Security & data, in plain English
Where your data lives
FleetMark runs in the UK/EU on SOC 2 / ISO 27001 infrastructure (Supabase, EU region; Vercel edge) [regions to be re-confirmed at launch]. Data is encrypted in transit and at rest, backed up daily, and access is scoped so your fleet's data is visible only to your fleet's managers.
Records you can trust
Every submitted check is locked instantly into a signed, dated PDF with a SHA-256 hash. Nobody can edit or backdate one — not your drivers, not you, not us. That's what makes them worth keeping.
What we deliberately don't collect
No medical or health information. No penalty points, endorsements or conviction data. No driver home addresses or personal phone numbers required. No tracking or telematics. No card details on our servers (Stripe handles payment). No advertising trackers, no data brokers, no selling data — ever. Drivers sign in with a name and a 4-digit PIN, not an email — because the least data we can hold is the least data anyone can lose.
Your way out, always
Export everything — every PDF, every photo, full spreadsheets — in one tap, on every plan, forever. If we ever wound FleetMark down: 90 days' notice minimum and full exports for everyone (Pledge item 6).
The formal stuff
Our Privacy Notice, Data Processing Terms and current sub-processor list are published and kept current. Found a vulnerability? [security@ email] — we respond fast and gratefully.