FleetPath360 Privacy Policy
Effective October 4, 2026
This policy explains how FleetPath360 ("we," "us" or "our") handles information when you use our fleet route and driver tracking app. It covers the app identified as com.fleetpath360.fleetpath360. For privacy questions or requests, contact support@northrootlawns.ca.
Information we collect
- Account information: your name, email address, Firebase account identifier, company membership, role and account status. Email and password are used through Firebase Authentication to create an account and sign in.
- Company and operational information: business names, route names, stop/property addresses and coordinates, notes, driver assignments, route runs, completion and skip records, timestamps and route history. This can include information entered by you or by an authorized member of your company.
- Location information: precise location, and approximate location when supplied by your device or reflected by the map area requested. Location records can include coordinates, accuracy, movement information, timestamps and the active assignment associated with the driver.
- App activity: operational actions such as completing or skipping a stop, and text submitted for address searches. Address-search requests are sent to the address service described below; they are not necessarily saved as a search-history list in FleetPath360.
- Technical identifiers: Firebase/Google services may process installation or app identifiers and authentication-related information. Firebase Authentication collects IP addresses for security and abuse prevention. Map and address services also receive the IP address and request information needed to serve their requests.
How we use information
We use information to create and manage accounts, authenticate users, associate users with the correct company, enforce access permissions, build and assign routes, find addresses, display maps, track active assignments, show dispatch and route progress, maintain operational history, process support and deletion requests, and protect the service against unauthorized access and abuse.
The current app does not display advertisements, sell personal information, or use personal information for advertising. It does not collect payment-card, financial or health information. It does not include Firebase Crashlytics or Firebase Performance Monitoring.
Active-route and background location
FleetPath360 collects and transmits driver location to enable live route and assignment tracking, including while the app runs in the background during an active tracking assignment. Authorized people in the driver's company, such as dispatch or company administrators, can see this information. Location data is sent to the app's Firebase backend and is associated with the driver and assignment.
You control location access through your device settings. Location permission is needed for live tracking. Denying or revoking it can prevent tracking features from working. Tracking begins for an active route, assistance or tag-in assignment and may resume while that assignment remains active. Ending the tracking assignment stops its ongoing updates. Previously stored operational records are handled under the retention and deletion section below.
Who receives information
- Your company: authorized company members receive the account, assignment, route and location information their role permits. FleetPath360 separates companies and applies company-based access controls. Your company is responsible for how its authorized people use or export information available to them.
- Firebase and Google: we use Firebase Authentication and Cloud Firestore for sign-in, account information and app data storage. These services process information to operate and secure the app. See Firebase privacy and security information and the Google Privacy Policy.
- Geoapify: text entered for address autocomplete is sent to Geoapify, which returns matching addresses and coordinates. Geoapify receives request information, including the query and IP address, and may retain technical request logs for its service operation, security and troubleshooting. See the Geoapify Privacy Policy.
- OpenStreetMap: maps load tiles from OpenStreetMap's servers. Tile requests disclose your IP address and the geographic areas being displayed, which can reflect driver or stop locations. OpenStreetMap Foundation operates as an independent data controller. See its services and tile users privacy information and Privacy Policy.
- External apps you choose: opening navigation in Google Maps passes the selected destination coordinates to that service. Opening an account-deletion email draft passes the draft's contents to your email app; you must send it to submit your request. These services apply their own privacy policies.
We may disclose information when required by law, to respond to a valid legal request, or when necessary to protect users and the service against fraud or security threats.
Security
Data transfers to Firebase and the map/address endpoints use encrypted connections. Authentication and company/role access controls limit access to app records. No storage or transmission method can guarantee absolute security. Keep your sign-in credentials private and use your company's authorized accounts.
Retention and deletion
Account and profile information remains while the account is maintained, unless removed through a verified deletion request. The current app has no general automatic expiry for route and operational history. Completed history can remain after a reusable route is deleted. These records support continuing company operations and are retained until applicable records are removed or account-linked personal information is removed through the deletion process.
You can request permanent deletion of your account and associated personal data at our account-deletion page, or from Account settings → Request account deletion in the app. Email support@northrootlawns.ca from the account email address with the subject FleetPath360 Account Deletion Request and your business name. Do not send your password. If you no longer have access to that email address, contact support for secure identity verification.
We verify account control and complete deletion within 30 days of receiving the request. The account remains active until processing is complete. We remove the sign-in account, profile, location records and personal identifiers in account-linked route/activity records. Shared business records may remain after the requester's personal information is removed. A request does not authorize deletion of another person's account or data. Business owners should indicate whether they want ownership transfer or authorized workspace closure, so we can coordinate this before removing the owner account.
If specific information must be retained for legal, security or fraud-prevention reasons, we identify the information, reason and retention period in our response. Such exceptions do not permit blanket retention of personal data in shared records. We confirm completion by email. Service providers may apply their own technical-log and backup retention processes; the linked provider policies explain their practices.
FleetPath360 does not currently provide a separate in-app request process for deleting all personal data while keeping the account active, and it does not promise automatic deletion of all user data within 90 days.
Your choices and requests
You can manage location permission in device settings, choose whether to use address-search and external-navigation features, and request account deletion as described above. Contact support for questions about access to or correction of your personal information. For company-managed route and work records, your company administrator can also help explain your company's use of those records.
Policy updates
We will update this page when our practices change and revise the effective date. Material changes will be communicated through the app or another appropriate channel.
Privacy contact: support@northrootlawns.ca