Privacy Notice

How FarangDrive handles account, practice, payment, and refund data.

Last verified: 2026-08-17

This notice explains how farangDrive collects, uses, retains, and shares personal data in connection with the farangDrive website and learning product. It is written for an English-speaking audience and follows the disclosure expectations of the EU General Data Protection Regulation (GDPR).

Controller

farangDrive is operated by Marcel Christophel, trading as farangDrive, Am Wandrahm 27, 28195 Bremen, Germany.

For privacy questions, write to marcel@christophel.io.

We have not appointed a Data Protection Officer. The controller can be contacted directly at the address above.

Categories of personal data we process

  • Account identifier: a deterministic SHA-256 hash of your email address. The plaintext address is used transiently for magic-link delivery, payment-related messages, and refund correspondence.
  • Authentication metadata: anonymous-session identifiers, signed user-session identifiers, magic-link tokens, CSRF secrets, IP-address hash, user-agent hash, and sign-in timestamps.
  • Practice and study data: answer attempts, mistake-queue entries, mock-test results, readiness snapshots, topic progress, and practice-session state.
  • Billing data: Stripe Checkout session ID, payment-intent ID, entitlement records, payment status, refund status, and related finance ledger records. farangDrive does not receive or store card numbers.
  • Refund data: the refund request, slip date, user notes, proof image such as a DLT result slip, proof hash, file metadata, and an admin decision audit trail.
  • Operational telemetry: event names, timestamps, and a small metadata payload for offer/checkout-intent measurement and failure health, such as `upgrade_offer_view`, `checkout_intent`, `stripe_webhook_failure`, or `scheduled_job_failure`.
  • Product feedback: pseudonymous prompt eligibility, display, dismissal, and one-tap answer records linked to an anonymous session and, after sign-in, optionally to the account. Prompts are versioned and contain no free-text field. They may reflect completion of the diagnostic, repeated sign-in visits, a sign-in email that expired, or leaving the upgrade page after a minimum viewing time.
  • Optional product analytics: after consent, an immutable first-touch record processes the landing path, external referrer hostname, allowed UTM source, medium, campaign, term, and content values, and a random acquisition visitor ID. A pseudonymous internal link uses the Stripe Checkout session ID, alongside the anonymous-session link, to measure consented cohorts through the diagnostic, checkout, and captured-purchase journey. This acquisition record does not contain a full URL or referrer, unknown query parameters, advertising click IDs, email address, IP address, user agent, consent ID, Stripe payload, payment-intent ID, charge ID, card data, or other payment details.
  • Optional Google Ads purchase measurement: after separate consent, request and device information available to Google, sanitised context for an eligible paid-search destination or the generic checkout-return page, a safe referrer when available, advertising-click information available to Google, purchase value, currency, and an opaque transaction ID derived from the internal finance-payment row. We do not send Google an email address, FarangDrive user ID, Stripe Checkout session ID, payment-intent ID, charge ID, practice state, or refund data.
  • Consent evidence: unlinked consent receipts containing random browser and decision IDs, policy version and content hash, category choices, action/source, server decision time, and expiry. Consent receipts do not contain account, finance, acquisition, URL, IP-address, user-agent, or advertising-click identifiers.
  • Admin data: admin sign-in/session data, admin actions, refund decisions, curation uploads, and audit logs.
  • Device storage and cookies: see the Cookies and device storage section below.

We do not sell personal data. We do not use Google Analytics, remarketing, personalised advertising, enhanced conversions, advertising audiences, or session replay. We do not intentionally collect special-category data under Art. 9 GDPR.

Purposes and legal bases

  • Account creation and magic-link sign-in: performance of contract (Art. 6 (1) (b) GDPR).
  • Operating the practice, mock, cheat-sheet, and paid-access surfaces: performance of contract.
  • Processing payments and granting entitlements: performance of contract and legal obligations for accounting and tax records.
  • Reviewing and resolving refund requests: performance of contract, legal obligation for transactional records, and legitimate interest in fraud prevention and chargeback defence.
  • Security, CSRF protection, abuse prevention, and rate limiting: legitimate interest (Art. 6 (1) (f) GDPR).
  • Required operational observability and aggregate product records: legitimate interest in service reliability, security, support, and business health. These records are distinct from optional first-touch acquisition analytics and remain necessary when optional processing is refused.
  • Short, contextual product-feedback questions: legitimate interest (Art. 6 (1) (f) GDPR) in identifying avoidable barriers in the learning, sign-in, and purchase journey. Prompts are frequency-limited, can be dismissed, use fixed one-tap answers only, and are not required to use the product.
  • Optional product analytics: consent (Art. 6 (1) (a) GDPR and, where applicable, §25 (1) TDDDG), to understand which first entry brought a consented visitor and how consented entry cohorts progress through the product. Refusal does not limit the product.
  • Optional Google Ads purchase measurement: consent (Art. 6 (1) (a) GDPR and, where applicable, §25 (1) TDDDG). This measures whether a Google ad led to a verified purchase. It is not required to buy or use FarangDrive.
  • Consent evidence: legal obligation and legitimate interest in demonstrating and administering privacy choices (Art. 6 (1) (c) and (f) GDPR).
  • Audit logging of administrative actions: legal obligation where records must be retained and legitimate interest in security and accountability.
  • Error monitoring: legitimate interest in detecting and fixing technical failures.

Where a browser-storage access requires consent under the Telecommunications Digital Services Data Protection Act (TDDDG), farangDrive handles that consent separately from the GDPR legal basis.

Recipients and service providers

We use the following service providers under written data-processing agreements where required:

  • Stripe Payments Europe, Ltd. - payment processing, checkout, tax calculation where enabled, receipts, disputes, and refunds.
  • Resend, Inc. - transactional email delivery for magic links and account, payment, or refund messages.
  • Neon, Inc. - managed Postgres database hosting for account, study, billing, refund, observability, and admin records.
  • Fly.io, Inc. - application hosting and production runtime infrastructure.
  • Tigris Data, Inc. - S3-compatible object storage for generated/media uploads and encrypted database backups where configured.
  • Upstash, Inc. - Redis-compatible infrastructure for rate limiting and operational state where configured.
  • Functional Software, Inc. d/b/a Sentry - error monitoring and diagnostics where enabled.

We keep this list current. Material changes will be reflected in the document version above.

For optional Google Ads purchase measurement, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, receives the data listed above. Under Google's Controller-Controller Data Protection Terms, FarangDrive and Google act as separate controllers for this Google Ads controller service; Google is not described here as FarangDrive's sub-processor. Google may combine or use data under its own terms and privacy policy, including data from Google services and partner sites, subject to the user's Google settings and applicable consent. Google Ads measurement is loaded only after the separate `adsMeasurement` choice. Personalised-ad signals, remarketing, audiences, and enhanced conversions remain disabled.

International data transfers

Some providers are based outside the European Economic Area or may process data outside the EEA. Where this happens, transfers are protected through the EU Standard Contractual Clauses, the EU-US Data Privacy Framework where applicable, and supplementary technical and organisational measures such as TLS in transit, access controls, and restricted operator access. Google's published Ads transfer information states that its advertising services use these mechanisms as applicable. For European Google Ads controller data, Google Ireland Limited is the European end controller; Google affiliates may process data in other countries under Google's controller terms and transfer safeguards.

Cookies and device storage

farangDrive uses cookies and device storage for sign-in, security, paid-access state, admin operation, remembering privacy choices, and the optional purposes selected below. Essential storage is not disabled because the site, checkout, security, and consent evidence depend on it.

  • fd_anon - signed anonymous-session identifier; HttpOnly; used for anonymous practice state, CSRF binding, and account-progress import.
  • fd_user - signed authenticated-user identifier; HttpOnly; used to keep you signed in.
  • fd_csrf - CSRF double-submit token for the public/user surface; readable by the client so write requests can attach the token.
  • fd_progress_saved - short-lived practice-only flag used once after sign-in to show that progress was saved.
  • fd_admin - signed admin-session identifier; HttpOnly; admin surface only.
  • fd_admin_csrf - CSRF double-submit token for the admin surface; readable by the client so admin write requests can attach the token.
  • fd_admin_nav - admin sidebar preference; admin surface only.
  • fd_maintenance_operator - signed HttpOnly, SameSite=Strict operator cookie used only to keep the Maintenance control reachable while public and database-backed traffic is held. It expires after two hours, is accepted only on the Admin settings page and its dedicated control endpoint, and is not issued to learners.
  • fd_maintenance_csrf - readable SameSite=Strict double-submit token paired with the Maintenance operator cookie so changing the Maintenance state or banner requires the same browser. It expires with the operator cookie and is not issued to learners.
  • fd_consent_preferences - essential localStorage record containing the current policy version, random browser consent ID, random decision ID, category choices, and decision time. It is valid for no more than 365 days. Unknown, malformed, expired, or old-policy records are ignored and optional processing stays off.
  • fd_landing_visitor - optional HttpOnly first-party acquisition visitor identifier, retained for up to 90 days and never refreshed beyond the structured first-touch record's original expiry. It is set only after product-analytics consent and is not sent to Google. Withdrawing `productAnalytics` deletes the current acquisition visitor record and its pseudonymous session and checkout links before clearing this cookie; linked historical purchases then appear internally as unattributed.
  • **Google Ads `_gcl_*` cookies, including `_gcl_aw` and `_gcl_gs`, and localStorage key `_gcl_ls`** - optional first-party advertising-click markers created by Google's conversion linker after `adsMeasurement` consent. They can retain click information for up to 90 days, subject to browser and Google configuration. FarangDrive removes controllable `_gcl_*` and `_gac_*` markers on withdrawal; browser or Google-side records already transmitted cannot be recalled.
  • fd_last_sign_in_email - localStorage marker on your device that helps recognise a returning sign-in surface. It may store the last email address used on that device and whether the user explicitly signed out.
  • Practice resume state - FarangDrive does not use localStorage or sessionStorage as a practice-draft owner. Active diagnostic and full-mock progress resumes from server-side mock sessions and accepted attempts; topic practice and mistake drills start fresh after leaving or reloading the flow.
  • farangDrive product-feedback trigger storage - a short localStorage queue records that a frequency-limited question may be considered on the next safe in-app surface. It contains a random visit ID and trigger type, not an email address or answer, and is removed after the server processes it or the related action succeeds.

Before `productAnalytics` consent, the first browser-entry candidate exists only in the current page's memory: it is not sent, logged, or written to cookies, browser storage, observability, or the database. After consent, FarangDrive stores at most one immutable structured first touch per acquisition visitor and uses pseudonymous session and checkout links for the consented first-touch section of the single internal Admin Dashboard. This internal section does not confirm that Google received, accepted, or attributed a Google Ads conversion.

Before `adsMeasurement` consent, FarangDrive uses Google Basic Consent Mode: no Google script, iframe, image, fetch, beacon, cookie, local-storage marker, or consent ping is sent. After consent, the Google tag may load only on the explicitly approved public paid-search destinations listed in FarangDrive's campaign configuration. It does not load on authentication, practice, upgrade, admin, refund, legal, or maintenance pages. Unknown routes, unexpected URL parameters, fragments, credentials, or unsafe referrers fail closed. On a verified purchase, FarangDrive removes the Stripe Checkout session parameter and fragment from the browser URL before loading or emitting Google measurement and supplies only the generic `/checkout/return` page context. The tag is configured with `ad_storage` and `ad_user_data` granted, while `ad_personalization` and Google `analytics_storage` stay denied. The Google Ads conversion action uses a 30-day click-through conversion window. You can review or withdraw either optional purpose through Manage privacy choices in the public footer or on this Privacy page whenever the public site is available. During brief maintenance, optional processing is suspended and these controls are temporarily unavailable; you can send a withdrawal request to marcel@christophel.io. Withdrawal affects future processing and does not make earlier lawful processing or data already sent to Google disappear.

Retention

  • Account record: kept while the account is active. On a verified deletion request, local study data is removed and the account link is removed from retained billing or refund records where full deletion is not legally possible. Billing or refund records are retained only where legal, tax, accounting, dispute, or fraud-prevention obligations require it. German bookkeeping records are commonly retained for up to 10 years under §147 AO.
  • Magic-link tokens: expire automatically after the configured validity window and are discarded or marked consumed once used.
  • Anonymous sessions: the browser cookie expires 30 days after it is issued. Unlinked server-side session, practice, and mock rows are removed after 90 days without activity so the rolling 90-day product report remains complete; signing in links the study history to the account instead.
  • Email outbox: the plaintext recipient is used for delivery and bounded retry, then cleared after a successful send or the third failed attempt. Once a row is older than 30 days, the next daily expiry sweep deletes the remaining recipient hash and message payload, plus any row whose final status write failed; during normal daily operation this occurs before the row reaches 31 days.
  • Practice and mock data: removed or anonymised on account deletion unless a legal retention reason applies.
  • Refund proof images: retained for refund review, dispute handling, and chargeback defence, then deleted when no longer needed under the configured refund-proof deletion workflow.
  • Operational telemetry: retained in the active database for operational dashboards and reliability analysis. The daily observability-retention job deletes events once they are older than 365 days.
  • Product feedback: once a prompt-eligibility, impression, dismissal, or fixed-answer record is older than 180 days from creation, the next daily sweep deletes it; during normal daily operation this occurs before the record reaches 181 days. Later interactions do not reset the creation-based threshold. When a stale anonymous session is removed, its identifier is detached from any retained feedback record. Account deletion removes feedback still linked to that account.
  • Optional product analytics: the landing visitor cookie is retained for up to 90 days. The immutable structured first-touch record and its pseudonymous session and checkout links expire no later than 120 days after the first touch and are removed by the daily acquisition-retention job. The cookie is never refreshed beyond the record's original expiry. This retention is separate from the 365-day operational-observability limit above.
  • Google Ads data: FarangDrive does not keep a separate Google-delivery log. Google's retention applies to data it receives; the configured click-through conversion window is 30 days, while controllable click markers may remain for up to 90 days unless withdrawn sooner.
  • Consent evidence: the current decision remains reconstructable through its validity. Expired, superseded, and withdrawn consent receipts are retained for three years after expiry or supersession, then removed by the daily retention job. Immutable policy snapshots are deleted only when no retained receipt references them.
  • Admin audit logs: retained while needed for security, accountability, legal defence, and operational review.

Deletion from the active database does not immediately remove the same row from isolated disaster-recovery copies. Neon point-in-time recovery may retain an earlier database state for up to 14 days, and encrypted off-site monthly backups may be retained for up to 12 months. These copies are not used for product analytics or normal application access. Before a restored copy can serve customer traffic, the restore procedure runs the active retention sweep again. Incident snapshots are removed after the incident and any documented legal-defence need have ended.

Account deletion

Signed-in users can request account deletion from the Privacy page. The in-app deletion flow removes local study data, removes acquisition first touches and pseudonymous session or checkout links connected to the account, and will, where full deletion is not legally possible, remove the account link from retained billing or refund records. Required finance records remain but become internally unattributed when their acquisition link is removed.

Some payment, refund, accounting, and dispute records may remain where legal, tax, fraud-prevention, chargeback, or legal-defence obligations require retention.

Deletion is not available while an active refund request still needs to be resolved, because farangDrive must keep enough information to complete the refund review.

Your rights

You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and objection (Art. 21 GDPR). You may withdraw either optional consent through Manage privacy choices whenever the public site is available, without affecting the lawfulness of processing before withdrawal. During brief maintenance, optional processing is suspended and you may send the request to the privacy contact below.

For rights requests, write to marcel@christophel.io.

You also have the right to lodge a complaint with a supervisory authority. For the operator's registered location, the competent authority is the Die Landesbeauftragte für Datenschutz und Informationsfreiheit der Freien Hansestadt Bremen. You may also contact the supervisory authority for your habitual residence, workplace, or the place of the alleged infringement.

Automated decision-making

farangDrive does not make decisions that produce legal effects on the user solely by automated means. Refund decisions are reviewed manually.

Changes to this notice

We will update the version and lastVerifiedAt fields above whenever this notice changes. Material changes will be flagged in-app where appropriate.

Contact

Privacy contact: marcel@christophel.io.

Privacy choices

Review or withdraw either optional purpose whenever the public site is available. During brief maintenance, optional processing is suspended and you can email the privacy contact shown in this notice.

Account data

Delete your account data

We delete your account and FarangDrive study data. Payment and refund records needed for accounting, tax, refund, or dispute handling may be retained without an active account link.

Done reading

Ready to practise?

Start the free diagnostic