Privacy Policy
Last updated: June 24, 2026
MIoT Cloud, operated by MaxwellTrack, is committed to protecting your privacy. This policy explains what information we collect, how we use and share it, how long we keep it, and the rights you have - wherever in the world you use the Platform. By using the Platform, you agree to this policy.
The short version
- We collect what we need to run the Platform: your account details, the device and usage data you generate, and - if you use them - location, AI, billing, and team data.
- We never sell your personal data, and we do not use it for advertising.
- You stay in control: insurance data sharing is opt-in and revocable, and you can access, correct, export, or delete your data at any time.
- We protect your data with encryption, scoped access, and audit logging, and keep it only as long as we need it.
- We operate across many regions and apply the privacy law that protects you, wherever you are.
This summary is for convenience only; the full policy below governs.
1. Who we are and what this covers
MIoT Cloud is operated by MaxwellTrack ("MIoT", "we", "us", "our"). This Privacy Policy explains what personal data we collect when you use our websites, dashboards, application programming interfaces (APIs), and connected-device services (together, the "Platform"), how we use, share, and protect it, and the rights and choices you have.
It applies to everyone who interacts with the Platform: account holders, members of their teams and organisations, fleet operators and drivers, insurance partners, developers, and visitors to our site.
Where we process device or customer data on behalf of a customer, that customer decides why and how it is used (they are the "controller" or "data fiduciary") and we act as their service provider (their "processor") under their instructions and agreement. This policy describes our own practices where we act as a controller. If you are an end user of a customer's deployment, please also review that customer's own privacy notice.
2. Key terms
To keep this policy clear, a few terms are used throughout:
- "Personal data" means information that identifies, relates to, or could reasonably be linked to an identifiable person.
- "Platform" means our websites, dashboards, APIs, and connected-device and related services.
- "Device" means any hardware you connect to the Platform.
- "Content" means the data, code, configurations, and other materials you submit to or create on the Platform.
- "Process" means any operation performed on personal data, such as collecting, storing, using, sharing, or deleting it.
3. Information you provide to us
When you create an account or use the Platform, you give us:
- Account and profile details - your name, email address, password (which we store only as a salted, irreversible hash), avatar image, timezone, and role.
- Sign-in details - if you sign in through a third-party identity provider, we receive your basic profile and a unique identifier from that provider. We never receive your third-party password.
- Billing and credit data - your prepaid credit balance, usage history, and transaction records. If you purchase credits, payment is handled by our payment provider; we do not receive or store your full card number.
- Team and organisation data - if you invite or are invited to a team, the membership, roles, and permissions that connect accounts.
- Insurance partner applications - if you apply as an insurer, your company name, registration and regulatory licence numbers, region, and contact details.
- Communications - the messages, support requests, and feedback you send us.
4. Device, telemetry, and usage data
As you operate connected devices through the Platform, we process the data those devices generate: sensor readings, status and health metrics (such as signal strength and uptime), configuration, firmware versions, and the timing of messages.
We process the code and projects you create in the in-browser development environment so we can compile them and deliver updates to your devices.
We record how you use the Platform - the features you use, the dashboards, automations, and templates you create, and the actions you take - to operate, secure, and improve the service.
5. Location and fleet data
If you use fleet, mapping, or vehicle-tracking features, we process precise location (GPS) data, trips, routes, speed, distance, and driving-behaviour signals, including crash and emergency events. Location data is sensitive, and we handle it with corresponding care.
Location data is tied to the device and its owner. We retain a device's last-known position so the Platform can show it while the device is offline. Mapping and routing requests you make are processed through specialist mapping and geolocation providers acting on our behalf.
6. Artificial-intelligence features
When you use AI features such as the assistant, anomaly detection, or forecasting, we process the content of your request and the relevant context - for example, the device or data you ask about - to generate a response, insight, or report. This processing is carried out through a third-party AI processing provider that acts under contract on our behalf.
Your inputs are sent only to produce your result. They are not used by that provider to train its own models.
AI conversations are stored so you can return to them, and are deleted after a fixed retention period (see "Data retention"). Generated report files are short-lived. Any AI-suggested action that controls a device requires your explicit approval and is logged.
7. Automations, webhooks, and integrations
The Platform lets you build automations that run on schedules or in response to device events and that can send notifications and emails, control devices, or call external endpoints (outbound webhooks) that you configure.
If you connect inbound webhooks or external services, we process the data exchanged through them to deliver the automation you set up. You are responsible for the endpoints and third-party services you connect and for the data you choose to send to or receive from them.
8. Teams and organisations
If you use the Platform as part of a team or organisation, an administrator may be able to invite or remove members, assign roles and permissions, and view activity within their workspace.
Data created within a team or organisation may be visible to other authorised members according to the roles set by the administrator. Where an organisation controls a workspace, it is the controller of the personal data within it, and its own privacy notice applies in addition to this one.
9. Communications and notifications
We send service communications you need to use the Platform - such as account verification, security alerts, billing and low-balance notices, device and automation alerts, and important policy updates. These are part of the service and are not marketing.
We deliver email through a transactional email provider acting on our behalf. We do not send you marketing messages without your consent, and where we ever do, you can opt out at any time. You can manage many notification preferences in your account settings.
10. Account activity and security data
To keep your account secure, we record activity such as sign-ins, active sessions, the approximate location and network address from which you connect, and the browser and operating system you use. You can review and revoke active sessions in your settings.
We also keep audit records of sensitive actions - such as changes to devices, automations, roles, and consents - so that activity can be traced and accounts protected.
11. Information we collect automatically
- Technical data - your network (IP) address, an approximate location derived from it, and your browser, device, and operating-system details.
- Cookies and local storage - used to keep you signed in and remember your preferences (see "Cookies and local storage").
- Logs and security data - records of requests, errors, and security events used to keep the Platform reliable and to detect and prevent abuse.
12. How we use your information
We use personal data to:
- Provide, operate, and maintain the Platform and its features.
- Authenticate you, manage sessions, and keep your account secure.
- Meter usage and manage your credit balance, billing, and records.
- Deliver device updates and run the automations and integrations you create.
- Provide the AI assistance, insights, and reports you request.
- Send service, security, billing, and account notifications.
- Provide support and respond to your requests.
- Monitor and improve performance, reliability, and safety, and develop new features.
- Prevent, detect, and investigate fraud, abuse, and security incidents.
- Comply with our legal and regulatory obligations and enforce our terms.
- Do anything else we describe to you at the time, with your consent.
13. Legal bases for processing
Where data-protection law applies to you - such as Tanzania's Personal Data Protection Act, 2022, the EU and UK GDPR, Kenya's Data Protection Act, Nigeria's Data Protection Act, South Africa's POPIA, India's Digital Personal Data Protection Act, the data-protection laws of the United Arab Emirates and Saudi Arabia, or US state privacy laws such as the CCPA - we rely on one or more of the following bases:
- Performance of our contract with you - to provide the Platform you have asked for.
- Your consent - for example, sharing your driving data with an insurer, or any optional communications. You may withdraw consent at any time.
- Our legitimate interests - to secure, maintain, improve, and protect the Platform, balanced against your rights and freedoms.
- Compliance with a legal obligation - where the law requires us to process or retain data.
- Protection of vital interests or the public interest - in the rare cases where processing is needed to protect someone's safety.
14. Automated processing and insights
Some features analyse your data automatically - for example, detecting anomalies, scoring driving behaviour, or forecasting trends. These are assistive: they surface information and suggestions to help you decide.
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing without a meaningful human involved or another lawful basis. Actions that control a device always require human approval.
15. Insurance and usage-based data sharing
The Platform lets a vehicle owner choose to share their driving data with a licensed insurance partner for usage-based insurance. This sharing happens only with your explicit, recorded consent, on a per-vehicle basis, and records the version of the consent terms you agreed to.
The insurer receives only the data needed to assess risk - such as trip history, behaviour scores, and verified incident evidence - for the vehicles you have consented to share, and nothing else.
You control this consent and can revoke it at any time, after which the insurer's access stops. MaxwellTrack is a data platform, not an insurer, and does not make underwriting, pricing, or claims decisions.
17. Aggregated and de-identified data
We may create aggregated or de-identified information that does not identify you - for example, overall usage statistics or performance benchmarks - and use it to operate, secure, analyse, and improve the Platform. We do not attempt to re-identify de-identified data, and we keep it de-identified.
18. International data transfers
The Platform operates across multiple regions - including parts of Africa, North America, Europe, Asia Pacific, and the Middle East - and may process and store data in a country other than your own, including through our service providers.
Whenever we transfer personal data across borders, we put in place the safeguards required by applicable law (such as approved contractual clauses, adequacy mechanisms, or your consent) to keep your data protected to the standard described in this policy.
19. Data retention
We keep personal data for as long as your account is active and as needed to provide the Platform. Specific cases include:
- AI conversations are retained for 90 days, then deleted.
- Device telemetry is retained according to your configuration and the history settings you choose.
- Billing, transaction, and audit records are kept for as long as required for accounting, tax, security, and legal purposes.
- Backups are kept for a limited period and then overwritten on a rolling basis.
When you delete your account, we delete or anonymise your personal data within a reasonable period, except where we must keep certain records to meet legal, accounting, security, or dispute-resolution obligations. Deletion may take time to propagate through backups.
20. Data security
We protect your data with encryption in transit, hashed credentials, scoped access tokens, role-based permissions, rate limiting, network and abuse controls, and audit logging, and we limit access to personal data on a need-to-know basis.
No system is perfectly secure, but we work continuously to safeguard your information and to detect, investigate, and respond to incidents. If a breach ever affects your personal data and the law requires it, we will notify you and the relevant authorities within the required timeframes. You are responsible for keeping your password and credentials secure.
21. Your rights and choices
Depending on where you live, you may have the right to:
- Access the personal data we hold about you and receive information about how we use it.
- Correct data that is inaccurate or incomplete.
- Delete your data ("right to be forgotten" / erasure).
- Export a copy of your data in a portable format.
- Object to, or ask us to restrict, certain processing.
- Withdraw consent you have given, without affecting processing already carried out.
- Opt out of any "sale" or "sharing" of personal data - although we do not sell or share it for advertising.
You can access, update, export, or delete much of your data directly in your account settings, or contact us to exercise any right. We will verify your request, respond within the time the law requires, and will not discriminate against you for exercising your rights. You may use an authorised agent where the law allows.
You also have the right to complain to your local data-protection or privacy authority - for example, the Personal Data Protection Commission in Tanzania, or the equivalent supervisory authority in your country - though we hope you will contact us first so we can help.
22. Region-specific rights
Some regions provide additional rights, which we honour where they apply to you:
- If you are in the European Economic Area or the United Kingdom, you have the rights described above under the GDPR, including the right to lodge a complaint with your supervisory authority.
- If you are in California, you have rights under the CCPA, including to know, delete, correct, and opt out of "sale" or "sharing" (we do neither for advertising), and the right to non-discrimination.
- If you are in Tanzania or another country with a data-protection law (such as Kenya, Nigeria, South Africa, India, the UAE, or Saudi Arabia), you have the rights granted by that law, and we apply the protection it requires.
23. Data about other people
If you provide us personal data about other people - for example, drivers, team members, or contacts - you confirm that you have the right to do so and have given them any notice and obtained any consent required by law. You are responsible for the data you bring to the Platform about others.
25. Children's privacy
The Platform is intended for adults and is not directed to children under 16 (or the minimum age of digital consent where you live, if higher). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
26. Third-party links and services
The Platform may link to, or interoperate with, third-party sites and services that we do not control. Their privacy practices are governed by their own policies, and we encourage you to review them. We are not responsible for the content or practices of third parties.
27. Changes to this policy
We may update this policy as the Platform evolves or the law changes. When we make material changes, we will revise the "Last updated" date above and, where appropriate, notify you. Your continued use of the Platform after changes take effect means you accept the updated policy.
28. Contact us
Questions, requests, or complaints about this policy or your personal data? Reach us through our contact page. We will do our best to resolve any concern, and we will help you exercise your rights under the privacy law that applies to you.

