Skip to content

Legal

Privacy Notice

Effective date: [DD Month 2026] · Last updated: [DD Month 2026]

Draft for legal review. Before publishing: complete the bracketed details (ABN, the named Privacy Officer and India Grievance Officer, dates), confirm the retention periods in section 7 and the markets in the regional sections, and have the notice reviewed by qualified legal counsel.

This notice explains how FleetConnect collects, uses, shares and protects personal information, and the rights and choices you have. It covers our website, our web and mobile apps, and the fleet-management platform behind them (together, the “Services”).

Read the core notice, then your region’s section at the end — or start from the Global Privacy Notice, which links to each one.

1. Who we are

FleetConnect is operated by FCG Intel Pty Ltd (ABN [__]) — “FleetConnect”, “we”, “us” or “our”. We are headquartered in Richmond, Melbourne, Australia, with a corporate office in Chennai and a regional office in Jaipur, India. Fleet operators use our software to track vehicles, receive alerts, manage fuel, plan routes, maintain vehicles and report on their operations.

This notice is about the people whose information we handle: visitors to our website; people who sign up, contact us or buy from us; people who use our apps, such as fleet managers, administrators and drivers; and people whose details our customers record in the platform — most often their drivers.

2. What this notice covers

We handle personal information in two roles, and which one applies affects who you should ask about it.

  • When we decide how and why it is used — our website, sign-up, your account, billing, support, security, marketing and the running of our business. Here we are responsible for your information (as a “controller”, an “APP entity” or a “Data Fiduciary”, depending on the law), and this notice explains how we handle it.
  • When we act for a customer — organisations that use FleetConnect decide which vehicles, devices and people they track and what they record about them: locations, trips, alerts, driver records and the like (“Customer Data”). The customer is responsible for Customer Data. We handle it only to provide the Services, on the customer’s instructions and under our agreement with them (as a “processor”, “service provider” or “Data Processor”), and the customer’s own privacy notice governs its use.

If you drive for, or work at, an organisation that uses FleetConnect, questions about how it uses the platform are best put to that organisation. If you contact us instead, we will tell the organisation and help it respond. This notice does not cover third-party websites or services that we link to; they have their own privacy terms.

3. The information we collect

Some information you give us; some comes from your organisation, from tracking devices fitted to its vehicles, or from your device and browser when you use the Services.

Identity and contact details

What it includes
Name, work email address, phone number, role, language and time zone, and the organisation you belong to.
Where it comes from
You, or your organisation’s administrator when they invite you or add you as a driver.

Account and sign-in

What it includes
Login email; password, kept only as a one-way hash (as are earlier passwords, to stop their reuse); authenticator-app settings and recovery codes, stored encrypted or hashed; and your sign-in sessions and history, with the IP address and browser or device used.
Where it comes from
You; our systems.

Sign-up details

What it includes
Email, name, company, the IP address and browser used, and the result of our automated abuse check (see section 5).
Where it comes from
You, when you sign up for a trial or plan.

Driver records

What it includes
Name, email, phone, driver-licence number, class and expiry, the vehicles assigned, and any other fields or documents your organisation records — which can include medical certificates or police-verification records.
Where it comes from
Your organisation.

Driving behaviour and safety

What it includes
Harsh acceleration, braking and cornering events, time spent speeding, safety scores, and SOS alerts raised from the app.
Where it comes from
Tracking devices in your organisation’s vehicles; calculated by the platform; our mobile app.

Vehicle location and telematics

What it includes
GPS position and altitude, speed, heading, ignition, odometer, fuel and battery levels, other sensor readings such as temperature, and identifiers for the tracking device and its SIM (IMEI, ICCID, IMSI and SIM phone number). This relates to a person when a driver is assigned to the vehicle.
Where it comes from
Tracking devices and sensors your organisation fits to its vehicles and assets.

Fleet operations

What it includes
Trips, with the route driven and start and end addresses; geofence entries and exits; alerts; routes and stops, including a delivery recipient’s name; maintenance records; fuel transactions, including the fuel card’s last four digits; and vehicle documents.
Where it comes from
The platform; your organisation, including files it uploads.

Support and communications

What it includes
Support tickets, comments and attachments; emails you send us; notification preferences, quiet hours and alert contact lists; and records of the notifications we send by email, push notification or in the app.
Where it comes from
You; your organisation; the platform.

Billing and subscription

What it includes
Your organisation’s plan and subscription, invoices and payment records, billing name, address and email, and tax number. Payments are made by bank transfer or similar and recorded by our team, so we hold no payment-card details.
Where it comes from
You or your organisation.

App and device information

What it includes
Push-notification token, device identifier, platform (Android, iOS or web) and app version.
Where it comes from
Your device or browser, when you turn on notifications.

Usage, security and logs

What it includes
IP address, browser or device type, the web addresses requested, error reports, and an audit trail of security and data-change events — who acted and on whose behalf, what they did, when, and from which IP address.
Where it comes from
Your browser or device; our systems.

Analytics

What it includes
Pages and screens viewed on our website and web app, how you arrived, browser and device type, approximate location derived from your IP address (city or country), and errors encountered.
Where it comes from
Your browser, through Google Analytics — on our website, only with your consent.

Enquiries

What it includes
What you tell us when you email us or speak with us.
Where it comes from
You.

We do not collect biometric data; the Services record no video or audio; and our mobile app never reads your phone’s location. Some information in the platform is sensitive, though: driver documents an organisation uploads can include health or police records, and some laws treat precise location and licence numbers as sensitive too. We hold these only for the organisation that recorded them, keep uploaded documents encrypted, and make them available only to the users that organisation authorises.

4. How and why we use it

Providing the Services

What this involves
Running accounts, showing vehicles on the map, recording trips, raising alerts, producing reports, and sending the notifications and reports your organisation sets up.
Legal basis (UK & EEA)
Our contract with you or your organisation; for Customer Data, the customer’s instructions.

Accounts, subscriptions and billing

What this involves
Setting up workspaces, managing plans and trials, invoicing and recording payments.
Legal basis (UK & EEA)
Contract; legal obligation (tax and accounting records).

Security and fraud prevention

What this involves
Authenticating users, enforcing multi-factor authentication, screening sign-ups for abuse, keeping audit trails, and detecting and investigating misuse.
Legal basis (UK & EEA)
Legitimate interests in keeping the Services and our customers safe; legal obligation.

Support

What this involves
Answering questions and fixing problems — which can mean our support team viewing a customer’s workspace as its users see it, with every such session recorded.
Legal basis (UK & EEA)
Contract; legitimate interests.

Improving the Services

What this involves
Understanding how our website and web app are used, diagnosing errors, and producing aggregated or de-identified statistics.
Legal basis (UK & EEA)
Legitimate interests in improving our products; your consent for analytics cookies on our website.

Communicating with you

What this involves
Service messages about your account, security, billing and changes to our terms — and, where allowed, news about our products.
Legal basis (UK & EEA)
Contract (service messages); consent or legitimate interests (marketing, which you can opt out of at any time).

Legal and compliance

What this involves
Keeping the records the law requires, responding to lawful requests from authorities, enforcing our terms, and defending legal claims.
Legal basis (UK & EEA)
Legal obligation; legitimate interests.

Business changes

What this involves
Sharing information, under confidentiality, with the other party to a merger, acquisition or sale of assets.
Legal basis (UK & EEA)
Legitimate interests.

We use personal information only for these purposes or for a related purpose you would reasonably expect. If we want to use it for something new, we will tell you first and, where the law requires, ask for your consent.

5. Automated decisions

We do not make decisions that have a legal or similarly significant effect on you based solely on automated processing. Two things happen automatically, and a person stays involved in both:

  • Sign-up checks. When someone signs up, we automatically look for signs of abuse — a disposable email address, or an unusual number of sign-ups from one IP address or email domain. A sign-up that trips these checks is stopped, and our team can review it and let it through; contact us if you think yours was stopped in error. Every new account is also approved by our team before it is created.
  • Fleet insights. For our customers, the platform raises alerts — such as speeding and geofence alerts — and gives drivers safety scores based on harsh-driving events. These help a fleet manager decide what to look at. Any decision about a driver — coaching, discipline or anything else — is made by the driver’s organisation, not by FleetConnect.

6. Who we share it with

We do not sell personal information, we do not use it to advertise to you, and we do not send it to AI or large-language-model providers. We share it only with:

  • Your organisation. If you use FleetConnect through an organisation, its administrators and other authorised users can see your information, according to the permissions they hold.
  • Our service providers, listed below, which run parts of the Services for us. They may use the information only to provide their service to us, and must protect it.
  • People and systems your organisation chooses — recipients it adds to alert and scheduled-report emails, systems it connects to FleetConnect through webhooks, and anyone it sends a live-location link, who can see that vehicle’s plate, position, speed and last report time until the link expires (after 8 hours unless set otherwise, and never more than 72).
  • Professional advisers — lawyers, accountants, auditors and insurers, who owe us duties of confidentiality.
  • Authorities, where the law requires it, or where it is needed to protect someone’s life, health or safety, or to establish, exercise or defend legal claims.
  • A buyer or successor, if we are involved in a merger, acquisition or sale of assets. Your information would stay protected by this notice.

Amazon Web Services

What they do for us
Hosts the FleetConnect platform — its servers, database, file storage and encrypted backups.
Where they process data
India (Mumbai)

Amazon Simple Email Service

What they do for us
Sends our emails: alerts, invitations, password resets, sign-up verification and scheduled reports.
Where they process data
India (Mumbai)

Google Firebase

What they do for us
Hosts our website and web apps, and delivers push notifications to phones and browsers — reaching iPhones through Apple’s push notification service.
Where they process data
Worldwide

Google Analytics

What they do for us
Measures how our website and web app are used, and records errors.
Where they process data
Worldwide

Google Maps Platform

What they do for us
Shows maps in our web and mobile apps, and turns coordinates into street addresses in our web app.
Where they process data
Worldwide

Cloudflare Turnstile

What they do for us
Checks the sign-up form for bots.
Where they process data
Worldwide

7. How long we keep it

We keep personal information only as long as we need it for the purposes in this notice, or as long as the law requires. Then we delete it, or de-identify it so that it no longer identifies anyone.

Account and profile details

How long we keep it
While the account is open. When an account is deleted on request, we remove or anonymise its personal details within 30 days of confirming the request, unless the law requires us to keep something longer.

Incomplete sign-ups

How long we keep it
Personal details are deleted 30 days after a sign-up is abandoned.

Vehicle positions and sensor readings

How long we keep it
About 13 months, after which they are deleted automatically.

Trips, alerts, documents, support tickets and other fleet records

How long we keep it
For as long as the customer’s account exists. When an account closes, we delete its Customer Data at the customer’s request.

Generated reports

How long we keep it
30 days, unless the customer sets a different period of up to a year.

Audit trail and sign-in records

How long we keep it
Up to 7 years — they are the record of who accessed or changed what.

Billing and tax records

How long we keep it
As long as tax, accounting and company law requires.

Analytics

How long we keep it
Event-level data for no longer than 14 months.

Temporary processing records

How long we keep it
Between 7 and 30 days.

Backups

How long we keep it
Encrypted, and kept for up to 13 months before they are overwritten.

8. How we protect it

We protect personal information with technical and organisational safeguards suited to what we hold. No system is perfectly secure, but these are the main measures:

Technical measures

Encryption in transit

What it means
Connections to our website, apps and APIs are encrypted with TLS (HTTPS).

Encryption at rest

What it means
Uploaded documents are encrypted with managed keys, backups are encrypted, and authenticator-app secrets are encrypted in our database.

Password protection

What it means
Passwords are kept only as Argon2id hashes — never in a form that can be reversed — and earlier ones are kept the same way so they cannot be reused.

Multi-factor authentication

What it means
Authenticator-app (TOTP) codes, with hashed single-use recovery codes. Mandatory for administrators; organisations can require it for everyone.

Session limits

What it means
Access tokens expire after 60 minutes, and every session ends within 90 days.

Access control

What it means
Role-based permissions, which can limit a user to particular vehicles.

Customer separation

What it means
Each customer’s data is kept apart from every other customer’s, enforced in the database itself.

Audit trail

What it means
Security and data-change events are recorded append-only — who acted and on whose behalf, what they did, when, and from which IP address.

Recorded support access

What it means
When our support team needs to see a customer’s workspace, they use a dedicated support-access tool, and every session is recorded.

Organisational measures

Need-to-know access

What it means
Our staff access personal information only where their role requires it.

Supplier safeguards

What it means
We use providers that commit to protecting data, and bind them to that by contract.

Incident response

What it means
We investigate suspected breaches promptly, and notify the people affected and regulators where the law requires.

9. Where we process it

Our platform — its database, files and backups — is hosted by Amazon Web Services in Mumbai, India, and our emails are sent from there. Our website and web apps are served worldwide by Google Firebase, and the other providers in section 6 run global networks, so information may also be processed in the United States and other countries. Our own team works in Australia and India.

Wherever it is processed, we protect it as this notice describes. We choose providers that are bound by contract to protect it and, where a transfer needs a legal safeguard, rely on one the law recognises — such as the standard contractual clauses in our providers’ data-processing terms. The regional sections explain the rules for each region.

10. Marketing

We send news about our products only where the law allows — with your consent, or to business contacts who would reasonably expect it — and always with a way to opt out. Every marketing email has an unsubscribe link, or you can simply email us. We do not sell or rent contact lists.

Service messages — about security, your account, billing or changes to our terms — are not marketing, so you will keep receiving them while you have an account.

11. Cookies and similar technologies

  • Our website uses Google Analytics to count visits and record errors — but only if you accept analytics cookies in our cookie banner, and you can change that at any time with Cookie settings at the bottom of the page. Google processes that data under its own terms.
  • Our web app also uses Google Analytics. It keeps your sign-in tokens, your email and role, and — if you turn on notifications — a push token in your browser’s local storage, so that you stay signed in and receive alerts. It loads Google Maps to draw maps, and Cloudflare Turnstile on the sign-up form.
  • Our mobile app contains no analytics or advertising tools and never reads your phone’s location. It keeps your sign-in token in your phone’s secure storage.

You can block or delete cookies and stored site data in your browser settings, or install Google’s Analytics opt-out add-on. Our website does not respond to “Do Not Track” or Global Privacy Control signals. Our Cookie Policy has more detail.

12. Children

FleetConnect is a business service for adults. It is not directed at children, and we do not knowingly collect personal information from anyone under 18. If you believe we hold a child’s information, contact us and we will delete it. Where India’s DPDP Act applies, we would process a child’s personal data only with verifiable consent from a parent or lawful guardian, and never for tracking, behavioural monitoring or targeted advertising.

13. Your rights

Depending on where you live, you may have the right to:

  • know what personal information we hold about you and how we use it, and get a copy of it;
  • have it corrected if it is wrong, out of date or incomplete;
  • have it deleted;
  • object to, or ask us to restrict, how we use it;
  • receive it in a portable format, or have it sent to another organisation;
  • withdraw consent you have given, without affecting what we did before;
  • appoint someone to act for you; and
  • complain to us and then to a regulator.

We will not treat you differently for using your rights. Some rights have legal limits — we may have to keep information to meet a legal obligation, for example. Your region’s section explains the rights that apply where you live. For Customer Data, please contact the organisation that uses FleetConnect; if you contact us, we will pass your request on and help it respond.

14. Making a request or complaint

  • Email us at support@fleetconnect.global with “Privacy request” in the subject line. The link opens an email with the details we need.
  • To delete your account, follow the steps on our account-deletion page.
  • Ask your administrator. Your organisation’s administrators can correct your details and remove you from its workspace.

Privacy Officer: [Name]. India Grievance Officer: [Name]. Both can be reached at support@fleetconnect.global.

To complain about how we have handled your information, email us with the details. We will acknowledge your complaint within 5 business days, look into it, and give you our response within 30 days. If you are not satisfied, you can complain to the regulator where you live — your region’s section says who that is.

15. How we handle your request

  • We check it is you. We usually ask you to write from, or confirm the request from, the email address on your account. If someone acts for you, we need proof of their authority.
  • We respond promptly. We acknowledge requests within 5 business days and aim to complete them within 30 days. If we need longer, as some laws allow, we will tell you why and when to expect an answer.
  • It is usually free. We charge only where the law allows — for example, for requests that are clearly unfounded or excessive — and we will tell you before we do.
  • If we cannot do what you ask, we will explain why — for example, a legal duty to keep the information — and how to complain.

16. If you don’t give us information

You can browse our website without telling us who you are. But we need some information to open an account and provide the Services, and without it we may not be able to provide them. If you ask us to stop using information we need to perform a contract, we may have to stop providing that part of the Services.

17. Changes to this notice

We update this notice when our practices, the Services or the law change. If a change is significant, we will tell you through the Services or by email before it takes effect. The date at the top shows when it last changed.

Regional sections

These sections add to the notice above for people in each region. Where a section differs from the rest of the notice, the section applies in that region.

Australia

Privacy Act 1988 (Cth) · Australian Privacy Principles

We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Australian law does not draw the controller–processor line that other laws do, so we meet our APP obligations whichever role we are in.

Dealing with us anonymously

You can browse our website and ask general questions without telling us who you are, or under a pseudonym. To open an account or use the Services, we need to know who you are.

Disclosure overseas

Our platform is hosted in India, our team works in Australia and India, and some of the service providers in section 6 process information in the United States and other countries. Before we disclose personal information overseas, we take reasonable steps — chiefly through contracts — to make sure the recipient handles it consistently with the APPs.

Data breaches

We follow the Notifiable Data Breaches scheme: if a breach is likely to cause serious harm, we notify the people affected and the Office of the Australian Information Commissioner (OAIC).

To be informed

What it means
To be told, when we collect your information or soon after, who we are, why we collect it, who we share it with and how to reach us. This notice does that.

To access

What it means
To ask for the personal information we hold about you. Asking is free.

To correction

What it means
To have information corrected if it is inaccurate, out of date, incomplete, irrelevant or misleading — and, if we disagree, to have your view noted with it.

To anonymity

What it means
To deal with us without identifying yourself, where that is practicable.

To complain

What it means
To complain to us first; if you are not satisfied with our response, to the OAIC.

India

Digital Personal Data Protection Act, 2023 · DPDP Rules, 2025 · Information Technology Act, 2000

Where the Digital Personal Data Protection Act, 2023 (DPDP Act) applies, we are the Data Fiduciary for the personal data we collect for our own purposes. For Customer Data, the customer is the Data Fiduciary and we are its Data Processor. Most of the Act’s duties take effect on 14 May 2027; until then the Information Technology Act, 2000 and its rules also apply. We already offer the rights below.

Consent and legitimate uses

We process your personal data with your consent, or for a use the Act permits without it — for example, where you give us data voluntarily for a particular purpose, or to meet a legal obligation. You can withdraw consent at any time, as easily as you gave it. Withdrawal does not undo processing already done, and it may mean we can no longer provide some of the Services.

Where your data is kept

Our platform and its backups are hosted in India. Some information is also processed in Australia, by our team, and in the other countries in section 9 — but never in a country the Central Government has restricted.

Data breaches

We notify the Data Protection Board of India and each affected Data Principal of a personal data breach, in the manner the Act and its rules set out.

To access

What it means
A summary of the personal data we process about you and how we process it, and who else — other Data Fiduciaries and Data Processors — we have shared it with.

To correction and erasure

What it means
To have your personal data corrected, completed or updated, and erased once it is no longer needed — unless the law requires us to keep it.

To grievance redressal

What it means
To have a complaint handled by our Grievance Officer, who will respond within the time the rules allow.

To nominate

What it means
To nominate someone to exercise your rights if you die or become unable to.

To withdraw consent

What it means
To withdraw your consent at any time, as easily as you gave it.

Grievance Officer: [Name], reachable at support@fleetconnect.global (subject “Grievance”). Please raise a grievance with us first; if you are not satisfied with our response, you can complain to the Data Protection Board of India.

New Zealand

Privacy Act 2020

When we collect or hold personal information in the course of doing business in New Zealand, we comply with the Privacy Act 2020 and its information privacy principles (IPPs). The Act does not use the controller–processor distinction.

Information we receive from someone else

When we receive information about you from someone else — for example, when your employer adds you as a driver — this notice is how we tell you who we are, why we hold it, who we share it with and how to access and correct it. Your employer should tell you too.

Sending information overseas

Our platform is hosted in India, and service providers outside New Zealand hold information on our behalf. If we disclose it to another organisation outside New Zealand, we do so only where the IPPs allow — for example, where that organisation is subject to comparable safeguards.

Privacy breaches

If a privacy breach causes, or is likely to cause, serious harm, we notify the Privacy Commissioner and the people affected.

To be informed

What it means
To know, when we collect your information — including from someone else — why we collect it and who will receive it.

To access

What it means
To ask whether we hold personal information about you, and to see it.

To correction

What it means
To ask us to correct it — and, if we do not agree, to have a statement of the correction you asked for attached to it.

To complain

What it means
To complain to us first and, if you are not satisfied, to the Office of the Privacy Commissioner.

United Kingdom & EEA

UK GDPR and Data Protection Act 2018 · EU General Data Protection Regulation

Where the UK GDPR or the EU General Data Protection Regulation applies, we are the controller of the personal information we collect for our own purposes, and a processor for Customer Data, which our customers control. Section 4 sets out the legal basis for each use. Where we rely on legitimate interests, we have weighed them against your rights, and you can ask us about that assessment.

International transfers

When your information leaves the UK or EEA — to our platform in India, to our team in Australia and India, or to our service providers — we protect it as this notice describes. Where the law requires a transfer safeguard, we rely on an adequacy decision or on standard contractual clauses (with the UK’s addendum for UK transfers); you can ask us for a copy.

To access

What it means
To get a copy of your personal information and details of how we use it.

To rectification

What it means
To have inaccurate information corrected and incomplete information completed.

To erasure

What it means
To have your information deleted where there is no good reason for us to keep it.

To restriction

What it means
To ask us to limit how we use your information — for example, while a dispute is resolved.

To portability

What it means
To receive information you gave us in a structured, machine-readable format, or have it sent to another organisation.

To object

What it means
To object to uses based on our legitimate interests — and, always, to direct marketing.

To withdraw consent

What it means
Where we rely on consent, to withdraw it at any time.

To complain

What it means
To complain to the Information Commissioner’s Office in the UK, or to the supervisory authority where you live or work in the EEA. We would welcome the chance to put things right first.

Rest of the world

Your local data-protection law

Wherever else you live, this notice applies in full. If your local law gives you rights beyond those described here, contact us and we will honour them as that law requires.