Who we are
FleetVault ("FleetVault", "we", "us") provides freight margin analysis services, including the Margin Leak Audit and the FleetVault Command subscription. We operate from 3528 Rue Elsie-Reford, Laval, Quebec H7Y 0B7, Canada.
For questions about this policy or about data we hold, contact nico@getfleetvault.com or +1 (514) 632-6426.
What we collect
Client operating data
This is the material you send us for an engagement. It typically includes settlement and load records, rate confirmations, fuel card transactions, factoring statements, ELD dwell and stop data, and lane and customer identifiers.
We ask you to send operational and financial records, not personnel records. Driver names, licence numbers, dates of birth, medical records, and similar personal identifiers are not required for the audit. Where your exports include them incidentally, we do not use them in the analysis, and we will pseudonymise or strip them on request.
Business contact data
Name, work email, phone number, company, and role — collected when you contact us, book an audit, or subscribe.
Payment data
Card and billing information is collected and processed entirely by Stripe. FleetVault never sees, stores, or has access to your full card number. We receive only a transaction record: amount, date, last four digits, and status.
Site data
Standard server logs (IP address, user agent, pages requested, timestamps) retained for security and troubleshooting.
What we do with it
| Data | Purpose | Legal basis |
|---|---|---|
| Operating data | Produce your audit, recovery plan and ongoing Command monitoring | Performance of contract |
| Business contact | Respond to enquiries, deliver reports, send service communications | Contract / legitimate interest |
| Payment records | Billing, accounting, tax and audit obligations | Legal obligation |
| Server logs | Security, abuse prevention, diagnostics | Legitimate interest |
What we never do
We do not sell your data. We do not rent, licence or share it with data brokers, load boards, brokers, shippers, carriers, insurers, or your competitors. We do not use your rate data to advantage another client in a negotiation. We do not train third-party models on your data, and we do not upload identifiable client data into public AI tools.
Where we publish benchmarks or case figures, they are aggregated across multiple fleets and de-identified so that no individual client, lane, customer or rate is reconstructable.
Who else touches it
We keep the processor list short on purpose. As of the effective date above:
- Stripe — payment processing and billing.
- Google Workspace — business email and document storage.
- Cloud hosting and storage providers — encrypted storage of working files during an engagement.
Each is bound by its own data protection terms. We do not add processors that receive identifiable client operating data without updating this page.
We may disclose data where required by law, court order, or lawful request by a competent authority. Where we are legally permitted to tell you, we will.
Where it lives and how it is protected
Data is stored on servers in Canada and the United States. Transfers are protected by contractual safeguards with each provider.
- Encrypted in transit (TLS) and at rest.
- Access limited to personnel working on your engagement.
- Client working files kept in per-client isolated storage, never pooled.
- Access credentials rotated on personnel change.
No system is perfect. If a breach affects your data, we will notify you without undue delay, and in any event within 72 hours of becoming aware, with what we know and what we are doing about it.
How long we keep it
| Category | Retention |
|---|---|
| Raw exports you send | Deleted 90 days after the engagement ends, or immediately on written request |
| Derived analysis & reports | Retained for the life of the engagement, then 12 months, then deleted |
| De-identified benchmarks | Retained indefinitely — cannot be traced to a client |
| Invoices & tax records | Seven years, as required by law |
| Business contact data | Until you ask us to remove it |
Your rights
You may ask us to give you a copy of the data we hold about you, correct it, delete it, restrict how we use it, export it in a portable format, or object to a particular use. If you are covered by Quebec's Law 25, PIPEDA, the GDPR, or a US state privacy law, those rights apply to you directly.
Write to nico@getfleetvault.com. We respond within 30 days. There is no charge. If you are unsatisfied with our answer, you may complain to your data protection authority — in Quebec, the Commission d'accès à l'information.
Cookies
This site uses only what it needs to function. We do not run advertising trackers, cross-site pixels, or third-party marketing cookies. Any analytics we run are configured without cross-site identifiers.
Children
FleetVault is a business service. It is not directed to anyone under 18 and we do not knowingly collect their data.
Changes
If we change this policy we will update the version and effective date above. Where a change materially affects how we handle client operating data, we will notify active clients by email before it takes effect.