Internal draft pending review by a licensed attorney. It does not constitute legal advice; the data controller's details (name, address, RFC) are placeholders.
Privacy Notice
Last updated: July 6, 2026
Introduction
This Privacy Notice is issued in compliance with the Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP) published in the Official Gazette of the Federation (Diario Oficial de la Federación) on March 20, 2025, and the applicable secondary provisions. It is addressed to every person (the “data subject”) who visits or uses the website licenciamexico.com, an informational and guidance service for the Mexico City Permanent Driver's License procedure.
By using this site, the data subject can learn which personal data we collect, for what purposes we process it, with whom we share it, and how to exercise their ARCO rights (Access, Rectification, Cancellation, Objection).
This is a courtesy translation. In case of any discrepancy, the Spanish version prevails as the legally binding text under Mexican law.
Identity and address of the data controller
The party responsible for the processing of personal data collected through this site is the natural person who operates the site (persona física con actividad empresarial):
- Name of the data controller: [NOMBRE DEL RESPONSABLE] (pending)
- Contact email for privacy matters and ARCO rights: [email protected]
- Tax ID (RFC): [RFC] (pending)
- Registered address: [DOMICILIO FISCAL] (pending)
The data controller's name, RFC and registered address are in the process of formalization and will be published on this same page as soon as they become available. The contact email indicated is fully operational for exercising the rights provided for in this notice.
Personal data we collect
This site collects only the minimum data necessary for its operation. At the current stage of the service, the following data is processed:
- IP address: stored persistently in our systems only when the rules search tool rejects a query that violates the acceptable use policy (internal refusal log, together with the length of the query; the text of the rejected query is NOT stored). The IP address is also used transiently for rate limiting and abuse prevention. Additionally, as with any web service, the IP address may appear temporarily in the technical access logs of the server and of Cloudflare's infrastructure.
- Search query text: the query entered by the data subject is transmitted to an external language model provider (OpenRouter, Inc., USA) to generate the response and is temporarily kept in an internal cache together with the generated response. We recommend not including personal data in search queries.
- Cookie choice (consent): your decision to accept or decline analytics is stored in your browser's local storage (localStorage, key “lp-cookie-consent”). This data remains on your device and is not transmitted to our servers.
- Aggregated usage data via analytics: only if the data controller activates an analytics provider (Plausible, Umami or Google Analytics 4) AND the data subject grants consent through the cookie banner. As of the date of this notice, no analytics provider is active.
- Email address and payment metadata (applicable once online payment is activated): when online purchases via Stripe Checkout are enabled, the buyer's email address and transaction metadata will be processed. We do not store card numbers; payment processing is handled by Stripe.
We do not collect sensitive personal data (ethnic origin, health status, beliefs, etc.), nor do we request the data subject's official documents through this site. IP addresses in the internal refusal log are kept for a maximum of 12 months, after which they are deleted or anonymized.
Purposes of processing
Primary purposes (necessary for providing the service):
- Providing the information and guidance service regarding the Mexico City Permanent License procedure.
- Preventing abuse of the rules search tool and ensuring its use complies with the acceptable use policy (refusal logging and per-IP rate limiting).
- Complying with the service's internal integrity controls (query hygiene checks).
- Managing payments and delivering purchased digital products (applicable once online payment is activated).
Secondary purposes (not necessary for providing the service):
- Aggregated site usage analytics to improve the service (only with consent granted through the cookie banner).
The data subject may object to the secondary purposes at any time by declining analytics in the cookie banner or through the revocation channels described below. Refusal does not affect the provision of the service.
ARCO rights and how to exercise them
Under the LFPDPPP, the data subject has ARCO rights (Access, Rectification, Cancellation, Objection): the right to Access their personal data, Rectify it when inaccurate, Cancel it when they consider it is no longer required for the stated purposes, and Object to its processing.
To exercise any of these rights, the data subject must send a request to [email protected], indicating: (i) the data subject's name and a means of communicating the response; (ii) documents proving their identity or, where applicable, legal representation; (iii) a clear and precise description of the personal data with respect to which they seek to exercise any of the ARCO rights; and (iv) any other element that facilitates locating the data.
- Response deadline: the data controller will communicate its determination within a maximum of 20 business days from the date the request was received.
- Compliance deadline: if the request is granted, it will be carried out within 15 business days following the date the response is communicated.
If the data subject believes their right to data protection has been violated, they may turn to the supervisory authority in this matter: the Anti-Corruption and Good Governance Ministry (Secretaría Anticorrupción y Buen Gobierno), through its Transparencia para el Pueblo unit (the authority that replaced INAI following the 2025 reform).
Data processors and data transfers
The following providers process data on behalf of the data controller as data processors (a “remisión” of data — a processor transfer under the LFPDPPP), which entails the processing of data outside Mexico (the United States and the European Union):
- Cloudflare, Inc. (USA) — CDN, DNS and reverse proxy services: all site traffic (including visitors' IP addresses) passes through Cloudflare's infrastructure.
- OVH Groupe SAS / OVHcloud (France) — hosting provider: the server where the site's application and database run.
- OpenRouter, Inc. (USA) — language model provider: receives the text of search queries in order to generate the responses.
- Stripe, Inc. (USA) (applicable once online payment is activated) — payment processor: receives the data necessary to process the transaction; the site does not store bank card data.
- Analytics provider (only if activated and with the data subject's consent) — as of the date of this notice, none is configured.
Beyond the cases above and the exceptions provided for in the LFPDPPP in force, we do not transfer personal data to third parties without the data subject's consent. We do not sell or trade personal data.
Revoking consent and limiting use
The data subject may revoke their consent to processing for analytics purposes, or limit the use of cookies, through any of the following means:
- Selecting the decline option (“necessary only”) in the site's cookie banner.
- Deleting the “lp-cookie-consent” key from your browser's localStorage (on your next visit, the banner will be shown again).
- Configuring your browser to block or delete cookies and local storage for this site.
- Sending a revocation request to [email protected].
Minors
This service is not directed at persons under 18 years of age: the driver's license procedure in Mexico City requires legal adulthood. We do not knowingly collect personal data from minors. If a parent or guardian becomes aware that a minor has provided data through the site, they may request its deletion through the contact channels in this notice.
Security measures
We apply reasonable administrative, technical and physical security measures to protect personal data against damage, loss, alteration or unauthorized use, including: encryption of traffic in transit (HTTPS via Cloudflare) and restricted access to the server hosting the application. No measure guarantees absolute security, but we strive to keep protections proportional to the data processed.
Changes to this privacy notice
This notice may be amended to reflect legislative changes, new service features or adjustments to processing practices. Any amendment will be published on this same page, updating the “last updated” date. Data subjects are encouraged to review this document periodically.
Contact
For any questions or comments regarding this privacy notice or the processing of your personal data, you may contact us at [email protected].
Last updated
This Privacy Notice was last updated on July 6, 2026.