacy), HeiGIT gGmbH (Germany), and the community-run OSRM demo infrastructure. We do not transfer personal data to any other third parties. Where a transfer outside your jurisdiction occurs (for example, UK-hosted map tiles viewed from elsewhere), it is limited to the technical minimum described above and protected by the recipient's own published safeguards.

Retention

Your rights

EU/EEA and UK: you have the rights of access, rectification, erasure, restriction, portability and objection, the right to withdraw consent at any time (without affecting prior processing), and the right to complain to a supervisory authority — either the authority of the EU country where the operator is established, or the authority where you live, whichever is easier for you.

California and other US states: you have the rights to know, access, correct and delete personal information, and to non-discrimination for exercising them. We do not sell or share personal information.

Canada (PIPEDA), Australia (Privacy Act 1988/APPs) and New Zealand (Privacy Act 2020): you may request access to and correction of personal information we hold, and complain to the OPC, OAIC or the NZ Privacy Commissioner respectively.

To exercise any right, email hello@drivenerve.com. In practice, the only personal data we could hold about you is a newsletter address and any email you sent us — and you can delete the newsletter entry yourself with the unsubscribe link.

Children

The site is a general-audience trip planner, not directed at children, and collects no data from anyone by default. The email sign-up is for people 16 and over.

Security

The site is served over HTTPS with a strict Content-Security-Policy; the routing key is held server-side and never reaches the browser; the newsletter list is stored outside web-accessible paths and confirmation links use signed tokens. No system is perfect, but the best-protected data remains the data we never collect.

Changes

If this policy changes, the new version appears here with a new effective date. If a change means data starts being processed that wasn't before (for example, the cookieless counter mentioned above), the policy is updated before that change goes live.