Privacy

Privacy Policy

This policy explains what Fleetlyf processes for companies and people worldwide, why it is needed, and the choices available under applicable privacy law.

Effective August 16, 2026

Who is responsible for the data

A company that creates a Fleetlyf workspace decides which vehicles, team members, trips, and operating records are entered. For that company-controlled fleet data, the company is normally the controller, business, or equivalent responsible party under its applicable law, and Fleetlyf processes the data to provide the service.

Fleetlyf is responsible for account administration, service security, billing, support, and website information that Fleetlyf collects for its own operation. Companies remain responsible for informing drivers and team members about their workplace policies and lawful use of Fleetlyf.

Information Fleetlyf processes

The exact information depends on the workflow and features selected by the company. Manager-managed trips can contain office-entered results without phone proof. Mixed and Driver-assisted trips may contain additional checkpoint evidence.

  • Account and profile information, including name, work email, contact number, job title, organization membership, role, and authentication records.
  • Company and billing information, including company profile, plan, vehicle count, invoice and subscription references, and payment status. Fleetlyf does not store complete card details.
  • Vehicle and driver records, including registration or license references and expiry dates entered by the company.
  • Trip, route, schedule, mileage, fuel, maintenance, issue, review, correction, notification, and audit records.
  • Questions, generated answers, validated source references, and limited usage metadata when an authorized user chooses to use Fleetlyf AI.
  • Checkpoint latitude, longitude, accuracy, time, and related device metadata when a person intentionally captures a checkpoint.
  • Odometer scan text, confidence, confirmed mileage, correction reason, and temporary validation image when phone-camera proof is used.
  • Technical and security information such as IP address, browser or user-agent information, session activity, request identifiers, and server logs.

Location and odometer images

Fleetlyf does not continuously track a driver and does not run background GPS surveillance. Location is requested only when a person chooses a checkpoint, issue-location, break-location, or Record trip location action. The active-trip map keeps one latest-location snapshot for management, while each intentional Record trip location submission is also added to that trip’s progress ledger with its captured time. Start, end, break, issue, and progress location evidence follows the applicable fleet record and retention workflow. A nearby saved-location label is only a display convenience; the recorded coordinates remain the evidence.

An authorized manager may create a revocable trip-progress link for a client. The public page shows only the company name, trip status and route, vehicle display name, and recorded progress points; it does not expose driver contact details, internal notes, documents, or financial records. The link closes 24 hours after trip completion and has a 90-day maximum life unless management turns it off or replaces it sooner.

An odometer image is temporary validation evidence. It is available while the submitted mileage needs management review, then Fleetlyf clears the image reference and deletes the file when management accepts the result. Unattached temporary uploads are scheduled for deletion after 24 hours. The confirmed mileage, OCR result, correction reason, decision, and audit history remain as structured records.

Why the information is used

  • Create and secure accounts, sessions, organizations, roles, and access controls.
  • Plan trips and preserve office-entered or driver-submitted operational records.
  • Provide an authorized client with a time-limited view of driver-submitted trip progress when a manager deliberately creates a share link.
  • Connect mileage, fuel, maintenance, issues, decisions, corrections, and printable vehicle history.
  • Surface factual differences, incomplete evidence, upcoming deadlines, and records that require human review.
  • Answer authorized Fleetlyf AI questions using the workspace records and selected files available to that user.
  • Provide support, prevent misuse, investigate errors, monitor reliability, and satisfy legal obligations.
  • Administer trials, subscriptions, invoices, and payment access.

Automated processing and human decisions

Fleetlyf applies deterministic rules to route distance, duration, mileage continuity, fuel evidence, checkpoint accuracy, OCR confidence, maintenance dates, and related records. Fuel and maintenance patterns can appear in reports, reminders, or Needs action; qualifying trip and issue records can enter a manager queue. These rules do not accuse a driver, impose employment consequences, or make the final operational decision.

Authorized company users may ask Fleetlyf AI to summarize permitted workspace records, explain calculated figures, locate a source, or provide product guidance. The selected structured context and explicitly selected files needed for a request may be sent to the configured Google Gemini service. Fleetlyf validates returned source references, but generated answers can still be incomplete or mistaken and must be checked against the linked records before a business, safety, employment, financial, or legal decision is made.

Service providers and international processing

Fleetlyf is designed for customers in supported countries worldwide. Fleetlyf shares information only as needed to operate the service, follow a company instruction, complete a transaction, protect the service, or comply with law. Fleetlyf and its providers may process information outside the user’s or customer’s country. Where applicable law requires a transfer mechanism or additional safeguards, Fleetlyf will use the appropriate contractual or legal measure.

  • Infrastructure and database hosting providers used to run Fleetlyf.
  • Google services used for sign-in, maps, routes, geocoding, requested Fleetlyf explanations, and Fleetlyf AI answers.
  • Email delivery providers used for invitations, verification, support, and operational notices.
  • Dodo Payments and its payment partners for checkout, subscriptions, invoices, and the customer billing portal.
  • Professional advisers, authorities, or other parties when disclosure is legally required or necessary to protect rights and security.

Retention and deletion

Fleet records are retained while the customer maintains the workspace and for a reasonable period needed for account recovery, audit continuity, disputes, security, and legal obligations. Expired or unpaid workspaces can become read-only rather than silently losing their records.

A user’s Fleetlyf AI conversation history is retained so the same conversation can be restored after a refresh. Choosing Clear removes that user’s Fleetlyf AI conversation history from the workspace. Limited request and daily usage metadata can be retained longer for quota enforcement, reliability, security, and cost monitoring; it does not include the user’s question, document text, or the provider response.

Temporary odometer images follow the shorter lifecycle described above. Session, security, billing, and server logs are retained only as long as reasonably needed for their operational, security, accounting, or legal purpose. Fleetlyf securely deletes or anonymizes information when it is no longer required, subject to lawful retention and the rights of other people whose records are connected.

Privacy rights and requests

Depending on location and applicable law, a person may request information about processing, access, correction, objection, restriction, portability, erasure or blocking, or may withdraw consent where consent is the legal basis. Fleetlyf may need to verify identity and coordinate with the company that controls the relevant fleet workspace.

  • Use Fleetlyf’s profile, company, correction, export, archive, and feedback tools where available.
  • Contact the company that created the fleet record for workplace-record requests.
  • Contact Fleetlyf at support@fleetlyf.com for an account or privacy request.
  • Raise a concern with the relevant privacy regulator, including the Philippine National Privacy Commission where applicable.

Security

Fleetlyf uses organization-scoped authorization, role controls, secure password hashing, HttpOnly sessions, request validation, rate limiting, security headers, audit history, structured server logging, and restricted access to temporary evidence. No service can promise absolute security, so customers must also protect accounts, devices, invitations, and exported records.

Cookies and similar storage

Fleetlyf uses an essential session cookie to keep users signed in and local browser storage for preferences such as appearance and selected workspace state. Fleetlyf does not currently use advertising cookies. If non-essential analytics or advertising technology is introduced, this policy and any required consent controls will be updated first.

Policy changes

Fleetlyf may update this policy when the product, providers, or legal requirements change. Material changes will be dated and communicated through the service or account contact information where appropriate.

Questions or Requests

Contact Fleetlyf

Signed-in users can use the Feedback module. You can also email support@fleetlyf.com.