Legal

Privacy policy

Savanna Fleet is fleet management software for trucking companies. This policy explains what the platform and the Savanna Fleet Android app collect, why, who else sees it, and how to get it deleted.

Last updated 27 August 2026

Two kinds of information, two different roles

Almost everything in Savanna Fleet is entered by a transport company about its own business — its trucks, its trips, its drivers, its customers. For that information the transport company decides what is collected and why; we only hold and process it on their instructions. In data-protection terms they are the controller and we are the processor. If you are a driver or an employee asking why a particular record about you exists, your employer is the right first stop, and we will help them answer.

A smaller set of information is ours to decide about: the account you sign in with, the device registration that lets us send you an alert, and the technical logs that keep the service running. For that we are the controller, and this policy is our own commitment.

What we collect

Your account

Your name, email address, a securely hashed password, your role, and which companies your account belongs to. One email address can belong to more than one company; we record which, so you can switch between them. Your session is kept in a cookie.

Your device, if you use the app

When you sign in to the Android app we store a push notification token, the platform (Android or iOS) and the time the app was last opened. The token is what lets us ring your phone when a truck moves at night. It identifies an app installation, not you personally, and it is removed when you sign out or when the installation stops responding.

Records you enter

Trucks, trailers, corridors, trips, fuel purchases, tolls, invoices, clients and suppliers. Driver records are the most sensitive of these, and they can include a full name, date of birth, nationality, national registration or ID number, blood type, phone number, home address, an emergency contact, licence, passport, work-permit and medical-certificate numbers with their expiry dates, bank account details and payroll figures. Your employer chooses which of these fields to fill in.

Photos and documents you upload

Proof-of-delivery photographs, vehicle documents, driver photographs and driver documents. The app asks for camera and photo-library permission only at the moment you choose to attach one, and only reads the file you pick. These are stored in a private bucket that is not publicly readable and served through short-lived signed links.

Vehicle location

Savanna Fleet shows where trucks are. Those positions come from the tracking hardware fitted to the vehicle, retrieved by our servers from your company’s telematics provider. They are the location of a truck, not of a person’s phone.

Technical logs

Ordinary server records — request paths, timestamps, error traces, IP address — kept to keep the service up, diagnose faults and detect abuse. Sign-in attempts are rate limited, which requires counting them.

What the app does not collect

  • Not your phone’s location. The Android app requests no location permission of any kind, in the foreground or the background. Truck positions come from vehicle hardware, as described above.
  • No contacts, calendar, call logs or SMS.
  • No advertising identifier, and no advertising of any kind.
  • No third-party analytics or tracking SDK. There is no analytics, attribution or session-replay tool in the app.
  • No microphone recording. Audio is played, never captured; the app is built with audio recording explicitly disabled.
  • No card or payment details. Subscription payments are arranged and recorded outside the app; we never see a card number.

We do not sell your data, and we do not share it for advertising. Nobody outside the list below receives it.

Why we use it

  • To run the service your company signed up for — dispatching trips, tracking trucks, keeping records.
  • To alert you: night movement, a missed checkpoint, an expiring licence. This is why push notifications exist, and the main reason the app exists at all.
  • To keep accounts secure — signing you in, rate-limiting attempts, and recording who changed what for audit.
  • To answer questions you type into the assistant, if your company uses it.
  • To bill your company and to support it when it contacts us.

Who else sees it

We use a small number of infrastructure providers. Each receives only what it needs to do its job, and none of them is permitted to use it for anything else.

ProviderWhat it handles
VercelHosting and delivery of the web application and API
MongoDB AtlasThe database where records are stored
Cloudflare R2Private storage for photos and documents
Expo and Google Firebase Cloud MessagingDelivering push notifications to your phone
ResendTransactional email — invitations, password resets, alert digests
MapTilerMap tiles and place lookup
openrouteserviceCalculating road routes between stops
AnthropicThe AI assistant, where your company has enabled it
Your telematics providerSupplying the positions of your vehicles

We will also disclose information where the law requires it, and to protect the rights or safety of people using the service. If Savanna Fleet is ever sold or merged, your data would transfer with it and this policy would continue to apply until we told you otherwise.

Where it lives, and for how long

Data is stored on servers operated by the providers above, which means it may be processed outside your country. Where it is transferred across borders we rely on those providers’ standard contractual protections.

Operational records are kept for as long as your company holds an account, because a transport business needs its trip and compliance history. We delete or anonymise data within 30 days of a deletion request, and within 90 days of an account closing, except where we are legally required to keep something longer — see Delete your data for exactly what that exception covers. Push tokens are removed as soon as an installation stops responding. Sign-in rate-limit counters expire within hours.

How we protect it

  • Traffic is encrypted in transit; passwords are hashed, never stored as text.
  • Secrets held on your behalf — such as a telematics access code — are encrypted at rest and are write-only through the interface.
  • Every request is scoped to your company. Permissions are checked per record, not just per page.
  • Uploaded files sit in a private bucket and are reachable only through short-lived signed links.
  • Changes to significant records are written to an audit log.

No system is perfectly secure, but if a breach affects your data we will tell you and the relevant authority as quickly as we reasonably can.

Your rights

You can ask for a copy of your data, ask us to correct it, ask us to delete it, or object to how it is used. Much of this you can do yourself inside the app. For anything else, and for deletion, see Delete your data — it sets out exactly what is removed and how long it takes.

Where a record belongs to your employer rather than to us, we will pass the request to them and support them in answering it, because they are the ones entitled to decide.

Children

Savanna Fleet is workplace software. It is not directed at children, and we do not knowingly collect information from anyone under 18. If you believe a child’s data has reached us, write to us and we will remove it.

Changes to this policy

If we change this policy we will update the date at the top of the page, and for anything significant we will tell account holders by email before it takes effect.

Contact us

Email support@savannafleet.com or use the contact form. We answer privacy requests within 30 days, and usually much sooner.

← Savanna FleetTerms of servicePrivacy policySecurityDelete your dataContact support