1. Who we are
This Privacy Policy describes how Rodigan Labs Ltd. doing business as Fleetr (“Fleetr,” “we,” “us,” or “our”) collects, uses, and protects personal information.
Privacy Officer
Rodigan Labs Ltd. o/a Fleetr
Victoria, British Columbia, Canada
jordan@fleetr.ca
2. Scope
This policy applies to visitors of fleetr.ca, people who request a demo, and users of the Fleetr platform, including insurance brokers and administrative users. It covers personal information under our custody or control, including information processed on behalf of a Customer (a brokerage) when that Customer uses the service.
3. Applicable privacy law
Rodigan Labs Ltd. is a private-sector organization in British Columbia. Our privacy practices are designed around:
- British Columbia’s Personal Information Protection Act (PIPA) — generally applicable to Fleetr as a BC private organization.
- PIPEDA — where federal private-sector privacy law applies to a particular activity.
- FIPPA — the statute that governs public bodies such as ICBC and may impose requirements on parties handling personal information within the custody or control of a public body, including service providers. Fleetr does not currently represent itself as an ICBC service provider, and any requirements applicable to a future relationship with ICBC would be addressed under the governing agreement.
4. Information we collect
We collect different categories of information for different purposes:
Website and demo information
When you request a demo, we collect your name, work email, and brokerage name. You may optionally tell us your approximate monthly transaction volume. If we follow up, we may also collect additional details such as job title and telephone number.
Account information
For users of the platform: name, email, agency assignment, role and permissions, authentication data (including password hashes and multi-factor authentication records), and related account settings.
Customer Data
Fleetr may process personal information contained in insurance documents and records submitted by authorized brokerage users. That can include customer identification, addresses, policy information, vehicle information (including VINs), licence information, signatures, transaction information, broker or agent information, and other insurance-related details that appear in uploaded files. Where that information originated with ICBC, the Customer remains responsible for its obligations to ICBC. Fleetr currently processes that information on behalf of the Customer and does not represent itself as an ICBC service provider.
Separately, Fleetr may extract and retain certain client-directory fields that a brokerage stores in the application, such as client name, address, and fleet number. Those directory fields are encrypted at rest. Uploaded source PDFs and generated outputs are encrypted in transit and at rest while they are processed, then removed as described in section 9.
Receiving a document is not the same as extracting or keeping every field in it. We describe both so it is clear what Fleetr may see and what it actually retains.
Technical and security data
We may collect IP addresses, login and access activity, and similar technical records needed to operate, secure, and audit the service.
5. Lawful authority
Customers are responsible for ensuring they have lawful authority to provide information to Fleetr. Fleetr processes Customer Data only to provide the contracted services, in accordance with the Customer’s instructions, applicable law, and applicable contractual restrictions.
We do not rely on a blanket statement that every individual has given express consent. PIPA and related privacy rules recognize more than one lawful basis for handling personal information, including processing on behalf of another organization for the original purpose in appropriate circumstances. Individual consent also does not necessarily override a confidentiality or contractual restriction that applies to the Customer.
6. How we use information
- Providing document processing and workflow automation to the Customer
- Creating and administering accounts, agencies, and permissions
- Responding to demo requests and support inquiries
- Billing, invoicing, and usage accounting
- Security, troubleshooting, and internal auditing
- Meeting legal obligations
We do not use personal information for marketing or analytics unrelated to these purposes.
7. Service providers
Fleetr uses carefully selected service providers to operate the service. Those providers receive only the information necessary to perform their functions and are subject to appropriate confidentiality and data-protection obligations. Material categories today include:
- Infrastructure hosting: production application and database hosting on DigitalOcean in Canada.
- Email delivery: demo requests, account notices, and similar operational messages. Email delivery may involve processing outside Canada. Uploaded insurance documents and generated outputs are not sent through this email path.
We may also disclose information if required by law, necessary to protect the security or integrity of the service, or otherwise authorized by the Customer.
For a current description of these providers, contact the Privacy Officer at jordan@fleetr.ca.
8. Storage, residency, and safeguards
- Production application and database data are hosted on Canadian-based DigitalOcean infrastructure.
- Production application, database and uploaded insurance-document processing occur on Canadian infrastructure. Limited business-contact and operational email information may be processed outside Canada; uploaded insurance documents are not sent through that email service.
- Sensitive client-directory fields are encrypted at rest (AES-256).
- Passwords are hashed using PBKDF2-SHA256 and are not stored in plain text.
- Access is agency-scoped and governed by role-based permissions.
- Uploaded and generated insurance documents are encrypted in transit and at rest while temporarily processed and are deleted upon download where possible, or within approximately 30 minutes.
- The production service is provided over HTTPS. Session cookies are marked Secure, HttpOnly, and SameSite=Lax in production.
Further detail is on our Security & Trust page. Fleetr does not currently hold SOC 2 or ISO 27001 certification.
9. Retention
We keep different categories of data for different periods:
| Data | Typical retention |
|---|---|
| Uploaded source documents and generated outputs | Until you download them, or about 30 minutes, whichever comes first |
| Client directory entries, stamps, and signatures | Until removed by your agency |
| Account records | Duration of the account, then as needed to close the account securely |
| Website and demo requests | As needed to respond and for related operations |
| Billing, usage, and audit records | As required for operations, accounting, security, and legal obligations |
Individuals may contact their broker or Fleetr’s Privacy Officer to request access to, correction of, or deletion of personal information, as described in section 10.
10. Access and correction
Individuals may contact their broker or Fleetr’s Privacy Officer to request access to or correction of personal information. Where Fleetr processes the information on behalf of a brokerage Customer, Fleetr may coordinate the request with that Customer as appropriate.
11. Privacy incidents
Fleetr maintains an incident-response process. We investigate suspected privacy or security incidents, promptly inform affected Customers as required by contract, and notify regulators and individuals where legally required.
If you believe a privacy incident involving Fleetr has occurred, contact the Privacy Officer at jordan@fleetr.ca.
12. Changes
We may update this Privacy Policy from time to time. The effective date at the top of this page will change when we do. Material changes will be communicated via email or within the app where appropriate.
13. Contact
Privacy Officer
Rodigan Labs Ltd. o/a Fleetr
Victoria, British Columbia, Canada
jordan@fleetr.ca