Privacy Policy

Road Guardian by Orpyxis Technologies · Last updated 2026-08-03

PRIVACY POLICY — ROAD GUARDIAN

Last Updated: 3 August 2026
Effective Date: 3 August 2026

This Privacy Policy explains how Orpyxis Technologies ("Orpyxis", "we", "us") processes personal data when you use Road Guardian — the customer app, the driver (Truck) app, and related APIs at https://rgs.orpyxis.com.

If you do not agree with this Policy, please do not use the Platform.

1. DATA CONTROLLER

Controller: Orpyxis Technologies
Contact (privacy): [email protected]
Support: [email protected]
Location: Malta (European Union)

For EU/EEA users, we process personal data under the GDPR.

2. APPS COVERED

This Policy covers:
- Road Guardian customer application
- Road Guardian Truck (driver) application
- Backend services used by those apps

Fleet manager and internal admin tools operated by Orpyxis may process additional operational data under the same organisation; end-user store apps typically only need this Policy.

3. DATA WE COLLECT

3.1 Account and profile
- Email address, password (stored hashed), optional name and username
- Profile picture (if uploaded)
- Role flags (customer, driver, etc.)
- Account status (active, confirmed)

3.2 Customer-specific
- Registered vehicles (plate, make, model, colour, year, fuel type)
- Service requests (pickup coordinates, destination locality, service type, truck type required, price, status, completion code)
- Payment-related metadata (amounts, Stripe payment/session identifiers — not full card numbers)
- Ratings and feedback you submit

3.3 Driver-specific
- Truck records (plate, make, model, capacity, status, equipment type, truck photo)
- Active truck selection
- Real-time and recent GPS location while using the driver app / on jobs
- Job acceptance and completion history
- Earnings and platform fee / debt ledger data
- Expo push notification tokens (if you register them)
- Device/app version metadata associated with push tokens

3.4 Technical and security data
- IP address, timestamps, app version where logged
- Authentication tokens and session records
- Crash or error diagnostics if collected
- Communications with support

3.5 Compliance records
- Acceptance of Terms / Privacy (timestamps)
- Data export or deletion requests

4. HOW WE USE DATA (PURPOSES AND LEGAL BASES)

| Purpose | Examples | Legal basis (GDPR) |
|---------|----------|--------------------|
| Provide the service | Accounts, matching jobs, quotes, maps integration | Contract (Art. 6(1)(b)) |
| Payments | Stripe PaymentIntents / Checkout, fee settlement | Contract; legal obligation for records |
| Safety and fraud | Session checks, abuse prevention | Legitimate interests (Art. 6(1)(f)) |
| Location for jobs | Driver location, pickup routing | Contract; legitimate interests; consent where required by OS |
| Push alerts | New matching jobs to online drivers | Contract / legitimate interests; token provided by you |
| Show truck photo to customer | After job accept | Contract / legitimate interests |
| Support and improvement | Diagnostics, analytics | Legitimate interests |
| Legal compliance | Tax, accounting, lawful requests | Legal obligation (Art. 6(1)(c)) |
| Marketing (if any) | Optional notices | Consent (Art. 6(1)(a)) where required |

5. LOCATION DATA

- Customers: pickup location is needed to create and price a request
- Drivers: GPS is used for dispatch/matching context, map features, and operational status
- You can control location permissions in the operating system; some features will not work without location
- We do not sell location data

6. SHARING

We share data only as needed with:
- Other users on a need-to-know basis for an active job (e.g. customer sees truck type, plate, photo; driver sees job details)
- Payment processors (e.g. Stripe)
- Infrastructure and communications providers (hosting, email SMTP, Expo push, maps/routing)
- Professional advisers and authorities when legally required

We do not sell personal data.

7. INTERNATIONAL TRANSFERS

Data is primarily processed in the EU. If a provider processes data outside the EEA, we use appropriate safeguards (e.g. Standard Contractual Clauses) where required.

8. RETENTION

Typical periods (may be extended if required for disputes or law):
- Account profile: life of account + up to 7 years for legal/tax needs
- Service and payment records: up to 10 years where financial rules require
- Location logs: shorter operational window (e.g. up to 90 days) unless needed for a dispute
- Push tokens: until you remove them or delete the account
- Support tickets: as needed to resolve then archive

9. YOUR RIGHTS (GDPR)

You may have the right to access, rectify, erase, restrict, object, and data portability, and to withdraw consent where processing is consent-based.

In-app / API options may include:
- Export data request
- Delete account / data request
- Review Terms and Privacy acceptance status

Contact: [email protected]
You may also lodge a complaint with the Information and Data Protection Commissioner (IDPC) in Malta, or your local EU supervisory authority.

10. SECURITY

We use HTTPS, access controls, hashed passwords, session management, and operational monitoring. No method of transmission or storage is 100% secure.

11. CHILDREN

The Platform is not directed at children under 18. We do not knowingly collect their data.

12. COOKIES / APP IDENTIFIERS

Mobile apps use device identifiers and tokens necessary for login, security, and push delivery. Any website cookies are limited to essential and similar operational needs unless we notify otherwise.

13. CHANGES

We may update this Policy. The "Last Updated" date will change, and material changes may be notified in-app or by email.

14. CONTACT

Privacy: [email protected]
Support: [email protected]
Legal: [email protected]
Web: https://rgs.orpyxis.com