WheelPlanner Privacy Policy

Effective Date: 2026-07-14

Last Updated: 2026-07-22

Table of Contents

  1. Overview and Scope
  2. Who Controls Your Data
  3. Information We Process
  4. How We Use the Information
  5. Subprocessors
  6. Data Retention
  7. Security Measures
  8. California Breach Notification
  9. No Sale or Sharing of Personal Information
  10. CalOPPA Disclosures
  11. US-Only Service
  12. Future Legal Frameworks
  13. Changes to This Policy
  14. Contact Us

1. Overview and Scope

WheelPlanner is a scheduling and operations platform for California behind-the-wheel (BTW) driving schools. This Privacy Policy explains how Andrew M. Sanchez(“WheelPlanner,” “we,” “our,” or “us”) collects, processes, and protects information in connection with the WheelPlanner platform at wheelplanner.com(the “Service”).

Who this policy covers. This policy applies to:

  • Driving schoolsthat create accounts and use WheelPlanner to manage their operations (“Schools”).
  • Instructors whose information Schools enter into the platform.
  • Students (and their parents or guardians) whose information Schools enter into the platform in order to schedule and manage behind-the-wheel lessons. Students are typically minors between the ages of 15 and 17.

WheelPlanner is a business-to-business (B2B) service. We do not solicit, collect, or market to students or parents directly. Schools subscribe to WheelPlanner and decide what information about their instructors and students to enter. Students and parents do not have independent WheelPlanner accounts and do not post or submit content directly to the Service; accordingly, California Business and Professions Code Section 22581 (minor online erasure rights) does not apply to WheelPlanner's current service model.

2. Who Controls Your Data

Schools are the data controllers for their student and instructor records. When a School enters information about an instructor or a student into WheelPlanner, the School is the party that decided to collect that information and determined the purpose. WheelPlanner acts as a data processor (service provider / custodian) — we process that information only to operate and improve the Service on the School's behalf, not for our own independent purposes.

Practical implications:

  • If a student or parent wants to know what information a School has entered about them, they should contact the School.
  • If a student or parent wants information corrected or deleted, that request goes to the School; the School may then direct WheelPlanner to take action.
  • WheelPlanner will assist Schools in responding to such requests as required by applicable law.
  • If a School is unreachable or has ceased operations, individuals may contact WheelPlanner directly at andrew@wheelplanner.com to request that student records be deleted from our systems.

3. Information We Process

3.1 School Account Data

When a School creates an account, we collect:

  • Business name, contact name, and email address of the account holder.
  • Billing information (payment card details — handled directly by our payments processor Stripe; we do not store full card numbers).
  • Business address (optional, for profile purposes).
  • Login credentials (email and hashed password).

3.2 Instructor Data

Schools may enter the following about their instructors:

  • Name and contact information (email address, phone number).
  • Availability schedules and assigned lesson slots.
  • Vehicle information (if entered by the School).
  • Any notes or records the School adds to an instructor profile.

3.3 Student Data — Including Minors

Schools may enter the following about their students (who are typically minors ages 15-17):

  • Full name, date of birth, and contact information (phone number, email address, or parent/guardian contact).
  • Scheduled lesson dates, times, locations, and instructor assignments.
  • Lesson completion records, notes, and progress information.
  • Any documents uploaded by the School in connection with a student's enrollment (such as DMV forms or progress certificates).
  • Voice recordings or transcribed notes if a School uses WheelPlanner's AI-assisted voice note feature. Voice notes are stored locally on the instructor's device using browser storage (IndexedDB) until they are synced to WheelPlanner's servers or discarded by the instructor. WheelPlanner does not control or purge local device storage; the 90-day retention schedule in Section 6 applies to server-side copies only. Audio submitted for transcription is processed by our AI subprocessor (see Section 5) and is not retained by that provider beyond the processing request.

We do not independently collect information directly from students or minors. All student data is entered by the School. WheelPlanner does not use student data for advertising, profiling, or any purpose beyond operating the Service for the School.

Children under 13.WheelPlanner does not knowingly collect personal information directly from children under 13. All student data is entered by the School. Schools are responsible for ensuring they have obtained any parental consents required for students under the age of 13 before entering that student's information into WheelPlanner. (Note: WheelPlanner does not collect data directly from children under 13, and California's minimum learner's permit age of 15½ means COPPA's under-13 threshold is practically inapplicable to driving-school students. However, edge cases could still trigger COPPA. The FTC's 2025 COPPA Rule amendments (effective April 22, 2026) considered a school-authorization exception and deliberately declined to codify it, leaving only the FTC's non-binding 2022 EdTech guidance. The 2025 rule also newly classifies biometric identifiers, including voiceprints, as personal information under COPPA — relevant to WheelPlanner's voice note feature.)

3.4 Technical and Usage Data

When someone accesses the WheelPlanner platform, we and our hosting and infrastructure providers automatically collect:

  • IP address, browser type, and operating system.
  • Pages visited within the application, timestamps, and general usage patterns.
  • Error logs and diagnostic data.

This data is used to operate, secure, and improve the Service. It is not linked to individual student records for marketing or analytics purposes.

WheelPlanner uses session cookies and similar browser storage mechanisms solely to maintain authenticated login sessions. We do not use third-party advertising or tracking cookies, and we do not track users across third-party websites.

3.5 Communications Data

When Schools, instructors, or parents receive SMS text reminders or transactional emails through WheelPlanner, we process the recipient's phone number or email address and the message content. This applies only to messages initiated by the School (e.g., lesson reminders).

4. How We Use the Information

We use the information described in Section 3 solely to:

  1. Operate the Service — schedule and manage BTW lessons, display calendars, send automated reminders, and generate records for the School.
  2. Process payments— charge the School's subscription fee through Stripe.
  3. Provide support — respond to questions, troubleshoot issues, and communicate with Schools about their accounts.
  4. Maintain security and integrity — detect and prevent fraud, abuse, or unauthorized access.
  5. Improve the Service — analyze aggregate usage patterns (not individual student records) to inform product decisions. We may use aggregate, de-identified statistical data (e.g., average lesson volumes, platform performance metrics) that cannot reasonably be re-linked to any individual School, instructor, or student for product improvement and industry benchmarking.
  6. Comply with law — respond to lawful requests, court orders, or legal obligations, including California breach-notification requirements.

We do not use student data for advertising, behavioral profiling, sale to third parties, or any purpose unrelated to operating the Service for the School that entered that data.

5. Subprocessors

To deliver the Service, WheelPlanner relies on the following third-party subprocessors. Each receives only the data necessary to perform its specific function.

SubprocessorRoleData Received
SupabaseDatabase hosting and authenticationAll application data (encrypted at rest)
VercelWeb hosting and application deliveryRequest logs, application traffic
StripePayment processing (school subscriptions)School billing contact, payment card (Stripe-vaulted; WheelPlanner does not store card numbers). Schools that accept student payments through WheelPlanner may also be subject to Stripe's own privacy policy as a Stripe Connect connected account; Stripe acts as an independent controller for certain payment and identity data under those arrangements.
ResendTransactional email deliveryRecipient email address, message content
TwilioSMS / text message deliveryRecipient phone number, message content
GroqVoice note audio transcription (primary provider)Voice note audio recordings submitted by instructors, which may contain student-identifiable information; sent for the transcription request only
OpenAIVoice note audio transcription (fallback provider, used only when Groq is unavailable)Voice note audio recordings submitted by instructors, which may contain student-identifiable information; sent for the transcription request only
AnthropicVoice note summarization and AI-assisted featuresText transcripts of voice notes and text submitted to AI features; not retained by the AI provider beyond the processing request and not used for AI model training (WheelPlanner's API usage is subject to Anthropic's commercial terms, which prohibit training on API inputs by default)
Google MapsMaps and location services within the platformLocation data for lesson addresses (no student identity sent)

We will update this table and notify Schools by email (per Section 13) when we add or replace a subprocessor.

6. Data Retention

  • School account datais retained for as long as the School's account is active. Upon cancellation, we retain account records for up to 90 days to allow reinstatement, then delete or anonymize them.
  • Student and instructor recordsare retained for as long as the School's account is active and for the 90-day wind-down period thereafter. Schools may delete individual student records at any time through the platform.
  • Voice note server-side copiesare subject to the same 90-day schedule. Voice notes stored locally on an instructor's device (browser storage) are outside WheelPlanner's retention control; instructors may clear browser data to remove local copies.
  • Technical logs are retained for up to 90 days for security and operational purposes.
  • Backup copies may be retained for up to 30 days beyond the deletion of primary records.

If a law, regulation, or legal proceeding requires us to retain records for a longer period, we will do so and notify the School where feasible.

7. Security Measures

We implement reasonable administrative, technical, and physical safeguards appropriate to the sensitivity of the data we hold, including:

  • Encryption of data in transit (TLS) and at rest.
  • Row-level security policies that enforce strict data isolation between Schools (one School cannot access another School's records).
  • Authentication requirements and access controls for all staff who access application infrastructure.
  • Logging of administrative database access.
  • Regular review of subprocessor security practices.

No security measure is perfect or impenetrable. We will notify affected Schools promptly if we discover a breach that may affect their data (see Section 8).

8. California Breach Notification

WheelPlanner processes personal information about California residents, including minors.

California Civil Code Section 1798.82 distinguishes two roles. Under Section 1798.82(b), WheelPlanner as the data maintainer is required to notify the data owner (the School) immediately following discovery of a breach of unencrypted personal information it maintains on the School's behalf. Under Section 1798.82(a), the School as data owner is then responsible for notifying the affected individuals. Schools whose breach affects more than 500 California residents (i.e., 501 or more) from a single breach must also electronically submit a sample copy of the breach notification to the California Attorney General under Section 1798.82(f), within 15 calendar days of notifying the affected individuals. Individual and AG notification are the School's statutory obligations, not WheelPlanner's. Note: as of January 1, 2026, California Civil Code Section 1798.82(a) (as amended by SB 446) requires Schools, as data owners, to notify affected California residents within 30 calendar days of discovering a breach; Schools should plan their response timelines accordingly.

Our commitment:

  • If we discover a data security breach affecting personal information we maintain, we will notify affected Schools immediately following discovery of a breach (or when we reasonably believe a breach has occurred), consistent with our duty as data maintainer under California Civil Code Section 1798.82(b). Our operational target is within 24-48 hours of confirmed discovery, so that Schools can fulfill their notification obligations to students and parents.
  • We will cooperate fully with each affected School's notification obligations and provide Schools with the information they need to fulfill their own duties to affected individuals under California law.
  • Notifications will be provided by email to the School's account email address on file, or by substitute notice where required under California law.
  • We will make reasonable efforts to investigate the scope and cause of any breach and to remediate the vulnerability.

Nothing in this policy limits any School's own notification obligations under applicable law.

9. No Sale or Sharing of Personal Information

WheelPlanner does not:

  • Sell personal information about students, instructors, or school personnel to any third party.
  • Share personal information with third parties for their own marketing or advertising purposes.
  • Use student data for behavioral advertising, cross-context advertising, or data brokering.
  • Disclose personal information to third parties other than the subprocessors listed in Section 5, except as required by law or with the express consent of the School.

If our practices change in the future, we will update this policy and provide advance notice as described in Section 13 before any such change takes effect.

10. CalOPPA Disclosures

The California Online Privacy Protection Act (CalOPPA) requires operators of commercial websites and online services that collect personally identifiable information from California consumers to post a conspicuous privacy policy.

Conspicuous posting. This Privacy Policy is posted in a clearly accessible location on the WheelPlanner website at wheelplanner.com/privacy. We will link to it from our signup flow and from the footer of our main website.

Categories of personally identifiable information collected. We collect the categories described in Section 3: account holder contact information, billing information, instructor information, student information (entered by Schools), technical usage data (including session cookies), and communications data.

Third-party disclosure. We disclose information to the subprocessors listed in Section 5. We do not disclose personally identifiable information to third parties for their own marketing purposes.

How to request changes. Schools may update or correct their own account information by logging into the WheelPlanner platform. To request correction or deletion of other records (including student records), contact us at the address in Section 14.

Do Not Track. California law requires us to disclose how we respond to Do Not Track (DNT) signals from browsers. WheelPlanner does not currently change its data collection or use practices in response to DNT signals because we do not engage in the cross-site behavioral tracking that DNT is designed to limit. We use only first-party session cookies to maintain authenticated login sessions and do not track users across third-party websites for advertising purposes. We will revisit this position if our data practices change.

Third-party collection across websites.WheelPlanner does not permit any third party to collect personally identifiable information about individual users' online activities over time and across different websites when they use this Service. Our infrastructure and service providers listed in Section 5 receive only the data necessary to operate WheelPlanner on our behalf and are prohibited from using that data for their own advertising or cross-site tracking purposes.

11. US-Only Service

WheelPlanner is designed for and marketed exclusively to driving schools operating in the United States. We do not knowingly offer the Service to businesses or individuals outside the United States, and we do not intentionally transfer personal data to recipients located outside the United States, except as necessary for our US-based subprocessors to operate their own US-infrastructure services.

12. Future Legal Frameworks

CCPA / CPRA.The California Consumer Privacy Act and California Privacy Rights Act establish rights for California consumers regarding personal information held by covered businesses. At our current size and scale, WheelPlanner does not meet any of the three thresholds that define a covered “business” under Civil Code Section 1798.140(d)(1): (i) annual gross revenues above $26,625,000 (the 2025 CPI-adjusted figure, adjusted biennially by the California Privacy Protection Agency); (ii) annually buying, selling, or sharing the personal information of 100,000 or more consumers or households; or (iii) deriving 50 percent or more of annual revenues from selling or sharing consumers' personal information. We will monitor the biennial threshold adjustments, and if we grow to a scale where these laws apply, we will update this policy, implement the required rights mechanisms, and notify Schools before those changes take effect.

GDPR. The EU General Data Protection Regulation does not currently apply to WheelPlanner because we do not offer services to individuals in the European Union. If we ever expand beyond the US, we will assess GDPR applicability and update this policy accordingly.

FERPA and AB-1584. These laws apply to educational agencies and institutions — primarily public schools and districts — not to private driving schools operating under DMV licensure. They do not directly bind WheelPlanner at this time. If a School customer is a public program or local educational agency, the School is responsible for its own compliance with applicable education privacy laws; WheelPlanner will cooperate as a service provider upon written request.

SOPIPA. Business and Professions Code Section 22584 (SOPIPA) restricts operators of online services designed and marketed for use in K-12 schools. WheelPlanner is designed for private driving schools licensed by the California DMV, not for K-12 educational institutions, so SOPIPA does not apply to WheelPlanner at this time.

California Age-Appropriate Design Code (AB 2273 / CAADCA).This law imposes design, disclosure, and data-use requirements on businesses that provide online services “likely to be accessed by children” (under 18). As of this writing, a Ninth Circuit preliminary injunction blocks portions of the statute, while other provisions are no longer enjoined following the Ninth Circuit's 2026 ruling in NetChoice v. Bonta. WheelPlanner is a B2B platform; students do not hold WheelPlanner accounts and do not directly access the platform, which may place WheelPlanner outside the statute's scope.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Post the updated policy at wheelplanner.com/privacy with a revised “Last Updated” date.
  • Send an email notice to the account email address on file for each School at least 30 days before the changes take effect, consistent with the notice period in the WheelPlanner Terms of Service.

Your continued use of the Service after the effective date of a revised policy constitutes your acceptance of the changes. If you do not agree to the updated policy, you may cancel your subscription before the effective date.

14. Contact Us

For privacy-related questions, data requests, or breach notifications, contact:

Andrew M. Sanchez
Email: andrew@wheelplanner.com
Address: 8939 Foothill Blvd Ste 130, PMB #4003, Rancho Cucamonga, CA 91730

We will respond to privacy inquiries within 10 business days.

WheelPlanner is operated by Andrew M. Sanchez, a California sole proprietorship.

See also our Terms of Service.