Privacy

Privacy policy.

How we handle your data - for the website and the TrackLog platform, clearly and in line with the GDPR.

English courtesy translation of the privacy statement. Processing follows the GDPR and the Austrian Data Protection Act (DSG). If wording differs, the German Datenschutzerklärung prevails.

1. Controller

TrackLog System GmbH
Spitalgasse 1/43, 1090 Vienna, Austria
Represented by: Arne Rünger, Jonas Regul
Phone: +43 670 607 23 17
Email: office@tracklog.at

This statement covers the marketing website tracklog.at as well as the TrackLog web application (including map.tracklog.at, demo.tracklog.at) and related services.

2. General information on processing

We process personal data only to the extent required to provide our website and our services. The legal framework is the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (Datenschutzgesetz, DSG).

Depending on the role, we may act:

  • as controller (for example website visitors, prospects, our own customer contacts), or
  • as processor for our customers (tenants) when they use TrackLog for fleet coordination and thereby process personal data (for example drivers, location data). In that case the customer remains the controller; the data-processing agreement (DPA) under Art. 28 GDPR applies.
3. Hosting and server log files

Website and platform run on servers in the European Union (hosting including Hetzner Online GmbH, Germany). When you visit, server log files are stored automatically:

  • Browser type and version
  • Operating system used
  • Referrer URL
  • Hostname of the accessing computer
  • Time of the server request
  • IP address

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operation, security and error analysis). Retention: typically a few days to weeks, unless longer storage is required for security reasons.

4. Contact form

If you send us an enquiry via the contact form, we store your details to handle it.

Data processed: name, company, email address, phone (optional), number of vehicles, message content, and technical metadata (for example IP, user agent) to prevent abuse.

Legal basis: Art. 6(1)(b) GDPR (steps prior to entering a contract) or Art. 6(1)(f) GDPR (legitimate interest).

Retention: until the enquiry has been fully handled, then deletion unless statutory retention duties apply.

5. Order form

When you order via our order form we process: name, company, email address, phone (optional), billing address, VAT number (optional), number of vehicles and chosen billing cycle.

To store the order we use Supabase (Supabase Inc.) with data hosted in the EU (Frankfurt am Main, Germany) as a processor. To send order and confirmation emails we use Brevo (Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany) as a processor.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract or steps prior to entering a contract).

Retention: for the duration of the business relationship and statutory retention duties (in particular § 132 BAO: 7 years).

6. TrackLog platform (GPS fleet coordination)

As a SaaS service we provide customers with a platform to locate and coordinate vehicles. The following describes typical processing; details may be set out in the DPA and the terms.

6.1 Registration and user accounts

For access we store, among other things, email address, password hash, name (optional), role (for example admin, user), tenant/company assignment, and login and security metadata.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract). Retention: for the life of the user account or the contractual relationship; then deletion or anonymisation unless statutory duties apply.

6.2 Vehicle, GPS and trip data

Via GPS trackers (TrackLog T1 / compatible devices) and the platform we process in particular:

  • Vehicle master data (for example name, number plate)
  • Location data (position, time, speed, heading)
  • Trip / logbook data (start/end, distance, addresses, business/private purpose, notes)
  • optional telematics/OBD data (for example consumption, engine data), where used by the customer
  • Geofencing zones and related events
  • Alerts and notifications (email/SMS to stored recipients)

Where this data relates to a person (for example driver assignment, movement profiles), the customer is the controller. TrackLog processes it on the customer's behalf.

Legal basis at the customer: typically Art. 6(1)(b) and/or (f) GDPR and - where required - consent or employment-law grounds. TrackLog as processor: Art. 28 GDPR in conjunction with the DPA.

Retention: according to the customer's configuration and contract; after the contract ends, deletion or return as provided in the terms/DPA, subject to statutory retention duties.

6.3 Driver data

Customers may create driver profiles (for example name, contact, assignments). Processing is on the customer's behalf. The customer is responsible for a lawful basis vis-à-vis the data subjects and for informing them where required.

6.4 Privacy mode

The platform can provide a privacy mode for vehicles/drivers that restricts live location. Whether and how it is used is controlled by the customer in their settings.

6.5 Maps, routing and geocoding

For map display and address resolution we use map services (including OpenStreetMap/OpenFreeMap map data, Nominatim geocoding; routing/map matching via self-hosted OSRM instances in the EU). Position or address information may be transmitted to those services to the extent required for the function.

6.6 Email and SMS notifications

For transactional emails (for example alerts, password reset, system notices) we use Resend as a processor. For SMS alerts a dedicated SMS gateway and/or Twilio (Twilio Inc.) may be used, where configured by the customer.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract) or, as processing on behalf, Art. 28 GDPR.

6.7 Public rental booking

If a tenant has enabled the public booking page (feature booking_enabled), rental prospects can place a reservation at /b/:slug. In that case we process on the tenant's behalf:

  • Name, email address, phone number
  • Date of birth
  • Driving-licence details (for example class, country of issue) and driving-licence photo including technical metadata
  • IP address (among other things to prevent abuse)

Without this enablement the booking page cannot be used. The tenant remains the controller. TrackLog processes the details on their behalf.

Legal basis at the tenant: typically Art. 6(1)(b) GDPR (steps prior to / performance of a contract). TrackLog as processor: Art. 28 GDPR in conjunction with the DPA.

6.8 ID and driving-licence uploads

For compliance workflows, tenants or drivers may store ID and driving-licence photos (front and back) in the platform. Image files are stored on the server (disk, EU hosting) and linked to the relevant driver or booking process. Processing is on the tenant's behalf.

6.9 Two-factor authentication (superadmin)

Accounts with the superadmin role must complete a second step at login. Available options:

  • TOTP via an authenticator app
  • One-time code by email (email OTP), sent via Resend from TrackLog <no-reply@tracklog.at>

Ordinary tenant users (admin, dispatch, driver) do not have this 2FA. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in securing superadmin access).

7. Cookies and analytics

We distinguish technically necessary cookies from analytics tools. Umami Cloud on the marketing website tracklog.at is loaded only after explicit consent (opt-in under the Austrian TKG 2021 and the GDPR). Analytics in the web application and first-party capture on tracklog.at are described in 7.4 and 7.5.

7.1 Technically necessary cookies

For login to the TrackLog web application we set the technically necessary cookie fleet_token (session/authentication cookie, httpOnly). The platform cannot be used without this cookie.

The marketing website tracklog.at itself does not set technically necessary cookies.

Legal basis: Art. 6(1)(f) GDPR or § 165(3) TKG 2021 (strictly necessary).

7.2 Analytics tools (Umami Cloud)

For anonymous evaluation of use of the marketing website tracklog.at (page views, referrer, device type) we use Umami Cloud (Umami Software, Inc., cloud.umami.is). Umami does not set tracking cookies and does not create user profiles. Aggregated usage data is processed (including page URL, referrer, browser/OS, anonymised IP).

On tracklog.at the analytics script is loaded only after your explicit consent via the cookie banner. Without consent this Umami analysis does not take place on the marketing website.

Legal basis: Art. 6(1)(a) GDPR (consent). You can withdraw consent at any time via "Cookie settings" in the footer or by deleting tl_cookie_consent in local storage.

Further information: Umami privacy policy.

7.3 Security mechanisms (Cloudflare Turnstile)

To protect against spam we use Cloudflare Turnstile (Cloudflare, Inc.) on the contact form (and, where applicable, at registration). Technically required data may be transmitted to Cloudflare.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in preventing spam and abuse).

7.4 Usage analytics of the web application (map.tracklog.at)

In the TrackLog web application (including map.tracklog.at, demo.tracklog.at), Umami Cloud (cloud.umami.is) is loaded with the application - without the marketing website cookie banner. The same technical properties as in 7.2 apply (no tracking cookies, no user profiles, aggregated usage data). The native app (iOS/Android) does not load this script.

7.5 First-party analytics of the marketing website

In addition, tracklog.at sends usage events to our own endpoint analytics.gettracklog.com (page view, clicks, referrer, UTM parameters, session duration). A visitor ID (local storage) and a session ID (session storage) are set for this. This endpoint is not part of the cookie banner.

8. Recipients and processors

Depending on the function, the following categories of recipients may receive data:

  • Hosting providers in the EU (including Hetzner Online GmbH)
  • Email sending (Resend; for orders Brevo)
  • SMS services (dedicated gateway and/or Twilio)
  • Order database (Supabase, EU region)
  • Bot protection (Cloudflare Turnstile)
  • optional website analytics of the marketing website (Umami Cloud, only after consent)
  • Usage analytics of the web application (Umami Cloud, map.tracklog.at)
  • First-party analytics of the marketing website (analytics.gettracklog.com)
  • Map services (OpenStreetMap/OpenFreeMap/Nominatim and others)

Where required we conclude data-processing agreements under Art. 28 GDPR. A current overview of subprocessors is available to customers on request or in the DPA.

9. Transfers to third countries

As a rule we store platform data in the EU. Individual providers (for example Umami Cloud, Cloudflare, Twilio, Resend) may be established outside the EU/EEA or use infrastructure there. In those cases transfer takes place only where appropriate safeguards exist (for example EU standard contractual clauses, an adequacy decision / Data Privacy Framework), where legally required, and - for Umami on the marketing website - additionally after your consent.

10. Retention (overview)

We store personal data only as long as required for the respective purposes or as statutory duties demand. Typical periods:

  • Server logs: short-term (operation/security)
  • Contact enquiries: until handled
  • Contract and invoice data: up to 7 years (§ 132 BAO)
  • Customer platform data: according to contract/DPA and customer configuration
11. Your rights

You have the following rights vis-à-vis us regarding your personal data:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent (Art. 7(3) GDPR)

To exercise these rights, contact office@tracklog.at. The steps to delete your TrackLog account are described at tracklog.at/en/account-loeschen.

If you are a driver or user of a TrackLog customer, please address access and erasure requests first to your employer or the TrackLog customer (controller). We support the customer under the DPA.

12. Right to lodge a complaint with the supervisory authority

You have the right to lodge a complaint with the Austrian Data Protection Authority:

Österreichische Datenschutzbehörde
Barichgasse 40-42, 1030 Vienna
Phone: +43 1 52 152-0
Email: dsb@dsb.gv.at
Web: www.dsb.gv.at

13. Changes

We may adapt this privacy policy if services, the legal situation or technical processes change. The current version is available at tracklog.at/en/datenschutz. The binding German text is at tracklog.at/datenschutz.

This privacy policy is currently in force and is dated September 2026. Binding wording: German privacy policy.