Skip to waitlist
FleetWarrant
LEGAL

Privacy Policy

Draft — pending legal reviewLast updated 21 September 2026

How FleetWarrant handles personal information — both the ordinary website/waitlist kind, and the Event data your Agents generate once you’re a Customer. The second half is written to match our own architecture exactly, including the client-side redaction and immutable-archive design described in the product documentation, so this page doesn’t promise more than the system actually does.

01

Scope, and two different roles we play

This Privacy Policy explains how FleetWarrant Pty Ltd [entity name and ACN to be confirmed on legal review] (“FleetWarrant”, “we”) handles personal information. It covers two different relationships, because we play two different roles depending on the data:

  • As a controller — for people who visit https://fleetwarrant.com, join our waitlist, or contact us. This is ordinary website-visitor and prospect data, and we decide how it’s used, as described below.
  • As a processor — for the Event data our Customers’ Agents generate once they’re on the Service. We handle that data on the Customer’s instructions, under our Terms of Service and their Order Form, not on our own. If you’re an individual whose information shows up inside a Customer’s Event data — for example, because you’re a colleague or counterparty an Agent interacted with — that Customer is who to contact about it; see Event data below for how it’s handled.
02

Information we collect from visitors and applicants

When you join the waitlist or otherwise ask to hear from us, we collect what the form asks for: your name, work email, company, role, a rough estimate of how many Agents you run, and anything you choose to add in the free-text field. We also capture, for that submission only, the page you came from and any campaign parameters in the URL, and your consent to be contacted.

The form is delivered to us by our forms processor, Anchor Forms. Submissions are screened for spam by a hidden field only a bot would fill in, an allowlist restricting submissions to our own domain, and rate limiting keyed to the submitter’s IP address — none of which read anything about you beyond what you typed into the form. We don’t run advertising or analytics trackers on this site — see Cookies.

If you email us or otherwise contact us directly, we collect whatever you send us and use it to respond.

03

Information we collect from customers

When you or your company becomes a Customer, we collect account and billing information — names, work emails, and (once self-serve billing is live) payment details handled by our payment processor, never stored by us in full — and the information you give us about each Agent you register: a name, the owner responsible for it, its purpose, and its vendor.

04

Event data — what your Agents generate

The FleetWarrant SDK, running inside your own environment, watches the calls your Agents make and reports a record of each one — an “Event” — to the Service. Two things about how that happens matter for privacy specifically:

  • Redaction happens before we ever see it. Fields you configure for redaction are stripped or masked inside the SDK, in your environment, before transmission. We receive the fact that a field was redacted and which field it was, never the value — there is no form of the redacted content on our side to protect, because it never arrives.
  • What isn’t redacted is captured in full, by design. The audit trail’s whole purpose is to be a complete, trustworthy record — including calls to LLM providers — so anything your redaction rules don’t cover is stored as sent: a bounded preview for the dashboard, and the complete capture in an immutable archive. If your Agents’ traffic can carry personal information you haven’t configured a redaction rule for, that information will be captured. It is your responsibility to configure redaction to match the data your Agents actually handle before sending real traffic through the Service — see the Documentation.

We act as a processor over Event data: we don’t use it to build profiles of the individuals it mentions, sell it, or use it for advertising. We may use de-identified, aggregated Event statistics that can’t reasonably be traced back to you, your Agents, or the individuals your Agents interacted with, to improve the Action Mapper’s pattern library and the Service’s reliability.

05

How we use information

  • To provide, operate, and secure the Service;
  • to respond to your waitlist request or enquiry, and to follow up about early access, where you’ve consented to that;
  • to bill and support Customer accounts;
  • to detect, investigate, and prevent abuse, fraud, or security incidents; and
  • to meet legal, tax, and regulatory obligations we’re subject to.
06

Storage, security, and retention

The Service runs on Amazon Web Services, in a single AWS region. We don’t currently offer a choice of region or a data residency commitment to any particular country or bloc — if your organisation needs one before you can use the Service, tell us at hello@fleetwarrant.com. Every Customer’s data is logically isolated by a tenant identifier on every read and write, and the payload-bearing parts of the audit record are additionally encrypted under an encryption key dedicated to your account, not shared with any other Customer’s.

The audit archive is retained for the length of your subscription plus the retention period in your Order Form, to serve as compliance evidence — its whole value is that entries in it aren’t edited or deleted individually, including by us. When your account is offboarded and any retention period expires, we remove your data by destroying your account’s dedicated encryption key, which renders the archive permanently unreadable, rather than by editing archived records one at a time.

We haven’t yet finished designing how a deletion or right-to-erasure request for a specific record inside an active, non-offboarded account is handled — the tension between an immutable audit trail and a per-record erasure request is a known open question in our own architecture docs. If you need this resolved contractually, tell us at hello@fleetwarrant.com before sending regulated data through the Service.

Waitlist and prospect data is kept for as long as reasonably needed to run the waitlist and follow up on it, or until you ask us to delete it.

07

Who we share information with

We don’t sell personal information. We share it with:

  • Infrastructure and security providers — Amazon Web Services (hosting and storage) and Cloudflare (hosting and content delivery), who process data on our instructions to run the Service.
  • Anchor Forms — processes waitlist and enquiry submissions on our behalf.
  • Payment processors — once self-serve billing is live, a processor such as Stripe handles your payment details directly; we don’t store your full card number ourselves.
  • Legal and safety — where required to comply with law, or to protect the rights, property, or safety of FleetWarrant, our Customers, or others.

We never disclose one Customer’s Event data to another Customer, and we don’t use it to train or fine-tune a general-purpose model outside the Service.

08

Your rights

Depending on where you’re located, you may have rights to access, correct, port, or request deletion of your personal information, to object to or restrict some processing, and to withdraw consent (which won’t affect anything we did before you withdrew it). To exercise any of these for information we hold as a controller — website visitor and waitlist data — email hello@fleetwarrant.com.

If your request concerns Event data we hold as a processor for a Customer, we’ll direct you to that Customer, who controls it, unless you tell us who they are and ask us to help directly.

09

International transfers

The Service runs in a single AWS region (see Storage, security, and retention), so if you or your organisation are located elsewhere, your information is necessarily processed outside your own country — including, for some visitors and Customers, a transfer out of the EU/EEA or UK. We haven’t yet put a specific transfer mechanism, such as Standard Contractual Clauses, in place for every combination of visitor location and processing location this could involve. If your organisation needs one documented before you can use the Service, tell us at hello@fleetwarrant.com and we’ll work through it as part of onboarding.
10

Cookies

This site doesn’t run analytics or advertising cookies, and the waitlist form doesn’t currently use Cloudflare Turnstile or any other bot-check that sets one either — it’s protected instead by a hidden honeypot field, an origin allowlist, and per-IP rate limiting, all evaluated on submission rather than through anything stored in your browser. Our hosting provider, Cloudflare, may still set strictly necessary cookies to route and secure traffic to the site.

11

Children's privacy

The Service is a B2B product and our website isn’t directed at children. We don’t knowingly collect personal information from anyone under 16. If you believe a child has given us information, contact us and we’ll delete it.

12

Changes to this policy

We may update this Policy as the Service and our practices change. For a material change, we’ll update the “Last updated” date above and, where the change is significant, give Customers notice by email or in-product notice.