Routerra Logo

Privacy Policy

Last updated: August 17, 2026

Routerra plans and optimizes delivery routes. To do that, we handle data about you — and, because of what the product is, data about the people you deliver to. This policy explains exactly what we collect, why, who processes it, how long we keep it, and how to delete it. It covers the Routerra web app (app.routerra.io), the Routerra mobile apps (iOS and Android), and our website (routerra.io), together the "Services".

It also covers Routerra Teams — our dispatch product for companies, at teams.routerra.io, with its own driver app. Our role there is different: for most of what a company puts into Teams we act on that company's instructions as a processor, not as the controller. Section 15 sets out exactly which parts are which, and is the section to read if you administer a team, drive for one, or receive a delivery from one.

The data controller for the Services is Routerra Anatolii Trubin (sole proprietorship, Poland), ul. Na Zjeździe 11, lok. 5p, 30-527 Kraków, Poland, NIP 6793319069. Questions and requests: info@routerra.io.

Summary of key points

Table of contents

  1. Who we are
  2. What this policy covers
  3. What we collect
  4. Why we process it (purposes & legal bases)
  5. AI processing of your imports
  6. Who we share data with
  7. International transfers
  8. How long we keep data
  9. Your rights and how to use them
  10. Data about people who don't use Routerra
  11. Shared route links
  12. Security
  13. Children
  14. Cookies
  15. Routerra Teams
  16. Changes to this policy
  17. Contact & data controller

1. Who we are

The data controller for the Services described in sections 3 to 14 is:

In Routerra Teams we are the controller only for the five things listed in section 15. For the rest of what a company puts into Teams, that company is the controller and we are its processor — the same contact details below reach us, but the decisions are theirs.

We have not appointed a Data Protection Officer — the law does not require one for a business of our size and processing profile. Our supervisory authority is the President of the Personal Data Protection Office in Poland (Prezes Urzędu Ochrony Danych Osobowych, UODO) in Warsaw.

2. What this policy covers

This policy covers the marketing site (routerra.io), the web app (app.routerra.io), the Routerra mobile apps for iOS and Android, and the backend services behind them. The backend runs on AWS in the us-east-1 region (USA).

It also covers Routerra Teams: the Teams dashboard at teams.routerra.io, the Routerra Teams driver app for iOS and Android, and the separate Teams backend behind them, which runs on AWS in the same us-east-1 region. Teams is a different product with its own vendors and its own division of responsibility, so it has a section of its own.

How to read this policy. Sections 3 to 14 describe the Services — the consumer product. Section 15 describes Routerra Teams and stands on its own: where it says something different from an earlier section, section 15 is the one that applies to Teams.

3. What we collect

Your account

When you sign up we collect your email, first and last name, and — if you sign in with Google or Apple — the identity those services share with us. Authentication is handled by Clerk, and your account gets a Clerk ID. We keep account data until you delete your account.

Routes, stops, and your address book

The core of the product: addresses, coordinates, stop notes, time windows, and route names you enter or import, plus the names, addresses, and notes you save to your address book.

Be aware: the addresses you add are typically other people's data — your customers and recipients, not you. You are responsible for having the right to use those addresses in Routerra. We process them only on your instructions, to plan and run your routes, and they are deleted with your account. Address book entries you delete are soft-deleted first and purged for good after 90 days.

Files you import

You can import stops from photos of address lists or package labels and from CSV/XLSX spreadsheets. These files may contain recipient names, addresses, and phone numbers. Uploaded files are automatically deleted from storage after 30 days. How we read them is described in section 5.

Files you export

Route exports you generate (CSV, XLSX, PDF) are automatically deleted after 3 days — they exist only long enough for you to download them.

Product analytics

We record which features are used so we can improve the product: event type, timestamp, route ID, app version and platform, and your plan and subscription status. These events are pseudonymous — keyed by your account ID, not your email. We use PostHog for this. If you submit in-app feedback, the text you write is also recorded, keyed by your account ID.

Behavioural events in our own database are anonymized after 24 months, and immediately when you delete your account. On mobile, you can switch analytics off in Settings; in the web app, analytics only runs after you consent.

Crash reports

When the app crashes or errors, we receive a report with the stack trace, device and OS details, app version — and your account ID, email, and name. The email is included deliberately: it lets support reach out to you proactively when something breaks for you, instead of you having to notice and report it. We use Bugsnag on mobile and Sentry on web and server. Crash reports are kept for up to 90 days. Crash reporting stays on while you use the apps — it is how we keep the Services working.

Session replay and recording

In the web app, and only after you consent to analytics, Sentry records masked session replays — about 10% of sessions, and sessions where an error occurred. Text inputs are masked by default. Replays are kept per Sentry's retention (up to 90 days). No session replay runs on the marketing site or in the mobile apps.

The Teams dashboard is a separate case. It does not use Sentry. The analytics tools it does load include Hotjar, a behaviour-analytics tool whose features include session recording, and it loads them only with analytics consent, only in production, and never when your browser sends a Do Not Track signal. We name that here rather than let the paragraph above be read as “no recording anywhere except the web app”. Hotjar is listed in the Routerra Teams section of our Subprocessors page, and withdrawing analytics consent in the dashboard turns it off.

Support chat

If you open live chat (Tawk.to), we process the conversation. When you are signed in to the app, the chat is linked to your verified email and name so support doesn't have to ask who you are. On our website the chat loads only when you open it; in the web app it loads only with your support-cookies consent.

Payments and subscriptions

Web purchases are sold by Lemon Squeezy as merchant of record: their checkout processes your payment, and we never receive your card number. Mobile purchases go through the App Store or Google Play, with RevenueCat managing subscription status. We keep provider subscription IDs, your plan, amounts, and the email on billing records. Billing records are retained for about 5 years after account deletion, as Polish accounting law requires.

Location (mobile)

With your OS permission, the mobile app uses your precise location — foreground only, on demand. It biases address search near you and shows where you are on the map. There is no background tracking, no continuous collection, and we do not store a history of where you have been.

Voice input (mobile)

If you add stops by voice, the audio is transcribed by your device's platform speech-to-text (Apple or Google). We use the transcript to add the stops; the audio is not stored by us, and the transcript is not kept unless you save the result.

Server logs

Our servers keep request logs with your account ID (not your email) for debugging and security. Application log files rotate after about 14 days. Our hosting and CDN providers (Cloudflare, Netlify) log IP addresses at the infrastructure level as part of serving requests.

Country lookup (web app)

When the web app loads, it asks ipapi.co which country your IP address is in, so we can pre-set sensible defaults (distance units, locale). Your IP is processed transiently for the lookup and is not stored by us.

4. Why we process it (purposes & legal bases)

Under the GDPR, every use of personal data needs a legal basis. Here are ours:

PurposeLegal basis (GDPR)
Providing the Services: your account, routes, optimization, imports/exports, maps and navigation, subscriptionsContract — Art. 6(1)(b). This is the service you signed up for.
Product analytics (with opt-out on mobile), crash reporting, securing the Services, and proactive support outreach when something breaks for youLegitimate interests — Art. 6(1)(f): running, improving, and protecting the Services.
Web-app analytics and support-chat cookies, and session replay in the web appConsent — Art. 6(1)(a), given via the web app's consent banner and withdrawable at any time.
Keeping billing recordsLegal obligation — Art. 6(1)(c), Polish accounting law.

We do no automated decision-making that produces legal effects about you, and no profiling beyond the product analytics described above.

5. AI processing of your imports

When you import stops from a photo or a spreadsheet, here is exactly what happens:

Data sent through the OpenAI API is not used to train OpenAI's models, per OpenAI's API terms. The uploaded files themselves are automatically deleted from storage after 30 days.

6. Who we share data with

We share personal data only with service providers (processors) that run parts of the Services for us — hosting, authentication, maps, route optimization, payments, analytics, crash reporting, support chat, and email. Each one processes data under a data processing agreement and only on our instructions. The complete, current list — every vendor, where it is, and what data it touches — is on our Subprocessors page.

We do not sell personal data. We do not share it with advertisers or ad networks, and there are no advertising SDKs or pixels in our apps or on our site. We would disclose data to authorities only where the law requires it.

7. International transfers

Our backend and primary storage are in the USA (AWS us-east-1), and several of our providers are US companies. For transfers of personal data out of the EEA, we rely on the EU–US Data Privacy Framework where the vendor holds a current certification, and/or the EU Standard Contractual Clauses included in each vendor's data processing agreement. Error monitoring is an exception to US processing: our Sentry ingest is pinned to Sentry's EU region.

8. How long we keep data

DataKept for
Account, routes, stops, address bookUntil you delete your account (deletion cascades immediately). Deleted address book entries are purged after 90 days.
Uploaded import filesAuto-deleted after 30 days.
Route exportsAuto-deleted after 3 days.
Behavioural events (our database)Anonymized after 24 months — and immediately when you delete your account.
Product analytics (PostHog)12 months.
Crash reportsUp to 90 days.
Session replays (web app)Per Sentry's retention — up to 90 days.
Server application logsRotate after about 14 days.
BackupsDeleted data leaves backups within 60 days.
Billing recordsAbout 5 years after account deletion (Polish accounting law).

For the full mechanics of what happens when you delete your account, see the Deletion Policy.

9. Your rights and how to use them

Under the GDPR you have the right to:

How to exercise them

The fastest way to erase everything is built into the product: both the web app and the mobile apps have Delete Account in Settings, and it works immediately. For anything else — access, correction, a data export, an objection — email info@routerra.io. We respond within 30 days. We may ask you to verify your identity first, so we don't hand your data to someone else.

Complaints

If you believe we are processing your data unlawfully, you can lodge a complaint with our supervisory authority — the President of the Personal Data Protection Office (UODO), Warsaw, Poland — or with the data protection authority where you live or work.

If you are outside the EEA

We apply the same standards to everyone: the rights above are honored regardless of where you live.

US state residents

Some US states give residents rights to access and delete their personal data and to opt out of its "sale" or "sharing" for cross-context advertising. We do not sell personal data and do not share it for cross-context behavioral advertising, so there is nothing to opt out of and no "Do Not Sell" link is required. Your access and deletion rights are honored the same way as everyone else's — in-app or by email, as above.

10. Data about people who don't use Routerra

Routes and stops usually describe our users' customers — people who have no Routerra account. That data comes from the Routerra user who entered or imported it, and that user is responsible for having the right to use it. We process it only to plan and run that user's routes; we do not use it for anything else, and it is deleted with the user's account (imported files even sooner — within 30 days). If your address or details appear in a Routerra user's route and you want them removed, email info@routerra.io and we will handle it.

You can share a route via a link. Anyone who has the link can see the route it points to — the stops, addresses, and progress — without signing in. That is what makes sharing work, and it means you should treat route links as sensitive: share them only with people who should see the route.

12. Security

Data moves between your device and our servers over TLS. Our managed storage (database, file storage) is encrypted at rest, application secrets are encrypted with AES-256-GCM, and access to production systems is restricted to those who need it. No system is perfectly secure — if a breach ever puts your rights at risk, we will notify the supervisory authority within 72 hours where required, and affected users without undue delay.

13. Children

The Services are not directed to anyone under 18. If we learn we have collected personal data from a minor, we will delete it.

14. Cookies

The short version: the marketing site runs nothing non-essential before you act (so it has no cookie banner), the web app and the Teams dashboard each ask for consent per category (essential / analytics / support), and the mobile apps use no cookies at all. The Cookie Policy names every cookie and storage key on the marketing site and in the web app — those are the surfaces it covers. For the Teams dashboard, the tools behind each consent category are named in section 15.

15. Routerra Teams

Routerra Teams is our product for companies that dispatch drivers: a dashboard at teams.routerra.io, a driver app, and a backend of its own. It is sold to a company, not to you personally, and that changes who decides what.

Our role: processor for the team's data, controller for the account

For everything a customer company and its people upload to, or generate in, Routerra Teams — recipient names, addresses, coordinates, delivery notes and time windows; the driver roster; team membership and invitations; proof-of-delivery photos; the team audit log; and, where live tracking is enabled, navigation trip and position data — the customer company is the controller and we are its processor. We process that data only on that company's documented instructions, under our Teams Data Processing Agreement. What happens to it is the company's decision, not ours, and this policy does not govern it.

We are an independent controller — and this policy applies — for five things, and only these five:

  1. the sign-in accounts of administrators and of drivers — email address, name, authentication identity, and preferences such as language, timezone, units and default navigator, held against the person rather than against a team. Drivers sign in to the driver app through the same authentication provider administrators use;
  2. billing — the subscription record for a team: its provider, status, plan, seat count, trial end and renewal date;
  3. our own product telemetry, including the crash and error diagnostics our apps report to us when something in them goes wrong;
  4. our support communications with a customer and its administrators, including the support chat in the dashboard;
  5. security and abuse handling.

The dividing line runs where the data came from: an account a person creates for themselves is ours to answer for, while what a company invites, enters, imports or generates inside its team is that company's. A driver shows both sides of the line at once — the account they sign in with is ours, and the entry their employer created for them on the driver roster — name, email, vehicle, shift, depot — is their employer's, held by us as its processor.

If you are a driver, or someone receiving a delivery

Drivers: the company you drive for decides what goes into Routerra Teams about you and why. Read the Driver Privacy Notice, which is written for you. Requests to see, correct or delete the data your employer holds about you go to your employer. If you write to us instead, we will pass the request to them and tell you that we have done so and who we sent it to — we will not show you, change or delete their records ourselves, because we may not act on their data without them. Your right to complain to a data-protection authority does not depend on any of that.

Closing your Routerra account immediately revokes your access to the team and its routes. It does not delete your entry on your employer's driver roster: that entry is their record, and we do not delete a customer's records without their instruction. Ask your employer if you want it removed.

Delivery recipients: if your name, address, phone number or delivery note is in a Teams customer's route, the company delivering to you put it there and is responsible for it. Ask them. If you write to us at info@routerra.io, we will pass your request on to them the same way.

What Routerra Teams processes

CategoryWhat it isWhose data it is
Administrator and driver accountsEmail address, name, authentication identity, language, timezone, units, default navigator.Ours (controller)
Team membership and invitationsWhich team a person belongs to and in what role; the email address, role and token of an invitation until it is accepted or revoked.The customer's (we process)
Driver rosterName, email, colour, vehicle type and capacity, maximum stops, shift start and end, start and finish depot with address and coordinates, routing preferences.The customer's (we process)
Stops and recipientsName, address, coordinates, notes, time windows, service time, priority and load — usually data about the customer's own customers, who are third parties.The customer's (we process)
Proof-of-delivery photosPhotos a driver takes at a stop, and the record of the upload.The customer's (we process)
Address-book filesFiles a customer attaches to an address-book entry.The customer's (we process)
Team audit logWho did what and when, with a record of what changed — which can include names and addresses. The customer can read it in the dashboard.The customer's (we process)
Navigation trips and positionsOnly where live tracking is enabled for a team: the team, driver, route and stop involved, the navigator used, trip status and timestamps, and the position, estimated arrival and remaining distance reported during the trip.The customer's (we process)
Notification deliveriesWhere a customer turns on recipient notifications: the recipient email address or phone number, the subject, the message as sent, the delivery status, the provider's message id and any error.The customer's (we process)
Webhook deliveriesWhere a customer configures a webhook: the payload we sent to their endpoint and the result.The customer's (we process)
Offline-sync ledgerAn identifier and a timestamp for each driver-app sync operation we have already applied, so that an edit made offline is not applied twice when the phone reconnects. The record holds nothing else — not the team, not the driver, not what the edit contained.Neither — a technical de-duplication record, not personal data
BillingOne subscription per team: provider, status, plan, seat count, trial end, renewal date and the provider's reference. Checkout runs at Lemon Squeezy as merchant of record, and we never receive card numbers.Ours (controller)
Teams product telemetry (from our servers)Billing-lifecycle events keyed to the team — team name, plan, seat count, renewal and trial dates. No personal identifiers.Ours (controller)
Teams dashboard analytics (from the browser)The dashboard itself sends us, from an administrator's browser and only with analytics consent: pageviews, a named set of billing and onboarding-tour events with their plan and seat-count details, and automatic error reports carrying the stack trace when something breaks in the page. There is no blanket capture of clicks or form contents. These are keyed to an anonymous device identifier, not to a person: we never call the analytics tool's identify function, and it is configured not to build a profile for an unidentified visitor. An error report can still include personal data incidentally, in the same way an internal alert can.Ours (controller)
Driver-app diagnostics and crash reportsNavigation diagnostic events, which are pseudonymous to the device, and crash reports with the stack trace and the device, OS and app version. We do not attach a driver's email address to either.Ours (controller)
Server logs and internal alertsEach request the dashboard or driver app makes, with the account identifier, the team, the role and a request identifier; when something fails, an alert to our own internal channel carrying the error and that context. The Teams alert currently also carries the signed-in person's email address; the change removing it ships in a backend release that is not yet deployed.Ours (controller)

The legal bases are the ones in section 4, applied to our own side of the split: contract for the account and the subscription, legitimate interests for telemetry, crash reporting, support and security, and legal obligation for billing records. For the data we hold as a processor, the customer company chooses the basis, not us.

Live driver tracking

Live driver tracking is an optional feature that a Teams customer may switch on for its team. It is off by default, and as at the date at the top of this page it is not running in production for anyone. We describe it here so that nobody meets it for the first time after it is turned on.

Where a customer does enable it, it works like this. The driver app does not stream position to us. A driver taps Navigate for a stop and is handed over to Google Maps or Waze through a Google service called Google Navigation Connect. While the driver is navigating to that stop — and only then — Google reports the driver's position and estimated arrival time, which their dispatchers can see and which we record on the customer's behalf. It does not run between stops, or after a shift.

The controls are Google's. Google shows the driver its own consent screen before this starts, shows an indicator in Google Maps while it is active, and lets the driver switch it off there. That is the switch that works, so we do not add a competing one of our own. Positions are kept for 90 days.

Separately from that feature, the driver app uses location only while it is open, to show the driver on the map and help them reach the next stop. There is no background tracking: the app does not follow a driver when it is closed, and it does not send a stream of position data to anyone.

How long we keep Teams data

DataKept for
Navigation positions90 days.
Navigation trip records90 days. †
Team audit log24 months. †
Notification deliveries90 days.
Webhook deliveries30 days.
Offline-sync ledgerAbout 90 days.
Proof-of-delivery photos365 days. An upload that never completed is cleared after 24 hours.
Address-book filesNo automatic expiry — kept until the customer deletes them or deletes the team. An upload that never completed is cleared after 24 hours.
Stops, address book, driver roster, team membersUntil the customer deletes them or deletes the team. There is no automatic clean-up, because how long a company needs its own operational records is its decision, not ours. Invitations are kept until accepted or revoked.
Administrator and driver sign-in accountsUntil the person deletes their account.
Teams telemetry and driver-app diagnostics12 months.
Driver-app crash reportsUp to 90 days.
Billing recordsAbout 5 years (Polish accounting law).

† Enforcement release pending. These two periods are our commitment from the date at the top of this page. The scheduled job that enforces each of them automatically ships in a backend release published alongside our Teams documents and not yet deployed, so until it is live, records in these two areas may be older than the period stated. Ask us and we will delete anything older on request. We will remove this note when the release is live. The same note appears in Annex IV of the Data Processing Agreement and on our Security page.

A customer can delete a team at any time, which removes that team's data. What that removal covers, and what it does not cover immediately, is set out in section 11 of the Data Processing Agreement and in section 7 of our Security page, as is what happens at the end of a subscription; we will confirm a deletion in writing on request. This policy deliberately does not restate it, so that there is only one description to keep true.

Teams subprocessors and transfers

Routerra Teams runs on a different set of vendors from the consumer product. Every one of them is named, with its region, purpose and the data it touches, in the Routerra Teams section of our Subprocessors page, which is also Annex III of the Data Processing Agreement and where changes are published in advance.

Twilio is not one of our subprocessors. Where a customer sends SMS notifications, they run on the customer's own Twilio account: the customer supplies the credentials, we store them encrypted and use them only to send on the customer's instruction. Twilio is that customer's processor under their own contract, not ours. We say so rather than let its absence from the list look like an oversight.

The Teams backend is hosted on AWS in the USA (us-east-1), so the transfers described in section 7 apply here too. Because we are established in Poland, a customer in the EEA sending us data is not itself making a restricted transfer; the transfer that needs a mechanism is ours onward to vendors outside the EEA, and it is covered by the Standard Contractual Clauses in section 13 of the Data Processing Agreement.

Cookies and consent in Teams

The Teams dashboard asks for consent by category — essential, analytics and support. Analytics covers PostHog, our product analytics and error tracking, and Hotjar, our behaviour-analytics tool. Both load only with that consent, only in production, and never when your browser sends a Do Not Track signal; support covers the Tawk.to chat in the dashboard. The driver app has no cookies and no analytics you need to consent to: its diagnostics are pseudonymous to the device, and crash reporting runs on our legitimate interest in keeping the app working. Advertising identifiers are actively blocked in the driver app, as they are in our consumer apps.

The other Teams documents

Data Processing Agreement (the agreement with the customer company), Security (the technical and organisational measures), Driver Privacy Notice (written for drivers), Teams Terms of Service, and the Routerra Teams section of the Subprocessors page.

16. Changes to this policy

When we change this policy, we post the new version here and update the date at the top. For material changes we will also notify you by email or in the app.

Change history

17. Contact & data controller

Related documents:

For Routerra Teams: