Sign in Get started
Legal

Privacy Policy

How FLOTA collects, uses and protects data across the platform, the web dashboard and the mobile apps.

Effective 11 September 2026 Last updated 11 September 2026 Version 1.0 CURRENT VERSION

This Privacy Policy explains how FLOTA (“FLOTA”, “we”, “us”) collects, uses, stores and shares information when you use our fleet management platform, including the FLOTA web dashboard (app.flota.me), the FLOTA mobile apps for iOS and Android, and related services (together, the “Service”).

FLOTA is a business-to-business (B2B) service provided to transport operators and fleet businesses (“Customers”). If you are a driver or employee of a Customer, that Customer is the controller of your data and this policy describes how we process it on their behalf.

01Who we are

The Service is operated by the FLOTA team. For any privacy questions or requests, you can reach us at sales@flota.me.

02Data we collect

Account & identity data

Vehicle & telemetry data

Because FLOTA is a fleet-tracking platform, we process operational data reported by GPS tracking hardware installed in Customer vehicles, including:

This vehicle and location data relates to Customer assets and operations. Where it can be associated with an identifiable driver, it constitutes personal data and is processed on behalf of, and under the instructions of, the Customer.

Device & usage data

Communications

03How we use data

Where the GDPR applies, we rely on the following legal bases:

For personal data processed on behalf of a Customer, FLOTA acts as a data processor and the Customer is the data controller.

05Location data & permissions

Vehicle location is collected from tracking hardware fitted to Customer vehicles, not from your phone, and is used to provide the fleet-tracking features of the Service. The mobile apps may request notification permission to deliver alerts; these permissions are optional and can be changed or revoked in your device settings at any time. The Service continues to function without them, minus the related feature.

06Sharing & sub-processors

We do not sell personal data. We share data only with service providers who help us operate the Service, under appropriate safeguards. These include:

ProviderPurpose
Google Firebase (FCM)Delivering push notifications to mobile devices.
Apple Push Notification serviceDelivering push notifications to iOS devices.
MapTiler / OpenFreeMapMap tiles and satellite imagery in the apps and dashboard.
ResendSending transactional and alert emails.
TelegramDelivering alerts to Telegram, where a Customer enables it.
CloudflareBot protection (Turnstile) on web sign-in.
Hosting / infrastructureRunning the Service on secured cloud servers.

We may also disclose data where required by law, to protect our rights, or in connection with a business transfer.

07International transfers

Some of our providers may process data outside your country. Where personal data is transferred internationally, we rely on appropriate safeguards such as the providers’ standard contractual clauses and equivalent mechanisms.

08Data retention

We retain account data for as long as your organisation uses the Service, and operational data (such as positions, trips and alerts) for as long as needed to provide the Service and as directed by the Customer. When an account or tenant is closed, we delete or anonymise associated data within a reasonable period, unless we are required to retain it by law.

09Security

We use technical and organisational measures to protect data, including encryption in transit (TLS), hashed passwords, per-tenant data isolation (row-level security), encrypted storage of authentication tokens on mobile devices, access controls, rate limiting, bot protection on sign-in, and audit logging. No system is perfectly secure, but we work to protect your information appropriately.

10Your rights

Depending on your location, you may have rights to access, correct, delete, restrict or object to the processing of your personal data, and to data portability. Because much of the data is processed on behalf of a Customer, please direct requests to your organisation (the controller) in the first instance; we will assist them as their processor. You can also contact us at sales@flota.me, and where applicable you have the right to lodge a complaint with a data protection authority.

11Children

The Service is a business tool and is not directed to children. We do not knowingly collect personal data from children.

12Changes to this policy

We may update this policy from time to time. We will post the updated version here and revise the “Last updated” date above. Material changes will be communicated where appropriate.

13Contact

Questions about this policy or your data? Email sales@flota.me.

Revision history

VersionDateChange
1.011 September 2026First published.
Read the Terms of Service → ← Back to flota.me