No-Reidentification Commitment
Version 1.0 · Effective 2026-08-09
If RateMyDOT publishes or licenses deidentified or aggregate data derived from driver reviews, this commitment governs that use. We make it publicly, because a private internal policy does not satisfy the public- commitment prong of California’s deidentification standard (Cal. Civ. Code § 1798.140(m)):
We will not attempt to reidentify any individual from published or licensed data. We will not run, commission, or knowingly permit any process whose purpose is to determine who wrote a given review or contributed a given data point.
We will not permit others to. Any recipient of deidentified or aggregate data must accept no-reidentification terms before receiving it. That includes API customers, research partners, and any other recipient. The same obligation must flow down to anyone they in turn share the data with. A recipient who cannot make that same promise to their own downstream recipients does not get the data.
We will maintain the technical controls that make this true. Keyed HMAC hashing under a database Vault-held pepper, not bare hashing, which the FTC has said does not anonymize on its own. No author-of-review column anywhere in our systems. K-anonymity thresholds and suppression on small populations. Randomized publication order, so that database insertion order itself can’t leak who wrote what and when.
This commitment is linked from our Privacy Policy, from the review submission form, and from every license we grant to deidentified or aggregate data.
