Legal Center
Review the terms and policies that govern your use of Sonar Telematics products, services, and integrations..
Terms of Use
Understand the terms and conditions for using Sonar Telematics products and services.
ViewPrivacy Policy
Learn how we collect, use, protect, and manage your personal information and vehicle data.
Table of Contents
Privacy Policy
Sonar Telematics USA LLC
Effective date:
This Privacy Policy describes how Sonar Telematics USA LLC ("Sonar Telematics," "we," "us," or "our") collects, uses, discloses, and retains personal information in connection with the Services defined below. It also describes the rights and choices available to individuals whose personal information we process.
Sonar Telematics does not sell vehicle location, tracking history, or other vehicle telematics data. Disclosure to an approved integration partner requires customer authorization, which the customer may revoke. We guarantee access to one year of tracking history, subject to the provisions of Section 11. Service data is stored in the United States as described in Section 17.
1. Scope of This Policy
This Privacy Policy applies to the Sonar Go mobile application, the Sonar Telematics web application, connected vehicle tracking devices, service accounts and subscriptions, alerts and reports, Glovebox and maintenance features, customer support, APIs, webhooks, and approved integrations (collectively, the "Services"). The information collected depends on the applicable device, vehicle, features, and account configuration.
The Services process information relating to account holders, authorized users, drivers, renters, employees, contractors, family members, and other vehicle users. Information may relate to an individual who does not have a Sonar Telematics account. For purposes of this Privacy Policy, "personal information" includes information that identifies, relates to, or is reasonably capable of being linked to an individual or household, including vehicle information where that connection exists.
The Shopify storefront at getsonar.shop is subject to a separate privacy policy, including with respect to shopping cookies and advertising technologies. This Privacy Policy does not govern an approved partner's independent processing of information or replace the privacy notices and obligations of customers using the Services.
2. Our Role in Processing Personal Information
Sonar Telematics determines the purposes and means of processing personal information for account administration, subscription billing, service communications, security, and its direct customer relationships. Depending on applicable law, Sonar Telematics acts as a controller or business with respect to those activities.
Where Sonar Telematics processes fleet or driver information on behalf of a business customer and in accordance with the applicable agreement, it may act as a processor or service provider. The customer determines the purposes of monitoring, vehicle assignments, account access, and authorized integrations and may provide a separate employee, driver, or rental privacy notice.
Individuals seeking information about a customer's use of their personal information should contact the organization responsible for the vehicle or account. Requests may also be submitted to Sonar Telematics under Section 18. Where we process information on behalf of a customer, we assist or coordinate with that customer as required by applicable law and the applicable agreement. Sonar Telematics remains responsible for obligations applicable to its own processing.
3. Personal Information We Collect
Account and Subscription Information
We collect names, business names, contact details, billing addresses, login and authentication information, account identifiers, permissions, vehicle assignments, subscription records, invoices, and payment status. Account administrators may provide information about other authorized users. Stripe processes subscription payments. We do not store full payment card numbers or card security codes. See Section 8.
Vehicle and Device Identifiers
We collect vehicle names and descriptions, make, model, year, vehicle identification numbers and license plates where provided or available, tracking device identifiers, and account-to-vehicle and device associations. Device status and connection records identify the source of reported events and whether a device is connected or reporting.
Driver Profiles and Vehicle Assignments
Fleet customers may submit driver information and assign drivers to vehicles. We process these profiles and assignments to associate trips, driving events, and historical driving patterns with individual drivers. Driver-specific reports are based on recorded assignments and do not independently establish the identity of the person operating a vehicle.
Location and Trip Information
We collect precise GPS coordinates, last reported locations, timestamps, direction and movement, routes, trip origins and destinations, stops, distances, and travel and idle time. Configured geofences and location alerts may record arrivals, departures, and boundary crossings. Location and trip records may reveal a driver's routines and places visited.
Vehicle Diagnostics and Driving Events
Depending on vehicle compatibility and enabled features, we collect speed, ignition status, odometer and fuel readings, engine RPM, coolant temperature, battery voltage, throttle information, diagnostic trouble codes, and device connection or disconnection events. We use these readings and related information to generate alerts and reports concerning speeding, applicable road speed limits, hard braking, rapid acceleration, cornering, idling, and possible collisions.
Documents and Other Customer Content
Information submitted through Glovebox and other features may include vehicle registration and insurance documents, images, PDFs, document numbers, expiration dates, maintenance records, notes, and vehicle or location labels. This content may contain personal information about drivers, policyholders, and other individuals. Optional submissions are voluntary. Customers must have authority to submit the information and should limit submissions to information relevant to the applicable feature.
Application and API Activity
Service activity records may include IP addresses, browser and operating system details, application versions, device information, login and session activity, feature usage, timestamps, errors, and security logs. API records may include the associated account or credential identifier, requested operation, and response status. Internal diagnostic records may contain account or vehicle information relevant to an error. Information disclosed to Google Analytics and Firebase is limited as specified in Section 14.
Communications and Support
We collect support requests, emails, chats, feedback, screenshots, and other communications, including relevant vehicle or device identifiers. Telephone calls through Quo are recorded and transcribed; we collect the resulting recordings and transcripts. We also maintain privacy preferences and requests. Passwords, API secrets, and unnecessary sensitive information should not be included in communications.
4. Sources of Information and Sensitive Information
We collect information directly from customers and authorized users, from account administrators, and automatically through tracking devices, applications, servers, and APIs. We may also receive information from providers supporting mapping, payments, connectivity, and approved integrations. Tracking devices collect and transmit vehicle, positioning, and movement information.
We associate information through account, vehicle, device, and integration identifiers to provide the Services within the relevant account. Information submitted by one authorized user may be accessible to other users in accordance with account permissions.
Precise geolocation, account credentials, and certain information contained in uploaded documents may constitute sensitive personal information under applicable law. We process such information as necessary to provide the requested Services and obtain consent where required. Customers should not submit unrelated medical records, complete payment card details, or other sensitive information unnecessary for the applicable feature.
5. Use of Personal Information
Service delivery. We use personal information to administer accounts and permissions, associate devices with vehicles, display maps and trip history, process vehicle readings, generate alerts and reports, and provide Glovebox and maintenance features. We also administer subscriptions, billing, and authorized integrations. For fleet accounts, we maintain driver profiles and assignments and generate driver-specific trip histories and driving reports.
Support and service improvement. We use information relevant to customer inquiries to investigate reporting, account, connectivity, and application issues; maintain and test the Services; and improve performance, reliability, and usability.
Security and legal compliance. We use personal information to authenticate users, detect suspicious activity, investigate unauthorized access or tracking, prevent fraud and misuse, and protect the Services and their users. We also process information to comply with legal obligations, resolve disputes, and establish, exercise, or defend legal claims.
Communications. We use contact information and preferences to deliver account, subscription, security, and service notices and configured vehicle alerts. We may send product updates and promotional communications subject to applicable law and communication preferences. See Section 14.
Reports and derived information. We combine vehicle readings, time, distance, and available road information to generate requested reports and alerts. These outputs concern the vehicle and associated records; they do not independently identify its driver. Sensor limitations and inaccurate assignments may affect report accuracy.
6. Drivers and Other Vehicle Users
This Privacy Policy applies to account holders and individuals who operate or use a vehicle equipped with an active Sonar Telematics tracker, including owners, renters, lessees, and borrowers.
Customers who make a tracked vehicle available to another person are responsible for informing that person that tracking services are active, directing them to this Privacy Policy, and providing notices and obtaining permissions required by applicable law. Fleet customers must also inform drivers when driver profiles and assignments are used to associate trips and driving patterns with them.
The Services may not be used for secret tracking or to monitor an individual without required consent or lawful authority.
7. Account Access and User Controls
Account holders and administrators manage access within the permissions available under their account configuration. The information accessible to an authorized user or integration depends on those permissions. Customers are responsible for managing authorized access and safeguarding shared devices and exported reports.
Device permissions. Where a mobile feature requests location, camera, photo, or file access, the applicable permission prompt identifies the requested access. Permissions may be modified through device settings. Restricting a permission may affect the relevant feature but does not stop location reporting by an active vehicle tracker.
Deactivation and transfers. Customers may contact Sonar Telematics for assistance with tracker deactivation, changes to authorized users, or transfers between vehicles or accounts. Subscription cancellation, integration revocation, and requests for deletion are separate actions. Before transferring a tracked vehicle, customers should review and update its device and account associations as appropriate.
An individual need not hold an account to submit a privacy request concerning their own information. Requests from former users and drivers without an account are subject to verification and the protections described in Section 13.
8. Disclosure of Personal Information
Account Holders and Authorized Users
Vehicle information, documents, reports, and alerts are accessible through the customer account in accordance with applicable permissions. Fleet administrators and other appropriately authorized users may access driver profiles, assignments, and driver-specific histories and reports. Customers are responsible for disclosures they make independently, including distribution of downloaded reports. Receipt of an exported copy does not confer continuing account access.
Service Providers
Service providers include Stripe for payments and subscription billing; Google Maps and Mapbox for mapping; HubSpot for customer relationship management and communications; and Quo for telephone calls, call recording, and transcription. We do not use Quo for messaging. Disclosures are relevant to each provider's functions. Mapping may require location information. Google Analytics and Firebase receive only the app usage and diagnostic information described in Section 14. Providers also support hosting, storage, connectivity, notifications, and security.
Stripe collects and processes payment card information. Sonar Telematics does not store full card numbers or card security codes. We retain subscription, invoice, and payment-status records for account administration, payment reconciliation, and legal requirements. Stripe processes personal information under its Privacy Policy at https://stripe.com/privacy. Customers must review that policy and accept applicable Stripe terms and authorizations presented during payment. Service-provider disclosures are governed by applicable agreements and law and are separate from optional connections to approved integration partners.
Approved Integration Partners
We disclose vehicle information to a Sonar Telematics-approved integration partner only with the customer's authorization, including for insurance integrations. Approval of a partner does not independently authorize access to customer information. The terms governing authorized connections and revocation are described in Section 10.
Legal Process and Protection of Rights
We may disclose personal information as required by applicable law or valid legal process, including a subpoena, warrant, or court order. We may also disclose information where permitted by law and reasonably necessary to investigate fraud or security incidents, protect individuals from a serious threat, enforce lawful rights, or establish, exercise, or defend legal claims.
Requests for disclosure must identify the requesting authority, legal basis, and information sought. We evaluate requests in light of applicable legal requirements and restrictions. Legal inquiries may be directed to the contact details in Section 18; those details do not replace any legally required method of service.
Professional Advisers and Corporate Transactions
We may disclose relevant information to legal, accounting, and other professional advisers. Personal information may also be disclosed or transferred in connection with a merger, acquisition, financing, restructuring, or transfer of business assets, subject to applicable confidentiality and privacy obligations. Any resulting change in processing remains subject to applicable notice and consent requirements.
9. No Sale of Vehicle Data
Sonar Telematics does not sell vehicle location, tracking history, or other vehicle telematics data. Customer- authorized disclosure of such data to integration partners is limited to partners approved by Sonar Telematics, including insurance partners. This provision does not restrict the operational disclosures or disclosures required or permitted by law described in Section 8.
10. APIs Webhooks and Integrations
Scope of Authorized Access
The Sonar Telematics API provides read-only access to information available through the Services. Customers may use the API to retrieve information for use in their own software. The API does not permit users to create, modify, or delete records within the Services or send commands to tracking devices. Where enabled, webhooks deliver event notifications to authorized software.
Subject to the access authorized for the account, the API permits retrieval of fleet locations, individual vehicle locations, trips, historical events, engine data, fault codes, and vehicle information. Access may encompass multiple vehicles and historical records. Access by a third-party integration partner requires both Sonar Telematics approval and customer authorization. Customer use of the API in its own software does not independently authorize disclosure to an unapproved partner.
Customers must accept an approved partner's privacy policy and terms of use before connecting that partner. Sonar Telematics configures the information disclosed through each integration. The partner's processing of information it receives is governed by its own terms and privacy policy. Customers must have authority to authorize the disclosure and provide any required notices or obtain required permissions from affected individuals.
Credentials and Continuing Access
Authorization may permit recurring API requests or event deliveries until expiration or revocation. Customers are responsible for maintaining the confidentiality of API keys and integration credentials and must not disclose them to unapproved services, publish them in source code, or include them in ordinary support communications.
Customers may cancel data sharing with a connected partner, upon which Sonar Telematics automatically stops further sharing through that connection. Customers should use available API controls or contact Sonar Telematics to address compromised credentials. Changing an account password or uninstalling an application may not revoke separately issued API credentials.
Effect of Revocation
Revocation terminates future authorized access through the affected connection but does not automatically delete information previously received by a partner or exported from the Services. Requests concerning partner-held copies may require a separate request to that partner. Sonar Telematics will comply with its own applicable obligations concerning deletion or restriction of disclosed information.
Internal AI Testing
Sonar Telematics currently tests AI integrations internally using only company-owned demo trackers. These integrations are not currently available as customer features.
Before introducing customer-facing AI integrations, Sonar Telematics will provide relevant disclosures concerning data handling and authorization and update this Privacy Policy as appropriate.
11. Retention and Deletion
We guarantee access to one year of tracking history collected through the Services. Records older than one year may be available upon request until deleted through our rollover process. Availability beyond one year is not guaranteed, and older records are not subject to a fixed deletion date. Subscription cancellation does not immediately delete existing history or restart the retention period. Retained records remain subject to rollover deletion and may be available upon reactivation. Access through the Services may require an active subscription. Deletion may be requested separately under Section 13, subject to applicable exceptions.
Retention periods for other information depend on the purposes of processing and applicable legal requirements, as follows.
Account and access records are retained as necessary to administer the customer relationship, manage permissions, resolve account inquiries, and satisfy applicable obligations. Billing and subscription records are retained for payment reconciliation, accounting, tax compliance, dispute resolution, and related legal requirements.
Glovebox documents, customer entries, and maintenance records are retained to provide the relevant storage and management features. Driver profiles and assignment records are retained to administer fleet accounts and provide driver-specific histories and reports. Support, diagnostic, and security records are retained according to the matter concerned, service reliability and security requirements, and applicable law. These records remain subject to applicable deletion rights.
We delete or de-identify personal information when it is no longer required for the relevant purposes, unless further retention is necessary for a lawful reason, including required recordkeeping, a legal hold, a dispute, or a fraud investigation. Information retained for such a reason is retained for that purpose. Removal of a name or account identifier alone does not necessarily de-identify location history.
Backup and disaster-recovery copies may be subject to separate deletion cycles and remain subject to applicable protections and deletion obligations. Requests concerning copies exported by account users or retained by approved partners may also need to be directed to the relevant recipient.
12. Information Security
We maintain administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, use, disclosure, alteration, and loss. Staff access is restricted through system roles according to job responsibilities and business need. Personnel receive training on privacy, confidentiality, and appropriate handling of customer information. No method of transmission or storage is completely secure.
Customers are responsible for safeguarding credentials and devices used to access the Services and should promptly report suspected unauthorized access or disclosure. Reports should not include the affected password or API secret.
We evaluate reported security incidents and take appropriate action based on the circumstances. Where notification is required, we notify affected individuals, customers, or authorities in accordance with applicable law and contractual obligations.
13. Privacy Rights and Requests
Depending on your jurisdiction, our role in processing the information, and applicable law, you may have the following rights, subject to relevant conditions and exceptions.
Access. You may request confirmation of whether we process your personal information, access to that information, and details concerning the categories of information, sources, processing purposes, recipients, and disclosures.
Correction and portability. You may request correction of inaccurate personal information, taking into account its nature and use, and a copy in a portable format where required by applicable law. Correction of a driver assignment does not necessarily alter the underlying vehicle reading.
Deletion and restriction. You may request deletion of personal information or restriction of processing where applicable. Exceptions may apply for recordkeeping, security, legal claims, or protection of other individuals' rights. We provide reasons for a refusal or limitation where required.
Consent and objections. Where applicable, you may withdraw consent, object to processing, limit certain uses of sensitive personal information, or opt out of legally defined sales, advertising-related sharing, targeted advertising, or certain profiling. Withdrawal of consent for processing necessary to a feature may require discontinuation of that feature.
Submitting a Request
Deletion requests should be sent to notifications@sonartelematics.com from the email address associated with the account and include the relevant tracker IMEI number or numbers and the scope of the request. Other privacy requests may be submitted through the same address or the contact details in Section 18. Individuals without an account, access to the account email, or an IMEI may contact us and describe their relationship to the information. Passwords, API secrets, and complete payment card numbers should not be submitted.
We may request information reasonably necessary to verify identity or authority and distinguish the requester's information from information relating to others. Verification information is used for the request and related security or legal requirements. Authorized agents may submit requests where permitted, subject to evidence of authorization and any identity verification required by law.
Where we process information on behalf of a business customer, we may coordinate with that customer or refer the request to it. A request concerning an individual driver does not authorize disclosure of unrelated fleet or third-party information. We apply these limitations in accordance with our own legal obligations.
Responses and Appeals
We respond within applicable statutory timeframes and provide notice of any permitted extension and its basis. Requests are generally processed without charge. Any fee or refusal will be limited to circumstances permitted by law and explained as required. We do not unlawfully discriminate or retaliate against individuals for exercising privacy rights.
Where an appeal right applies, an individual may appeal a denial by replying to our response or emailing us with the subject "Privacy Appeal" and stating the grounds for the appeal. We review appeals under applicable requirements. Individuals may also submit complaints to the relevant state attorney general or other competent privacy authority.
14. Application Technologies and Communications
We use Google Analytics and Firebase solely to analyze application usage, diagnose application issues, and improve the application experience. Information disclosed to these tools is limited to application usage and diagnostic information. We do not disclose tracker data, vehicle locations, trip history, driver information, or other telematics-service data to these tools, and we do not use them for advertising. The web application may use cookies or local storage for authentication, security, and preferences. The Shopify storefront is governed by its separate privacy policy.
Application permissions and push notifications may be managed through device settings and available application controls. Browser settings may permit users to delete or block locally stored information, which may affect authentication and preferences. These settings do not deactivate tracking devices, revoke API credentials, or delete server-side records.
Recipients may unsubscribe from promotional emails using the instructions provided in those messages. Account, billing, security, and other necessary service communications may continue. Vehicle alerts are subject to the applicable alert configuration and notification permissions.
15. Additional Information for US Residents
This section supplements Section 13 to the extent applicable US state privacy law governs Sonar Telematics and the personal information concerned. Rights and obligations vary according to statutory coverage, definitions, and exemptions.
The information described in Section 3 may fall within the following statutory categories: identifiers and customer records; commercial information, including subscription and payment history; internet or electronic activity, including application and API records; precise geolocation; employment-related information supplied through fleet accounts; and inferences or derived information, including trip and driving summaries. Sensitive personal information may include precise geolocation, account credentials, and information contained in uploaded documents.
Sections 3 through 5 describe the sources and purposes of collection; Section 8 identifies recipient categories; and Section 11 describes retention periods and criteria. The commitment not to sell vehicle data appears in Section 9. Approval of an integration partner does not authorize disclosure without customer authorization.
California Privacy Rights
To the extent the California Consumer Privacy Act, as amended, applies, eligible California residents may exercise rights of access, correction, deletion, nondiscrimination, and applicable rights concerning sale or sharing and use of sensitive personal information. Requests to know, delete, or correct generally receive a response within 45 calendar days. We provide notice of any extension permitted by law. Other request types and jurisdictions may be subject to different deadlines.
16. Children and Teen Drivers
The Services are intended for adult account holders and organizations and are not directed to children under 13. Vehicle information may nevertheless relate to a minor, including where a parent or organization uses the Services in a vehicle operated by a teenager. Applicable notice, authorization, and consent requirements continue to apply.
A parent or guardian who believes a child under 13 has provided personal information directly to Sonar Telematics without required authorization may contact us. We investigate and take appropriate action, including deletion where required. Customers should not submit unnecessary information about children through Glovebox, notes, or support communications.
17. Data Storage and Changes to This Policy
US Data Storage
Service data is stored in the United States. Information collected in connection with use of the Services in Canada is transferred to and stored in the United States, where it is subject to US law and may be accessible to courts, law enforcement, and national security authorities under applicable legal process.
Canadian Privacy Rights
This provision applies to individuals across all Canadian provinces and territories, including Quebec, to the extent applicable Canadian privacy law governs the processing. Individuals may request access to their personal information, information about its use and disclosure, and correction of inaccurate or incomplete information. Individuals may withdraw consent, subject to applicable legal or contractual restrictions and reasonable notice. We will explain any resulting limitations on the Services. Requests and complaints may be submitted to the Chief Operating Officer using the contact details in Section 18. Individuals may also complain to the Office of the Privacy Commissioner of Canada (https://www.priv.gc.ca) or the applicable provincial privacy commissioner, including the Commission d'accès à l'information du Québec.
Amendments
We may amend this Privacy Policy to reflect changes in our practices, the Services, or applicable law. The revised policy will be made available with an updated effective date. We provide additional notice of material changes and obtain consent where required. An amendment does not replace any separate consent or other legal requirement applicable to a new use of previously collected information.
18. Contact Sonar Telematics
For privacy questions, requests, suspected unauthorized tracking, or security concerns, contact:
1073 Willa Springs Drive, Suite 2021
Winter Springs, FL 32708
United States
Email: notifications@sonartelematics.com
Phone: +1 (650) 772-4059