+65 6727 6060sales (at) itrack (dot) com (dot) sg SupportLogin

Legal

Privacy Policy

How we handle personal data under Singapore's Personal Data Protection Act 2012 — what we collect, why, who we share it with, how long we keep it, and what you can ask us to do.

Effective: 1 August 2026  ·  Version: 2.0  ·  Entity: Pivotal Pte Ltd (Singapore)

Scope of this policy

This Privacy Policy explains how Pivotal Pte Ltd, trading as iTrack, collects, uses, discloses and protects personal data. It applies to itrack.com.sg, to the iTrack platform and mobile applications, and to all GPS services and goods we market (together, the "Services").

We handle personal data in accordance with the Personal Data Protection Act 2012 of Singapore (the "PDPA").

Contractual terms are set out separately in our Terms of Service.

Two roles we play

This distinction matters, because different rights apply depending on which situation you are in.

When we act for ourselves

For our own website visitors, enquirers and account contacts, we determine why and how personal data is used. If you contacted us, or hold a login on your employer's account, this policy governs how we handle your data and you may exercise the rights in section 8 directly with us.

When we act on a customer's instructions

When a fleet operator uses the Services to track its own vehicles, drivers or staff, that organisation decides what is collected and why. We process that data on their instructions. If you are a driver or employee of one of our customers, direct access, correction and withdrawal requests to your employer in the first instance. We will support them in responding, and will not disclose their data to you without their authorisation, except where the law requires it.

Personal data we collect

CategoryWhat it includes
Contact and identityName, business email, telephone number, job title, company name
AccountUser ID, hashed password, access level, account activity and audit logs
BillingBilling address, payment references, invoice and payment history
Location and telematicsVehicle position records, trip histories, speed, engine and sensor readings, geofence events
Driver-linked dataDriver identifiers where driver ID readers are used, driver behaviour events and scores
Video and imageDashcam footage and still images where video telematics is subscribed
TechnicalIP address, browser and device information, referring URL, pages viewed

Payment card data. We do not store full payment card numbers on our systems. Card payments are handled by our payment provider.

Where a field is required in order to provide a service we indicate this. Fields not marked as required are optional.

Why we use personal data

  • to provide, operate and support the Services you or your employer have subscribed to;
  • to authenticate users and maintain account security;
  • to invoice, collect fees owed, and maintain accounting records;
  • to respond to enquiries, provide technical support and troubleshoot faults;
  • to notify you of service changes, maintenance windows and security matters;
  • to detect, investigate and prevent fraud, misuse and unauthorised access;
  • to produce aggregated, de-identified statistics about platform performance and usage;
  • to comply with legal, regulatory and tax obligations.

Marketing

We will only send marketing communications where you have consented or where permitted for existing business contacts. Every marketing message includes an unsubscribe option, and you may withdraw consent at any time under section 8.

We do not use Subscriber Data to train machine learning models, and we do not build products for other customers from it.

Disclosure of personal data

We do not sell or rent personal data to third parties for their marketing purposes, under any circumstances.

  • Service providers. Hosting, connectivity, payment processing and mapping providers who process data on our behalf under written obligations of confidentiality and security.
  • Your organisation. Where you are an Authorised User, your account administrator can see activity carried out under your login.
  • Regulatory integrations. Where you have instructed us to forward vehicle or geofence events to a regulatory system, we transmit the data you have configured for that purpose.
  • Corporate transactions. In connection with a merger, acquisition or sale of assets, subject to equivalent protections applying.
  • Legal obligation. As described below.

Requests from law enforcement

We will disclose personal data in response to a subpoena, court order, warrant or other legally binding requirement. We will also disclose where we believe in good faith that disclosure is necessary to prevent imminent physical harm or serious financial loss, or to report suspected illegal activity.

Where we receive a request that is not legally binding on us, we will assess it and, unless prohibited by law, notify the affected customer before disclosing anything, so they have the opportunity to respond.

Where your data is stored

Personal data, Subscriber Data and recording files are stored on secure servers located in Singapore, operated by us.

We maintain backup and disaster recovery procedures for this data. The technical detail is not published, for the reasons set out in our Terms of Service; a description of current arrangements is available on request under a non-disclosure agreement.

Where a service provider necessarily processes limited data outside Singapore, we will ensure the transfer meets the standard of protection required by the PDPA, by contract or other lawful mechanism.

How long we keep it

DataRetention
Position and trip historyFor the duration of the subscription, and for the period configured by the customer
Video and image filesFor the retention period configured by the customer, subject to device storage
Account and contact recordsFor the duration of the relationship, then up to 12 months
Invoices and accounting records5 years, as required by Singapore law
Security and access logsUp to 12 months
BackupsUntil the backup cycle overwrites them
After terminationMay be deleted from active systems; download what you need before your subscription ends

You may retrieve Subscriber Data through the platform's reporting tools at any time while your subscription is active. Access to those tools ends on the effective date of termination, so download what you need before your subscription ends. After termination we may delete Subscriber Data from active systems. We may retain limited records where necessary to prevent fraud, collect fees owed, resolve disputes or comply with law.

Your rights

Under the PDPA you may:

  • Access the personal data we hold about you, and information on how it has been used or disclosed in the past year;
  • Correct personal data that is inaccurate or incomplete;
  • Withdraw consent to our use or disclosure of your personal data, on reasonable notice;
  • Request deactivation of your account and associated contact, billing and financial information.

How to make a request

Email our Data Protection Officer at sales (at) itrack (dot) com (dot) sg with "PDPA request" in the subject line. We will acknowledge within 10 business days and respond substantively within 30 days. If we cannot meet that timeframe we will tell you when we can.

We may need to verify your identity before acting on a request. Where a request would affect the rights of another party, or where we are legally required to retain the data, we will explain what we can and cannot do.

Withdrawing consent may mean we can no longer provide some or all of the Services to you.

Security

We apply procedural and technical safeguards to protect personal data against loss, theft, unauthorised access and unauthorised disclosure, including access controls, role-based permissions, encryption in transit, audit logging and segregation between customer accounts.

No system connected to the internet can be guaranteed perfectly secure and we do not claim otherwise. If a data breach occurs that is likely to result in significant harm, or that meets the notification thresholds under the PDPA, we will notify the Personal Data Protection Commission and affected individuals or customers as required.

Your part

  • You are responsible for all actions taken under your user ID and password, including fees charged.
  • Do not share credentials. If you share them with a third party, you are responsible for what they do.
  • Change your password immediately if you believe it has been compromised, and tell us.

Cookies and website analytics

Our website uses cookies and similar technologies to keep you signed in, remember preferences, and understand how the site is used so we can improve it.

You can block or delete cookies through your browser settings. Blocking essential cookies may prevent parts of the site or platform from working.

Children

The Services are intended for business use by adults. Persons under 18 may not use the Services unsupervised, and we ask that they do not submit personal information to us. If you are under 18, use this site only with the involvement of a parent, guardian or employer.

If we become aware that we have collected personal data from a person under 18 without appropriate authorisation, we will delete it.

Changes to this policy

We may update this policy. Where a change materially affects how we use your personal data, we will give at least 30 days' notice before it takes effect, by posting the updated policy and notifying registered account contacts.

The effective date and version at the top of this page always reflect the current version. Continued use of the Services after a change takes effect indicates acceptance.

Contact and complaints

Data Protection Officer
Pivotal Pte Ltd (trading as iTrack)
80 Kaki Bukit Industrial Terrace
Singapore 416160

Email: sales (at) itrack (dot) com (dot) sg
Telephone: +65 6727 6060

If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Commission of Singapore.

Contact us

Common questions

Does iTrack store fleet data in Singapore?
Yes. Personal data, subscriber data and recording files are stored on secure servers located in Singapore and operated by iTrack. Where a service provider necessarily processes limited data overseas, the transfer must meet the standard of protection required by the PDPA.
Can I get my data after my iTrack subscription ends?
Download what you need before your subscription ends. While the subscription is active you can retrieve data at any time through the platform's reporting tools, without charge and with no limit on frequency. Access to those tools ends on the effective date of termination.
I am a driver tracked by my employer. Who do I contact about my data?
Your employer decides what is collected and why, and iTrack processes that data on their instructions. Direct access, correction and withdrawal requests to your employer in the first instance. iTrack will support them in responding but will not release their data without authorisation.
How do I make a PDPA access or correction request to iTrack?
Email the Data Protection Officer, using the address published on the contact page, with \u201cPDPA request\u201d in the subject line. iTrack acknowledges within 10 business days and responds substantively within 30 days.
Does iTrack sell personal data?
No. iTrack does not sell or rent personal data to third parties for their marketing purposes under any circumstances, and does not use subscriber data to train machine learning models.
Will iTrack give my data to law enforcement?
iTrack will disclose personal data in response to a subpoena, court order, warrant or other legally binding requirement, or where necessary to prevent imminent physical harm or serious financial loss. Where a request is not legally binding, iTrack will notify the affected customer before disclosing anything unless prohibited by law.