Privacy Policy

Effective Date: 2026-08-21

1. Who we are

This Privacy Policy describes how Rodigan Labs Ltd. doing business as Fleetr (“Fleetr,” “we,” “us,” or “our”) collects, uses, and protects personal information.

Privacy Officer
Rodigan Labs Ltd. o/a Fleetr
Victoria, British Columbia, Canada
jordan@fleetr.ca

2. Scope

This policy applies to visitors of fleetr.ca, people who request a demo, and users of the Fleetr platform, including insurance brokers and administrative users. It covers personal information under our custody or control, including information processed on behalf of a Customer (a brokerage) when that Customer uses the service.

3. Applicable privacy law

Rodigan Labs Ltd. is a private-sector organization in British Columbia. Our privacy practices are designed around:

  • British Columbia’s Personal Information Protection Act (PIPA) — generally applicable to Fleetr as a BC private organization.
  • PIPEDA — where federal private-sector privacy law applies to a particular activity.
  • FIPPA — the statute that governs public bodies such as ICBC and may impose requirements on parties handling personal information within the custody or control of a public body, including service providers. Fleetr does not currently represent itself as an ICBC service provider, and any requirements applicable to a future relationship with ICBC would be addressed under the governing agreement.

4. Information we collect

We collect different categories of information for different purposes:

Website and demo information

When you request a demo, we collect your name, work email, and brokerage name. You may optionally tell us your approximate monthly transaction volume. If we follow up, we may also collect additional details such as job title and telephone number.

Account information

For users of the platform: name, email, agency assignment, role and permissions, authentication data (including password hashes and multi-factor authentication records), and related account settings.

Customer Data

Fleetr may process personal information contained in insurance documents and records submitted by authorized brokerage users. That can include customer identification, addresses, policy information, vehicle information (including VINs), licence information, signatures, transaction information, broker or agent information, and other insurance-related details that appear in uploaded files. Where that information originated with ICBC, the Customer remains responsible for its obligations to ICBC. Fleetr currently processes that information on behalf of the Customer and does not represent itself as an ICBC service provider.

Separately, Fleetr may extract and retain certain client-directory fields that a brokerage stores in the application, such as client name, address, and fleet number. Those directory fields are encrypted at rest. Uploaded source PDFs and generated outputs are encrypted in transit and at rest while they are processed, then removed as described in section 9.

Receiving a document is not the same as extracting or keeping every field in it. We describe both so it is clear what Fleetr may see and what it actually retains.

Technical and security data

We may collect IP addresses, login and access activity, and similar technical records needed to operate, secure, and audit the service.

5. Lawful authority

Customers are responsible for ensuring they have lawful authority to provide information to Fleetr. Fleetr processes Customer Data only to provide the contracted services, in accordance with the Customer’s instructions, applicable law, and applicable contractual restrictions.

We do not rely on a blanket statement that every individual has given express consent. PIPA and related privacy rules recognize more than one lawful basis for handling personal information, including processing on behalf of another organization for the original purpose in appropriate circumstances. Individual consent also does not necessarily override a confidentiality or contractual restriction that applies to the Customer.

6. How we use information

  • Providing document processing and workflow automation to the Customer
  • Creating and administering accounts, agencies, and permissions
  • Responding to demo requests and support inquiries
  • Billing, invoicing, and usage accounting
  • Security, troubleshooting, and internal auditing
  • Meeting legal obligations

We do not use personal information for marketing or analytics unrelated to these purposes.

7. Service providers

Fleetr uses carefully selected service providers to operate the service. Those providers receive only the information necessary to perform their functions and are subject to appropriate confidentiality and data-protection obligations. Material categories today include:

  • Infrastructure hosting: production application and database hosting on DigitalOcean in Canada.
  • Email delivery: demo requests, account notices, and similar operational messages. Email delivery may involve processing outside Canada. Uploaded insurance documents and generated outputs are not sent through this email path.

We may also disclose information if required by law, necessary to protect the security or integrity of the service, or otherwise authorized by the Customer.

For a current description of these providers, contact the Privacy Officer at jordan@fleetr.ca.

8. Storage, residency, and safeguards

  • Production application and database data are hosted on Canadian-based DigitalOcean infrastructure.
  • Production application, database and uploaded insurance-document processing occur on Canadian infrastructure. Limited business-contact and operational email information may be processed outside Canada; uploaded insurance documents are not sent through that email service.
  • Sensitive client-directory fields are encrypted at rest (AES-256).
  • Passwords are hashed using PBKDF2-SHA256 and are not stored in plain text.
  • Access is agency-scoped and governed by role-based permissions.
  • Uploaded and generated insurance documents are encrypted in transit and at rest while temporarily processed and are deleted upon download where possible, or within approximately 30 minutes.
  • The production service is provided over HTTPS. Session cookies are marked Secure, HttpOnly, and SameSite=Lax in production.

Further detail is on our Security & Trust page. Fleetr does not currently hold SOC 2 or ISO 27001 certification.

9. Retention

We keep different categories of data for different periods:

Data Typical retention
Uploaded source documents and generated outputs Until you download them, or about 30 minutes, whichever comes first
Client directory entries, stamps, and signatures Until removed by your agency
Account records Duration of the account, then as needed to close the account securely
Website and demo requests As needed to respond and for related operations
Billing, usage, and audit records As required for operations, accounting, security, and legal obligations

Individuals may contact their broker or Fleetr’s Privacy Officer to request access to, correction of, or deletion of personal information, as described in section 10.

10. Access and correction

Individuals may contact their broker or Fleetr’s Privacy Officer to request access to or correction of personal information. Where Fleetr processes the information on behalf of a brokerage Customer, Fleetr may coordinate the request with that Customer as appropriate.

11. Privacy incidents

Fleetr maintains an incident-response process. We investigate suspected privacy or security incidents, promptly inform affected Customers as required by contract, and notify regulators and individuals where legally required.

If you believe a privacy incident involving Fleetr has occurred, contact the Privacy Officer at jordan@fleetr.ca.

12. Changes

We may update this Privacy Policy from time to time. The effective date at the top of this page will change when we do. Material changes will be communicated via email or within the app where appropriate.

13. Contact

Privacy Officer
Rodigan Labs Ltd. o/a Fleetr
Victoria, British Columbia, Canada
jordan@fleetr.ca