FleetPath
Platform
Platform overviewAutonomous OperationsCompliancePricing
Owner-Operators and TruckersFleets and CarriersBrokers
Industries
Heavy HaulPermit photo to compliant dispatch packetAggregate and BulkScale ticket to billable tonsHazmat and TankerPapers, endorsements, and route checked before rollLong-Haul OTRKnow the load before you book itReeferEvery load watched to the degreePrivate FleetRun your trucks like the cost center they areSee all industries
AboutVisionInvestorsDisclosures
Sign inGet started
PlatformIndustriesHeavy HaulAggregate and BulkHazmat and TankerLong-Haul OTRReeferPrivate FleetFor TruckersFor FleetsFor BrokersPricingCompanySign in
Data Processing Addendum

How we process your data,
in writing.

The processor terms that govern FleetPath's handling of personal data on your behalf.

Last updated July 18, 2026

Overview

This Data Processing Addendum, including its Schedules (this "DPA"), forms part of and is incorporated by reference into the Terms of Service, Master Subscription Agreement, or other written or electronic agreement (the "Agreement") between FleetPath Technologies, Inc. ("FleetPath") and the customer organization identified in the Agreement ("Customer") governing Customer's access to and use of the FleetPath platform and related services (the "Services"). This DPA reflects the parties' agreement with respect to the Processing of Personal Data by FleetPath on Customer's behalf in connection with the Services.

In the event of any conflict between this DPA and the Agreement with respect to the subject matter hereof (the Processing and protection of Personal Data), this DPA controls. Except as expressly modified here, the Agreement remains in full force and effect.

1. Definitions

Capitalized terms used but not defined in this DPA have the meanings given in the Agreement. For purposes of this DPA:

1.1 "Affiliate" means an entity that directly or indirectly controls, is controlled by, or is under common control with a party.

1.2 "Applicable Data Protection Laws"means all data protection and privacy laws and regulations applicable to a party's Processing of Personal Data under the Agreement, including, to the extent applicable, the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act (collectively, the "CCPA") and its implementing regulations; other U.S. state privacy laws (including the Virginia CDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, and comparable enacted statutes); and, where applicable, the EU General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR") and the UK GDPR.

1.3 "Business," "Business Purpose," "Consumer," "Sell," "Share," and "Service Provider" have the meanings given in the CCPA.

1.4 "Controller," "Processor," "Data Subject," "Personal Data Breach," "Processing" (and "Process"), and "Supervisory Authority" have the meanings given in the GDPR, and, where the CCPA applies, are read to include their CCPA analogues ("Business," "Service Provider," "Consumer," and a breach of the security of Personal Data, respectively).

1.5 "Customer Personal Data" means Personal Data contained within Customer Data (as defined in the Agreement) that FleetPath Processes on behalf of Customer in the course of providing the Services, as further described in Schedule 1.

1.6 "Personal Data" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with an identified or identifiable natural person or household, where protected as personal data or personal information under Applicable Data Protection Laws.

1.7 "Sub-processor" means any third party engaged by FleetPath or its Affiliates to Process Customer Personal Data in connection with the Services.

1.8 "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries approved by the European Commission (Commission Implementing Decision (EU) 2021/914) and/or the UK International Data Transfer Agreement or Addendum, as applicable and as incorporated by reference under §9.

1.9 "Technical and Organizational Measures" or "TOMs" means the technical and organizational security measures set out in Schedule 3.

2. Roles of the Parties and Scope

2.1 Roles. With respect to Customer Personal Data, the parties agree that Customer is the Controller / Business and FleetPath is the Processor / Service Provideracting on Customer's behalf. Where Customer is itself a Processor acting on behalf of a third-party Controller, FleetPath acts as a Sub-processor, and Customer's instructions to FleetPath must be consistent with that third-party Controller's instructions.

2.3 Scope.This DPA applies only to FleetPath's Processing of Customer Personal Data on Customer's behalf. It does not apply to (a) data Customer connects from third-party telematics/ELD providers using Customer's own provider credentials, to the extent FleetPath reads such data on Customer's authorization (see §6.5), or (b) data FleetPath Processes as an independent Controller for its own legitimate business purposes (for example, account administration, billing, security, fraud prevention, and product operation and improvement in de-identified and aggregated form), which is governed by FleetPath's Privacy Policy.

2.4 Compliance.Each party will comply with its obligations under Applicable Data Protection Laws in respect of its Processing of Customer Personal Data. Customer is responsible for the lawfulness of Customer Personal Data and of Customer's instructions, including having provided all notices and obtained all rights, consents, and legal bases necessary for FleetPath to Process Customer Personal Data as contemplated by the Agreement and this DPA.

3. Details of Processing

3.1 The subject matter, duration, nature and purpose of the Processing, the categories of Data Subjects, and the categories of Personal Data are set out in Schedule 1 (Details of Processing), which the parties will keep current.

3.2 Documented instructions.FleetPath will Process Customer Personal Data only on Customer's documented instructions, including as set out in the Agreement, this DPA, and Customer's configuration and use of the Services, unless required to Process by applicable law to which FleetPath is subject, in which case FleetPath will (to the extent legally permitted) inform Customer of that legal requirement before Processing. Customer's use of the Services constitutes Customer's complete and final documented instruction to FleetPath for the Processing of Customer Personal Data. FleetPath will inform Customer if, in FleetPath's reasonable opinion, an instruction infringes Applicable Data Protection Laws (without obligation to provide legal advice).

3.3 No sale, no share, no unauthorized use.FleetPath will not (a) Sell or Share Customer Personal Data; (b) retain, use, or disclose Customer Personal Data for any purpose other than the specific purpose of performing the Services, or otherwise as permitted by the CCPA; (c) retain, use, or disclose Customer Personal Data outside the direct business relationship between the parties; or (d) combine Customer Personal Data with Personal Data received from, or on behalf of, any third party, or collected from FleetPath's own interactions, except as permitted by the CCPA to perform a Business Purpose. FleetPath certifies that it understands the restrictions in this §3.3 and will comply with them.

3.4 No third-party model training. FleetPath will not use Customer Personal Data to train, fine-tune, or improve any third-party general-purpose artificial-intelligence model. FleetPath routes document extraction and inference to its AI Sub-processors (Schedule 2) solely to provide the Services to Customer.

3.5 Aggregated and de-identified data. FleetPath may create and use aggregated and de-identified data derived from Customer Personal Data to operate and secure the Services (broader product-improvement use, such as cross-fleet benchmarking, is offered only as an opt-in feature as described in the Terms), provided FleetPath (a) implements technical safeguards and business processes that prohibit re-identification, (b) makes no attempt to re-identify the data and does not authorize any third party to do so, and (c) does not disclose the data in a form that identifies any Customer, Data Subject, or counterparty.

4. Confidentiality

4.1FleetPath will treat Customer Personal Data as Customer's Confidential Information under the Agreement. FleetPath will ensure that personnel authorized to Process Customer Personal Data are bound by appropriate obligations of confidentiality (whether contractual or statutory) and are subject to the access controls described in the TOMs.

4.2FleetPath will limit access to Customer Personal Data to personnel who need access to perform the Agreement, and will ensure such access is governed by role-based access controls (Schedule 3, §3).

5. Security

5.1 Security measures. Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk to Data Subjects, FleetPath will implement and maintain the Technical and Organizational Measures set out in Schedule 3 designed to ensure a level of security appropriate to the risk, including protection against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.

5.2 Evolution of measures. FleetPath may update the TOMs from time to time provided the updates do not materially reduce the overall level of security of the Services during the term.

5.3 Customer responsibilities.Customer is responsible for its own secure use of the Services, including safeguarding account credentials, configuring role-based access and multi-factor authentication for its users, managing the authority and spend limits of any automated and Operator features, and determining that the TOMs meet Customer's requirements.

6. Sub-processors

6.1 Authorization.Customer provides general written authorization for FleetPath to engage Sub-processors to Process Customer Personal Data, subject to this §6. The Sub-processors engaged as of the effective date are listed in Schedule 2.

6.2 Flow-down.FleetPath will (a) enter into a written agreement with each Sub-processor imposing data-protection obligations that are, in substance, no less protective than those in this DPA to the extent applicable to the Sub-processor's Processing, and (b) remain responsible for each Sub-processor's performance of its obligations to the same extent FleetPath would be responsible if performing the Services directly.

6.3 Change notice and objection. FleetPath will notify Customer of any intended addition or replacement of a Sub-processor in advance of the new Sub-processor beginning to Process Customer Personal Data, giving Customer an opportunity to object on reasonable data-protection grounds.

6.4 Reserved and non-engaged providers. For the avoidance of doubt, Anthropic is nota Sub-processor: FleetPath maintains a reserved, un-provisioned configuration slot but no live Processing path to Anthropic exists. Should that change, FleetPath will add Anthropic to Schedule 2 under the change-notice process in §6.3.

6.5 Customer-connected data sources.Third-party telematics/ELD providers (for example, Motive and Samsara) that Customer connects using Customer's own provider credentials are data sources Customer directs FleetPath to read on Customer's authorization, not FleetPath Sub-processors.

7. Data Subject Requests

7.1 Assistance. Taking into account the nature of the Processing, FleetPath will provide reasonable assistance to Customer, by appropriate technical and organizational measures and insofar as possible, to enable Customer to respond to requests from Data Subjects to exercise their rights under Applicable Data Protection Laws (including rights of access, correction, deletion, portability, restriction, and objection).

7.2 Routing.If FleetPath receives a request from a Data Subject relating to Customer Personal Data, FleetPath will, unless legally prohibited, promptly inform the Data Subject to submit the request to Customer and/or forward the request to Customer, and will not respond to the request itself except on Customer's documented instruction.

7.3 Current fulfillment posture. As of the effective date, FleetPath fulfills assistance with Data Subject requests through a documented manual process. Account deletion is implemented as a self-service, retention-aware flow (see §8); a full-account self-service export (JSON, CSV, and stored documents) is available, and any remaining access and portability requests are fulfilled manually (per-module machine-readable exports are also available).

7.4 Customer is responsible for verifying the identity and authority of a requesting Data Subject before instructing FleetPath to act.

8. Deletion and Return of Customer Personal Data

8.1 Export window. On expiration or termination of the Agreement, Customer may, for a period of thirty (30) days, retain access to export Customer Data (including Customer Personal Data) in a machine-readable format, after which the retention-aware deletion process described in §8.2 begins.

8.2 Retention-gated deletion.Following the export window, FleetPath will delete or anonymize Customer Personal Data, except that FleetPath will retain (in restricted, and where appropriate anonymized, form) the specific record classes that FleetPath or Customer is required to retain by applicable law. These include DOT and FMCSA record-retention windows (for example, 49 CFR §§ 395.8(k)(1), 391.51), IFTA and tax record-keeping periods, e-signature and consent evidence, and any records subject to a legal hold. FleetPath retains each such class for exactly as long as the applicable obligation requires, and then deletes it. This "soft-delete now, retention-gated hard-delete when each record class's clock runs out" model is implemented by FleetPath's account-purge process. This deletion executes in production: after the applicable retention window for a record class expires, the corresponding Customer Personal Data is hard-deleted.

8.3 Legal hold. FleetPath will suspend deletion of Customer Personal Data that is subject to a legal hold or preservation obligation and will retain it until the hold is released.

8.4 Certification.On Customer's written request, FleetPath will confirm in writing that it has completed deletion in accordance with this §8, subject to the retention exceptions in §8.2.

9. International Transfers

9.1 U.S.-region Processing. FleetPath Processes Customer Personal Data on infrastructure located in the United States, and the Services are operated from the United States.

9.2 Transfer mechanism. Where any Customer Personal Data is subject to a law that requires a specific mechanism for cross-border transfer, the parties will incorporate the applicable transfer mechanism, which may include the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and the UK International Data Transfer Agreement or Addendum, with their annexes populated from Schedules 1 through 3.

10. Personal Data Breach

10.1 Notification.FleetPath will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. FleetPath's operational data-breach-notification plan currently targets prompt tenant notice within seventy-two (72) hours.

10.2 Contents.To the extent known and reasonably available, FleetPath's notification will describe the nature of the Personal Data Breach (including, where possible, the categories and approximate number of Data Subjects and records concerned), the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. Where FleetPath cannot provide all information at once, it may provide it in phases without undue further delay.

10.3 Assistance. FleetPath will take reasonable steps to mitigate and, where practicable, remediate the Personal Data Breach, and will reasonably cooperate with Customer and provide information reasonably necessary for Customer to meet its own breach-notification obligations to Supervisory Authorities and Data Subjects.

10.4 No admission.FleetPath's notification of, or response to, a Personal Data Breach is not an acknowledgment of fault or liability.

11. Audit and Inspection

11.1 Records and information.FleetPath will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including, at Customer's written request, responses to a reasonable security questionnaire and any then-current third-party attestations, certifications, or summary audit reports FleetPath maintains.

11.3To the extent the SCCs apply (§9), the audit provisions of the SCCs govern audits of transfers subject to them.

12. Liability

12.1Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement, and any reference in the Agreement to a party's liability means the aggregate liability of that party and its Affiliates under the Agreement and this DPA together.

13. General

13.1 Term.This DPA takes effect on the effective date of the Agreement (or, if later, the date it is incorporated into or countersigned under the Agreement) and continues until FleetPath has ceased all Processing of Customer Personal Data and completed deletion and return under §8.

13.2 Governing law.This DPA is governed by the law and jurisdiction and dispute-resolution provisions of the Agreement (Terms §13: State of Wyoming; individual-basis binding arbitration), except to the extent Applicable Data Protection Laws or the SCCs require otherwise.

13.3 Order of precedence. With respect to the subject matter of this DPA, the order of precedence is: (1) the SCCs (where applicable and only for transfers subject to them); (2) this DPA; (3) the Agreement.

13.4 Notices. Data-protection notices to FleetPath may be sent to admin@fleetpath.app, with a copy to FleetPath at its registered address (30 N Gould St, Ste N, Sheridan, WY 82801).

13.5 Effective date. This DPA is in effect as of its last-updated date and applies in coordination with the Privacy Policy and Terms of Service.

Schedule 1: Details of Processing

Subject matter

FleetPath's Processing of Customer Personal Data as necessary to provide the Services (a multi-tenant software platform for commercial motor-carrier operations) under the Agreement.

Duration

For the term of the Agreement, plus the export window and retention-gated deletion tail described in §8.

Nature and purpose of Processing

To operate the Services on Customer's behalf, including: hosting and displaying Customer's operational records; extracting structured fields from documents Customer uploads (automated document field extraction); surfacing operational alerts and status; routing and mapping trips; calculating and displaying settlements, invoices, and financial records; processing subscription billing; sending transactional notifications (email and SMS); orchestrating durable workflows; providing in-product search; and securing, monitoring, auditing, and supporting the Services. Processing operations include collection, recording, organization, structuring, storage, retrieval, use, display, transmission to Sub-processors as described in Schedule 2, restriction, anonymization, and deletion.

Categories of Data Subjects

  • Customer's personnel and authorized users (owners, dispatchers, administrators, back-office staff);
  • Drivers and owner-operators associated with Customer;
  • Individual contacts at Customer's counterparties (brokers, shippers, receivers, and other carriers, including interchange partners).

Categories of Personal Data

  • Account and identity data: name, work email, role, tenant association, and authentication metadata (FleetPath does not store user passwords; authentication is handled by the identity-provider Sub-processor).
  • Contact data of counterparties: names, emails, phone numbers, and addresses of broker, shipper, receiver, and carrier contacts.
  • Operational and document data: loads, trips, rate confirmations, bills of lading, proofs of delivery, lumper, scale, and fuel receipts, invoices, expenses, permits, inspections, and messages Customer creates or uploads, together with the personal data contained within those documents.
  • Telematics and location data, only where Customer connects a provider: vehicle and location data made available by a Customer-connected telematics/ELD provider, displayed on Customer's authorization (FleetPath is not a registered ELD and does not record Hours of Service).
  • Technical and request metadata: IP address, timestamps, and user-agent, retained for security and audit logging.

Special categories of Personal Data

The Services are not intended for the Processing of special-category data.

Frequency of Processing

Continuous, for the duration of the Agreement.

Schedule 2: Approved Sub-processors

FleetPath engages the following Sub-processors to Process Customer Personal Data in connection with the Services. Each receives only the data necessary for its function and is bound by data-protection obligations consistent with §6.2. Processing location is the United States unless otherwise confirmed.

Supabase
Primary database, authentication and identity, and file storage. Data received: account and identity, operational, document, and technical. Location: United States.
Cloudflare
API edge hosting (Workers), CDN, and edge security. Data received: technical and request metadata; data in transit. Location: United States.
Vercel
Web application hosting. Data received: account and identity, and technical. Location: United States.
Fly.io
Backend worker and service hosting. Data received: operational, document, and technical. Location: United States.
Temporal Cloud
Durable workflow orchestration. Data received: operational and document (workflow payloads). Location: United States.
Google (Gemini API)
Primary AI provider: automated document field extraction and chat and inference. Data received: document contents and operational data submitted for extraction and inference. Location: United States.
xAI
Backup AI provider (used only if the primary is unavailable). Data received: the same categories as the primary AI provider, on failover only. Location: United States.
Voyage AI
Text embeddings for in-product search. Data received: text derived from operational and document data. Location: United States.
HERE Technologies
Routing and mapping. Data received: location and route data. Location: United States.
Stripe
Subscription billing and payments (card data is handled entirely by Stripe; FleetPath never stores card numbers). Data received: billing contact and account data (no card numbers held by FleetPath). Location: United States.
Sentry
Error monitoring and diagnostics (credentials stripped before storage). Data received: technical and diagnostic data; internal account identifiers. Location: United States.
Resend
Transactional email delivery. Data received: recipient email and notification content. Location: United States.
Twilio
SMS notifications only (not voice). Data received: recipient phone number and notification content. Location: United States.

Notes

  • Anthropic is not a Sub-processor(reserved configuration, no live Processing path). See §6.4.
  • Twilio to Telnyx:the SMS Sub-processor is expected to change to Telnyx on the communications migration; Schedule 2 and a §6.3 change notice will follow that event.
  • Customer-connected telematics and ELD providers(for example, Motive and Samsara) are addressed in §6.5 as data sources that Customer connects and directs, not as FleetPath Sub-processors, and are therefore not listed here.

Schedule 3: Technical and Organizational Security Measures (TOMs)

FleetPath maintains the following technical and organizational measures. These are grounded in FleetPath's implemented controls. FleetPath may update these measures under §5.2 provided the overall level of security is not materially reduced.

1. Encryption

  • In transit: all public surfaces terminate TLS and enforce TLS 1.2 or higher; no plaintext listener is exposed. Enforced by the managed edge and hosting platforms (Vercel, Cloudflare, Supabase, and Fly.io).
  • At rest, sensitive credentials: third-party integration credentials (API keys and OAuth tokens) are encrypted at the application layer using PostgreSQL pgcrypto symmetric encryption (pgp_sym_encrypt) under a dedicated server-side key held outside the row data, with masked display and a key-rotation metadata model.
  • At rest, primary stores: databases and object storage are operated on managed cloud platforms (Supabase Postgres and Supabase Storage) that provide storage-level encryption at rest.

2. Access control and authentication

  • Authentication is handled by the identity-provider Sub-processor; FleetPath does not store user passwords.
  • Multi-factor authentication (TOTP) is available, with hashed, single-use recovery codes and audited recovery flows.
  • Role-based access control (RBAC): a tenant-configurable effective-permission resolver enforces role-scoped access, with sensitive permissions that fail closed (deny) on resolver error and protected-core invariants that cannot be denied to owner and admin roles.

3. Tenant isolation (multi-tenancy)

  • Every tenant-owned table carries a tenant_id with row-level security (RLS) policies for direct client-SDK access.
  • The server-side API layer (which runs with elevated privileges and bypasses RLS) enforces mandatory per-request tenant_id scopingin every handler; workers use a tenant_table() helper that auto-chains the tenant filter so a forgotten scope is structurally prevented. The outcome is that one tenant cannot access another tenant's data.

4. Audit logging and monitoring

  • Credential access is recorded in a dedicated audit log capturing tenant, provider, action (read, write, rotate, revoke), actor, IP address, and user-agent.
  • Significant actions are written to a canonical events audit sink (including security-sensitive events such as MFA recovery-code use), stamped with actor and actor type (person versus automated seat).
  • Error diagnostics are captured via Sentry with credentials (authorization and cookie headers) stripped before storage.

5. Data minimization and purpose limitation

  • Telematics and ELD reads are scoped to the fields required for the features Customer uses and occur only on Customer's connection; disconnecting revokes FleetPath's stored credential and stops further collection.
  • Transient processing artifacts (for example, document-analysis screenshots) are swept on a short cycle: screenshots at 24 hours and analysis results at 30 days, via a scheduled retention job.

6. Retention and secure deletion

  • A retention-aware account-purge process performs tenant-scoped hard-deletion of PII stream tables and column-level anonymization of records retained for financial and audit value, honoring DOT, FMCSA, and IFTA retention floors and legal holds, after a 30-day grace window (see §8).

7. Resilience and incident response

  • FleetPath maintains incident-response runbooks and a data-breach-notification plan, and secret-rotation and worker-recovery runbooks.
  • Durable workflow orchestration (Temporal) provides retry and recovery for long-running Processing operations.

8. Governance

  • FleetPath runs recurring internal security audits and maintains change-controlled database migrations and code-ownership review.
Data protection questionsadmin@fleetpath.app

See also Privacy Policy, Subprocessors, Terms of Service.

FleetPath

The operations platform for American trucking. Snap the rate con and FleetPath builds the load, plans the truck-legal route, and lines up the invoice.

Industries

Heavy HaulAggregate and BulkHazmat and TankerLong-Haul OTRReeferPrivate Fleet

Product

PlatformAutonomous OperationsCompliancePricing

Company

AboutVisionInvestorsContact

Legal & Compliance

Privacy PolicyTerms of ServiceSubprocessorsSecurity & TrustData Processing AddendumAcceptable UseCarrier Bill of RightsCookie PolicyAccessibilityDisclosures
© 2026 FleetPath Technologies, Inc. All rights reserved.Built for the people who move America.
FleetPath Technologies, Inc. is a Delaware corporation and a wholly-owned subsidiary of Lavish Enterprises, Inc., which is publicly traded under the symbol VXIT. Nothing on this site is an offer to sell, or a solicitation of an offer to buy, any security, and nothing here should be relied upon in connection with any investment decision.