Last updated: August 17, 2026
Routerra plans and optimizes delivery routes. To do that, we handle data about you — and, because of what the product is, data about the people you deliver to. This policy explains exactly what we collect, why, who processes it, how long we keep it, and how to delete it. It covers the Routerra web app (app.routerra.io), the Routerra mobile apps (iOS and Android), and our website (routerra.io), together the "Services".
It also covers Routerra Teams — our dispatch product for companies, at teams.routerra.io, with its own driver app. Our role there is different: for most of what a company puts into Teams we act on that company's instructions as a processor, not as the controller. Section 15 sets out exactly which parts are which, and is the section to read if you administer a team, drive for one, or receive a delivery from one.
The data controller for the Services is Routerra Anatolii Trubin (sole proprietorship, Poland), ul. Na Zjeździe 11, lok. 5p, 30-527 Kraków, Poland, NIP 6793319069. Questions and requests: info@routerra.io.
The data controller for the Services described in sections 3 to 14 is:
In Routerra Teams we are the controller only for the five things listed in section 15. For the rest of what a company puts into Teams, that company is the controller and we are its processor — the same contact details below reach us, but the decisions are theirs.
We have not appointed a Data Protection Officer — the law does not require one for a business of our size and processing profile. Our supervisory authority is the President of the Personal Data Protection Office in Poland (Prezes Urzędu Ochrony Danych Osobowych, UODO) in Warsaw.
This policy covers the marketing site (routerra.io), the web app (app.routerra.io), the Routerra mobile apps for iOS and Android, and the backend services behind them. The backend runs on AWS in the us-east-1 region (USA).
It also covers Routerra Teams: the Teams dashboard at teams.routerra.io, the Routerra Teams driver app for iOS and Android, and the separate Teams backend behind them, which runs on AWS in the same us-east-1 region. Teams is a different product with its own vendors and its own division of responsibility, so it has a section of its own.
How to read this policy. Sections 3 to 14 describe the Services — the consumer product. Section 15 describes Routerra Teams and stands on its own: where it says something different from an earlier section, section 15 is the one that applies to Teams.
When you sign up we collect your email, first and last name, and — if you sign in with Google or Apple — the identity those services share with us. Authentication is handled by Clerk, and your account gets a Clerk ID. We keep account data until you delete your account.
The core of the product: addresses, coordinates, stop notes, time windows, and route names you enter or import, plus the names, addresses, and notes you save to your address book.
Be aware: the addresses you add are typically other people's data — your customers and recipients, not you. You are responsible for having the right to use those addresses in Routerra. We process them only on your instructions, to plan and run your routes, and they are deleted with your account. Address book entries you delete are soft-deleted first and purged for good after 90 days.
You can import stops from photos of address lists or package labels and from CSV/XLSX spreadsheets. These files may contain recipient names, addresses, and phone numbers. Uploaded files are automatically deleted from storage after 30 days. How we read them is described in section 5.
Route exports you generate (CSV, XLSX, PDF) are automatically deleted after 3 days — they exist only long enough for you to download them.
We record which features are used so we can improve the product: event type, timestamp, route ID, app version and platform, and your plan and subscription status. These events are pseudonymous — keyed by your account ID, not your email. We use PostHog for this. If you submit in-app feedback, the text you write is also recorded, keyed by your account ID.
Behavioural events in our own database are anonymized after 24 months, and immediately when you delete your account. On mobile, you can switch analytics off in Settings; in the web app, analytics only runs after you consent.
When the app crashes or errors, we receive a report with the stack trace, device and OS details, app version — and your account ID, email, and name. The email is included deliberately: it lets support reach out to you proactively when something breaks for you, instead of you having to notice and report it. We use Bugsnag on mobile and Sentry on web and server. Crash reports are kept for up to 90 days. Crash reporting stays on while you use the apps — it is how we keep the Services working.
In the web app, and only after you consent to analytics, Sentry records masked session replays — about 10% of sessions, and sessions where an error occurred. Text inputs are masked by default. Replays are kept per Sentry's retention (up to 90 days). No session replay runs on the marketing site or in the mobile apps.
The Teams dashboard is a separate case. It does not use Sentry. The analytics tools it does load include Hotjar, a behaviour-analytics tool whose features include session recording, and it loads them only with analytics consent, only in production, and never when your browser sends a Do Not Track signal. We name that here rather than let the paragraph above be read as “no recording anywhere except the web app”. Hotjar is listed in the Routerra Teams section of our Subprocessors page, and withdrawing analytics consent in the dashboard turns it off.
If you open live chat (Tawk.to), we process the conversation. When you are signed in to the app, the chat is linked to your verified email and name so support doesn't have to ask who you are. On our website the chat loads only when you open it; in the web app it loads only with your support-cookies consent.
Web purchases are sold by Lemon Squeezy as merchant of record: their checkout processes your payment, and we never receive your card number. Mobile purchases go through the App Store or Google Play, with RevenueCat managing subscription status. We keep provider subscription IDs, your plan, amounts, and the email on billing records. Billing records are retained for about 5 years after account deletion, as Polish accounting law requires.
With your OS permission, the mobile app uses your precise location — foreground only, on demand. It biases address search near you and shows where you are on the map. There is no background tracking, no continuous collection, and we do not store a history of where you have been.
If you add stops by voice, the audio is transcribed by your device's platform speech-to-text (Apple or Google). We use the transcript to add the stops; the audio is not stored by us, and the transcript is not kept unless you save the result.
Our servers keep request logs with your account ID (not your email) for debugging and security. Application log files rotate after about 14 days. Our hosting and CDN providers (Cloudflare, Netlify) log IP addresses at the infrastructure level as part of serving requests.
When the web app loads, it asks ipapi.co which country your IP address is in, so we can pre-set sensible defaults (distance units, locale). Your IP is processed transiently for the lookup and is not stored by us.
Under the GDPR, every use of personal data needs a legal basis. Here are ours:
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing the Services: your account, routes, optimization, imports/exports, maps and navigation, subscriptions | Contract — Art. 6(1)(b). This is the service you signed up for. |
| Product analytics (with opt-out on mobile), crash reporting, securing the Services, and proactive support outreach when something breaks for you | Legitimate interests — Art. 6(1)(f): running, improving, and protecting the Services. |
| Web-app analytics and support-chat cookies, and session replay in the web app | Consent — Art. 6(1)(a), given via the web app's consent banner and withdrawable at any time. |
| Keeping billing records | Legal obligation — Art. 6(1)(c), Polish accounting law. |
We do no automated decision-making that produces legal effects about you, and no profiling beyond the product analytics described above.
When you import stops from a photo or a spreadsheet, here is exactly what happens:
Data sent through the OpenAI API is not used to train OpenAI's models, per OpenAI's API terms. The uploaded files themselves are automatically deleted from storage after 30 days.
We share personal data only with service providers (processors) that run parts of the Services for us — hosting, authentication, maps, route optimization, payments, analytics, crash reporting, support chat, and email. Each one processes data under a data processing agreement and only on our instructions. The complete, current list — every vendor, where it is, and what data it touches — is on our Subprocessors page.
We do not sell personal data. We do not share it with advertisers or ad networks, and there are no advertising SDKs or pixels in our apps or on our site. We would disclose data to authorities only where the law requires it.
Our backend and primary storage are in the USA (AWS us-east-1), and several of our providers are US companies. For transfers of personal data out of the EEA, we rely on the EU–US Data Privacy Framework where the vendor holds a current certification, and/or the EU Standard Contractual Clauses included in each vendor's data processing agreement. Error monitoring is an exception to US processing: our Sentry ingest is pinned to Sentry's EU region.
| Data | Kept for |
|---|---|
| Account, routes, stops, address book | Until you delete your account (deletion cascades immediately). Deleted address book entries are purged after 90 days. |
| Uploaded import files | Auto-deleted after 30 days. |
| Route exports | Auto-deleted after 3 days. |
| Behavioural events (our database) | Anonymized after 24 months — and immediately when you delete your account. |
| Product analytics (PostHog) | 12 months. |
| Crash reports | Up to 90 days. |
| Session replays (web app) | Per Sentry's retention — up to 90 days. |
| Server application logs | Rotate after about 14 days. |
| Backups | Deleted data leaves backups within 60 days. |
| Billing records | About 5 years after account deletion (Polish accounting law). |
For the full mechanics of what happens when you delete your account, see the Deletion Policy.
Under the GDPR you have the right to:
The fastest way to erase everything is built into the product: both the web app and the mobile apps have Delete Account in Settings, and it works immediately. For anything else — access, correction, a data export, an objection — email info@routerra.io. We respond within 30 days. We may ask you to verify your identity first, so we don't hand your data to someone else.
If you believe we are processing your data unlawfully, you can lodge a complaint with our supervisory authority — the President of the Personal Data Protection Office (UODO), Warsaw, Poland — or with the data protection authority where you live or work.
We apply the same standards to everyone: the rights above are honored regardless of where you live.
Some US states give residents rights to access and delete their personal data and to opt out of its "sale" or "sharing" for cross-context advertising. We do not sell personal data and do not share it for cross-context behavioral advertising, so there is nothing to opt out of and no "Do Not Sell" link is required. Your access and deletion rights are honored the same way as everyone else's — in-app or by email, as above.
Routes and stops usually describe our users' customers — people who have no Routerra account. That data comes from the Routerra user who entered or imported it, and that user is responsible for having the right to use it. We process it only to plan and run that user's routes; we do not use it for anything else, and it is deleted with the user's account (imported files even sooner — within 30 days). If your address or details appear in a Routerra user's route and you want them removed, email info@routerra.io and we will handle it.
You can share a route via a link. Anyone who has the link can see the route it points to — the stops, addresses, and progress — without signing in. That is what makes sharing work, and it means you should treat route links as sensitive: share them only with people who should see the route.
Data moves between your device and our servers over TLS. Our managed storage (database, file storage) is encrypted at rest, application secrets are encrypted with AES-256-GCM, and access to production systems is restricted to those who need it. No system is perfectly secure — if a breach ever puts your rights at risk, we will notify the supervisory authority within 72 hours where required, and affected users without undue delay.
The Services are not directed to anyone under 18. If we learn we have collected personal data from a minor, we will delete it.
The short version: the marketing site runs nothing non-essential before you act (so it has no cookie banner), the web app and the Teams dashboard each ask for consent per category (essential / analytics / support), and the mobile apps use no cookies at all. The Cookie Policy names every cookie and storage key on the marketing site and in the web app — those are the surfaces it covers. For the Teams dashboard, the tools behind each consent category are named in section 15.
Routerra Teams is our product for companies that dispatch drivers: a dashboard at teams.routerra.io, a driver app, and a backend of its own. It is sold to a company, not to you personally, and that changes who decides what.
For everything a customer company and its people upload to, or generate in, Routerra Teams — recipient names, addresses, coordinates, delivery notes and time windows; the driver roster; team membership and invitations; proof-of-delivery photos; the team audit log; and, where live tracking is enabled, navigation trip and position data — the customer company is the controller and we are its processor. We process that data only on that company's documented instructions, under our Teams Data Processing Agreement. What happens to it is the company's decision, not ours, and this policy does not govern it.
We are an independent controller — and this policy applies — for five things, and only these five:
The dividing line runs where the data came from: an account a person creates for themselves is ours to answer for, while what a company invites, enters, imports or generates inside its team is that company's. A driver shows both sides of the line at once — the account they sign in with is ours, and the entry their employer created for them on the driver roster — name, email, vehicle, shift, depot — is their employer's, held by us as its processor.
Drivers: the company you drive for decides what goes into Routerra Teams about you and why. Read the Driver Privacy Notice, which is written for you. Requests to see, correct or delete the data your employer holds about you go to your employer. If you write to us instead, we will pass the request to them and tell you that we have done so and who we sent it to — we will not show you, change or delete their records ourselves, because we may not act on their data without them. Your right to complain to a data-protection authority does not depend on any of that.
Closing your Routerra account immediately revokes your access to the team and its routes. It does not delete your entry on your employer's driver roster: that entry is their record, and we do not delete a customer's records without their instruction. Ask your employer if you want it removed.
Delivery recipients: if your name, address, phone number or delivery note is in a Teams customer's route, the company delivering to you put it there and is responsible for it. Ask them. If you write to us at info@routerra.io, we will pass your request on to them the same way.
| Category | What it is | Whose data it is |
|---|---|---|
| Administrator and driver accounts | Email address, name, authentication identity, language, timezone, units, default navigator. | Ours (controller) |
| Team membership and invitations | Which team a person belongs to and in what role; the email address, role and token of an invitation until it is accepted or revoked. | The customer's (we process) |
| Driver roster | Name, email, colour, vehicle type and capacity, maximum stops, shift start and end, start and finish depot with address and coordinates, routing preferences. | The customer's (we process) |
| Stops and recipients | Name, address, coordinates, notes, time windows, service time, priority and load — usually data about the customer's own customers, who are third parties. | The customer's (we process) |
| Proof-of-delivery photos | Photos a driver takes at a stop, and the record of the upload. | The customer's (we process) |
| Address-book files | Files a customer attaches to an address-book entry. | The customer's (we process) |
| Team audit log | Who did what and when, with a record of what changed — which can include names and addresses. The customer can read it in the dashboard. | The customer's (we process) |
| Navigation trips and positions | Only where live tracking is enabled for a team: the team, driver, route and stop involved, the navigator used, trip status and timestamps, and the position, estimated arrival and remaining distance reported during the trip. | The customer's (we process) |
| Notification deliveries | Where a customer turns on recipient notifications: the recipient email address or phone number, the subject, the message as sent, the delivery status, the provider's message id and any error. | The customer's (we process) |
| Webhook deliveries | Where a customer configures a webhook: the payload we sent to their endpoint and the result. | The customer's (we process) |
| Offline-sync ledger | An identifier and a timestamp for each driver-app sync operation we have already applied, so that an edit made offline is not applied twice when the phone reconnects. The record holds nothing else — not the team, not the driver, not what the edit contained. | Neither — a technical de-duplication record, not personal data |
| Billing | One subscription per team: provider, status, plan, seat count, trial end, renewal date and the provider's reference. Checkout runs at Lemon Squeezy as merchant of record, and we never receive card numbers. | Ours (controller) |
| Teams product telemetry (from our servers) | Billing-lifecycle events keyed to the team — team name, plan, seat count, renewal and trial dates. No personal identifiers. | Ours (controller) |
| Teams dashboard analytics (from the browser) | The dashboard itself sends us, from an administrator's browser and only with analytics consent: pageviews, a named set of billing and onboarding-tour events with their plan and seat-count details, and automatic error reports carrying the stack trace when something breaks in the page. There is no blanket capture of clicks or form contents. These are keyed to an anonymous device identifier, not to a person: we never call the analytics tool's identify function, and it is configured not to build a profile for an unidentified visitor. An error report can still include personal data incidentally, in the same way an internal alert can. | Ours (controller) |
| Driver-app diagnostics and crash reports | Navigation diagnostic events, which are pseudonymous to the device, and crash reports with the stack trace and the device, OS and app version. We do not attach a driver's email address to either. | Ours (controller) |
| Server logs and internal alerts | Each request the dashboard or driver app makes, with the account identifier, the team, the role and a request identifier; when something fails, an alert to our own internal channel carrying the error and that context. The Teams alert currently also carries the signed-in person's email address; the change removing it ships in a backend release that is not yet deployed. | Ours (controller) |
The legal bases are the ones in section 4, applied to our own side of the split: contract for the account and the subscription, legitimate interests for telemetry, crash reporting, support and security, and legal obligation for billing records. For the data we hold as a processor, the customer company chooses the basis, not us.
Live driver tracking is an optional feature that a Teams customer may switch on for its team. It is off by default, and as at the date at the top of this page it is not running in production for anyone. We describe it here so that nobody meets it for the first time after it is turned on.
Where a customer does enable it, it works like this. The driver app does not stream position to us. A driver taps Navigate for a stop and is handed over to Google Maps or Waze through a Google service called Google Navigation Connect. While the driver is navigating to that stop — and only then — Google reports the driver's position and estimated arrival time, which their dispatchers can see and which we record on the customer's behalf. It does not run between stops, or after a shift.
The controls are Google's. Google shows the driver its own consent screen before this starts, shows an indicator in Google Maps while it is active, and lets the driver switch it off there. That is the switch that works, so we do not add a competing one of our own. Positions are kept for 90 days.
Separately from that feature, the driver app uses location only while it is open, to show the driver on the map and help them reach the next stop. There is no background tracking: the app does not follow a driver when it is closed, and it does not send a stream of position data to anyone.
| Data | Kept for |
|---|---|
| Navigation positions | 90 days. |
| Navigation trip records | 90 days. † |
| Team audit log | 24 months. † |
| Notification deliveries | 90 days. |
| Webhook deliveries | 30 days. |
| Offline-sync ledger | About 90 days. |
| Proof-of-delivery photos | 365 days. An upload that never completed is cleared after 24 hours. |
| Address-book files | No automatic expiry — kept until the customer deletes them or deletes the team. An upload that never completed is cleared after 24 hours. |
| Stops, address book, driver roster, team members | Until the customer deletes them or deletes the team. There is no automatic clean-up, because how long a company needs its own operational records is its decision, not ours. Invitations are kept until accepted or revoked. |
| Administrator and driver sign-in accounts | Until the person deletes their account. |
| Teams telemetry and driver-app diagnostics | 12 months. |
| Driver-app crash reports | Up to 90 days. |
| Billing records | About 5 years (Polish accounting law). |
† Enforcement release pending. These two periods are our commitment from the date at the top of this page. The scheduled job that enforces each of them automatically ships in a backend release published alongside our Teams documents and not yet deployed, so until it is live, records in these two areas may be older than the period stated. Ask us and we will delete anything older on request. We will remove this note when the release is live. The same note appears in Annex IV of the Data Processing Agreement and on our Security page.
A customer can delete a team at any time, which removes that team's data. What that removal covers, and what it does not cover immediately, is set out in section 11 of the Data Processing Agreement and in section 7 of our Security page, as is what happens at the end of a subscription; we will confirm a deletion in writing on request. This policy deliberately does not restate it, so that there is only one description to keep true.
Routerra Teams runs on a different set of vendors from the consumer product. Every one of them is named, with its region, purpose and the data it touches, in the Routerra Teams section of our Subprocessors page, which is also Annex III of the Data Processing Agreement and where changes are published in advance.
Twilio is not one of our subprocessors. Where a customer sends SMS notifications, they run on the customer's own Twilio account: the customer supplies the credentials, we store them encrypted and use them only to send on the customer's instruction. Twilio is that customer's processor under their own contract, not ours. We say so rather than let its absence from the list look like an oversight.
The Teams backend is hosted on AWS in the USA (us-east-1), so the transfers described in section 7 apply here too. Because we are established in Poland, a customer in the EEA sending us data is not itself making a restricted transfer; the transfer that needs a mechanism is ours onward to vendors outside the EEA, and it is covered by the Standard Contractual Clauses in section 13 of the Data Processing Agreement.
The Teams dashboard asks for consent by category — essential, analytics and support. Analytics covers PostHog, our product analytics and error tracking, and Hotjar, our behaviour-analytics tool. Both load only with that consent, only in production, and never when your browser sends a Do Not Track signal; support covers the Tawk.to chat in the dashboard. The driver app has no cookies and no analytics you need to consent to: its diagnostics are pseudonymous to the device, and crash reporting runs on our legitimate interest in keeping the app working. Advertising identifiers are actively blocked in the driver app, as they are in our consumer apps.
Data Processing Agreement (the agreement with the customer company), Security (the technical and organisational measures), Driver Privacy Notice (written for drivers), Teams Terms of Service, and the Routerra Teams section of the Subprocessors page.
When we change this policy, we post the new version here and update the date at the top. For material changes we will also notify you by email or in the app.
Related documents:
For Routerra Teams: