FleetHelm

Privacy Policy

Back to sign in

Last updated: September 2, 2026

This Privacy Policy explains how FleetHelm ("we", "us") collects, uses, and protects information when a company ("Customer", "you") and its employees use the FleetHelm application (the "Service"), and how end customers of a Customer's rental business are affected when their data is entered into the Service.

1. Overview

FleetHelm is a business-to-business tool: rental companies use it to manage their own fleet, customers, contracts, and invoices. In most cases, the rental company is the "data controller" for its customers' and drivers' personal data, and FleetHelm acts as a "data processor" that stores and processes that data on the company's behalf.

2. Data we collect

Account & company data

  • Name, email, phone, and password (hashed) for each user.
  • Company name, address, tax ID, and logo.
  • Subscription and billing status (handled by Stripe — we do not store full card numbers).

Data you enter about your business

  • Fleet/asset records (vehicles, documents, photos).
  • Customer and driver records (name, contact details, license/ID documents where uploaded).
  • Rental, contract, signature, invoice, and payment records.
  • Optional integrations you connect (e.g. your Stripe account for rental payments, Google/Microsoft calendar sync, API keys for your booking website).

Technical data

  • Login activity, IP address, and basic device/browser information for security and rate-limiting.
  • Error and performance diagnostics via Sentry when something goes wrong.

3. How we use data

  • To provide the Service: authentication, storing your records, generating contracts/invoices, sending emails you trigger (invites, invoices, contracts, rental reminders).
  • To process subscription payments and manage your plan.
  • To secure the Service: detect abuse, enforce rate limits, and investigate incidents.
  • To provide support when you contact us.
  • We do not sell personal data, and we do not use your Customer Data to train third-party AI models.

4. Third parties we use

We rely on the following sub-processors to run the Service. Each only receives the data it needs to perform its function:

  • Supabase — database, authentication, and file storage.
  • Stripe — subscription billing, and (if enabled) rental/deposit payments processed through your own connected Stripe account.
  • Mailgun — delivery of transactional emails (invites, invoices, contracts, reminders).
  • Sentry — error monitoring to help us fix bugs quickly.
  • Google / Microsoft — only if you choose to sign in with, or sync your calendar to, one of these providers.
  • Vercel — application hosting.

5. Google user data

FleetHelm offers "Sign in with Google" as an optional way to create and access your account, and an optional Google Calendar sync for rentals. This section describes, specifically, how we handle data obtained through your Google Account when you choose to use these features.

What we request and receive

  • Sign in with Google: your name, email address, and profile picture, so we can create and authenticate your FleetHelm account. We do not request access to your contacts, Drive, Gmail, or any other Google data for sign-in.
  • Google Calendar sync (optional, separate consent): if you explicitly connect a calendar under Settings → Integrations, we request calendar read/write access solely to create, update, and remove events that mirror your rental bookings.

How we use, store, and share this data

  • Google Account data is used exclusively to operate the features described above — account authentication and, if enabled, calendar sync. It is never used for advertising, profiling, or resale.
  • We do not share Google user data with any third party except Supabase, which stores your account record on our behalf as our authentication database and infrastructure provider under a data processing agreement, strictly to run the Service.
  • We do not use Google user data to train AI/ML models, general or otherwise.
  • Google Calendar access tokens are stored encrypted at rest and are used only for the sync you configured. You can disconnect Google Calendar at any time from Settings → Integrations, which revokes our stored access token.
  • You can revoke FleetHelm's access to your Google Account entirely at any time via your Google Account permissions page.

FleetHelm's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

6. Storage & security

  • Data is stored in Supabase with row-level security so each company can only access its own records.
  • Passwords are hashed and never stored in plain text.
  • Traffic to the Service is encrypted with HTTPS/TLS.
  • Access to production data is limited to what is necessary to operate and support the Service.

7. Data retention & deletion

We retain Customer Data for as long as your account is active. If you cancel your subscription, data is retained for a limited grace period in case you resubscribe or need an export, after which it may be deleted. You can request deletion of your company's account and associated data at any time by contacting support@getfleethelm.com.

8. Your rights

Depending on where you're located, you may have the right to access, correct, export, or delete personal data we hold about you, and to object to certain processing. To exercise these rights, contact support@getfleethelm.com.

If your data was entered into the Service by a rental company you rented from (e.g. as a customer or driver), please contact that company directly first, since they control what data is stored about you; we will assist them in fulfilling your request.

9. Cookies & sessions

We use strictly necessary cookies to keep you signed in and to protect against cross-site request forgery. We do not use third-party advertising or tracking cookies.

10. Children

The Service is intended for business use by adults and is not directed at children under 16. We do not knowingly collect personal data from children.

11. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email or an in-app notice. See our Terms of Service for the terms governing use of the Service generally.

12. Contact

Questions about this Privacy Policy or how your data is handled can be sent to support@getfleethelm.com.