Compliance & Legal FAQ
Straight answers for customers and compliance/legal teams evaluating Fleet Street GPS — GPS tracking consent law, who owns your data, who can see it, and how it's secured.
Is it legal to GPS-track a vehicle or shipment?
Generally yes, when you own, lease, or otherwise operate the asset — or have the clear authorization of whoever does. That covers the overwhelming majority of how this product is actually used: your own fleet, your own shipments, cargo you're responsible for in transit.
The exposure is on the other side of that line. Several states have statutes that specifically criminalize installing a tracking device on a vehicle without the owner's or lessee's consent — California Penal Code §637.7 and Texas Penal Code §16.06 are commonly cited examples, and similar laws exist in other states. These are aimed at using a tracker to monitor a person without their knowledge, not at businesses tracking assets they're responsible for — but the distinction matters, and it's why our Terms of Service explicitly restrict the product to property you own, operate, or are authorized to track.
We rent vehicles to customers — do we need to disclose tracking?
We recommend it, explicitly and in writing, in the rental agreement itself. A renter's expectation of privacy in a vehicle they've rented is a live legal question, and clear disclosure at the point of rental — "this vehicle is GPS-equipped for fleet management and recovery purposes" — meaningfully reduces that exposure and is standard practice across the rental industry.
This matters more, not less, for independent and regional operators without the legal infrastructure of a major rental brand behind them — see our guide for independent rental fleets for the operational side of this. Have your specific rental agreement language reviewed by your own counsel; we can't draft it for you.
Who owns the location data?
You do. Whichever account — an individual customer or a business account — a device is assigned to owns the data that device generates: position history, trip records, alerts, everything. We don't sell it, and we don't share it with third parties outside of what's needed to operate the service (e.g. hosting infrastructure) or a valid legal request (see below).
Who inside our company can see our data?
Only the people you give access to, and only what you've explicitly scoped them to. The dashboard has three enforcement layers, all server-side (not just hidden in the interface):
- Business isolation. If you're set up as a multi-seat business account, every device assigned to your organization is visible to your team and no one else's — a different customer using the platform can't see your fleet, and you can't see theirs, enforced on every single request.
- Tiered internal roles. Within your own team, you control who's an org-admin (can add/remove teammates) versus a regular member (view-only access to your shared fleet).
- Full audit trail. Every account and device change — who added a teammate, who reassigned a device, who changed a setting — is logged with who, what, and when, available to review at any time.
How long is data kept, and can we delete it?
By default, location history is kept indefinitely so you have a full record for as long as you need it. Retention is configurable — data older than a set number of days can be automatically purged if you'd rather not keep an indefinite history. You can also clear a specific device's saved route history on demand at any time, independent of its ongoing enrollment.
How is our data secured?
- All traffic (dashboard and device reporting) runs over TLS.
- Device tokens and account passwords are hashed, never stored in plaintext.
- Access is role-scoped server-side, not client-side — see "Who can see it" above.
- Every account and device-configuration change is captured in an audit log.
- Backups run on a schedule with freshness monitored, so a hardware failure on our end doesn't mean lost history.
How are law enforcement or legal requests for data handled?
We comply with valid legal process (subpoena, court order, or similar) but don't hand over account data on request outside of one. Where we're not legally prohibited from doing so, we'll make a reasonable effort to notify the affected account holder before producing data in response to a legal request.
Questions specific to your situation?
Happy to talk through your setup before you commit to anything — reach out directly.
Contact us