Preview — sample data · d980d21

Review draft — not approved or in force.

Kentrak Privacy Policy

DRAFT FOR REVIEW — not published or legally approved. Prepared 29 September 2026. Effective date: [to be approved]. Bracketed items must be resolved before publication. Read with the review notes.

Who we are

Kentrak — ABN 52 393 434 873. “We”, “us” and “our” refer to Kentrak.

This policy explains how we handle personal information when providing the Kentrak vehicle-tracking app at kentrak.app and associated support. Location records can reveal a person's movements even when a record names only a vehicle. If your employer, fleet operator or another person manages your vehicle access, that organisation may also handle your information under its own privacy arrangements. Ask it who can see your vehicle and why it is tracked. This policy does not replace its obligations or notices.

Information we collect and where it comes from

We collect information you provide, information provided by the person administering your account or vehicle, and information sent by assigned trackers or service providers:

Please avoid adding unrelated personal or sensitive information to journey purposes, notes, uploads or support requests. Tracking information comes primarily from the vehicle's tracker, rather than continuous background tracking of your phone.

Why we use information

We use information to authenticate users, apply vehicle permissions, receive and display tracker reports, calculate journey and distance estimates, maintain records, provide requested sharing and reminders, investigate faults, protect accounts, manage support and administer the service. Billing information supports the billing functions actually offered. We may also retain or disclose information where required or authorised by law, including handling disputes or lawful requests.

Providing an account email and necessary vehicle/tracker information is needed to use the corresponding service. Optional vehicle fields and uploads can be left blank. Disabling phone notifications prevents delivery to that browser; it does not stop vehicle tracking. If essential information is unavailable, some functions may not work. You can make a general enquiry without supplying vehicle locations where those details are unnecessary.

[Confirm before publication: whether any information is used for direct marketing, advertising, analytics unrelated to service operation, data sales or other secondary purposes. Add the actual practice and any required choices; these purposes are not authorised by this draft.]

Who can see or receive information

Vehicle information is accessible to users granted access to that vehicle and to authorised administrators for administration and support. Vehicle owners have additional management controls. Installer access is restricted; administrator and installer permissions are not the same as an ordinary driver's. Reassigning a tracker does not move earlier journeys to the new vehicle.

If a user creates a live sharing link, anyone with that link can view the shared vehicle name, reported position, report time and expiry while it is valid, without signing in. They can forward it. Stop the link when it is no longer needed. Stopping access cannot recall screenshots, downloaded information or one-time positions already sent. Exports and receipts can contain information about other people; share them carefully.

Service providers receive information needed for the function they supply:

Provider or categoryPurpose and relevant information
DigitalOceanHosts the application and its stored service data; the documented application server is in Sydney.
Google DriveSeparate backup copies have been made to private operator-controlled Drive storage. Backups can contain account, vehicle and location records.
OpenStreetMap map servicesMap requests reveal the displayed map area and ordinary connection information such as IP address. This also applies to shared maps.
Simbase and mobile network providersTracker connectivity, SIM administration and supported SMS operations; identifiers, usage and message details needed for those services.
Resend and email delivery providersAccount recovery and other enabled service emails, including recipient address and message content.
Browser/operating-system push providersDeliver notifications using subscription routing information. Alert content may be displayed on a phone's lock screen.
OpenAIAdministrator troubleshooting prompts, relevant account/vehicle diagnostic context and, if used, voice audio for transcription. Customer accounts cannot open the administrator assistant.
StripeTest checkout/portal and billing reconciliation in the current sandbox. A live payment service requires an updated disclosure before launch.

These providers may operate or use support/subprocessors outside Australia. [Complete the verified countries and applicable provider arrangements before publication, including backup, email, AI, push, mapping, mobile and any live payment processing.] A Sydney application server does not mean all information remains in Australia. We do not treat acceptance of this policy as a blanket waiver of privacy rights concerning overseas disclosures. Provider access and retention must be considered separately from Kentrak's own settings.

Privacy controls, cookies and device choices

The app uses sign-in cookies and browser storage for functions such as session security and map preferences. Browser push requires permission. Administrator voice dictation requires microphone permission. [Confirm any separate marketing website cookies or analytics before extending this policy to that site.]

Under Vehicle → Location privacy, an authorised person with the vehicle privacy PIN can pause new recording. Supported trackers also offer Hide location, keep kilometres, which records an aggregate distance estimate without a private route. Privacy mode continues until explicitly resumed. It does not delete earlier history; the last recorded position can remain visible to authorised users and through existing sharing links. Tracker contact can still update. It does not control the tracker's own memory, mobile-provider records or independently sent SMS. Choosing “Private” as a journey category does not activate location privacy.

Storage, retention and deletion

We use access controls, password verification protections, HTTPS for the web app, administrative restrictions and backups. No system can guarantee that every security incident will be prevented. Tracker communication protections depend on the device and protocol; we do not claim that every tracker transmission is end-to-end encrypted.

Current behaviour: historical locations and original packet evidence are preserved, including in compressed archives. Moving older records into an archive is not deletion or anonymisation. Routine diagnostic logs are subject to cleanup, but this does not remove the underlying journey evidence. Geofence evidence and administrator conversation records also have no general automatic deletion deadline. Removing a vehicle from the active list archives it and preserves history. Backups can retain information after it is no longer visible in the app; separate Drive copies are not automatically removed by local backup rotation.

[Publication decision required: approve a justified retention schedule and a working deletion/de-identification process covering active data, archives, uploads, audit/support records, backups and provider copies. Specify any legal holds and expiry periods. No deletion deadline is promised by this draft.]

Contact us to request account closure or deletion. We will assess the request, verify authority proportionately and explain what can be removed, what must be retained and why. A request does not itself switch off a physical tracker or erase copies already shared with others. The app does not currently offer a general self-service account-and-history erasure function.

Access, correction and complaints

Contact [privacy contact] to request access to or correction of personal information about you, or to make a complaint. You need not be the fleet account owner to contact us about your own information. Give enough detail to locate the issue, but do not send passwords, privacy PINs or setup links. We may need to verify identity and protect other people's information before providing records. If we cannot fulfil a request, we will explain the reason and available next steps, subject to applicable law.

[Approve an operational complaint procedure and response target; proposed target: respond within 30 days.] If a complaint remains unresolved, you may contact the Office of the Australian Information Commissioner where it has jurisdiction, or another appropriate regulator. See OAIC privacy complaints.

Where an incident triggers applicable breach-notification obligations, we will notify affected individuals and the appropriate regulator as required. [Confirm Privacy Act coverage and the incident-response owner before publication.]

Changes

We will date the published policy and explain material changes through an appropriate service notice. A policy change does not retrospectively authorise unrelated new uses of information or replace any consent required by law.

Document version: draft-2026-09-29-2f3418d0b3ddabe32528614230460b26fd2e1a2961374fa3ac5dd7f640770596