Privacy Policy
Effective September 14, 2026
This policy explains what FleetLobby collects, why, who it is shared with, and what you can do about it. It covers fleetlobby.com and the application at app.fleetlobby.com.
1. Who is responsible
FleetLobby is the data controller for the personal data described in this policy. For any privacy question or request, use the support form.
2. What we collect
Account details. Your first and last name, email address, an optional phone number, and a securely hashed password. We never store your password in readable form.
The records you enter. Vehicles (make, model, year, VIN, licence plate and state, colour, platform tags, photos), income and expense entries, expense categories and allocations, receipts and other file attachments, reminders and to-dos, and your team members' accounts.
Connected mailbox data. If you choose to connect a mailbox, we store the mailbox provider, connected address, provider account identifier, granted permissions, encrypted access credentials, sync status, and the minimum identifiers needed to avoid importing the same message twice. We search for authenticated Turo messages used to create or update your trip records. During the temporary email-template discovery period, the text and HTML content of those Turo messages may be stored encrypted for up to 90 days to maintain import compatibility as Turo changes its emails. We do not retain unrelated mailbox content, attachments, or tracking images. A failed import may also retain an encrypted, sanitised text excerpt for up to 30 days so it can be corrected. FleetLobby's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Security and sign-in records. Each sign-in attempt is logged with the email used, whether it succeeded, the IP address, the browser user-agent string and the time. This protects accounts and the service from abuse.
Billing details. Your account may contain subscription-status fields, but FleetLobby does not currently charge accounts. If paid billing is introduced later, card details will be entered with our payment processor and will not be held by FleetLobby.
Technical data. Standard server logs needed to operate and secure the service.
Crash and error diagnostics. When the mobile app crashes or hits an error, it can send a diagnostic report containing the app version, device model, operating system version and the technical stack trace. These reports carry no account identifiers and no content from your records.
3. Why we use it
- To provide the service: storing your records, producing your dashboard and reports, and sending the reminder emails you set up.
- To manage your account: signing you in, resetting passwords, inviting team members, and sending service messages such as a welcome email.
- To import and update Turo trip records when an account owner chooses to connect a mailbox.
- To let an authorised support administrator review and correct failed Turo imports only when the account owner has enabled that access.
- To manage billing if paid plans are introduced and enabled later.
- To keep the service secure: detecting and investigating suspicious sign-ins and abuse.
- To meet legal, accounting and tax obligations.
We do not sell your data, we do not share it with advertisers, and we do not use your fleet or financial records to build advertising profiles.
4. Legal basis
Where the GDPR or similar law applies, we rely on: performance of a contract (running the service you signed up for), our legitimate interests (securing the service, preventing abuse), legal obligation (tax and accounting records), and consent where we ask for it, which you can withdraw at any time.
5. Who we share it with
We use a small number of processors, each handling only what their job requires and bound to protect it:
- Stripe: payment processing if paid billing is introduced and enabled later.
- Brevo: transactional email such as password resets, team invitations and reminder notifications.
- Google: OAuth account authorisation and Gmail access when you choose to connect a Google mailbox for Turo trip sync.
- Sentry: crash and error diagnostics (app version, device model, OS, stack traces; no account identifiers).
- Our hosting and database providers, and S3-compatible object storage for file attachments.
We may also disclose data where the law requires it, or to establish or defend legal claims. If the business is ever sold or merged, data may transfer to the buyer under this same policy.
6. Where your data is held
Data is stored with cloud hosting providers and may be processed outside your region. Where applicable law requires safeguards for an international transfer, those legal requirements apply.
7. How long we keep it
- Your account and the records you enter: for as long as your account is open, and for up to 90 days after you delete it, after which the deactivated data is erased and the account record anonymised automatically.
- Sign-in history: 90 days by default, then deleted automatically.
- Turo email template discovery: authenticated Turo email text and HTML may be kept encrypted for up to 90 days while this temporary compatibility program is enabled. Attachments and unrelated mailbox content are not retained.
- Successful mailbox imports: parsed trip records are kept with your account.
- Failed mailbox imports: an encrypted, sanitised text excerpt may be kept for up to 30 days. During the temporary template-discovery program, authorised support administrators may review retained Turo trip email HTML for up to 90 days when you enable support review access. Enabling access starts an idempotent historical Turo rescan, and every administrator view is recorded.
- Connected mailbox credentials: until you disconnect the mailbox or delete your account, then they are deleted and provider access is revoked where supported.
- Billing and tax records: for the period the law requires, typically several years after the transaction.
- Backups: deleted data may remain in routine backups until those backups are overwritten or deleted under the provider backup schedule.
8. Your rights
Subject to local law, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or provide it in a portable form. Much of this is available directly in the app: you can edit your profile, export your reports, and delete your account from your settings. You can also disconnect a mailbox and disable support review access at any time. Disconnecting stops future sync and deletes stored mailbox credentials and temporary email excerpts, but does not delete trip records already imported into your account. Deleting your account deactivates it immediately and signs you out on every device. Account data is then retained in deactivated form for up to 90 days for dispute resolution, fraud prevention and legal purposes, after which it is erased or anonymised automatically. You can ask us to erase it sooner by contacting support, and backups may persist for a limited period. Step-by-step instructions, and exactly what is erased, are on our Delete your account page.
To make a request, use the support form. We respond within the period the law allows, normally 30 days. If you are unhappy with our response, you may complain to your local data protection authority.
9. Security
Passwords are stored hashed, access to your records is scoped to your account and the team members you authorise, sessions use expiring tokens, and file attachments are served through short-lived private links. Connected mailbox credentials and retained failed-import excerpts are encrypted at rest. No system is perfectly secure, so please use a strong, unique password and tell us promptly if you suspect a problem.
10. Cookies and similar technology
The marketing site and the application use Google Analytics to measure visits and page views; it sets cookies to tell returning browsers apart and sends page addresses and technical data to Google. We use it only for aggregate usage statistics, not for advertising, and your fleet records are never sent to it. You can block it with a browser setting or extension. The application also stores what it needs to keep you signed in and to remember preferences such as your theme. See our Terms of Service for the wider agreement.
11. Children
FleetLobby is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child has given us data, contact us and we will delete it.
12. Changes to this policy
We will post any update here with a new effective date, and notify account owners by email where the change is material.