Privacy Policy
Effective date: 2026-08-04
This policy describes how Pittasoft Co., Ltd. ("we", "us") handles personal data when you use the Fleeta Open API, the Fleeta Developers portal (this website), and the Fleeta MCP server. It supplements — and does not replace — the privacy policy that governs your underlying Fleeta service account.
Data we process
When you use the Open API, the portal, or the MCP server, we process the following categories of data:
- Account identifiers — the email address of the account (masterEmail) an API key is bound to, used as the tenant anchor for every request.
- Organization, vehicle, and device metadata — device serial numbers (PSN), device names and models, vehicle information (VIN, plate, maker, model, year), and vehicle group membership, as stored in your Fleeta account and returned through the API.
- Telemetry and event data — GPS locations, trips and tracks, safety events (type, time, location, speed), and time-limited presigned URLs for event videos and thumbnails. This data originates from the dashcams registered to your organization.
- API credentials — we store only a SHA-256 hash of each API key, never the plaintext. The key plaintext is shown once at issuance and cannot be recovered by us afterwards.
- OAuth client information — for MCP connections using OAuth, we process dynamic client registration data submitted by your AI client. Access tokens are self-contained (encrypted with AES-256-GCM) and are not stored in a server-side token database.
- Access logs — request metadata such as the request path, timestamp,
request ID, response status, and the key that made the call, including
the audit log exposed to you via
GET /v1/audit-logs.
We do not collect payment card details through the API or this portal.
Why we process it
- To operate the API — authenticate keys, enforce tenant isolation, scopes, rate limits, and quotas, and return your organization's data.
- To secure the service — detect abuse, investigate incidents, and provide the audit trail of API activity to account owners.
- To meter usage — count API calls and volume-quota consumption per key for the limits described in the Rate Limits guide.
- To support you — resolve issues you report, typically using the
requestIdyou provide.
We do not sell personal data, and we do not use API data for advertising.
Retention
- Fleet data (devices, telemetry, events) is retained under the retention rules of your Fleeta service account and remains available through the API while your account is active.
- API keys (hashes and their metadata) are retained while the key exists; revoked keys stop authenticating immediately.
- Access and audit logs are retained for a limited operational period and are deleted or anonymized thereafter.
- Presigned media URLs are short-lived by design (minutes to hours) and expire on their own.
- Other records tied to your account are retained while your account is active and removed or anonymized after account deletion, except where a longer period is required by law.
Third parties and international transfer
The API, portal, and MCP server run on Amazon Web Services (AWS) infrastructure, primarily in the US West (Oregon, us-west-2) and US West (N. California) regions. Data you access through the API is therefore processed and stored in the United States. AWS acts as our infrastructure processor; we do not share your API data with other third parties except where required by law.
If you connect an AI client via the MCP server, the responses returned to that client are handled by the AI provider you chose under their terms and privacy policy — connect only clients you trust, and note that with OAuth your API key itself is never revealed to the client.
Your rights
Depending on your jurisdiction, you may have the right to access, correct, delete, or export personal data we hold about you, and to object to or restrict certain processing. Requests can be made through the contact below or through your Fleeta account channels; account owners can review API activity themselves via the audit log.
Security
- API keys are stored as SHA-256 hashes only; plaintext keys are never stored server-side.
- Traffic is encrypted in transit with TLS (HTTPS is required everywhere, including webhook endpoints).
- OAuth access tokens are sealed with AES-256-GCM, are short-lived (1 hour), and cannot be tampered with or forged.
- Tenant isolation is enforced fail-closed in a shared authentication layer — see Tenant Isolation.
Changes to this policy
We may update this policy as the service evolves. Material changes will be announced on this portal (see the Changelog) with an updated effective date.
Contact
Questions and requests regarding this policy:
FLEETA Support (Pittasoft Co., Ltd.)
Email: sales@fleeta.io
18000 Studebaker Rd #700, Cerritos, CA 90703
ABN Tower 4F, 331, Pangyo-ro, Bundang-gu, Seongnam-si, Gyeonggi-do 13488, Republic of Korea