Privacy Policy
Effective date: September 15, 2026
Who we are
TTJ Equipment, Inc., 6004 South First St Lufkin Tx 75901(“we”, “us”) provides a fleet tracking and telematics platform at vebric.app that lets organizations monitor the location and condition of their equipment and vehicles, and sells the per-machine tracking plans bought through the customer portal. For questions or requests about your data, contact us at Terrence@ttjequipment.com.
Information we collect
- Account information. When you sign in with Google, Microsoft, or an email magic link, we receive and store your email address and display name from your identity provider, along with your sign-in times and role within your organization. We never see or store a password.
- Machine location and telemetry.GPS trackers and manufacturer telematics feeds installed on your organization’s equipment report position (latitude/longitude), speed, heading, ignition state, engine and CAN-bus data (such as fuel level, RPM, and battery voltage), and device identifiers (IMEI, serial number, SIM number/ICCID, VIN). This data describes machines; where a machine is operated by an identifiable person, it may also constitute personal data about that person.
- Customer records your organization enters. Organizations may store contact records for their own customers (name, company, email, phone, notes) to associate machines with them. Your organization controls this data; we process it on their behalf.
- Customer portal users. An organization using Vebric (a dealer) can invite the people at one of its customers into a separate customer portal, where that customer can follow the machines it pays us to track. For those users we hold an email address and display name, the role held within the customer account (administrator or viewer), and a record of the invitation — who sent it, when, and when it was accepted. When an administrator of a customer account buys a machine tracking plan, we also hold their billing identity: name, email address, and billing address, and a record of the consent given at purchase (which plan, which version of these documents, and when). The payment method itself is handled entirely by Stripe — card numbers never reach our servers — and Stripe retains the invoice history for those charges.
- Preferences and activity. Your interface preferences (theme, map style, alert settings) and an audit log of administrative actions taken in the app.
We do not collect payment card details (billing is handled by Stripe), and we do not run any advertising or analytics trackers.
Who is responsible for your data
Two different relationships run through the same platform, and which one applies decides who answers for the data:
- An organization’s data — we are a processor. The machine telemetry, the customer records, and the staff accounts belonging to an organization using Vebric are controlled by that organization. We process them on its behalf and on its instructions. A request about that data is usually a matter for the organization, and we may refer you to it.
- A portal user’s own account and payments — we are the controller. If you were invited to a customer portal, your account details and everything to do with the plans you buy are ours to answer for: you buy from TTJ Equipment, Inc. and pay TTJ Equipment, Inc.directly, not your dealer. Bring those requests to us, at the address above. The machine data you can see in the portal still belongs to the dealer’s organization.
What the customer portal shows
The customer portal is deliberately narrow. It shows the location and status of only those machines the customer account is currently paying for— never the dealer’s other equipment, never another customer’s machines, and not machines whose plan has lapsed or was never bought. That access is re-checked against the live subscription on every request, so it ends when the plan does.
What your dealer can see. The narrowing runs one way. Staff at the dealer organization that owns a machine can see the location, history, and telemetry of every machine assigned to your customer account — paid for or not, in their own fleet app. Your dealer also decides which machines are assigned to your account in the first place. If you would rather a machine were not visible to them, that is a conversation to have with your dealer: cancelling a plan removes the machine from your portal, not from theirs.
Sensitive data and precise location
Machine location is precise geolocation data, which several US state privacy laws treat as sensitive personal data when it can be linked to an identifiable person — the operator of a tracked machine, for example. We collect it because it is the product: reporting where a machine is is the entire purpose of a tracker. We use it only to show that machine to the people authorized to see it, and never for advertising, profiling, or any purpose unrelated to the tracking service.
TTJ Equipment, Inc. does not sell personal data of any kind, and does not sell or share sensitive personal data. The organization that owns or leases the machine decides who is tracked and is responsible for the notices and consents the law requires of it; we process that data on its instructions.
Your device's location
When you open the map, your browser may ask permission to use your device’s location. If you allow it, your location is used only on your device to center the map — it is never transmitted to our servers or stored. You can decline the prompt or revoke the permission in your browser at any time; the map works without it.
Cookies and on-device storage
We use only strictly necessary cookies — the ones required to keep you signed in and to secure the service. Because we set no optional, analytics, or advertising cookies, there is nothing to opt in or out of; we show a one-time notice for transparency instead of a consent wall.
- Authentication cookies (names beginning sb-): hold your encrypted Supabase sign-in session so you stay logged in. Deleted when you sign out.
- vebric_backup_oauth_state: a short-lived (10 minute) security cookie used only during the administrator Google Drive backup connection flow, to prevent cross-site request forgery.
- Browser local storage (keys beginning vebric:): your theme choice, whether you dismissed the welcome tour and the cookie notice, and the last product announcement you saw. These never leave your device.
- Map imagery cache: to make the map fast, satellite and street map tiles you view are cached on your device for up to 30 days. Cached tile addresses can reveal which geographic areas you viewed. You can clear this cache at any time from Account → Privacy & Data → Clear cached map imagery (customers: Portal → Account), or by clearing your browser’s site data.
Third-party services
We share data with a small set of service providers, only as needed to run the platform:
- Supabase — authentication and magic-link sign-in emails. Your browser communicates with Supabase directly during sign-in.
- Google and Microsoft — if you choose them as your sign-in provider, your browser is redirected to them and they learn that you sign in to Vebric.
- Map tile providers — Mapbox, Esri/ArcGIS, OpenStreetMap, CARTO, and OpenMapTiles serve map tiles and fonts directly to your browser. They receive your IP address and the tile coordinates of the areas you view, subject to their own privacy policies.
- Location lookup services— to turn coordinates into something readable, our servers send a machine’s precise latitude and longitude to OpenStreetMap’s Nominatim service for reverse geocoding (the street address shown beside a machine), and the coordinates of a route to Mapbox’s map-matching service to snap a trail onto roads. These requests carry machine coordinates only — neither service receives your name, email address, or any account, organization, or customer identifier.
- Resend — delivers our transactional email: organization invitations (recipient address, inviter name, organization name), customer-portal invitations (recipient address, dealer organization name, customer account name), and the purchase confirmations and renewal reminders sent to customer-account administrators.
- Stripe— subscription billing, both for organizations and for the per-machine tracking plans a customer buys directly in the portal. We send Stripe the payer’s name, email address, and billing address, together with our own identifiers for the customer, the organization, and the machine as metadata, so a payment can be matched to what it paid for. Card details go to Stripe, never to us; Stripe stores the payment method and the invoice history under its own privacy policy.
- Google Drive — encrypted-in-transit system backups (which include the database) are stored in a Vebric-controlled Google Drive account.
- Connectivity and telematics partners— Hologram (tracker SIM management) and equipment manufacturers’ telematics APIs (e.g. MyDevelon) that supply machine data for your organization’s equipment.
We never sell personal information or share it for advertising.
How long we keep data
- Machine position and event history: 90 days.
- Snapped trail geometry (the road-matched version of a route): 90 days.
- The tracking gateway’s own copy of incoming positions: 30 days.
- Raw device diagnostic data: 30 days.
- Administrative audit logs: 365 days.
- Stripe payment-event records (kept so the same billing event is never processed twice): 90 days.
- Subscription records: our copy of a plan’s status lives as long as the machine and customer account it belongs to, and is deleted with them. Stripe keeps the underlying payment and invoice records for as long as tax and accounting law requires.
- Account, organization, and customer records: for as long as the account or organization remains active, then deleted on request or on account closure.
- System backups: encrypted snapshots are kept on a rotation of 7 daily, 4 weekly, and 6 monthly copies. Data you have deleted, or that has aged out of the windows above, can therefore still exist in a backup for up to about seven months before that backup is itself rotated out.
Your rights
If you live in Texas, the Texas Data Privacy and Security Act gives you the right to confirm whether we process personal data about you, to access and obtain a copy of it, to correct it, to delete it, and to appeal if we decline a request. Residents of other US states with comparable privacy laws — California, Colorado, Connecticut, Virginia and others — have substantially the same rights, and we apply the same process to everyone rather than checking your address first. If you are in the EU or the UK, we will honor requests under the GDPR on request. You can export your data and permanently delete your account yourself at any time from Account → Privacy & Data in the app (customers: Portal → Account). For anything else, email Terrence@ttjequipment.com — we respond within 30 days. If your data was entered by an organization using Vebric (for example, a customer record or telemetry from a machine you operate), we may refer your request to that organization, which controls that data.
The export covers your profile and preferences, your organization memberships, your customer portal memberships (which customer account, which role, since when), the machine tracking plans on the customer accounts you belong to (machine, plan, status, and renewal date), invitations still outstanding to your email address, and your recent administrative activity. Deleting your account removes it along with those memberships and invitations. Two checks stand in the way of stranding someone else: we refuse to delete the only owner of an organization, and the only administrator of a customer account — appoint a replacement first, then delete.
A note for organizations using Vebric
If your organization tracks vehicles or equipment operated by employees or other identifiable people, your organization is responsible for having a lawful basis to do so and for informing those individuals, as described in our Terms of Service.
Security
All traffic is encrypted in transit (HTTPS/TLS). Access to data is scoped to your organization and role, administrative actions are audit-logged, and we retain raw data only as long as described above. No system is perfectly secure; if a breach affecting your personal data occurs, we will notify affected users and authorities as required by law.
Children
Vebric is a business tool and is not directed at children under 16. We do not knowingly collect personal data from children.
Changes to this policy
If we make material changes to this policy, we will update the effective date above and email the administrators of any customer account with an active plan at least 30 days before the change takes effect. Continued use of the service after a change takes effect constitutes acceptance of the updated policy.