1. Information We Collect
Personal Information
When you register for FleetGear TMS, we collect:
- Name and contact information (email, phone)
- Company information (name, address, DOT/MC numbers)
- Driver information (CDL numbers, medical certificates)
- Vehicle information (VIN, registration details)
- Load and shipment data
- Financial information (for invoicing and payments)
Automatically Collected Information
We automatically collect:
- IP address and device information
- Browser type and version
- Usage data and analytics
- Cookies and similar tracking technologies
2. How We Use Your Information
We use your information to:
- Provide and maintain the Service
- Process transactions and generate invoices
- Send service-related notifications
- Provide customer support
- Improve and optimize the Service
- Ensure compliance with DOT regulations
- Detect and prevent fraud
- Send marketing communications (with your consent)
3. Data Sharing and Disclosure
We do not sell your personal information. We may share your data with:
- Service Providers: Third-party vendors who assist in operating the Service (e.g., cloud hosting, email services)
- Factoring Companies: When you use factoring services, we share necessary documents with your chosen factoring partner
- Legal Requirements: When required by law or to protect our rights
- Business Transfers: In connection with a merger, acquisition, or sale of assets
4. Data Security Measures
We implement comprehensive security measures to protect your data:
4.1 Technical Safeguards:
- Encryption: 256-bit SSL/TLS encryption for data in transit; AES-256 encryption for data at rest
- Authentication: Multi-factor authentication available; secure password requirements
- Access Controls: Role-based access control (RBAC); principle of least privilege
- Network Security: Firewall protection; intrusion detection and prevention systems
- Monitoring: 24/7 security monitoring and logging; automated threat detection
4.2 Physical Security:
- Data stored in SOC 2 compliant data centers
- 24/7 physical security and surveillance
- Controlled access with biometric authentication
- Environmental controls and redundant power systems
4.3 Operational Security:
- Regular security audits and penetration testing
- Vulnerability scanning and patch management
- Employee security training and background checks
- Incident response and disaster recovery plans
- Daily automated backups with 30-day retention
4.4 Data Isolation: Each company's data is logically isolated through multi-tenancy architecture. No company can access another company's data.
4.5 Security Limitations: While we implement industry-leading security measures, no method of electronic storage or transmission is 100% secure. You use the Service at your own risk.
5. Data Retention
We retain your data for as long as your account is active or as needed to provide services. After account termination, we retain data for:
- 90 days for general account data
- 7 years for compliance and tax records (as required by law)
- Longer periods if required by legal obligations
6. Your Rights
You have the right to:
- Access: Request a copy of your personal data
- Correction: Update or correct inaccurate data
- Deletion: Request deletion of your data (subject to legal requirements)
- Export: Download your data in a portable format
- Opt-Out: Unsubscribe from marketing communications
- Object: Object to certain data processing activities
7. Cookies and Tracking
We use cookies and similar technologies to:
- Maintain your session and preferences
- Analyze usage patterns and improve the Service
- Deliver targeted advertising (with your consent)
You can control cookie preferences through your browser settings.
8. Third-Party Services and Integrations
Our Service integrates with various third-party services. Each has its own privacy policy:
- Stripe: Payment processing (PCI DSS compliant)
- Google Maps API: Route planning and location services
- Supabase: Cloud database and file storage (SOC 2 certified)
- Email Service Providers: Transactional and marketing emails
- ELD Providers: Hours of Service data synchronization (Motive, etc.)
- Analytics Services: Usage analytics and service improvement
We share only the minimum necessary data with these services. When you use these integrations, you agree to their privacy policies. We are not responsible for third-party data handling practices.
9. Children's Privacy
FleetGear TMS is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children.
10. International Data Transfers
Your data may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for such transfers.
11. State-Specific Privacy Rights
11.1 California (CCPA/CPRA): California residents have the right to:
- Know what personal information we collect and how it's used
- Request deletion of personal information
- Opt-out of sale of personal information (we do not sell data)
- Non-discrimination for exercising privacy rights
- Correct inaccurate personal information
- Limit use of sensitive personal information
11.2 Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA): Residents have similar rights including access, deletion, correction, and data portability.
To exercise these rights, contact privacy@fleetgeartms.com. We will respond within 45 days.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through the Service.
13. Compliance and Certifications
13.1 Industry Standards: We adhere to industry best practices including:
- SOC 2 Type II compliance (data security and availability)
- GDPR principles for international data handling
- PCI DSS standards for payment card data (through Stripe)
13.2 DOT/FMCSA Compliance: We assist with DOT compliance but do not guarantee regulatory compliance. You are responsible for ensuring your use of the Service meets all applicable DOT, FMCSA, and state requirements.
14. Data Breach Notification
In the event of a data breach affecting your personal information, we will:
- Notify you within 72 hours of discovering the breach
- Provide details about what data was affected
- Outline steps we're taking to address the breach
- Advise on actions you should take to protect yourself
- Notify relevant authorities as required by law
15. Contact Us
For privacy-related questions or to exercise your rights, contact us at:
Email: privacy@fleetgeartms.com
Phone: 1-800-FLEET-01
Mail: FleetGear TMS, Privacy Department
Attn: Data Protection Officer
Dallas, TX 75201
Response Time: We respond to privacy inquiries within 10 business days and complete requests within 45 days (or as required by applicable law).
Your Privacy Matters: We are committed to protecting your privacy and handling your data responsibly. If you have any concerns, please don't hesitate to contact us.