Legal

Privacy policy

Last updated 7 August 2026

This website

no cookies
no analytics
no trackers

Two different things need explaining, and most privacy policies blur them: what this website does, and what the platform does with data our customers put into it.

1. This website

This site sets no cookies, runs no analytics, embeds no third-party scripts, and loads no fonts or images from anyone else's server. There is no tracking pixel and no advertising identifier. Nothing you do here is recorded against you.

Our hosting provider keeps standard server logs, which include IP addresses, for a short period for security and abuse prevention. We don't use them to build a profile of you.

If you email us, we keep that correspondence so we can answer it and follow up.

2. The platform: who controls what

When an organisation uses Optics Fleet, they decide what data to collect about their vehicles, drivers and delivery recipients. They are the data controller. We process it on their instructions, as the processor, to provide the service.

If you're a driver, or someone expecting a delivery, and you want to know what's held about you or have it corrected or erased, the organisation you're dealing with is who to ask. Contact us and we'll point you to them, but we can't change their records for them.

3. What the platform processes

Vehicle and device data
Position, speed, heading, ignition state, trip start and end, distance, and device diagnostics. Reported by the tracking device at the cadence the customer's plan sets, or by the driver's phone while they're on shift.
Driver data
Name, contact details, the vehicle assigned, the stops worked, and driving events such as harsh braking or speeding against a zone. Location while on shift.
Delivery recipient data
Name, delivery address, and where the customer has provided it, an email address for tracking and milestone notifications. Proof of delivery — photographs, signatures and notes captured at the door.
Account data
Names, work email addresses, roles and permissions of the people who use the console, plus authentication records and an audit log of actions taken.
Billing data
Company name, billing address, tax identifiers, plan and quantities, and metered usage. Card details are handled by our payment processor and are never stored on our systems.

4. Driver location — the part that deserves care

Tracking a person's vehicle is tracking a person. Employers using the platform are responsible for telling their drivers that vehicles are tracked, what is recorded, and why — and, where the law requires it, for obtaining consent. Several jurisdictions require exactly this.

The product is built so location is tied to work: the driver app reports while a driver is on shift, not around the clock. The plan's refresh cadence determines how often a vehicle device reports.

5. How long it's kept

Operational history — trips, positions, safety events, completed stops — is retained for the window the customer's plan provides: 30 days on Solo, 90 on Deliver and Track, 365 on Deliver Pro and Fleet, or a period agreed in writing on Enterprise terms. Older records age out.

Proof-of-delivery media is kept for the same window unless a longer period is agreed. Audit logs and records we need for accounting and tax are kept for as long as the law requires. When an account closes, we delete or anonymise customer data within 90 days, except where we must retain it.

One deliberate exception: when a driver is removed from an organisation, their account and access are disabled immediately, but the historical record of work they did — trips, deliveries, proof of delivery, safety events — is retained with their name recorded against it. Deleting it would falsify the customer's own delivery history.

6. Where it's processed

The platform runs on Amazon Web Services in [[DATA REGION]]. Where data moves between regions, we rely on the appropriate safeguards, including standard contractual clauses.

7. Who else touches it

We use a small number of providers to run the service: cloud infrastructure and storage, email delivery, cellular connectivity for the tracking devices, and a payment processor. Each processes data only to provide their part of the service, under contract. We don't sell data, and we don't share it for advertising.

We disclose data if the law compels us to, and we'll tell the affected customer unless we're prohibited from doing so.

8. Security

Data is encrypted in transit and at rest. Access within the platform is scoped to a single organisation and enforced on every request — an account cannot read another organisation's records. Internal access is limited to people who need it and is logged. Sessions are cookie-based, HTTP-only, and expire.

If a breach affects personal data, we notify affected customers without undue delay and within the periods the applicable law sets.

9. Your rights

Depending on where you are, you may have the right to access, correct, delete, restrict or port your personal data, to object to processing, and to complain to a supervisory authority. If your data is in a customer's account, ask that customer. For data we control — the account holders we contract with, and anyone who emails us — contact [[PRIVACY CONTACT EMAIL]].

10. Changes

If we change this policy materially, we'll update the date at the top and tell account holders by email before it takes effect.

11. Contact

[[LEGAL ENTITY NAME]]
[[BUSINESS ADDRESS]]
[[PRIVACY CONTACT EMAIL]]