Data Protection
The practical detail behind the privacy policy: where data sits, who can reach it, how long it stays and what happens if something goes wrong.
This document is a working draft prepared for VouchTrack’s website. It should be reviewed by your own legal counsel and adjusted to match how your systems actually operate before you rely on it. Sections marked [confirm] need a decision from you.
1. Our principles
- Collect what the service needs. We do not gather data because it might be interesting later.
- Your data is yours. Exportable at any time, in a standard format, including on the way out.
- Least privilege. Users and our own staff see only what their role requires.
- Log the consequential actions. Anything that affects a vehicle is attributable to a person.
2. Data in transit
Traffic between the tracking device and our servers is encrypted. Traffic between our servers and your browser or mobile app runs over TLS. Nothing sensitive is transmitted in the clear.
3. Data at rest
Databases are encrypted at rest, backups are encrypted, and passwords are stored as salted hashes rather than recoverable values — meaning we cannot tell you your password, only help you reset it.
[confirm — state where servers are physically hosted, and whether any data leaves Pakistan]
4. Access control
- Role-based permissions: owners, managers, dispatchers and client users each see a defined slice.
- Sensitive commands — most importantly engine immobilisation — are restricted to roles you nominate.
- Every such command is written to an audit log with the user, the vehicle, the time and the outcome.
- Our support staff access customer accounts only when required to resolve a request, and that access is logged.
5. Retention and deletion
| Data | Kept for |
|---|---|
| Position and trip history | 12 months as standard; extended on request [confirm] |
| Alert and event records | Same as trip history |
| Command audit log | Retained for the life of the account |
| Account and billing records | Duration of the relationship plus statutory accounting period |
| Website enquiries | Until the enquiry is closed, then archived |
| Backups | Rolling window, overwritten on cycle [confirm the window] |
On termination we provide a full export on request and then delete operational data on the agreed schedule, except where law requires us to keep it.
6. Sub-processors
We use third parties to deliver parts of the service. Each is engaged under contract and only for the purpose stated.
| Purpose | Provider |
|---|---|
| Server hosting | [confirm] |
| Mobile connectivity (SIM) | [confirm — the operators your multi-network SIM roams across] |
| SMS alert delivery | [confirm] |
| Map tiles and geocoding | [confirm] |
| Push notifications | Apple Push Notification service, Firebase Cloud Messaging |
| Website analytics | As configured — see cookies |
7. Driver data specifically
Where an RFID reader is fitted, trips are attributed to a named driver. That is personal data about your employee, and using it fairly is your responsibility as their employer. We recommend:
- Telling drivers in writing what is recorded and how it will be used, before installation.
- Using behaviour scores for coaching and incentives, not solely for discipline.
- Restricting who in your organisation can see individual driver data.
- Not tracking outside working hours where a vehicle is also used privately — ask us and we can configure private-mode reporting.
8. If something goes wrong
If we become aware of a security incident affecting your data, we will contain it, investigate, and notify affected customers promptly with what we know, what is affected and what we are doing. We would rather tell you early with partial information than late with a complete story.
9. Contact
Questions about data protection, or a request relating to data we hold, should go to [email protected], marked for the attention of the data protection contact. [confirm — name an individual or role responsible]
Last updated: 08 August 2026