Privacy Policy
- Who We Are
- Scope of This Policy
- The Data We Collect
- How We Collect Your Data
- Legal Bases for Processing (including Criminal Offence Data)
- How We Use Your Data
- Data Sharing and Disclosure
- International Data Transfers
- Data Retention
- Your Rights Under UK GDPR
- Our Role as Processor and Fleet Operator Responsibilities
- Cookies and Tracking Technologies
- Security
- Children
- Third-Party Links
- Changes to This Policy
- How to Contact Us
1. Who We Are
APFleet is a fleet management and compliance service operated by Auto Princess Ltd, a company registered in England and Wales (Company Number: 17155826), whose registered office is at 71-75 Shelton St, London WC2H 9JQ ("we", "us", "our").
Auto Princess Ltd is registered with the Information Commissioner's Office (ICO) as a data controller under registration number 00014589025. Our data protection contact is reachable at [email protected].
For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018):
- Auto Princess Ltd is the data controller for personal data relating to account holders, billing contacts, and platform usage;
- Auto Princess Ltd acts as a data processor on behalf of fleet operators (our customers) in respect of personal data relating to their drivers and employees held within the APFleet platform.
This distinction is important. Where we act as a processor, the fleet operator is the controller, the fleet operator's own privacy obligations apply to its use of driver data, and our Data Processing Agreement (DPA), incorporated into our Terms of Service, governs that relationship. Section 11 explains this in more detail.
Where you are a fleet operator or your business is established in, or you offer the service to drivers in, the European Economic Area (EEA), the EU GDPR may also apply. In that case, our EU representative appointed under Article 27 EU GDPR is: EU Representative Name, Address, Email. If you have no EEA establishment or drivers, this paragraph does not apply.
2. Scope of This Policy
This Privacy Policy applies to:
- The APFleet web application accessible at apfleets.com and any associated subdomains, including app.apfleets.com;
- The APFleet mobile application for iOS and Android;
- All related services, APIs, and integrations provided by Auto Princess Ltd under the APFleet brand.
This Policy primarily serves our customers — the fleet owners and managers who hold APFleet accounts — and explains both the data we control about them and the role we play as processor of their drivers' data. If you are a driver invited to APFleet by a fleet operator, the controller of your data is your employer or engaging operator; please refer to their privacy notice in the first instance, and see Section 11.
This Policy does not apply to the main Auto Princess website at www.autoprincess.com or the consumer Auto Princess app, which are governed by their own privacy notice, nor to third-party services we integrate with (such as GaragePlus or the DVLA), which have their own privacy policies.
By creating an account or using APFleet, you confirm that you have read and understood this Policy. If you do not agree, you must not use the service.
3. The Data We Collect
We collect and process the following categories of personal data. Where data relates to third parties (such as drivers), the fleet operator is responsible for ensuring those individuals have been informed appropriately and that an appropriate lawful basis and, where relevant, an Article 10 condition is in place (see Sections 5 and 11).
3.1 Account and Identity Data
- Full name, email address, and password (hashed — never stored in plain text);
- Business name and role (fleet owner, fleet manager);
- Phone number (optional, used for account recovery);
- Account preferences and notification settings;
- Authentication method (email/password or Google OAuth).
3.2 Vehicle and Fleet Data
- Vehicle registration marks (number plates) submitted by you;
- Vehicle details retrieved via the DVLA lookup API: make, model, year of manufacture, fuel type, MOT expiry, vehicle tax status, colour, engine capacity, and CO₂ emissions;
- Service history and maintenance records entered manually by fleet managers;
- OBD (on-board diagnostics) fault-code data where the OBD sync feature is enabled (Fleet Pro tier). The OBD sync feature transmits diagnostic trouble codes and related vehicle sensor data; it does not transmit continuous real-time location or driver behaviour telematics unless separately enabled and disclosed to you;
- Defect reports, including written descriptions and photographs uploaded by drivers;
- Compliance alert history and dismissal records;
- Garage booking records via the GaragePlus integration.
3.3 Driver and Personnel Data
This data is entered by fleet owners or managers on behalf of their drivers, or submitted by drivers themselves. Auto Princess Ltd processes this data as a data processor on the fleet operator's instruction.
- Driver full name and contact details (email address, phone number);
- Driving licence number and licence validity status (see the important note below regarding criminal offence data);
- Vehicle assignment records;
- Defect reports submitted by the driver, including any GPS metadata embedded in photographs where present. Where technically feasible, location (EXIF) metadata is not extracted or used by us for any purpose beyond storing the photograph as submitted; fleet operators should be aware that submitted images may contain such metadata;
- Invitation acceptance records.
3.4 Usage and Technical Data
- IP address, browser type, and operating system;
- Device identifiers (mobile devices);
- Login timestamps and session duration;
- Pages and features accessed, click paths, and error logs;
- Firebase Authentication and Firestore access logs (retained by Google Cloud per their terms).
3.5 Payment and Billing Data
- Billing contact name and email address;
- Invoice history and subscription tier (Solo, Business, Fleet Pro);
- Payment card details — we do not store card numbers. Card data is handled exclusively by our payment processor, Stripe, and is subject to its PCI-DSS obligations;
- VAT number (where provided).
3.6 Communications Data
- Content of emails or support messages sent to us;
- Records of any disputes or complaints raised.
3.7 Special Category Data
We do not intentionally collect special category data (such as health, biometric, or racial/ethnic data) under Article 9 UK GDPR through APFleet. Criminal offence data under Article 10 is addressed above and in Section 5. Fleet operators must not upload special category data into free-text fields without an appropriate lawful basis and Article 9 condition.
4. How We Collect Your Data
- Directly from you — when you register, complete your profile, add vehicles, create driver records, or contact us;
- From the DVLA — when you submit a vehicle registration mark, we query the DVLA's Vehicle Enquiry Service API on your behalf, and the data returned is stored within your fleet account;
- From drivers — when a driver accepts an invitation, submits a defect report, or updates their profile via the mobile app;
- Automatically — through cookies, Firebase Analytics, and server logs when you interact with the web or mobile application;
- From Google — if you choose to sign in with Google OAuth, we receive your name and email address from Google's authentication service;
- From OBD devices — where the OBD sync feature is enabled, fault-code data is transmitted from the vehicle to our platform via the connected device.
5. Legal Bases for Processing
Under Article 6 of the UK GDPR, we rely on the following legal bases:
| Purpose | Legal Basis |
|---|---|
| Creating and managing your account | Performance of a contract (Art. 6(1)(b)) |
| Providing the APFleet platform and its features | Performance of a contract (Art. 6(1)(b)) |
| Processing payments and generating invoices | Contract; Legal obligation (Art. 6(1)(b) and (c)) |
| Sending compliance and expiry alerts | Performance of a contract (Art. 6(1)(b)) |
| Maintaining security and preventing fraud | Legitimate interests (Art. 6(1)(f)) |
| Improving and developing the platform | Legitimate interests (Art. 6(1)(f)) |
| Service communications (downtime, material changes) | Contract / Legitimate interests (Art. 6(1)(b) and (f)) |
| Marketing communications (where opted in) | Consent (Art. 6(1)(a)) |
| Compliance with legal and regulatory obligations | Legal obligation (Art. 6(1)(c)) |
| Processing driver data on behalf of fleet operators | Under controller's instruction (Art. 28); operator's basis applies |
Where we rely on legitimate interests, we have conducted a balancing test (a Legitimate Interests Assessment) to confirm that our interests do not override your rights and freedoms. You may request a summary by contacting us.
Where we rely on consent (for example, marketing emails), you may withdraw that consent at any time by emailing [email protected] or clicking the unsubscribe link in any marketing communication. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
5.1 Criminal Offence Data (Article 10)
Where licence data processed through APFleet includes penalty points, endorsements, disqualifications, or other criminal offence data, the fleet operator (as controller) must identify a condition for processing under Schedule 1 DPA 2018 — typically the condition relating to processing necessary for reasons of substantial public interest, or the legal-obligation or employment conditions — and must maintain an Appropriate Policy Document as required by paragraph 5 of Schedule 1. As processor, Auto Princess Ltd processes such data strictly on the operator's documented instructions, applies the access controls described in Section 13, and does not use it for its own purposes.
6. How We Use Your Data
- Account provision: creating and authenticating your account; managing your subscription; providing customer support;
- Platform services: enabling DVLA lookups; generating compliance alerts; managing vehicle, driver, and defect records; facilitating GaragePlus garage bookings; providing AI diagnostic functionality (see Section 7.1 for how AI processing works);
- Billing: processing subscription payments; generating and storing invoices; handling cancellations and refunds;
- Communications: sending alert notifications, service updates, and security notices. With your consent, we may also send promotional communications about APFleet and Auto Princess products;
- Safety and security: detecting, investigating, and preventing fraudulent transactions, abuse, or unauthorised access to accounts;
- Legal compliance: retaining records as required by HMRC, Companies House, or other regulatory bodies; responding to lawful requests from authorities;
- Product improvement: analysing aggregated, anonymised usage patterns to improve platform performance and develop new features.
We do not use individual driver data for profiling or automated decision-making that produces legal or similarly significant effects on the driver. Compliance alerts (such as MOT or licence expiry warnings) are automated but are informational notifications to fleet managers; they do not themselves make a decision about a driver. We will not use your personal data for any purpose incompatible with those listed above without first notifying you and, where required, obtaining consent.
7. Data Sharing and Disclosure
We do not sell, rent, or trade personal data. We share data only in the following circumstances:
7.1 Service Providers (Data Processors and Sub-Processors)
We engage trusted third-party providers who act on our documented instructions and are bound by data processing terms. Where we act as a processor for fleet operators, these are our sub-processors, and our DPA sets out how we notify you of, and allow you to object to, changes to our sub-processors.
- Google Cloud Platform / Firebase — cloud infrastructure, database hosting (Firestore), authentication, and storage, hosted in the europe-west2 (London) region. Google LLC relies on the UK Extension to the EU–US Data Privacy Framework and/or Standard Contractual Clauses for transfers outside the UK, where applicable;
- Stripe (Stripe Technology Europe Limited) — payment processing and subscription management;
- Google (Gemini AI) — the APFleet AI diagnostic functionality is powered in part by Google's Gemini API. Relevant vehicle and diagnostic data is transmitted to Google for inference purposes under Google's API data processing terms. We do not permit this data to be used to train Google's own general-purpose models, and we do not transmit personal data to this service beyond what is necessary to generate a diagnostic result;
- GaragePlus — garage network platform. When you initiate a garage booking, the relevant vehicle registration, contact details, and fault description are shared with GaragePlus to facilitate the booking;
- SendGrid and Firebase Cloud Messaging — transactional email and push notification delivery.
7.2 The DVLA
Vehicle registration lookups are performed against the DVLA's Vehicle Enquiry Service API. Data is retrieved from, not shared with, the DVLA. Use of that data is subject to the DVLA's API terms, which prohibit certain downstream uses (see Section 11 of our Terms of Service).
7.3 Fleet Operators
If you are a driver using APFleet at the invitation of a fleet operator, that operator (your employer or contracting party) can access the data you submit through the platform, including defect reports, vehicle assignment records, and your driver profile. This is the intended purpose of the service. Refer to your employer's privacy notice for further information about how they use your data as controller.
7.4 Legal and Regulatory Disclosure
We may disclose personal data to law enforcement agencies, courts, regulators, or other authorities where we are legally required or permitted to do so, including in connection with legal proceedings, court orders, or to protect the rights, property, or safety of Auto Princess Ltd, our users, or the public.
7.5 Business Transfers
In the event of a merger, acquisition, sale of assets, or restructuring of Auto Princess Ltd, personal data may be transferred to the successor entity. We will notify affected users by email and/or prominent in-platform notice before any transfer occurs, and we will ensure the successor is bound by terms no less protective than this Policy. Where we act as processor, any such transfer will comply with our DPA obligations to fleet operators.
8. International Data Transfers
APFleet is operated from the United Kingdom. Some of our service providers (notably Google Cloud/Firebase) operate infrastructure in the United States and other jurisdictions. Where personal data is transferred outside the UK, we ensure an appropriate safeguard is in place in accordance with Chapter V of the UK GDPR and the ICO's guidance on international transfers. These safeguards include:
- Adequacy regulations — transfers to countries granted adequacy status by the UK Government;
- UK International Data Transfer Agreements (IDTAs), or the EU Standard Contractual Clauses with the UK Addendum, where no adequacy decision applies;
- The UK Extension to the EU–US Data Privacy Framework — where applicable to certified US-based processors.
You may request a copy of the relevant transfer mechanism by contacting [email protected].
9. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, or as required by law. For driver and fleet data where we act as processor, retention is determined by the fleet operator's instructions under our DPA; the periods below are our defaults where we act as controller or where the operator has not specified otherwise.
| Category | Retention Period | Basis |
|---|---|---|
| Account data (active accounts) | Subscription + 7 years | Contract; HMRC financial records |
| Account data (deleted accounts) | 90 days from request, then purged | Re-activation; then legal obligation |
| Vehicle and compliance records | Subscription + 3 years | Contract; potential liability period |
| Defect reports (incl. photographs) | Per operator instruction; default 5 years | Operator compliance; Road Traffic Act |
| Driver records | Per operator instruction (processor) | Controller-determined under DPA |
| Invoices and payment records | 7 years from invoice date | HMRC VAT requirement |
| Security and access logs | 12 months | Security monitoring |
| Marketing consent records | Until withdrawn + 3 years | PECR; proof of consent |
At the end of the applicable retention period, data is securely deleted or anonymised. Anonymised aggregate data (with no re-identification risk) may be retained indefinitely for product analytics. You may request early deletion, subject to the exceptions in Section 10.
10. Your Rights Under UK GDPR
As a data subject, you have the following rights under the UK GDPR and DPA 2018. These apply to data for which Auto Princess Ltd is the controller. Where we act as a processor (for driver data held on behalf of a fleet operator), please direct requests to the fleet operator in the first instance; we will assist them in responding as required by our DPA.
| Right | What it means |
|---|---|
| Access (Art. 15) | Confirmation we process your data and a copy of it, with supplementary information. |
| Rectification (Art. 16) | Have inaccurate personal data corrected without undue delay. |
| Erasure (Art. 17) | Request deletion where a specified ground applies. Not absolute — some data is retained for legal or contractual reasons. |
| Restriction (Art. 18) | Request that we limit how we use your data in certain circumstances. |
| Portability (Art. 20) | Receive your data in a structured, machine-readable format and transmit it elsewhere, where automated and based on consent or contract. |
| Object (Art. 21) | Object to processing based on legitimate interests or to direct marketing. We stop marketing immediately, without exception. |
| Automated decisions (Art. 22) | Not to be subject to solely automated decisions with legal or similar effects. APFleet does not make such decisions. |
| Withdraw consent | Where processing is based on consent, withdraw it at any time, without affecting prior processing. |
To exercise any of these rights, submit a written request to [email protected]. We respond within one calendar month of receipt, extendable by two further months for complex or numerous requests, with notice. We may ask you to verify your identity. There is no charge in most circumstances; where requests are manifestly unfounded or excessive, we may charge a reasonable administrative fee or refuse.
10.1 Right to Complain
If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Helpline: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
We would welcome the opportunity to address your concerns directly first — please contact us at [email protected].
11. Our Role as Processor and Fleet Operator Responsibilities
APFleet enables fleet operators to manage and monitor their drivers and vehicles. Where APFleet processes personal data about drivers, Auto Princess Ltd is the data processor and the fleet operator is the data controller. This section explains what that means and what your responsibilities are as a fleet operator.
11.1 Our Obligations as Processor
As processor, and as set out in our Data Processing Agreement, we: process driver data only on your documented instructions; ensure persons authorised to process the data are bound by confidentiality; implement appropriate technical and organisational security measures (Section 13); engage sub-processors only under written terms and with notice to you; assist you in responding to data subject rights requests and with your security, breach-notification, and DPIA obligations; and delete or return driver data at the end of the service, subject to legal retention requirements.
11.2 Your Responsibilities as Fleet Operator (Controller)
As controller of your drivers' data, you are responsible for:
- Providing your drivers with a privacy notice explaining how you use their data, including the fact that you use APFleet;
- Identifying and documenting a lawful basis for processing driver data, and, where licence data includes penalty points, endorsements, or disqualifications, an Article 10 condition under Schedule 1 DPA 2018 and an Appropriate Policy Document;
- Carrying out a Data Protection Impact Assessment (DPIA) where required — the ICO considers that monitoring of workers, and processing of criminal offence data, may require a DPIA;
- Ensuring any monitoring of drivers through APFleet (such as defect reporting, vehicle assignment, or OBD data) is necessary, proportionate, and transparent to those drivers, consistent with the ICO's guidance on monitoring workers;
- Responding to your drivers' data subject rights requests as controller (we will assist as described above);
- Not uploading special category data or excessive personal data into free-text fields without an appropriate basis.
12. Cookies and Tracking Technologies
APFleet uses cookies and similar technologies to operate the platform and improve your experience. We use the following categories:
- Strictly necessary cookies: required for authentication (Firebase session cookies), security (CSRF protection), and core functionality. These cannot be disabled without breaking the service;
- Analytics cookies: Firebase Analytics collects anonymised usage data (page views, feature usage, error rates). These can be disabled in your account settings, and non-essential analytics are set only with your consent where required;
- Preference cookies: store your UI preferences (such as notification settings).
We do not use third-party advertising or tracking cookies, and we do not share cookie-derived data with advertising networks. You can manage or delete cookies through your browser settings, though disabling strictly necessary cookies will prevent you logging in. This Policy, together with your consent settings, constitutes our cookie notice in compliance with the Privacy and Electronic Communications Regulations 2003 (PECR), as amended.
13. Security
We implement technical and organisational measures appropriate to the risk presented by our processing, including:
- Encryption of data in transit using TLS 1.2 or higher;
- Encryption of data at rest within Google Cloud Firestore and Cloud Storage;
- Role-based access controls enforced at the Firestore security-rules layer, ensuring fleet data is accessible only to authorised users within that fleet;
- Passwords hashed using Firebase Authentication; we never store or transmit passwords in plain text;
- Multi-factor authentication available to all account holders (recommended for fleet owners);
- Periodic security reviews and testing of the platform;
- Access to production data limited to authorised Auto Princess Ltd personnel on a need-to-know basis.
No transmission over the internet or method of electronic storage is fully secure, and we cannot guarantee absolute security. In the event of a personal data breach likely to result in a risk to rights and freedoms, we will notify the ICO within 72 hours and, where required, affected individuals without undue delay. Where we act as processor, we will notify the affected fleet operator without undue delay so that they can meet their own breach obligations as controller. To report a suspected vulnerability, contact [email protected].
14. Children
APFleet is a business-to-business service intended for commercial fleet operators and their employees. It is not directed at, and we do not knowingly collect personal data from, anyone under the age of 18. If you believe a person under 18 has provided personal data to us, please contact [email protected] and we will take steps to delete it.
15. Third-Party Links
The APFleet platform may contain links to third-party websites or services, including the GaragePlus booking platform, DVLA public services, and the Auto Princess main website. Following such links takes you outside APFleet, and you become subject to the privacy policies of those third parties. We are not responsible for the content, privacy practices, or security of third-party sites and encourage you to review their policies before providing personal data.
16. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the services we provide. When we make material changes, we will:
- Update the "Last updated" date at the top of this page;
- Send an email notification to registered account holders in advance of the changes taking effect; and
- Display a prominent in-platform notice on your next login.
If you do not accept a material change, you may terminate your subscription in accordance with our Terms of Service before the change takes effect, and we will refund any prepaid fees for the unused portion of your subscription. Where a change requires consent under applicable law, we will seek that consent rather than relying on continued use. This Section does not limit your statutory rights.
17. How to Contact Us
For all privacy-related enquiries, rights requests, or data protection concerns, please contact us:
Data Protection — Auto Princess Ltd
Email: [email protected]
Post: Data Protection, Auto Princess Ltd, 71-75 Shelton St, London WC2H 9JQ
Please mark all correspondence clearly as a data protection matter. We will acknowledge receipt within 3 working days and provide a substantive response within one calendar month.