Last updated on September 12, 2019
We reserve the right to update and change this Policy from time to time and will provide notice to you by changing the “last updated” date above. All changes are prospective only. It is your obligation to be familiar with the most current version of the Policy. Continued use of the Service after any such changes shall constitute your acknowledgment of and consent to such changes. You can review the most current version of the Policy at any time at https://www.fleetio.com/privacy.
If you are using the Service on behalf of a company or other legal entity, you represent and warrant that you have the authority to bind that company or other legal entity to this Policy, in such event, “You” will refer and apply to that company or other legal entity.
We collect, use and disclose two types of information: Personal Information and Non-Personal Information.
- “Personal Information” is information that is directly associated with a specific person or entity, including but not limited to, names, email addresses, usernames, passwords, and payment information.
- “Non-Personal Information” is information we collect or compile that by itself cannot be directly associated with a specific person or entity.
- We may further compile “Non-Personal Information” into “Aggregate Data”. This Policy in no way restricts or limits our collection and use of Non-Personal Information and Aggregate Data, and we may share Non-Personal Information and Aggregate Data that we collect or compile with third parties for various purposes, including to help us better understand our customer needs and improve our Service, and for advertising and marketing purposes.
- We automatically receive certain types of information when you interact with our Service. That information includes your computer’s IP address, access times, your browser type and language, and referring website addresses. We may also collect information about the type of operating system you use, your account activity, and files or pages accessed or used by you.
- You reserve the right to ask us what personal data is being processed and the rationale for such processing if that should ever be unclear.
- While using our Service, you will have access to all data within your account. You reserve the right to access this data and/or request copies of this data.
- While using our Service, you’ll be able to update all personally identifiable information to maintain accuracy.
- You maintain the right to withdraw consent to manual or automated data processing when previous consent has been given. This could include all future processing or processing during a specific timeframe. This could include removal of data from an account or a request to remove an email from a specific mailing list.
- You reserve the right to erasure and data portability. You will have the ability to export data in your account and keep for yourself or import into another system. After Service cancellation, data will not be retained on our servers if requested in writing. In addition, you can delete any type of personally identifiable information within your account or request to be removed from any type of customer communication at any time.
OPT-OUT OF TARGETED ADVERTISING
If you would like to opt-out of targeted advertising, you may find additional information at www.aboutads.info, networkadvertising.org/choices, or youronlinechoices.eu (Europe only), otherwise no additional action is required.
We have also included information about cookies set by third parties. Given that these relate to third party services, we cannot guarantee the completeness or accuracy of the list, but we can say that we have done our best to ensure the list is as accurate as possible at the time this policy was prepared. Nevertheless, we strongly recommend that you consult the third party websites listed in the cookie descriptions to find out more about the third party cookies in question.
Cookies set by Fleetio
id This cookie provides a temporary identifier so that we can track unique users across different requests.
rememberMe This is a cookie which allows you to return to secure.fleetio.com without having to type in your username/password combination again.
_fleetio_reports_distance_unit, _fleetio_reports_volume_unit, mp, nav_state This cookie is used to keep track of a user’s preferences.
_fleetio_session This cookie is used to keep track of a user’s session, so that they can remain logged in.
Cookies set by third parties
We recommend that you review your browser's privacy settings and adjust them accordingly if you wish to deny cookies from any sites.
USE OF PERSONAL INFORMATION
We use collected information about you to process your requests or billing transactions, to provide you with information or services you request, to inform you about other information, events, promotions, products, or services we think will be of interest to you, and to support and facilitate your usage of the Service.
We also use collected information to track engagement in key product areas in an effort to continually improve the user experience. As mentioned above, you reserve the right to remove yourself from that type of tracking.
INFORMATION SHARING AND DISCLOSURE
We will not give, sell, rent, share, or trade any of your Personal Information or any data that you store using our Service to any third party except i) with your explicit consent or ii) as outlined in this Policy. We reserve the right to share Non-Personal Information and Aggregate Data as described in this Policy.
We may share Personal Information with third party service and technology providers to facilitate the operation of the Service, to perform related services (e.g., without limitation, maintenance services, database management, web analytics and improvement of the Service’s features, or to process credit card payments), or to assist us in analyzing how our Service is used.
We may disclose Personal Information to a third party to comply with a court order, subpoena, search warrant, or other legal processes; to comply with legal, regulatory, or administrative requirements of any governmental authorities; to protect and defend us, our subsidiaries and our affiliates, and our officers, directors, employees, attorneys, agents, contractors, and partners, in connection with any legal action, claim, or dispute; to enforce the Terms of Service; to prevent imminent physical harm; and in the event that we find that your actions violate any laws, our Terms of Service, or any of our usage guidelines for specific products or services.
MODIFYING YOUR PERSONAL INFORMATION
If you are a registered user of our Service, you may review, update, correct or delete your personal information by logging into the Service and editing your profile.
We are very concerned with safeguarding your information. We take reasonable steps to protect the information we collect from you to prevent loss, misuse and unauthorized access, disclosure, alteration, and destruction. Highly confidential personal information such as credit card data is protected with encryption using Secured Socket Layer (SSL) technology during transmission over the Internet. But, remember that no method of transmission over the Internet or method of electronic storage is 100% secure.
Your account information and access to our Service is accessible only through the use of an individual username and password. You should keep your password confidential and do not disclose it to any other person. Please note that we will never ask you to disclose your password in an unsolicited phone call or email. You are responsible for all activities which are conducted using your account or password.
All data in the Service is stored and processed through third party subprocessor Amazon Web Services (AWS), which has its processing in the United States of America and Ireland. You can learn more about AWS’ privacy and security processes here: https://aws.amazon.com/privacy/
In the case of a data breach, we will notify affected users – without undue delay and where feasible – within 72 business hours. The notification will include the nature of the breach, likely consequences, a detail action plan and a main technical point of contact at Fleetio.
European Union General Data Protection Regulation (GDPR)
As a data controller, we have updated our Service and processes as required by GDPR, including giving data subjects in the European Union the following rights
- Right of access
- Right to rectification
- Right to erasure
- Right to restriction of processing
- Right to object
- Right to data portability
Please see below for more details about the GDPR compliance of our data subprocessor, AWS.
We are responsible for the processing of personal data we receive under the EU-U.S. Privacy Shield Framework and subsequently transfers to a third party acting as an agent on our behalf. We comply with the EU-U.S. Privacy Shield Principles for all onward transfers of personal data from the EU and Switzerland, including the onward transfer liability provisions.
In compliance with the Privacy Shield Principles, we commit to resolve complaints about our collection or use of your personal information. European Union individuals with inquiries or complaints regarding our Privacy Shield policy should first contact us at firstname.lastname@example.org.
We commit to cooperate with Data Protection Authorities and comply with the advice given by the panel established by Data Protection Authorities with regard to data transferred from the EU. The Federal Trade Commission has jurisdiction over our compliance with the Privacy Shield.
An individual has the possibility, under certain conditions, to invoke binding arbitration for complaints regarding Privacy Shield compliance not resolved by any of the other Privacy Shield mechanisms as outlined here: https://www.privacyshield.gov/article?id=ANNEX-I-introduction
Amazon Web Services (AWS)
As mentioned above, all data in the Service is stored and processed through third party subprocessor Amazon Web Services (AWS), with processing in the United States of America and Ireland. AWS’ security and compliance experts confirm that AWS has in place effective technical and organizational measures for data processors to secure personal data in accordance with the GDPR (https://aws.amazon.com/blogs/security/all-aws-services-gdpr-ready/), and AWS is also certified by Privacy Shield (https://www.privacyshield.gov/participant?id=a2zt0000000TOWQAA4&status=Active) on both the EU-U.S. and Swiss-U.S. privacy frameworks.