Privacy Policy
1. Introduction
Oculamor Ltd, a company registered in England and Wales (Company No. 17011848; ICO Registration: ZC090570) ("Oculamor," "we," "us," or "our") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our services, or interact with us in any way.
We provide family vehicle monitoring and teen driver safety solutions. Given the sensitive nature of location data and driving information, we take our responsibility to protect your data extremely seriously.
By accessing or using our services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with our policies and practices, please do not use our services.
2. Information We Collect
2.1 Information You Provide Directly
We collect information you voluntarily provide when you:
- Join our waitlist (email address, optional first name)
- Create an account (name, email, password, mobile phone number). To prevent fraudulent and automated signups, we verify your mobile number at registration by sending a one-time passcode (OTP) via SMS; we record only that a code was sent (not the number itself) for operational and abuse-prevention purposes.
- Subscribe to our services (billing information, address)
- Contact our support team (communication content, attachments)
- Participate in surveys or promotions (responses, preferences)
- Configure your vehicle monitoring settings (vehicle information, driver profiles)
2.2 Information Collected Automatically
When you access our website or services, we automatically collect:
- Device Information: Browser type, operating system, device identifiers, screen resolution, and language preferences
- Log Data: IP address (hashed for privacy), access times, pages viewed, referring URLs, and clickstream data
- Location Data: Approximate location based on IP address (for fraud prevention and service optimization)
- Cookies and Tracking Technologies: Session cookies, persistent cookies, and similar technologies (see Section 7)
2.3 Vehicle and Driving Data (Service Users)
When you use our vehicle monitoring services, we collect:
- Location Data: Real-time and historical GPS coordinates of monitored vehicles
- Driving Behavior: Speed, acceleration, braking patterns, and route information
- Vehicle Diagnostics: Engine status, fuel levels, mileage, and maintenance alerts (where available)
- Trip Information: Start/end times, duration, distance traveled, and stops made
- Safety Events: Hard braking, rapid acceleration, speeding incidents, and potential collision alerts
Important: Vehicle and driving data is only collected from devices you have installed and configured. All monitored drivers must be informed of and consent to monitoring in accordance with applicable laws.
2.4 Information from Third Parties
We may receive information from:
- Payment processors (transaction confirmations, not full card details)
- Analytics providers (aggregated usage statistics)
- Marketing partners (with your consent)
- Public databases (for fraud prevention)
3. How We Use Your Information
We use the information we collect for the following purposes:
3.1 Service Delivery
- Provide, maintain, and improve our vehicle monitoring services
- Process your waitlist registration and notify you of launch
- Send real-time alerts about vehicle location and driving events
- Generate driving reports and safety scores
- Process payments and manage subscriptions
- Provide customer support and respond to inquiries
3.2 Safety and Security
- Detect, prevent, and address fraud, abuse, and security threats
- Enforce our Terms of Service and other policies
- Protect the safety of our users, employees, and the public
- Comply with legal obligations and respond to lawful requests
3.3 Communications
- Send service-related announcements and updates
- Respond to your comments, questions, and requests
- Send marketing communications (with your consent)
- Notify you about changes to our services or policies
3.4 Research and Development
- Analyze usage patterns to improve our services
- Develop new features and products
- Conduct research on driving safety (using anonymized data only)
- Train and improve our algorithms and models
3.5 Anonymised and Aggregated Data for Business Purposes
We may use fully anonymised or aggregated data derived from our services for marketing, promotional, and business development purposes. This includes publishing fleet-level statistics such as average safety scores, total miles monitored, trip counts, and general driving behaviour trends on our website, social media channels, presentations, and investor materials.
This data will not identify any individual user, vehicle, or household. Where our user base is small, we take additional care to ensure that published statistics cannot reasonably be used to identify any participant. Anonymised data that falls outside the scope of personal data (as defined by the UK GDPR) is not subject to the data rights described in Section 8 of this policy.
3.6 Internal Access to Personal Data
To operate the Service safely and reliably, authorised Oculamor personnel may access, review, and process personal data — including account information, location data, driving behaviour, device telemetry, and support communications — for the following purposes:
- delivering and maintaining the Service;
- diagnosing bugs, investigating incidents, and validating data pipelines;
- responding to your support requests;
- investigating suspected abuse, fraud, or breaches of our Acceptable Use Policy;
- complying with legal obligations and responding to lawful requests from authorities;
- security monitoring and protection of the Service and its users.
Access is restricted to personnel who need it for their role, is purpose-limited, and is governed by our internal Data Access Policy. We do not access personal data out of curiosity, for marketing purposes, or for any purpose not listed above or described elsewhere in this policy.
Our lawful bases for this access are contract performance (Article 6(1)(b) UK GDPR) and legitimate interests (Article 6(1)(f) UK GDPR), and, where applicable, legal obligation. We have conducted a Data Protection Impact Assessment covering internal access to location data.
3.7 Product Analytics
When you are signed in, we record which Oculamor features your account uses (for example, viewing trips or reports) and key account milestones (such as adding your first device or completing your first trip). We use this to understand which features are useful and to improve the service. This processing relies on our legitimate interests in improving Oculamor. The data consists of feature-usage counts, a record of key account milestones you have reached, and timestamps. It stays within Oculamor and is never shared with or sold to advertising platforms. Usage counts are deleted after 24 months, milestone records are kept for the life of your account, and everything is deleted when your account is deleted (see Section 6).
4. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA) and United Kingdom, we process your personal data based on the following legal grounds:
- Contract Performance: Processing necessary to provide our services to you
- Legitimate Interests: Processing for fraud prevention, security, service improvement, and direct marketing (where not overridden by your rights)
- Consent: Processing based on your explicit consent (e.g., marketing emails, cookies)
- Legal Obligation: Processing required to comply with applicable laws
5. How We Share Your Information
We do not sell your personal information. We may share your information in the following circumstances:
5.1 Service Providers
We share information with trusted third-party service providers who assist us in operating our services, including:
- Cloud hosting providers (data storage and processing)
- Payment processors (transaction processing)
- Email service providers (communications)
- SMS / phone-verification providers (sending one-time passcodes to verify your mobile number at signup)
- Analytics providers (usage analysis)
- Customer support platforms (ticket management)
All service providers are contractually bound to protect your data and may only use it for the specific purposes we authorize.
5.2 Within Your Account
If you have a family or business account, information may be shared with other authorized users on your account as configured by the account administrator.
5.3 Legal Requirements
We may disclose your information if required to do so by law or in response to valid legal requests, including:
- Court orders, subpoenas, or other legal processes
- Requests from law enforcement or government agencies
- To protect our rights, property, or safety
- To protect the rights, property, or safety of others
- To detect, prevent, or address fraud or security issues
5.4 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and the choices you may have.
6. Data Retention
We retain your information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
| Data Type | Retention Period |
|---|---|
| Waitlist Information | Until service launch + 2 years, or until you unsubscribe |
| Account Information | Duration of account + 7 years (for legal/tax purposes) |
| Raw GPS Position Data | Removed from live systems within 90 days; the journey's route and distance stay on the trip record |
| Trip Records | Personal and family workspaces: 90 days (journeys you classify as business are kept up to 6 years for tax evidence). Business workspaces: at least 7 years for HMRC benefit-in-kind evidence |
| Safety Alerts | 3 years (for insurance and safety dispute records) |
| Support Communications | 3 years from resolution |
| Payment Records | 7 years (legal requirement) |
| Server Logs | 90 days |
| Product Analytics Data | Feature-usage counts: 24 months. Account-milestone records: duration of account. All deleted when your account is deleted (see Section 3.7) |
| Phone-Verification (SMS) Logs | 90 days (operational records of one-time-passcode sends — no phone number is stored) |
You may request deletion of your data at any time, subject to our legal obligations to retain certain information.
7. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to collect and store information about your interactions with our services.
7.1 Types of Cookies We Use
- Essential Cookies: Required for the website to function properly (authentication, security, load balancing)
- Analytics Cookies (optional): Set only if you opt in via our consent banner, to help us understand how visitors interact with our website (page views, traffic sources). Our core site analytics is cookieless — it runs without storing anything on your device (see our Cookie Policy).
We do not currently use functional or marketing cookies. If this changes in the future, we will update this policy and our Cookie Policy, and request your consent before setting any such cookies.
7.2 Managing Cookies
You can control cookies through your browser settings. Most browsers allow you to:
- View what cookies are stored and delete them individually
- Block third-party cookies
- Block all cookies
- Clear all cookies when you close your browser
Note that blocking essential cookies may affect the functionality of our services.
8. Your Rights and Choices
Depending on your location, you may have the following rights regarding your personal information:
8.1 Access and Portability
You have the right to request a copy of the personal information we hold about you in a structured, commonly used, and machine-readable format. We will provide exports in CSV or JSON format. We are not obliged to provide live API access, database dumps, or proprietary binary formats. Exports are delivered via secure download link within 30 days of a valid request.
8.2 Correction
You have the right to request that we correct any inaccurate or incomplete personal information.
8.3 Deletion
You have the right to request deletion of your personal information, subject to certain exceptions (e.g., legal obligations, ongoing disputes).
8.4 Restriction and Objection
You have the right to restrict or object to certain processing of your personal information, including processing for direct marketing purposes.
8.5 Withdraw Consent
Where we rely on your consent to process personal information, you have the right to withdraw that consent at any time.
8.6 How to Exercise Your Rights
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days (or as required by applicable law).
8.7 Right to Lodge a Complaint
If you believe we have violated your privacy rights, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's data protection regulator:
Information Commissioner's Office (ICO)
Website: ico.org.uk/make-a-complaint
Phone: 0303 123 1113
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
9. Children's Privacy
Our services are designed for use by parents and guardians to monitor teen drivers. We take special care regarding the privacy of minors.
9.1 Age Requirements
- You must be at least 18 years old to create an account or join our waitlist
- Monitoring of drivers under 18 requires verifiable parental/guardian consent
- We do not knowingly collect personal information directly from children under 13
9.2 Parental Controls
Parents and guardians have full control over the monitoring of teen drivers, including:
- Setting up and managing driver profiles
- Configuring what data is collected and how long it is retained
- Reviewing and deleting driving data
- Disabling monitoring at any time
9.3 Teen Driver Notification
We recommend that parents inform their teen drivers about the monitoring. Our service includes tools to help facilitate this conversation. We do not support covert surveillance of adults.
9.4 Monitored Drivers' Independent Rights
Where a person is monitored through the Service but is not the account holder (for example, a teen driver or partner), that person retains independent rights under UK GDPR in respect of their own personal data, including:
- the right to request a copy of their own driving and location data;
- the right to request correction or deletion (subject to legal retention obligations);
- the right to withdraw consent to monitoring at any time;
- the right to lodge a complaint with the ICO;
- the right to contact Oculamor directly without going through the account holder.
A monitored driver may contact us at [email protected]. We will handle such requests in line with UK GDPR and, where appropriate, independently of the account holder. We do not require the account holder's permission to respond to a monitored driver's data rights request.
9.5 Age Transition
When a monitored driver reaches 18, parental consent alone is no longer sufficient for continued monitoring. The driver must provide their own informed consent. We may prompt the account holder and driver to re-confirm consent at or around the driver's 18th birthday. If independent consent is not obtained, monitoring of that driver must cease.
10. International Data Transfers
Your information may be transferred to, stored, and processed in countries other than your country of residence, including the United States and other countries where our service providers operate.
When we transfer data internationally, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses approved by the European Commission
- Data Processing Agreements with all service providers
- Adequacy decisions where applicable
- Compliance with the UK GDPR and UK International Data Transfer Agreement
11. Data Security
We implement comprehensive security measures to protect your personal information, including:
11.1 Technical Safeguards
- Encryption in transit (TLS/SSL) for all data transmission
- Secure hosting with reputable cloud providers (Vercel)
- Input validation and sanitization to prevent injection attacks
- Cross-site scripting (XSS) and CSRF protection
- Rate limiting to prevent abuse
- Security headers and Content Security Policy
- Automated vulnerability scanning of dependencies
- Code security analysis (CodeQL)
11.2 Organizational Safeguards
- Limited access to personal data on a need-to-know basis
- Secure development practices
- Regular review of security measures
- Use of trusted third-party service providers
11.3 Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant authorities as soon as reasonably practicable and in accordance with applicable law.
12. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to Know: What personal information we collect, use, and disclose
- Right to Delete: Request deletion of your personal information
- Right to Correct: Request correction of inaccurate information
- Right to Opt-Out: Opt out of the sale or sharing of personal information (we do not sell your data)
- Right to Non-Discrimination: We will not discriminate against you for exercising your rights
- Right to Limit Use: Limit the use of sensitive personal information
To exercise these rights, contact us at [email protected] or call us at the number provided below.
13. Do Not Track Signals
Some browsers offer a "Do Not Track" (DNT) setting. There is currently no industry standard for how companies should respond to DNT signals. Our website uses minimal tracking (primarily for analytics and service improvement), and we do not currently alter our data collection practices based on DNT signals.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the new Privacy Policy on this page
- Updating the "Last Updated" date at the top
- Sending you an email notification (for material changes affecting active users)
- Displaying a prominent notice on our website
Your continued use of our services after any changes constitutes acceptance of the updated Privacy Policy.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Oculamor Ltd
Registered in England and Wales. Company No. 17011848
ICO Registration: ZC090570
Email: [email protected]
Website: https://oculamor.com
16. Data Processing Agreements
We maintain Data Processing Agreements (DPAs) with all third-party processors who handle your personal data. These agreements ensure GDPR-compliant data handling and appropriate safeguards.
| Processor | Purpose | DPA |
|---|---|---|
| Stripe | Payment processing | View DPA |
| Resend | Transactional email delivery | View DPA |
| Vercel | Application hosting & CDN | View DPA |
| DigitalOcean | Backend hosting & infrastructure | View DPA |
| Cloudflare | DNS, CDN & security services | View DPA |
| Monogoto | IoT SIM management & device connectivity | Contact us |
| Twilio (Twilio Inc., USA) | SMS one-time-passcode delivery for signup phone verification (transfers safeguarded by Standard Contractual Clauses and the UK International Data Transfer Agreement) | View DPA |
For copies of our executed DPAs or further information, contact us at [email protected].
See also: Terms of Service