Privacy Policy
Last updated: 4 October 2026. Draft for review: to be reviewed by a qualified lawyer and completed with the controller's details before FleetAsset360 is sold.
What we collect
- Account data: names, work email addresses, roles, and a securely hashed password (never the password itself).
- Your organisation's data: the assets, contracts, job cards, pictures, tracker positions and running hours, invoices and other records your team enters or connects. You control this data; we process it on your behalf.
- Billing data: your plan and payment history. Card details are collected and stored by Stripe, not by us.
- Technical data: sign-in times and an audit log of changes, kept for security.
- Messages you send us through the contact form.
Why
To provide and secure the Service, to bill subscriptions, to answer you, and to meet legal obligations. We do not sell personal data and do not use it for advertising.
Cookies
We use one essential cookie to keep you signed in. We do not use advertising or tracking cookies, so there is nothing to opt out of.
Who processes data for us
- Cloudflare, Inc.: hosting, database and content delivery.
- Stripe, Inc.: payments and invoices.
- An email provider, for invitations and password resets [name to be inserted when chosen].
Separation and security
Every organisation's data is kept strictly separate. Connections are encrypted (HTTPS). Passwords are stored as salted hashes. Access within an organisation follows roles chosen by its administrator, and changes are recorded in an audit log.
How long we keep data
For as long as the account is active, then for [90] days after closure so it can be restored on request, then deleted, unless the law requires us to keep records longer (for example invoices).
Your rights
You can ask to access, correct, export or delete your personal data. Organisation administrators can export their organisation's data at any time. To exercise your rights, contact us.
Contact
[Data controller name and address to be inserted.] Questions: contact us.