Privacy
What FleetTrestle collects and how personal information is handled.
Review privacy →Review the controls, data practices, service information, accessibility posture, integrations, and customer contact paths that support FleetTrestle.
Each destination describes the current product or policy. FleetTrestle does not use this page to imply certifications, uptime guarantees, subprocessors, integrations, or controls that are not actually in place.
What FleetTrestle collects and how personal information is handled.
Review privacy →Customer data ownership, exports, retention, and deletion paths.
Review data & portability →Current service-status information and incident communication surface.
Review service status →Accessibility approach, supported interaction patterns, and contact path.
Review accessibility →Current provider/integration status without implying unsupported integrations.
Review integrations →A direct path for security, privacy, accessibility, or service concerns.
Review support →We describe what FleetTrestle actually uses today and avoid claiming certifications, audit results, uptime guarantees, or recovery guarantees that have not been independently earned or verified.
FleetTrestle uses Supabase authentication for account sign-in and session management instead of building a custom password system.
Customer records are scoped to the organization workspace, with row-level security used as an additional database boundary.
Administrative actions such as team management, billing, and organization controls are restricted by role rather than being available to every signed-in user.
Documents, issue photos, and receipts use organization-scoped storage paths, file validation, and short-lived signed download links rather than public attachment buckets.
Subscription checkout and payment-method management are handled through Stripe-hosted payment experiences. FleetTrestle does not need to store raw card numbers in the application.
A vehicle QR code is a routing convenience only. Authentication, organization authorization, and Driver ID verification for driver field work still apply before field actions are accepted.
FleetTrestle's internal Autopilot area is separated from the customer workspace and protected by server-enforced owner access checks.
Production traffic is served over HTTPS, while authentication, service, and billing secrets remain in protected server environments rather than client-side code.
Organization administrators have product paths for data export and account/data-management requests rather than needing an undocumented back-channel process.
FleetTrestle uses managed infrastructure, and organization administrators can download a copy of their fleet records from the application.
The security posture includes a defined response sequence for suspected access, secret, organization-isolation, or service-integrity incidents.
FleetTrestle will only advertise formal certifications, audit results, uptime guarantees, or compliance designations after those claims are supportable.