Legal & Compliance
PDPA Compliance
Last updated: 1 July 2026
FleetTrust OS is committed to the responsible handling of personal data in accordance with the Singapore Personal Data Protection Act 2012 (PDPA). This policy describes how we collect, use, disclose, and protect personal data.
1. Our Commitment to PDPA
FleetTrust OS recognises that the privacy of personal data is a fundamental right. We are fully committed to complying with the Personal Data Protection Act 2012 (PDPA) administered by the Personal Data Protection Commission (PDPC) of Singapore.
We adhere to the following PDPA obligations: the Consent Obligation, the Purpose Limitation Obligation, the Notification Obligation, the Access and Correction Obligation, the Accuracy Obligation, the Protection Obligation, the Retention Limitation Obligation, the Transfer Limitation Obligation, and the Data Breach Notification Obligation.
Our platform is built with privacy by design — we collect only what we need, retain it only as long as necessary, and protect it with appropriate technical and organisational safeguards.
2. Data Protection Officer (DPO)
We have appointed a Data Protection Officer (DPO) responsible for ensuring our compliance with the PDPA and for handling all data protection matters, including responding to access and correction requests and managing data breach incidents.
Data Protection Officer
FleetTrust OS
Email: dpo@fleettrust.io
For all PDPA-related queries, access requests, correction requests, or complaints, please contact our DPO directly at the email above.
3. Types of Personal Data We Collect
Depending on your role (fleet operator or registered driver), we may collect the following categories of personal data:
Identity & Contact Data
- Full name (as per NRIC or passport)
- NRIC number or FIN (Foreign Identification Number)
- Date of birth
- Email address
- Mobile phone number
- Residential address
Licensing & Regulatory Data
- Singapore driving licence number and class
- Private Hire Car Driver Vocational Licence (PDVL) number and expiry date
- Vehicle licence plate number(s)
- Insurance policy details and expiry dates
- LTA compliance and inspection records
Payment & Financial Data
- Payment method details (processed and tokenised by Stripe; we do not store raw card numbers)
- Billing address
- Rental and invoice transaction history
- Bank account information (where applicable for payouts)
Operational & Performance Data
- Trip records and mileage data
- Driver performance and safety scores
- Platform login activity and audit logs
- Device information and IP address
4. Purpose of Collection
We collect and use personal data only for the specific purposes for which it was collected and for directly related purposes. These include:
- Fleet Management: Managing driver profiles, vehicle assignments, and operational records for PHV fleet operators
- Invoicing & Billing: Generating rental invoices, processing subscription payments, and maintaining financial records
- Compliance Monitoring: Tracking PDVL, driving licence, insurance, and vehicle inspection expiry dates to ensure LTA regulatory compliance
- Communications: Sending service notifications, compliance alerts, invoice reminders, and platform updates
- Safety & Analytics: Generating driver performance reports and fleet analytics to support operator decision-making
- Legal & Regulatory: Complying with applicable Singapore laws and responding to lawful requests from government authorities
- Security: Detecting and preventing fraud, unauthorised access, and other security incidents
5. Consent
We collect personal data only with the informed consent of the individual, or where permitted by the PDPA without consent (for example, where collection is necessary for a contract, legal obligation, or legitimate interest that outweighs the individual’s privacy interest).
Consent is obtained at the point of account registration and, where applicable, when collecting sensitive categories of data such as NRIC numbers for identity verification purposes. Individuals are informed of the purpose of collection before or at the time of collection.
Individuals have the right to withdraw consent at any time by contacting our DPO at dpo@fleettrust.io. Withdrawal of consent may affect our ability to provide certain services. We will inform you of the consequences before processing your withdrawal.
6. Access & Correction Rights
Under the PDPA, individuals have the right to:
- Access the personal data we hold about you and information about how it has been used or disclosed in the past year
- Correct any personal data that is inaccurate, incomplete, misleading, or not up to date
- Data Portability (where applicable) to receive a copy of your personal data in a commonly used machine-readable format
To submit an access or correction request, please email our DPO at dpo@fleettrust.io. We will respond to all requests within 30 days. In some cases, we may need to verify your identity before processing the request. A reasonable fee may be charged for access requests in accordance with PDPC guidelines.
7. Data Retention
We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable law or regulation.
Standard Retention Period
Personal data related to fleet operations, driver records, and contractual relationships is retained for 3 years following the end of the contractual relationship (i.e., 3 years post-contract termination or account closure). This period reflects typical statutory limitation periods under Singapore law and standard business record-keeping requirements.
Financial and transaction records may be retained for up to 7 years in accordance with Singapore accounting and tax regulations. After the applicable retention period, data is securely deleted or anonymised.
Data retained in backup systems may take up to 90 days to be fully purged following a deletion request.
8. Cross-Border Data Transfers
As a cloud-based platform, some personal data may be transferred to and stored or processed in servers located outside Singapore. We ensure that all cross-border transfers comply with the PDPA Transfer Limitation Obligation by implementing appropriate safeguards.
Fly.io (Infrastructure)
Our application servers are hosted on Fly.io, with primary deployment in the United States (US-SJC region). Fly.io maintains SOC 2 Type II compliance and implements enterprise-grade security controls.
Supabase (Database)
Our database is hosted on Supabase, with data stored in the AWS ap-southeast-1 (Singapore) region where possible. Supabase implements encryption at rest and in transit, and access controls aligned with SOC 2 standards.
Stripe (Payments)
Payment data is processed by Stripe, a PCI DSS Level 1 certified payment processor. Stripe may process data in various jurisdictions. We rely on Stripe’s certified security controls and adequacy measures as the basis for this transfer.
We require all third-party processors to implement appropriate contractual protections and technical safeguards equivalent to the standards required by the PDPA.
9. Data Breach Notification
In the event of a data breach that is likely to result in significant harm to affected individuals, FleetTrust OS will:
- Notify the Personal Data Protection Commission (PDPC) within 3 calendar days of becoming aware of the breach, in accordance with the mandatory breach notification requirements under the PDPA
- Notify affected individuals as soon as practicable, providing details of the breach, the data affected, and recommended protective actions
- Conduct a thorough investigation, contain the breach, and implement remediation measures to prevent recurrence
- Maintain a record of all data breaches (including those that do not require mandatory notification) for internal accountability purposes
We maintain an incident response plan and conduct regular security reviews to minimise the risk of data breaches.
10. Contact & Complaints
If you have any questions, concerns, or complaints about how FleetTrust OS handles your personal data, please contact our DPO in the first instance:
If you are not satisfied with our response, you have the right to lodge a complaint with the Personal Data Protection Commission (PDPC) of Singapore:
Personal Data Protection Commission
Website: www.pdpc.gov.sg
Lodge a complaint: www.pdpc.gov.sg/complaints