Privacy Policy
How Future Telematics collects, uses and retains information in the VTS vehicle tracking platform and its mobile applications.
1. Who we are and what this covers
FUTURE TELEMATICS PRIVATE LIMITED operates a vehicle tracking and fleet management platform. Our customers are businesses that fit tracking hardware to their own vehicles; the people whose information appears in the platform are those businesses' drivers, staff and managers.
In most cases our customer is the data controller for the vehicle and driver information in their account, and FUTURE TELEMATICS PRIVATE LIMITED acts as a processor on their instructions. We are the controller for the accounts we issue, our own operational logs, and the information described in section 3.4.
2. What the mobile apps do and do not collect
This is the part most people want answered first, so it is stated plainly.
VTS Fleet and Care do not track your phone
These apps display vehicle positions that are reported by tracking hardware fitted to vehicles. They do not collect location from the device they are installed on, in the foreground or the background. They request no location permission for tracking purposes.
What the apps do send us
| Information | Why |
|---|---|
| Your username and password at sign-in | To authenticate you. Passwords are stored only as an Argon2 hash and are never recoverable. |
| Device model or name, platform, app version | So you can recognise and sign out your own devices, and so we can support the versions actually in use. |
| A push notification token | To deliver alerts you or your administrator have configured. It identifies an app installation, not a person or a location. |
| IP address of requests | Security: rate limiting, detecting brute-force attempts, and showing you where a session was last used. |
If we later publish a VTS Driver application that uses a phone as the tracking device, that app will collect location in the background. It will be a separate application with a separate listing, it will ask for that permission explicitly with an in-app explanation before the system prompt, and this policy will be updated before it is released. No existing app will begin collecting location through an update.
3. What the platform holds
3.1 Vehicle and telemetry data
Position, speed, heading and time from tracking units; ignition state, fuel level, odometer, CAN bus readings and sensor values where the hardware reports them; trips, stops, geofence entries and exits derived from those readings; alarms raised by the device.
3.2 Driver and assignment data
Driver names and identifiers entered by our customer, and the record of which driver was assigned to which vehicle over time. This information is supplied by the employer, not collected by us from the individual.
3.3 Account data
Username, display name, email address, role and the company the account belongs to, as entered by the administrator who created it.
3.4 Security and audit records
We keep an append-only audit log of administrative actions — who created, changed or deleted a record, and when — together with successful and failed sign-in attempts and the addresses they came from. This is deliberately not editable, including by us, because its purpose is to answer questions about what happened to a record after the fact.
4. Why we process it
| Purpose | Basis |
|---|---|
| Providing the tracking service our customer has contracted for | Performance of a contract, and our customer's own lawful basis as employer |
| Delivering alerts and scheduled reports | Performance of a contract |
| Securing accounts and investigating misuse | Legitimate interests |
| Meeting statutory and regulatory obligations | Legal obligation |
We do not sell personal information. We do not use it for advertising, profiling unrelated to the service, or training third-party models.
5. Who can see it
Access follows the account hierarchy. A company sees its own vehicles, drivers and users; a partner company that manages it can see the accounts beneath it; no account can see a company that is not beneath it in that hierarchy. Individual users may additionally be restricted to named vehicles.
Our own staff access customer data only where necessary for support, maintenance or investigating a fault, and such access is subject to the audit record described in section 3.4.
6. Third parties and where data goes
The platform is deliberately built to keep data on our own infrastructure.
- Map tiles and address lookup are self-hosted. Both the map imagery and the reverse-geocoding that turns a coordinate into a street name run on our own servers, so viewing a vehicle does not disclose its position to a mapping provider.
- Google Firebase Cloud Messaging delivers push notifications. The notification text and a push token are transmitted to Google for delivery to your handset. If you turn notifications off, nothing is sent.
- Email and messaging destinations you configure. Where an administrator configures an email address, webhook or messaging channel to receive alerts, the alert content is sent to that destination on their instruction.
Data is processed on servers operated for FUTURE TELEMATICS PRIVATE LIMITED. Where data is transferred across borders, it is transferred under appropriate contractual safeguards.
7. How long we keep it
| Record | Retained |
|---|---|
| Vehicle positions and telemetry | 24 months, after which whole months are removed |
| Trips, stops and derived summaries | 24 months |
| Audit and sign-in records | 24 months |
| Mobile sessions | Up to 90 days, or 60 days without use, or until signed out |
| Push tokens | Until notifications are turned off, the app is removed, or the session ends |
| Account records | For the life of the account, then removed on the customer's instruction |
| Encrypted backups | Rolling, and expire on their own schedule |
8. Security
Traffic to the platform is encrypted in transit. Passwords are stored as Argon2 hashes. Mobile refresh credentials are stored only as a SHA-256 hash, so a copy of our session table cannot be used to sign in as anyone. Repeated failed sign-ins are rate-limited per account and per address. Administrative functions are reachable only from a separate address that customer accounts cannot use.
No system is perfectly secure. If we become aware of a breach affecting personal information, we will notify affected customers without undue delay.
9. Your rights
You may ask for a copy of the personal information we hold about you, ask for it to be corrected, ask for it to be deleted, or object to particular processing.
If you are a driver or employee, the vehicle and driver records in your employer's account belong to your employer. Please raise such requests with them first — we will assist them in responding, but we cannot alter or release their records on our own initiative.
Deleting your account. Accounts on this platform are created and removed by your organisation's administrator, not through self-service sign-up in the app. To have an account removed, contact your administrator or write to us at the address below and we will act on your organisation's instruction.
10. Children
The platform is a business tool and is not directed at children. We do not knowingly collect information from anyone under 18.
11. Changes to this policy
We will update this page when our practices change, and will change the date at the top. Material changes affecting how personal information is collected — in particular any new collection of location from a mobile device — will be notified to customers before they take effect.
12. Contact
FUTURE TELEMATICS PRIVATE LIMITED
CIN U62099PN2026PTC258385
Privacy enquiries: info@future-telematics.me
Telephone: +91 88790 46008