Who we are
Compass Solutions ("Compass", "we", "us"), established in Tunisia, operates the Compass GPS fleet-tracking platform — the web dashboard and the Compass GPS mobile app on Android and iOS. The service is provided to fleet operators and their drivers in Tunisia. This policy explains what data we collect, why, how long we keep it, and what choices you have about it under Tunisian law.
This policy is governed by Organic Law n° 2004-63 of 27 July 2004 on the protection of personal data and is supervised by the Tunisian National Authority for the Protection of Personal Data (Instance Nationale de Protection des Données Personnelles, "INPDP").
If you signed in via your fleet operator, your operator is the data controller (responsable du traitement) for vehicle and driver data attached to their organization; Compass is the data processor (sous-traitant). For your account credentials and platform access, Compass is the controller.
Notice to drivers — vehicle monitoring
Compass GPS is a workplace monitoring tool. When you drive a vehicle equipped with a Compass-supported GPS tracker, the tracker continuously reports the vehicle's location, speed, ignition state and other telemetry to your fleet operator. If a driver profile has been assigned to you, your trips, hours and behavior scores are linked to your name inside the platform.
Your employer is the data controller for this monitoring and is responsible for telling you what is collected, the lawful basis they rely on (typically the employment contract and legitimate interests in operational safety and asset protection) and how long it is kept. If you have questions about how your employer uses Compass data, ask them directly — they have access to deletion, export and correction tools inside the platform. Compass cannot lawfully modify or release your data without their instruction.
Data we collect
Account and identity data
- Email address and password (hashed with bcrypt, never stored in clear)
- Full name and role (admin, manager, driver) within the organization
- Phone number, when provided
- Profile photo, when uploaded — optional
- Authentication session tokens (signed JWT) used to keep you signed in
- Internal user and organization identifiers — used to link the records described below to your account
Vehicle and tracking data
Note: GPS positions and ignition / fuel / odometer telemetry are reported directly by the GPS tracker hardware installed in the vehicle, over the tracker's own cellular connection. They are not collected from your phone or web browser. The Compass app receives and displays this data; it is not the source.
- GPS positions (latitude, longitude, speed, heading, altitude) from the tracker
- Ignition state, fuel level, odometer and other telemetry reported by the tracker
- Trip records (start, end, distance, duration) and stop records derived from the positions
- Maintenance schedules and service history per vehicle
- Vehicle metadata: license plate, model, color, year
- Vehicle documents (insurance certificates, technical inspection, registration) and their expiry dates, when an operator uploads them
Driver data
- Driver name, phone, photo (when assigned to a vehicle)
- Driving behavior scores derived from telemetry (speeding, harsh braking, idle time)
- Trip assignments and driver–vehicle history
AI assistant conversations
When you use the in-app AI assistant (powered by Anthropic's Claude), your prompts and the fleet data needed to answer them are sent to Anthropic for processing. Anthropic processes the data on Compass's behalf under its API terms and does not train models on it. The conversation and a usage record (tokens consumed, model used) are stored against your account for review and billing. The assistant is an optional feature — if you never open the chat, no message data is collected.
Phone geolocation (optional and local-only)
The mobile app uses your phone's location only for convenience features — for example, the "centre on me" button on the map. Your phone's coordinates are read locally and discarded immediately after use. They are not transmitted to Compass servers or to any third party, and they are not stored. You can deny the location permission and the rest of the app continues to work.
Technical data
- IP address, browser type, device model and OS version (server logs)
- Push notification tokens, when you opt in to mobile notifications — sent to Expo Push Service and Firebase Cloud Messaging so we can deliver alerts to your device
- Activity audit trail (which user took which action, when) — used for security, accountability and incident forensics
- Crash reports and performance diagnostics, captured by Sentry to help us fix bugs (authentication headers and cookies are stripped before transport)
How we use the data
- Provide the live tracking, replay, alerts, geofencing, maintenance and reporting features that are the core of the service
- Authenticate you and protect your account from unauthorized access
- Send operational notifications (alerts, maintenance reminders, security events)
- Answer your questions through the AI assistant by querying your fleet's data
- Maintain an audit trail of administrative actions for your operator
- Improve the platform's reliability and performance through aggregated, non-identifying telemetry
- Comply with applicable legal obligations (tax records, lawful requests from authorities)
We do not sell your data. We do not share fleet or driver data with advertisers. We do not use your data to train AI models — neither ours nor third parties'.
Who can see your data
Inside your organization, access follows the role assigned to each user (admin, manager, driver). Drivers see their own trips and assignments; managers and admins see the wider fleet. Your fleet operator can update these roles at any time.
Compass employees access the underlying systems only to operate the service (incident response, support, infrastructure) and only under strict, audited controls.
We use the following service providers to operate the platform. Each acts as a processor under Compass's instructions and processes only the categories of data noted against their entry.
- Cloud hosting (OVH, France): the application servers, PostgreSQL database, Redis cache and the Traccar GPS ingest server run on a dedicated VPS hosted in the European Union. All platform data is stored here at rest.
- Object storage (Cloudflare R2): driver and user profile photos, and vehicle documents (insurance certificates, technical inspection, registration, etc.) uploaded by operators. Stored encrypted at rest; retrieved through short-lived signed URLs.
- Map tiles: MapTiler for the web dashboard's vector tiles; Google Maps (Android) and Apple Maps (iOS) for the mobile basemap. Map providers see tile-coordinate requests but never your account or trip data.
- SMS gateway (L2T / Url2Sms): outbound SMS commands to GPS trackers (configuration, fallback channel when a tracker is offline). The gateway sees the tracker's SIM phone number and the command text, not the user's identity.
- Push notifications: Expo Push Service and Firebase Cloud Messaging deliver alert and maintenance notifications to the mobile app. They receive the device's push token and the notification payload.
- AI assistant (Anthropic — Claude):processes prompts you send to the in-app assistant together with the fleet data needed to answer them. Anthropic does not train models on this data per their API terms.
- Error monitoring (Sentry): captures crashes, exceptions and request diagnostics. Authentication headers and cookies are stripped before transport; personally identifying request bodies are not transmitted.
How long we keep it
- Raw GPS positions: 30 days (for trip replay and recent history)
- Trip and stop records (compressed): retained for the lifetime of the account so historical reports stay available
- Account data: retained while your account is active and for up to 90 days after deletion (for backup recovery), then permanently erased
- Audit logs: 12 months, then aggregated and anonymized
- AI conversation history: retained while your account is active; deletable on request
Your rights under Tunisian law
Under Organic Law n° 2004-63, you have the following rights regarding your personal data:
- Right of access (Article 32) — ask what personal data we hold about you and how it is processed.
- Right of rectification (Article 36) — have inaccurate or incomplete data corrected.
- Right of opposition (Article 38) — object to processing on legitimate grounds.
- Right of deletion — request erasure of your personal data, subject to legal retention obligations (tax records, mandatory road safety logs).
- Right to withdraw consent — for any processing you previously consented to, without affecting the rest of the service.
- Right to lodge a complaint with the INPDP if you believe your data has been mishandled.
If your data was added by your fleet operator, contact them first — they are the controller. We will help any operator act on a request. To exercise a right directly with us, write to support@compasssolutions.ai. We will respond within 30 days as required by Tunisian law.
Security
All connections between the app, the dashboard and our servers use HTTPS / TLS 1.2+. Passwords are hashed with bcrypt. Database credentials, API keys and signing secrets are stored in encrypted secret stores, never in source control.
Access to production systems requires a hardware-backed SSH key and is restricted to a small operations team. We monitor for unusual activity and have an incident-response plan that notifies affected customers without undue delay if a breach occurs.
Legal basis for processing (GDPR)
Where the GDPR or comparable law applies, we rely on the following legal bases:
- Performance of a contract — to provide the service you (or your operator) signed up for: tracking, replay, reporting, alerts.
- Legitimate interests — operational safety, asset protection, theft recovery, fraud prevention, and platform security. We balance these against your rights and document the assessment.
- Legal obligation — tax records, lawful requests from competent authorities, mandatory road safety reporting where required.
- Consent — for optional features that need it, such as marketing email or driver photo uploads. You can withdraw consent at any time without affecting the rest of the service.
Automated decisions and AI
The AI assistant answers your questions and renders reports based on your fleet data. It does not make decisions that produce legal or similarly significant effects on drivers — for example, it will not approve, fire, fine, or discipline anyone on its own.
Driver behavior scores (speeding, harsh braking, idle time) are computed automatically from telemetry and shown inside the platform. They are informational; any HR or commercial action taken on top of them is a decision made by humans at your operator, not by Compass. If you disagree with a score, your operator can review the underlying trip data with you.
International data transfers
Our primary servers are in the European Union. Some sub-processors operate globally (for example, Anthropic for the AI assistant, Sentry for error monitoring). When data is transferred outside its country of origin, we rely on European Commission Standard Contractual Clauses or equivalent safeguards. A list of sub-processors is available on request.
Cookies and similar technologies
The web dashboard uses a small number of cookies, all strictly necessary for the service:
- Authentication session — a signed, HttpOnly cookie carrying your JWT. Required to stay logged in.
- Locale preference — remembers your English / French / Arabic choice.
- Theme preference — remembers light / dark mode.
We do not use third-party advertising cookies, social-media trackers, or cross-site behavioural analytics. The mobile app uses secure device storage for the same session token — no cookies inside the app.
Data breach notification
If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it (as required by GDPR Article 33) and notify affected users and operators without undue delay, with a description of what happened, what data was affected, and what mitigations we are taking.
Tunisia
When Compass processes data of individuals in Tunisia, we observe Organic Law n° 2004-63 of 27 July 2004 on the protection of personal data and the related decisions of the National Authority for the Protection of Personal Data (Instance Nationale de Protection des Données Personnelles — INPDP). Operators using Compass to monitor drivers are responsible for any INPDP notification or authorisation required for their own processing.
Children
Compass GPS is not directed at children under 16 and we do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
Changes to this policy
When we make material changes, we will update the "Last updated" date above and, for changes that meaningfully affect your rights, send you a notice in-app or by email. Minor editorial changes will not trigger a notice.
Contact us
Questions, requests, or complaints: write to support@compasssolutions.ai. We aim to respond within 7 working days.
Compass Solutions · Tunisia