Difference between revisions of "PublicHome/Software/Products/SplX23/PrivacyPolicy"

Line 1: Line 1:
−
[[PublicHome/Software/Products/SplX23|SpartanLync X23 System]]
 
−
 
 
= SpartanLync X23 Manager — Privacy Policy =
 
= SpartanLync X23 Manager — Privacy Policy =
  
 
'''Effective date: July 28, 2026'''
 
'''Effective date: July 28, 2026'''
  
−
This Privacy Policy explains how '''SpartanLync Technologies Corp.'''
+
This policy explains how '''SpartanLync Technologies Corp.''' ("SpartanLync", "we", "us") handles information in the '''SpartanLync X23 Manager''' ("X23-Mgr", the "App") for iOS, Android, Windows and macOS.
−
("SpartanLync", "we", "us") handles information in connection with the
 
−
'''SpartanLync X23 Manager''' ("X23-Mgr", the "App") for iOS, Android, Windows
 
−
and macOS. It supplements the general
 
−
[https://help.spartansense.com/PrivacyPolicy SpartanLync Privacy Policy] and,
 
−
where they differ, this document governs the X23-Mgr App.
 
  
−
The X23-Mgr App is a fleet sensor-monitoring tool. '''When you are not signed
+
It supplements the general [https://help.spartansense.com/PrivacyPolicy SpartanLync Privacy Policy]. Where they differ, this document governs the X23-Mgr App.
−
in, the App works entirely on your own device''' — the only information it
+
 
−
sends off the device is a check to confirm whether the SpartanLync service is
+
'''Signed out, the App stays on your device.''' The only thing it sends off-device is a check that the SpartanLync service is reachable — so it can warn you if the service is down. Nothing personal or vehicle-related leaves your device until you sign in and choose to use '''Fleet-Share'''.
−
reachable, so it can notify you if the service is temporarily inaccessible. No
 
−
personal or vehicle data leaves your device unless and until you sign in and
 
−
choose to use the authenticated '''Fleet-Share''' feature described below.
 
  
 
__TOC__
 
__TOC__
  
−
== Section 1 — Data controller and contact ==
+
== Section 1 — Who we are ==
  
−
The controller responsible for the processing of personal data in connection
+
The controller for personal data in the X23-Mgr App is:
−
with the X23-Mgr App is:
 
  
−
: SpartanLync Technologies Corp.
+
: '''SpartanLync Technologies Corp.'''
 
: Burlington, Ontario, Canada
 
: Burlington, Ontario, Canada
−
: Email: support@spartanlync.com
+
: support@spartanlync.com
 +
 
 +
== Section 2 — Your rights ==
  
−
If you have questions about this Policy or your data, contact us at the address
+
Subject to applicable law, you have the right to:
−
above.
 
  
−
== Section 2 — Your rights ==
+
* information;
 +
* rectification or erasure;
 +
* restriction of processing;
 +
* object to processing;
 +
* data portability.
 +
 
 +
You may also complain to a data-protection supervisory authority. To exercise any right, email support@spartanlync.com.
  
−
Subject to applicable law, you have the following rights regarding your
+
== Section 3 — What the App stores on your device ==
−
personal data:
 
  
−
* Right to information;
+
To do its job, the App stores the following '''on your device''' — and, when signed out, nowhere else:
−
* Right to rectification or erasure;
 
−
* Right to restriction of processing;
 
−
* Right to object to processing;
 
−
* Right to data portability.
 
  
−
You also have the right to lodge a complaint with a data-protection
+
* '''Configuration and preferences''' — Fleet and Group layout, Train layouts, sensor assignments, TPMS / TempTrac / Door settings, and display preferences.
−
supervisory authority. To exercise any of these rights, contact us at
+
* '''Sensor and vehicle data''' read from Gateway/Node hardware (see Section 4).
−
support@spartanlync.com.
+
* '''Cached history''' — Gateway/Node Logs, Statistics and Alerts/Status, so the App works offline.
  
−
== Section 3 — Information the App collects on your device ==
+
Signed out, this data '''never leaves your device''' (except the service-availability check above). Uninstalling the App removes it; on Desktop, the uninstaller also removes the App's configuration.
  
−
To perform its function, the X23-Mgr App stores the following '''on your
+
'''Permissions the App uses:'''
−
device''' (and, when signed out, nowhere else):
 
  
−
* '''App configuration and preferences''' — Fleet and Group organization,
+
; Bluetooth
−
  vehicle (Train) layouts, sensor assignments, TPMS / TempTrac / Door
+
: Connects to Gateway/Node hardware on phones and tablets.
−
  configuration, and display preferences.
 
−
* '''Sensor and vehicle data read from GwNode hardware''' — see Section 4.
 
−
* '''Cached history''' — GwNode Logs, Statistics and real-time Alerts/Status
 
−
  are cached locally so the App works without connectivity.
 
  
−
When you are signed out, this information '''remains only on your device and is
+
; Location
−
never shared off the device''', except for the service-availability check
+
: On Android, the OS requires location permission to scan for Bluetooth (BLE) devices. The App uses it '''only to find nearby Trains'''. It '''does not track, collect or store your GPS location''' — there is no code or permission to do so.
−
noted above. Uninstalling the App removes this locally-stored data; on Desktop,
 
−
the uninstaller also removes the App's configuration.
 
  
−
'''Device permissions the App requests:'''
+
; Camera
 +
: Scans a sensor's QR code or barcode when assigning IDs. Images are used on-device only and are never stored or transmitted.
  
−
* '''Bluetooth''' — to establish the J1939 link to GwNode hardware on phones
+
; Local network / USB (Desktop)
−
  and tablets.
+
: Talks to wired RP1210 / USB-Serial CAN adapters.
−
* '''Location''' — on Android, the operating system requires location
 
−
  permission in order to perform Bluetooth (BLE) scanning. The App uses this
 
−
  permission '''solely to discover nearby GwNode Trains'''. The X23-Mgr App
 
−
  '''does not track, collect or store your device's GPS location''', and
 
−
  contains no code or permission to do so.
 
−
* '''Camera''' — to scan a sensor's QR code or barcode when assigning sensor
 
−
  IDs. Camera images are used only for on-device scanning and are not stored or
 
−
  transmitted.
 
−
* '''Local network / USB (Desktop)''' — to communicate with wired RP1210 /
 
−
  USB-Serial CAN adapters.
 
  
 
== Section 4 — Vehicle and sensor (TPMS) data ==
 
== Section 4 — Vehicle and sensor (TPMS) data ==
  
−
When connected to GwNode hardware, the App reads sensor and configuration data
+
When connected to Gateway/Node hardware, the App reads sensor and configuration data from the vehicle's J1939 / CAN bus:
−
from the vehicle's J1939 / CAN bus, including:
 
  
−
* Tire pressure and temperature, and standard-pressure / temperature-warning
+
* Tire pressure and temperature, and standard-pressure / temperature-warning status (TPMS);
−
  status (TPMS);
 
 
* Reefer / zone temperatures (TempTrac);
 
* Reefer / zone temperatures (TempTrac);
 
* Door open/closed status (Door Status);
 
* Door open/closed status (Door Status);
−
* Sensor identifiers, sensor battery voltage, and leak/fault indications;
+
* Sensor IDs, sensor battery voltage, and leak / fault indications;
−
* Vehicle configuration (Train layout, axle/zone configuration) and GwNode
+
* Vehicle configuration (Train layout, axles, zones) and Gateway/Node device IDs;
−
  device identifiers;
+
* Diagnostic Logs and Statistics from the Gateway/Node.
−
* Diagnostic Logs and Statistics generated by the GwNode.
 
  
−
This data is used to display the health of your vehicles and to configure the
+
This data shows the health of your vehicles and configures the sensor systems. Signed out, it stays on your device (Section 3).
−
sensor systems. While signed out, it stays on your device (Section 3).
 
  
−
== Section 5 — Account sign-in and authentication ==
+
== Section 5 — Signing in ==
  
 
Fleet-Share and cloud history require a '''SpartanLync account'''.
 
Fleet-Share and cloud history require a '''SpartanLync account'''.
−
Authentication is handled through SpartanLync's centralized single sign-on
 
−
(Keycloak). When you sign in, we process your '''account email, credentials
 
−
and account role''' (for example User, Subscriber, Partner, Partner_Manager,
 
−
Staff, Admin) to authenticate you and to determine which features and sharing
 
−
capabilities are available to you. Your password is validated by the
 
−
SpartanLync identity service and is not stored by the App or the X23-Mgr
 
−
service.
 
  
−
== Section 6 — Fleet-Share: sharing data with Producers and Consumers ==
+
When you sign in, we process your '''email, credentials and account role''' (User, Subscriber, Partner, Partner_Manager, Staff or Admin) to authenticate you and decide which features you can use.
 +
 
 +
Sign-in runs through SpartanLync's single sign-on (Keycloak). Your password is validated there and is '''never stored''' by the App or the X23-Mgr service.
 +
 
 +
== Section 6 — Fleet-Share ==
 +
 
 +
'''Fleet-Share is optional and lives entirely behind a login.''' Nothing is shared unless you sign in and choose to take part.
 +
 
 +
; Producers
 +
: Signed-in users with sufficient privileges (Partner_Manager or higher) can publish live Train status, Alerts, Logs and Statistics to their Fleet.
  
−
'''Fleet-Share is optional and operates entirely behind an authentication
+
; Consumers
−
wall.''' No Train data is shared with anyone unless you are signed in and
+
: Signed-in Fleet members without local CAN/BLE range to a Train can view the status and Alerts a Producer chooses to share.
−
choose to participate.
 
  
−
* '''Producers''' — signed-in users with sufficient privileges
+
; You stay in control
−
  (Partner_Manager or higher) may publish live Train status, Alerts, and
+
: A Producer decides '''which''' Trains are visible, and can change or revoke that at any time. Sharing is limited to members of the same Fleet.
−
  associated Logs and Statistics to their Fleet, so that other members of the
 
−
  same Fleet can view them.
 
−
* '''Consumers''' — signed-in members of a Fleet who do not have local
 
−
  CAN/BLE proximity to a GwNode Train may view the Train status and Alerts
 
−
  that a Producer has chosen to share.
 
−
* '''Owner control''' — a Producer decides '''which''' scanned GwNode Trains
 
−
  are visible to other members of the Fleet, and can change or revoke that
 
−
  visibility. Sharing is limited to members of the same Fleet.
 
  
−
Data shared through Fleet-Share is transmitted to SpartanLync's cloud service
+
Shared data goes to SpartanLync's cloud only to reach authorized Fleet members. It is '''never sold''' or shared with third parties for advertising.
−
so it can be delivered to authorized Fleet members; it is not sold or shared
 
−
with third parties for advertising.
 
  
−
== Section 7 — Cloud archival, Logs and Statistics ==
+
== Section 7 — Cloud archival ==
  
−
Once you are signed in, GwNode Logs, Statistics and real-time Alerts/Status
+
Once you're signed in, the Gateway/Node Logs, Statistics and Alerts/Status cached on your device may upload to the '''SpartanLync X23-Mgr-Service'''.
−
that were cached on your device may be uploaded to the '''SpartanLync
 
−
X23-Mgr-Service'''. This enables Fleet-wide status display, historical
 
−
archival, and query/reporting for your organization. This upload occurs only
 
−
for authenticated users.
 
  
−
== Section 8 — Information security ==
+
This powers Fleet-wide status, historical archival and reporting for your organization. It happens for authenticated users only.
  
−
Data exchanged between the X23-Mgr App and the '''SpartanLync X23-Mgr-Service'''
+
== Section 8 — Security ==
−
is protected in transit by '''SSL/TLS (HTTPS)'''. The X23-Mgr-Service is a
 
−
Laravel web application running on a LAMP stack.
 
  
−
Access to the service requires authentication. Signing in validates your
+
Traffic between the App and the '''SpartanLync X23-Mgr-Service''' is protected in transit by '''SSL/TLS (HTTPS)'''. The service is a Laravel web application on a LAMP stack.
−
credentials against SpartanLync's centralized single sign-on (Keycloak) over an
 
−
encrypted (TLS) connection. The service then issues a session token to your
 
−
device and stores only a one-way (SHA-256) hash of that token — never the token
 
−
itself. Every request for shared Fleet data is authorized by that session token
 
−
and is restricted to authorized members of the relevant Fleet according to your
 
−
account role. Inactive sessions expire and are removed automatically.
 
  
−
Fleet data (status, alerts, logs and statistics) is stored in the
+
Access requires authentication. Sign-in validates your credentials against SpartanLync single sign-on (Keycloak) over TLS. The service then issues a session token and stores only a one-way '''SHA-256 hash''' of it — never the token itself. Every request is authorized by that token and scoped to your Fleet and role. Inactive sessions expire and are removed automatically.
−
X23-Mgr-Service database. This stored data is not additionally encrypted at
 
−
rest; it is protected by the transport encryption, authentication, session and
 
−
role-based access controls described above, together with the operational
 
−
security of the hosting environment.
 
  
−
== Section 9 — Data retention and deletion ==
+
Fleet data (status, alerts, logs, statistics) is stored in the X23-Mgr-Service database. It is '''not additionally encrypted at rest'''; it is protected by the transport encryption, authentication, session and role-based controls above, plus the operational security of the hosting environment.
  
−
* '''On-device data''' is retained until you delete it in the App or uninstall
+
== Section 9 — Keeping and deleting data ==
−
  the App.
 
−
* '''Cloud data''' shared through Fleet-Share or archived via the X23-Mgr-Service
 
−
  is retained for as long as needed to provide the service to your
 
−
  organization, or as required by law. You may request deletion of your
 
−
  personal data by contacting support@spartanlync.com.
 
  
−
== Section 10 — Children's privacy ==
+
* '''On your device''' — kept until you delete it in the App or uninstall.
 +
* '''In the cloud''' — kept as long as needed to provide the service, or as required by law. Request deletion any time at support@spartanlync.com.
  
−
The X23-Mgr App is a professional fleet-management tool and is not directed to
+
== Section 10 — Children ==
−
children under 13. We do not knowingly collect personal data from children.
 
  
−
== Section 11 — Changes to this Policy ==
+
The X23-Mgr App is a professional fleet tool, not directed to children under 13. We do not knowingly collect data from children.
  
−
We may update this Privacy Policy from time to time. Material changes will be
+
== Section 11 — Changes ==
−
reflected by updating the "Effective date" above and, where appropriate,
+
 
−
through notice within the App or on this page.
+
We may update this policy. Material changes update the "Effective date" above and, where appropriate, are noted in the App or on this page.
  
 
== Section 12 — Contact ==
 
== Section 12 — Contact ==
  
−
For any privacy question or request, contact:
+
: '''SpartanLync Technologies Corp.'''
−
 
+
: support@spartanlync.com
−
: SpartanLync Technologies Corp.
 
−
: Email: support@spartanlync.com
 

Revision as of 06:27, 28 July 2026

SpartanLync X23 Manager — Privacy Policy

Effective date: July 28, 2026

This policy explains how SpartanLync Technologies Corp. ("SpartanLync", "we", "us") handles information in the SpartanLync X23 Manager ("X23-Mgr", the "App") for iOS, Android, Windows and macOS.

It supplements the general SpartanLync Privacy Policy. Where they differ, this document governs the X23-Mgr App.

Signed out, the App stays on your device. The only thing it sends off-device is a check that the SpartanLync service is reachable — so it can warn you if the service is down. Nothing personal or vehicle-related leaves your device until you sign in and choose to use Fleet-Share.

Section 1 — Who we are

The controller for personal data in the X23-Mgr App is:

SpartanLync Technologies Corp.
Burlington, Ontario, Canada
support@spartanlync.com

Section 2 — Your rights

Subject to applicable law, you have the right to:

  • information;
  • rectification or erasure;
  • restriction of processing;
  • object to processing;
  • data portability.

You may also complain to a data-protection supervisory authority. To exercise any right, email support@spartanlync.com.

Section 3 — What the App stores on your device

To do its job, the App stores the following on your device — and, when signed out, nowhere else:

  • Configuration and preferences — Fleet and Group layout, Train layouts, sensor assignments, TPMS / TempTrac / Door settings, and display preferences.
  • Sensor and vehicle data read from Gateway/Node hardware (see Section 4).
  • Cached history — Gateway/Node Logs, Statistics and Alerts/Status, so the App works offline.

Signed out, this data never leaves your device (except the service-availability check above). Uninstalling the App removes it; on Desktop, the uninstaller also removes the App's configuration.

Permissions the App uses:

Bluetooth
Connects to Gateway/Node hardware on phones and tablets.
Location
On Android, the OS requires location permission to scan for Bluetooth (BLE) devices. The App uses it only to find nearby Trains. It does not track, collect or store your GPS location — there is no code or permission to do so.
Camera
Scans a sensor's QR code or barcode when assigning IDs. Images are used on-device only and are never stored or transmitted.
Local network / USB (Desktop)
Talks to wired RP1210 / USB-Serial CAN adapters.

Section 4 — Vehicle and sensor (TPMS) data

When connected to Gateway/Node hardware, the App reads sensor and configuration data from the vehicle's J1939 / CAN bus:

  • Tire pressure and temperature, and standard-pressure / temperature-warning status (TPMS);
  • Reefer / zone temperatures (TempTrac);
  • Door open/closed status (Door Status);
  • Sensor IDs, sensor battery voltage, and leak / fault indications;
  • Vehicle configuration (Train layout, axles, zones) and Gateway/Node device IDs;
  • Diagnostic Logs and Statistics from the Gateway/Node.

This data shows the health of your vehicles and configures the sensor systems. Signed out, it stays on your device (Section 3).

Section 5 — Signing in

Fleet-Share and cloud history require a SpartanLync account.

When you sign in, we process your email, credentials and account role (User, Subscriber, Partner, Partner_Manager, Staff or Admin) to authenticate you and decide which features you can use.

Sign-in runs through SpartanLync's single sign-on (Keycloak). Your password is validated there and is never stored by the App or the X23-Mgr service.

Section 6 — Fleet-Share

Fleet-Share is optional and lives entirely behind a login. Nothing is shared unless you sign in and choose to take part.

Producers
Signed-in users with sufficient privileges (Partner_Manager or higher) can publish live Train status, Alerts, Logs and Statistics to their Fleet.
Consumers
Signed-in Fleet members without local CAN/BLE range to a Train can view the status and Alerts a Producer chooses to share.
You stay in control
A Producer decides which Trains are visible, and can change or revoke that at any time. Sharing is limited to members of the same Fleet.

Shared data goes to SpartanLync's cloud only to reach authorized Fleet members. It is never sold or shared with third parties for advertising.

Section 7 — Cloud archival

Once you're signed in, the Gateway/Node Logs, Statistics and Alerts/Status cached on your device may upload to the SpartanLync X23-Mgr-Service.

This powers Fleet-wide status, historical archival and reporting for your organization. It happens for authenticated users only.

Section 8 — Security

Traffic between the App and the SpartanLync X23-Mgr-Service is protected in transit by SSL/TLS (HTTPS). The service is a Laravel web application on a LAMP stack.

Access requires authentication. Sign-in validates your credentials against SpartanLync single sign-on (Keycloak) over TLS. The service then issues a session token and stores only a one-way SHA-256 hash of it — never the token itself. Every request is authorized by that token and scoped to your Fleet and role. Inactive sessions expire and are removed automatically.

Fleet data (status, alerts, logs, statistics) is stored in the X23-Mgr-Service database. It is not additionally encrypted at rest; it is protected by the transport encryption, authentication, session and role-based controls above, plus the operational security of the hosting environment.

Section 9 — Keeping and deleting data

  • On your device — kept until you delete it in the App or uninstall.
  • In the cloud — kept as long as needed to provide the service, or as required by law. Request deletion any time at support@spartanlync.com.

Section 10 — Children

The X23-Mgr App is a professional fleet tool, not directed to children under 13. We do not knowingly collect data from children.

Section 11 — Changes

We may update this policy. Material changes update the "Effective date" above and, where appropriate, are noted in the App or on this page.

Section 12 — Contact

SpartanLync Technologies Corp.
support@spartanlync.com