Privacy Policy
In effect from 19 August 2026.
Cronenta is in active development
Cronenta is early software, in limited use with a small group of Ontario instructors. The product changes often; this policy does not change quietly along with it. Anything material is posted here with the date above updated, and instructors are told directly — see Changes to this policy.
This policy applies to the information Cronenta holds today, not only to some future launched version of it. It has to: the obligations under PIPEDA begin when information is collected, not when a product is finished.
The short version
- Your driving instructor uses Cronenta to text you about your licence milestones and to book lessons.
- We hold your name, phone number, email, licence stage and the messages between you and your instructor. We do not hold your licence number, your date of birth, your address or any card details.
- It is stored in Canada. Some of the services we use to send messages and book appointments are in the United States, and that is set out below.
- Reply STOP to any message and we stop for good. You can ask to see your information, correct it, or have it deleted — write to privacy@cronenta.ca.
Cronenta is scheduling and reminder software used by driving instructors and driving schools in Canada. This policy explains what personal information moves through Cronenta, why, where it is stored, how long it is kept, and what you can ask us to do with it.
Two organizations are involved when you get a message or book a lesson:
- Your instructor or driving school — the business you have a relationship with. They decide who to contact and why.
- Cronenta — the software they use. We store and send that information on their behalf, and we are accountable for what we do with it.
Either one can act on a request to correct or delete your information.
Who is accountable
Pedro Bastos, operating as Cronenta Technologies
Privacy contact: privacy@cronenta.ca
Under PIPEDA — the Personal Information Protection and Electronic Documents Act, Canada's federal privacy law — we designate a person accountable for the personal information we hold. Write to the address above to reach them. PIPEDA applies to us independently of CASL, Canada's anti-spam law, which separately governs the messages we send.
What we collect about clients
Either your instructor enters it, or you give it to us on their booking page:
- your name
- your mobile number
- your email address
- your licence stage — G1, G2 or full G
- the date you got your G2, if you know it
- whether you agreed to receive text messages, and when you agreed
- whether you asked us to stop, and when
While you are being contacted, we also keep the full text of every message we send you and every reply you send back, with the time and the delivery status, and the details of any appointment you book — which type, and when.
If you pay for a lesson through your instructor's booking page, the payment is processed by Stripe on the instructor's behalf. Your card details go directly to Stripe — Cronenta never sees a card number. What we keep is the payment's amount and its status (paid, refunded), attached to your booking, and the email address the receipt goes to.
We do not collect your driver's licence number, your date of birth, or your home address.
What we collect about instructors
Business name, contact name, email, phone, timezone, working hours, the number messages are sent from, and the plan. Billing runs through Stripe — we store only the customer and subscription identifiers Stripe gives us. If you turn on lesson payments, we also store the identifier of your Stripe payment account and, for each paid booking, the amount and payment status. Sign-in runs through Amazon Cognito — we store an account identifier and an email address, never a password. If you connect a calendar, we store the identifier for that connection, not the contents of your calendar.
Why we collect it
- To send the milestone reminders you agreed to receive — a G-test reminder about 12 months after your G2, and a licence-expiry reminder about five years after
- To handle your replies — book you in when you say yes, and stop contacting you when you say STOP
- To show your instructor who has been contacted, who replied, who booked
- To keep the record of consent and of every message sent that CASL requires us to be able to produce
- To bill instructors, and to keep the service secure and working
We do not sell personal information, and we do not share it with anyone for advertising.
Consent, and how to withdraw it
We send text messages only to clients who have given express consent — by ticking the box on a booking page, or because the instructor recorded that consent before adding them.
Reply STOP to any message and we stop, permanently. That opt-out is recorded against your number and is not undone by adding you again: a number that has opted out is excluded from every future reminder. You can also ask your instructor, or write to privacy@cronenta.ca.
Withdrawing consent stops the messages. On its own it does not delete your record — see below.
Where your information is stored
In Canada. The application and its database run in Amazon Web Services'ca-central-1 region, in Montréal. That was a deliberate choice, not an accident of hosting.
Some services we depend on process information outside Canada. When that happens, the information is subject to the laws of the country it sits in, including access by that country's courts and authorities. PIPEDA permits this provided we tell you plainly, which is what this table is for.
| Service | What it handles | Where |
|---|---|---|
| Amazon Web Services | Hosting, database, sign-in, account email | Canada (ca-central-1) |
| Twilio | Sending and receiving SMS — your number and the message text | United States and the carrier network |
| Nylas | Calendar availability and booking — your name, email, appointment time | United States |
| Only when an instructor connects a Google Calendar — the events Cronenta creates, updates and cancels for bookings | United States | |
| Google Analytics | Site usage on cronenta.ca — pages viewed and how the site was found, only loaded after you accept the cookie banner | United States |
| Stripe | Instructor subscription billing, and lesson payments collected on the instructor's behalf — the client's email address and the payment amount; card details stay with Stripe | United States and elsewhere |
| EmailListVerify | Checks at signup whether an email address exists — the address only | Outside Canada |
Google Analytics only loads on cronenta.ca after you accept the cookie banner. Decline it, or leave the banner untouched, and no analytics request is ever made.
How long we keep it
We keep client records for as long as the instructor's account is active and they keep you on their list. There is no automatic deletion after a fixed period, and we would rather say so than promise one we don't run.
Google Analytics data about visits to cronenta.ca is kept for 14 months, then deleted automatically by Google.
Your instructor can erase your record at any time, and we act on a request sent to privacy@cronenta.ca.
When a record is erased, the name is replaced, the phone number is scrambled, the email address is removed, and the content of every message to and from you is deleted. What remains is the bare fact that a message was sent or received, when, in which direction, and whether it was delivered. That skeleton is the proof of consent and compliance CASL requires, and CASL allows enforcement for up to three years, so we keep it at least that long. It no longer identifies you.
Your choices and your rights
Under PIPEDA you may ask what personal information we hold about you and get a copy of it, ask us to correct anything wrong, withdraw your consent to be contacted at any time, and ask us to delete your record — subject to the compliance record described above. If our answer doesn't satisfy you, you can complain to the Office of the Privacy Commissioner of Canada.
Write to privacy@cronenta.ca, or ask your instructor. We answer within 30 days, as PIPEDA requires. We may need to confirm who you are first, so that nobody else can reach your information.
How we protect it
- One instructor cannot see another's clients. The database enforces that itself, not just the application code on top of it.
- Instructors can turn on two-factor authentication.
- The app is served over HTTPS, and session cookies are restricted to secure connections.
- Messages arriving from Twilio, Nylas and Stripe are cryptographically verified before we act on them, so a forged request cannot alter your record.
- Access to production data is limited to the people who run the service.
No service can promise perfect security, and we won't.
Young drivers
Ontario issues a G1 from age 16, so some clients are minors. We collect the same limited information either way, and we don't knowingly collect anything from a child under 16. If you are a parent or guardian and believe we hold information about your child that shouldn't be there, write to privacy@cronenta.ca and we will remove it.
A shared number — a parent's phone on two learners — is normal and supported. A STOP from that number stops the messages for everyone on it.
If something goes wrong
If personal information in our care is lost or exposed and there is a real risk of significant harm, we will report it to the Office of the Privacy Commissioner of Canada and tell the people affected, as PIPEDA requires. We keep a record of every such incident for 24 months.
If your instructor connects a Google Calendar
Connecting a calendar is optional and is done by the instructor, not by you. When an instructor connects one, Cronenta uses Google's Calendar API through Nylas for two purposes only: to create, update or cancel the calendar event for a lesson booked through Cronenta, and to read when the instructor is busy — busy times only, never the content of any event — so the booking page does not offer times the instructor has blocked.
Cronenta does not read calendar event content, does not use Google data for advertising, does not sell it, and does not use it to train any model. It is not shared with anyone beyond the processors named in the table above, and it is used only to provide the scheduling features described here. Cronenta's use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
An instructor can revoke Cronenta's access at any time at myaccount.google.com/permissions, or by asking Cronenta to disconnect the calendar. Revoking stops all further access; after that Cronenta can no longer create, update or cancel events on the calendar.
Email you receive from us
Clients receive SMS, not email — the STOP instruction above is the opt-out that matters for them. Instructors with a Cronenta account receive a small amount of account email: confirming an address, resetting a password, sign-in messages. That email is part of having an account and cannot be turned off while the account exists — the way to stop it is to close the account.
Cronenta does not send marketing email to instructors or to clients, and does not sell or rent either list. If Cronenta adds an optional email feature — a daily activity summary is planned — it will be off unless the instructor turns it on, and every such email will carry an unsubscribe link.
Changes to this policy
Any change is posted here, with the date at the top updated. If a change materially affects how we handle your information, we tell instructors directly so they can tell their clients.
Contact
privacy@cronenta.ca
Pedro Bastos, operating as Cronenta Technologies
Ontario, Canada
Office of the Privacy Commissioner of Canada — priv.gc.ca — 1-800-282-1376