Section 01
Introduction
Drive Service USA is a professional designated-driver and chauffeur service operated by Рамазан Жаксылык (hereinafter "we," "us," or "our"). We are committed to handling the personal information of every person who visits our website, contacts us by phone, or engages our services with the highest degree of care, transparency, and responsibility.
This Privacy Policy applies to all information collected through drive-serviceusa.com and any communication channel associated with our business. It has been drafted to meet the requirements of the General Data Protection Regulation (GDPR — Regulation EU 2016/679), Brazil's Lei Geral de Proteção de Dados (LGPD — Law 13.709/2018), and applicable U.S. consumer-privacy standards.
By using our website or contacting us to enquire about our services, you acknowledge that you have read and understood this policy. If you do not agree with any part of it, please discontinue use of our website and direct any questions to the contact address listed in Section 11 of this document.
Section 02
Information We Collect
We collect personal data in two principal ways: information you actively provide to us, and technical data that is collected automatically when you browse our website.
2.1 — Information You Provide Directly
When you reach out to us — by telephone, by email, via messaging applications such as WhatsApp, or through any contact form on our website — you may share:
- Full name — so we can address you correctly and identify the right account record.
- Phone number — to confirm bookings, send arrival notifications, and reach you in case of changes to your service.
- Email address — for booking confirmations, invoices, and follow-up correspondence.
- Pick-up and drop-off locations — physical addresses or general areas required to plan your journey.
- Date, time and service type — the operational details necessary to fulfil your request.
- Any additional information you volunteer — such as special accessibility requirements or preferences you include in a message.
Providing this information is always voluntary. However, without a minimum set of contact and logistics details we cannot confirm or complete your service booking.
2.2 — Information Collected Automatically
Like virtually every website on the internet, our site automatically receives certain technical information from your browser each time you load a page. This includes:
- IP address — used to infer approximate geographic region for analytics and to block malicious traffic.
- Browser type and version — to ensure our site renders correctly across different devices and software.
- Operating system — for the same compatibility purposes.
- Referring URL — the address of the page or search result you came from before landing on our site.
- Pages visited, time on page, and click paths — aggregated to understand how visitors navigate the site so we can improve it.
- Date and time of each visit — standard server-log information retained for security and diagnostic purposes.
None of this technical data is linked to your personal identity unless you have also submitted contact information during the same session.
2.3 — Information We Do Not Collect
We do not collect payment card numbers, bank account details, government identification numbers, biometric data, or sensitive special-category data as defined under GDPR Article 9. All financial transactions, when applicable, are handled by licensed payment processors who operate under their own privacy and security frameworks.
Section 03
How We Use Your Information
We process personal data only for specified, explicit, and legitimate purposes. Every use of your information described below rests on one of the legal bases defined under GDPR Article 6 and the corresponding provisions of Brazil's LGPD. We do not use your data for any purpose incompatible with those stated here.
- Service fulfilment (Contract performance): Processing your booking, dispatching a driver, confirming arrival details, and issuing a receipt or invoice. This is the primary reason we collect contact and logistics information.
- Customer communication (Legitimate interest / Contract): Responding to enquiries you send us, following up on a completed trip if there is an outstanding matter, and notifying you of significant changes to your booking.
- Service improvement (Legitimate interest): Analysing aggregated, anonymised usage data from our website to identify which pages are most useful, where navigation breaks down, and how we can present our services more clearly.
- Legal and regulatory compliance (Legal obligation): Retaining records as required by applicable commercial, tax, and transport-sector legislation. We are legally obligated to keep certain transaction records for a minimum period.
- Safety and security (Legitimate interest): Detecting and preventing fraudulent activity, unauthorised access, or misuse of our services or website.
- Marketing communications (Consent): Only if you have explicitly opted in, we may occasionally send information about new services or seasonal promotions. You may withdraw this consent at any time by replying "unsubscribe" to any such message or by emailing us at the address in Section 11.
We do not make automated decisions about you — including profiling — that produce legal or similarly significant effects.
Section 04
Cookies & Tracking Technologies
Cookies are small text files placed on your device by a website you visit. They allow the site to remember certain information about your session and preferences. Our website uses a minimal, purposeful selection of cookies — we have deliberately avoided loading unnecessary third-party tracking scripts.
Categories of cookies we use
| Category | Purpose & Examples | Duration |
|---|---|---|
| Strictly NecessaryThese are required for the website to function. They cannot be disabled. | Session management, CSRF security tokens, cookie-consent preference storage. | Session / up to 12 months |
| AnalyticsHelp us understand how visitors use the site so we can improve it. | Google Analytics 4 — tracks page views, session duration, traffic sources, and device type. Data is anonymised at collection; IP addresses are truncated. | Up to 13 months |
| Advertising & RemarketingSupport measurement of paid campaigns. | Google Ads conversion tracking — records when a visitor from a paid ad subsequently contacts us, allowing us to measure campaign effectiveness. No personal profile is built for resale. | Up to 90 days |
Your cookie choices
When you first visit our website you will be presented with a cookie consent banner where you can accept all, reject non-essential, or customise your preferences. You can change or withdraw your consent at any time by clicking the "Cookie Settings" link in our site footer.
Additionally, you can control cookies at the browser level. The following links explain how to manage cookies in the most common browsers: Google Chrome, Mozilla Firefox, Microsoft Edge, and Apple Safari. Please note that disabling analytics cookies will not degrade the functional experience of our website.
For opt-out of Google Analytics measurement specifically, you may install the Google Analytics Opt-out Browser Add-on.
Section 05
Sharing With Third Parties
We do not sell, rent, or trade your personal data. We share it only in the limited circumstances described below, and only to the extent strictly necessary in each case.
- Operational service providers (Data processors): We engage carefully selected technology vendors — including our website hosting provider, email infrastructure, and analytics platform — who process data on our behalf under binding data-processing agreements. These agreements require them to implement appropriate technical and organisational safeguards and to process data only on our documented instructions.
- Google LLC: We use Google Analytics and Google Ads tools. Data is processed in accordance with Google's applicable data-processing terms and the EU Standard Contractual Clauses for international transfers. Google's privacy policy is available at policies.google.com/privacy.
- Telecommunications and messaging platforms: When you contact us via WhatsApp or a similar platform, your message passes through that platform's servers. We recommend reviewing the privacy policy of any third-party application you choose to communicate through.
- Legal and regulatory authorities: We will disclose personal data to competent authorities — such as police, courts, or regulators — when required to do so by a binding legal obligation, court order, or lawful government request. Where legally permissible, we will notify you before making such a disclosure.
- Business transfers: In the event that the business undergoes a restructuring, acquisition, or sale of assets, personal data held at the time may be transferred to the successor entity. Any such transfer will be subject to binding confidentiality obligations, and you will be notified in advance through this policy or directly.
In every case of third-party sharing we ensure that appropriate contractual, technical, and organisational safeguards are in place to protect your data.
International data transfers
Our primary operations are based in Brazil. When data is transferred to countries outside Brazil or the European Economic Area — for example, to servers operated by Google in the United States — we rely on the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, LGPD adequacy determinations. If you have questions about the specific safeguards governing a particular transfer, contact us at the address in Section 11.
Section 06
Data Retention
We retain personal data only for as long as is necessary for the purpose for which it was collected, or as required by applicable law. The following guidelines govern our retention practices:
- Active customer records: Information related to a confirmed or completed service engagement is retained for five (5) years from the date of the last service interaction. This period reflects Brazilian commercial-law requirements (Código Civil, Art. 205) and allows us to address any post-service query or dispute.
- Enquiries that did not result in a booking: If you contacted us but no service was arranged, we retain your contact details for up to six (6) months in case the enquiry is resumed, after which they are deleted from all active systems.
- Accounting and tax records: Brazilian fiscal law requires that records supporting tax filings be kept for at least five (5) years from the end of the fiscal year in question.
- Website analytics data: Aggregated and anonymised analytics data collected via Google Analytics is retained for up to thirteen (13) months, as configured in our Analytics account settings. Raw event-level data subject to sampling is purged after fourteen (14) months.
- Marketing opt-in records: We retain a record of your consent to marketing communications for as long as you remain opted in, plus an additional period of three (3) years after you withdraw, as evidence that the communication was lawfully sent.
When data reaches the end of its retention period, it is securely deleted or irreversibly anonymised. Anonymised data — which can no longer be linked to any individual — may be retained indefinitely for statistical and business-planning purposes.
Section 07
Data Security
We take the security of your personal information seriously and have implemented a layered set of technical and organisational measures to protect it against unauthorised access, accidental loss, disclosure, or destruction.
- Transport-layer encryption: All data transmitted between your browser and our website is encrypted using TLS 1.2 or higher (HTTPS). Our SSL certificate is maintained and renewed on an ongoing basis.
- Access controls: Administrative access to systems that hold personal data is restricted to authorised personnel only, protected by strong passwords and, where the platform supports it, multi-factor authentication.
- Data minimisation: We instruct our teams and service providers to access only the minimum personal data required to perform a specific task — the principle of least privilege.
- Vendor security assessments: Before engaging any data processor, we review their security posture, certifications (such as ISO 27001 or SOC 2 where applicable), and privacy commitments.
- Incident response: We maintain a documented procedure for responding to personal-data breaches. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and will inform affected individuals without undue delay, as required under GDPR Article 33–34 and LGPD Article 48.
Section 08
Your Rights
Depending on your country of residence, you hold a comprehensive set of rights over your personal data under GDPR, LGPD, and other applicable legislation. We are committed to honouring all of them without requiring you to jump through unnecessary hoops.
Right of Access
You may request a copy of all personal data we hold about you, along with information about how it is used and with whom it is shared.
Right to Rectification
If any information we hold about you is inaccurate or incomplete, you have the right to have it corrected without delay.
Right to Erasure
Also known as the "right to be forgotten." You can ask us to delete your personal data when it is no longer necessary for the purpose it was collected, or when you withdraw consent.
Right to Restriction
You can ask us to temporarily halt processing of your data — for example, while you contest its accuracy — without requiring full deletion.
Right to Data Portability
Where processing is based on your consent or a contract, you may request your data in a structured, machine-readable format (e.g., CSV or JSON) for transfer to another provider.
Right to Object
You may object at any time to processing based on legitimate interests, including direct marketing. We will cease processing upon a valid objection unless we demonstrate compelling legitimate grounds.
Right to Withdraw Consent
Where we rely on your consent as the legal basis for processing, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Right to Lodge a Complaint
If you believe we have mishandled your data, you have the right to lodge a complaint with your local data-protection authority — for example, the ANPD (Brazil), the ICO (UK), or your EU member-state supervisory authority.
How to exercise your rights
Submit your request by email to [email protected] with the subject line "Privacy Rights Request." Please include your full name and a brief description of the right you wish to exercise. We will acknowledge your request within 48 hours and respond substantively within 30 calendar days. If we require additional time due to complexity, we will inform you before the initial 30-day period expires. We will not charge a fee for reasonable requests; however, we reserve the right to charge an administrative fee or decline manifestly unfounded or excessive requests, as permitted by law.
We may need to verify your identity before releasing data or actioning a deletion request. We ask that you provide information sufficient to confirm who you are — we will never ask for more than is necessary for this purpose.
Section 09
Children's Privacy
Our services are designed for and marketed exclusively to adults (18 years of age and over). We do not knowingly collect, solicit, or retain personal information from anyone under the age of 18. Our website is not directed at, and does not target, children.
Under Brazil's LGPD (Article 14), the processing of personal data of children requires specific consent from a parent or legal guardian. If you are a parent or guardian and you believe that your child has provided us with personal information without your knowledge or consent, please contact us immediately at [email protected]. Upon receiving such a notification, we will investigate promptly and, where confirmed, delete the information from our records without delay.
Section 10
Changes to This Policy
Privacy law, technology, and our own business practices evolve over time. We review this Privacy Policy at least once annually and update it whenever a material change occurs — such as the introduction of a new processing activity, a change in the legal basis we rely on, or new regulatory guidance that affects our obligations.
When we make substantive changes, we will update the "Last updated" date at the top of this page and, where the change is significant enough to affect your rights or expectations, we will make reasonable efforts to notify you directly — for example, by email if you are an existing customer, or via a prominent notice on our website homepage.
We encourage you to revisit this page periodically. Your continued use of the website or our services after the effective date of a revised policy constitutes acknowledgement of the changes. If you disagree with a material change, you are entitled to exercise your data-rights as described in Section 8 or to discontinue use of our services.
Archived versions of previous policy editions are available on request — contact us at the address in Section 11 if you need to review an earlier version.
Section 11
Contact Us
If you have any questions about this Privacy Policy, wish to exercise a data right, want to report a potential security concern, or simply need clarification on how we handle a specific type of personal information, please reach out to us. We aim to respond to every privacy-related enquiry within two business days.
- Legal Entity
- Рамазан Жаксылык
- [email protected]
- Website
- drive-serviceusa.com
- Response Time
- Within 48 hours on business days
If you are located in the European Union and feel your concern has not been adequately addressed, you have the right to contact your national data-protection supervisory authority. If you are in Brazil, you may contact the Autoridade Nacional de Proteção de Dados (ANPD) at www.gov.br/anpd.