Privacy
Your students' data, treated with care.
Last updated: September 8, 2026
copilotBC ("we", "us", "our") is committed to protecting personal information. This Privacy Policy explains what we collect, why, where it lives, and the rights you and the students in your records have. We handle personal information in accordance with British Columbia's Personal Information Protection Act (PIPA) and Canada's PIPEDA where it applies.
Who we are, and our two roles
copilotBC is the business name under which Shandria Caroline Kyla Slade, a sole proprietor located in British Columbia, Canada, carries on business. You can reach us about privacy at [email protected].
copilotBC is a tool for BC driving schools. The school — which in BC always has at least one licensed instructor, and may have several — is our direct customer. Its students (and, where applicable, their parents or guardians) are not our direct customers, but their personal information is processed through copilotBC on the school's behalf.
- For an instructor's own account information, copilotBC is the organization responsible for that information.
- For student records entered in the app, the driving school is responsible for that information and for obtaining the consents required under PIPA; copilotBC processes it on the school's behalf to provide the Service. Where a school runs more than one instructor, the school's records are visible to the people who run it as well as to the instructor who entered them.
What we collect
- Instructor account data: name, email address, instructor/licence identifiers you enter, and subscription status. Payments are processed by Stripe (see below) — we never see or store your full card number. Instructors who enable lesson payouts also complete Stripe's identity/banking verification directly with Stripe; copilotBC stores only the Stripe account reference and whether payouts are enabled.
- Student records the instructor enters: student name, contact details, parent/guardian contact (for minors), licence details (BC driver's licence number and class, e.g. "Class 7L"), lesson dates and notes, readiness assessments, signatures captured for lesson sign-off, and instructor reports. We do not ask for medical information or any government ID beyond the driver's licence details the record requires.
- Lesson distance (optional, off by default): if the instructor turns on GPS distance measurement, the app measures only the total kilometres driven during a lesson as a cross-check for mileage/tax tracking. No location, route, or coordinates are stored or transmitted — the live position is processed on the instructor's device and discarded.
- Operational data: sync timestamps, device type and user-agent for offline reconciliation and security, and error logs.
- Voice notes (optional, off by default, and only with the student's agreement): a lesson is not recorded unless two separate things are true — the instructor has turned the feature on, and that particular student has agreed to be recorded. Students are asked once, when they enrol, in a document of their own, and saying no is a complete answer: it changes nothing about their lessons, booking, reports or record, and they are not asked again. A student (or their parent or guardian) can withdraw at any time from My account in the student portal. Where a student has agreed: audio is transcribed on the instructor's device and is not sent to us for transcription; the clips themselves are stored only in the instructor's own browser, on the instructor's device and are never uploaded to copilotBC; only the text transcription the instructor chooses to keep reaches the lesson record. Clips are deleted automatically after a window the instructor sets, up to a maximum of 90 days, and can be deleted sooner by hand. Two limits we want to state plainly rather than bury: withdrawing agreement deletes the audio, not the training record — written notes already saved are part of that record, which BC's driver-training rules require be kept for six years; and because the audio lives on the instructor's own device and nowhere else, deletion happens the next time that instructor opens the app, with the confirmed date shown in the student's portal.
Why we collect it
We use this information only to provide and operate the Service: to run your account, store and sync your records, generate reports and exports based on ICBC/BC formats, process your subscription, keep the Service secure, and respond to support requests. We do not sell personal information, and we do not use student records for advertising.
Where it lives
Your records database is stored in Google Cloud Firestore in the Toronto (northamerica-northeast2) region. We do not take or hold separate backup copies of it ourselves; its durability is Google Cloud's. A few operational pieces of the Service do involve processing outside Canada. Two of them reach Google's Gemini API in the United States, and they are separate: the optional AI assistance feature (off by default) sends limited, de-identified lesson text to tidy transcripts and draft reports, if and only if an instructor turns it on; and the in-app help assistant sends the question an instructor types, so it can be answered from our published help pages, with no student record, lesson or report attached. The third is the delivery of transactional emails and some serverless processing (via ZeptoMail and Cloudflare, see below), which route recipient email addresses and lesson details through infrastructure that may sit outside Canada. The records database itself stays in the Canadian region. The Service is delivered over encrypted (HTTPS) connections.
Service providers we rely on
- Google Cloud / Firebase — hosting, authentication, and the Firestore database (Canadian region).
- Stripe — our payments processor. Stripe handles checkout, card processing, subscription billing, and (for instructors who enable lesson payouts) identity and banking verification through Stripe Connect. Card details go directly to Stripe and never touch copilotBC's systems. Stripe is subject to its own privacy policy (available at stripe.com/privacy) and may process payment data outside Canada.
- Google (Gemini API) — AI assistance (optional, off by default) and in-app help — two separate uses, both reaching Google's Gemini API in the United States. Only if an instructor enables AI assistance, limited de-identified lesson text is sent to clean up transcripts and draft reports. Separately, when an instructor uses the help assistant inside the app, the question they type is sent so it can be answered from our published help pages. That one carries only what the instructor types, and no student record, lesson or report is attached to it.
- ZeptoMail (Zoho Corporation) — our transactional email provider. ZeptoMail delivers instructor account emails (email verification, password reset, subscription and service notices) and the automatic lesson notifications — lesson confirmed, lesson cancelled, and reminders — that copilotBC sends to the students and parents/guardians whose contact details the instructor enters, along with any payment-request links. To send a message, it processes the recipient's email address, name, and the lesson details contained in that message; ZeptoMail is subject to Zoho's own privacy policy and may process this information outside Canada (in the United States).
- Cloudflare — serverless Cloudflare Workers power scheduled lesson reminders, our transactional email dispatch pipeline, and our payment (Stripe) endpoints, so some personal data (such as email addresses, lesson details, and payment metadata) passes through Cloudflare's global edge network in transit and processing, which may be outside Canada. Cloudflare also provides the cookieless, aggregate Web Analytics on this website (see below). It is subject to its own privacy policy.
- An instructor's own calendar provider (Google, Apple or Microsoft) — optional, off by default, and chosen by the instructor rather than by copilotBC. An instructor may create a read-only calendar link and subscribe to it from the calendar app on their phone, so their lessons appear beside the rest of their day. A new link carries the date, the time and the length of each lesson and nothing else. If the instructor also turns on the separate student-details setting, the link additionally carries the student's name and the pickup address for each lesson, and the calendar provider then fetches and stores its own copy on its servers, which may be outside Canada. The link is per instructor, is revocable at any time, and can be replaced, though replacing it does not remove entries the provider has already stored.
These providers are bound to process information only as needed to provide their services to us.
Who can see your data
- The instructor who entered the data.
- Other people at the driving school that holds the record: the people who run the school, and any other instructor there who teaches that student. A school owner's access is read-only, and it exists only where the instructor has accepted a seat at that school — an owner cannot reach the records of an instructor who has not.
- A student or their parent/guardian, only for the specific report or sign-off link the instructor chooses to share with them.
- copilotBC operators, only as needed to maintain the Service or respond to a support request you raise.
- ICBC — only when the instructor uses the DTC205 consent form to book a road test on a student's behalf; the limited information listed on that form is disclosed to ICBC.
Email & notifications
copilotBC sends email on your behalf. Instructors receive account and service emails — email verification, password reset, and subscription or service notices. Students and their parents/guardians receive automatic transactional lesson notifications — when a lesson is confirmed or cancelled, and lesson reminders — along with any payment-request links the instructor sends. These are transactional, relationship messages tied to a specific booking, not marketing, so there is no marketing opt-out; they are part of using the Service. The instructor is responsible for having the consent required under PIPA and Canada's anti-spam law (CASL) to add the student and parent/guardian contacts they enter. These emails are delivered through our email provider, ZeptoMail (Zoho Corporation), described above.
How long we keep it
We retain instructor account data while the account is active. Student training records are retained to help instructors meet BC record-keeping expectations (ICBC's Motor Vehicle Act Regulations contemplate retaining instruction records for six years). Instructors can export a student's full data dossier (JSON) at any time from that student's page, and can archive and request deletion of records subject to that retention period. When you close your account, we delete or de-identify data that we are not required to retain.
Self-enrollment submissions: when a prospective student fills in a self-enrollment form an instructor sent them, that submission waits for the instructor to accept or decline it. If a submission is never accepted or declined, it is automatically deleted 30 days after it was submitted, so pending intake details are not kept indefinitely.
Cookies & local storage
copilotBC sets no cookies of its own and uses no advertising or cross-site
tracking technologies — on this website or in the app. That's why you don't see a cookie banner.
This website uses Cloudflare Web Analytics, a privacy-first measurement tool that counts
page views in aggregate without cookies, local storage, or any personal identifiers — it
tells us how many people visited a page, never who. The app itself contains no analytics at all. The app
stores your settings and a copy of recent records in your browser's local storage so it works
offline; that data stays on your device and is cleared when you sign out. Two third-party services are
the only other exceptions: the app uses Google reCAPTCHA to verify that requests come from the
genuine app (an anti-abuse security check — Google may set a cookie such as _GRECAPTCHA for
its risk analysis, governed by Google's privacy policy), and when you pay you are redirected to
Stripe's own checkout page (checkout.stripe.com), where Stripe may set its own fraud-prevention cookies
under Stripe's privacy policy. Both serve security purposes only — neither is used for advertising or
cross-site tracking by us.
Security
We protect personal information with measures including encrypted connections, server-side access rules that isolate each instructor's data, email verification on accounts, app-integrity checks, and input validation. No system is perfectly secure, but we work to safeguard your information and to limit access to only what is necessary.
Your rights
Under PIPA, individuals have the right to access the personal information held about them, to request corrections, and to ask questions about how it is used. If you are a student or parent, the instructor who holds your record is your first point of contact. For requests about an instructor account, or to reach us directly, email [email protected] — we'll respond within 30 days as PIPA requires. If you are not satisfied with our response, you may contact the Office of the Information and Privacy Commissioner for British Columbia at oipc.bc.ca.
Children's information
Many driving students are minors. copilotBC is used by the instructor, not directly by students. Under BC's privacy law the test here is capability, not age. A student who is able to understand what they are agreeing to gives their own consent, and holds their own access and correction rights, whatever their age. A parent or guardian may consent for a student, or use the rights above on the student's behalf, only where the student is not capable of doing so themselves. That is the test set by s.2(2) of the Personal Information Protection Act Regulation.
A parent or guardian of a student under 19 is still asked to sign at enrolment, and that is a separate thing. They are agreeing to the fees and to the instructor's policies, as the person arranging and paying for the lessons, which is a matter of contract. It does not replace the student's own consent: the student signs their own enrolment consent alongside them, and ICBC's road test consent form is signed by the student alone, whatever their age.
Where a parent or guardian follows a student's progress in the student portal, that is because the student agreed to share it, or because that parent enrolled the student and arranges their lessons. It is not a separate right the parent holds over the student's record.
Changes to this policy
We may update this policy from time to time. We'll change the "Last updated" date above and, for material changes, notify you in the app or by email.
Contact
Privacy questions or requests: [email protected].