Legal
Privacy Policy
Last updated 2 September 2026.
Who this policy covers
This policy covers two things: this website, fuelone.pk, and the FuelOne platform that Oil Marketing Companies (OMCs) license from Fintectual Pvt Ltd, Rawalpindi ("we", "us").
Roles
When an OMC runs its fuel card programme on FuelOne, the OMC is the controller of the personal data in its tenant: its staff, its business customers, their employees, and its individual cardholders. We are the processor. We act on the OMC's instructions under the agreement between us, and this policy describes the processing we perform on the OMC's behalf. Questions about a specific OMC's programme go to that OMC first.
For this website and for demo requests, we are the controller.
This website
This website sets no cookies. It uses Cloudflare Web Analytics, which records page views without cookies and without identifying visitors. Fonts are served from this site's own host; no request goes to a font provider. The site loads no other third-party script.
If you request a demo, the form sends your name, company, role, work email, phone number, the number of stations and fleet size you enter, and your message to our platform's API, which stores them and emails them to contact@fuelone.pk. We use them to reply to you and for nothing else. Demo requests are kept indefinitely. To see what we hold about you, or to have it deleted, email contact@fuelone.pk with "Privacy Policy" in the subject line. Deletion takes effect within 90 days of the request.
What the platform stores
Within an OMC's tenant the platform stores, on the OMC's instruction:
- Accounts. Name, email, phone, password (hashed), two-factor secret (encrypted), passkeys, trusted devices, notification preferences, and sessions with IP address and browser.
- Cardholder identity. For individual cardholders, the KYC profile the OMC collects: name, CNIC (encrypted at rest, with a one-way hash for uniqueness), date of birth, gender, marital status, mobile number, residential address, and where supplied, NICOP or passport number and mother's maiden name. For fleet cards, the name on the card, the driver, and a contact person.
- Cards and transactions. Card numbers, card status, PIN (hashed), limits, and every swipe: station, fuel type, litres, rate, amount, time, and outcome, including declines and the reason for each. No location is captured at the swipe beyond the station's own address.
- Business customers. Legal and trading names, NTN, GST number, entity type, addresses, and contact details, including those submitted through the public sign-up form.
- Payments. Payments recorded against invoices, with bank reference, cheque number and date, the OMC's receiving account, and proof attachments (bank slips, cheque images), which are kept permanently as evidence.
- Stations and supply chain. Station addresses and coordinates, tank readings, daily stock, and where the supply chain module is on, depots, trucks, and drivers, including a driver's name, CNIC, licence number, contact number, and photo, which print on delivery notes.
- Support chat. Where the support chat module is on, the documents the OMC uploads to its knowledge base and the full text of conversations.
- Audit trail. Every create, update, and delete on audited records, with the actor, their IP address and browser, and the values before and after.
The cardholder Android app stores the sign-in token, name, and email in encrypted storage on the device and no other data. When the app shows nearby stations it sends the device's location to the platform for sorting; the platform does not store it.
Who receives data from the platform
The platform sends data to the following third parties. The OMC can switch off the ones marked as a module; the rest are part of how the platform works.
| Recipient | What | Why | OMC control |
|---|---|---|---|
| OpenAI | Uploaded knowledge base documents and the text of support chat messages, with station names and addresses | To answer support chat from the OMC's documents | Support chat module, off by default |
| Google (Geocoding, Places, Maps) | Street addresses entered for stations, depots, offices, and customers; browser IP on pages with a map | To place addresses on a map | None |
| Firebase Cloud Messaging | Notification titles and bodies, with the card's last four digits, and device tokens | Push notifications to the cardholder app | Per-user notification preferences |
| Mapbox | Browser IP and map viewport on pages with a vehicle map | Map tiles and route display | Supply chain module |
| ip-api.com | The IP address of a signed-in user's sessions | To show city and country on the user's own security page | None |
| Bunny Fonts | Browser IP and user agent | Web fonts on the platform's pages | None |
| Resend | Transactional email, including invoices, receipts, sign-in links, and alerts | Sending email | None |
| Endpoints the OMC configures | Webhook payloads for the events the OMC subscribes to, including card and transaction records | Integration with the OMC's own systems | Per webhook |
| DigitalOcean | Everything above, at rest | Hosting | None |
Retention
Records are retained for the life of the OMC's tenant. Payment proof attachments are retained permanently as evidence of the payments they support. There are no shorter periods for particular kinds of record. A request about a particular record follows the process in the next section.
Access, correction, and erasure
Cardholders can see their own cards, transactions, and limits, and can download their own receipts and statements from the web portal and the app. Staff of the OMC can correct account and profile details through the platform. A signed-in user can file an account closure request from their settings. Closure requests are reviewed by a person.
To ask for a copy of the data held about you, or for its deletion, email contact@fuelone.pk with "Privacy Policy" in the subject line.
If your account belongs to an OMC's programme, as a cardholder, as a business customer or its employee, or as the OMC's own staff, the OMC is the controller of that data and we pass your request to the OMC, which decides it. Deleting a cardholder's or a customer's data means surrendering their fuel cards and their access to the platform, and because money is owed and settled through those records, that decision is the OMC's to make.
Where deletion is agreed, the data is deleted within 90 days of the request. Transactions, ledger entries, invoices, payments and their proof, and the audit trail are immutable records. They survive deletion and account closure, because the OMC's and its customers' audit obligations depend on them.
Security measures
Passwords, PINs, and API tokens are stored hashed. CNIC, date of birth, and the other sensitive KYC fields on a cardholder profile are encrypted at rest. Two-factor secrets and single sign-on client secrets are encrypted. Two-factor authentication, passkeys, and 30-day trusted devices are available to every user. Payment attachments and knowledge base documents are stored on private storage and served only through permission checks. Webhook payloads are signed with HMAC-SHA256. Each OMC's tenant is served from its own subdomain with host-only sessions, so a session from one tenant cannot be presented to another.
Children
The platform is for OMCs, their business customers, and adult cardholders. It is not directed at children and the OMC is responsible for the age of the cardholders it registers.
Changes
The date at the top is the date of the current version.
Contact
Fintectual Pvt Ltd, Rawalpindi, Pakistan. Privacy questions: contact@fuelone.pk.