Skip to content
Legal

Privacy Policy

Last updated: June 12, 2026

What this covers

This policy describes how PathMarkr, Inc. (“PathMarkr”) collects, uses, and protects information when you use PathMarkr.

Data we collect

  • Account information: name, email, organization, authentication identifiers (managed via Supabase Auth).
  • Geotab telematics data: device positions, trips, and basic vehicle metadata pulled via read-only API. See “Geotab data scope” below.
  • Ad-platform metadata: campaign and audience metadata from connected Meta accounts, used solely to deliver the service.
  • Usage telemetry: aggregated, anonymized product usage data used to improve PathMarkr.
  • Geotab fetch log: a record of every data fetch from Geotab (timestamp, source, success status, stop count). Retained for 90 days. See “Data retention” below.

Geotab data scope

PathMarkr connects to Geotab via read-only API access using credentials you provide. We fetch:

  • Device positions, stop records, and trip data (last 90 days at connection)
  • Basic vehicle metadata (device ID, name, group)

PathMarkr does not:

  • Write to your Geotab account
  • Resell Geotab data to third parties
  • Use Geotab data to train machine learning models
  • Share Geotab data outside your tenant

Coordinate data derived from your Geotab account is shipped to Meta only via PathMarkr's authorized publish pathways, and only for paid subscribers who have explicitly connected their Meta account.

What we don't collect

We don't collect customer-level PII (names, phones, emails of homes inside your service area). PathMarkr uses geographic targeting only — pins around your stops, not personal contacts.

How we use data

Telematics data is used exclusively to generate location pins and reports for your own organization. PathMarkr does not sell or share customer data with third parties for marketing purposes.

Security

PathMarkr uses per-user encryption, row-level security, and audit logging. Geotab credentials are stored encrypted at rest (AES-256) and never exposed to client-side code. Meta credentials stay in your accounts; PathMarkr accesses them via scoped tokens you generate.

Data retention

  • Geotab fetch log (geotab_fetch_log): retained for 90 days, then automatically deleted. Per security spec §4.5. Used for throttle enforcement, anomaly detection, and dispute resolution.
  • Account type change audit log: retained indefinitely for compliance.
  • Magic-link emails: retained per Supabase Auth defaults (links expire in 60 minutes; no email content is stored by PathMarkr).
  • Cached telematics data: purged within 30 days of account disconnection. Heatmaps and pins remain accessible for export until you delete them.

Your rights

You may request access, correction, or deletion of personal data associated with your account by emailing hello@pathmarkr.com.

Changes to this policy

We will post material updates to this page and notify account holders by email.