Privacy Policy
stepwaves.com/privacy1. Introduction
StepWaves Inc. (“StepWaves,” “we,” “us,” or “our”) is committed to protecting the privacy and security of the personal information we collect from our customers, website visitors, and users of our products and services. This Privacy Policy describes how we collect, use, store, share, and protect your information when you:
- (a) Visit or use our website at stepwaves.com (the “Website”);
- (b) Use the Fleet Portal web dashboard or mobile application (collectively, the “Services”);
- (c) Purchase or subscribe to the StepWaves Neon product (the “Product”); or
- (d) Otherwise interact with StepWaves.
This Privacy Policy is incorporated by reference into our Terms of Service (stepwaves.com/terms) and our Neon Order Agreement (stepwaves.com/order-agreement). Together, these documents form the complete legal framework governing your relationship with StepWaves. By using our Website, Services, or Product, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy.
If you do not agree with the practices described in this Privacy Policy, please do not use our Website, Services, or Product.
2. Information We Collect
We collect information in several ways depending on how you interact with StepWaves. The categories below describe the types of information we may collect.
2.1 Information You Provide Directly
When you create an account, place an order, contact us, or otherwise interact with StepWaves, you may provide:
- (a) Contact Information: name, email address, phone number, mailing address, and shipping address;
- (b) Account Credentials: username and password;
- (c) Billing Information: payment card number, billing address, and other payment details (note: payment processing is handled through the Stripe payment platform; StepWaves does not store full payment card numbers on its servers);
- (d) Business Information: company or fleet name, DOT number, MC number, fleet size, and role or title;
- (e) Order Information: product selections, configuration choices, purchase mode, installation preferences, connectivity options, and add-ons;
- (f) Communication Content: messages, inquiries, support requests, and any other content you provide when communicating with us; and
- (g) Feedback: product reviews, survey responses, suggestions, and other feedback you voluntarily submit.
2.2 Information Collected Automatically Through the Website and Services
When you visit our Website or use the Fleet Portal and mobile application, we automatically collect:
- (a) Device Information: device type, operating system, browser type and version, screen resolution, and unique device identifiers;
- (b) Log Data: IP address, access times, pages viewed, referring URL, and actions taken on the Website;
- (c) Usage Data: features accessed, frequency and duration of use, interaction patterns, and preferences within the Fleet Portal and mobile application; and
- (d) Cookies and Similar Technologies: we use cookies, web beacons, pixel tags, and similar tracking technologies to collect information about your browsing activity. See Section 7 (Cookies & Tracking Technologies) for more details.
2.3 Information Collected Through the Neon Product
The Neon Product collects and transmits data to StepWaves through its embedded connectivity. This data includes:
- (a) Geographic Location Data: real-time and historical GPS coordinates of the device and APU;
- (b) APU Usage Data: runtime hours, operational cycles, start/stop events, heating and cooling mode activity, and duty cycle patterns;
- (c) Performance and Diagnostic Data: temperature readings, voltage levels, system health indicators, error codes, fault conditions, and operational parameters;
- (d) Fleet and Vehicle Data: vehicle identification data associated with the APU unit, operational patterns, and fleet-level aggregated metrics;
- (e) Connectivity Data: cellular network usage, signal strength, data transmission volumes, and connection status;
- (f) Device Configuration Data: software version, firmware version, hardware configuration, feature settings, and update history; and
- (g) Fuel Optimization Data: data generated by the Product’s self-teaching algorithms, including learned usage patterns, optimization decisions, and predicted performance metrics.
As described in Section 19 (Data Collection & Privacy) of the Neon Order Agreement, certain data collection is essential to the operation of the Product and its connected services. Disabling or interfering with data collection may impair Product functionality.
2.4 Information from Third-Party Sources
We may receive information about you from third-party sources, including:
- (a) Payment processors and financial institutions (transaction verification and payment processing);
- (b) Shipping and logistics providers (delivery status and confirmation);
- (c) Publicly available sources and databases (business verification); and
- (d) Analytics and advertising partners (aggregated usage trends).
3. How We Use Your Information
We process your personal information based on one or more of the following legal grounds, depending on the context: (a) performance of a contract with you (e.g., fulfilling orders, providing Services); (b) our legitimate business interests (e.g., product improvement, fraud prevention, security); (c) your consent, where applicable (e.g., marketing communications); and (d) compliance with legal obligations. For California residents, the categories of personal information we collect and the purposes for which they are used are described in Section 9.
We use the information we collect for the following purposes:
3.1 Service Delivery and Operations
- (a) To process and fulfill orders, including shipping, delivery, and installation coordination;
- (b) To manage your account and provide access to the Fleet Portal and mobile application;
- (c) To deliver Product functionality, including remote control, diagnostics, alerts, and fuel optimization;
- (d) To provide customer support and respond to inquiries;
- (e) To process payments and manage subscriptions;
- (f) To communicate with you about your account, orders, and services; and
- (g) To deliver over-the-air (OTA) software updates to the Product.
3.2 Product Improvement and Development
- (a) To analyze Product performance, usage patterns, and operational data to improve product design and functionality;
- (b) To train and improve the Product’s self-teaching algorithms and machine learning models;
- (c) To develop new features, products, and services;
- (d) To conduct internal research and analytics; and
- (e) To create aggregated, anonymized, or de-identified datasets for benchmarking and industry research.
3.3 Communication
- (a) To send transactional communications, including order confirmations, shipping notifications, billing reminders, and service alerts;
- (b) To send service-related announcements, including maintenance notices, product updates, safety notifications, and changes to our policies;
- (c) To send promotional communications and newsletters (from which you may opt out at any time); and
- (d) To respond to your comments, questions, and support requests.
3.4 Safety, Security, and Compliance
- (a) To detect, prevent, and address fraud, security breaches, and unauthorized access;
- (b) To enforce our Terms of Service, Order Agreement, and other policies;
- (c) To comply with applicable laws, regulations, legal processes, and government requests;
- (d) To protect the rights, property, and safety of StepWaves, our users, and the public; and
- (e) To verify identity and prevent misuse of our Services.
4. How We Share Your Information
StepWaves does not sell individually identifiable personal information to third parties without prior written consent. We may share your information in the following circumstances:
4.1 Service Providers
We share information with third-party service providers who perform services on our behalf, including:
- (a) Payment processing and fraud prevention;
- (b) Cloud hosting and data storage;
- (c) Shipping and logistics;
- (d) Customer support platforms;
- (e) Email and communication services;
- (f) Analytics and performance monitoring; and
- (g) Cellular connectivity providers for Product data transmission.
These service providers are contractually obligated to use your information only for the purposes of providing services to StepWaves and are required to maintain appropriate security measures.
4.2 Payment Processor
All payments for StepWaves products and services are processed through the Stripe payment platform. In connection with payment processing, Stripe receives and processes billing information, including payment card details, billing address, transaction amounts, and related transaction data. Stripe uses this information solely for the purpose of processing payments on behalf of StepWaves. Stripe’s handling of your data is governed by Stripe’s own privacy policy, available at stripe.com/privacy. Charges on your credit card, debit card, or bank statement will appear under the name “STEPWAVES” or a similar descriptor. StepWaves may change its payment processing arrangements, payment processor, or merchant account at any time. If a change requires you to update your stored payment information, StepWaves will notify you by email with instructions. This Privacy Policy will be updated accordingly to reflect any such change.
4.3 Fleet Account Sharing
If you use the Services as part of a fleet account, certain information (including device location, APU status, operational data, and usage history) may be visible to the fleet account administrator and other authorized users within the same fleet organization. Fleet administrators are responsible for managing access permissions within their organization.
4.4 Aggregated and De-Identified Data
We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify you for purposes including:
- (a) Industry research and benchmarking;
- (b) Product development and improvement;
- (c) Academic and scientific research; and
- (d) Marketing and promotional activities (in aggregate form only).
4.5 Legal Obligations and Protection
We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or if we believe in good faith that disclosure is necessary to:
- (a) Comply with a legal obligation, subpoena, court order, or regulatory inquiry;
- (b) Protect and defend the rights, property, or safety of StepWaves, our users, or the public;
- (c) Detect, prevent, or address fraud, security issues, or technical problems; or
- (d) Enforce our Terms of Service, Order Agreement, or other policies.
4.6 Business Transfers
In the event of a merger, acquisition, bankruptcy, reorganization, or sale of all or a portion of StepWaves’ assets, your information may be transferred as part of that transaction. We will notify you via email or prominent notice on the Website of any change in ownership or use of your personal information, as well as any choices you may have regarding your information.
4.7 With Your Consent
We may share your information with third parties when you have given us your explicit consent to do so.
5. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes for which it was collected, as described in this Privacy Policy, unless a longer retention period is required or permitted by law.
Specific retention periods include:
- (a) Account Information: retained for the duration of your active account and for a period of three (3) years following account closure or termination, to comply with legal obligations, resolve disputes, and enforce agreements;
- (b) Order and Transaction Records: retained for a minimum of seven (7) years from the date of the transaction to comply with tax, accounting, and regulatory requirements;
- (c) Product Telemetry and Usage Data: retained for as long as the Product is active and for a period of two (2) years following Product deactivation or subscription cancellation;
- (d) Website and Services Usage Logs: retained for up to two (2) years from the date of collection;
- (e) Communication Records: retained for three (3) years from the date of the last communication; and
- (f) Aggregated and De-Identified Data: may be retained indefinitely, as it cannot reasonably be used to identify you.
When personal information is no longer necessary for the purposes described above, we will securely delete or anonymize it in accordance with our data retention and disposal procedures.
6. Data Security
StepWaves implements reasonable administrative, technical, and physical security measures designed to protect your personal information from unauthorized access, use, alteration, disclosure, and destruction. These measures include, but are not limited to:
- (a) Encryption of data in transit using TLS/SSL protocols;
- (b) Encryption of sensitive data at rest;
- (c) Access controls and authentication mechanisms for systems containing personal information;
- (d) Regular security assessments, vulnerability testing, and monitoring;
- (e) Employee training on data protection and security practices; and
- (f) Incident response procedures for addressing security breaches.
While we strive to protect your personal information, no method of electronic transmission or storage is completely secure. We cannot guarantee the absolute security of your information. You are responsible for maintaining the security of your account credentials and for promptly notifying StepWaves of any suspected unauthorized access to your account.
7. Cookies & Tracking Technologies
7.1 Types of Cookies We Use
- (a) Essential Cookies: required for the operation of the Website and Services, including authentication, security, and session management. These cookies cannot be disabled without impairing core functionality.
- (b) Performance and Analytics Cookies: collect information about how you use the Website, including pages visited, time spent, and errors encountered. This data helps us improve the Website and Services. We may use third-party analytics tools such as Google Analytics for this purpose.
- (c) Functional Cookies: remember your preferences and settings to provide a personalized experience, including language preferences, display settings, and previously viewed content.
- (d) Advertising and Marketing Cookies: may be used to deliver relevant advertisements, measure advertising effectiveness, and track referral sources. These cookies may be placed by third-party advertising partners.
7.2 Managing Cookies
You can manage your cookie preferences through your browser settings. Most browsers allow you to block or delete cookies. However, disabling essential cookies may prevent you from using certain features of the Website and Services.
For more information about managing cookies, visit your browser’s help documentation or allaboutcookies.org.
If StepWaves deploys a cookie consent or preference mechanism on the Website, you may also manage your cookie preferences through that mechanism. StepWaves will honor your selections in accordance with applicable law.
7.3 Do Not Track
Some browsers offer a “Do Not Track” (DNT) signal. StepWaves does not currently respond to DNT signals, as there is no industry-wide standard for how websites should respond to such signals. However, StepWaves honors Global Privacy Control (GPC) signals where required by applicable law.
8. Your Rights and Choices
Depending on your jurisdiction, you may have certain rights regarding your personal information.
8.1 Access and Portability
You may request a copy of the personal information we hold about you. Where technically feasible, we will provide this information in a structured, commonly used, machine-readable format.
8.2 Correction
You may request that we correct any inaccurate or incomplete personal information we hold about you. You may also update certain information directly through your account settings.
8.3 Deletion
You may request that we delete your personal information. Please note that we may retain certain information as required by law, to complete transactions, to resolve disputes, or to enforce our agreements. Deletion of account information will result in the termination of your account and loss of access to the Services.
8.4 Opt-Out of Marketing Communications
You may opt out of receiving promotional emails from StepWaves at any time by clicking the “unsubscribe” link in any promotional email or by contacting us. Please note that opting out of marketing communications does not affect transactional or service-related communications.
8.5 Data Collection from the Product
Certain data collection through the Neon Product is essential to the delivery of core Product functionality and cannot be selectively disabled. If you wish to cease all data collection from the Product, you must deactivate the Product or terminate your subscription in accordance with the Neon Order Agreement.
8.6 Exercising Your Rights
To exercise any of the rights described above, please contact us at the contact information provided in Section 15 of this Privacy Policy. We will respond to your request within thirty (30) days. We may require you to verify your identity before processing your request.
StepWaves will not discriminate against you for exercising your privacy rights. We will not deny you services, charge different prices, or provide a different quality of service because you exercised a right under applicable privacy law.
9. California Privacy Rights
If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA).
9.1 Right to Know
You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which the information was collected, the business or commercial purposes for collection, and the categories of third parties with whom we share the information.
9.2 Right to Delete
You have the right to request deletion of personal information we have collected from you, subject to certain exceptions.
9.3 Right to Correct
You have the right to request that we correct inaccurate personal information we maintain about you.
9.4 Right to Opt Out of Sale or Sharing
StepWaves does not sell personal information as defined by the CCPA. StepWaves does not share personal information for cross-context behavioral advertising purposes.
9.5 Right to Limit Use of Sensitive Personal Information
To the extent we collect sensitive personal information as defined by the CCPA (such as precise geolocation data), you have the right to limit the use and disclosure of such information to purposes necessary to provide the Services. Because precise geolocation data collected through the Neon Product is used solely for core Product functionality (including fleet tracking, diagnostics, and fuel optimization), limiting the use of this data requires deactivation of the Product or termination of your subscription in accordance with the Neon Order Agreement, as described in Section 8.5 above. To exercise this right or to request information about how your sensitive personal information is used, please contact us at help@stepwaves.com.
9.6 Non-Discrimination
We will not discriminate against you for exercising your CCPA rights.
9.7 How to Submit a Request
California residents may submit requests by contacting us at the contact information in Section 15 or by emailing help@stepwaves.com. We will verify your identity before processing your request. You may also designate an authorized agent to submit a request on your behalf. If you use an authorized agent, the agent must provide either (a) a valid power of attorney pursuant to California Probate Code sections 4000–4465, or (b) your signed written authorization. In either case, StepWaves may independently verify your identity directly before processing the request.
9.8 Categories of Information Collected and Disclosed
In the preceding twelve (12) months, StepWaves has collected and may have disclosed the following categories of personal information for business purposes:
- (a) Identifiers (name, email, phone, IP address, device identifiers);
- (b) Customer records (billing address, payment information, order history);
- (c) Commercial information (purchase and subscription history, product preferences);
- (d) Internet or electronic network activity (browsing history, interaction with Website and Services);
- (e) Geolocation data (GPS location from Neon Product, approximate location from IP address);
- (f) Professional or employment-related information (company name, fleet information, DOT number);
- (g) Inferences drawn from the above (usage patterns, preferences, operational profiles); and
- (h) Sensitive personal information (precise geolocation data).
StepWaves has not sold personal information in the preceding twelve (12) months. StepWaves has not shared personal information for cross-context behavioral advertising purposes.
10. Children’s Privacy
The Website, Services, and Product are not intended for use by children under the age of eighteen (18). StepWaves does not knowingly collect personal information from children under eighteen (18). If we become aware that we have collected personal information from a child under eighteen (18), we will take steps to delete such information promptly.
If you believe that a child under eighteen (18) has provided personal information to StepWaves, please contact us at the contact information provided in Section 15.
11. International Data Transfers
StepWaves is based in Ohio, United States. If you access the Website, Services, or Product from outside the United States, your information may be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country of residence.
By using the Website, Services, or Product, you consent to the transfer of your information to the United States and the processing of your information in accordance with this Privacy Policy. StepWaves will take reasonable steps to ensure that your information is treated securely and in accordance with this Privacy Policy regardless of where it is stored or processed.
12. Third-Party Services and Links
The Website and Services may contain links to third-party websites, applications, or services. This Privacy Policy does not apply to any third-party websites, applications, or services, even if they are accessible through the Services.
We encourage you to review the privacy policies of any third-party services you access through the Website or Services. StepWaves is not responsible for the privacy practices or content of third-party services.
13. Data Breach Notification
In the event of a security breach that results in the unauthorized access, acquisition, or disclosure of personal information, StepWaves will:
- (a) Investigate and take steps to contain and remediate the breach;
- (b) Notify affected individuals as required by applicable law, which may include notification by email, postal mail, or prominent notice on the Website;
- (c) Notify applicable regulatory authorities as required by applicable law; and
- (d) Provide information about the nature of the breach, the types of information involved, and steps individuals can take to protect themselves.
Notification timelines will comply with applicable federal and state data breach notification laws, including but not limited to Ohio Revised Code Section 1349.19.
14. Changes to This Privacy Policy
StepWaves reserves the right to modify this Privacy Policy at any time. If we make material changes, we will notify you by posting the revised Privacy Policy on the Website with an updated effective date and, where appropriate, by sending notice to the email address associated with your account.
Your continued use of the Website, Services, or Product after the effective date of any changes constitutes your acceptance of the revised Privacy Policy. If you do not agree with the revised Privacy Policy, you should discontinue use of the Website, Services, and Product.
We encourage you to review this Privacy Policy periodically. The “Effective Date” at the top of this Privacy Policy indicates when it was last updated.
15. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
StepWaves Inc.
3540 Burbank Rd
STE 142
Wooster, OH 44691
Phone: 1-888-968-0505
Email: help@stepwaves.com
For product-specific inquiries, warranty claims, or order-related questions, please refer to the Neon Order Agreement at stepwaves.com/order-agreement.
For questions about the general terms governing your use of our Website and Services, please refer to our Terms of Service at stepwaves.com/terms.
16. Additional Provisions
Relationship to Other Agreements
This Privacy Policy is incorporated by reference into the StepWaves Terms of Service (stepwaves.com/terms) and the Neon Order Agreement (stepwaves.com/order-agreement). In the event of any conflict between this Privacy Policy and those agreements regarding the handling of personal information, this Privacy Policy shall control.
Governing Law
This Privacy Policy shall be governed by and construed in accordance with the laws of the State of Ohio, without regard to its conflict-of-law provisions.
Severability
If any provision of this Privacy Policy is found to be invalid or unenforceable, the remaining provisions shall continue in full force and effect.