Legal
Privacy Policy
Effective date: 18 August 2026
FleetMan ("we", "us", or "our") operates the FleetMan platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you use the Service.
FleetMan is an Australian business. This Privacy Policy is governed by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). By accessing or using the Service you agree to the practices described here. If you do not agree, please do not use the Service.
1. About us (APP 1)
FleetMan is committed to managing personal information openly and transparently in accordance with the APPs. We maintain this policy to explain our information handling practices and make it freely available on our website.
Privacy Officer
For any privacy-related enquiries, requests, or complaints, contact our Privacy Officer:
- Email: contact.fleetman@gmail.com
- Response time: within 30 days of receipt
2. Whose information we handle, and in what capacity
Most personal information in the Service is not entered by the person it describes. A fleet operator ("Organisation") records details about its drivers, mechanics, and customers. Understanding who does what matters for knowing who to approach about your information.
- Account holders. The Organisation and its administrators contract with us directly. We handle their information as described throughout this policy.
- Drivers and mechanics. Their records are created and controlled by the Organisation. We host and process that information on the Organisation's behalf and on its instructions. The Organisation decides what is collected, how long it is kept, and who within its account may see it, and it is responsible for having a lawful basis to provide it to us.
- Members of the public. Where an Organisation embeds our public booking form on its own website, people who submit a booking request give their details to that Organisation. We receive and store those details on its behalf.
If you are a driver, mechanic, or booking customer and want to access, correct, or delete your information, contact the Organisation you deal with in the first instance — it controls the record. You may also contact our Privacy Officer, and we will assist or refer you to the relevant Organisation. Nothing in this section limits any right you have against us directly under the Privacy Act.
3. Information we collect (APPs 3 & 5)
We only collect personal information that is reasonably necessary for our functions. Where practicable, we collect personal information directly from the individual concerned; where an Organisation provides information about a third party, we rely on that Organisation to have given the required notice.
Information you provide
- Account registration data (name, email address, password hash)
- Organisation details (fleet name, ABN/ACN, address, billing information)
- Driver and mechanic profiles (name, date of birth, residential address, licence number and expiry, contact details)
- Vehicle and maintenance records, including registration and insurance expiry dates and inspection outcomes
- Ledger records — rent charges, payments, late fees, refunds, and security deposits
- Damage reports, inspection records, and odometer readings
- Booking requests submitted through an Organisation's public booking form (name, email, phone, pickup and drop-off locations, service type, vehicle capacity)
- Communications you send to our support team
Information collected automatically
- Log data: IP address, browser type, pages visited, timestamps
- Device information: operating system, screen resolution
- Usage and error events generated while operating the Service
- Session cookies required for authentication (see Section 9)
- IP address and a challenge token when you complete a bot-protection check on a public form
Payment card details are never collected by us. See Section 6.
Notice at collection (APP 5): At the time we collect personal information, or as soon as practicable afterwards, we will take reasonable steps to notify you of the matters set out in APP 5, including the purposes of collection, whether disclosure overseas is likely, and your rights of access and correction.
4. How we use your information (APP 6)
We use personal information only for the primary purpose for which it was collected, or for a directly related secondary purpose, or where you have otherwise consented. Specifically:
- Provide, operate, and improve the Service
- Generate charges, record payments, and apply the billing rules the Organisation configures
- Send transactional communications (invoices, payment reminders, work-order and document-expiry notifications)
- Route a card payment from a driver to their Organisation's own payment account, and record the result in the ledger
- Detect and prevent fraud, abuse, and security incidents, including automated checks on maintenance and parts records
- Protect public forms from automated abuse
- Respond to support requests and provide customer success
- Comply with applicable Australian laws and regulations
- Analyse aggregate, de-identified usage patterns to guide product development
We do not sell your personal information to third parties, we do not use it for automated decision-making that produces legal effects about you, and we do not use it for purposes unrelated to providing the Service without your consent.
5. Direct marketing (APP 7)
We may send you product updates, feature announcements, or promotional materials relating to the Service where you have consented or where we reasonably believe you would expect to receive such communications. All commercial electronic messages comply with the Spam Act 2003 (Cth) — they will clearly identify us as the sender and include a functional unsubscribe mechanism.
You may opt out of marketing communications at any time by clicking the unsubscribe link in any marketing email or by contacting us at contact.fleetman@gmail.com. Opting out of marketing does not affect transactional notifications required to deliver the Service.
We do not use driver, mechanic, or booking-customer contact details supplied by an Organisation to market to those individuals.
6. Payments and card data
Where an Organisation enables card payments, rent is paid by a driver directly to that Organisation. Payments are processed by Stripe Payments Australia Pty Ltd and its affiliates ("Stripe") into a Stripe account held by the Organisation in its own name.
- We never receive, process, or store card numbers, expiry dates, or security codes. Card details are entered into fields hosted by Stripe and are transmitted to Stripe directly.
- We store only non-sensitive references issued by Stripe — an identifier for the stored payment method, the card brand and last four digits, and the status of a payment.
- Funds are never held by FleetMan. They settle into the Organisation's account, and we do not deduct any commission or fee from a driver's rent payment.
- Stripe handles the payment as a data controller in its own right under its own privacy policy, including for fraud prevention and its legal obligations as a payment processor.
Refunds, chargebacks, and payment disputes are handled by the Organisation through its own Stripe account. See our Terms of Service for how responsibility for those payments is allocated.
7. How we share your information (APP 6)
We may disclose personal information to:
- Service providers — cloud hosting, database, email delivery, payment processing, and bot-protection providers who process data on our behalf under terms that require them to protect your information and use it only to provide services to us. The specific providers are named in Section 8.
- Within your organisation — admin users of an Organisation's FleetMan account can view data for all drivers, mechanics, vehicles, and customers in that account. Drivers see only their own records; mechanics see only work assigned to them.
- Between organisations, in one limited case — an independent mechanic may accept work from more than one Organisation. Such a mechanic sees only the vehicles and work orders assigned to them by each Organisation.
- Legal obligations — if required by Australian law, a court order, or a request from a government agency with lawful authority (e.g. the Australian Federal Police, an Australian court, or a regulatory body).
- Business transfers — in connection with a merger, acquisition, or sale of assets, with prior notice to you.
We do not disclose personal information beyond these purposes without your consent.
8. Cross-border disclosure (APP 8)
Some of our service providers are located outside Australia. By using the Service, you acknowledge that personal information may be transferred to, stored, or processed in countries including the United States of America, the European Union, and other countries in which these providers operate infrastructure.
Our overseas recipients are:
- Vercel (application hosting) — serves the application. Our production compute region is Sydney, Australia; supporting infrastructure and logs may be processed in the United States.
- Neon (database hosting) — servers located in AWS regions. Neon complies with SOC 2 Type II and applies encryption at rest and in transit.
- Stripe (payment processing) — payment data is processed in the United States and other countries where Stripe operates. Stripe is PCI DSS Level 1 certified.
- Resend (transactional email) — email delivery infrastructure located in the United States.
- Cloudflare (bot protection) — processes the IP address and challenge response of visitors to our public forms, on a globally distributed network.
Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure the recipient does not breach the APPs in relation to that information (APP 8.1). Where we are unable to ensure this, we will obtain your consent before disclosure or otherwise comply with our obligations under APP 8.
9. Cookies and tracking (APP 3)
We use strictly necessary cookies to maintain your authenticated session. These cookies are essential to operate the Service and cannot be disabled without preventing login. Our bot-protection provider may set a short-lived token when you submit a public form. We do not use third-party advertising cookies, behavioural tracking, or cross-site profiling, and we do not run third-party analytics scripts on the Service.
10. Data quality and security (APPs 10 & 11)
We take reasonable steps to ensure personal information we hold is accurate, up-to-date, complete, and relevant (APP 10). We implement industry-standard safeguards to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure (APP 11), including:
- TLS encryption in transit (HTTPS)
- Encryption at rest for stored data
- Salted password hashing; we never store passwords in a recoverable form
- Row-level security (RLS) policies enforced in the database, isolating each Organisation's data
- Role-based access controls (Admin, Driver, Mechanic) enforced on every request, not only in the interface
- Bot protection and rate limiting on public and authentication endpoints
- Regular security audits and monitoring
No method of transmission over the internet is 100% secure. We cannot guarantee absolute security, but we are committed to continuous improvement and will act promptly if a security incident occurs.
11. Notifiable Data Breaches (NDB scheme)
We comply with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth). If we become aware of an eligible data breach — one that is likely to result in serious harm to any individual whose information is involved — we will:
- Contain the breach and assess whether it is likely to result in serious harm
- Notify the Office of the Australian Information Commissioner (OAIC) as soon as practicable (and within 30 days of becoming aware)
- Notify affected individuals directly, or publish a notification on our website if direct notification is not reasonably practicable
- Notify the affected Organisation without undue delay where the breach concerns information we hold on its behalf, so it can meet its own notification obligations
- Provide recommendations on steps you can take to protect yourself
12. Data retention (APP 11)
We retain personal information for as long as an account is active and as required to fulfil the purposes described in this policy, or as required by Australian law (e.g. financial records under the Corporations Act 2001 (Cth) and taxation law).
Archived drivers are retained, not deleted. When an Organisation retires a driver, that driver's login is revoked but their ledger, deposits, damage reports, and vehicle assignment history are kept. This is deliberate: an infringement notice or an insurance query can arrive long after a driver has left, and the Organisation needs to be able to establish who held which vehicle on a given date. An Organisation may request erasure of an archived driver where it is not required to retain the record.
If an account is closed, we retain data for 90 days to allow recovery, after which it is deleted from production systems within 30 days. Backups are purged on a rolling 12-month cycle. You may request earlier deletion at any time (see Section 13).
13. Your rights (APPs 12 & 13)
Under the Privacy Act 1988 (Cth) and the APPs, you have the following rights:
- Access (APP 12) — request access to the personal information we hold about you. We will respond within 30 days.
- Correction (APP 13) — request that we correct personal information that is inaccurate, out-of-date, incomplete, irrelevant, or misleading.
- Deletion — request deletion of your personal information where we no longer need it to provide the Service and are not required to retain it by law.
- Anonymity (APP 2) — where lawful and practicable, you may interact with us anonymously or using a pseudonym.
- Opt out of direct marketing (APP 7) — as described in Section 5.
To exercise any of these rights, contact our Privacy Officer at contact.fleetman@gmail.com. We will respond within 30 days. We may ask you to verify your identity before processing a request. We do not charge a fee for access requests unless the request is complex or voluminous, in which case we will notify you of the estimated fee before proceeding.
Where the information is held on an Organisation's behalf (see Section 2), we will direct your request to that Organisation and confirm to you that we have done so.
14. Complaints
If you believe we have breached the APPs or otherwise mishandled your personal information, you may lodge a complaint with us first:
- Email: contact.fleetman@gmail.com
- We will acknowledge your complaint within 5 business days and provide a substantive response within 30 days.
If you are not satisfied with our response, you may refer your complaint to the Office of the Australian Information Commissioner (OAIC):
- Website: www.oaic.gov.au
- Phone: 1300 363 992
- GPO Box 5218, Sydney NSW 2001
15. Children
The Service is intended for use by businesses and is not directed to individuals under 18. We do not knowingly collect personal information from persons under 18. If you believe a person under 18 has provided us personal information without appropriate authority, please contact us and we will delete it promptly.
16. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we do, we will update the effective date at the top. For material changes, we will notify account administrators by email at least 14 days before the changes take effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
17. Contact
Questions about this Privacy Policy or our privacy practices? Contact our Privacy Officer:
- Email: contact.fleetman@gmail.com