Introduction
This Privacy Policy (hereinafter, the “Policy”) explains how Route Watch (hereinafter, the “Company”, “we”, “us”, “our”) collects, uses, stores and protects personal information when you use our website, GPS‑monitoring hardware and other related online services (collectively, the “Service”).
By using the Service, you confirm that you have read and agree to the terms of this Policy. For additional clarification, please contact us via the contact page on our website.
Definitions
- Client / User – a legal entity or individual who has signed an agreement with the Company and uses the Service to manage a vehicle fleet.
- Equipment – GPS trackers, OBD‑II devices and other devices offered by the Company to enable data collection.
- Personal data – any information that directly or indirectly relates to an identified or identifiable natural person.
What data we collect
The scope and nature of the data collected depend on how you use the Service. We may collect the following categories of personal data:
1. Registration and contact data
- name, surname and/or company name;
- contact details (email, telephone number, postal address);
- details for delivering equipment;
- billing and payment information.
These data are required to create an account, conclude and perform the contract and communicate with the Client.
2. Vehicle and technical data
- vehicle identification data (make, model, registration number, VIN — if required);
- data from GPS trackers: coordinates, speed, direction, trip route, start and end times;
- data from OBD‑II or other sensors: diagnostic trouble codes (DTC), engine revolutions, temperature, fuel level, battery voltage, etc.;
- other telematics parameters that allow analysis of vehicle condition and driving style.
3. Technical and login data
When you interact with our website or applications, we automatically receive certain information:
- IP address, device, browser and operating system data;
- session time and duration, page navigation routes, interaction with buttons and forms (information about your interaction with the website);
- information about cookies and other identifiers.
We use cookies and similar technologies (web‑beacons, pixels) to improve the website, personalise the interface, analyse traffic and determine the effectiveness of marketing campaigns. Google Analytics or similar systems may collect information about your use of our site as described in Google’s policy. You can refuse cookies by changing your browser settings, but in this case some functions of the Service may not work correctly.
4. Data from third‑party sources
- Payment data are processed by a payment processor (for example, Stripe). We receive only partial transaction information (payment ID, amount, status).
- Data for sending SMS messages are transmitted to the communications provider (for example, Twilio). This may include your phone number and the content of service messages.
- Where necessary, we may receive data from logistics companies (for equipment delivery) or equipment suppliers.
- If you log in to our site through third‑party authentication services (OAuth), we may receive from them the basic information you have permitted to transfer.
Data received from third parties are used only to provide the Service and are subject to this Policy.
Legal bases for processing data
We have lawful grounds for collecting and processing personal data. Under data protection law, there are several possible grounds for processing, of which we use the following:
- Performance of a contract – when processing is necessary for concluding or performing a contract between you and the Company. For example, we process your contact and telematics data to provide GPS‑monitoring services, issue invoices, support your account and ensure that the equipment functions properly.
- Legitimate interest – when processing is required for our legitimate interests, such as improving the Service, usage analytics, fraud prevention or ensuring security, and these interests do not override your rights and freedoms. We perform a balancing test to ensure that our aims are justified and proportionate.
- Compliance with legal obligations – when the law obliges us to process or store certain data, for example, to maintain accounting records, fulfil tax or other regulatory requirements, or respond to lawful requests from public authorities.
- Consent – when we ask for your explicit consent for certain purposes, such as marketing newsletters or the use of optional cookies. Providing consent is voluntary, and you may withdraw it at any time; withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
In exceptional cases, we may rely on other bases provided by the GDPR (for example, protecting vital interests or performing a task in the public interest), but such situations are unlikely for our Service. We will not process data if we do not have a lawful basis.
How we use data
We use the collected data solely for the purposes stated in this Policy, in particular:
- Providing and maintaining the Service – creating and managing an account, deploying software, tracking vehicles, monitoring routes and technical condition, sending notifications, generating reports and analytics.
- Processing orders and payments – selling and delivering equipment, renewing subscriptions, issuing invoices, processing payments through the payment processor.
- Communicating with the Client – sending service messages (event alerts, tariff changes, important updates), responding to support requests and sending informational newsletters.
- Marketing and promotional offers – with your consent, we may send information about new features, promotions and partner offers and analyse the effectiveness of such messages. You can opt out of marketing emails at any time.
- Analytics and improvement – analysing use of the Service, testing new features, identifying and fixing errors, optimising the interface.
- Ensuring security and preventing fraud – detecting suspicious activity, protecting account access, preventing unauthorised use of devices and data.
- Compliance with the law and protection of rights – responding to lawful requests from public authorities, courts or other competent bodies, and protecting our rights or those of Clients, for example in case of claims or disputes.
International data transfers
The Service’s servers are located in the European Union (AWS Frankfurt region). Because we provide services to international clients, data may be transferred between countries. Where such transfers occur, we ensure an adequate level of protection by using standard contractual clauses or other mechanisms permitted by law. By using the Service, you acknowledge that your information may be transferred and processed outside your country of residence.
Data retention
We retain data only for as long as necessary to fulfil the purposes described in this Policy or as required by law. Approximate terms:
- GPS and telematics data: 6 months for the Base plan, 12 months for Pro, unlimited for Enterprise (after the term ends, data may be deleted or anonymised).
- Account and contact data: retained for the entire period of your account’s existence. You can update or delete these data via the “Delete account” function in the administration panel. In case of deletion, we anonymise or delete data unless we are required to retain them longer by law.
- Payment data: the Company does not store bank card numbers; these data are processed by the payment processor. We may retain transaction information (date, amount, status) for financial reporting.
- Cookies and analytics data: according to cookie settings and the policy of the relevant analytics service.
After the specified periods expire, the data are deleted, anonymised or blocked, except when the law requires longer storage.
Data security
We implement technical and organisational measures to protect personal information from unauthorised access, alteration, loss or destruction. These include:
- encryption of data during transmission (HTTPS, TLS);
- access control and authentication;
- separation of data between clients;
- regular security monitoring and system updates;
- supplier audits.
Despite our efforts, no method of transmission or storage of data can guarantee absolute security. If you suspect a security breach, please notify us immediately.
Data subject rights
Depending on the applicable law (for example, the Ukrainian Law “On Personal Data Protection”, the GDPR or others), you may have the following rights:
- Right of access – to obtain confirmation of whether your data are being processed and to receive a copy of them.
- Right to rectification – to correct inaccurate or incomplete personal data.
- Right to erasure – in certain circumstances to request deletion of your data (the “right to be forgotten”).
- Right to restrict processing – to temporarily restrict the use of data.
- Right to data portability – to receive your data in a structured format for transfer to another service provider.
- Right to object – to contest processing if it is based on legitimate interest.
- Right to withdraw consent – to withdraw consent to processing (for example, for marketing mailings).
- Right to lodge a complaint – to contact a competent data protection authority if your rights are violated.
To exercise your rights, you can submit a request using the contact details provided on our website. We may require confirmation of your identity and may refuse to comply with the request where permitted by law (for example, when deletion conflicts with an obligation to retain data).
Important: users may modify and update only those personal data that they provide during registration (name, email, contact information, etc.). Telematics data, GPS records and diagnostic readings are factual records of the movement and technical state of vehicles; these data are presented for information purposes and cannot be edited. You may view and export them, but modification or deletion is possible only within the retention period.
Use of the Service by minors
The Service does not include a specific age restriction; however, its use requires the ability to enter into a contract and accept the terms of this Policy. If a user has not reached the age of majority under the law of their country, they should use the Service with the consent and under the supervision of parents or legal guardians. If you become aware that a minor has provided us with their data without such consent, please let us know and we will take steps to delete them.
Changes to the Policy
We may update this Policy from time to time to reflect changes in legislation, technology or our activities. The updated version will be published on our website with a new date. We recommend reviewing the Policy periodically. By continuing to use the Service after changes take effect, you agree to the new version.