Loading…
Legal
This policy describes how FleetAxis Inc. (“FleetAxis”, “we”, “us”) collects, uses, discloses, retains, and protects personal information through the FleetAxis Mobile and OneFestivalmobile applications (collectively, the “Apps”) on iOS and Android.
Effective date: 2026-06-23
For the web platform privacy policy that applies to fleetaxis.maximinimal.ca and tenant-branded storefronts, see /privacy. For our security posture, see /security.
FleetAxis Inc. is a Canadian company headquartered in British Columbia. We act as the data controller for account-holder information (operators and staff who sign in to manage events, rentals, and inventory) and as a data processorfor information about guests, customers, and crew that operator-tenants upload or collect through the Apps. Each tenant operator is the controller of their own customer data.
Contact: privacy@maximinimal.ca. For privacy requests, please include the email address associated with your account and the name of the operator (tenant) you interacted with.
Email address, name, phone number (optional), employee ID, profile photo (optional), department and role assignment, the tenant(s) you belong to. Collected when you sign in or are invited by an operator. Used to authenticate, authorize, and route notifications.
Hashed password (we never store plaintext), TOTP secret (if MFA enabled), recovery codes (encrypted at rest), session tokens, biometric-unlock state (the biometric itself never leaves your device — only a yes/no signal from the OS).
When you accept a crew assignment that requires geofence check-in or ETA sharing, the App collects precise GPS location only while the App is in use and only while you are on an active assignment window. We do not collect background location. Location collection is gated by an explicit, per-tenant consent toggle and is disabled by default. Retention: 24 hours of trail data, then summarized to entry/exit events for 30 days.
The App accesses the camera when you scan a barcode/QR for serialized inventory, snap a condition photo for an item check-out/in, capture a delivery proof-of-pickup, or upload a receipt for a department-card expense. The App accesses the photo library only when you choose a photo to attach. Photos are uploaded to Vercel Blob storage scoped to the uploading tenant.
Expo push tokens (which wrap APNs on iOS and FCM on Android), device model, OS version, App version, time zone, and locale. Used to deliver assignment notifications, acknowledgments, and operational alerts; and to debug device-specific issues. No advertising identifier (IDFA / AAID) is collected.
Anonymized error reports and crash stack traces via Sentry, including the screen on which the crash occurred and a redacted breadcrumb trail. Network latency telemetry. We do not use third-party advertising or behavioral analytics SDKs in the Apps.
We do not sell personal information, use it for cross-context behavioral advertising, or share it with data brokers.
Where the EU GDPR or UK GDPR applies, we rely on the following bases under Article 6:
The Apps rely on the following subprocessors. We have Data Processing Agreements in place with each, or rely on their standard terms where a DPA is not separately offered:
| Vendor | Purpose | Region |
|---|---|---|
| Vercel | Application hosting, compute, blob storage | United States |
| Neon | Postgres database | United States |
| Expo | Push notification relay (APNs / FCM) | United States |
| Apple Push Notification service | iOS push delivery | United States |
| Google Firebase Cloud Messaging | Android push delivery | United States |
| Stripe | Payment processing and card issuing | United States |
| Sentry | Crash & error monitoring | United States |
| Resend | Transactional email | United States |
| Twilio | SMS / phone notifications | United States |
| Upstash | Rate-limit and session caching | United States / EU |
| Inngest | Background job orchestration | United States |
| QuickBooks (Intuit) | Accounting sync (opt-in per tenant) | United States |
A current list is mirrored on our security page. We update this list when subprocessors are added or removed.
FleetAxis is headquartered in Canada and the Apps’ primary infrastructure is in the United States. If you are located in the European Economic Area, the United Kingdom, or Switzerland, your personal information will be transferred to and processed in jurisdictions that may not provide an equivalent level of data protection. We rely on the European Commission’s Standard Contractual Clauses (SCCs) and equivalent UK and Swiss mechanisms with our subprocessors.
Depending on where you live, you may have the right to:
You can self-serve account export and deletion from inside the App (Settings → Privacy) or via the web at fleetaxis.maximinimal.ca/me/privacy. To exercise rights against your employer-tenant’s data, contact them directly; we will assist them as their processor.
In the past 12 months we have collected the categories of personal information described in Section 2 (identifiers, professional information, geolocation when consented, audio/visual when you upload, internet activity metadata). We have notsold or shared personal information for cross-context behavioral advertising. We do not knowingly process the personal information of consumers under 16 years of age in California. You may exercise your CCPA/CPRA rights using the contact in Section 1. You may designate an authorized agent; we will verify the agency relationship before processing the request.
FleetAxis collects, uses, and discloses personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws (including BC PIPA and Quebec Law 25). You can submit a complaint to the Office of the Privacy Commissioner of Canada at priv.gc.ca. We will respond to access and correction requests within 30 days.
The Apps are not directed to and not knowingly used by individuals under 16 (or under 13 for COPPA purposes in the United States). If we learn that we have collected information from a child without verifiable parental consent, we will delete it.
We protect personal information using TLS 1.2+ in transit, AES-256 at rest, database-enforced tenant isolation (Postgres FORCE ROW LEVEL SECURITY on every table), tamper-evident audit logging (hash chain), least-privilege access controls, and continuous vulnerability scanning. A summary of controls is at /security.
For the Google Play Console Data Safety form, the FleetAxis Mobile and OneFestival Android apps collect the following data types. All collection is encrypted in transit; all can be requested for deletion.
For Apple’s App Store Connect Privacy Nutrition Labels, the FleetAxis Mobile and OneFestival iOS apps declare data Linked to You for App Functionality (Contact Info, User Content, Identifiers, Usage Data, Diagnostics) and, when you enable geofencing, Coarse and Precise Location. No data is used for Tracking. App Tracking Transparency is not invoked because we do not access the IDFA.
When we make material changes, we will update the effective date above and, where appropriate, notify you in-App or by email. Continued use of the Apps after a change constitutes acceptance of the updated policy.
Privacy questions, requests, or complaints: