Skip to content

Security & compliance

Where your fleet data lives

Fleet data is hosted in India. This page sets out what is collected, who can reach it, how long it is kept and what we deliberately do not claim.

Principles

How this works in practice

Hosted in India

Fleet data is hosted in India. For public-sector and defence procurement this is usually a threshold condition rather than a preference.

Access is scoped

Role-based access means a branch sees its own vehicles and a central function sees everything, without separate systems per department.

Personal data is minimised

A number-plate lookup returns the vehicle, not the owner. Owner details are masked at source and no API unlocks them.

Retention is a decision

How long footage and trip history are kept should be set deliberately, long enough to evidence a claim and no longer.

Records are exportable

Trip history, alerts and delivery records can be exported, so evidence remains available independently of the platform.

Drivers are told

Cabin video and consent-based location involve a person. Both work better when the person knows, and one of them legally requires it.

In detail

Security, privacy and residency

Written to be checkable rather than reassuring.

Where the data lives, and why it is the first question

For most commercial buyers data residency is a preference. For government departments, defence logistics and several enterprise procurement processes it is a threshold condition, and a platform storing fleet movement outside India is excluded before its capabilities are assessed.

MoboSafe hosts fleet data in India. That is stated plainly because it is usually the first thing asked and the point at which most public-sector evaluations end.

The related question, and the one asked second, is who inside the organisation can see it. That is an access-control design rather than a hosting one, and it is covered below.

What is actually collected

Being specific here is more useful than a general assurance, because the categories carry different obligations.

The last three are personal data under India’s data-protection regime. Treating them as ordinary fleet telemetry is the common mistake. See the DPDP Act.

  • Vehicle telemetry: position, speed, ignition, and where sensors exist, fuel level and temperature. This is data about an asset.
  • Driver-associated data: which driver was assigned to which vehicle and trip, licence verification results, and behaviour events. This is data about a person.
  • Video, where dashcams are fitted: road-facing footage and, with driver monitoring, cabin-facing footage of an identifiable person.
  • Consent-based location, where SIM tracking is used: approximate position of a phone, returned only after the SIM holder agrees.

Cabin video and the driver

A driver monitoring camera records a person at work for the length of their shift. That is the most sensitive data most fleets will ever hold, and the approach to it determines whether a rollout survives.

What works in practice: tell drivers the camera is there and what triggers a recording, be specific about who can view footage and for what purpose, and use footage to clear drivers of blame as readily as to attribute it.

What does not work: installing quietly, or describing a continuously recording camera as event-only. Both are discovered, and what follows is a dispute with the workforce you need.

Retention deserves a deliberate answer rather than a default. Long enough that a claim filed weeks later can still be evidenced; short enough that you are not holding cabin video of your staff indefinitely for no stated purpose. See AI dashcams.

Consent-based tracking is not a formality

SIM-based tracking locates a person’s phone, and it operates on their explicit agreement. A request goes to the number and nothing is returned until the driver agrees; consent can be withdrawn and tracking stops when it is.

Two things follow that are worth getting right rather than working around. Scope consent to the trip rather than leaving it open indefinitely, and describe accurately what is being tracked.

A consent obtained by telling someone it is a formality is a consent that gets withdrawn the first time it is noticed, which is worse operationally than not having asked. See SIM-based tracking.

What government lookups do and do not return

Verification against Vahan and Sarathi is a frequent source of confusion, and the limits are a privacy feature rather than a gap.

A registration number returns the vehicle: make and class, registering RTO, insurance and PUC validity, fitness expiry, hypothecation and challan history. Owner personal details are masked at source.

A licence check returns validity, authorised vehicle classes and issuing RTO. It does not return a background file, driving history or past accidents.

Any service claiming to return a name, phone number or address from a plate is either misrepresenting what it does or should not be doing it. That is worth treating as information about the vendor. See vehicle verification.

Access, export and leaving

Access is role-based, so visibility can be scoped to a branch, a department or a function rather than granted wholesale. On sensitive deployments, knowing where every vehicle is at all times is itself information that should not be broadly available.

Records are exportable. That matters more than it sounds: a detention claim or an insurance dispute months old depends on data from a platform you may no longer be paying for, and "we can provide an export on request" is a different answer from "you can export it yourself".

Ask that question of any vendor, including this one, before signing. A platform that cannot answer it plainly is telling you something.

What we do not claim

Procurement teams verify certifications, so this page lists none that have not been obtained. If a tender requires a specific certification or audit report, ask directly and the answer will be accurate rather than aspirational.

Regulatory obligations also sit with the operator, not the platform. Retention periods, consent practice and lawful basis for processing depend on your organisation and your sector, and are not something a fleet system determines on your behalf.

What is stated here — India hosting, masking behaviour, consent requirements, role-based access and export — is verifiable, and that is the intended standard for this page.

FAQ

Frequently asked questions

Where is MoboSafe fleet data hosted?

Fleet data is hosted in India. For government, defence and several enterprise procurement processes this is a threshold condition rather than a preference.

Does a number-plate lookup return owner personal details?

No. A registration lookup returns the vehicle — make and class, registering RTO, insurance and PUC validity, fitness expiry, hypothecation and challan history. Owner personal details are masked at source, and no API unlocks them.

Is cabin-facing dashcam footage personal data?

Yes. It records an identifiable person at work, which places it under India’s data-protection regime. Drivers should be told the camera is present, what triggers a recording, and who can view footage.

Can drivers refuse SIM-based tracking?

Yes. Consent is requested from the SIM holder and nothing is returned until they agree. Consent can be withdrawn at any time and tracking stops when it is.

Can we export our data if we leave?

Yes. Trip history, alerts and delivery records are exportable, which matters because a claim or dispute months old may depend on data from a platform you are no longer paying for.

Which security certifications does MoboSafe hold?

This page deliberately claims no certification that has not been obtained, because procurement teams verify them. If a tender requires a specific certification or audit report, ask directly and the answer will be accurate rather than aspirational.

Begin

Ready to connect your whole operation?

Explore tracking, trips, assets, fuel, inventory, accounting, and payroll with the MoboSafe team. Build a rollout around the workflows your fleet needs.