Privacy Policy
1. Who We Are
QuickliTrack ("we", "us", "our") is a hire management application developed and operated by Artifexon Design, a company registered in Brazil (CNPJ: 52.422.571/0001-18), with its registered address at 691 Rua Moçambique, Rio Vermelho, Florianópolis, SC, Brazil.
Although we are based in Brazil, QuickliTrack is designed for and offered to users in the United Kingdom. We comply with:
- UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018
- Lei Geral de Proteção de Dados (LGPD) — Brazil's data protection law
This Privacy Policy describes how we collect, use, store, and protect your personal data when you use QuickliTrack on iOS, Android, or the web.
2. Data Controller
Artifexon Design is the data controller responsible for your personal data. For any data protection enquiries, contact us at support@quicklitrack.com.
3. Data We Collect
Account Data
- Email address — used for authentication and account recovery
- Company name — entered during business owner signup
- User role — admin or driver, set during registration
Operational Data
- Hire records — customer name, phone number, address, skip details, rental dates, pricing, driver assignment, collection status
- Location data — GPS coordinates for hire address mapping and route planning (only when the app is actively in use)
- Photo proof — images taken by drivers to confirm deliveries or collections
- Driver profiles — name and email of drivers added to a company account
Technical Data
- Device information — OS version, app version, screen size, browser type (collected automatically by Firebase and reCAPTCHA)
- Crash reports — error data to improve stability (via Sentry; all on-screen text is masked)
- Session replays — anonymised screen recordings to diagnose bugs (via Sentry; all text is masked, no personal data is captured)
- Performance metrics — page load times and network latency (via Firebase Performance Monitoring)
- Behavioural signals — reCAPTCHA Enterprise collects interaction patterns to distinguish genuine users from bots (no personal identification)
- Push notification tokens — device tokens for delivering push notifications (only with your explicit permission)
Local Device Data
The following data is stored locally on your device and is not transmitted to our servers:
- Theme preference — light or dark mode setting
- Cached driver list — for offline access
- Cached company settings — for offline access
- Onboarding completion flag — whether you've completed initial setup
- Preferred navigation app — your chosen map app for driving directions
- Depot location — your saved depot address for route planning
- Offline database — Firestore uses IndexedDB for offline data persistence
4. How We Use Your Data
| Purpose | Legal Basis (UK GDPR) |
|---|---|
| Account creation and authentication | Performance of contract (Art. 6(1)(b)) |
| Displaying hires on maps | Performance of contract (Art. 6(1)(b)) |
| Route planning and optimisation | Performance of contract (Art. 6(1)(b)) |
| Email verification and password reset | Performance of contract (Art. 6(1)(b)) |
| Photo proof of deliveries | Legitimate interest (Art. 6(1)(f)) |
| Driver location tracking during work | Legitimate interest (Art. 6(1)(f)) — drivers are informed at signup |
| Crash reporting, error tracking, and session replay | Legitimate interest (Art. 6(1)(f)) |
| Usage analytics and performance monitoring | Legitimate interest (Art. 6(1)(f)) |
| Fraud prevention (reCAPTCHA) | Legitimate interest (Art. 6(1)(f)) |
| AI-powered insights (Gemini) | Legitimate interest (Art. 6(1)(f)) — hire data is anonymised before processing |
| Push notifications | Consent (Art. 6(1)(a)) — only with your explicit permission |
We do not use your data for advertising, profiling, or automated decision-making.
5. Third-Party Services
QuickliTrack uses the following third-party services, all of which maintain their own privacy policies:
| Service | Provider | Purpose | Data Shared |
|---|---|---|---|
| Firebase Authentication | Google LLC | User login and signup | Email, UID |
| Cloud Firestore | Google LLC | Data storage and real-time sync | All operational data |
| Firebase Cloud Storage | Google LLC | Photo proof upload and storage | Images, file metadata |
| Firebase Cloud Functions | Google LLC | Server-side email processing, AI proxy | Email addresses, anonymised hire context |
| Firebase Analytics (GA4) | Google LLC | Usage analytics | Anonymous device data, screen views, events |
| Firebase Performance Monitoring | Google LLC | Page load and network performance | Anonymous performance metrics |
| Firebase Cloud Messaging (FCM) | Google LLC | Push notifications | Device token (with permission) |
| reCAPTCHA Enterprise | Google LLC | Bot and fraud prevention | Device signals, interaction patterns |
| Sentry | Functional Software Inc. | Error tracking and session replay | Error data, anonymised screen recordings (all text masked) |
| Leaflet / OpenStreetMap | OSM Foundation | Map display | Tile requests (no personal data) |
| Google Gemini AI | Google LLC | AI-powered business insights | Anonymised hire context only |
Google processes data in accordance with its Data Processing Terms.
6. International Data Transfers
Your personal data may be transferred and processed outside the United Kingdom:
- Google Cloud infrastructure — Firebase services are hosted across Google's global data centres (primarily in the US and EU)
- Sentry — error data is processed on Sentry's EU servers (Frankfurt, Germany)
- Artifexon Design (Brazil) — as the data controller, we access data for administration and support
These transfers are protected by Standard Contractual Clauses (SCCs) and the UK International Data Transfer Agreement (IDTA) where applicable.
7. Data Retention
| Data Type | Retention Period |
|---|---|
| Account data | Lifetime of your account |
| Hire records | Lifetime of the company account |
| Photo proof | 12 months after a hire is marked as collected |
| Analytics data | Aggregated and anonymised after 14 months |
| Error and session replay data | 90 days (Sentry retention policy) |
| Local device data | Until you clear browser storage or delete the app |
8. Your Rights
Under the UK GDPR
You have the following rights regarding your personal data:
- Access — request a copy of your personal data
- Rectification — correct inaccurate personal data
- Erasure — request deletion of your personal data ("Right to be Forgotten")
- Portability — receive your data in a machine-readable format
- Restriction — limit how we process your data
- Objection — object to processing based on legitimate interest
- Withdraw consent — where processing is based on consent, you may withdraw it at any time
To exercise any of these rights, contact us at support@quicklitrack.com. We will respond within 30 days of receiving your request.
Under the LGPD (for Brazilian Users)
If you are located in Brazil, you also have rights under the LGPD, including the right to confirmation of processing, access, correction, anonymisation, portability, deletion, and information about third parties with whom data is shared.
Account Deletion
You can delete your account at any time from the app's Settings screen. This will:
- Remove your user profile and login credentials
- Remove your association with any company
- Delete your
userLookuprecord
Company data (hires, drivers) remains accessible to other company members. If you are the sole owner and wish to delete all company data, contact us at support@quicklitrack.com.
Right to Complain
If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Website: ico.org.uk
Phone: 0303 123 1113
9. Data Security
- All data is transmitted over HTTPS/TLS encryption
- Firestore data is encrypted at rest by Google Cloud
- Passwords are hashed by Firebase Authentication (never stored in plain text)
- Access to company data is restricted by Firestore security rules (role-based access control)
- reCAPTCHA Enterprise provides an additional layer of protection against automated abuse
10. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms:
- We will notify the ICO within 72 hours of becoming aware of the breach
- We will notify affected users without undue delay if the breach is likely to result in a high risk
- We will document all breaches internally, including those that do not require notification
11. Children's Privacy
QuickliTrack is not intended for use by children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at support@quicklitrack.com and we will delete the data promptly.
12. Cookies and Local Storage
QuickliTrack does not use traditional browser cookies. Instead, it uses:
| Storage Type | Purpose |
|---|---|
| Firebase Auth tokens | Session persistence (secure device storage) |
| localStorage | Theme preference, cached settings, onboarding flag, navigation app preference, depot location |
| IndexedDB | Firestore offline data persistence |
| sessionStorage | Temporary email pre-fill during login flows |
We do not use third-party cookies or tracking pixels.
reCAPTCHA Enterprise may set its own cookies/local storage as part of Google's fraud prevention system. See Google's Privacy Policy for details.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via in-app notification or email. The "Last updated" date at the top of this page reflects the most recent revision.
14. Governing Law
This Privacy Policy is governed by and construed in accordance with the laws of England and Wales. Any disputes relating to this policy shall be subject to the exclusive jurisdiction of the courts of England and Wales.
15. Contact Us
Artifexon Design
691 Rua Moçambique, Rio Vermelho
Florianópolis, SC, Brazil
CNPJ: 52.422.571/0001-18
Email: support@quicklitrack.com
Website: artifexon.com
For data protection enquiries within the UK, please contact our DPO directly at support@quicklitrack.com.