What we collect, why, and how long we keep it.
Last updated 23 September 2026
GreatFleet is delivery software for couriers moving dental work between laboratories and dental practices. Two different groups of people appear in it, and they are in very different positions.
People who use GreatFleet — drivers, dispatchers and laboratory staff — have an account and chose to sign in.
People who receive a delivery mostly did not choose anything. A practice's contact details are entered by the laboratory that sends to them, and whoever answers the door when a package arrives may have their name and signature recorded. This policy covers both, and the second group is the reason several sections below exist.
Location, including while the app is in the background. While a driver is signed in and on shift, the app reports the vehicle's position so their own dispatcher can see where a round has got to and give the receiving practice an accurate arrival time. This is the most sensitive thing the app does, so to be exact about it: collection runs during a shift and stops when the driver goes offline. It is not collected when the driver is not working. If location permission is declined the rest of the app still works — the route, the stop list and proof of delivery all function, and only live tracking is lost.
Proof that a delivery arrived. Completing a stop records a photograph taken at the door, a signature, the name the recipient gives, and the position and time at which that happened.
Barcodes scanned when loading a van. Scanning happens on the device; the camera image is not sent anywhere.
Account details — name, email address, and the fleet the account belongs to.
Device details needed to deliver notifications and to keep a session working: a push notification token, the app version, and the device model and operating system.
We do not sell personal data, we do not share it with advertisers or data brokers, and we do not use it to build advertising profiles. A driver's location is visible to their own fleet, not to other fleets and not to us as a product.
Diagnostic reporting is configured not to send personal information: crash reports have personal information disabled at source, screenshots are switched off, and request contents are stripped before a report leaves the device.
The fleet the data belongs to. Each laboratory sees only its own deliveries, drivers and vehicles. Fleets are separated from one another, and a person signed into one fleet cannot read another's records.
The practice receiving a delivery can follow the tracking link for that delivery.
Suppliers who run parts of the service on our behalf, under contract and only to provide it: our hosting and database provider, Google (maps, routing, push notifications), our error and crash reporting provider, and our email provider for sign-in codes and notifications.
We also disclose data where the law requires it.
In the United Kingdom. The service runs from a single region in London, and that is where the database lives. Some of the suppliers above process limited data outside the UK; where they do, that transfer is covered by the safeguards in our contracts with them.
Delivery records, including proof of delivery, are kept for as long as the fleet's account is active, because a laboratory needs to be able to show that a delivery arrived. Account details are kept while the account exists.
Location history is the exception worth stating separately: it exists to show where a van went during a shift, and it is not needed indefinitely for that purpose.
If you want a specific record removed sooner, contact us using the address below and we will deal with it.
Under UK data protection law you can ask for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, object to how we are using it, or ask us to restrict that use. If you received a delivery and want the signature or doorstep photograph relating to it removed, you can ask for that too.
Write to support@greatfleet.io. If the records concern deliveries made by a particular laboratory, we may need to pass the request to them, because it is their delivery record — we will tell you if that happens.
You can also complain to the Information Commissioner's Office, the UK regulator, at ico.org.uk.
GreatFleet is a tool for people doing a job. It is not directed at children and we do not knowingly collect data about them.
Traffic is encrypted in transit. Sign-in is by a one-time code sent to your email address rather than a password you have to remember and reuse. Files such as delivery photographs are stored under keys the system generates, and are reachable only through short-lived links issued to someone who is entitled to see them.
No system is perfectly secure, and we do not claim otherwise.
If this policy changes materially we will update the date at the top of this page and, where the change affects how we use data people have already given us, tell account holders directly.
Questions about this policy, or about data we hold: support@greatfleet.io.