PDPICK ADRIVE
EnglishРусскийDeutschFrançais简体中文
User agreementPrivacy policyBooking fee refunds
1. Who handles your data2. Data we process3. Purposes and required permissions4. Identity verification and historical documents5. Recipients and public information6. International processing7. Retention and deletion8. Cookies and device storage9. Your requests and changes
Version 2026-10-04-didit

Privacy policy

This notice describes personal-data processing for Pick a Drive accounts, listings, bookings, payments, verification and support on the website and mobile app. It is separate from the user agreement and any specific consent requested for verification.

1. Who handles your data

North Growth Lab LLC handles current account and marketplace data. Historical bookings and payments retain their original operator context. Use /support or the contact details below for privacy requests. Submit identity documents and selfies only in the verification provider’s secure flow, not in public listings or chat.

2. Data we process

Account and profile data include name, email, phone, address, country, date of birth where provided, user role, language and preferences. Login records include protected password representations, sessions, verification/recovery tokens and technical security information such as IP and device/browser details.

Marketplace records include host/business information, vehicle listings and photos, location, prices and availability; booking participants, dates, amounts and statuses; messages, reviews, inspection photos and support requests. Verification records include provider identifiers, consent time, results, review reasons and historical driving-eligibility records where already collected. Payment records include amounts, currency, references and payment/reconciliation status, not card details entered in Stripe / the provider’s hosted checkout.

We also process language preferences and technical request/security data. Search-entry events record source, language, city and time. Do not post unnecessary personal data in public listings, reviews, messages or trip photographs.

3. Purposes and required permissions

We use relevant data to provide accounts and marketplace functions, arrange bookings and communications, account for our fee, check identity, prevent fraud, secure access, handle complaints and meet applicable legal duties. Processing is based on the consent or other lawful ground required for the particular activity under applicable law; accepting the user agreement does not authorise every possible use.

Where consent is required for verification, biometrics or another purpose, it must cover that specific processing. Optional marketing is not a condition of booking and needs a separate applicable permission. A default notification preference is not evidence of marketing consent.

4. Identity verification and historical documents

Didit provides new identity checks. It processes the chosen identity document, live selfie, biometric comparison and technical fraud-prevention data. Pick a Drive sends the account reference and date of birth, and checks the returned name/date of birth against the account; it stores the session reference, consent time, decision and review reason, not new document or selfie image files. Didit’s privacy notice is https://didit.me/terms/privacy-policy/. Provider retention follows the configured application policy and applicable obligations; account deletion on Pick a Drive does not automatically delete a Didit record. Contact support for access, correction, erasure or a challenge to a decision. Veriff can retain records of historical checks under https://www.veriff.com/privacy-notice; these are not silently transferred to Didit. Previously uploaded platform files remain private and subject to the retention provisions below.

5. Recipients and public information

Listing and review information intended for publication is visible to visitors. Participants in a booking receive information necessary for the relevant booking and communication functions. Authorised personnel access records for their assigned support, safety or administration duties.

Cloudflare supplies hosting, database, private file storage and transactional email. Didit supplies identity verification for guests and hosts. Stripe processes new LLC payments under https://stripe.com/privacy; Whop remains a processor for existing Whop transactions under https://whop.com/privacy. The LLC receives settlement through its bank, Mercury; bank-account numbers are not published. Map services may receive technical request data.

We may disclose relevant records when legally required or necessary to address a specific lawful claim. We do not authorise selling identity documents, using KYC material in advertising or unrestricted staff access through this policy.

6. International processing

Our infrastructure and external providers can process data outside your country of residence. We use Cloudflare D1/R2 and external verification/payment services; this notice does not represent that all data are stored in Kazakhstan. Any applicable localisation requirements and safeguards for cross-border processing remain the operator’s responsibility and are not waived by accepting this policy. Contact us for information about the relevant recipients and transfers.

7. Retention and deletion

Retention is assessed by data category and purpose: account data for providing the account; booking/payment records for performance, applicable accounting duties and specific disputes; messages and trip evidence for the relevant booking, complaint and counterparties’ rights; verification data for the relevant check, fraud review and provider obligations. Security logs, tokens and backups follow their technical lifecycle and applicable retention requirements. The mere existence of an old booking does not justify keeping everything indefinitely.

A deletion request is reviewed to determine what can be erased and what, if anything, must remain for a specific lawful purpose. Account closure, logout or a pending request is not confirmation that all data have been erased. Provider records and backups may require separate handling. We communicate the outcome and applicable retained categories; this notice does not promise an immediate automatic deletion that the service does not perform.

Private uploaded documents are kept for the specific review, fraud prevention and relevant disputes, with access limited to authorised review. They are not public and are not used for advertising. You can request deletion or correction through support; the operator must assess and explain any lawful need to retain a category. This release does not promise automatic document deletion or an unimplemented retention deadline.

8. Cookies and device storage

Session/security cookies support login and protected functions. Language preferences use a cookie and local storage; the language cookie can last up to one year unless cleared or replaced. You can clear browser storage, but this may sign you out or reset preferences. These necessary/preference functions do not provide permission for unrelated advertising tracking.

9. Your requests and changes

Subject to applicable law, you can request information, access, correction, deletion or restriction, withdraw relevant consent, and challenge a decision or complain to a competent authority. Use /support with the Other topic and “Personal data”, or contact the operator below. Withdrawing consent may prevent a function that needs the relevant check; it does not authorise unrelated processing or erase a legal retention duty.

This policy carries a date and version. We communicate material changes as required. Versioned acceptance/acknowledgement records document what was presented, not consent to marketing or a waiver of legal rights.

Operator and contact

North Growth Lab LLC

30 N Gould St Ste N, Sheridan, WY 82801, United States (mailing address)

support@pickadrive.com

Contact support