Privacy Policy
Last updated: September 1, 2026
Effective date: September 1, 2026
This Privacy Policy explains how TINYFLEETPM LLC ("TinyFleet," "we," "us," or "our") collects, uses, shares, and retains information when you use tinyfleetpm.com, the TinyFleet PM mobile application, and related services.
1. Information we collect
Information you provide
- Account information: email address, display name, authentication details, and account preferences. Authentication is provided by Supabase; TinyFleet does not receive your plaintext password.
- Fleet and organization information: organization name, team memberships, permissions, assets, maintenance tasks and history, meter readings, parts, costs, notes, ownership records, and related operational data.
- Files and images: photos, receipts, invoices, manuals, and other files you choose to upload.
- Location: an asset location when you choose to use the foreground location feature or enter a location manually. TinyFleet does not require continuous background location tracking.
- Support information: messages and information you send when requesting support, privacy assistance, cancellation, or deletion.
- Billing information: subscription, invoice, payment status, and limited payment-method details supplied by Stripe. Stripe, not TinyFleet, receives and stores your full payment-card number.
Information collected through use of the Service
- Authentication and technical information: session data and information such as timestamps, device or browser type, IP address, and user agent where available for security, troubleshooting, and abuse prevention.
- Audit information: records of certain changes, which may include the acting user, organization, action, affected record, and before-and-after values. Audit coverage varies by feature.
- First-party product and demand events: a session identifier and limited information about landing pages, referral or campaign context, and product milestones such as starting signup or checkout. We use these events to understand whether our own product and marketing work. We do not use third-party advertising trackers or sell this information.
- Cookies and browser storage: essential authentication state, security information, and user preferences. We do not use advertising cookies.
Information from service providers
We may receive account, billing, delivery, or diagnostic information from providers that help operate the Service, including Supabase, Stripe, Vercel, OpenAI, and Google Play.
2. Optional AI features
TinyFleet sends information to OpenAI only when an applicable AI feature is invoked. Depending on the feature, this may include:
- a receipt or invoice image submitted for extraction;
- selected asset details used to suggest a maintenance plan; or
- limited, allowlisted fleet metrics used to draft a manager briefing.
AI output is a suggestion and may be inaccurate. You should review it before using or saving it as an authoritative record. Avoid submitting sensitive personal information that is not needed for the requested feature. Information sent to OpenAI is also handled under OpenAI's applicable terms and privacy practices.
3. How we use information
We use information to:
- create accounts, authenticate users, and enforce organization permissions;
- provide fleet, maintenance, parts, reporting, sharing, and storage features;
- process subscriptions, taxes, invoices, cancellations, and refunds;
- provide user-invoked AI features;
- secure, troubleshoot, measure, and improve the Service;
- respond to support, privacy, and deletion requests;
- send account, security, billing, and service notices; and
- comply with law and protect users, TinyFleet, and others.
TinyFleet does not sell personal information and does not share it for cross-context behavioral advertising. We do not use third-party ad networks.
4. How information is shared
We share information only as needed for the following purposes:
- Within your organization: authorized team members can view and change shared information as their permissions allow.
- Service providers: Supabase provides authentication, database, and file storage; Vercel provides web hosting and delivery; Stripe provides billing; OpenAI provides user-invoked AI processing; and Google distributes the Android application. Providers receive information needed for their work and process it under their own terms and privacy practices.
- Public Maintenance Passports: when an authorized user intentionally publishes a Passport, anyone with the link can see the limited information displayed there. Private attachments, precise location, team data, and internal identifiers are not intended to be public.
- User-selected destinations: when you follow an external supplier or affiliate link, the destination receives information normally sent by a web browser and any details you choose to provide there. TinyFleet does not send private maintenance records through those links.
- Legal, safety, and rights: we may disclose information when reasonably necessary to comply with law, respond to valid legal process, prevent fraud or harm, or protect legal rights.
- Business transfer: information may transfer as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of the Service, subject to applicable law.
5. Retention
We keep information for as long as reasonably needed to provide the Service, protect record integrity, resolve disputes, enforce agreements, prevent fraud, and meet legal, tax, accounting, and security obligations. Retention varies by record type and context.
TinyFleet is designed to preserve durable equipment history. Canceling a subscription or deleting a login does not necessarily erase shared maintenance, ownership, cost, billing, security, or audit records. Where appropriate, we may restrict, separate, or de-identify personal contact information while preserving historical attribution and records that other organization members rely on.
6. Security
We use reasonable administrative, technical, and organizational safeguards, including encrypted network connections, Supabase authentication, row-level database access controls, organization-scoped permissions, and protected file storage. Access controls are designed to limit users to information they are authorized to use.
No service is completely secure. Protect your credentials, use a unique password, and contact us if you suspect unauthorized access. If a security incident requires notice, we will notify affected users and authorities as required by applicable law.
7. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal information, or to object to or restrict certain processing. You may also have the right to appeal our response or contact a data protection authority. We will not discriminate against you for exercising a privacy right.
To make a request, email Tinyfleetpm@yahoo.com from the address associated with your account and use the subject Privacy request. We will verify identity and authority before disclosing or changing information and will respond within the time required by applicable law.
For account deletion details, see the Account and Data Deletion Policy.
8. Children's privacy
The Service is intended for adults and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided information, contact us so we can investigate and take appropriate action.
9. International processing
TinyFleet is based in Washington State, United States. Our providers may process information in the United States and other locations where they operate. Those locations may have privacy laws different from the laws where you live. Where required, we use legally recognized safeguards for cross-border processing.
10. Changes to this policy
We may update this policy as the Service or law changes. We will post the revised policy with a new effective date and provide additional notice for material changes when required.
Contact
Privacy questions or requests: Tinyfleetpm@yahoo.com