Difference between revisions of "PublicHome/Software/Products/SplX23/PrivacyPolicy"

 
(One intermediate revision by the same user not shown)
Line 112: Line 112:
 
* '''Delete your cloud data from the App''' — when you're signed in and have data stored in the cloud, the App's '''Factory Reset''' (Settings screen) offers an opt-in to '''delete your X23 Fleet account preferences from the cloud''' before it wipes the App. The App confirms the cloud deletion actually succeeded first; if it can't reach the service, the reset is cancelled so nothing is left half-deleted.
 
* '''Delete your cloud data from the App''' — when you're signed in and have data stored in the cloud, the App's '''Factory Reset''' (Settings screen) offers an opt-in to '''delete your X23 Fleet account preferences from the cloud''' before it wipes the App. The App confirms the cloud deletion actually succeeded first; if it can't reach the service, the reset is cancelled so nothing is left half-deleted.
 
* '''In the cloud''' — any remaining data is kept only as long as needed to provide the service, or as required by law. You can request deletion at any time at support@spartanlync.com.
 
* '''In the cloud''' — any remaining data is kept only as long as needed to provide the service, or as required by law. You can request deletion at any time at support@spartanlync.com.
 +
 +
'''How to delete your data:''' step-by-step options are on the [[PublicHome/Software/Products/SplX23/DataDeletion|Data Deletion Request]] page.
 +
  
 
== Section 10 — Children ==
 
== Section 10 — Children ==

Latest revision as of 16:46, 6 August 2026

SpartanLync X23 Manager — Privacy Policy

Effective date: July 28, 2026

This policy explains how SpartanLync Technologies Corp. ("SpartanLync", "we", "us") handles information in the SpartanLync X23 Manager ("X23-Mgr", the "App") for iOS, Android, Windows and macOS.

It supplements the general SpartanLync Privacy Policy. Where they differ, this document governs the X23-Mgr App.

Signed out, the App stays on your device. The only thing it sends off-device is a check that the SpartanLync service is reachable — so it can warn you if the service is down. Nothing personal or vehicle-related leaves your device until you sign in and choose to use Fleet-Share.

Section 1 — Who we are

The controller for personal data in the X23-Mgr App is:

SpartanLync Technologies Corp.
Burlington, Ontario, Canada
support@spartanlync.com

Section 2 — Your rights

Subject to applicable law, you have the right to:

  • information;
  • rectification or erasure;
  • restriction of processing;
  • object to processing;
  • data portability.

You may also complain to a data-protection supervisory authority. To exercise any right, email support@spartanlync.com.

Section 3 — What the App stores on your device

To do its job, the App stores the following on your device — and, when signed out, nowhere else:

  • Configuration and preferences — Fleet and Group layout, Train layouts, sensor assignments, TPMS / TempTrac / Door settings, and display preferences.
  • Sensor and vehicle data read from Gateway/Node hardware (see Section 4).
  • Cached history — Gateway/Node Logs, Statistics and Alerts/Status, so the App works offline.

Signed out, this data never leaves your device (except the service-availability check above). Uninstalling the App removes it; on Desktop, the uninstaller also removes the App's configuration.

Permissions the App uses:

Bluetooth
Connects to Gateway/Node hardware on phones and tablets.
Location
On Android, the OS requires location permission to scan for Bluetooth (BLE) devices. The App uses it only to find nearby Trains. It does not track, collect or store your GPS location — there is no code or permission to do so.
Camera
Scans a sensor's QR code or barcode when assigning IDs. Images are used on-device only and are never stored or transmitted.
Local network / USB (Desktop)
Talks to wired RP1210 / USB-Serial CAN adapters.

Section 4 — Vehicle and sensor (TPMS) data

When connected to Gateway/Node hardware, the App reads sensor and configuration data from the vehicle's J1939 / CAN bus:

  • Tire pressure and temperature, and standard-pressure / temperature-warning status (TPMS);
  • Reefer / zone temperatures (TempTrac);
  • Door open/closed status (Door Status);
  • Sensor IDs, sensor battery voltage, and leak / fault indications;
  • Vehicle configuration (Train layout, axles, zones) and Gateway/Node device IDs;
  • Diagnostic Logs and Statistics from the Gateway/Node.

This data shows the health of your vehicles and configures the sensor systems. Signed out, it stays on your device (Section 3).

Section 5 — Signing in

Fleet-Share and cloud history require a SpartanLync account.

When you sign in, we process your email, credentials and account role (User, Subscriber, Partner, Partner_Manager, Staff or Admin) to authenticate you and decide which features you can use.

Sign-in runs through SpartanLync's single sign-on (Authentication Server). Your password is validated there and is never stored by the App or the X23-Mgr service.

Section 6 — Fleet-Share

Fleet-Share is optional and lives entirely behind a login. Nothing is shared unless you sign in and choose to take part.

Producers
Signed-in users with sufficient privileges (Partner_Manager or higher) can publish live Train status, Alerts, Logs and Statistics to their Fleet.
Consumers
Signed-in Fleet members without local CAN/BLE range to a Train can view the status and Alerts a Producer chooses to share.
You stay in control
A Producer decides which Trains are visible, and can change or revoke that at any time. Sharing is limited to members of the same Fleet.

Shared data goes to SpartanLync's cloud only to reach authorized Fleet members. It is never sold or shared with third parties for advertising.

Section 7 — Cloud Archival and Sync

Once you're signed in, the Gateway/Node Logs, Statistics and Alerts/Status cached on your device may upload to the SpartanLync X23-Mgr-Service.

Each upload is labelled so your Fleet can make sense of it. Alongside the Logs, Statistics and Alerts/Status themselves, we transmit the Gateway/Node ECU identifier the data came from, your Fleet ID, and the email address of the signed-in account. Sensor IDs and Gateway/Node Bluetooth addresses are included where they form part of the Train configuration you publish. These identifiers remain associated with your account for as long as the record is kept (see Section 9).

This powers Fleet-wide status, historical archival and reporting for your organization. It happens for authenticated users only.

Section 8 — Security

Traffic between the App and the SpartanLync X23-Mgr-Service is protected in transit by SSL/TLS (HTTPS). The service is a Laravel web application on a LAMP stack.

Access requires authentication. Sign-in validates your credentials against SpartanLync single sign-on (Authentication Server) over TLS. The service then issues a session token and stores only a one-way SHA-256 hash of it — never the token itself. Every request is authorized by that token and scoped to your Fleet and role. Inactive sessions expire and are removed automatically.

Fleet data (status, alerts, logs, statistics) is stored in the X23-Mgr-Service database. It is not additionally encrypted at rest; it is protected by the transport encryption, authentication, session and role-based controls above, plus the operational security of the hosting environment.

Section 9 — Keeping and deleting data

  • On your device — kept until you delete it in the App or uninstall.
  • Delete your cloud data from the App — when you're signed in and have data stored in the cloud, the App's Factory Reset (Settings screen) offers an opt-in to delete your X23 Fleet account preferences from the cloud before it wipes the App. The App confirms the cloud deletion actually succeeded first; if it can't reach the service, the reset is cancelled so nothing is left half-deleted.
  • In the cloud — any remaining data is kept only as long as needed to provide the service, or as required by law. You can request deletion at any time at support@spartanlync.com.

How to delete your data: step-by-step options are on the Data Deletion Request page.


Section 10 — Children

The X23-Mgr App is a professional fleet tool, not directed to children under 13. We do not knowingly collect data from children.

Section 11 — Changes

We may update this policy. Material changes update the "Effective date" above and, where appropriate, are noted in the App or on this page.

Section 12 — Contact

SpartanLync Technologies Corp.
support@spartanlync.com