Thervise Thervise
Legal

Privacy Policy

Last updated: 17 June 2026  ·  Effective: 17 June 2026  ·  Applies to: thervise.com and all Thervise mobile apps

Summary in plain language: Thervise tracks GPS location data from devices you register. We store this data to show you maps, history, and alerts. We do not sell your data. You can request deletion at any time by contacting us.

1 Who We Are

Thervise ("we", "us", "our") is a vehicle and asset tracking platform operated by Thervise — Systems & Technology Infrastructure. Our registered contact address is: [email protected].

This Privacy Policy explains what personal data we collect when you use our website (thervise.com), our web application, or our mobile application, and how we use, store, and protect it.

2 Data We Collect

CategoryData pointsSource
Account data Username, display name, email address, hashed password, phone number (optional), avatar (optional) Provided by you at registration
GPS location data Latitude, longitude, speed, heading, altitude, timestamp — per GPS update from your registered device Your GPS tracker device (hardware)
Device data Device ID, ICCID (SIM card number), device name, plate number, subscription tier Provided at device registration / activation
Usage data Login timestamps, browser type (via User-Agent header), IP address (request logs, not stored to database) Automatically collected
Alert data Geofence alerts, stop events, motion events — tied to GPS events Auto-generated by the platform

We do not collect payment card numbers directly. Any subscription payments are processed by a PCI-compliant third-party provider.

3 How We Use Your Data

We do not use your GPS data for advertising. We do not sell or rent your data to third parties.

4 Legal Basis for Processing (GDPR)

If you are in the European Economic Area (EEA), we process your data under the following legal bases:

5 Data Storage & Retention

Your data is stored in a secured database server. GPS position history is retained for 90 days by default from the date of recording, after which it is automatically deleted by a scheduled purge job. Account data is retained for the lifetime of your account and is permanently deleted when you close your account.

Sensitive fields (username, email) are stored in encrypted form using AES-256-GCM encryption. Passwords are hashed using bcrypt with a minimum cost factor of 12.

6 Data Security

In the event of a security breach affecting your personal data, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33.

7 Cookies & Local Storage

We use the following browser storage:

NameTypePurposeDuration
app_gate httpOnly Cookie Authenticates access to the app bundle after login Session (8 hours)
wt_theme localStorage Stores your light/dark mode preference Persistent (no expiry)
wt_lang localStorage Stores your language preference (EN/FR/AR) Persistent (no expiry)
wt_consent localStorage Records that you accepted these terms and the privacy policy Persistent (1 year)

We do not use any third-party tracking cookies or advertising cookies.

8 Third-Party Services & Google API Disclosure

Gmail API Disclosure (required by Google API Services User Data Policy):
Thervise uses the Gmail API with the gmail.send scope exclusively to send transactional emails to registered Thervise users on behalf of the platform's own sender address. Specifically, the Gmail API is used only to send:
  • Email address verification codes when a new user registers
  • Password-reset codes when a user requests a password reset
  • Security notifications for account events
Thervise does not read, access, modify, index, or store any Gmail inbox messages or any other Google account data. Thervise does not send marketing or promotional emails. The Gmail API is used solely to send system-generated transactional messages; no Gmail or Google user data is ever collected, retained, or shared with third parties. Our use of Google APIs complies with the Google API Services User Data Policy , including the Limited Use requirements.

We do not share your GPS data or account data with any of these providers.

9 Your Rights

Depending on your location, you have the following rights regarding your personal data. You can exercise your right to access and your right to erasure directly from the app: go to Settings → Account and use Download my data or Delete my account. For all other requests, contact us at [email protected].

We will respond to all manual requests within 30 days. We may ask you to verify your identity before fulfilling a request.

10 Children's Privacy

Thervise is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

11 Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (to your registered address) and update the "Last updated" date at the top of this page. Continued use of the service after the effective date constitutes acceptance of the updated policy.

12 Contact Us

For any questions, requests, or concerns about this Privacy Policy or your personal data:

If you are in the EEA and believe we have not addressed your concern, you have the right to lodge a complaint with your local data protection authority.