LEGAL & GOVERNANCE

FleetQore Privacy Policy & Data Governance

How FleetQore collects, protects, retains, and governs operator and customer records across our mobility operating system in strict alignment with GCC privacy mandates.

100% Client Owned
Operator Retains Full Data Ownership
0% Brokered
Zero Selling of Fleet or Client Records
GCC Native
KSA PDPL & Qatar Law No. 13 Compliant
Encrypted
Field-Level Cryptographic Protection
SECTION 01

Our Privacy Philosophy & Data Stewardship

At FleetQore, we believe that enterprise trust is built upon transparency, sovereignty, and strict data stewardship. Our business model is straightforward: we provide a software operating system for car rental and commercial fleet operators.

We never sell, rent, monetize, or broker operator data, vehicle telemetry streams, driver profiles, or end-customer personal records to advertising brokers, insurance aggregators, or third-party data brokers. Fleet operators retain 100% proprietary ownership of all data generated across their deployments.

  • Zero commercialization or monetization of operator, driver, or customer data
  • Operator retains absolute ownership and unrestricted export rights to all system records
  • Strict purpose-limitation: data is processed solely to fulfill platform service delivery
  • Full compliance with Saudi Arabia Personal Data Protection Law (PDPL) and Qatar Privacy Mandates
Data Ownership Guarantee: Your fleet database belongs exclusively to your business. FleetQore serves strictly as a data processor on behalf of the operator, who acts as the primary data controller.
SECTION 02

Categories of Data Processed on the Platform

To power customer reservations, branch dispatching, driver trip navigation, and executive reporting, FleetQore processes specific categories of operational data based on the modules enabled by the operator.

These categories are collected either directly through customer mobile apps, counter check-in desks, vehicle telemetry hardware, or operator back-office configurations.

  • Customer Profile & KYC Data: Full name, verified mobile number, email, government national ID or passport scans, and driving license details required for car rental agreements.
  • Vehicle Telemetry & Asset Logs: GPS coordinate streams, odometer readings, vehicle battery/fuel levels, speed alerts, and maintenance diagnostic trouble codes (DTCs).
  • Trip Lifecycle & Dispatch Timestamps: Pickup/return timestamps, branch terminal locations, driver assignment logs, curbside SLA metrics, and digital handover inspection photos.
  • Billing & Transaction Records: Invoicing summaries, payment token references (via certified PCI-DSS payment gateways), security deposit authorizations, and corporate cost-center codes.
SECTION 03

How FleetQore Uses Operational Information

We process operational records strictly to deliver, maintain, secure, and enhance our mobility operating system on behalf of our licensed operators.

Specific operational use cases include generating live dispatch countdown timers, calculating dynamic rental rates, routing drivers to pickup terminals, automating corporate monthly invoicing, and compiling executive HQ utilization benchmarks.

  • Executing customer reservation flows and issuing automated digital rental agreements
  • Triggering real-time curbside SLA countdown alerts for branch dispatch teams
  • Facilitating digital vehicle handover damage inspections with timestamped photo records
  • Generating compliant tax invoices (including ZATCA phase 2 QR codes in KSA and MOCI invoicing in Qatar)
  • Compiling aggregated, anonymized system performance metrics to optimize platform throughput
SECTION 04

Subprocessors & Infrastructure Partners

FleetQore partners with carefully vetted tier-1 technology infrastructure providers to host, secure, and deliver our cloud platform. Every subprocessor undergoes rigorous security and privacy due diligence.

All infrastructure partners are bound by strict Data Processing Agreements (DPAs) requiring equivalent or superior security standards, encryption, and confidentiality controls.

  • Cloud Hosting & Database Storage: Enterprise tier-4 data centers with localized hosting options in the GCC
  • SMS & Notification Gateways: Telecom providers delivering transactional OTPs and booking updates
  • Mapping & Navigation Services: High-precision geospatial and routing APIs for driver app navigation
  • Payment Processing Gateways: Certified PCI-DSS Level 1 payment gateways handling tokenized card transactions
SECTION 05

Data Retention, Archival & Right to Erasure

FleetQore retains operational and transaction records in accordance with the operator’s configured data retention schedules and applicable statutory commercial regulations.

Commercial accounting and tax laws in Saudi Arabia and Qatar require businesses to maintain financial records and rental agreements for statutory audit periods (typically 5 to 10 years). Customer accounts inactive beyond regulatory thresholds can be scheduled for automated anonymization.

  • Customizable data retention policies configured per branch or jurisdiction
  • Automated data scrubbing and anonymization workflows for departed customer profiles
  • Complete data export options in standard open formats (CSV, JSON, and encrypted database dumps)
  • Immediate and verifiable data destruction upon termination of commercial subscription agreements
SECTION 06

GCC Regulatory Privacy Compliance (KSA PDPL & Qatar)

FleetQore is purpose-built to comply with the evolving regulatory frameworks of the Gulf Cooperation Council. In the Kingdom of Saudi Arabia, our architecture adheres to the Personal Data Protection Law (PDPL) enacted by Royal Decree No. (M/19) and overseen by the Saudi Data & AI Authority (SDAIA).

In the State of Qatar, our processing aligns with Law No. 13 of 2016 Concerning the Protection of Personal Data Privacy, ensuring lawful processing, explicit consent mechanisms, and cross-border data transfer safeguards.

  • Consent management workflows integrated into customer mobile booking applications
  • Dedicated Data Protection Officer (DPO) oversight and privacy compliance audit schedules
  • Transparent data subject access request (DSAR) workflows for customer profile inquiries
  • Sovereign in-country database hosting options for operators with strict public-sector compliance requirements
For privacy inquiries, data subject access requests (DSAR), or Data Processing Agreement (DPA) execution, please contact our legal desk at privacy@fleetqore.com.
ENTERPRISE TRUST

Built for enterprise security, scale & governance

Schedule a dedicated session with our solutions architects to review our multi-tenant data isolation, cryptographic DuckDB audit trails, and localized GCC compliance models.