Skip to content

Legal

Privacy Policy

Last updated 2 September 2026.

Who this policy covers

This policy covers two things: this website, fuelone.pk, and the FuelOne platform that Oil Marketing Companies (OMCs) license from Fintectual Pvt Ltd, Rawalpindi ("we", "us").

Roles

When an OMC runs its fuel card programme on FuelOne, the OMC is the controller of the personal data in its tenant: its staff, its business customers, their employees, and its individual cardholders. We are the processor. We act on the OMC's instructions under the agreement between us, and this policy describes the processing we perform on the OMC's behalf. Questions about a specific OMC's programme go to that OMC first.

For this website and for demo requests, we are the controller.

This website

This website sets no cookies. It uses Cloudflare Web Analytics, which records page views without cookies and without identifying visitors. Fonts are served from this site's own host; no request goes to a font provider. The site loads no other third-party script.

If you request a demo, the form sends your name, company, role, work email, phone number, the number of stations and fleet size you enter, and your message to our platform's API, which stores them and emails them to contact@fuelone.pk. We use them to reply to you and for nothing else. Demo requests are kept indefinitely. To see what we hold about you, or to have it deleted, email contact@fuelone.pk with "Privacy Policy" in the subject line. Deletion takes effect within 90 days of the request.

What the platform stores

Within an OMC's tenant the platform stores, on the OMC's instruction:

  • Accounts. Name, email, phone, password (hashed), two-factor secret (encrypted), passkeys, trusted devices, notification preferences, and sessions with IP address and browser.
  • Cardholder identity. For individual cardholders, the KYC profile the OMC collects: name, CNIC (encrypted at rest, with a one-way hash for uniqueness), date of birth, gender, marital status, mobile number, residential address, and where supplied, NICOP or passport number and mother's maiden name. For fleet cards, the name on the card, the driver, and a contact person.
  • Cards and transactions. Card numbers, card status, PIN (hashed), limits, and every swipe: station, fuel type, litres, rate, amount, time, and outcome, including declines and the reason for each. No location is captured at the swipe beyond the station's own address.
  • Business customers. Legal and trading names, NTN, GST number, entity type, addresses, and contact details, including those submitted through the public sign-up form.
  • Payments. Payments recorded against invoices, with bank reference, cheque number and date, the OMC's receiving account, and proof attachments (bank slips, cheque images), which are kept permanently as evidence.
  • Stations and supply chain. Station addresses and coordinates, tank readings, daily stock, and where the supply chain module is on, depots, trucks, and drivers, including a driver's name, CNIC, licence number, contact number, and photo, which print on delivery notes.
  • Support chat. Where the support chat module is on, the documents the OMC uploads to its knowledge base and the full text of conversations.
  • Audit trail. Every create, update, and delete on audited records, with the actor, their IP address and browser, and the values before and after.

The cardholder Android app stores the sign-in token, name, and email in encrypted storage on the device and no other data. When the app shows nearby stations it sends the device's location to the platform for sorting; the platform does not store it.

Who receives data from the platform

The platform sends data to the following third parties. The OMC can switch off the ones marked as a module; the rest are part of how the platform works.

RecipientWhatWhyOMC control
OpenAIUploaded knowledge base documents and the text of support chat messages, with station names and addressesTo answer support chat from the OMC's documentsSupport chat module, off by default
Google (Geocoding, Places, Maps)Street addresses entered for stations, depots, offices, and customers; browser IP on pages with a mapTo place addresses on a mapNone
Firebase Cloud MessagingNotification titles and bodies, with the card's last four digits, and device tokensPush notifications to the cardholder appPer-user notification preferences
MapboxBrowser IP and map viewport on pages with a vehicle mapMap tiles and route displaySupply chain module
ip-api.comThe IP address of a signed-in user's sessionsTo show city and country on the user's own security pageNone
Bunny FontsBrowser IP and user agentWeb fonts on the platform's pagesNone
ResendTransactional email, including invoices, receipts, sign-in links, and alertsSending emailNone
Endpoints the OMC configuresWebhook payloads for the events the OMC subscribes to, including card and transaction recordsIntegration with the OMC's own systemsPer webhook
DigitalOceanEverything above, at restHostingNone

Retention

Records are retained for the life of the OMC's tenant. Payment proof attachments are retained permanently as evidence of the payments they support. There are no shorter periods for particular kinds of record. A request about a particular record follows the process in the next section.

Access, correction, and erasure

Cardholders can see their own cards, transactions, and limits, and can download their own receipts and statements from the web portal and the app. Staff of the OMC can correct account and profile details through the platform. A signed-in user can file an account closure request from their settings. Closure requests are reviewed by a person.

To ask for a copy of the data held about you, or for its deletion, email contact@fuelone.pk with "Privacy Policy" in the subject line.

If your account belongs to an OMC's programme, as a cardholder, as a business customer or its employee, or as the OMC's own staff, the OMC is the controller of that data and we pass your request to the OMC, which decides it. Deleting a cardholder's or a customer's data means surrendering their fuel cards and their access to the platform, and because money is owed and settled through those records, that decision is the OMC's to make.

Where deletion is agreed, the data is deleted within 90 days of the request. Transactions, ledger entries, invoices, payments and their proof, and the audit trail are immutable records. They survive deletion and account closure, because the OMC's and its customers' audit obligations depend on them.

Security measures

Passwords, PINs, and API tokens are stored hashed. CNIC, date of birth, and the other sensitive KYC fields on a cardholder profile are encrypted at rest. Two-factor secrets and single sign-on client secrets are encrypted. Two-factor authentication, passkeys, and 30-day trusted devices are available to every user. Payment attachments and knowledge base documents are stored on private storage and served only through permission checks. Webhook payloads are signed with HMAC-SHA256. Each OMC's tenant is served from its own subdomain with host-only sessions, so a session from one tenant cannot be presented to another.

Children

The platform is for OMCs, their business customers, and adult cardholders. It is not directed at children and the OMC is responsible for the age of the cardholders it registers.

Changes

The date at the top is the date of the current version.

Contact

Fintectual Pvt Ltd, Rawalpindi, Pakistan. Privacy questions: contact@fuelone.pk.