Legal · Privacy

We barely know you. By design.

Sentinel runs in your infrastructure, so your data stays yours. This page covers the little that reaches us — completely.

P-01 The short version

Settlegate sells software that runs inside your infrastructure. The interesting data — vehicle telemetry, incidents, investigations, provenance — never reaches us. What does reach us is ordinary business data: who you are, how to bill you, and what you asked support. This page covers that, completely.

P-02 What we hold

Contact and account records for the people who deal with us (names, work emails, roles). Contract and invoice records for the companies they represent. Support threads sent to our addresses. License-activation events from deployed runtimes, which carry a deployment identifier and a timestamp — not payloads. First-party, cookie-less page counts from this website; no advertising trackers, no fingerprinting, no third-party pixels, and therefore no cookie banner.

P-03 What we do with it

Run the relationship: provision licenses, answer support, send incident and release notices, invoice, and keep the books the tax authorities require. Marketing mail goes only to people who asked for it and stops the moment they click unsubscribe. We buy no data about anyone, and nothing we hold is ever sold, rented, or traded.

P-04 Who else touches it

A short, boring list: our cloud host, our billing system, our email provider, and our support desk — each under contract to protect the data at least as well as we must. Beyond those, data leaves us only when a law with teeth compels it, and we tell you when that happens unless the order forbids us.

P-05 How long

Business contact records: while the relationship is live, then two years. Contracts and invoices: the retention statutes for financial records, typically seven years. Support threads: three years from the last message. License-activation logs: twenty-five months, then aggregated. When a period lapses, deletion is automatic, not aspirational.

P-06 Your say over it

Ask privacy@settlegate.xyz what we hold on you, and you will get an answer within a month — corrections, copies, and deletions included, except where a financial-records statute overrides a deletion, in which case we say so and name the statute. Colorado residents have these rights under the CPA, EU and UK readers under the GDPR; in practice we answer everyone the same way.

P-07 Where it lives

On infrastructure in the United States, encrypted on disk and on the wire, reachable by the small set of employees whose jobs require it, behind hardware-key MFA. If we ever suffer a breach that touches your data, you hear it from us promptly and with specifics — never from the press first, if we can possibly help it.

Effective June 19, 2026 · questions to privacy@settlegate.xyz