Version: 5.7.2 Effective date: August 20, 2026 Market: United States
1. Who controls your information
The Local FleetOS Entity displayed to you at account creation and recorded in your acceptance evidence is the controller of your personal information for account administration, platform security, fraud prevention, billing, analytics and legal compliance in that market. “FleetOS” in this Policy means that Local FleetOS Entity only, unless a specific recipient is separately identified.
For an Operator Network Ride, each Office is a separate and independent controller for its own transportation operations: managing its Drivers, setting its fares, handling complaints, meeting regulatory obligations, and using information it collects independently of FleetOS. Information necessary for that Ride is shared with the Office and its own privacy notice governs its independent use. For an activated FleetOS Direct Ride, the Local FleetOS Entity acts as controller for the Direct transportation operation, including its own direct-driver administration, fare, safety, compliance and complaint handling.
FleetOS acts as a processor on behalf of an Office only where the Data Processing Addendum (FOS-07) expressly applies — broadly, when we handle information at the Office's instruction for the Office's own purposes.
Market data ring-fencing. FleetOS market entities are not joint controllers merely because they use the same brand, software or ownership structure. Personal information is assigned to the market tenant for your Local FleetOS Entity. Another market entity may access or receive it only where this Policy identifies a lawful recipient role, FOS-07 lists it as a subprocessor for Office-controlled data, or law otherwise requires the transfer.
Separate requests and records. A privacy, litigation, regulatory or law-enforcement request directed to one FleetOS market entity does not by itself authorise another market entity to search, disclose or act on records controlled by the Local FleetOS Entity. Requests are routed to the entity that controls the relevant records, unless applicable law requires a different response.
2. What we collect and why
| Category | Examples | Why we process it | Legal basis |
|---|---|---|---|
| Identity and account | Name, phone, email, photo, credentials, language, role, date of birth | Create and secure your account, authenticate you, support you, keep legal records | Contract; legal obligation |
| Driver and vehicle compliance | Licences, permits, vehicle registration, insurance, training records, Office affiliations, screening status | Eligibility workflow, document-expiry gating, audit, regulator response | Contract; legal obligation; legitimate interests |
| Trip and precise location | Pickup, destination, route, online status, timestamps, distance | Booking, dispatch, navigation, safety, fare calculation, dispute resolution, fraud prevention | Contract; legitimate interests; consent where required |
| Payment | Payment tokens, masked card details, processor identifiers, balances, currency, refunds, chargebacks | Take payment, settle to Offices, accounting, fraud detection, support | Contract; legal obligation |
| Communications | In-app messages, support tickets, call metadata, and call recordings where separately disclosed | Provide service, investigate safety incidents, resolve disputes, quality assurance | Contract; legitimate interests; consent where required |
| Device and usage | IP address, device identifiers, operating system, app version, crash logs, cookies, analytics events | Security, diagnostics, abuse prevention, product analytics, preferences | Legitimate interests; consent for non-essential cookies |
| Identity and document verification | ID documents, document images, verification result and status; no FleetOS biometric template at launch | Verify identity and documents, prevent account takeover and fraud | Contract; legitimate interests; consent where required |
| Background screening | Screening result and status where lawfully obtained; ordinarily for an Office, and for FleetOS Direct Drivers only where the Local FleetOS Entity is legally responsible for the Direct-driver engagement | Office or Direct-driver eligibility under applicable law | Consent; legal obligation; see §14 |
| Safety and incident | Incident reports, photographs, witness accounts, telematics where enabled | Investigate incidents, protect users, respond to authorities, insurance | Legitimate interests; vital interests; legal obligation |
3. How we use information
We use personal information to provide and operate the Platform Services; to authenticate and secure accounts; to match Passengers with Offices and Drivers; to calculate and process payment; to communicate with you about your account, bookings and safety; to detect, investigate and prevent fraud, abuse and security incidents; to comply with legal, regulatory, tax and sanctions obligations; to investigate safety incidents and respond to lawful requests; to improve and develop the Platform Services; and to produce aggregated or de-identified analytics.
4. Automated processing and profiling
We use automated systems for fraud scoring, security risk assessment, dispatch matching and objective document-expiry gating.
We do not make solely automated decisions that produce legal or similarly significant effects on you without human involvement, except for objective document-expiry gates, which are mechanical (a document has expired or it has not) and are reversed immediately when the document is renewed.
We do not make hiring, engagement or termination decisions for an Office. If FleetOS Direct is activated, the Local FleetOS Entity may make decisions concerning its own Direct Drivers under a separate engagement process and applicable employment/contractor, background-screening and transport law. Where an automated control materially restricts Platform access, you may request human review under FOS-01 §17 where required and, in practice, where you ask.
5. Who we share information with
| Recipient | What is shared | Why |
|---|---|---|
| The Office you booked with, or are affiliated with | Booking, contact, trip, fare and relevant compliance information | To perform the Ride and manage the affiliation |
| The Driver performing your Ride | First name, pickup and destination, contact via masked channel where available | To perform the Ride |
| Payment processors | Payment and transaction data | To take payment and settle funds |
| Cloud, communications and mapping providers | As necessary for hosting, messaging and navigation | To operate the Platform Services |
| Identity verification and screening vendors | Identity documents and verification data | To verify identity and, where lawful, to screen |
| Professional advisers and insurers | As necessary | Legal advice, audit, claims |
| Authorities | As required by valid legal process | Legal compliance — see §11 |
| A successor | Account and transaction data | Merger, acquisition or asset sale, with notice to you |
FleetOS does not sell personal information as "sale" is defined under applicable California privacy law. Where applicable law separately regulates "sharing" for cross-context behavioural advertising, those rights and choices are described in Annex A.
6. Location information
Location is central to how the Platform Services work, so we treat it with particular care.
Passengers. We collect precise location when the app is in use to set pickup, match you with a nearby vehicle, navigate, calculate fare and support safety features. You may grant location permission while using the app only. If you deny location permission you can still enter addresses manually, but matching quality and safety features will be reduced.
Drivers. We collect precise location while you are online in Fleet DriverX, and for a short period after a trip ends for fare, dispute and safety purposes. Background location is collected while you are online so that dispatch and safety features work when the app is not in the foreground. We do not collect your location when you are offline in the app.
You can change or withdraw location permission at any time in your device settings. Doing so will disable the features that depend on it.
Detailed precise trip location is ordinarily retained for 12 months and is then aggregated or deleted. A specific record may be retained longer only for an open claim, safety investigation, fraud investigation, insurance matter, legal hold, regulatory obligation, tax/accounting requirement that applies to that record, or other documented legal necessity.
7. Identity verification and biometric information
At launch, FleetOS may collect ID documents and document images and may use an approved verification provider to return a verification result. FleetOS does not create or retain a facial-recognition, fingerprint, voiceprint or other biometric identifier/template at launch. Ordinary photographs and copies of identity documents are not treated by FleetOS as biometric templates merely because they contain a face. If a future feature creates or uses biometric identifiers, that feature must remain disabled until the relevant market notice, consent, retention/destruction schedule, vendor assessment and applicable legal review and approval have been completed.
Where we or an Office use identity verification that involves a facial scan or similar biometric process, we will tell you before it happens, tell you what is collected, tell you who processes it and for how long, and obtain your separate written consent. You are not required to consent; if you decline, an alternative verification route will be offered where one exists, and where none exists the affected function will be unavailable.
Biometric identifiers are not sold, leased, traded or otherwise profited from. They are retained only as long as necessary for the verification purpose and are deleted no later than the earlier of the satisfaction of that purpose or the deadline set by applicable law. See Annex A for United States state-specific rules, including Illinois.
8. How long we keep information
The Data Retention Register (FOS-07 Schedule 3) is the authoritative source. The table below is a summary and is subject to local law, legal holds and open disputes.
| Record | Default retention |
|---|---|
| Account profile after closure | 3 years |
| Ride, fare, refund and dispute records | 7 years |
| Detailed precise trip location | 12 months, then aggregated or deleted |
| Driver applications not accepted | 2 years (United States); shorter where local law requires |
| Biometric templates | Purpose satisfied, or statutory deadline, whichever is earlier |
| Marketing consent and opt-out records | 5 years after last relevant communication |
| Security and authentication logs | 24 months |
| Agreement acceptance evidence | Term of the agreement plus 7 years |
| Safety incident records | 7 years, or longer where a claim or investigation is open |
9. Your rights
Depending on where you are, you may have the right to: access the information we hold about you; correct inaccurate information; delete information; obtain a portable copy; restrict or object to certain processing; withdraw consent; opt out of certain sharing or targeted advertising; and appeal a decision we make on your request.
Submit requests through the Privacy Request form in the FleetOS Legal Center, or at the Privacy Request channel in the FleetOS Legal Center. We verify requests proportionately to the sensitivity of the information — we will ask you to confirm control of the account, and for high-risk requests we may ask for more.
We respond within the period applicable law requires, and in any event without undue delay. If we decline a request we will tell you why and how to appeal or complain.
Requests to an Office. Where an Office is the controller — for its own operations, its own Driver management, or its own complaint records — direct your request to that Office. We will help you identify the right contact.
10. Deletion and what survives it
When you delete your account we delete or de-identify your personal information, except where we must retain it to: comply with a legal, tax, accounting or regulatory obligation; resolve a dispute or defend a claim; complete a payment, refund or chargeback; enforce our agreements; prevent fraud or abuse; or preserve evidence under a legal hold.
Backups are overwritten on our ordinary backup cycle. Aggregated and de-identified information that cannot be linked back to you is not deleted.
11. Law enforcement and government requests
We disclose personal information to authorities only where the Local FleetOS Entity that controls the records is compelled by valid legal process, or where that entity reasonably believes in good faith that disclosure is necessary to prevent imminent death or serious physical harm. Another FleetOS market entity does not become a records custodian merely because it shares branding or technology.
We require legal process appropriate to the request. We review each request for validity, scope and proportionality, and we push back on requests that are overbroad, defective or unlawful. Where we are legally permitted to do so, we notify the affected user before disclosing, unless doing so would create a risk of harm or obstruct an investigation.
We intend to publish a periodic transparency report on request volumes once operational volumes make one meaningful.
12. Cookies and similar technologies
We use strictly necessary cookies to operate the website and keep it secure; these cannot be disabled. We use functional, analytics and — where enabled — advertising cookies only with your consent where consent is required.
You can manage your choices in the cookie preference centre on our website, or in your browser settings. Withdrawing consent does not affect the lawfulness of prior processing. See Annex A for applicable United States state opt-out signals.
13. Marketing
We send marketing only where you have opted in, or where applicable law permits us to contact an existing customer about similar services and you have not opted out.
Every marketing message contains an unsubscribe mechanism. You can also manage marketing preferences in your account settings. Opting out of marketing does not stop service, security, transactional, safety or legal messages, which you receive as long as you hold an account.
Where an Office markets to you, that Office is the sender and is responsible for its own compliance. We do not provide your contact details to an Office for its independent marketing without your consent.
Advertising and measurement technologies. Where enabled for a market and only after any consent required by applicable law, FleetOS may use Google Analytics and may use advertising/measurement technologies such as Google Ads, Meta and TikTok to measure campaigns, attribute conversions, limit frequency and deliver or measure advertising. These tools are non-essential. We provide consent/choice controls where required, and in the United States we honour applicable opt-out preference signals such as Global Privacy Control as described in Annex A. Advertising vendors do not receive Office-controlled data merely because the Office uses FleetOS.
14. Background screening
Some markets require, and some Offices lawfully conduct, background or driving-record checks on Drivers. Where such a check is performed in the United States through a consumer reporting agency, it is subject to the Fair Credit Reporting Act, and you will receive a standalone written disclosure and provide written authorisation before it happens, and will receive pre-adverse and adverse action notices with a copy of the report and a summary of your rights before any adverse decision becomes final.
For an Office-affiliated Driver, the Office, not FleetOS, is the decision-maker. We may transmit a result and record a status; we do not decide whether the Office engages the Driver. For a FleetOS Direct Driver, the Local FleetOS Entity may be the decision-maker only under its separate Direct-driver process and must follow applicable background-screening, adverse-action, transport and worker-classification law.
15. Children and minor passengers
The Platform Services are not directed to children and a person under the minimum account age in FOS-01 §3.2 may not create a FleetOS account. An adult account holder may, however, provide limited information about a minor passenger when lawfully arranging transportation for that minor through a provider that expressly offers such service. That information may include the minor passenger's name or identifier, pickup and destination information, trip location/status, guardian contact details and safety information reasonably necessary for the Ride.
FleetOS uses minor-passenger information only for the lawful Ride, safety, support, legal-compliance and records purposes described in this Policy, applies heightened minimisation and access controls, and does not use known child data for behavioural advertising. If FleetOS has actual knowledge that it is collecting personal information online from a child under 13 in circumstances subject to COPPA, FleetOS will obtain verifiable parental consent or another lawful basis/exception before the collection, use or disclosure required by COPPA, or will not collect the information. If we learn that a child created an account contrary to these Terms, we will disable the account and handle the information in accordance with applicable law. A parent or guardian may contact the Privacy Request channel in the FleetOS Legal Center regarding a child's information.
16. Security
We maintain technical and organisational measures described in FOS-06 Schedule 3, including encryption in transit and at rest, access control on a least-privilege basis, multi-factor authentication for administrative access, logging and monitoring, vulnerability management, and personnel training.
No system is perfectly secure. If a personal data breach occurs, we notify affected individuals and regulators within the period applicable law requires, and we notify Offices within the contractual period in FOS-07 §7.
17. Where information is processed
Personal information may be processed outside your country by approved cloud providers and subprocessors. The current hosting locations, subprocessors and transfer safeguards are published in FOS-07 Schedule 2. Other FleetOS market entities are not default recipients or processors; if one performs a service involving personal information, it must be specifically documented with its role, purpose, access scope and transfer basis.
Where information is transferred out of a jurisdiction that restricts transfers, we rely on the mechanism identified in that Register — such as standard contractual clauses, an adequacy decision, or your explicit consent where permitted. A market is not activated until its data-location and transfer assessment is completed and recorded.
18. Changes to this Policy
We will post changes here with a new effective date. Where a change materially affects how we use your personal information, we give you conspicuous notice and, where the law requires it or where the change is material, we ask for your renewed consent.
19. Contact and complaints
United States public contacts: Legal/support: info@fleetapp.net · Privacy: privacy@fleetapp.net · Legal Center: https://fleetapp.net/#legal. No public telephone support number is designated for this market.
Contact us at the market-specific privacy contact details shown in the FleetOS Legal Center. Our data protection contact is the Data Protection Lead identified in the FleetOS Legal Center.
If you are not satisfied with our response, you may complain to the supervisory authority or other competent complaint body identified for your market in the relevant Annex or the FleetOS Legal Center. Where no dedicated privacy authority is available for the relevant issue, the Legal Center identifies the applicable general complaint route.
Annex A — United States
A1. Scope
This Annex applies where you are a resident of a United States state with an applicable privacy statute, and supplements the main Policy.
A2. Notice at collection (California)
We collect the categories of personal information listed in §2. For California residents, those categories map to the CCPA categories as follows: identifiers; customer records information; commercial information; internet or network activity; geolocation data; audio or visual information; professional or employment information; and sensitive personal information (precise geolocation, government identifiers, and biometric information where collected).
We collect this information for the business and commercial purposes in §3. We retain it for the periods in §8. We disclose it to the recipient categories in §5.
A3. Sale and sharing
FleetOS does not sell personal information as "sale" is defined under California privacy law. FleetOS does not share personal information for cross-context behavioural advertising unless a legally compliant choice mechanism and any required authorization have been implemented. Where such sharing occurs, California consumers may exercise the applicable opt-out right through the "Do Not Sell or Share My Personal Information" mechanism or another method required by law.
We honour Global Privacy Control and comparable opt-out preference signals as a valid opt-out of sharing.
FleetOS does not knowingly sell or share personal information of consumers under 16 where applicable law requires opt-in authorization, and FleetOS does not knowingly sell personal information as "sale" is defined under applicable California privacy law.
A4. Sensitive personal information
We use sensitive personal information only for the purposes permitted without a right to limit — providing the services you requested, security, fraud prevention, safety, and compliance — and we do not use or disclose it for inferring characteristics about you.
A5. Your California rights
You have the right to know, delete, correct, opt out of sale or sharing, limit use of sensitive personal information, and to non-discrimination for exercising these rights. You may use an authorised agent with proof of authority. Submit requests using the methods set out in §9 and the FleetOS Legal Center. If applicable law requires an additional request method for FleetOS at the time of your request, that method will be made available before the relevant market feature is activated.
Shine the Light. California residents may request information about disclosure of personal information to third parties for their direct marketing purposes. We do not make such disclosures.
A6. California risk assessments, cybersecurity audits and automated decisionmaking
California privacy regulations effective January 1, 2026 include risk-assessment and, for covered businesses, cybersecurity-audit requirements. Separate requirements governing covered uses of automated decisionmaking technology (ADMT) phase in beginning January 1, 2027. FleetOS assesses applicability before enabling processing or product functionality that may trigger those requirements.
Where a requirement applies, the relevant California processing or feature remains unavailable until FleetOS has documented the required risk assessment or applicability determination, implemented the controls and consumer rights required for the applicable phase, and stored approval evidence in the legal compliance record. A documented determination that a requirement is not applicable must be reviewed and evidenced; an internal product setting alone is not a legal determination.
A7. Other state rights
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy statutes have rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale and certain profiling, together with a right to appeal a denial. We honour these rights through the same request channel. Our appeal process is described in the response to any denial.
California processor contracts. Where a United States Local FleetOS Entity acts as a service provider or contractor for an Office under the CCPA, FOS-07 Schedule 4 applies and contractually restricts selling/sharing, use outside the specified business purposes or direct business relationship, impermissible combining of personal information, and downstream processing, and provides compliance, monitoring, assistance and remediation rights required by applicable California law.
A8. Biometric information — Illinois and comparable states
Where biometric identifiers or biometric information are collected from an Illinois resident, we comply with the Biometric Information Privacy Act: we obtain written consent before collection, we disclose the specific purpose and the retention period, we do not sell or profit from biometric information, and we destroy it when the purpose is satisfied or within three years of the last interaction, whichever is earlier. Comparable rules in Texas and Washington are applied to residents of those states.
| Biometric features are not enabled for a user unless the notices, consents, retention rules, vendor protections and other safeguards required by applicable law for that feature and jurisdiction are in place. If those requirements are not satisfied, the biometric feature remains unavailable. |
|---|
A9. Sanctions and screening data
Restricted-party screening required by FOS-01 §24 involves processing your name, date of birth, nationality and ownership information against government lists. This processing is necessary for compliance with legal obligations and cannot be opted out of while you hold an account.