Provider: AquilaIQ LLC, operating FleetSynq
(“AquilaIQ,” “FleetSynq,” “we,” “us,” or “our”)
Effective
date: September 13, 2026
Privacy contact:
privacy@aquilaiq.com
This Privacy Policy explains how AquilaIQ collects, uses, discloses, retains, and protects personal information through FleetSynq, its web application, backend API, driver portal and paperwork links, support channels, and related services (collectively, the “Service”).
For AquilaIQ’s own account administration, security, support, product operation, and business records, AquilaIQ generally acts as a controller or business. For company operational data processed on a customer’s instructions, the customer generally acts as controller or business and AquilaIQ acts as processor or service provider. The Customer Agreement and data processing addendum govern that processing. Customers are responsible for giving required notices to drivers, employees, brokers, carriers, and other people whose information they submit or connect.
Depending on how you use FleetSynq, we may collect:
Please do not upload unnecessary sensitive personal information, payment-card numbers, bank credentials, passwords, or secrets into documents, notes, email, or prompts.
We collect information from users and administrators; from Supabase authentication and database records; from Google OAuth, Sheets, Drive, and Gmail when a customer authorizes those integrations; from uploaded files and connected business systems; from driver sign-up and capability-link workflows; from support and communications; and automatically from browsers, devices, APIs, and server logs.
We use information to:
We do not sell personal information for money.
Where GDPR, UK GDPR, or similar law applies, AquilaIQ may rely on performance of a contract, steps requested before a contract, legitimate interests in operating and securing an enterprise service, consent where required, and compliance with legal obligations. When AquilaIQ acts as a processor, it processes Customer Data under the customer’s documented instructions and the customer determines the legal basis.
When a customer connects Google Workspace, FleetSynq requests and uses scopes for Sheets, Drive, Gmail sending, Gmail read-only access, and the Google account email needed for onboarding. FleetSynq uses the customer’s authorized Google resources to create or update company-specific projections, organize files, search relevant threads, and send configured operational messages. Customers may revoke access through Google; doing so may disable related features.
FleetSynq sends eligible document text and, for supported Rate Confirmation extraction, page images to Google Gemini. Gemini returns candidate structured fields that users review before commit. The Service may log processing errors and warnings. Do not send unnecessary personal or sensitive data to Gemini through FleetSynq. Google’s terms and privacy practices also apply to Google’s independent processing.
We may share or make information available to:
We do not rent or trade personal information. We do not disclose Customer Data to unrelated third parties for their own advertising.
FleetSynq uses browser storage and similar mechanisms for authentication sessions, cross-tab auth state, setup progress, and necessary application behavior. The reviewed frontend uses local storage for Supabase authentication state in normal operation and session storage for setup and workflow state. The current reviewed code does not identify a separate advertising cookie, Google Analytics tag, or Clarity tag.
Browser controls can clear or block local/session storage, but doing so may sign you out or reset setup state. If analytics, advertising, or non-essential cookies are introduced, AquilaIQ must update this Policy and implement consent or opt-out controls where required by law.
AquilaIQ and its providers may process information in the United States and other countries. Where required, AquilaIQ uses recognized transfer safeguards, such as contractual clauses and supplementary measures appropriate to the transfer. Customer-specific residency and transfer commitments belong in the Customer Agreement or data processing addendum.
We retain information only as long as reasonably necessary for service delivery, security, support, dispute resolution, and legal obligations. FleetSynq’s reviewed code does not establish one universal retention period for all tables, uploaded files, Google resources, emails, logs, or backups. Retention and deletion must therefore be confirmed in the Customer Agreement, data processing addendum, configuration, and documented operational schedule.
Subject to those terms and legal obligations, customers may request return or deletion of Customer Data. Terminating FleetSynq does not automatically delete copies in customer-controlled Google Sheets, Drive, Gmail, connected systems, exports, or backups. Supabase authentication records, audit records, invoices, security logs, and legal records may need to be retained for defined periods. Deletion from active systems may not immediately remove encrypted backups.
FleetSynq’s current implementation includes Supabase JWT validation for protected routes, role and company checks, company-scoped operational queries, hashed and revocable driver capability tokens, per-company Google resource boundaries, Drive ancestry checks, file and input validation, rate limits, audit events, operation leases, security headers, and server-side handling of provider credentials. No method of transmission, storage, AI processing, or third-party service is completely secure, and controls may vary by deployment.
Customers must protect credentials and capability links, use least-privileged roles, maintain Google permissions, review outbound messages and attachments, and notify AquilaIQ of suspected compromise or unauthorized disclosure.
Depending on your location and AquilaIQ’s role, you may have rights to request access, correction, deletion, restriction, portability, objection, withdrawal of consent, or appeal of a denied request. You may also have the right to complain to a data-protection authority and opt out of certain targeted advertising, sale, sharing, or profiling. AquilaIQ does not sell personal information for money.
Send requests to privacy@aquilaiq.com. We may verify identity and authority, apply lawful exceptions, and direct requests about Customer Data to the customer that controls it. An authorized agent may submit a request where law permits. We will respond within the time required by applicable law.
FleetSynq is designed for businesses, logistics professionals, and authorized adult users. It is not directed to children under 18, and we do not knowingly collect children’s personal information through consumer use. If you believe a child provided information to AquilaIQ, contact privacy@aquilaiq.com.
FleetSynq may link to or interoperate with third-party services that AquilaIQ does not control. Their own terms and privacy policies apply to independent processing. Review Google, Supabase, Gemini, carrier, broker, payment, and other connected-provider notices before authorizing access or sending information.
We may update this Policy as FleetSynq, its providers, or applicable law changes. We will post a revised version with a new effective date. If a change materially affects active customers or requires consent, we will provide additional notice or obtain consent as required.
Questions, requests, or complaints may be sent to:
AquilaIQ LLC — FleetSynq
Privacy:
privacy@aquilaiq.com
Legal: legal@aquilaiq.com
Support:
support@aquilaiq.com