Legal

Privacy Policy

Last updated: September 25, 2026

The short version: we collect personal information to run the platform, we use AI from Anthropic for a few drafting and summarizing features, we share data only with the service providers listed in Section 5, we never sell it, and when you delete a file we actually delete it. We measure our own advertising on our own marketing pages only, never on a storefront or dashboard, and you can opt out of that in Section 7.

1. Who We Are, and Which Data Is Whose

Fleet Market is a software platform used by equipment dealers, distributors, and manufacturers to run their websites, inventory, rentals, service, events, hiring, and customer communications. This policy covers fleetmarket.us, the Fleet Market dashboards, and the storefronts and embeds we host on our customers’ behalf.

Two different relationships are described in this policy, and the distinction matters for your rights:

  • Account data: information about the businesses and people who subscribe to Fleet Market and sign in to our dashboards. Fleet Market decides how this is used, so we are the controller of it.
  • Tenant data: information that a dealer, distributor, or manufacturer collects from their own customers, applicants, and site visitors using Fleet Market (contact forms, quote requests, rental bookings, service records, event RSVPs, job applications, marketing contacts). That business is the controller. Fleet Market is the processor: we store and process it on their instructions and do not use it for our own purposes.

If you submitted your information to a dealer, distributor, or manufacturer that uses Fleet Market and you want it accessed, corrected, or deleted, the fastest route is to contact that business directly. You may also contact us at the address in Section 12 and we will route your request to them and assist in fulfilling it.

2. Information We Collect

We do collect personal information. This section lists what we collect and where it comes from.

Information you give us directly

  • Account and identity: name, work email address, phone number, business name, job title, role, and the profile photo and biography you choose to publish in a team directory.
  • Authentication: your email address and a securely hashed password, plus session tokens. We never store your password in readable form.
  • Business and billing: business address, locations, tax registration details, purchase orders, and the billing contact. Card numbers are handled by Stripe and never reach our servers.
  • Content you upload: photographs, logos, videos, fonts, brochures and spec sheets, blog posts, and product and inventory listings.
  • Support and correspondence: the contents of messages you send us, and messages sent through in-platform chat.

Information collected through our customers’ sites

  • Form submissions: contact and quote requests, rental and service bookings, event registrations and RSVPs, and dealer-locator searches, typically name, email, phone, address, and whatever the business asks on its own form.
  • Job applications: applicant name, contact details, cover letter, answers to screening questions, and any résumé or CV uploaded. A CV frequently contains a home address, employment history, and education. We treat these as our most sensitive uploads and store them in a private, access-controlled location, never in a publicly readable one.
  • Commerce: order, quote, invoice, deposit, and rental-agreement records. Payment card data goes directly to Stripe; we retain only the last four digits, card brand, and Stripe identifiers.
  • Marketing consent: whether you opted in to email or text messages, when, from which form, and the policy text in force at that moment. We keep this because it is the evidence that an opt-in happened.
  • Equipment records: the machines you own or rent, assembled by the business from your service bookings, purchases, rentals, and quote requests, typically make, model, type, serial number, hour-meter reading, purchase date, warranty expiry, and the dates it was serviced. A business uses this to know what you run and when it is next due for a service. Some of it describes equipment you bought somewhere else, because you told them when you booked a repair.

What a business holds about you is matched into a single customer record using your email address or your phone number, so a service booking made by phone and a quote requested by email can be recognised as the same person. A record can exist with a phone number and no email address. Job applicants also become part of a business’s contact records, but an application is never treated as marketing consent and does not add you to a mailing list.

Information collected automatically

  • Log and device data: IP address, browser and device type, operating system, referring page, and timestamps.
  • Usage data: pages and listings viewed, features used, and interactions with embeds, used to produce the traffic and lead analytics we show the business whose site you visited. Where you are identified, as described below, these views are also recorded against your customer record with that business.
  • Cookies and local storage: see Section 8.

When browsing is linked to you by name

Most browsing on our customers’ storefronts is anonymous and stays that way. There are exactly two ways it becomes linked to you by name, and both are first-party: the information goes to the business whose site you are on, and to nobody else.

  • You are signed in to that business’s customer portal. While you are signed in, the pages and listings you view are recorded against your customer record with them.
  • You followed a link from an email that business sent you. The link carries a signed token, and following it sets a first-party cookie on that storefront (fm_vid, in Section 8) lasting up to 45 days. While it is set, the pages and listings you view on that storefront are recorded against your customer record with that business.

This only ever works forwards. We do not go back and attach your earlier anonymous browsing to you once you become identified, and we do not follow you between different businesses’ sites, each storefront’s cookie is separate and is readable only by that storefront.

One limitation worth stating plainly: if someone forwards you a marketing email and you follow the link, that browsing is attributed to the person the email was addressed to, because the link is what identifies the reader. For that reason a link click can only ever add browsing activity to a record, it can never change a name, contact details, or equipment on file. If you would rather not be recognised this way, delete that site’s cookies or block them.

We do not run third-party advertising trackers or analytics pixels on Fleet Market storefronts, embeds, dashboards, or portals. There is no Google Analytics, Meta Pixel, or comparable ad-tech on any page that belongs to a business using Fleet Market or to their customers. We do not sell personal information.

Advertising measurement on our own marketing site

Fleet Market advertises to equipment dealers, and we measure whether those ads work. On our own marketing pages only (the fleetmarket.us homepage, pricing, features, templates, the demo sign-up pages, registration and the checkout confirmation page, and the demo sandbox while you are trying the product), we load Google Analytics 4, the Google Ads tag, and the Meta Pixel. They record the pages you view there and the steps you take toward becoming a customer (starting a demo, saving it with your email, registering, subscribing). When you give us your email at one of those steps, Google and Meta receive it only in a hashed (one-way encoded) form, from your browser or from our server, so that a conversion can be matched to an ad you clicked. Because Google and Meta use this data under their own policies, this may count as “sharing” for cross-context behavioral advertising under some state laws. You can opt out in Section 7, and we honor Global Privacy Control signals automatically.

If you arrive from an ad, the click identifier in the link (a gclid or fbclid) and the campaign parameters are kept in a first-party cookie (fm_attr, Section 8) and, if you start a demo or subscribe, recorded with that demo or subscription so we can tell which campaign brought you. That record identifies an ad click, not a person, and is never combined with a storefront visitor’s record.

We do not knowingly collect Social Security numbers, government identification numbers, precise geolocation, biometric data, health data, or other categories of sensitive personal information, and we ask that you do not submit them through Fleet Market forms.

3. How We Use Information

  • To provide the platform: host sites, publish listings, deliver forms and leads to the right business, process orders and rentals, and schedule service.
  • To authenticate you, keep accounts secure, detect fraud and abuse, and enforce seat limits and permissions.
  • To bill subscriptions and add-ons, and to process payments through Stripe.
  • To send transactional messages you asked for: confirmations, invoices, notifications, invitations, and password resets.
  • To send marketing messages where you have opted in, and to let our business customers send marketing to contacts who opted in to them. Every marketing message carries an unsubscribe mechanism.
  • To provide the AI-assisted features described in Section 4.
  • To produce analytics and reporting for the business whose site or dashboard the data belongs to.
  • To assemble the customer record a business keeps about its own customers, contact details, the history of quotes, bookings and purchases, the equipment they own, and how they have engaged with messages, and to prompt that business when a machine is due for a service or a warranty is ending.
  • To maintain, debug, and improve the platform, and to meet legal, tax, and accounting obligations.

We do not use tenant data to train machine-learning models, and we do not use one customer’s data to benefit another customer except in the explicitly aggregated form described in Section 5.

4. Our Use of Artificial Intelligence

Fleet Market uses AI in parts of the product. We think you are entitled to know exactly where, what gets sent, and what happens to it.

Where AI is used today

  • Website copy assistance: generating draft marketing text for a storefront from a short description you provide.
  • Product categorization: suggesting which catalog category an inventory listing belongs in, from the listing’s title and specifications.
  • Feedback summarization: condensing product demo write-ups and customer survey responses into a short summary and a coarse sentiment label for reporting.

How it works

  • Our AI features are provided by Anthropic, PBC, using the Claude models via Anthropic’s API. Anthropic acts as our subprocessor.
  • What is sent is limited to the text needed for the specific task: a product description, a listing title, a demo write-up. We do not send payment details, passwords, or uploaded résumés to any AI service.
  • Anthropic does not use data submitted through its API to train its models, and content is retained only transiently for the purpose of returning a result and for abuse monitoring.
  • AI output is a draft, not a decision. It is presented to a person who can edit, accept, or discard it.

What AI is not used for

  • We do not use AI to make automated decisions that produce legal or similarly significant effects about you. In particular, AI does not screen, rank, score, or reject job applicants, and it does not make credit, pricing, or eligibility decisions about individuals.
  • We do not use AI to profile individual consumers for advertising.

If we introduce a customer-facing AI assistant or chatbot, we will disclose it clearly at the point of use, so you always know when you are talking to software rather than a person, and it will operate under our published AI safety standards, including trained responses that direct anyone expressing distress or risk of self-harm to appropriate human crisis support. We will update this policy before any such feature launches.

5. Who We Share Information With

We do not sell, rent, or trade personal information. We share it only in the circumstances below.

Service providers (subprocessors)

These providers process data on our behalf, under contract, for the stated purpose only:

ProviderPurposeData involved
Supabase (AWS, United States)Primary database, authentication, and file storageAll account and tenant data, including uploads
Vercel (United States)Application hosting and content deliveryRequest and log data, IP addresses
Sentry (United States)Error monitoring for the dashboards and storefrontsError messages and stack traces, the page or API path that failed, browser and operating system. No IP addresses, cookies, or account identity are sent.
StripeSubscription billing, checkout, deposits, and Stripe Connect payoutsName, email, billing address, payment details, transaction records
ResendTransactional and marketing email deliveryRecipient name and email, message content, delivery events
AnthropicAI features described in Section 4Only the task text described in Section 4
OpenStreetMap / NominatimConverting business addresses to map coordinates for dealer locatorsBusiness address strings and locator search terms
goQR (api.qrserver.com)Generating QR codes for equipment shipment receivingA shipment receiving URL only
Google FontsWeb font delivery on some storefrontsVisitor IP address and browser data, sent to Google when the font loads
Google (Analytics 4 and Google Ads)Measuring visits to our own marketing site and conversions from our ads (Section 2). Not a subprocessor for any business’s storefront data.Marketing-site page views, browser and device data, ad click identifiers, and at conversion steps a hashed email address. Denied ad-personalization consent when you opt out or send Global Privacy Control.
Meta Platforms (Meta Pixel and Conversions API)Measuring conversions from our ads on Facebook and Instagram (Section 2). Not a subprocessor for any business’s storefront data.Marketing-site page views, browser data, ad click identifiers, IP address and browser type on server-sent events, and at conversion steps a hashed email address. Not loaded at all when you opt out or send Global Privacy Control.

Between businesses on the platform

  • When you submit a form on a dealer, distributor, or manufacturer site, that information goes to that business. That is the point of the form.
  • Distributors can see data belonging to the dealer sites they administer, and manufacturers can see data for their own brand workspace.
  • Manufacturers who are tagged as brand partners receive product feedback and equipment service insights in aggregated form only: counts, average ratings, summarized themes, and failure or parts patterns by product model. They do not receive raw customer surveys, individual service records, salespeople’s internal notes, or the names or contact details of the customers behind those numbers.

Other disclosures

  • Legal compliance: when required by law, subpoena, or valid legal process, or to establish, exercise, or defend legal claims. Where we are legally permitted, we will notify the affected customer first.
  • Safety: to protect the rights, property, or safety of Fleet Market, our customers, or the public, including preventing fraud and abuse.
  • Business transfers: if Fleet Market is involved in a merger, acquisition, financing, or sale of assets, information may transfer as part of that transaction. It remains subject to this policy, and we will give notice before your information becomes subject to a materially different policy.

6. Uploads, Deletion, and Retention

When you delete an upload (a photograph, a document, a video, a résumé), we delete the file itself from storage. We do not merely hide it from your dashboard while keeping the file retrievable. Deletion of a record deletes the files attached to it.

Two consequences worth stating plainly. First, deletion is permanent and we cannot recover a deleted file for you. Second, files that were published on a public website may persist outside our control: in search engine caches, in web archives, or on the devices of people who downloaded them. We can delete our copy; we cannot retract copies other people already have.

How long we keep things

  • Active accounts: for as long as the account is open and the service is being provided.
  • After cancellation: account and site data is retained for 30 days so the account can be reactivated, then deleted. You may ask us to delete it sooner.
  • Job applications and résumés: kept while the business hiring is considering the application, and deleted when that business deletes them. Incomplete uploads from applications that were never submitted are purged automatically.
  • Financial and tax records: invoices, payments, and transaction records are kept for as long as tax, accounting, and audit law requires, generally seven years, even after an account closes.
  • Marketing consent and opt-out records: retained after you unsubscribe, because they are the proof that we honored your opt-out and the record of the consent that preceded it.
  • Equipment records: kept for as long as the business keeps the customer record they belong to. Two points of detail, because they are exceptions to “deleted means gone”: when two records turn out to describe the same machine and are merged, the merged-away record is kept rather than erased, so the service visit or purchase it came from can still be traced; and removing a machine marks it removed rather than deleting that history. Both are reversible by the business, and both are deleted with the account.
  • Backups: deleted data may persist in encrypted backups for a limited period before those backups age out on their normal cycle.

7. Your Privacy Rights

Depending on where you live, you may have some or all of the following rights. We extend the core of these rights to everyone who asks, regardless of location.

  • Know and access: what personal information we hold about you, where it came from, why we process it, and who we share it with, and to receive a copy.
  • Correct: have inaccurate personal information fixed.
  • Delete: have your personal information erased, subject to the legal retention obligations in Section 6.
  • Portability: receive your information in a portable, machine-readable format.
  • Opt out: of marketing email and text messages at any time, using the unsubscribe link or reply keyword in any message.
  • Limit: restrict or object to certain processing, and withdraw a consent you previously gave.
  • Non-discrimination: we will not deny service, charge a different price, or provide a lesser quality of service because you exercised a privacy right.

Do Not Share My Personal Information

We do not sell personal information. On our own marketing site we share limited data with Google and Meta to measure our advertising (Section 2), which some state laws treat as sharing for cross-context behavioral advertising. You can opt out of that here. The opt-out is stored in a cookie in this browser, takes effect immediately, and lasts one year; if your browser sends a Global Privacy Control signal we treat it as the same opt-out without you pressing anything. It does not affect storefronts, embeds, dashboards or portals, which never carry those tags.

To exercise a right, email privacy@fleetmarket.us. We will verify your identity before acting, which normally means confirming control of the email address on the record. We respond within 45 days and will tell you if we need a permitted extension. You may use an authorized agent, with proof of authorization. If we decline a request, we will explain why, and you may appeal by replying to our response; where your state provides one, you may also complain to your attorney general or supervisory authority.

If your information was submitted to a business that uses Fleet Market, we act on that business’s instructions. We will forward your request to them promptly and help them fulfill it.

8. Cookies and Similar Technologies

  • Strictly necessary: authentication and session cookies that keep you signed in, and security cookies that protect against forged requests. The platform does not function without these.
  • Functional: local storage that remembers preferences such as dismissed prompts, saved views, and cart or quote contents.
  • Analytics: first-party measurement of page and listing views, used to report traffic to the business whose site you visited. No third-party advertising cookies are used on storefronts, embeds, dashboards or portals.
  • Advertising measurement (our marketing site only): Google Analytics, Google Ads and Meta cookies, and our own fm_attr and fm_optout cookies, described in Section 2 and named below. Opt out in Section 7.
  • Identification: one first-party cookie, set only when you follow a link from a business’s email, which lets that business see which pages you looked at afterwards. It is named below.
CookieWhat it doesHow long it lasts
Authentication and sessionKeeps you signed in to a dashboard or a customer portal, and protects against forged requests. Strictly necessary.Until you sign out or the session expires
fm_vidSet when you follow a link from an email a business sent you. It tells that business’s storefront which contact you are, so the pages and listings you view there are recorded against your customer record with them. It holds a signed reference, not your name or email address; it is readable only by that storefront and not by our servers’ other tenants; and it is never used for advertising or shared with anyone else.Up to 45 days, then it stops identifying you
Preference storageRemembers dismissed prompts, saved views, and cart or quote contents in your browser. Never leaves your device.Until you clear your browser storage
fm_attr (marketing site only)Our own first-party cookie. Set when you arrive at a marketing page from a link that carries campaign parameters or an ad click identifier, so that a demo or subscription started later can be credited to that campaign. Campaign parameters only; never your name or email.90 days
fm_optoutRecords that you pressed “Do Not Share My Personal Information” (Section 7). While set, the Meta Pixel is not loaded and Google’s advertising features are denied consent.1 year
_ga, _ga_* (Google Analytics, marketing site only)Distinguishes returning visitors to our marketing site so visits and conversions can be counted.Up to 2 years
_gcl_au, _gcl_aw (Google Ads, marketing site only)Stores the identifier of a Google ad you clicked so a later conversion on our marketing site can be attributed to it. Not set when you opt out.90 days
_fbp, _fbc (Meta, marketing site only)Distinguishes your browser to Meta and stores the identifier of a Facebook or Instagram ad you clicked. Not set when you opt out.90 days

You can block or delete cookies in your browser settings, but authentication cookies are required to sign in, so blocking them will prevent the dashboards from working. Deleting fm_vid, or blocking cookies for a storefront, stops that business linking your later browsing to you, everything else on the site keeps working. The advertising-measurement cookies exist only on our own marketing pages; the Section 7 control turns them off, and we honor Global Privacy Control signals as the same opt-out.

9. Email and Text Messages

  • Transactional messages (order confirmations, invoices, booking reminders, password resets, and account notices) are part of the service and are sent without separate marketing consent.
  • Marketing email requires opt-in. Every marketing email includes a one-click unsubscribe.
  • Text messages require express written consent tied to the specific number, captured on a form that also collects that number. Message and data rates may apply; frequency varies. Reply STOP to opt out and HELP for help.
  • Consent is never a condition of purchase, and we do not make a marketing opt-in mandatory on any form.
  • Businesses using Fleet Market to message their own contacts are responsible for having obtained valid consent, and publish their own messaging terms and privacy notice.

10. Security and Data Location

  • Data is encrypted in transit with TLS and encrypted at rest.
  • Access is controlled by row-level security in the database and by a role and permission model in the application, so each tenant reaches only its own records.
  • Files containing personal information (résumés, internal documents, and attachments) are held in private storage reachable only through short-lived signed links issued to authorized users. Publicly readable storage is used only for material intended for publication on a website, such as product photographs and brochures.
  • Payment card data is handled by Stripe, a PCI-DSS Level 1 provider, and does not touch our servers.
  • Administrative access is limited to staff who need it, and production credentials are held in a managed secret store.

Our infrastructure is located in the United States. If you use Fleet Market from outside the United States, your information will be transferred to and processed there, where privacy laws may differ from those of your country. Where a transfer mechanism is legally required, we rely on Standard Contractual Clauses.

If a breach affects your personal information, we will notify affected customers and, where required, regulators, without undue delay and within the timeframes the applicable law sets.

No system is perfectly secure. We work hard to protect your information but cannot guarantee absolute security. If you believe you have found a vulnerability, please report it to security@fleetmarket.us; we will not pursue legal action against good-faith security research that respects user privacy and avoids service disruption.

11. Children

Fleet Market is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16. If we learn that we have, we will delete it promptly. A parent or guardian who believes a child has provided us information should contact privacy@fleetmarket.us.

12. Changes and How to Reach Us

We may update this policy. When we do, we will change the date at the top and post the revised policy here. For material changes (new categories of data, a new purpose, or a new category of recipient), we will give notice by email to account holders before the change takes effect. Earlier versions are available on request.

Privacy requests and questions: privacy@fleetmarket.us Security reports: security@fleetmarket.us General support: support@fleetmarket.us Web: fleetmarket.us