Passenger Mode is operated by Sean Allen Michael Brown, trading as Passenger Mode (referred to as “Passenger Mode”, “we”, “us” or “our”). Sean Allen Michael Brown is the controller responsible for the personal information described in this policy.
45 Raley Road, SO31 6PA, United Kingdom
privacy@passengermode.co.uk
support@passengermode.co.uk
1. Who this policy covers
This policy covers learner drivers, including users aged 16 and 17, driving instructors, and anyone who contacts Passenger Mode for support or about privacy.
Passenger Mode helps learners develop observation and independent thinking by reflecting on road situations while travelling as a passenger. It is not a driving-test service and must not be used by the person driving.
2. Information we collect and use
Account and identity information
We process:
- email address;
- first name or display name;
- Firebase account identifier;
- whether the account is a learner or instructor;
- account creation and update timestamps; and
- authentication and account-security records.
Firebase Authentication handles passwords and password-reset requests. Passenger Mode does not receive or store users’ passwords in its application database.
Learner and instructor relationship
We process the identifiers needed to link a learner to an instructor, a temporary invitation record, the invitation expiry and redemption status, the join date, and whether the relationship remains active. Invite codes are temporary and single-use. The stored server lookup key is a cryptographic hash rather than the plaintext invite code.
Practice and observation information
We process:
- topics opened and prompts shown;
- the observation choice selected for each prompt;
- shuffled answer-display order;
- response timing and session dates;
- streak and practice totals;
- assigned topics, target question counts and assignment progress; and
- optional lesson-context notes entered by the instructor.
Observation choices are reflection records. Passenger Mode does not create a right-or-wrong learner score. Users and instructors should not put health information, criminal information or other sensitive personal information in lesson notes or support messages.
Preferences
We process the learner’s chosen notification hour, time zone and appearance setting. Reminder notifications are scheduled locally on the device. Passenger Mode does not use these settings to collect precise location.
Product, service and security information
We process limited first-party product events, such as feature use and prompt/session counts, to operate and improve Passenger Mode. Event properties are allowlisted and scrubbed before upload. We also process technical and security information generated when the service is used, which may include IP address, device or app information, user-agent information, request time, authentication events, Firebase App Check/App Attest signals, and Cloud Functions or Google Cloud service logs.
Passenger Mode does not currently use Firebase Analytics, Google Analytics, Firebase Crashlytics, advertising SDKs or cross-app tracking. We do not collect precise location, contacts, photographs, microphone recordings, date of birth or advertising identifiers. We do not sell personal information.
Support information
If someone contacts support, we process their contact details and anything they choose to include in the message, together with our response and resolution notes.
Support and privacy email are provided through Zoho Mail. Do not send passwords, invite codes, detailed medical information or other unnecessary sensitive information in a support request.
3. Why we use information and our lawful bases
We use personal information only where we have a lawful basis under UK data-protection law.
| Purpose | Information used | Lawful basis |
|---|---|---|
| Create and operate an instructor account and provide requested account features | Account, relationship, assignment, preference and practice information | Performance of our contract with the instructor |
| Provide a learner with the requested service and link them to their chosen instructor | Account, relationship, assignment, preference and practice information | Our legitimate interests in providing a private learner–instructor coaching service; balanced through data minimisation, high-privacy defaults, limited instructor visibility and deletion controls |
| Protect accounts, prevent misuse, validate requests and investigate faults | Account-security, App Check, connection and service-log information | Our legitimate interests in securing Passenger Mode and protecting users |
| Understand whether core features work and improve reliability without advertising or cross-app tracking | Allowlisted first-party product events and aggregated usage patterns | Our legitimate interests in maintaining and improving the service, using limited data and no advertising profiles |
| Respond to support and privacy requests | Contact details, correspondence and relevant account records | Our legitimate interests in providing support; compliance with a legal obligation where the request concerns a statutory data-protection right |
| Establish, exercise or defend legal claims and meet binding legal requirements | Relevant account, security and correspondence records | Legal obligation or our legitimate interests, depending on the circumstances |
We do not rely on a learner’s consent merely because they are under 18. iOS notification permission is a separate device permission and can be withdrawn in iOS Settings. If Passenger Mode later introduces an optional use of information that legally requires consent, this policy and the app will be updated before that feature is enabled.
Providing the account details marked in the app is necessary to create and operate an account. Without them, we cannot provide the linked learner–instructor features. Lesson notes are optional.
4. Who can see or receive information
Linked instructors
A learner’s linked instructor can see that learner’s first name, recent practice activity, streak, assigned topic, assignment progress and relevant practice patterns. The instructor may also see lesson-context notes that the instructor added. Other instructors cannot access that learner through Passenger Mode. There are no public profiles, leaderboards or social features.
An instructor’s “parent or guardian told” record is an administrative note only. It does not contact a parent or guardian and is not treated as legal consent.
Service providers
Google provides the production backend and generally acts as our processor for customer data:
- Cloud Firestore stores Passenger Mode application records in
europe-west2(London). - Cloud Functions for Firebase processes Passenger Mode API requests in
europe-west2(London). - Firebase Authentication / Google Identity Platform manages accounts and password-reset email. Google states that Firebase Authentication is operated from data centres in the United States.
- Firebase App Check helps confirm that requests come from the genuine app, and Apple App Attest provides attestation signals.
- Google Cloud Logging stores operational, security and audit logs.
Google’s Firebase privacy information is available at firebase.google.com/support/privacy. The applicable Firebase and Google Cloud data-processing terms and subprocessor information are also available online.
Apple separately processes App Store, device and App Attest information under Apple’s own terms and privacy policies.
Zoho Mail processes the sender and recipient addresses, message content, attachments and associated email metadata needed to deliver and store support and privacy correspondence. Zoho’s privacy information, data-processing terms and subprocessor information are available online.
We may disclose information where required by law, to protect someone’s vital interests, or to establish, exercise or defend legal claims. We do not share personal information with advertisers or data brokers.
We require processors handling Passenger Mode customer data to protect it under written data-processing terms. Before adding another provider or SDK that can receive personal information, we assess its protections and update this policy and our App Store disclosures where necessary.
5. International transfers
Some processing takes place outside the UK. In particular, Google states that Firebase Authentication processes data in the United States, and Firebase or Apple services that do not offer a customer-selected location may use global infrastructure. Passenger Mode’s Zoho Mail account uses Zoho’s EU service environment, although authorised Zoho personnel or subprocessors may process or access information outside the UK where required to provide the service.
Where UK personal information is transferred to a country that is not covered by a UK adequacy regulation, we rely on appropriate contractual safeguards provided under the applicable processor terms. For Google services, these include the relevant EU Standard Contractual Clauses as supplemented for UK transfers by the UK Addendum, or another lawful transfer solution identified in Google’s applicable data-processing terms. A copy of, or information about, the relevant safeguards can be requested using the privacy email above.
6. How long we keep information
- Live accounts and practice records: retained while the account is open and needed to provide Passenger Mode. Accounts with no sign-in or practice activity for 24 months are reviewed and, where reasonably possible, the user is warned before deletion.
- Pending invitations: an invite can be redeemed for 14 days. Expired, unused invitation records and any unclaimed learner placeholder are deleted within 30 days after expiry.
- Account deletion: learner self-deletion, instructor removal of a learner, and instructor self-deletion remove the relevant live Firebase Authentication account and live Firestore records. Instructor self-deletion also removes linked learner accounts and associated live practice data. Deletion cannot be undone.
- Application and service logs: ordinary logs in Google Cloud’s
_Defaultlog bucket are retained for 30 days unless a shorter period is configured. Google Cloud retains required administrator and system audit logs in its_Requiredbucket for 400 days; this period cannot be shortened by Passenger Mode. - Support messages: retained for 12 months after the request is resolved, unless a longer period is reasonably necessary for an ongoing complaint, security investigation or legal claim.
- Privacy-rights records: retained for up to six years after a request is closed where reasonably necessary to demonstrate compliance or handle a legal claim.
- Backups: Passenger Mode does not intentionally maintain a separate long-term Firestore backup at publication. If backup or point-in-time recovery is enabled later, this policy will be updated with the actual expiry period before that change is used for personal information.
Deletion from live systems does not remove information immediately from a log or backup that must complete its stated retention cycle. Such retained copies are not restored for ordinary product use and remain protected until expiry.
7. Young people
Passenger Mode is likely to be used by people under 18 and is designed primarily for learner drivers aged 16 and over. Young users have the same data-protection rights as adults.
We use high-privacy defaults, collect limited information, do not collect precise location or date of birth, do not use advertising or cross-app tracking, do not expose public profiles, and do not use persuasive streak penalties or right/wrong scores. A linked instructor receives only the information described in section 4.
We consider the best interests of young users when designing and changing the service. If a young user does not understand this policy, they may ask a trusted adult or contact us. A parent or guardian may contact us about a young user, but we may need to confirm the young user’s identity and take their own rights and wishes into account before disclosing or changing information.
8. Security
Passenger Mode uses HTTPS for production requests. Firebase Authentication manages password credentials and password-reset messages. Authentication state is stored using Apple platform-protected storage. Production callable functions use Firebase App Check with Apple App Attest, authentication, role and ownership checks, strict input validation and deny-by-default Firestore rules. Direct access from the iOS app to Firestore records is blocked.
No service can guarantee absolute security. If you believe an account or personal information is at risk, contact the privacy email above. Do not send passwords or active invite codes.
9. Automated decisions
Passenger Mode does not make decisions based solely on automated processing that produce legal or similarly significant effects. Practice activity is used to show progress and support instructor-led coaching; it is not used to determine driving-test eligibility, insurance, employment or access to public services.
10. Your data-protection rights
Depending on the circumstances and lawful basis, UK data-protection law may give you the right to:
- be informed about how your information is used;
- request access to your personal information;
- have inaccurate or incomplete information corrected;
- request deletion of your information;
- request restriction of processing;
- object to processing based on legitimate interests;
- receive certain information in a portable format; and
- complain to the Information Commissioner’s Office (ICO).
Your right to object: you may object to processing based on our legitimate interests. We will stop that processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims.
To exercise a right, contact privacy@passengermode.co.uk. We may need to verify identity and clarify the request. We normally respond within one month, subject to the extensions permitted by law.
Users can also delete their account in the app. Learners can use Settings → Delete account permanently. Instructors can use Instructor settings → Delete instructor account. A linked instructor can remove a learner from the instructor panel.
If you are dissatisfied with our response, you may complain to the ICO. You may also seek a remedy through the courts.
11. Changes to this policy
We will review this policy when the app, our service providers or the law changes. The current version will remain available at the privacy-policy URL and will show its effective and last-updated dates. Material changes affecting young users will be explained clearly and in age-appropriate language before or when the change takes effect, as appropriate.
12. Contact us
- Controller: Sean Allen Michael Brown, trading as Passenger Mode
- Postal address: 45 Raley Road, SO31 6PA, United Kingdom
- Privacy email: privacy@passengermode.co.uk
- Support email: support@passengermode.co.uk
- Website: www.passengermode.co.uk