Back to home
Movoright

Legal document

Privacy Policy — Movoright Driver

Last updated: 18/08/2026

This policy describes the personal data processed by the Movoright Driver mobile application (Android and iOS), which is reserved for professional drivers. It complements the public website privacy policy and prevails over it for everything concerning the application.

In short: the application records your location only during a trip you have started and consented to. It contains no advertising, no trackers, and your data is never sold.

1. Who processes your data

The data controller is the transport company that employs you: it determines the purposes and means of the processing. The application is used by several companies; yours can provide you with its exact details.

MRMT NEXTGen Conseils & Associés Inc., publisher of the Movoright platform, acts as a processor: it hosts and operates the service on behalf of the controller and does not use your data for any purpose of its own.

For any question, or to exercise your rights: [email protected].

2. Who the application is for

Movoright Driver is a professional tool. Your account is created by your employer: there is no self-registration from the application. The application is not intended for minors and does not knowingly collect any data concerning them.

3. Data you or your employer provide

This information makes up your professional file. It is entered by your employer, or by you from your profile.

  • Identity and contact details: name, email address, phone number, profile picture, display language.
  • Professional documents: driving licence number and categories, issue and expiry dates, national identity card number, and where applicable images of these documents.
  • Employment information: hire date, postal address, emergency contact and their phone number.
  • Payroll items: pay components and payslips, viewable from the application.

4. Data generated by your use of the application

  • Trips: milestones reached, status changes, timestamps, delay reasons.
  • Vehicle inspections: checkpoints, defects found, observations.
  • Incidents: type, severity, description, place, date.
  • Mission expenses and fuel purchases: amount, station, odometer reading, payment method, receipt photo, and the location of the fuel stop at the time of entry.
  • Location during trips: see section 5, which is entirely devoted to it.

5. Location, including in the background

This is the most sensitive data the application processes. Here is exactly how it works.

Why. To follow the progress of the current trip so as to inform operations and the customer, estimate the arrival time, evidence the service performed, and enable assistance to reach you in the event of an incident.

When, exactly. Recording starts only when two conditions are met: a trip is assigned to you and is in progress (or reported delayed), and you have accepted tracking for that specific trip. Outside those periods, the application records no location at all. There is no tracking outside your trips — not in the evening, not at weekends, not between assignments.

How often. One reading per minute for a trip shorter than 4 hours, one reading every 2 minutes beyond that. Readings are sent in batches roughly every 2 minutes, and held temporarily on the phone when the network is unavailable.

What is recorded. Latitude, longitude, speed, heading, measurement accuracy and timestamp. No audio recording, no imagery, no content of your communications.

In the background. So that tracking stays reliable with the phone in your pocket or the screen locked, the application requests permission to access your location in the background. While tracking is active it remains visible: a permanent notification on Android, the system location indicator on iOS.

How to stop it. You may decline tracking when prompted and carry on with the trip normally. You may withdraw the location permission at any time in your phone settings. Tracking also stops automatically when the trip is closed.

Who sees what. Your employer’s operations and management teams see the route. When a tracking link is shared with the customer, that customer sees the position of the vehicle and nothing else: not your name, not your contact details, not your history.

6. Camera and receipt photos

The application uses the camera only when you choose to photograph a fuel receipt. The image is sent to Google (Gemini service) to automatically read the amount, volume and station, saving you manual entry. No identifier relating to you accompanies the image. You check and correct the suggested values before saving. The application does not access your photo gallery.

7. Technical data

  • Sign-in: IP address and device type at sign-in, kept for account security and detection of unusual access.
  • Notifications: a device identifier issued by your operating system, required to deliver notifications to you. Notification content is encrypted.
  • Operations log: actions performed in the application are timestamped and recorded, for evidence and security purposes.
  • Technical errors: in the event of a malfunction, a technical report may be sent to our monitoring tool. No recording of your screen is made.

8. Why we process this data

PurposeLegal basis
Organise and monitor transport assignmentsPerformance of your employment contract
Evidence the service to the customer, invoiceLegitimate interest of the company
Safety of the driver, the vehicle and the loadLegitimate interest of the company
Produce payroll and social declarationsLegal obligation
Retain accounting recordsLegal obligation (OHADA)
Monitor the validity of licences and identity documentsLegal obligation and road safety

9. What the application does not do

  • No advertising and no advertising identifier is collected.
  • No third-party analytics or profiling tool is embedded.
  • No sale, rental or transfer of your data to third parties.
  • No tracking of your location outside your trips.
  • No access to your contacts, your messages, your photo gallery or your microphone.
  • No recording of your screen.

10. Who your data is shared with

Within your company, access is limited to authorised staff (operations, management, payroll), according to their role. Outside it, the following technical providers are involved on behalf of the platform publisher:

ProviderRoleWhat it receivesCountry
OVHcloudHosting of the servers, the database and the backupsAll service dataCanada (Quebec)
CloudflareWeb traffic routing and filteringThe traffic between your device and our servers, including your IP address. Cloudflare decrypts and re-encrypts that traffic in order to filter it.United States (global network)
Google (Gemini)Automatic receipt readingThe receipt image, without identifierUnited States
MapboxRoute calculationOrigin and destination coordinates, sent by our servers. The application does not contact Mapbox from your phone.United States
SentryServer-side error monitoringTechnical reportsDepending on plan
ResendEmail deliveryEmail address and message contentUnited States
Notification service (Google / Apple)Notification deliveryDevice identifier, encrypted contentDepending on vendor

Where your data is located. The servers running the service, the database and the files you upload are located in a data centre in Quebec, Canada. The platform publisher, MRMT NEXTGen Conseils & Associés Inc., is also a Canadian company: its authorised staff may access this data in order to operate and maintain the service. The company that employs you, as the controller, is established in its own country, and it is with that company that you exercise your rights.

What leaves that infrastructure. Some of the providers listed above receive data from our servers into other countries, shown in the “Country” column — chiefly the United States. Each of these exchanges is limited to what the “What it receives” column describes, and is governed by that provider’s contractual terms, which include the data protection clauses it publishes. Your data may also be disclosed to an administrative or judicial authority where the law so requires.

On the applicable framework. Depending on the country where you work, the country where your employer is established and the country where the data is hosted, several data protection regimes may come into play, and they do not characterise these movements in the same way. This document states the facts — where the data is, who accesses it, where it goes. Its legal characterisation is a matter for the controller and its advisers; it is not settled here. To find out which framework your employer applies, contact it at [email protected].

11. How long your data is kept

DataRetention period
Timestamped location readingsWithin 90 days of the trip being closed, and 12 months at most after they were recorded in all cases, then automatic deletion
Route trace and trip milestones attached to the tripKept with the trip file, which is a supporting document (10 years)
Trips, milestones and transport documents10 years (OHADA accounting obligations)
Fuel receipt photosKept with the fuel purchase, an accounting record (10 years)
Payslips and pay components10 years
Driver file and incidents5 years after the end of the employment relationship
User accountDuration of the contract, then 5 years
Operations log10 years; sign-ins are kept without time limit for evidence purposes
Sign-in sessions30 days after expiry
Database and file backups30 days. Data erased from the service may remain in a backup for up to 30 days after erasure, then disappears along with it.

12. Security

  • Exchanges between your phone and our servers are encrypted in transit (TLS), without exception.
  • Data is hosted in a data centre located in Quebec, Canada, on infrastructure leased from OVHcloud and administered by the platform publisher.
  • A full backup of the database and of the files is taken every day, its integrity is verified automatically after it is written, and it is kept for 30 days. These backups reside on the same infrastructure as the service: we do not currently hold an application-level copy with a separate storage provider.
  • What we do not claim: the server disk is not encrypted at volume level, and neither are the backups. Protection of your data at rest relies on the field-level encryption described below, on access controls, and on the physical security of the data centre.
  • Passwords are never stored in clear text. The most sensitive fields — two-factor authentication secret, social security and tax identifiers in the payroll file, bank details — are subject to field-level encryption in the database.
  • Other data, including your licence number, identity document number, address and locations, is not encrypted at column level: it is protected by application access controls, strict partitioning between client companies, and the security of the hosting environment.
  • Access to data is partitioned by company and restricted by role; every operation is recorded in a timestamped, tamper-evident log.

13. Your rights

You have the right to access, rectify, erase, restrict, port and object to the processing of your personal data.

  • Access and portability: a complete copy of your data is provided on written request, in a machine-readable format.
  • Rectification: you can correct your contact details from your profile; other items in your file are corrected by your employer.
  • Erasure: the procedure, together with the list of what is erased and what must legally be retained, is set out on the /suppression-compte page.
  • Objection to location tracking: decline the tracking prompt, or withdraw the location permission in your phone settings.

To exercise these rights, write to [email protected] with “GDPR request” in the subject line. You will receive a reply within thirty days at the latest. You may also lodge a complaint with the competent data protection authority.

14. Changes to this policy

This policy may change along with the application or the regulatory framework. The date of the latest update appears at the top of the page. Any substantial change to the processing of your location will be notified to you in the application.

15. Contact

The company that employs you — [email protected].

Movoright Driver is an application of the Movoright platform, published by MRMT NEXTGen Conseils & Associés Inc.. Movoright acts as a processor for your employer, who remains your point of contact for any request concerning your data.

Privacy Policy — Movoright Driver