1. About this Policy
Flext Inc. (“Flext,” “we,” “us,” or “our”) provides a business fleet-management and telematics platform. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information in connection with:
- the Flext marketing website;
- the Flext web and mobile applications;
- Flext APIs, integrations, telematics devices, Fleet Tags, and related services;
- alerts, emails, text messages, voice calls, and push notifications;
- billing, support, and account administration; and
- public or limited-access vehicle-location sharing features, including Live Share.
This Policy applies to customer administrators, authorized users, drivers and employees whose information is processed through Flext, emergency contacts, notification recipients, mobile application users, Live Share viewers, and individuals whose information is imported through customer-enabled integrations.
Flext is intended for business use and is not directed to children.
Flext’s contact information
Legal entity: Flext Inc.
Privacy Officer: Privacy Officer
Privacy email: [email protected]
Telephone: +1 (226) 407-7960
Flext does not publish a physical business address on this website. Legal and privacy notices may be sent using the contact information above.
2. Our Privacy Roles
Flext may handle personal information in two different roles.
2.1 Information Flext handles for its own business purposes
Flext determines the purposes and means of processing certain information needed to operate our business, including:
- website inquiries and sales communications;
- customer account, administrator, and authorized-user information;
- authentication, account security, fraud prevention, and audit information;
- billing, subscriptions, quotes, invoices, and payment-administration information;
- support requests and service communications;
- information required to administer Live Share access and protect the service; and
- legal, regulatory, security, and corporate records.
For this information, Flext is responsible for the privacy practices described in this Policy.
2.2 Customer-controlled information
Our customer organizations generally decide why and how Flext is used to process:
- driver and employee records;
- precise vehicle and device location;
- trip and route history;
- driving events, alerts, and safety scores;
- vehicle assignments and operational records;
- licence, insurance, compliance, and emergency-contact information;
- job, customer, technician, or employee data received through integrations;
- notification-recipient information; and
- information disclosed through customer-created Live Share links.
For this information, Flext generally acts as a service provider processing information on the customer’s instructions. The customer is responsible for its own collection, use, disclosure, employment, labour, and privacy obligations.
A driver, employee, or other individual seeking access to or correction of customer-controlled information should normally contact the relevant employer or customer organization first. Flext will support the customer in responding where required by law or contract. An individual may also contact our Privacy Officer if the customer cannot be identified, does not respond, or the concern relates directly to Flext’s practices.
Customer-controlled processing may be further governed by a Data Processing Addendum or other written agreement between Flext and the customer.
3. Information We Collect
The information we collect depends on the Flext services used and the choices made by the customer.
3.1 Account and identity information
This may include:
- name and display name;
- email address and telephone number;
- profile photograph;
- external or integration identifier;
- company memberships, roles, permissions, and selected company;
- account status, suspension information, and administrative notes; and
- invitations and account-activation records.
3.2 Authentication and security information
This may include:
- password hashes and salts;
- refresh-token and trusted-device records;
- multi-factor authentication telephone number;
- protected authenticator secrets and recovery-code information;
- login, logout, session, password-reset, and security-event timestamps;
- device, browser, network, and IP information; and
- audit and access-control activity.
Flext does not store a user’s password in readable form.
3.3 Company and organizational information
This may include:
- legal and operating names;
- business address;
- billing and contact email addresses;
- telephone number;
- logo;
- time zone and unit preferences;
- groups, departments, locations, yards, and memberships; and
- customer configuration and administrative settings.
3.4 Driver and employee information
A customer may enter, upload, or synchronize information such as:
- name, email address, and telephone number;
- home or mailing address;
- employee identifier and hire date;
- profile photograph;
- driver’s licence number, class, jurisdiction, and expiry date;
- insurance information;
- employment, safety, training, or compliance notes;
- emergency-contact name and contact information; and
- licence, insurance, and other compliance documents.
Some of this information may be sensitive. Customers should collect only information that is reasonably necessary for their lawful business purposes.
3.5 Vehicle, device, and asset information
This may include:
- vehicle identification number, licence plate, make, model, and year;
- vehicle images and labels;
- assigned driver;
- telematics-device, SIM, and Fleet Tag identifiers;
- odometer, engine or run hours, ignition state, and operational status;
- device health, connectivity, installation, and diagnostic information; and
- vehicle groups and assignments.
3.6 Precise location and telemetry information
Installed telematics devices and enabled integrations may provide:
- latitude and longitude;
- date and time;
- speed and heading;
- altitude and location accuracy;
- ignition and motion state;
- road, locality, and map context;
- device-provider attributes; and
- linked vehicle and driver information.
This data may reveal a vehicle’s movements and, where a vehicle is assigned to a person, may reveal that person’s location, work patterns, travel history, or activities. Precise location and historical movement information may be sensitive.
3.7 Trips, events, alerts, and derived information
Flext may create or display information derived from customer data, including:
- trips, routes, stops, arrivals, departures, and distance;
- geofence entry and exit activity;
- speeding, harsh braking, acceleration, cornering, or other driving events;
- maximum speed and speed-limit comparisons;
- safety scores, grades, trends, and coaching context;
- alert acknowledgement, dismissal, and escalation history; and
- vehicle, driver, and fleet-level summaries.
These outputs are operational tools. They can be affected by device, map, road, network, configuration, and data-quality limitations and should be reviewed in context.
3.8 Notification and communication information
When customers configure alerts or communications, we may process:
- recipient names, email addresses, and telephone numbers;
- push tokens and mobile-installation metadata;
- templates and message content;
- delivery, failure, acknowledgement, and callback status;
- provider-generated SMS, voice, email, or push identifiers;
- call duration and acknowledgement input; and
- support and troubleshooting records.
3.9 Mobile application information
The mobile application may process:
- account and session information;
- selected company and application preferences;
- push-notification and device-installation identifiers;
- optional foreground phone location used to centre a map; and
- where enabled, a phone reference coordinate sent to Flext to support a Live Activity or related feature.
Phone location is distinct from telematics-device location. Flext will request device permission where the operating system requires it. A user can generally change mobile location or notification permissions in device settings, although disabling permissions may limit features.
3.10 Billing and transaction information
This may include:
- billing contact and billing email;
- Stripe customer and payment-method identifiers;
- masked card details, card brand, and expiry date;
- subscription, quote, invoice, tax, payment, and total information;
- hosted invoice or payment links;
- saved-payment-method consent records; and
- failed-payment and account-suspension information.
Payment-card numbers and security codes are entered into Stripe-controlled payment components and are not intended to be received or stored directly by Flext.
3.11 Files and documents
Customers and users may upload:
- profile, company, driver, or vehicle images;
- driver’s licence, insurance, training, or compliance documents; and
- other files enabled by the service.
These files may be stored by an S3-compatible storage provider.
3.12 Technical, website, and usage information
We and our service providers may automatically process:
- IP address;
- request path, response status, and trace identifier;
- authenticated user identifier;
- browser, device, operating-system, and network information;
- timestamps and security events;
- cookie and local-storage identifiers; and
- diagnostic and performance information.
At the date of this Policy, Flext does not use advertising cookies, behavioural-advertising SDKs, or session-replay technology in the reviewed web applications. We will update this Policy if those practices change.
3.13 Integration information
At a customer’s direction, Flext may receive or send information through enabled integrations, such as:
- employee, technician, customer, job, and location information from ServiceTitan;
- telemetry and device information from Digital Matter;
- SIM usage, connectivity, and account information from 1NCE; and
- other information authorized by the customer through APIs, webhooks, or connected services.
4. Where Information Comes From
We may collect personal information:
- directly from an individual;
- from a customer owner, administrator, dispatcher, fleet manager, safety employee, or other authorized user;
- from installed telematics devices, Fleet Tags, vehicles, SIMs, or related equipment;
- from the Flext web or mobile application;
- from customer-enabled integrations and service providers;
- from Stripe and payment-related providers;
- from email, SMS, voice, and push-notification providers;
- from maps, address, and location services; and
- automatically through request, security, and diagnostic logging.
5. How We Use Information
Depending on our role and the services selected, we use personal information to:
5.1 Provide and administer accounts
- create, authenticate, and manage accounts;
- provide multi-factor authentication and account recovery;
- maintain company memberships, permissions, and administrative controls;
- keep accounts secure and investigate suspected misuse.
5.2 Operate fleet-management services
- show current and historical vehicle location;
- support map views, trip replay, routes, stops, and operational status;
- manage vehicles, drivers, devices, SIMs, locations, yards, and groups;
- calculate or display trips, geofence activity, driving events, and safety scores;
- provide fleet reporting and operational records.
5.3 Deliver alerts and communications
- send customer-configured emails, texts, voice calls, and push notifications;
- deliver security, account, billing, and service messages;
- diagnose delivery failures and manage acknowledgements;
- support emergency-contact or escalation workflows configured by the customer.
Flext is not an emergency-dispatch or life-safety service. Customers should not rely on Flext as the only means of communicating an emergency.
5.4 Provide Live Share
At a customer’s instruction, Flext may create and operate expiring links that disclose selected vehicle information to recipients. More detail appears in section 8.
5.5 Process billing and transactions
- administer quotes, subscriptions, invoices, payments, taxes, credits, and saved payment methods;
- detect and prevent fraud or misuse;
- maintain accounting and transaction records;
- enforce contractual payment obligations.
5.6 Support customers and improve reliability
- respond to support requests;
- troubleshoot devices, connectivity, integrations, and applications;
- monitor service health and performance;
- maintain logs, audits, backups, and records;
- prevent, detect, and investigate security incidents.
5.7 Meet legal and business obligations
- comply with laws, court orders, and lawful requests;
- establish, exercise, or defend legal claims;
- protect Flext, customers, users, and the public;
- complete corporate transactions, due diligence, financing, or restructuring;
- enforce agreements and acceptable-use requirements.
5.8 Product improvement and service reliability
Flext does not use identifiable Customer Data for independent product benchmarking or to train generalized artificial-intelligence models.
We may use system-level and aggregate operational metrics that do not identify a customer or individual to secure, maintain, troubleshoot, and improve service reliability. We do not attempt to re-identify this information.
6. Consent, Authority, and Customer Responsibilities
Depending on the circumstances and our role, Flext handles personal information with consent, to provide contracted services, for purposes a reasonable person would consider appropriate, or under another authority permitted by applicable federal or provincial privacy law. These laws may include the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial private-sector privacy legislation.
6.1 Required and optional information
Some information is required to create an account, secure the service, provide contracted functionality, process payments, or comply with law. If required information is not provided, Flext may be unable to provide the relevant service.
Optional features may require additional information or permissions, such as:
- mobile phone location;
- push notifications;
- an MFA telephone number;
- integration access; or
- information selected for Live Share.
Where appropriate, Flext will provide a feature-specific or just-in-time notice.
6.2 Customer authority
Each customer is responsible for:
- having lawful authority to collect and provide Customer Data to Flext;
- giving drivers, employees, emergency contacts, and other individuals notices required by law;
- obtaining any consent or authorization required for monitoring, location tracking, communications, integrations, document uploads, and disclosures;
- complying with employment, labour, collective-agreement, human-rights, and workplace-monitoring obligations;
- limiting access to people with a legitimate business need;
- configuring retention, alerts, Live Share, and permissions appropriately; and
- responding to individual requests concerning customer-controlled information.
6.3 Workplace monitoring
Flext can enable detailed vehicle and driver monitoring. Customers should ensure their use is specific, proportionate, transparent, and reasonably necessary.
Ontario employers with 25 or more employees on January 1 of a year are generally required to maintain a written electronic-monitoring policy before March 1 of that year. Customers are responsible for determining and meeting their obligations in every jurisdiction where they operate.
6.4 Withdrawing consent
Where processing is based on consent, an individual may withdraw consent subject to legal and contractual restrictions and reasonable notice. Withdrawal may limit or prevent use of certain features. Withdrawal does not affect processing already lawfully completed.
For customer-controlled information, Flext may need to refer the request to the customer.
7. How We Disclose Information
Flext does not sell personal information. We disclose information only as described below, as instructed by a customer, with consent, or as otherwise permitted or required by law.
7.1 Customers and authorized users
Information may be visible to customer administrators, dispatchers, fleet managers, safety staff, and other authorized users based on their permissions and company configuration.
Customer administrators may manage user access and may be able to view, correct, export, or delete information.
7.2 Service providers and subprocessors
We use service providers to host, secure, operate, and support Flext. Depending on the services enabled, these include:
| Provider | Purpose and information involved |
|---|---|
| Mapbox | Maps, traffic or imagery, geocoding, location display, and Live Share maps. Location coordinates and technical request information may be transmitted. |
| Google Maps Places | Company or address autocomplete. Search text, selected address information, and technical request information may be transmitted. |
| Stripe | Payment methods, customers, subscriptions, quotes, invoices, taxes, and payment links. Billing and transaction information is transmitted. |
| Mailgun | Email and website-lead delivery. Recipient, message, form-submission, and delivery information may be transmitted. |
| Twilio | SMS and voice delivery. Telephone numbers, message or call content, delivery status, and acknowledgement information may be transmitted. |
| Expo, Apple APNs, and applicable mobile push providers | Push notifications and iOS Live Activities. Push tokens, installation metadata, and notification content may be transmitted. |
| DigitalOcean Spaces and other approved S3-compatible storage | Images, documents, and related metadata selected for upload to the service. |
| Digital Matter | Device and Fleet Tag management and telemetry. Device, vehicle, location, and diagnostic information may be exchanged. |
| 1NCE | SIM connectivity and usage. SIM, device, usage, and connectivity information may be exchanged. |
| ServiceTitan | Optional customer-authorized synchronization of employee, technician, customer, job, and location context. |
| Cloudflare Pages and Cloudflare Turnstile | Marketing-site delivery, network protection, request handling, and bot detection. IP address, request metadata, challenge results, and submitted form context may be processed. |
| ClickUp | Contact and demo request intake. Names, business contact details, areas of interest, messages, submission time, and request identifiers may be transmitted. |
Flext may also use approved hosting, database, backup, logging, support, and security providers needed to operate the service. We contractually limit service providers to authorized purposes and require appropriate security and confidentiality measures. Provider details may change as the service evolves; material changes will be reflected in this Policy or an applicable customer agreement.
7.3 Live Share recipients
Information selected by a customer may be disclosed to anyone who possesses a valid Live Share link. Section 8 describes this feature and its risks.
7.4 Customer-enabled integrations
At a customer’s direction, Flext may exchange information with third-party applications, APIs, webhooks, or connected services. The third party’s own terms and privacy practices apply to its independent processing.
7.5 Legal, safety, and security disclosures
We may disclose information where we reasonably believe it is necessary to:
- comply with applicable law, legal process, subpoena, court order, or lawful government request;
- investigate fraud, security incidents, unlawful conduct, or violations of our agreements;
- protect the rights, safety, or property of Flext, a customer, an individual, or the public;
- respond to an emergency where disclosure is permitted by law; or
- establish, exercise, or defend legal claims.
7.6 Corporate transactions
Information may be disclosed in connection with a financing, merger, acquisition, reorganization, sale of assets, insolvency, or similar transaction, subject to applicable confidentiality, use, and legal requirements.
8. Live Share
Live Share allows an authorized customer user to create an expiring link for selected vehicles. A person with the link may be able to view:
- current vehicle location and heading;
- vehicle label, make, and model;
- driver name;
- licence plate;
- vehicle identification number;
- current speed and speed limit;
- alerts and geofence names; and
- realtime updates,
depending on the customer’s settings.
8.1 Bearer-link access
A Live Share link acts like a bearer credential: anyone who has it may be able to access the shared information while the link remains valid. Link creators must:
- share it only with intended recipients;
- use a secure communication channel;
- select only information reasonably necessary for the purpose;
- avoid posting it publicly unless public access is intended and authorized;
- revoke it when it is no longer needed; and
- have authority to disclose the relevant driver and vehicle information.
8.2 Recipient responsibilities
A recipient must not:
- republish or distribute the link or information without authority;
- scrape, systematically collect, or create a separate tracking database;
- stalk, harass, intimidate, discriminate against, or endanger anyone;
- use the information for unlawful surveillance;
- attempt to bypass expiry, revocation, rate limits, or access controls; or
- use Live Share contrary to applicable law or the customer’s instructions.
Links may expire, be revoked, or close when a trip ends. Flext cannot control information that a recipient copies, screenshots, records, or otherwise retains while access is valid.
9. Cookies, Local Storage, and Similar Technologies
9.1 Authentication cookies
The authenticated web application uses HTTP-only, SameSite=Lax cookies for:
- access tokens;
- refresh tokens; and
- trusted-device status.
These cookies are used to authenticate users, maintain sessions, and support account security.
9.2 Live Share cookies
A valid Live Share link may be exchanged for a strictly necessary HTTP-only cookie used to maintain access to the shared view.
9.3 Local storage
The web application may store functional preferences such as:
- sidebar state;
- company-specific map camera position;
- map style, layers, and marker mode;
- selected vehicle and Fleet Tag identifiers; and
- operator map-display preferences.
9.4 Session storage
Session storage may temporarily hold authenticator setup information, including a setup URI or secret, until setup is completed. Users should not share authenticator setup screens or leave setup unattended on a shared device.
9.5 Marketing-site security technologies
Cloudflare and Cloudflare Turnstile may use cookies, local storage, or similar technologies that are necessary to deliver the website, prevent abuse, and verify that a form submission is made by a person rather than an automated system.
9.6 Third-party map and address requests
Mapbox and Google Maps Places may receive location, search, IP, device, and request information necessary to provide map and address features. Their own privacy terms may also apply.
Flext does not use advertising cookies, behavioural-advertising SDKs, or session-replay technology on the reviewed website and applications.
10. International and Cross-Border Processing
Flext is a Canadian company. Flext and its service providers may process or store information in Canada, the United States, and other jurisdictions in which an approved provider operates or makes authorized support available. Flext does not make a Canadian-only hosting or backup commitment in this Policy.
When information is processed in another jurisdiction, it may be subject to that jurisdiction’s laws and may be accessible to courts, law-enforcement agencies, or national-security authorities in accordance with those laws.
Flext uses contractual and organizational measures intended to require service providers to protect information appropriately. Customers requiring a particular data-residency commitment must ensure that commitment is included in a signed Order, DPA, or service agreement.
11. Retention and Deletion
Flext retains personal information only as long as reasonably necessary for the identified purposes, customer instructions, contractual commitments, legal obligations, dispute resolution, security, fraud prevention, and legitimate recordkeeping.
Retention depends on the information and context. Customer-controlled information may follow settings selected by the customer or periods stated in an Order or DPA. Account and operational records are retained while needed to provide the service. Security, audit, support, and billing records are retained while reasonably required for their purposes and applicable legal obligations.
11.1 Customer configuration and instructions
Where the service provides retention controls, customers are responsible for choosing settings appropriate to their legal and operational requirements. Flext may preserve limited records where necessary to maintain audit integrity, establish or defend legal claims, investigate incidents, prevent fraud, or meet tax and accounting requirements.
11.2 Termination and deletion
Customers should export information they wish to retain before termination. After termination, Flext handles Customer Data according to available export functions, the applicable Order or DPA, and Flext’s operational retention schedule.
Production copies are deleted or deidentified when no longer reasonably required for an authorized purpose. Backup copies expire through ordinary protected backup rotation. Flext does not promise a fixed export, production-deletion, or backup-expiry deadline unless one appears in a signed agreement.
Deleting a user account may not remove every historical operational reference. Audit, billing, driver, vehicle, or security records may remain where independently required, controlled by the customer, or necessary for an authorized purpose.
12. Security
Flext uses administrative, technical, and physical safeguards designed to protect personal information in light of its sensitivity and the risks involved. Current safeguards may include:
- company-scoped and role-based authorization;
- multi-factor authentication;
- HTTP-only authentication cookies;
- hashed passwords and refresh tokens;
- protection of selected secrets and tokens;
- audit and security activity records;
- access restrictions and administrative controls;
- provider and infrastructure security measures; and
- backup, monitoring, and incident-response practices.
No method of transmission, storage, or security is completely secure. Flext does not guarantee absolute security.
Flext will not claim a certification, penetration-testing program, universal encryption-at-rest configuration, Canadian-only storage, or specific security service level unless that claim has been verified and formally approved.
Customers are responsible for:
- safeguarding credentials and Live Share links;
- using multi-factor authentication where available;
- managing authorized users and permissions;
- promptly removing access for departed or reassigned personnel;
- securing installed devices and customer networks; and
- notifying Flext of suspected compromise.
13. Privacy and Security Incidents
Flext maintains procedures to investigate and respond to suspected unauthorized access, use, disclosure, loss, or alteration of personal information.
Where required by applicable law, Flext will:
- assess the nature, scope, and potential harm of an incident;
- report a breach to the appropriate privacy regulator;
- notify affected individuals or support the customer in doing so;
- notify relevant organizations that may reduce the risk of harm; and
- retain required breach records.
The timing and content of a notice will depend on the circumstances and applicable law. Flext does not promise a fixed notification deadline unless a separate agreement expressly provides one.
Customers must promptly notify Flext of suspected incidents involving Flext accounts, credentials, links, devices, integrations, or Customer Data.
14. Individual Rights and Choices
Subject to applicable law, an individual may request:
- access to personal information;
- information about how it has been used or disclosed;
- correction of inaccurate or incomplete information;
- withdrawal of consent where consent is the legal basis;
- deletion or deidentification where applicable;
- information about Flext’s privacy practices; or
- review of a privacy complaint.
Flext may need to verify identity before responding. We may refuse or limit a request where permitted or required by law, including where disclosure would reveal another person’s information, confidential commercial information, legally privileged material, security-sensitive information, or information that cannot reasonably be severed.
For customer-controlled information, Flext may refer the request to the relevant customer and assist that customer. Customers are responsible for ensuring they can respond to requests concerning their own use of Flext.
To make a request, contact [email protected] and include enough detail to identify the relevant account, customer organization, and information.
If a privacy concern is not resolved, an individual may contact the Office of the Privacy Commissioner of Canada or an applicable provincial privacy regulator.
15. Geographic Availability and Quebec
Flext’s standard service is offered to Canadian businesses outside Quebec. Flext is not currently offered or actively marketed in Quebec. A customer headquartered or primarily operating in Quebec, or a customer requesting service in another country, may use the service only with Flext’s separate written approval.
Where Quebec or another jurisdiction’s law nevertheless applies to personal information handled by Flext, Flext will comply with obligations applicable to its role. Availability restrictions do not remove rights that an individual has under applicable privacy law.
16. Operational and Marketing Communications
16.1 Operational communications
Flext and customers may send service-related messages necessary to:
- authenticate or secure an account;
- deliver configured alerts;
- provide billing, invoice, support, or service information;
- notify users of material service or policy changes; or
- administer a customer relationship.
Some operational communications cannot be opted out of while an account or feature remains active.
16.2 Marketing communications
Flext will send commercial electronic messages in accordance with applicable law, including Canada’s Anti-Spam Legislation where applicable. Marketing messages will use an appropriate consent basis, identify the sender, provide required contact information, and include a functioning unsubscribe mechanism.
An unsubscribe request does not prevent Flext from sending permitted operational or transactional messages.
17. Changes to this Policy
We may update this Policy to reflect changes in our services, providers, legal requirements, or practices.
For material changes, we will provide notice appropriate to the significance of the change, such as through:
- email;
- an in-application notice;
- an account-administration notice; or
- a notice on our website.
The “Last updated” date and version number identify the current version. Previous versions may be requested from [email protected].
Where law requires consent to a new purpose, Flext or the relevant customer will seek that consent before using information for the new purpose.
18. Contact and Complaints
Questions, requests, or complaints may be directed to:
Privacy Officer
Flext Inc.
Email: [email protected]
Telephone: +1 (226) 407-7960
Flext does not publish a physical business address on this website. We will investigate privacy complaints and explain the outcome, subject to legal and security limitations.
Related legal document
Review the document that accompanies this policy.