Crash Card™ Privacy Policy

Last updated: September 1, 2026 · Effective: August 2, 2026

Crash Card is a mobile and web application that lets drivers store their driver's license, insurance, and vehicle information on their phone and exchange that information with another driver after a collision. This policy explains, in detail, what information Crash Card collects, where it comes from, how it is processed, who it is shared with, how long it is kept, and what control you have over it.

Crash Card is operated by [LEGAL ENTITY NAME] ("Crash Card," "we," "us," or "our"). This policy applies to the Crash Card iOS and Android apps, the website and web portals at crashcard.app (including the exchange/verify page and Crash Portal™), and all related services (collectively, the "Service").

Please read this first: what Crash Card is not

Crash Card is a record-keeping and information-exchange tool. It is not an insurer, an adjuster, a law enforcement system, a legal advisor, or an arbiter of fault.

Insurance and liability outcomes are decided by insurers, courts, and other authorities using their own processes. See our Terms of Service for disclaimers and limitations of liability.

Contents

  1. Our role and your role
  2. Information we collect
  3. Where the information comes from
  4. How and why we use information
  5. Automated scanning, OCR, and face detection
  6. Location and scene context data
  7. The exchange: information about other people
  8. How information is shared
  9. Service providers and third parties
  10. On-device storage and cookies
  11. Retention and deletion
  12. Security
  13. Your rights and choices
  14. U.S. state privacy notices
  15. Biometric privacy statement
  16. International users and transfers
  17. Children and minors
  18. Beta notice
  19. Changes to this policy
  20. Contact us

1. Our role and your role

Crash Card processes two broad kinds of information, and our responsibility differs for each:

By using the exchange feature, you confirm that you are collecting and sharing information lawfully, for the purpose of documenting a motor vehicle incident, and that you have the other party's cooperation or a lawful basis to do so. If you invite a witness to upload via QR, you are asking them to send a report to insurers on this claim. If someone shared their information with you through Crash Card and wants a copy or deletion, see Section 13.

2. Information we collect

The tables below list the actual categories of data the Service handles. Not every field applies to every user; the app only stores what you scan, type, or permit.

2.1 Account and authentication

DataNotes
Email addressUsed as your login identifier and for confirmation and password-reset emails.
PasswordHandled by our authentication provider and stored only as a salted hash. We never see or store your plaintext password.
Mobile phone numberCollected at registration and shown on your Crash Card so the other driver can reach you.
Session tokensStored securely on your device (see Section 10).
Account timestampsCreated, updated, and last-modified times.

2.2 Driver's license information

When you scan the front and/or back of a driver's license, or type the details in manually, we store:

DataNotes
Full name and date of birthPrinted on the license or encoded in its barcode.
Driver's license number, issuing state, and expiration dateTreated as sensitive information (see Section 14).
AddressRead from the license barcode. For your own profile this is used only during scanning and is not saved to your profile. For a counterparty in an exchange, the address is saved to that incident record.
Learner's permit indicatorA flag noting that the scanned document appears to be a permit rather than a full license. This is a document-type observation, not a judgment about the person or their driving.
Cropped portrait imageA small image of the photo area of the license, used so both drivers can confirm they exchanged with the right person. See Section 15.
Full images of the scanned documentThe photo you take or upload is stored in our private document storage so scanning can run and so you can re-check a bad scan.
Data-quality metadataWhether a field came from automated scanning or was typed by hand, a confidence score, and which fields were edited. This exists so a reviewer can tell how a value was produced. It is not a measure of honesty.

2.3 Insurance and vehicle information

DataNotes
Insurance company, policy number, insurer phone, policy expiration dateScanned from an insurance card or entered manually.
Named insuredThe name printed on the insurance card, and a flag noting whether it differs from the name on the license. A mismatch is common and lawful (family policies, business vehicles, rentals). The flag is descriptive only and is not an allegation of fraud, misrepresentation, or lack of coverage.
"No insurance" declarationRecorded only if a user explicitly selects it. It records a statement made by that user; we do not independently confirm insurance status.
Vehicle year, make, model, colorEntered manually or read from a registration document.
License plate number and state 
VINMay be sent to public vehicle-data services to decode specifications or retrieve a representative vehicle image (see Section 9).
Registration expiration date 
Images of insurance cards and registration documentsStored in private document storage as described above.

Expiration dates shown as "expired" reflect a date printed on a document compared to the current date. Documents can be renewed without the card being replaced, and scanning can misread dates. An "expired" label is not a determination that a person is uninsured or unlicensed.

2.4 Incident and scene information

DataNotes
Date and time of the exchangeWhen the QR code was scanned and when the exchange was completed.
GPS coordinates and a flag for which device supplied themCaptured only with your permission. See Section 6.
Approximate street addressDerived from the coordinates by a reverse-geocoding service.
Weather snapshotConditions summary, temperature, wind, and precipitation at the coordinates and time, from public weather services.
Scene photographs and videosStored on your device only — taken in the app or chosen from your photo library. Not uploaded to Crash Card cloud or shared with the other driver via the exchange portal.
Structured notesStored on your device only — what happened, damage, police, injuries, and witness names and phone numbers you type in yourself.
Witness QR reportsStored in Crash Card private cloud — name, optional phone, statement, and photos/videos a bystander uploads after scanning a witness QR. Shown on the Crash Portal™ link you share with insurers and adjusters. Neither driver sees the video, photos, statement, or phone — only a notice that a report was submitted by that name. Kept about 90 days unless a driver deletes the report or you ask us to.
Free-text notesAnything else you write for your own claim file. Stored on your device only.
Counterparty detailsSee Section 7.
Sharing tokensRandom identifiers used to build your QR code and any Crash Portal™ link you generate.
Multi-vehicle groupingIf more than two vehicles were involved, related exchanges can be grouped into a single accident record with shared scene details.

Notes and photos you take are your account of events. Fields such as "what happened," "point of impact," "injuries," and "damage" record what a user observed or believed at the time. They are statements by that user. Witness reports submitted via QR are different: those files are stored by Crash Card and appear on the Crash Portal™ link you share with insurers. Crash Card does not evaluate them, does not corroborate them, and does not use them to draw any conclusion about who caused a collision.

2.5 Communications and consent records

DataNotes
Text-message consent flag and send timeRecorded if a driver opts in to receive a one-time text with a link to their exchange record. This feature is optional and may not be enabled in all releases.
Support correspondenceIf you email us, we keep the message and our reply.

2.6 Technical and diagnostic data

Our hosting and infrastructure providers generate standard server logs, which may include IP address, timestamps, request paths, device and browser type, and error information. These are used for security, abuse prevention, and troubleshooting. As of the effective date of this policy, Crash Card does not include third-party advertising SDKs, cross-app tracking, marketing analytics, or an advertising identifier. If we add crash reporting or product analytics, we will update this policy before enabling it.

3. Where the information comes from

We do not buy personal information from data brokers, and we do not obtain records from motor vehicle departments or law enforcement databases. License and insurance details reach Crash Card only because a person put their own document in front of a camera or typed it in.

4. How and why we use information

PurposeWhat we useLegal basis (EEA/UK)
Create and secure your accountEmail, password hash, session tokens, server logsContract; legitimate interests (security)
Build and display your digital Crash Card and QR codeProfile, license, insurance, and vehicle data; sharing tokenContract
Read your documents so you don't have to type themDocument imagesContract; explicit consent where required
Exchange information with another driverProfile fields both parties agree to shareContract; legitimate interests of both drivers in documenting an incident
Record the incident and its contextTimestamps, coordinates, address, weather, photos, notesContract; legitimate interests (creating an accurate contemporaneous record)
Hold witness QR reports for insurers on a claimWitness name, optional phone, statement, photos, and videosContract; legitimate interests; the witness's consent at upload
Generate Exchange Reports and Crash Portal™ links you choose to shareIncident record, exchange facts, and witness QR reportsContract; consent (each share is initiated by you)
Send transactional messages (confirmation, password reset, optional exchange receipt)Email, phone numberContract; consent for text messages
Keep the Service secure and prevent abuseLogs, tokens, account metadataLegitimate interests; legal obligation
Respond to support requests and rights requestsCorrespondence and account dataContract; legal obligation
Comply with law and respond to lawful requestsAs requiredLegal obligation

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not use your incident data, documents, photos, or notes to build advertising profiles, to score or rate any individual, or to make automated decisions that produce legal or similarly significant effects about you.

5. Automated scanning, OCR, and face detection

To save you typing, Crash Card reads your documents automatically. Here is exactly how that works:

  1. You capture or select an image of a license, insurance card, or registration.
  2. The image is uploaded to our private storage in a folder scoped to your account.
  3. Our server sends the image to a vision model operated by OpenAI, which returns the text fields it reads and, for a license, the rectangular region where a portrait appears.
  4. For license fronts, our server may also call Amazon Web Services' Rekognition DetectFaces operation. This returns only the coordinates of a rectangle around the photo on the card. We use it to crop the portrait cleanly.
  5. If the license has a PDF417 barcode, it is decoded on your device and the encoded fields are read locally.
  6. The extracted fields are shown to you for review. You can correct any value. Corrected fields are marked as manually entered.

Accuracy of automated extraction

Automated reading is imperfect. Glare, damage, unusual layouts, out-of-state formats, and handwriting all cause errors, and a confidence score is an estimate, not a guarantee. You are responsible for reviewing extracted values before relying on them or sharing them. Crash Card is not liable for consequences arising from mis-scanned or mistyped data, including a claim that is delayed, denied, or disputed.

The vendors above process images to return a result to us. We do not authorize them to use your images to train their general-purpose models, and we rely on their enterprise/API terms, which provide that API content is not used for model training by default. We cannot, however, guarantee the internal practices of any third party; their handling is governed by their own agreements and policies, linked in Section 9.

During development builds only, an alternate scanning path may send an image directly from the device to OpenAI. This path is disabled in the released app.

6. Location and scene context data

A recorded location is where a device reported itself to be when a button was pressed. It is not a determination of where a collision occurred, of the point of impact, or of any traffic violation.

7. The exchange: information about other people

The core feature of Crash Card involves two people deliberately giving each other information. It works like this:

Because the whole point is disclosure, anything on your Crash Card that is part of the exchange will be visible to the other driver and to anyone they show it to. Only include information you are willing to hand over, as you would with a paper license and insurance card.

Where the law requires consent to record or share another person's information, obtaining it is your responsibility. Crash Card provides the mechanism; it does not supervise the interaction, does not confirm identity, and is not a party to the exchange. If the other driver later asks us to delete their submission, we will handle it under Section 13, which may mean removing it from your record as well.

A person who used the exchange without creating an account may still contact us to access or delete what they submitted, using the contact details in Section 20.

8. How information is shared

8.1 With the other driver

As described in Section 7, and only for an exchange you or they initiate.

8.2 Through links you generate

You can create a Crash Portal™ link or export an Exchange Report as a PDF or web page to give to an insurer, adjuster, attorney, or repair shop.

Anyone with the link can view it

A Crash Portal™ link contains a long random token and is not password-protected. Treat it like a key. Anyone you send it to, and anyone they forward it to, can open the exchanged details — names, license and insurance facts, license portraits, location, weather, and witness reports submitted via QR (name, phone, statement, photos, and videos). Scene photos, videos, and written accident notes you take or type yourself stay on the driver's device and are not included on the shared link; those appear only if the driver exports an Exchange Report and sends it. Share a link only with people who need it, and contact us if a link needs to be revoked.

Exported files leave our control entirely once you send them. What happens to a PDF after you email it is outside our ability to manage or retract.

8.3 With service providers

See Section 9. Providers may process data only to deliver their service to us.

8.4 For legal reasons

We may disclose information when we believe in good faith that it is necessary to comply with a law, subpoena, court order, or other lawful request; to enforce our Terms; to investigate suspected fraud or abuse; or to protect the rights, property, or safety of any person. Where we are legally permitted to do so, we will make reasonable efforts to notify the affected user before disclosing.

Incident records are frequently relevant to insurance claims and litigation. If you or another party requests records in connection with a claim or legal proceeding, we may provide them to the extent required or permitted. We produce records; we do not testify to their truth or interpret them.

8.5 Business transfers

If Crash Card is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction. We will require the recipient to honor this policy or provide notice and a choice before materially different handling.

8.6 What we never do

9. Service providers and third parties

ProviderWhat it receivesWhy
Supabase (database, authentication, private file storage, serverless functions)All account, profile, incident, and file dataPrimary backend and hosting
VercelWeb requests and standard server logsHosting for the website and web portals
OpenAIImages of documents you scanReading text fields from documents
Amazon Web Services (Rekognition)License imagesLocating the portrait area so it can be cropped
Twilio (optional feature)Phone number and message textOne-time text receipt after an exchange, if opted in
BigDataCloudLatitude and longitudeConverting coordinates into an approximate address
National Weather Service and Open-MeteoLatitude and longitudeWeather conditions at the scene
OpenStreetMap / Wikimedia, and optionally Mapbox or Google MapsLatitude and longitude within a map image requestStatic map images in reports
NHTSA vPICVINDecoding vehicle year, make, and model. This is a U.S. government public service.
Vehicle image services (including a VIN-based photo service and a stock vehicle image API)VIN or year/make/modelDisplaying a representative image of a vehicle
Apple and GoogleApp distribution and, if you use them, platform services on your deviceApp stores and mobile platforms

We select providers that offer appropriate security and contractual protections, and we limit each to the minimum data needed. Their processing is also governed by their own privacy policies. This list may change; we will keep it current.

10. On-device storage and cookies

11. Retention and deletion

11.1 How long we keep things

DataRetention
Account and profile dataKept while your account is active, and until you delete it or ask us to.
Images of scanned documentsKept in private storage while your account is active so scans can be re-checked. You may ask us to purge them at any time.
Incident exchange records (timestamps, GPS, weather, counterparty fields, handshake)Kept in Crash Card cloud while your account is active. These are the verified exchange facts shared through the Crash Portal™ link.
Scene photos, videos, structured notes, and free-text notes you createKept on your device only until you delete the app, clear site data (web), or remove the incident from your log. We do not retain copies in Crash Card cloud. Export a PDF to preserve a copy for your insurer.
Witness QR reports (name, phone, statement, photos, videos)Kept in Crash Card private cloud for about 90 days after submission, then deleted by an automated purge. Either driver on the claim can delete a report sooner from the Crash Portal™. You or the witness can also email us to request deletion.
Server and security logsKept for a limited period by our infrastructure providers for security and troubleshooting.
Records we must keep by law or for dispute resolutionKept as long as legally required.

11.2 Deleting your account

You can delete your Crash Card profile from Settings → Delete Account. This removes your driver profile data from the app and signs you out.

Important limits on deletion. Deleting your profile in the app does not automatically erase every trace of your data. To have your authentication record, stored document images, and remaining incident data fully removed, email us at crashcardapp@gmail.com and we will complete the erasure and confirm when it is done, ordinarily within 30 days.

We also cannot retrieve or delete the copy another driver holds. Once you complete an exchange, the information you shared exists in that person's incident record, in any report they exported, and with anyone they gave it to. This is inherent to exchanging information, exactly as it is with a photo of a paper insurance card. Similarly, we cannot recall reports or Crash Portal™ links you have already sent to others. Witness QR reports remain on a shared Crash Portal™ link until they expire (about 90 days), a driver deletes them, or we process a deletion request.

We may retain a minimal record of a deletion request itself in order to demonstrate compliance.

12. Security

No method of transmission or storage is completely secure. We cannot guarantee absolute security, and we are not responsible for data exposed because a user shared a Crash Portal™ link or exported report with someone, lost an unlocked device, or reused a compromised password. If a breach affecting your personal information occurs, we will notify you and any regulator as required by applicable law.

13. Your rights and choices

13.1 In the app

13.2 Rights you can exercise by contacting us

Depending on where you live, you may have the right to: know what personal information we hold and how we use it; access a copy; correct inaccuracies; delete it; obtain it in a portable format; limit our use of sensitive personal information; opt out of sale, sharing, or targeted advertising (we do none of these); withdraw consent; and not be discriminated against for exercising these rights.

To make a request, email crashcardapp@gmail.com with the email address on your account and a description of your request. We will verify your identity, typically by confirming control of the account email, before acting, and will respond within the time required by applicable law (generally 30 to 45 days, extendable where permitted). An authorized agent may submit a request on your behalf with proof of authorization.

If you submitted information through an exchange without creating an account, contact us with the phone number or name you provided and the approximate date and place of the exchange, and we will locate the record. If you submitted a witness report via QR, include the name and phone you entered and the approximate date of the crash.

If you believe we have not resolved your request, you may appeal by replying to our decision, and you may lodge a complaint with your state attorney general or, in the EEA/UK, your supervisory authority.

14. U.S. state privacy notices

14.1 Categories of personal information

In the past 12 months we have collected the following categories under the California Consumer Privacy Act, as amended:

CategoryExamples in Crash CardDisclosed to
IdentifiersName, email, phone, address, driver's license number, license plate, VIN, account IDHosting and scanning providers; the other driver in an exchange; recipients of links you share
Customer recordsInsurance policy details, vehicle recordsSame as above
Protected classificationsAge or date of birth, read from a licenseHosting and scanning providers; the other driver
Internet or network activityServer logs, device and browser informationHosting providers
Geolocation dataPrecise coordinates at the time of an exchangeHosting, geocoding, weather, and map providers; the other driver
Visual informationDocument images, cropped license portraits, scene photos and videosHosting and scanning providers; license portraits to the other driver and recipients of a Crash Portal™ link. Scene photos and videos you take stay on the device unless you export an Exchange Report. Witness photos and videos uploaded via QR are stored by Crash Card and shown to recipients of the Crash Portal™ link.
Sensitive personal informationDriver's license number, precise geolocation, account credentials, and images that show a person's faceAs above
InferencesNone. We do not generate profiles, scores, or predictions about you.

We have not sold personal information or shared it for cross-context behavioral advertising in the preceding 12 months, and we do not do so today. We use sensitive personal information only for the purposes of delivering the Service described in this policy, which are purposes for which the right to limit use does not generally apply; even so, you may ask us to restrict or delete it and we will honor the request unless we are legally required to keep it.

14.2 Other states

Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have rights to access, correct, delete, and port their data, and to appeal a denial. We extend these rights to all users regardless of residence. We do not conduct targeted advertising, sell personal data, or engage in profiling that produces legal or similarly significant effects.

14.3 Driver's license information

Crash Card obtains license information from the physical document a person presents or from what they type. We do not obtain it from any state motor vehicle department, and we do not resell, redistribute, or make it available for any purpose other than the exchange the user initiates.

15. Biometric privacy statement

Crash Card does not perform facial recognition and does not collect biometric identifiers.

Portrait images are retained under the same rules as other profile data in Section 11 and are deleted on request or on account erasure.

If your device offers Face ID or fingerprint unlock and you use it, that check happens entirely on your device under Apple's or Google's control. Crash Card never receives your biometric data.

16. International users and transfers

Crash Card is operated from and intended for use in the United States, and information is processed and stored on servers in the United States and in other countries where our providers operate. Data protection laws in those countries may differ from those where you live. If you access the Service from outside the United States, you consent to this transfer and processing. Where required, we rely on appropriate safeguards such as the European Commission's standard contractual clauses for transfers from the EEA, UK, or Switzerland.

17. Children and minors

The Service is intended for licensed drivers and permit holders. It is not directed to children, and we do not knowingly collect personal information from anyone under 13. If you are under 18, you may use the Service only with the involvement and consent of a parent or legal guardian.

A driver's license or permit may contain a date of birth showing that its holder is a minor. We store that value because it appears on the document; we do not use it for any purpose other than displaying and exchanging the document's contents. If you believe a child has provided information to us, contact crashcardapp@gmail.com and we will delete it promptly.

18. Beta notice

Crash Card is offered as a beta service. Features may change, and data created during beta may be affected by migrations or resets. Do not rely on Crash Card as your only record of an incident. Keep your own copies of anything you may need, and continue to follow the reporting requirements of your insurer and local law, including filing a police report where required.

19. Changes to this policy

We may update this policy as the Service evolves. When we do, we will revise the "Last updated" date above. For material changes, such as adding a new category of data, a new type of processing, or a new class of recipient, we will provide notice in the app or by email before the change takes effect where required. Your continued use after an update means you accept the revised policy.

20. Contact us

Questions, requests, and complaints about privacy:

Please include the email address associated with your account so we can locate your records.