Driveway Alert is built privacy-first. We recognize a vehicle's general appearance — make, model, body type, and color — to label arrivals in your driveway, and stop there. We do not read, store, or process license plate numbers. This policy explains exactly what we collect, how we use it, and the control you keep.
Solely to operate Driveway Alert: recognize familiar vehicles by their general appearance on your private property, send arrival notifications, show your arrival timeline with its snapshot, and flag unfamiliar vehicles. We do not read or process license plates, and we do not sell or share your data with third parties for advertising.
There is exactly one way in which something we derive from a Ring event can leave our systems to a destination you pick, and it is the optional gate-trigger feature described below. It is off unless you turn it on, and you can turn it off in one click.
Today, your email address is used only for:
Starting August 22, 2026, we will also send account notices — service emails about the state of your account: reminders before your free trial ends, a notice when the trial ends and alerts pause, a confirmation when a subscription is activated, and a notice if the connection to your Ring account stops working (which means alerts are not being delivered). You will be able to turn account-notice emails off in your dashboard Settings.
Also from that date, an optional weekly arrivals summary will be available — it is strictly opt-in from Settings and never sent unless you enable it.
We never send marketing or promotional email, and none of these emails ever include camera images.
Driveway Alert detects a vehicle's general appearance — its make, model, body type, and color — to label arrivals as familiar or unfamiliar. This is non-identifying vehicle information.
4.2.1 — What we detect. When your Ring camera reports a motion event, a snapshot is analyzed to determine whether a vehicle is present and, if so, its general appearance (make, model, body type, color) with a confidence score. We match this appearance "signature" against the vehicles you have registered to decide whether an arrival is familiar.
4.2.2 — What we do NOT do. We do not read, store, or process license plate numbers, VINs, or any personally identifying vehicle information. We perform no license-plate recognition (LPR), no optical character recognition of plates, and no biometric analysis of any kind. We do not attempt to identify the owner or driver of a vehicle.
4.2.3 — How the analysis works. Appearance detection is performed by an open-weights Qwen vision model that we self-host on Erbacci-owned GPU hardware — first-party equipment, not a third-party AI service. Anthropic Claude Haiku 4.5, via Amazon Bedrock inside Amazon Web Services (US East), remains configured as an automatic fallback and is used only when the self-hosted model is unreachable or returns an error. Both are inference-only: snapshots are analyzed for this purpose and are not used to train any AI model, and nothing is retained by either model.
4.2.3a — Where the analysis happens. The model that describes the vehicle runs on Erbacci-owned hardware rather than in the cloud. The path is encrypted end to end: TLS to an Erbacci-managed relay server (hosted on Contabo infrastructure, Germany; TLS termination and encrypted-tunnel forwarding only — it performs no analysis and stores nothing), then over an encrypted tunnel to an Erbacci-owned GPU workstation located in Dubai, United Arab Emirates, where the image is processed in memory only. No image is written to disk, cached, or retained anywhere on this path; only a short text description is returned — make, model, body type and color. All storage remains exclusively in AWS (see 4.2.4). A previous revision of this section described a coarse "is a vehicle present?" pre-screen on the same hardware, with the full analysis in AWS; that pre-screen has been removed and the roles are as described here.
4.2.4 — Snapshot storage. So you can see who arrived — the core purpose of the app, and the only way an alert about an unknown vehicle is useful — the arrival snapshot is stored in Amazon S3 within AWS. Storage is private (public access blocked) and encrypted at rest (AES-256). The image is served to you only through your authenticated dashboard via a short-lived, single-use link; it is never public. Snapshots are automatically deleted after 90 days by an S3 lifecycle rule, and immediately when you unlink Ring or delete your account.
If you switch it on, Driveway Alert can send a signal to gate equipment you own when a vehicle you have registered and separately marked arrives. The feature is off unless you turn it on, you must arm it separately for each vehicle, and you can turn it off at any time in Settings. It is included in your existing subscription at no extra cost. Nothing in this section happens to you unless you enable it.
Outbound web request. If you enter a web address, we send a single HTTPS request to that address. Every such request contains exactly these eight things and nothing else: a format tag, the event name (it has one possible value, "a vehicle you trust arrived"), the identifier of the signing key version we used, a delivery identifier, the time we sent it, the time of the arrival, the identifier of the saved vehicle that matched, and a flag saying whether it was a test. Two further items are sent only if you switch them on: the name you gave the vehicle, and a stand-in reference for the camera. That camera reference is derived with a key held only by us, is stable within your account and meaningless outside it; it is not your camera's Ring identifier, and that identifier cannot be worked out from it.
The request contains no image, no snapshot link, no email address, no Ring account identifier, no Ring device identifier and no location. It is signed with a key we derive for you so your equipment can verify it came from us; we show you that key once and never store it — we keep only its version number, and you can replace it at any time. The address is one you choose and control. Once the request leaves our systems, what the receiving service does with it is governed by that service, not by this policy: it is not a processor we select, vet or control.
Outbound telephone ring. If you enter a telephone number, we place a short call and do not wait for it to be accepted — many gate openers open on an incoming call from a number they recognise. If your equipment, a voicemail service or a person does answer, we hang up immediately, having played nothing. Those calls play no audio and record nothing. There is one exception, which happens at your request and only when you ask us to check the number: a single verification call that reads a six-digit code aloud in a synthetic voice, and nothing else. To place calls we use a telephony provider, Twilio Inc. (United States, Delaware). That provider receives the number dialled, our caller ID, and the time and duration of each call — which is to say, the times a vehicle you trust arrived at your home. We state that plainly rather than minimise it. The provider receives no camera data of any kind, no image, and nothing about which vehicle arrived. You must confirm that the number is yours or that you are authorised to have it called, and we verify that you control it before the feature can be enabled. Customer accounts may save United States (+1) numbers only.
What we never do. We never send a close, lock, stop or deny command: no such message exists in what we send. We never trigger for a vehicle you have not marked, and never for a vehicle we do not recognise. We never trigger on a person. We do not read license plates, for this or for any other purpose.
Not a security system. Gate triggers are a convenience. They can be late, missed, or wrong, and they depend on your camera, your internet connection and, for calls, the telephone network. What a trigger does to your gate is decided by your own controller: most treat a single pulse as "change state", so a trigger arriving while your gate is already open or moving can reverse it. Only use this feature if your gate's safety devices (photocells or safety edges) are fitted and working. Do not rely on it for safety, and never connect it to an alarm or life-safety system. A gate that opens for a recognised caller ID will open for anyone able to spoof that caller ID.
Your consent. Turning the feature on requires a dialogue that lists exactly what is sent and to whom, with two acknowledgements you must tick yourself. It is separate from linking your Ring account and cannot be inherited: we record which version of that text you agreed to, and if we change it materially the feature switches off until you agree again.
Your control and deletion. Turning the feature off deletes the web address, the signing key version and the telephone number immediately, and switches every vehicle you had marked back off in the same action. When you turn the telephone trigger off, change the number, withdraw consent, unlink Ring or delete your account, we also delete the corresponding call records at our telephony provider using their deletion interface. Where a deletion does not succeed on the first attempt we retain only the provider's call identifier until it does, and nothing else — except on unlink and on account deletion, where our own list of those identifiers is erased with the rest of your record rather than kept for a retry. Trigger log entries are deleted with the arrival record they belong to after 90 days, and everything is deleted when you unlink Ring or delete your account.
Event records and arrival snapshots are retained for 90 days, then automatically purged — event records by a database time-to-live, snapshots by an Amazon S3 lifecycle rule. Both are also deleted immediately when you unlink Ring or delete your account. Vehicle registrations and account data are retained until you delete your account. Deletion takes effect within 30 days.
Gate triggers. Trigger log entries live on the arrival record they describe, so they carry the same 90-day limit and are purged with it — enabling gate triggers creates no new retention period. The web address, the signing key version and the telephone number are kept only while the feature is switched on and are deleted the moment you switch it off. The consent record (which version of the text you agreed to, and when) is deleted together with that configuration when you withdraw: we do not keep a record of your consent after you have taken it back. That is why switching the feature on again always asks you again, from the beginning. Call records held by our telephony provider are deleted at the provider on the same events, as described above.
If you are a California resident, you have the right to:
Driveway Alert is not directed to children under 13. We do not knowingly collect data from children.
Data is encrypted in transit (TLS 1.2+) and at rest. OAuth refresh tokens are stored encrypted in DynamoDB. Access is restricted via IAM least-privilege policies.
We may update this policy. Material changes will be communicated via in-app notice at least 30 days before taking effect.
Erbacci LLC — info@erbacciltd.com