Legal
Privacy notice
Last updated 27 September 2026
We hold driver records because carriers are required to keep them. This is what we hold, why, and who else can see it.
1. Who we are, and who this is about
Ledger Road and Fleet Files are operated from France. It is published by Staunch Digital, SIREN 898 721 865. Because we are established there, European data protection law applies to what we do with personal data, wherever our customers are and wherever the data is stored.
This notice covers Ledger Road and Fleet Files, including the Fleet Files iPhone and iPad app, its browser team portal, and the drivers whose records our customers keep in either service. For account data we decide what is collected and why. For driver records the carrier decides, and we hold and process them under their instructions.
2. What we hold
- Account data
- Names, work email addresses and roles for the people you invite. Used to sign them in and to record who did what.
- Driver records
- The personal data a compliance file requires: dates of birth, licence numbers and states, medical certificate details, and the documents you upload. Driver personal details are encrypted before storage, and the documents are encrypted in storage and in transit.
- Vehicle and inspection records
- Units, inspections, defects, maintenance and roadside events, with the signatures attached to them.
- Drug and alcohol testing records
- In Ledger Road, held separately from the rest of your account, behind an access grant given per person, with every access logged. These are never included in a general export.
- Technical data
- Sign-in times, IP addresses and audit entries, kept so a change to a compliance record can be attributed to somebody.
Fleet Files app and browser access
Fleet Files also processes company settings, team invitations and roles, assigned trucks, uploaded photos and PDFs, document review decisions, inspection signatures, and subscription transaction identifiers and status. When enabled, device tokens are used to deliver notifications. Apple processes App Store payments; we receive purchase and renewal information to verify access, not your full payment-card details.
Document text recognition in the iPhone and iPad app runs on your device. The documents and details you choose to save are uploaded to your company's workspace for storage and synchronisation. The app keeps local records for offline use. The browser portal uses a necessary session cookie to keep invited users signed in. Company owners and admins manage records and review driver submissions; drivers have access limited to their own files and assigned trucks. Browser access does not make company records public. The advertising tags described below do not run inside the Fleet Files app or its team portal.
Fleet Files hazmat records
When your company uses Hazmat Records, we also process haul dates, linked drivers and trucks, shipping names, UN/NA identifiers, hazard classes, placarded status, shipping papers and other uploaded supporting documents. Employee records may include names and job functions of people who are not drivers, training evidence and dates. We also process endorsement, registration and permit documents and dates, submission review decisions and notes, and add-on subscription status. Uploaded documents may contain other personal information that you choose to include.
We use these records to organise haul files, provide applicable reminders, synchronise authorised app and browser access, support office review and produce exports. Owners and admins manage company records; drivers have access to their own haul records and associated shipping papers within their assigned permissions. Non-driver employee training records are limited to office users. The same storage, security and service-provider arrangements described in this notice apply.
If only the Hazmat Records add-on expires, existing records remain available to authorised users to view and export, and to delete where their role permits, while the base subscription stays active. Specialised hazmat training and registration reminders stop. Add-on expiration alone does not trigger the ninety-day deletion period; existing storage limits, over-plan rules and deletion requests still apply. The retention period below starts when base-subscription access ends, and an active hazmat add-on does not extend it.
3. Why we hold it
To run the service: to keep the records our customers must keep, to warn them before something expires, to produce an export when they ask for one, and to be able to say who changed a record and when.
We do not sell personal data, and we do not use customer records to train machine learning models.
We do advertise, and that means a visitor to our marketing pages is measured. A Google Ads tag runs on this website, and on the single page of the console you reach immediately after paying, to tell us which adverts lead to a subscription. It sends Google the address of the page you opened along with your IP address and browser. It does not run on any screen holding driver records, and nothing about your drivers reaches an advertiser.
We also count visits to our marketing pages using software we run on our own server. It records which page was opened, roughly where in the world the visit came from and which site linked here. It sets no cookies, it does not follow you between websites, and the figures it produces cannot be traced back to a person. Nothing about it leaves our server, and it does not run on any screen of the console.
4. Drug and alcohol testing records
In Ledger Road, these are treated differently from everything else. Reaching them takes an access grant given to a named person, every access is written to a log, and they are excluded from general exports by how the software is built rather than by policy.
In Fleet Files, the restricted drug/alcohol-policy and Clearinghouse document categories are accessible to owners and admins and are excluded from driver access. Fleet Files does not provide Ledger Road's separate per-person access-grant workflow for confidential testing records. Only upload information your organisation is authorised to hold and share with those roles.
5. Who else sees it
A small number of companies help us run the service. They act on our instructions, cannot use your data for their own purposes, and are bound by contract to protect it.
| Company | What they do |
|---|---|
| Cloudflare, Inc. | Delivers the service, stores the documents you upload, and holds our backups. |
| Stripe, Inc. | Takes payment. Stripe receives your billing details and the number of power units on your plan. It never receives driver records. |
| Infrastructure hosting | Runs the servers the service is delivered from. Named on request under a confidentiality agreement. |
We will give at least 30 days' notice before adding a company to this list. Your data is stored and processed in the United States.
The providers above apply where used by the relevant service: Stripe processes Ledger Road payments, while Fleet Files App Store payments are handled by Apple under Apple's privacy policy. Fleet Files uses Resend to deliver sign-in codes and team invitations; it receives the recipient's email address and the message contents. When push notifications are enabled, Apple's notification service receives a device token and notification content. Purchasing Fleet Files does not automatically link your records to a separate Ledger Road account.
6. How long we keep it
While your account is open and within its allowances, we keep your records for as long as you keep them. That is deliberate: most of this material is subject to federal retention periods that belong to you, not to us, and deleting a driver file on our own schedule could take away something you are required to produce.
For both Ledger Road and Fleet Files, we retain your company's files and records for three months, defined in this policy as ninety days, after the base subscription lapses. The period starts when paid access ends, not when you turn off renewal. During that period, records remain available for export by authorised users, even though paid editing and other subscription features may be unavailable. After that we delete them, except where we are required to keep specific information longer. You can ask us to delete sooner. Renewing the base subscription before the deadline stops deletion due to that lapse; an add-on alone does not extend this period.
Audit entries and sign-in records are kept for as long as the records they describe, since an audit trail with holes in it is not an audit trail.
This service-retention period does not replace your own legal recordkeeping duties. Export the files you need before the deadline. Required billing or legal records may be retained separately for the applicable obligation. Deleted data may remain in restricted backups until those backups expire under their rotation; backups are not an extension of the customer export window. Copies you export or keep on an offline device are under your control and cannot be remotely recalled immediately.
Fleet Files registrations that never subscribe
Unverified registrations are deleted thirty days after account creation. Registrations with a verified email that never start a base subscription or trial are deleted thirty days after email verification. Later sign-ins do not reset these periods. No warning or deletion-confirmation email is sent for this cleanup. We remove saved setup and personal account details, revoke access and release the email for reuse. Limited anonymised account markers and security audit records may remain, and restricted backups expire through normal rotation. We may defer cleanup while checking billing history or unexpected records; test and review accounts may be excluded.
Free trials count as subscription access. Accounts with previous subscription, trial or support-granted access instead follow the ninety-day process after that access ends, including its warning notices and safeguards. These registration rules apply to Fleet Files, not Ledger Road accounts.
Fleet Files records beyond plan allowances
While a Fleet Files base subscription remains active, excess trucks, drivers and storage are subject to a separate ninety-day resolution window from when we record the excess. The most recently added trucks and drivers beyond the allowance become view-only. We notify the owner and allow time to increase capacity or export and remove excess data. After the window and at least seven days after a final warning, we may delete paused trucks and drivers, their linked records and files, and related driver logins. If storage remains over its allowance, abandoned uploads are removed first, then documents starting with the newest, including documents on retained trucks or drivers. Inspection reports are not selected solely to reduce storage. Returning within all allowances ends this window. See the Fleet Files over-plan terms for details.
7. Your rights
Depending on where you are, you may have the right to ask what we hold about you, to have it corrected, or to have it deleted. Write to us and we will respond within the time the law allows.
If you are a driver whose records a carrier keeps in Ledger Road or Fleet Files, ask the carrier first: the records are theirs to control, and we will pass your request to them.
If you think we have handled your personal data badly, tell us first and we will try to put it right. You can also complain to our supervisory authority, the CNIL (Commission Nationale de l'Informatique et des Libertés), which oversees us because the company is established in France.
8. Security
In Ledger Road, access is limited to the people a customer invites. Driver names, dates of birth, licence numbers, licence state and employment dates are encrypted before they are written to storage, so a copy of the database is not a copy of every driver's personal details. Documents you upload are encrypted in storage and in transit. Changes to compliance records go to an append-only audit trail. Drug and alcohol testing records sit behind a separate access grant with every access logged.
Fleet Files encrypts saved record contents on the server and limits access by company and role. Browser sessions use protected sign-in cookies; local iPhone and iPad data uses the device's data-protection features. You should protect any device or exported copy that contains company records.
We hold no security certification today. If we obtain one we will say so here, and we would rather list what we actually do than imply an audit we have not had.
9. If something goes wrong
If personal data we hold is breached, we will tell affected customers without undue delay once we understand what happened, along with what we know and what we are doing about it.
10. Changes
We may update this notice. The date at the top says when it last changed, and we will tell customers directly about changes that matter.
11. Contact
Privacy questions go to our contact page.