Privacy Policy
MapSafe is a convoy situational-awareness platform for pilot and escort vehicle operators. This policy explains what we collect, why, how long we keep it, who it is shared with, and how to get it deleted. It applies to the MapSafe mobile apps, the agent and transport-company dashboards, and the MapSafe API.
We are the data controller. Contact us at privacy@mapsafe.com.au.
1. What we collect
Account and business information
Name, email address, phone number, and the role you register as (pilot, load driver, steerer, viewer, agent, or transport company). Depending on role we also collect a driver licence number and issuing state, business structure details (ABN, ACN, entity type, trust name), a business address, and for pilots a home address. Licence details are self-attested; we do not currently verify them against any licensing authority.
Location data
This is the most sensitive category we handle, and the reason the app exists.
- Live position while you are on a job. When you join a convoy job and start work, the app records your device's position, heading, speed and GPS accuracy and shares it with the other members of that job, and with the agent and transport company responsible for it.
- In the background. Position is collected while the app is backgrounded or the screen is off, because a convoy does not stop when you put your phone down. See section 2.
- Home or current location, only if you turn it on. Pilots may optionally broadcast either their registered home address or a one-time "I'm here" snapshot, so an agent can see who is near a job. This defaults to off, it is not continuous tracking, and it can be switched off at any time.
Operational records
Jobs you are assigned to or create, the times you joined and started work, permits uploaded and the route information extracted from them, compliance documents and their expiry dates, invoices and payment status, and any incidents or charges recorded against a job.
Device and technical data
A push-notification token (if you enable notifications), and ordinary server logs including IP address and timestamps.
2. Background location — what it is used for
MapSafe collects location in the background for convoy safety awareness: so that the pilot vehicles and the load driver on a job can see one another's position in real time, including when the app is not on screen.
Oversize and over-mass road transport depends on the escort vehicles and the load keeping formation and knowing where each other are. If location stopped when the app was backgrounded, a driver would disappear from their own convoy's map at exactly the moment they were concentrating on driving.
Background location is collected only while you are an active member of a job you have joined and started. It is not collected when you are not working. You are asked to allow it separately from ordinary location permission, and you can revoke it at any time in your device settings — the app continues to work, with reduced awareness for your convoy.
3. How we use it
- To show convoy members each other's position, proximity and heading.
- To provide navigation along a permitted route, and advisory compliance checks (for example speed and positioning rules that apply in some states).
- To calculate hours and distance worked, and generate invoices from them.
- To let an agent roster, book and pay the pilots they supply.
- To produce compliance and incident reports for a job.
- To send you notifications about jobs, invitations, invoices and documents.
- To operate, secure, debug and improve the service.
We do not sell personal information, and we do not use it for advertising.
4. Who it is shared with
Other MapSafe users
Your position and role are visible to the other members of a job you are on, and to the agent and transport company responsible for that job. Your name, phone number and compliance status are visible to an agent whose pool you have joined. Nearby convoys see anonymised proximity information only — position without identity.
MapSafe staff and automated systems
Our staff, and automated systems acting on our behalf, may access your data where necessary to operate and support the service — investigating a fault, responding to a support request, or handling an incident. Access is limited to what the task requires.
Service providers
We use the following processors. Each receives only what its function requires:
- Supabase — authentication and database hosting. Holds account details and all operational records, including location history. Hosted in Sydney, Australia.
- Railway — application hosting for the MapSafe API. Hosted in Singapore.
- Mapbox — maps, geocoding, directions and turn-by-turn navigation. Receives coordinates and addresses in order to return maps and routes.
- Anthropic — used to extract structured route and condition data from permit PDFs you upload, and to summarise activity for agents and transport companies. Receives the permit content and the operational records being summarised. Anthropic does not train models on this data.
- Expo — push notification delivery. Receives your device push token and the notification content.
- Cloudflare — hosting for our web dashboards and this site.
Some of these providers process data outside Australia. We may also disclose information where required by law, or to protect the safety of a person.
5. How long we keep it
- Location history for a job — retained for the life of the job record, because it is the evidence behind billing, compliance and any incident report.
- Invoices and financial records — retained for at least seven years, as Australian tax law requires. These cannot be deleted on request; see section 6.
- Account details — retained while your account is open.
- Compliance documents — retained while relevant to the jobs they were relied on for.
6. Deleting your account and your data
You can delete your account at any time:
- In the app — Profile → Delete account.
- On the web — mapsafe.com.au/delete-account.
When you delete your account we remove your identifying information: name, email, phone number, licence details, addresses, business details and device tokens. Your login is destroyed and you cannot sign in again.
What is not deleted, and why. Records of work already done — the job, the hours, the route travelled, invoices issued — are not ours alone to erase. Another party has a legitimate and, in the case of tax invoices, legally required interest in them: the agent who paid you, the transport company whose load you escorted, and an insurer assessing an incident. Those records are kept but anonymised, so they no longer identify you. We would rather tell you this plainly than promise an erasure we cannot perform.
If you want a copy of your data, or believe something is wrong, email privacy@mapsafe.com.au.
7. Withdrawing consent
You can withdraw consent for specific collection without closing your account:
- Location while working — revoke location permission in your device settings, or leave the job. Convoy awareness stops working for you and for the people relying on seeing you, which is why we ask for it.
- Background location — revoke "Always" location permission in device settings; the app continues to work in the foreground.
- Home / current location broadcast — set it to Off on the Jobs tab. It is off by default.
- Notifications — turn them off in device settings.
Withdrawing consent does not affect processing already carried out.
8. Security
Data is encrypted in transit. Access to production systems is restricted. Report a vulnerability to security@mapsafe.com.au — see our security policy.
9. Children
MapSafe is a tool for working commercial drivers and the businesses that engage them. It is not directed at, and must not be used by, anyone under 18.
10. Complaints
If you are unhappy with how we have handled your information, contact us first at privacy@mapsafe.com.au. If you are not satisfied with our response you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
11. Changes
We will update this page when our practices change, and change the date at the top. Material changes affecting how location is used will be notified in the app.