Horus GPS

Website, business-contact, customer-account, and fleet-service data

Privacy Policy

Company:
CDL Protect Inc. d/b/a Horus GPS
Effective:
August 10, 2026
Version:
2026-08-10.1

This Policy explains how Horus GPS handles personal data through horusgps.io, sales and support interactions, customer accounts, and the Horus fleet platform. Business customers control most fleet and driver data and are responsible for their own notices, consents, and lawful instructions. Privacy contact: privacy@horusgps.io.

CDL Protect Inc. d/b/a Horus GPS ("Horus," "we," "us," or "our") provides commercial GPS, telematics, equipment-rental, and related services. This Policy applies to information we handle as a business or controller for our own purposes and describes our processing role when a business customer directs us to process fleet or driver data.

1. Our roles and whose data this covers

Website and business relationships. Horus acts as the business or controller for website visitors, prospects, account contacts, payers, support contacts, and users when we decide why and how to use their information for sales, account administration, security, legal compliance, and our own business operations.

Fleet and Service Data. A business customer generally decides which vehicles and individuals are monitored, why they are monitored, who may use the Service, and how long the customer needs the data. For that Customer Data, Horus generally acts as a processor or service provider under the Service and Equipment Rental Agreement.

Customer responsibilities. Customers must have lawful authority over each equipped vehicle, provide required notices, obtain required consent, respond to individuals' requests for data they control, restrict user access, and stop monitoring when authority ends. Individuals should first direct fleet-employment or vehicle-monitoring questions to the relevant customer.

2. Information we collect

Identity and contact information. Name, business, job title, business address, email, phone number, account username, and communications preferences.

Account and transaction information. Orders, selected plans and Devices, billing status, invoices, tax and shipping information, acceptance records, returns, disputes, and limited payment metadata. Payment-card numbers are handled by our payment processor rather than stored in full by Horus.

Website and lead information. Form entries, requested fleet size, product interests, demo or callback requests, referral source, campaign data, and scheduling details.

Device, vehicle, and telematics information. Device and vehicle identifiers; installation and diagnostic data; precise GPS location; route and movement; speed; ignition, power, sensor, and device status; geofence and alert events; and platform history available under the Service plan.

Command and safety records. Remote Immobilization and other commands, requesting user, time, Device and vehicle status, response, safeguards, failures, and related audit or support information.

User activity and security information. Login and authentication events, permissions, IP address, browser and device information, audit logs, suspected misuse, and security incident information.

Communications and support. Emails, texts, call details and recordings where notice and law permit, support tickets, diagnostic materials, feedback, and testimonial or release records.

Cookies and similar technologies. IP address, browser and device characteristics, pages and features viewed, interactions, approximate location derived from IP, referral information, and identifiers generated by analytics or preference technologies.

3. Sources of information

  • directly from individuals and business customers;
  • from authorized account administrators, installers, owners, lessors, fleet managers, drivers, employees, and contractors;
  • automatically from Devices, vehicles, browsers, applications, cookies, and Service use;
  • from payment, shipping, scheduling, communications, analytics, mapping, cellular, and support providers;
  • from public records, vehicle or ownership documents, law enforcement when authorized, and fraud or security sources; and
  • from referrals, marketing partners, and event or business-contact lists where lawful.

4. Why we use information

Provide the Service. Create and administer accounts; ship, activate, support, test, maintain, and recover Devices; display location and telematics; send alerts; execute authorized commands; process orders; and provide customer support.

Safety, security, and misuse prevention. Authenticate users; verify vehicle authority; record Remote Immobilization commands; investigate suspected unauthorized use; maintain system integrity; issue safety notices; and prevent fraud or abuse.

Transactions and communications. Process payments, returns, and equipment charges; send receipts, service notices, security messages, product updates, and responses; and maintain records of acceptance and consent.

Improve and operate our business. Diagnose performance, plan capacity, understand product use, train personnel, improve workflows, and create aggregated or deidentified analytics that do not reasonably identify an individual.

Marketing. Send business marketing where permitted, manage preferences and suppression lists, evaluate campaigns, and personalize business-facing website content. We do not use fleet Service Data for targeted advertising.

Law and rights. Comply with law and legal process; establish, exercise, or defend claims; enforce agreements; protect people, vehicles, property, and rights; and cooperate with authorized theft response.

5. Precise geolocation and other sensitive data

Precise geolocation. The Service processes precise vehicle location and related movement data. When Horus processes that data for a business customer, it does so under the customer's documented instructions and the Service Agreement. Customers must provide required notice and obtain required consent before monitoring. Where Horus must obtain consent directly under applicable law, we will request it before the sensitive processing.

Limited purpose. We use precise geolocation to provide fleet tracking, telematics, alerts, history, diagnostics, authorized commands, theft response, safety, support, and legal compliance. We do not use fleet precise geolocation for targeted advertising, data brokerage, or training a general-purpose artificial-intelligence model.

Minimization. We limit access through permissions, log sensitive commands, retain information under Section 10, and require customers to end access when their authority ends. Customers should configure user roles and retention features to match their legitimate need.

6. When we disclose information

Service providers and subprocessors. Hosting, database, connectivity, mapping, payment, shipping, email, SMS, scheduling, analytics, support, security, and professional-service providers operating under contract. Current examples may include Vercel, Supabase, Stripe, Resend, Twilio, Cal.com, PostHog, and Google, depending on the function used.

Customers and authorized users. Account, vehicle, user, telematics, location, command, and support information according to customer permissions and instructions.

Installers, carriers, and support partners. Information reasonably needed to install, ship, troubleshoot, maintain, replace, or recover equipment.

Law enforcement and safety recipients. Information when required by valid legal process, to respond to an emergency where permitted, or at an authorized customer's request in connection with a verified theft or safety matter.

Corporate transactions. Information to advisers, lenders, investors, and a successor in a merger, financing, acquisition, reorganization, bankruptcy, or sale, subject to appropriate protection and law.

Rights and compliance. Information when reasonably necessary to protect rights, prevent fraud or misuse, enforce agreements, or comply with law.

7. Sale, sharing, targeted advertising, and cookies

No sale for money. We do not sell personal data for money and do not sell fleet Service Data.

Analytics and legally defined sharing. We use first-party analytics technologies (PostHog and Google Analytics) to understand website and product use. We do not use advertising or cross-context behavioral tracking cookies. Some laws define "sale," "sharing," or "targeted advertising" broadly enough to cover certain cookie or partner disclosures even when no money is paid; where those laws apply, we provide the required notice and opt-out controls and honor qualifying browser-based opt-out preference signals.

Cookie choices. Because we use no advertising cookies, we take a notice-only approach rather than a consent banner. Our website honors the Global Privacy Control (GPC) signal: when your browser sends it, we disable our analytics for your visit. You can also limit nonessential technologies through browser settings and extensions, or email privacy@horusgps.io. Necessary technologies that support security, requested functions, and basic site operation cannot always be disabled. Blocking technologies may affect features.

Email and text choices. Marketing email includes an unsubscribe method. Marketing text messages are sent only after a separate opt-in; reply STOP to end them. Service, security, and transactional messages may continue where permitted and necessary.

8. U.S. privacy rights and requests

Depending on residence, relationship, and applicable law, an individual may have the rights listed below.

  • confirm whether we process personal data and access that data;
  • correct inaccurate personal data;
  • delete personal data, subject to lawful exceptions;
  • obtain a portable copy of data the individual provided or that law makes portable;
  • opt out of sale, sharing, targeted advertising, or certain profiling;
  • limit or withdraw consent for sensitive-data processing where applicable;
  • use an authorized agent, subject to verification; and
  • appeal a denied request and receive information about further complaint options.

How to request. Email privacy@horusgps.io with the subject "Privacy Request." Describe your relationship with Horus and the right requested. For data controlled by a business customer, we may direct the request to that customer or assist it.

Verification and timing. We will verify a request proportionately, respond within the period required by applicable law, ordinarily 45 days, and explain any extension or denial. We may request account, contact, vehicle, or transaction details needed to confirm identity and authority. We will not discriminate for exercising a privacy right.

Appeal. To appeal a denial, email privacy@horusgps.io with the subject "Privacy Appeal" within 30 days after the decision. A different reviewer will evaluate the appeal, and we will respond within the time required by law.

9. Customer-controlled data requests

Fleet and employment data. When a business customer controls fleet, driver, or employee data, the customer is responsible for deciding whether to grant access, correction, deletion, portability, or objections. Horus will reasonably assist under the Agreement and applicable law.

Lawful preservation. We or a customer may preserve information needed for security, fraud prevention, safety investigations, legal holds, claims, billing, equipment recovery, or another lawful exception. A deletion request does not require deletion of information lawfully retained for those limited purposes.

10. Retention

We keep personal data only for the period or under the criteria below, subject to shorter customer settings, legal holds, disputes, security needs, and applicable law.

Data categoryRetention period or criterion
Location and telematics historyThe rolling history period included in the selected Service plan, then deleted or deidentified from active systems within a reasonable operational period; backups expire on their ordinary cycle.
Commands and safety audit logsFor the Service term and generally up to seven years afterward when reasonably needed for safety, claims, authority, and compliance records.
Account, Order, billing, acceptance, and return recordsFor the business relationship and generally seven years afterward for contract, tax, accounting, payment, and dispute purposes.
Support and security recordsFor the time needed to resolve the matter and generally up to three years afterward; serious security or legal records may be retained longer where necessary.
Website analytics and cookie identifiersUnder the configured analytics retention period, generally no longer than 14 months unless a shorter period or lawful operational need applies.
Prospect and marketing recordsUntil opt-out or generally 24 months after the last meaningful interaction; suppression records are retained as needed to honor the opt-out.

At the end of a retention period, information is deleted, securely destroyed, or deidentified unless continued retention is legally required. Residual copies may remain temporarily in protected backups and are not restored except for recovery or legal need.

11. Security

Safeguards. We maintain administrative, technical, and physical safeguards designed for the nature of the information and risk, including access controls, authentication, logging, vendor management, incident response, and protection of data in transit where appropriate. No method is completely secure.

Customer security. Customers must use individual accounts, least-privilege roles, available multi-factor authentication, prompt user removal, secure installation practices, and immediate notice of suspected unauthorized access. Customers should not send payment-card numbers or unnecessary sensitive information through ordinary email or support forms.

Incident handling. We investigate suspected incidents and provide notices and cooperation required by law and our contracts. Customers must maintain current Account Administrator and security contacts.

12. Communications

Service communications. We may send account, order, billing, safety, security, support, and operational messages by email, text, in-app message, push notification, or phone using contact information provided by the customer. These are not marketing merely because they relate to a commercial service.

Marketing. We send marketing email or text only where permitted. Marketing text consent is separate from purchase and can be withdrawn by reasonable methods, including STOP. We maintain suppression records so we can honor opt-outs.

Call recording. We may record support or sales calls after providing notice and obtaining consent where required. We use recordings for quality, training, support, security, and dispute resolution.

13. Children's data

The website and Service are business offerings not directed to children under 18. We do not knowingly collect personal data directly from a child for account use. Contact us if you believe a child submitted data without appropriate authorization.

14. Other sites and services

Our website may link to third-party sites, maps, scheduling tools, payment pages, applications, or documentation. Their privacy practices are governed by their own notices. Customers should evaluate third-party integrations before enabling them.

15. Changes to this Policy

We may update this Policy prospectively. We will post the updated version with a new date and provide additional notice of material changes where required, including direct notice to customer administrators when the change materially affects Service Data. If applicable law requires consent or an opportunity to withdraw for a new sensitive-data purpose, we will provide it before that processing.

16. Contact us

Privacy requests and questions: privacy@horusgps.io. Mail: CDL Protect Inc. d/b/a Horus GPS, Attn: Privacy, 157 Church St, 19th Floor, New Haven, CT 06510. Phone: (779) 200-3401. Website: https://horusgps.io.