Privacy policy
Provisional notice. This policy describes exactly how the site handles data today. Three elements — the lawful basis, the data-retention periods, and the process for exercising your rights — are pending professional legal review and are marked as such below. No operating entity is registered yet, so the data controller is not yet named (see below).
Who runs this site
DMVCA (dmvca.info) is an independent guide to the California DMV. It is not affiliated with, endorsed by, or connected to the California DMV or any government agency.
Data controller — to be completed on registration. No operating entity is registered yet, so this policy does not name one. When it is, the controller's legal name, registration number, and registered address will be added here — this section is not yet complete. Until then, the contact and rights route for anything in this policy is [email protected].
Two layers: the application and the host
This site is a static website — pre-built pages served as files. Two layers process data differently:
- The application (the pages and their code) sets no cookies, writes nothing to your browser's local or session storage, collects nothing through forms, and loads no third-party script or resource on page load. Loading any page requests files from dmvca.info only — until you click to load a map (see below). This is verifiable: the source contains no cookie,
localStorage, orsessionStoragecode, and the server returns noSet-Cookieheader on any page. - The host and CDN (Cloudflare) receives and processes each request to serve the page, which necessarily includes your IP address and standard request metadata. This is host processing, not something the application does.
The only two third parties
There are two, and no others — no advertising, no social-media trackers, no tag managers, no affiliate networks.
Cloudflare — host, CDN, and analytics
- Hosting and delivery. Cloudflare serves the site from its edge network and processes each request's IP address, timestamp, requested URL, HTTP method, response status, user-agent, and approximate location/network — the standard metadata any host or CDN handles, retained by Cloudflare for security and operational purposes.
- Analytics — no client-side tracking. There is no analytics beacon, no analytics cookie, and no client-side analytics script on this site. Cloudflare's client-side Web Analytics has been turned off, verified against the deployed pages: no analytics script (
static.cloudflareinsights.com/beacon.min.js) loads on any page, and a page load requests files from dmvca.info only. Any usage measurement is limited to what Cloudflare derives at the edge from ordinary request logs as our host — server-side, script-free, and cookieless — using the request metadata above. We set no analytics identifier and do not track you across sites. - Cloudflare may also emit standard browser network-error reporting (NEL) headers, which ask the browser to report failed requests to Cloudflare; no successful-load data is sent this way.
OpenStreetMap — map tiles, only if you click
Some pages offer a map. The map does not load until you click "Load map." Until that click, no request is made to OpenStreetMap. If you load a map, your browser requests map image tiles directly from OpenStreetMap (tile.openstreetmap.org), which then necessarily receives your IP address, the tiles requested (which indicate the area you are viewing), and a referrer of https://dmvca.info/ — the origin only, not the specific page. These tile requests carry no cookie, and this happens only on map pages, only after you click. OpenStreetMap's own privacy terms govern that request.
Cookies and local storage
The application sets no cookies and uses no local or session storage, and there is no analytics cookie. If anything cookie-based is ever added, this policy will be updated first.
Forms and search
- There are no forms that collect or transmit personal data — no account, contact, or newsletter form.
- Search runs entirely in your browser against an index served from dmvca.info; your query is not sent to any external search service. If you submit the search form, your query appears in the dmvca.info URL, which Cloudflare handles as host like any other URL.
- Two on-page tools (a practice-test quiz and a smog-eligibility helper) run entirely in your browser and send nothing anywhere.
Legal basis (GDPR)
The operator has a Latvian establishment, so the EU GDPR applies to this processing regardless of where you are. The likely lawful basis for the limited processing above (host request handling and script-free, cookieless edge analytics) is legitimate interests (Art. 6(1)(f)) — operating and securing the site — with no special-category data processed.
Provisional — the lawful basis is under professional review.
Categories of data processed
Only your IP address and standard request metadata (via Cloudflare as host — the same data behind its script-free, cookieless edge analytics) and, only if you click a map, the IP/referrer/tile data sent to OpenStreetMap. No client-side analytics, no cookies, no names, emails, accounts, payment data, or profiles — unless you choose to email [email protected], in which case we process the contents of your message to reply.
Retention
The application stores nothing. Cloudflare's edge-log and traffic-analytics retention is set by Cloudflare; emails you send are kept only as long as needed to handle your request.
Provisional — the specific retention periods are under professional review.
Your rights
Where the GDPR applies, you have the rights of access, rectification, erasure, restriction, objection, and data portability, and the right not to be subject to solely-automated decisions (none are made here). To exercise any of these, email [email protected]. Note that we may be unable to identify you from Cloudflare's edge logs alone, so some requests may require additional information.
Provisional — the rights-request (DSAR) process is under professional review.
Supervisory authority
If you believe your data has been mishandled, you may complain to the Latvian supervisory authority, the Data State Inspectorate (Datu valsts inspekcija), or to your local EU supervisory authority.
California (CCPA / CPRA)
This site is about the California DMV, so we note the CCPA/CPRA explicitly: it is not currently triggered, because the operation does not sell or share personal information, runs no advertising, and does not meet the CCPA's business thresholds. This will be revisited if advertising is ever added.
Children
The site is general-audience DMV information, is not directed at children, and collects no personal data through the application.
Changes and contact
If this policy changes, the updated version will be posted here with a new date. For privacy questions, to exercise your rights, or to reach the operator: [email protected]. (Controller legal identity to be added on registration; see above.)