Privacy Policy
Last updated June 26, 2026
DMV+ is operated by DMV.org. This policy explains what we collect, how we use it, who processes it on our behalf, and the choices you have. It does not create any legal rights beyond what applicable law provides.
What we collect
- Plan inputs — your answers to the widget (state, topic, scenario).
- Account data — if you create a DMV+ account: email, display name, household name.
- Garage data — vehicles, drivers, and documents you choose to add.
- Usage events — anonymous session id, page URL, widget interactions, conversion events.
- Payment metadata — handled by Stripe; we store subscription status and the last four digits of your card only.
What we don't collect
- Social security numbers.
- Driver license numbers (unless you upload an image of your license to your private Vault).
- Full payment card numbers.
How we use it
- Generate your DMV Plan and (optionally) email it to you.
- Send transactional emails: account confirmation, password reset, maintenance/registration reminders, recall alerts.
- Send a short lead-nurture sequence if you provided your email without creating an account. You can unsubscribe at any time using the link in any of those emails.
- Run product analytics on aggregated usage events to improve the widget.
We do not sell personal data. We do not share data with third-party advertisers.
Subprocessors
We share data with vendors only to operate the service:
- Lovable Cloud — hosting, database, authentication, file storage.
- Cloudflare — edge network, CDN, DDoS protection, and Worker runtime that serves the app.
- Stripe — subscription billing and payment processing.
- Mailgun (via Lovable Emails) — transactional and lead-nurture email delivery.
- NHTSA — public recall lookup. Your VIN is only sent to NHTSA's public API if you explicitly add a vehicle to your Garage and opt in to recall alerts; we do not share VINs with NHTSA otherwise.
Retention
- Anonymous Plans — retained as long as needed to serve the plan back to you, and pruned periodically.
- Account data — kept while your account is active. Deleted within 30 days of account closure.
- Documents in the Vault — deleted with the account or when you remove them.
- Email send logs — kept 1 year for deliverability diagnostics.
Your choices
- Request a copy of your data, correct it, or delete it via the data request form.
- Unsubscribe from marketing/nurture emails using the link in any such email.
- Transactional emails (password reset, receipts, legally required notices) will continue while your account is active.
- EEA/UK residents: this policy reflects your rights under the GDPR; DMV+ is the data controller.
California residents (CCPA / CPRA)
California residents have the right to know, delete, correct, and limit the use of sensitive personal information collected about them, and to not be discriminated against for exercising these rights.
Do Not Sell or Share My Personal Information: DMV+ does not sell personal information and does not share personal information for cross-context behavioral advertising. To submit a verifiable consumer request under the CCPA/CPRA, use the data request form or email privacy@dmvplus.club.
Cookies
We use first-party cookies and localStorage for sign-in sessions and to remember your last DMV Plan. We do not use third-party advertising cookies.
Children
DMV+ is not directed to children under 13 and we do not knowingly collect their personal data.
Contact
Email privacy@dmvplus.club with any privacy question or to escalate a request. For security reports, email security@dmvplus.club.
DMV.org
8583 Irvine Center Drive, Suite 85
Irvine, CA 92618-4298