Privacy Policy — neweb GPS

Last updated: 2026-08-01

neweb GPS is the web portal for the Track DZ fleet tracking service. It shows the position and activity of vehicles fitted with GPS tracking devices to the account holder who operates them. This policy explains what the portal and the service collect, why, and who it is shared with. The same commitments apply to the Track DZ mobile application, which uses the same accounts and the same data.

1. Who we are

Track DZ is operated by WEB GPS. Vehicle and account data is stored on servers under our control. Where vehicles are operated by an employer or fleet owner, that organisation decides how the service is used and is responsible for informing its drivers.

Contact us:

To complete before store submission: registered company name and postal address. Both stores expect a policy to identify the responsible legal entity.

2. What the service collects

2.1 Account information

DataWhy
Username and passwordTo authenticate you. Passwords are stored as a hash, never in readable form.
Email addressAccount recovery and notification delivery.
IP address and last sign-in timeSecurity: detecting and rate-limiting failed sign-in attempts.
Preferences (language, units, time zone, map choice)To present the interface the way you set it.

2.2 Vehicle position data

Location data comes from the GPS tracking devices installed in the vehicles, not from your phone. The mobile application does not read your phone's location, and does not request location permission.

DataWhy
Position, speed, heading, altitudeTo display vehicles on the map and produce history and reports.
Device status (ignition, battery, sensor inputs)To show vehicle state and trigger the alerts you configure.
Tracker identifier (IMEI) and reporting timeTo associate reported data with the correct vehicle.

2.3 This web portal

The portal sets two cookies, both strictly for signing you in. Neither is used for advertising, profiling or analytics, and no third party can read them.

CookieWhy, and for how long
PHPSESSIDIdentifies your signed-in session. Deleted when you sign out or close the browser.
gs_sess_hashSet only if you tick “remember me”. Lets the browser sign in again for 30 days. Signing out with “everywhere” revokes it.

The portal does not read your device's location and never asks for location permission: the positions you see come from the GPS trackers in the vehicles. It loads no third-party scripts, no advertising or analytics tags, and no social-network widgets. Map imagery is requested through the operator's own map proxy, so your account identity is not sent to a tile provider.

2.4 Mobile application

DataWhy
Push notification tokenTo deliver the alerts you enable. Issued by Firebase Cloud Messaging.
Device model and platformTo label the device in your account so you can identify it.

The application does not collect contacts, photos, microphone, phone location, advertising identifiers, or usage analytics.

3. Who the data is shared with

Vehicle and account data is not sold, rented, or shared for advertising. It is disclosed only to:

4. How long data is kept

5. Security

Traffic between the applications and the service is encrypted with HTTPS. Passwords are stored hashed. Access to vehicle data is restricted to the account that owns the vehicle and to sub-accounts explicitly granted access.

6. Your rights

You may request access to the personal data held about you, correction of inaccurate data, deletion of your account, or a copy of your data. Requests should be sent to the operator contact address above. Because vehicles are usually operated by an employer or fleet owner, some requests may need to be directed to that organisation, which decides how the service is used.

7. Children

The service is intended for business fleet management and is not directed at children.

8. Changes

Material changes to this policy will be reflected here with an updated date at the top of the page.