Protecting your privacy is fundamental to the way One Step GPS (we,” “us,” or “our”) conducts business. If you are a One Step GPS customer or a visitor to our website, this Privacy Policy applies to you. This Privacy Policy explains how we collect, use, and disclose your Personal Information when you access and use our products and services, including our website (www.onestepgps.com/) and the One Step GPS platform (collectively, the “Services”).
This Privacy Policy may change from time to time. Any updates will be posted on this page, and your continued use of the Services constitutes your acceptance of the changes. We encourage you to review this policy periodically to stay informed about how we are protecting your data. If you are our customer, we will notify you of important changes to this policy.
You can jump to particular topics by going to the headings below:
We will inform you, by publishing this Privacy Policy, about how we collect, use, process and store your data.
If the way in which we collect, use, process, or store your data changes, we will publish updates to this policy to inform you.
Read this Privacy Policy and our Cookie Policy.
If you are our customer, please also check our Terms and Conditions or any signed agreement between us, as these may contain further details on how we collect and process your data.
If you provide us with personal information about other people, or if others give us your information, we will only use that information for the specific reason for which it was provided to us. By submitting the information, you confirm that you have the right to provide us with the data and to allow us to collect, use, process and store it. You are responsible for providing accurate, up-to-date information and ensuring its continued accuracy while using our services.
Consult this Privacy Policy periodically to check for updates.
You must be at least 18 years of age to use this website. We may ask you to confirm your age when providing certain services to ensure compliance with this requirement.
If our products and services collect data about you but you are not our customer (including for example if you are an employee or contractor of one of our customers, or you receive our device via your insurance company), you should consult the business that operates our devices to learn about their privacy practices. This Privacy Policy applies only when the purposes and means of processing your personal data are determined by One Step GPS, meaning when we are a “controller” or “business” as defined by applicable data protection laws. It does not apply to any of your personal data that we process on behalf of our customers, meaning when we are a “processor” or “service provider” as defined by applicable data protection laws.
Please contact the relevant controller or business (this would your employer if you are an employee or contractor of a One Step GPS customer, or your insurance company if they provided your device) for more information about their privacy practices.
When you visit our website or use our products or services, we collect data. Sometimes you provide us with data, sometimes data about you is collected automatically.
Browse any page of our website, use the chat feature of our website, request a demo, use our products or services, and when you contact us for support, or when we send emails to you.
Opt-in to marketing messages, use the chat feature of our website, request a demo, place an order, use our products or services, contact us for support, send us emails, and when we call you or you call us.˝
We collect the following information in the course of providing you with our services:
Context | Types of Information | Primary Purpose for Collection and Use of Information |
---|---|---|
Client & Prospective Client Contact Information | We collect the names, emails, and contact data of our clients, prospective clients, and their employees with whom we may interact. | We are executing on a contractual obligation in contacting our clients and a legitimate interest in contacting our prospective clients, to communicate with them concerning normal business administration such as billing, registration, and our services. |
Client and User Account Information | We collect personal information from our clients and users of our Services when they create an account to access and use the Services. This information could include business contact data such as name, email address, title, company information, phone number and password for the Services. | We are executing on a contractual obligation by providing account-related functionalities to our users, monitoring account log-ins, and detecting potential fraudulent logins or account misuse. |
Client Employee & Vehicle Tracking Information | Our clients use our Services to collect information on their employees and their workforce vehicles. Employee information may include data such as employee name, driver’s license information, date of birth, address, phone number, email address, and IP address. Vehicle information may include company addresses, vehicle make and model, VIN of vehicle, license plate information, vehicle computer data, device names, telematics device identification numbers, GPS location, vehicle speed, miles traveled, routes and places visited by vehicle, time spent in transit or idle, and screenshots, images, or recordings from vehicle cameras, Additionally, our clients may store information related to their customers, such as addresses, appointments, and other business data entered into our products by their employees or users, or collected using our devices. | We are executing on a contractual obligation to provide our clients and their employees with our Services. Our clients have a legitimate interest to manage their workforce and employees, and they are responsible for managing this information in accordance with all applicable local laws and regulations. |
Cookies and First-Party Tracking | We use cookies and clear GIFs. “Cookies” are small pieces of data that a website sends to a computer’s hard drive while a website is viewed. | We have a legitimate interest in making our website operate efficiently and improving our marketing efforts and Services. |
Cookies and Third-Party Tracking | We participate in behavior-based advertising and the gathering of analytics. This means that a third- party uses technology (e.g., a cookie) to collect data about your use of our website so that they can provide us with website and user analytics, as well as for the purposes of advertising products and services tailored to your interests on our website, or on other websites. | We have a legitimate interest in engaging in behavior-based advertising and capturing website analytics in improving our marketing efforts. For additional information on our use of cookies, please review our Cookie Policy. Additionally, you can manage your cookie consent preferences in the cookie consent manager via our website’s cookie banner. |
Email Interconnectivity | If you receive an email from us, we may use certain tools to capture data related to when you open our message or click on any links or banners contained within. | We have a legitimate interest in understanding how you interact with our communications to you. |
Employment | If you apply for a job posting or become an employee of One Step GPS, we collect the information necessary to process your application or to retain you as an employee. This may include, among other things, your name, address, email address, I-9 information, Social Security Number, work history, resume, EEO information, veteran status, disability status, healthcare information, and banking account information. Providing this information is required for employment. | We use information about current employees to fulfil our contract of employment or the anticipation of a contract of employment with you. In some contexts, we are also required by law to collect information about our employees. We are executing on a contractual obligation in using your information to have efficient staffing and workforce operations. |
Feedback and Support | We collect personal information from you contained in any inquiry you submit to us regarding the Services, such as completing our online forms, calling, or emailing for the purposes of general inquiries, support and chat requests, or to report an issue. When you communicate with us through our live support chat or over the phone, your messages and calls may be recorded and analyzed for training, quality control, and for sales and marketing purposes. During such interactions, we will notify you of the recording via either voice prompt or script. | We have a legitimate interest in receiving and acting upon, your feedback, issues, or inquiries. |
Mailing List and Demo Requests | When you sign up for one of our blogs, mailing lists, or webinars, or when you submit a demo request, we collect contact information such as your name, email address and company affiliation. | We share information about our Services with individuals that consent to receive such information. |
Payment Information | We collect payment and billing information when you register for certain paid Services. For example, we ask you to designate a billing representative, including name and contact information, upon registration. You might also provide payment information, such as bank account number, credit card number and CVV, or debit card details that you provide to pay for our products and services, which we collect via secure payment processing services. | We are executing on a contractual obligation in obtaining payments for certain Services. |
Order Placement | We collect your name, billing address, e-mail address, phone number, and use a third-party PCI compliant service to process your payment card number when you place an order. Specifically, we use Stripe and Braintree for payment processing. | We use your data to perform our contract to provide you with Services. For questions about how Stripe or Braintree processes your data, please refer to their respective Privacy Policies: https://stripe.com/privacy; or https://www.braintreepayments.com/legal/braintree-privacy-policy |
Promotions | Promotions, incentives, or giveaways may be made available by us or third parties from time to time. You do not have to participate in these, however, if you choose to participate, you may be asked to disclose some personal information. Additionally, at the time of entering the promotion, we will disclose in the promotion’s materials specific terms and conditions regarding how your personal information will be used. Please do not participate in any promotion if you do not agree to such usage. | We obtain consent to share information about our Services and providing incentives to our customers. |
Video & Online Reviews | When you participate in providing video or online reviews, we collect data that you provide through the review. If the review is provided by a third-party service provider, the third-party’s privacy policy applies to the collection, use, and disclosure of your information. | When you complete and submit reviews, you consent for us to use your reviews for our advertising or marketing purposes. One Step GPS has a legitimate interest in using and sharing your reviews to inform other clients and perspective clients about our services. |
Surveys | When you participate in a survey, we collect data that you provide through the survey. If the survey is provided by a third-party service provider, the third-party’s privacy policy applies to the collection, use, and disclosure of your information. | We obtain consent for any surveys and use them to gain an understanding of your opinions and collecting data relevant to our organization. |
Website Interactions | We use technology to monitor how you interact with our Services. When visiting our website, we may capture information on the links or products/services viewed, page response time, download errors, how long you stay on our pages, what you do on those pages, how often you view those pages, and other actions or information that you type into our online forms. This may also include information about your device or browser. | We have a legitimate interest in understanding how you interact with our Services to better improve them, and to understand your preferences and interests in order to select offerings that you might find most useful. We also have a legitimate interest in detecting and preventing fraud. |
Social Media | When an individual interacts with our Services through various social media networks, such as when someone follows us or shares our content on Facebook, Twitter (X), LinkedIn, YouTube, or other social networks, we may receive some information about individuals that they permit the social network to share with third parties. The information we receive is dependent upon an individual’s privacy settings with the social network, and may include your profile information, profile picture, gender, username, user ID associated with your social media account, age range, language, country, and any other information you permit the social network to share with third parties. | We use this information to update and maintain the page to provide you with content and features of our Services, as well as to improve our product outreach. Individuals should always review and, if necessary, adjust their privacy settings on third-party websites and social media networks and services before sharing information and/or linking or connecting them to other services. We have a legitimate interest and/or may obtain your consent to collect this information. |
Web Logs, Device, and Usage Information | We collect information, including your login information, device and browser type and version, browser plug-in types, operating system and version, Internet Protocol (IP) address, derived IP address location, geolocation information, time zone setting, domain name, URL clickstreams and click-activity, referring website, and/or a date/time stamp for visitors. Additionally, we collect user account activity to include when an activity is completed, the type of activity taken, and the related data for the activity (for example, if a user sends a message, etc.). | We have a legitimate interest in monitoring our networks and visitors to our Services. Among other things, it helps us to monitor performance and to understand which of our Services and features are the most popular. |
In addition to the information that we collect from you directly, we may also receive information about you from other sources, including third parties, business partners, our affiliates, or publicly available sources. For example, if you submit a job application, or become an employee, we may conduct a background check.
We empower you to manage your personal data and limit the use and disclosure of your personal data. Through your account settings, you can control location tracking, data sharing, and notifications. You can opt-out of marketing emails or personalized ads easily. You have the right to access or delete your data by contacting us. For sensitive data uses, we will always request your explicit consent.
We collect precise geolocation data (within 1,750 feet or less) about your vehicles in order to provide our services to you. We do not sell geolocation data or use it for advertising purposes.
We do not collect any other “sensitive data” (like racial or ethnic origin, political opinions, religious/philosophical beliefs, union membership, genetic data, biometric data, health data, data about your sex life or orientation, or criminal history) except when we have your specific consent, or when the law requires us to. We ask that you not provide us with sensitive data or use our products to process sensitive data.
Data protection laws applicable in some places provide that we can only use your data for certain reasons and when we have a legal basis or your permission to do so. Here are the reasons for which we process your data:
If you provide us with your contact information, we may send you emails and messages (including via social media) about new features, products and services, and content.
We may also use data collected by third parties to serve retargeting ads to you about our products and services, and we may permit third-party providers such as Google, LinkedIn, Facebook, Mail Chimp to match our customer data to their user data and serve our ads to you. Those third parties’ use of your data is subject to their privacy policies. If you have previously given consent to send you marketing emails or to use your data to advertise to you, and you wish to withdraw your consent, please see the How to Contact Us section at the bottom of this policy to withdraw your consent.
Group | Data Shared | Why Data is Shared |
---|---|---|
Service Providers: Companies (e.g., hosting, analytics, payment processing). | Server logs, IP addresses, usage data, Website traffic, user behavior, billing information. | This helps One Step GPS operate its services effectively. |
Acquiring Entities | Personal information, location history, usage data, and billing information. | Facilitating the transfer of ownership or assets in a merger, acquisition, or sale. |
Law enforcement or courts | Customer information, location data, communication logs. | Complying with legal requirements, such as subpoenas, court orders, or investigations. |
Business Partners: Companies we collaborate with for specific offerings | Aggregated location data, customer demographics, usage statistics, or data related to specific joint offerings. | Collaborating on new products or services, marketing initiatives, or data sharing for mutual benefit. |
You have the right to access your personal data. You may request access to your information by contacting us at legal@onestepgps.com. If required by law, upon request, we will grant you reasonable access to the personal information that we have about you.
You can do this by asking us to erase any personal data we hold about you or any consumer if it is no longer necessary for us to hold the data for purposes of your use of our products or services. See the “How to contact us” section at the bottom of this policy. To the extent that you have submitted your personal data when placing an order, it is necessary for us to hold that data to enable you to use our products and services. You can also delete your account information by clicking here.
If you or a consumer whose data you have provided asks for access to their personal data, information about the categories of sources from which it is collected, or information about the categories or specific pieces of personal data, we will cooperate, including by providing the requested information in a portable and, to the extent technically feasible, readily useable format.
If we are unable to delete personal data for a valid legal reason, we will tell you why, we will only retain the personal data for that reason, and we will delete the personal data after the reason for keeping it no longer exists.
Please see the “How to Contact Us” information at the bottom of this policy.
We use physical, electronic, and managerial measures to safeguard and secure the information we collect. In the event of a data breach, we will notify affected users without undue delay and, where applicable, within 72 hours of becoming aware of the breach. We will also take all necessary measures to mitigate the impact of the breach. Please remember, however:
For additional information on our security practices, controls, and measures, please visit our Trust Center.
Sometimes, we may need to share your data with third parties. For example, we submit geolocation data to Google to improve geocoding. We store data on Amazon servers, and have partnerships with SpeedGauge, Inc., Rarestep, Inc. (providers of Fleetio), and ServiceTitan, Inc., among others. We may share your data with your insurance carrier, with your permission. Your data is shared with third parties only when necessary and according to the safeguards and good practices detailed in this Privacy Policy, but third parties’ use and processing of your data will be governed by those companies’ privacy policies.
For additional information regarding One Step GPS’s partnerships and use of third party services, please review our Subprocessor List.
We may transfer your personal data to any countries where we have data processing locations, including the United States, and may process it globally. For transfers outside regions with strict data protection laws, such as the EU/EEA, we use Standard Contractual Clauses (SCCs) or other legal mechanisms to safeguard your data. By submitting personal data, you consent to this transfer, including any transfers outside your country of residence. If you do not consent, please do not use our site or submit your data.
One Step GPS complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. One Step GPS has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union and the United Kingdom in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF. One Step GPS has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov .
In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, One Step GPS commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs) and the UK Information Commissioner’s Office (ICO) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF.
We are committed to taking all necessary steps to ensure that your data is treated securely and in accordance with this Privacy Policy. If you would like more information on our data protection measures, please contact us at legal@onestepgps.com
One Step is responsible for the processing of personal data it receives and subsequently transfers to a third party acting as an agent on its behalf. One Step GPS complies with the EU-U.S. DPF Principles, the UK Extension to the EU- U.S. DPF and the Swiss-U.S. Data Privacy Framework Principles for onward transfers of personal data, including the onward transfer liability provisions.
One Step GPS remains responsible and liable under the EU-U.S. DPF Principles, the UK extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework Principles if third-party agents that it engages to process the personal data on its behalf do so in a manner inconsistent with the Principles unless One Step GPS proves that it is not responsible for the event giving rise to the damage.
Under Annex I of the EU-U.S. Data Privacy Framework (DPF) Principles, One Step GPS provides you with the right to pursue binding arbitration if you believe your personal data has been mishandled and other dispute resolution methods have been unsuccessful. This arbitration mechanism ensures an independent review of claims related to violations of the DPF Principles, offering a fair and transparent resolution process for your concerns.
The Federal Trade Commission has jurisdiction over One Step GPS’ compliance with the EU-U.S. DPF, the UK Extension to the EU- U.S. DPF and the Swiss-U.S. Data Privacy Framework. In certain situations, One Step GPS may be required to disclose personal information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
The California Consumer Privacy Act (hereafter: 'CCPA') and the California Privacy Rights Act (hereafter: ‘CPRA’) provide California consumer residents who reside in California with specific rights regarding their personal information (which we also refer to as personal data). In addition to the above this section describes your CCPA/CPRA rights and explains how to exercise those rights.
This Supplemental California Privacy Rights Notice supplements the information about how we collect and use your data, why we use or share your data, and the types of data we collect, contained in our Privacy Policy. The following does not apply to de-identified or aggregated personal data or data publicly available, which are not considered Personal Information since they do not identify any individual.
We will not discriminate against you for exercising your rights under the CCPA/CPRA. Based on the complexity of the request and the applicable regulations, we may charge a fee for your request. We may offer a CCPA/CPRA-permitted financial incentive, participation in a financial incentive program requires your prior opt-in consent, which you may revoke at any time.
Please note that the above rights depend on a few things, and we may refuse requests if there are exceptions under the applicable law.
If we cannot verify you (or your authority to act on behalf of another person) we have the right to deny the requests. While verifying your identity we generally avoid requesting additional information from you for verification purposes. If, however, we cannot verify your identity from the information already maintained by us, we may request additional information from you, which shall only be used to verify your identity while you are seeking to exercise your rights under applicable law, and for security or fraud-prevention purposes.
We delete any new Personal Information collected for verification as soon as practical after processing your request, except as required to comply with applicable legislation.
An "authorized agent" means a natural person, or a business entity registered with the Secretary of State that you have authorized to act on your behalf, conditioned you have:
Subsection 1 does not apply when you have provided the authorized agent with a valid power of attorney.
We do our utmost to timely respond to a verifiable Individual, and in a portable format unless it is excessive, repetitive, or materially unfounded. If we require more time, we will inform you of the reason thereof and the extension period in writing.
We do not respond to “Do Not Sell” requests as we do not sell your Personal Information to third parties. In the twelve months before the effective date of this Privacy Notice, we have not sold any Personal Information of Clients, as per the definition of the CCPA/CPRA and similar laws.
After receiving your opt-in consent, we sometimes disclose Personal Information collected via cookies for cross-contextual behavioral advertising purposes, which may qualify as sharing your Personal Information under the CCPA/CPRA. To opt-out of this use, you can adjust your cookie preferences on our website’s cookie banner to block our advertising cookies.
Additionally, you can change your device settings to block cookies or install a third-party plugin to control how cookies interact with your device.
If you are a current employee or candidate of One Step GPS, please refer to our Candidate and Employee Privacy Notice for additional information on how we may collect, process, disclose, and retain your personal data.