Last updated: August 17, 2026
A subprocessor is a third-party service provider we use to help deliver Routerra, and who may process personal data as part of that work. This page lists them for both of our products, in a section each: Routerra, the consumer route planner, and Routerra Teams, the dispatch product for companies. The two run on separate backends and do not share the same vendor set, so read the section for the product you use.
The Teams table in section 2 is the list referenced by our Teams Data Processing Agreement: it is the current, authoritative version of Annex III of that agreement, and the notice period in its section 7 runs from what is published here.
If we make a material change to either list — adding or replacing a subprocessor — we reflect it on this page. Check back periodically, or contact us at info@routerra.io to be notified of changes. Teams customers additionally get normally at least 30 days’ advance notice of a new or replacement Teams subprocessor, and a right to object, under section 7 of the Data Processing Agreement — with the exception that section makes for a subprocessor we must appoint at short notice to keep the service secure or available, where we give what notice we can and the right to object is unaffected.
These are the subprocessors behind the consumer product — the Routerra web app (app.routerra.io), the Routerra mobile apps, and routerra.io.
| Vendor | Region | Purpose | Data touched |
|---|---|---|---|
| Clerk Inc. | USA | authentication & account management | email, name, OAuth identity, session data |
| Amazon Web Services | USA (us-east-1) | hosting: compute, database, file storage, geocoding/optimization functions; Textract OCR for photo imports | all product data; uploaded images (OCR) |
| OpenAI | USA | parsing imported files: OCR text and spreadsheet rows are processed by OpenAI models to extract stops (API — not used for model training per OpenAI API terms) | text content of user imports (may include recipient names/addresses/phones) |
| Google (Maps Platform) | USA/EU | geocoding, places autocomplete | address strings, coordinates |
| Mapbox | USA | maps, geocoding, directions | address strings, coordinates, map interactions |
| GraphHopper GmbH | Germany | route optimization matrices/directions | coordinates of stops |
| TomTom | Netherlands | live traffic data for routing | route coordinates |
| Lemon Squeezy (a Stripe company, merchant of record) | USA | web payments, checkout, billing portal, invoicing, tax | billing identity and payment details (processed and held by Lemon Squeezy; we never receive card numbers) |
| RevenueCat | USA | mobile subscription management (App Store / Play receipts) | app user id, purchase history, account email and display name |
| PostHog Inc. | USA (us.posthog.com) | product analytics & web error tracking | pseudonymous usage events keyed by account ID; billing events |
| Bugsnag (SmartBear) | USA | mobile crash reporting | crash data + account ID, email, name |
| Functional Software Inc. (Sentry) | EU ingest (de.sentry.io) | web/server error monitoring & consent-gated session replay | error data + account ID; masked replays |
| Tawk.to Inc. | USA | live support chat | chat content; email/name of signed-in users |
| Loops (loops.so) | USA | transactional & product email | email, first/last name, membership type |
| Netlify | USA | web hosting/CDN for routerra.io and app | request metadata |
| Cloudflare | USA/global | DNS/proxy for routerra.io | request metadata |
| Grafana Labs (Grafana Cloud/Loki) | EU/USA | infrastructure logs & metrics | server logs with account IDs |
| Slack | USA | internal error alerting | alert messages (account IDs only — no email addresses) |
| ipapi.co | — | IP-based country lookup for web-app defaults (units/locale) | IP address (processed transiently) |
| Apple / Google | USA | app distribution, in-app purchases, speech-to-text, push/OAuth platform services | per platform terms |
These are the subprocessors behind Routerra Teams — the Teams dashboard (teams.routerra.io), the Routerra Teams driver app, and the separate Teams backend. This table is Annex III of the Teams Data Processing Agreement as it stands today.
| Vendor | Region | Purpose | Data touched |
|---|---|---|---|
| Clerk Inc. | USA | authentication for administrators and drivers | email, name, session data |
| Amazon Web Services | USA (us-east-1) | hosting: compute, PostgreSQL database, object storage | all Teams product data |
| Google (Maps Platform) | USA/EU | geocoding, places, maps | address strings, coordinates |
| Google (Navigation Connect) | USA | live driver navigation trips and progress events — only where live tracking is enabled for the team | driver position, ETA, destination coordinates |
| Mapbox | USA | maps in the dashboard and the driver app | coordinates, map interactions |
| GraphHopper GmbH | Germany | route optimization | coordinates of stops |
| TomTom | Netherlands | live traffic for routing | route coordinates |
| OpenAI | USA — SCCs only, not DPF-certified | parsing imported stop lists (API — not used for model training per OpenAI’s API terms) | text content of customer imports, which may include recipient names, addresses and phone numbers |
| Lemon Squeezy (a Stripe company, merchant of record) ‡ | USA | Teams subscription checkout and billing | billing identity and payment details |
| Loops (loops.so) | USA | transactional email (invitations, dispatch-failure notices) | recipient email, name |
| Expo (EAS and push service) | USA | driver-app builds, over-the-air updates, push notifications | device push tokens |
| PostHog Inc. ‡ | USA | product analytics and error tracking (team-keyed server events, dashboard pageviews and product events, driver-app diagnostics, browser error reports) | team identifier and name, plan, seat count; pseudonymous dashboard and driver-app events; stack traces from an administrator’s browser |
| Bugsnag (SmartBear) ‡ | USA | driver-app crash reporting | crash data, device metadata |
| Hotjar Ltd | EU (Malta) | behaviour analytics in the Teams dashboard — consent-gated, production only, honours Do Not Track | session interactions in the dashboard |
| Tawk.to Inc. ‡ | USA | live support chat in the dashboard | chat content, identity of signed-in administrators |
| Netlify | USA | hosting and CDN for the Teams dashboard | request metadata |
| Cloudflare | USA/global | DNS and proxy | request metadata |
| Grafana Labs | EU/USA | infrastructure logs and metrics | server logs |
| Slack | USA | internal error alerting | alert messages — the error, the account identifier, the team, the role and the request identifier, and currently also the signed-in person’s email address † |
† The email address is being removed. The Teams alert layout still interpolates the signed-in person’s email address, and the change that drops it ships in a backend release published alongside our Teams legal documents but not yet deployed. We say so rather than describe the fixed state, and we will remove this note when the release is live. The equivalent field has already been removed from the consumer product, and that change is deployed — which is why the Slack row in section 1 reads differently. The two products run on separate backends and ship separately.
‡ Engaged for our own processing, not for the customer’s. Lemon Squeezy (billing), PostHog and Bugsnag (our own product telemetry and crash diagnostics) and Tawk.to (our support conversations with administrators) serve processing we carry out as an independent controller, not on a Teams customer’s instructions, so strictly they are not subprocessors of customer data. We list them here anyway so that one table shows every vendor standing behind the service, and we bind them to the same terms to the extent any of them does receive customer data. Cloudflare, Grafana Labs and Slack stay unmarked even though they also serve that controller-side work, because the same systems carry and hold customer data as well — Grafana holds the server logs and Cloudflare proxies the traffic — so we treat all three as full subprocessors rather than split them. Annex III of the Data Processing Agreement sets this out in full, and our Privacy Policy covers them in that capacity.
Twilio is not a Routerra subprocessor. We say so explicitly, because its absence from the table above would otherwise look like an oversight. SMS notifications run on the customer’s own Twilio account: the customer supplies the account credentials, we store them encrypted, and we use them only to send messages on the customer’s behalf at their instruction. Twilio is therefore the customer’s processor under the customer’s own contract with Twilio, not ours, and the data-protection arrangement with Twilio is the customer’s to make. The same is true of any other integration a customer configures with their own credentials, and of any outbound webhook pointed at a system the customer operates.
We're based in Poland (EU) and our product backends are hosted in the USA (AWS us-east-1), so personal data is transferred internationally to deliver both products. Each vendor is engaged under a data-processing agreement incorporating the EU Standard Contractual Clauses and/or is certified under the EU-U.S. Data Privacy Framework.
Because we are an EEA (Polish) business, a customer in the EEA sending us data is not making a restricted transfer; the transfer that needs a mechanism is the one from us to our US subprocessors. OpenAI is the one vendor we will not describe as covered by the Data Privacy Framework — it does not hold a current certification, and transfers to it rely on the Standard Contractual Clauses in its data processing agreement alone.
For how we handle personal data more broadly, see our Privacy Policy, whose Routerra Teams section explains which parts of Teams we handle as a processor for the customer and which as a controller in our own right. Teams customers should also read the Data Processing Agreement and our Security page, and drivers the Driver Privacy Notice.
For questions about this subprocessors list, or to object to a Teams subprocessor, email info@routerra.io.