FleetVault ← Back to site
Legal

Privacy Policy

Effective 27 July 2026 · Version 1.0

You are about to hand us settlements, fuel cards, factoring statements and ELD exports — the operating core of your business. This page states exactly what we do with that data, what we never do with it, and how you get it back or destroyed.

Who we are

FleetVault ("FleetVault", "we", "us") provides freight margin analysis services, including the Margin Leak Audit and the FleetVault Command subscription. We operate from 3528 Rue Elsie-Reford, Laval, Quebec H7Y 0B7, Canada.

For questions about this policy or about data we hold, contact nico@getfleetvault.com or +1 (514) 632-6426.

What we collect

Client operating data

This is the material you send us for an engagement. It typically includes settlement and load records, rate confirmations, fuel card transactions, factoring statements, ELD dwell and stop data, and lane and customer identifiers.

We ask you to send operational and financial records, not personnel records. Driver names, licence numbers, dates of birth, medical records, and similar personal identifiers are not required for the audit. Where your exports include them incidentally, we do not use them in the analysis, and we will pseudonymise or strip them on request.

Business contact data

Name, work email, phone number, company, and role — collected when you contact us, book an audit, or subscribe.

Payment data

Card and billing information is collected and processed entirely by Stripe. FleetVault never sees, stores, or has access to your full card number. We receive only a transaction record: amount, date, last four digits, and status.

Site data

Standard server logs (IP address, user agent, pages requested, timestamps) retained for security and troubleshooting.

What we do with it

DataPurposeLegal basis
Operating dataProduce your audit, recovery plan and ongoing Command monitoringPerformance of contract
Business contactRespond to enquiries, deliver reports, send service communicationsContract / legitimate interest
Payment recordsBilling, accounting, tax and audit obligationsLegal obligation
Server logsSecurity, abuse prevention, diagnosticsLegitimate interest

What we never do

We do not sell your data. We do not rent, licence or share it with data brokers, load boards, brokers, shippers, carriers, insurers, or your competitors. We do not use your rate data to advantage another client in a negotiation. We do not train third-party models on your data, and we do not upload identifiable client data into public AI tools.

Where we publish benchmarks or case figures, they are aggregated across multiple fleets and de-identified so that no individual client, lane, customer or rate is reconstructable.

Who else touches it

We keep the processor list short on purpose. As of the effective date above:

Each is bound by its own data protection terms. We do not add processors that receive identifiable client operating data without updating this page.

We may disclose data where required by law, court order, or lawful request by a competent authority. Where we are legally permitted to tell you, we will.

Where it lives and how it is protected

Data is stored on servers in Canada and the United States. Transfers are protected by contractual safeguards with each provider.

No system is perfect. If a breach affects your data, we will notify you without undue delay, and in any event within 72 hours of becoming aware, with what we know and what we are doing about it.

How long we keep it

CategoryRetention
Raw exports you sendDeleted 90 days after the engagement ends, or immediately on written request
Derived analysis & reportsRetained for the life of the engagement, then 12 months, then deleted
De-identified benchmarksRetained indefinitely — cannot be traced to a client
Invoices & tax recordsSeven years, as required by law
Business contact dataUntil you ask us to remove it

Your rights

You may ask us to give you a copy of the data we hold about you, correct it, delete it, restrict how we use it, export it in a portable format, or object to a particular use. If you are covered by Quebec's Law 25, PIPEDA, the GDPR, or a US state privacy law, those rights apply to you directly.

Write to nico@getfleetvault.com. We respond within 30 days. There is no charge. If you are unsatisfied with our answer, you may complain to your data protection authority — in Quebec, the Commission d'accès à l'information.

Cookies

This site uses only what it needs to function. We do not run advertising trackers, cross-site pixels, or third-party marketing cookies. Any analytics we run are configured without cross-site identifiers.

Children

FleetVault is a business service. It is not directed to anyone under 18 and we do not knowingly collect their data.

Changes

If we change this policy we will update the version and effective date above. Where a change materially affects how we handle client operating data, we will notify active clients by email before it takes effect.