Privacy Policy — Canada
Last updated: June 2026
1. Introduction
TechTrust AutoSolutions ("we", "us", or "our") is committed to protecting your personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and Quebec's Act Respecting the Protection of Personal Information in the Private Sector (Law 25). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our mobile applications, our website at techtrustautosolutions.com, and related services (collectively, the "Services").
2. Privacy Officer
Our Privacy Officer is responsible for ensuring compliance with this policy and applicable privacy legislation. You may direct any questions or concerns to:
3. Information We Collect
3.1 Vehicle and Fleet Data
- GPS location and route history
- Fuel consumption and analytics
- Maintenance records and service history
- Vehicle make, model, year, VIN, and licence plate
3.2 Account Information
- Name, email address, and phone number
- Company name and business type
- Password and security credentials
3.3 Payment Information
- Billing address and payment method details
- All payment data is processed by our PCI-DSS compliant third-party payment processor; we do not store full card numbers on our servers
3.4 Usage Data
- Device type, operating system, and browser information
- App interactions, features used, pages viewed, and timestamps
- IP address and approximate geographic location
4. Purpose of Collection
We collect and use your personal information for the following purposes:
- Provide fleet management services: GPS tracking, fuel analytics, maintenance management, compliance tools, and reporting.
- Process payments: Handle subscription billing, invoicing, and transaction records.
- Improve our platform: Analyse usage patterns to enhance features, performance, and user experience.
- Communicate with you: Send service confirmations, updates, appointment reminders, and respond to support inquiries.
- Comply with legal obligations: Meet requirements under PIPEDA, Law 25, and other applicable legislation.
5. Consent
We obtain your consent before collecting, using, or disclosing your personal information, except where permitted or required by law. Your consent may be express (e.g., signing up for an account) or implied (e.g., providing information voluntarily for a stated purpose).
Under Quebec's Law 25, explicit opt-in consent is required for the use of non-essential cookies, tracking technologies, and any profiling activities. We will not activate analytics or marketing cookies until you have provided your affirmative consent through our cookie banner.
You may withdraw your consent at any time, subject to legal or contractual restrictions, by contacting our Privacy Officer. We will inform you of the consequences of withdrawing consent.
6. Access and Correction
You have the right to access the personal information we hold about you and to request corrections if it is inaccurate or incomplete. To exercise this right, contact our Privacy Officer at contact@techtrustautosolutions.com.
We will respond to your request within 30 days, as required by PIPEDA and Law 25. If we are unable to fulfil your request within that timeframe, we will notify you in writing and explain the reason for the delay.
7. Data Security
We implement industry-leading security measures to protect your personal information against unauthorized access, disclosure, alteration, or destruction:
- Encryption in transit: TLS 1.3 protocol for all data transmitted between your device and our servers.
- Encryption at rest: AES-256 encryption for all stored data.
- Infrastructure: SOC 2 compliant cloud infrastructure hosted on Amazon Web Services (AWS).
- Multi-factor authentication (MFA): Available and encouraged for all user accounts.
- Monitoring: 24/7 security monitoring, intrusion detection, and regular vulnerability assessments.
- Access controls: Role-based access controls and principle of least privilege for all employees.
8. Data Retention
We retain your personal information only as long as necessary to fulfil the purposes for which it was collected, or as required by law. Specifically:
- Vehicle and fleet data: Retained for the duration of your active subscription plus 12 months after cancellation.
- Account information: Retained while your account is active; deleted within 30 days of an account deletion request, subject to legal retention requirements.
- Payment records: Retained as required by applicable tax and financial regulations.
- Usage data: Aggregated and anonymized data may be retained indefinitely for analytics purposes.
9. Third-Party Disclosure
We do not sell your personal information. We may share your data with trusted third-party service providers who assist in operating our platform, including:
- Cloud infrastructure: Amazon Web Services (AWS) for hosting and data storage.
- Payment processing: PCI-DSS compliant payment processors for transaction handling.
- Email services: For transactional emails, service notifications, and communications.
- Analytics: To understand usage patterns and improve our Services (only with your consent for non-essential analytics).
All third-party service providers are bound by confidentiality agreements and are contractually required to handle your personal information in accordance with PIPEDA and applicable privacy legislation.
10. Breach Notification
In the event of a privacy breach that creates a real risk of significant harm to affected individuals, we will:
- Notify affected individuals as soon as feasible, describing the nature of the breach, the information involved, and steps they can take to protect themselves.
- Report the breach to the Office of the Privacy Commissioner of Canada as required under PIPEDA.
- For Quebec residents, notify the Commission d'accès à l'information du Québec as required under Law 25.
- Maintain a record of all breaches, regardless of whether they meet the notification threshold.
11. Cookies
Essential cookies are used for core site functionality, such as maintaining your session and remembering your preferences. These cookies are strictly necessary and do not require consent.
Non-essential cookies (analytics, marketing, and performance cookies) require your explicit consent before being activated. You can manage your cookie preferences at any time via our cookie consent banner. If you decline non-essential cookies, the core functionality of our Services will not be affected.
12. Your Rights
Under PIPEDA and Law 25, you have the following rights regarding your personal information:
- Right to access: Request a copy of the personal information we hold about you.
- Right to correct: Request corrections to inaccurate or incomplete personal information.
- Right to delete: Request deletion of your personal information, subject to legal retention requirements.
- Right to withdraw consent: Withdraw your consent for the collection, use, or disclosure of your personal information at any time.
- Right to data portability: Under Law 25, request your personal information in a structured, commonly used format.
- Right to file a complaint: If you are unsatisfied with how we handle your personal information, you may file a complaint with:
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Privacy Officer:
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable legislation. Material changes will be communicated to you via email or a prominent notice on our website. The "Last updated" date at the top of this page indicates the most recent revision. We encourage you to review this policy periodically.