Privacy Policy
Last updated: September 23, 2026 · Operator: Routella, LLC, a Delaware limited liability company · 131 Continental Dr, Suite 305, Newark, DE 19713, United States · +44 7756 988088
Routella, LLC operates both Routella services at routella.app: the general delivery-dispatch and route-optimization software used by businesses with their own customers and drivers, and the Routella Partners marketplace, including the Routella Driver mobile app, for business merchants and independent drivers. This Privacy Policy explains which participant decides how data is used, what each service collects, why it is used, who receives it, how long it is kept, and how to ask for access, correction, export, or deletion. A local Partners explanation takes priority over a general-SaaS description that does not fit that marketplace.
1. Who We Are and the Roles We Play
Routella, LLC, a Delaware limited liability company with the public business address 131 Continental Dr, Suite 305, Newark, DE 19713, United States, operates the general Routella software service and the separate Routella Partners marketplace at routella.app. The services have different participant roles and data flows.
We play two different privacy roles depending on whose data it is, and it matters because it decides who you contact about your rights.
For general-SaaS data Routella, LLC decides the purpose and means of, Routella, LLC is the controller. This covers merchant account holders, visitors to our public website, marketing, and Routella's own operational and security records.
For personal data a general-SaaS merchant uploads or feeds into Routella about that merchant's own end customers and drivers — delivery recipients’ names, addresses, phone numbers, emails, order contents, delivery locations, driver records, and driver GPS — the merchant is the controller and Routella, LLC acts as processor. The merchant decides why and how its customers and drivers are messaged and is responsible for the required notices and lawful basis. The processor terms are set out in the Data Processing Agreement (/dpa).
For a general-SaaS end customer or a driver added and managed by a merchant, contact that merchant first about your rights and Routella, LLC will assist it. A Routella Partners merchant or independent driver may contact Routella, LLC directly as explained in the matching local Partners section or notice.
For customer conversations on business-owned Facebook Pages and Instagram professional accounts connected through Routella MCP, the connected business decides how those conversations are handled for support, and Routella follows its instructions. The Meta Business Messaging Privacy Notice linked above explains this connection and its separate request process.
1A. Statewide Florida Partners Marketplace — Routella, LLC
For the statewide Florida Partners marketplace, Routella, LLC is the controller or business for the applicant and participant account, marketplace, safety, payment-status, support, and legal records for which it decides the purposes and means. Routella, LLC uses them to receive applications from throughout Florida, create and secure accounts, apply the current account, declaration, Stripe, legal, and operational checks before paid-work access, check the Florida job boundary, let a merchant select exactly one currently eligible driver, bind the exact seller to the request, support the job, record payment outcomes, prevent fraud, meet legal duties, and answer complaints, refunds, and card disputes.
Saved current vehicle declarations are used for Florida driver applications. Routine Routella vehicle-document review is not required for the nine current vehicle modes. Stripe identity and account checks remain separate. A future vehicle type or a genuine individual licensing, insurance, or vehicle-safety exception may require only the exact evidence, expiry fact, or strict human review needed for that affected mode.
The Florida merchant and independent driver are separate marketplace participants, not a merchant-owned-driver relationship. The merchant decides which recipient and parcel facts to supply and is responsible for giving any required notice to that recipient. The driver may use job information only to decide and perform that delivery. Each participant can have its own duties under applicable law; this notice does not turn either participant into Routella, LLC's employee or agent.
Routella, LLC does not sell Florida Partners personal information and does not use recipient, cargo, vehicle-document, tax, payment, refund, or dispute data for advertising. If the participant grants the optional Marketing cookie choice, Routella may send only the saved broad vehicle type or merchant business type and the saved Jacksonville or Tampa market to Meta or TikTok to show more relevant Routella ads. Routella does not send an address, ZIP code, business name, vehicle plate, phone, email, cargo text, recipient fact, payment fact, or user identifier with that audience event. Declining or later withdrawing Marketing consent does not affect marketplace access.
- Florida applicant, participant, and contact data — merchant or driver name; the driver's full date of birth for age eligibility; the merchant business name, broad business type, merchant registration number, and business address where supplied or required for review; email, phone, one-time sign-in and verification status, application, eligibility, service-area and readiness facts, account state, agreement versions and acceptance times. Source: the applicant and account/security events. Purpose: account access, age and Florida marketplace eligibility, participant identification, support, security, proof of current agreements, and the narrow optional advertising use described above when Marketing consent is granted.
- Florida cargo, route, and recipient data, including delivery-chat data — pickup, stop, and destination addresses and coordinates; recipient/contact and access details, including any leave-at-door permission and merchant responsibility acknowledgement; parcel description, package count by size where required, quantity, packing, weight, dimensions or fit, required transport type, return instructions, scheduled time, merchant declarations, job status, and road-distance proof. If the merchant turns on recipient updates for a delivery, the assigned merchant, driver, and recipient can exchange private delivery-coordination messages for that exact delivery leg. Every stop has a separate room, participant phone numbers are not shown, and each stored message keeps its original text plus English, Spanish, and Hebrew copies so each participant can read it in the language selected for that account or WhatsApp conversation. Routella asks participants not to put card, bank, identity-document, or unrelated contact details in the chat. Posting closes when the delivery reaches a terminal state, while the existing thread remains read-only for delivery support. For deliveries using the item checklist, Routella also records item-by-item pickup and delivery outcomes, such as collected, delivered, returned, refused, missing, or damaged, with the time the driver recorded each result. A mixed or unclear result opens a Routella team review and does not itself charge, refund, credit, or pay either participant. Source: the merchant, selected driver, recipient, U.S. Census Geocoder address and geography result, OpenCage fallback address result, and Google routing result. Purpose: validate a local Florida job, let the selected driver decide and perform it, coordinate the exact handoff, and resolve safety, nonreceipt, return, or delivery questions.
- Statewide Florida paid-route address-boundary check — Florida’s statewide delivery scope covers all 411 active incorporated cities. When paid operations are enabled, every pickup, stop, and dropoff must be inside an incorporated city boundary. Routella checks every point separately; a postal city name or ZIP does not prove eligibility. A route is blocked if any point is outside an incorporated Florida city or in an unincorporated county area. The separate 75-mile cap still applies. Routella first sends the full address to the U.S. Census Geocoder and accepts it only when one result matches the submitted house number, street, Florida state, and ZIP and supplies the official incorporated city and county. If the Census Geocoder cannot return that one matching result, Routella sends the full address to OpenCage to obtain a coordinate. The fallback request includes OpenCage's no_record=1 setting, which OpenCage documents as preventing the query contents from being logged; the full address is still transferred to produce the result. Routella then sends only that returned longitude and latitude — not the street address, postal-city text, or ZIP — to the U.S. Census Geocoder to confirm the incorporated city and county. Routella makes its own boundary and eligibility decision.
- Florida driver vehicle-declaration and exception-review data — selected transport types; responsibility, delivery-use coverage, endorsement, operating-authority, and vehicle-control declarations; readiness status; and, only for legacy records, a future vehicle mode, or a genuine individual exception, vehicle descriptions or plates, document references, expiry facts, and human-review outcomes. The driver remains responsible for complete lawful records and safe operation.
- Florida tax and identity flow — Routella does not run a separate Florida tax-identity form. The driver gives identity, taxpayer, business, bank, document, and financial-compliance details directly to Stripe in Stripe-hosted onboarding. Stripe identity and account checks remain separate. Stripe decides what its services require and processes those details under Stripe's privacy notice. Routella keeps only the Stripe connected-account reference, readiness and status facts, public Stripe business name and statement descriptor, and account evidence needed to prove that the selected driver is ready for this marketplace; Routella does not store the driver's full Stripe-hosted taxpayer, identity-document, or bank details.
- Florida payment, refund, dispute, and receipt records — Stripe customer, payment-method, connected-account, PaymentIntent, charge, application-fee, refund, dispute, event, and receipt references; amounts and currency; authorization, capture, release, refund, dispute and payout-readiness statuses; public Stripe business name and statement descriptor; and payment or dispute review evidence. Purpose: request the agreed card action, keep the marketplace ledger accurate, provide receipts, reconcile signed Stripe events, and answer payment complaints. Routella does not store the full merchant card number or the driver's full Stripe-hosted bank or taxpayer number.
- Seller selection and visibility between participants — the merchant selects exactly one currently eligible driver for the request. Before publishing and before any card authorization, the merchant sees that driver's public Stripe business name and statement descriptor and must freshly confirm that exact seller. Routella does not silently replace the seller: a changed driver requires a new disclosure, fresh merchant confirmation, and a new authorization for the replacement's connected account. Before acceptance, that selected driver receives only the offer, cargo, transport, timing, driver-proceeds, merchant-name, and approximate-area facts needed to decide; the merchant's Routella fee and card total are not included in Routella driver views. Precise pickup, stop, destination, recipient, contact, and access details are revealed only after that driver accepts and the card authorization is confirmed active. Neither participant may reuse the other person's data for another purpose.
- Florida ratings and reliability records — merchant and recipient ratings of the driver; driver ratings of the merchant; a required named reason and short written explanation for a 1 to 3 star delivery rating; whether that low rating is waiting, counted, or excluded after a Routella team decision; accepted-job completion and missed-pickup counts; pickup timing; the route-based delivery target frozen at pickup and the resulting on-time delivery fact; driver cancellation reason and written explanation; and the Routella team's separate cancellation-review outcome. Purpose: show participants their records, give drivers an overall transparent score, let a human decide whether a low rating or accepted-job cancellation affects that score, and use the score as one small Florida automatic-offer-order factor. A low rating does not affect the displayed score or offer ordering while it waits for that decision. Missing route facts are not guessed or scored, and rejecting or ignoring an unaccepted request is not a score input.
- This paragraph applies only to the current controlled Florida web pilot, not to the Routella Driver mobile app. The current controlled Florida paid pilot does not collect live GPS, provide customer tracking links, require delivery photos, signatures, or PIN proof, or promise an automatic backup driver. It uses manual job status confirmations instead. Routella Driver's separate location, tracking, and proof data flows are described immediately below in section 1B.
1B. Routella Driver Mobile App — Store Review and Approved Programs
Routella Driver is the native mobile app prepared for invited independent delivery partners. The native functions in this section are used for isolated store review and can be enabled for a paid local program only after that exact program's legal, vehicle, tax, payout, operating, and release checks are complete and its controlling local documents allow the same functions. This section does not silently expand the current controlled Florida paid pilot described in section 1A.
For native app account, delivery, safety, support, fraud-prevention, and payment-status records for which Routella decides the purposes and means, Routella, LLC is the controller or business. The app does not sell driver, recipient, location, proof, payout, or device information and does not use it for advertising.
- Native driver account and app data — driver name, full date of birth, email, phone, signup IP address and app or browser user-agent string, one-time sign-in and verification status, application and readiness facts, service area, vehicle and licence or insurance references where required, online status, device notification tokens, earnings, payout status, ratings, delivery history, account state, agreement versions, and acceptance times. Source: the driver, the Routella Driver app, delivery activity, Stripe readiness results, and account or security events. Purpose: account access, eligibility, delivery operation, notifications, support, fraud prevention, security, payments, and proof of current agreements.
- Native precise location — when a driver chooses to be online, the app may collect foreground precise location to find nearby work and support dispatch. Background precise location is collected only while the driver remains online with an active delivery, so the assigned merchant and recipient can follow progress. It stops when the delivery ends or the driver goes offline and expires within 24 hours. Location is not used for ads or marketing.
- Native delivery proof and participant visibility — after the assigned driver accepts and the delivery is active, the merchant and recipient can see delivery progress and the driver's current position. Depending on the merchant's selected proof requirement, the driver may submit a delivery photo, recipient signature, recipient PIN verification, or delivery note. Routella uses this information to complete the delivery, support the participants, prevent fraud, and resolve delivery questions or disputes.
- Native notifications — if the driver permits notifications, Routella stores the device notification token and can send a generic alert that a delivery offer or account update is available. The signed-in app retrieves the private offer, route, earnings, payout, or account details from Routella after the alert; those private details are not placed in the push-notification payload.
- Native account deletion — a signed-in driver can permanently delete the account from Settings by choosing Delete my account, typing DELETE, and confirming. A driver who cannot use the app can start a verified deletion request at /delete-account or by emailing support@routella.app. Active deliveries and unsettled balances must be resolved first, and legally required transaction, payment, tax, dispute, fraud, safety, security, and deletion-confirmation records can remain for the required period.
2. The Personal Data We Process, the Sources, and Why
The categories below describe the general SaaS product. Separate Routella Partners categories, sources, purposes, and visibility rules appear in the matching local section or notice. Where Routella, LLC is a processor for the general SaaS product, the lawful basis belongs to the merchant controller and Routella relies on that merchant's basis and instructions.
We do not ask for or want special-category data — data revealing health, racial or ethnic origin, religious or political beliefs, trade-union membership, genetic or biometric identifiers, or data about a person's sex life or sexual orientation. Merchants must not put special-category data into free-text fields (such as delivery notes or reviews); where a merchant uploads a driver's licence image it is used only to identify the driver, not to derive any special-category attribute. The merchant is the controller for any such data it chooses to enter and is responsible for having a lawful basis under GDPR Article 9.
- Merchant account data — name, email, hashed password, login one-time codes, company name, phone, plan, and account-verification status (an internal “KYC” / risk-review flag on the account). Source: provided by the merchant at signup, or from Google/Apple sign-in. Purpose: account creation, sign-in, billing, support, fraud and abuse prevention. Legal basis (we are controller): performance of our contract with the merchant; legitimate interest for fraud/abuse prevention; legal obligation for billing records.
- Acquisition and marketing context — sign-up source and campaign tags (e.g. utm_source/utm_campaign) and the country we detect from the visitor’s IP at signup. Source: the visitor’s browser and IP. Purpose: understanding where sign-ups come from and improving our marketing. Legal basis (controller): legitimate interest, and consent where it comes from non-essential cookies.
- End-customer order data — customer name, full delivery address (including building, floor, apartment where provided), latitude/longitude, phone, email, order line items, totals, cash-on-delivery amount, notes, and tags. We also retain the full raw order payload received from the connected platform for re-sync and troubleshooting, which may contain additional fields the platform sent. Source: imported from the merchant’s connected store/platform, or entered by the merchant as a manual order. Purpose: building delivery rounds, route optimization, dispatch, and sending the customer their delivery updates and tracking link. Legal basis: the merchant is the controller and supplies the basis; Routella acts as processor on the merchant’s instructions.
- Saved recipient delivery preference — only when a recipient actively selects the permission box on a signed tracking page, Routella stores the preferred delivery-time window and safe-spot note that recipient enters, together with the consent version and time, for future deliveries from that same merchant. The profile is separated by merchant and matched through a one-way hash derived from the recipient phone; it is not shared across merchants, sold, or used for advertising. Routella does not infer a preference from delivery behavior. Recipients should not place door codes, health information, or other sensitive details in the safe-spot note and can update or delete the saved preference directly from the same tracking page at any time.
- General-SaaS driver data — driver name, phone, email, vehicle details, an optional driving-license photo, an optional contract file, and real-time GPS location only while a general-SaaS delivery round is active. Source: entered by the merchant; GPS comes from the driver’s device during a round. Purpose: dispatching, live tracking, and proof of delivery. Legal basis: merchant is controller; Routella, LLC is processor. This is not the Routella Partners data flow described in the matching local notice.
- Proof of delivery and reviews — delivery-confirmation photos, recipient signatures or PIN verification where requested, delivery notes, and ratings or reviews that can include a name and free-text comment. In the general SaaS product, the merchant is controller and Routella, LLC is processor. In a Routella Driver store-review or approved local program that enables native proof, Routella, LLC is controller for the marketplace delivery proof and review records it uses to complete deliveries, provide support, prevent fraud, and resolve disputes. The current controlled Florida paid pilot remains subject to section 1A.
- Integration credentials — access tokens, API keys, and OAuth secrets for the merchant’s connected platforms. Source: provided/authorized by the merchant. Purpose: importing orders and writing back fulfillment status. These are stored with an extra layer of AES-256-GCM field-level encryption (see section 9). Legal basis (controller): performance of contract.
- Operational, security, and telemetry data — sign-in events; driver-signup security metadata including signup IP address and app or browser user-agent string; a personal-data access audit log (who viewed which order/customer/driver records, when, and from which hashed IP); error logs; public tracking-page view logs (with the IP hashed, not stored raw); and webhook or scheduled-processing records. Source: generated as you use the service. Purpose: security monitoring, duplicate-account detection, abuse and fraud prevention, debugging, and meeting regulatory obligations. Legal basis (controller): legitimate interest and legal obligation.
- Billing references — subscription and customer identifiers held by our payment providers, and which plan/packs you have. Routella does not collect or store payment-card numbers; the card is handled entirely by the payment provider (see section 3). Legal basis (controller): performance of contract and legal obligation (tax/accounting).
- Website and app analytics — page-visit and conversion data from visitors to our public site, only with consent. Source: cookies/SDKs in the visitor’s browser. Purpose: measuring website and advertising performance. Legal basis (controller): consent (see section 7).
3. Payments — Handled by Third Parties, Not by Us
Subscription and pack charges are processed by our payment providers, not by Routella. For merchants who installed Routella through Shopify, billing runs through the Shopify Billing API. For merchants who signed up directly, billing runs through Stripe. (Some historical direct subscriptions were billed through LemonSqueezy before July 2026.) SMS/WhatsApp top-ups and prepaid packs are charged through these same providers.
For those general-SaaS purchases, Routella never sees or stores your full payment-card details. We keep only references such as a subscription ID, a customer ID, and which plan or pack balance you hold. When you subscribe, the applicable provider’s own terms and privacy practices apply to the card payment.
The statewide Florida marketplace uses Stripe Connect differently. The driver completes Stripe-hosted onboarding, where Stripe collects and verifies the identity, taxpayer, business, document, bank, and financial-compliance information Stripe requires. Routella, LLC keeps the connected-account reference, readiness facts, and the driver's public Stripe business name and statement descriptor; it does not run a separate Florida tax form or store the full taxpayer number, bank number, or identity documents entered in Stripe's hosted form.
After the selected driver accepts, the merchant payment is a direct charge on the selected driver's connected Stripe account. Stripe processes the merchant's card, applies the disclosed Routella application fee, records refunds and disputes, and carries out the driver's automatic bank payouts under the driver's Stripe agreement. Routella, LLC stores the limited provider references, amounts, statuses, and signed event evidence described in section 1A so the marketplace and participant records agree. Stripe also processes data for its own payment, verification, fraud, compliance, and legal purposes under Stripe's privacy notice.
4. Sub-processors and Other Recipients
We share personal data only with the providers needed to run Routella, and only for the purposes shown. The sub-processors that handle merchant end-customer and driver data also appear in our Data Processing Agreement (/dpa); the website analytics and advertising tools listed at the end of this section touch only public-website visitor data and are covered by the Cookies section (section 7), not the DPA. We keep this list current when providers change, and each provider receives only what its job requires.
- MongoDB Atlas — our primary database. Encrypted at rest (AES-256) and in transit (TLS). Receives all stored personal data.
- Vercel — application hosting and TLS termination. Processes data in transit as you use the service.
- Infobip — SMS delivery worldwide, and WhatsApp delivery on Routella’s shared/managed number. Receives the recipient phone number and message content for the messages a merchant sends.
- WAHA Plus — WhatsApp delivery for merchants using their own connected WhatsApp number (the primary self-connected WhatsApp transport for paid tiers). Receives the recipient phone number and message content.
- Resend — transactional email delivery. Receives the recipient email and message content.
- Expo, Apple Push Notification service (APNs), and Google Firebase Cloud Messaging (FCM) — native Routella Driver build support and delivery of driver notifications. If a driver permits notifications, this delivery chain receives the device push token and a deliberately limited notification payload. Native offer alerts contain a generic prompt and opaque internal delivery and offer identifiers needed for the signed-in app to refresh the correct offer. Earnings, payout or account status, suspension reasons, deadlines, route areas, precise addresses, contact details, and order contents are not sent in the native notification payload.
- Shopify Billing — subscription billing for merchants installed via Shopify. Receives merchant billing identifiers; processes the card.
- Stripe — subscription and pack billing for general-SaaS merchants, plus Connect onboarding and direct-charge payment services for the statewide Florida marketplace. For Florida, Stripe receives driver identity, business, bank, document and compliance information in its hosted onboarding; merchant card and billing contact data; connected-account, payment, refund, dispute and payout data; and information used for fraud and regulatory checks. Stripe acts under its own agreements and privacy notice as well as providing payment services to the driver and Routella, LLC. Routella does not store full card or bank numbers entered in Stripe.
- Google (Maps Platform – Routes API) — traffic-aware route optimization and Florida local-route proof. Google Maps Platform Routes API receives the pickup, stop, and destination waypoints as coordinates (origin, destination, and intermediate stops). It does not receive participant names, phone numbers, emails, parcel descriptions, or payment information from the route request.
- Google (Maps Platform – Places) — address autocomplete. Receives the address text a user types into the address box, plus an optional location bias. It does not receive other customer identifiers.
- OpenCage — fallback address geocoding for current paid delivery requests whose every pickup, stop, and dropoff must be inside an incorporated Florida city boundary. Routella uses OpenCage only when the U.S. Census Geocoder cannot return one address result matching the submitted house number, street, Florida state, and ZIP. OpenCage then receives that full pickup, stop, or dropoff address and returns a coordinate. Routella includes no_record=1, which OpenCage documents as preventing the query contents from being logged. The full address is still transferred to OpenCage to produce the result. OpenCage does not receive participant names, phone numbers, parcel descriptions, or payment information from this request.
- U.S. Census Bureau Geocoder — address, incorporated-city, and county lookup for current paid delivery requests whose every pickup, stop, and dropoff must be inside an incorporated Florida city boundary. It first receives each full pickup, stop, and dropoff address. If that address does not produce one matching result and Routella uses OpenCage as a fallback, the later Census request receives only the longitude and latitude returned by OpenCage — not the street address, postal-city text, or ZIP. The Census requests do not include participant names, contact details, parcel details, or payment information. Routella uses the U.S. Census Geocoder API and makes its own boundary and eligibility decisions. Census Bureau API notice: This product uses the Census Bureau Data API but is not endorsed or certified by the Census Bureau.
- OpenStreetMap (Nominatim) and Photon — address geocoding. Receive the address query text only, no other customer identifiers.
- OpenFreeMap and Esri — map tile and satellite imagery for the dashboard and tracking pages. Receive the map viewport/coordinates being viewed, not customer identifiers.
- Anthropic — translates interface strings and message templates. It can also receive only the text that a participant typed when Routella translates an account-bound merchant-driver delivery or issue conversation for a WhatsApp viewer, or when a merchant has enabled recipient updates and a merchant, assigned driver, or recipient uses the private delivery chat. Recipient-chat text is translated into English, Spanish, and Hebrew in one request. Routella does not automatically attach a participant phone number, account email, payment fact, or identity document to these requests, but typed chat text can itself contain delivery details such as an address, access instruction, package fact, or name. Participants are told not to type card, bank, identity-document, or unrelated contact details into chat. Private participant text and its translations are not put into Routella's shared interface-translation cache. Recipient-chat originals and translated copies stay only in the account-bound delivery-chat record described in sections 1A and 5; a merchant-driver issue-room translation is made only for that viewer and the translated copy is not stored in the shared cache.
- Analytics and advertising — Google (Analytics 4, Tag Manager, Signals, Search Console), Meta Pixel, TikTok Pixel, Microsoft Clarity (session replay and heatmaps on our public website), and PostHog (EU-hosted product analytics and session replay for the signed-in app). The advertising pixels receive page-visit and conversion data from website visitors who consent. For a consenting Florida Partners participant, Meta or TikTok may also receive only one fixed broad vehicle type or merchant business type together with the saved Jacksonville or Tampa market; they do not receive the participant's address, ZIP, business name, plate, contact details, cargo, recipient, payment, refund, or dispute data with that event. The two session-replay tools (Clarity and PostHog) additionally receive the signed-in account's user ID and email address, after analytics consent, so we can find a specific account's sessions when supporting them; on app screens, all typing and all personal data — end-customer names, phone numbers, addresses, order contents, and driver details — are blanked in the browser before anything is sent; only general interface text (menus, buttons, labels, filters, and system messages) is visible in recordings, so we can see where the product confuses people without seeing anyone's personal data. See section 7 for details and opt-outs. NOTE: the absolute statement that “Google never receives order data” applies to these analytics/advertising products — it does NOT apply to Google Maps Platform (Routes/Places) above, which does receive delivery coordinates and typed address text for the purpose of routing and address lookup.
- Merchant-connected platforms (Shopify, WooCommerce, Wix, Salesforce, Monday, and others) — these are the general-SaaS merchant’s own systems that the merchant chooses to connect. Routella reads orders from and writes fulfillment status back to them on the merchant’s instruction. The merchant’s use of these platforms is governed by those platforms’ own terms.
- Selected Florida driver — receives the staged job information described in section 1A to decide and perform the delivery. The driver is an independent participant and may use recipient, address, access, and cargo information only for that job.
- Florida merchant — receives the selected driver's public Stripe business name and statement descriptor before fresh seller confirmation, plus job statuses, payment outcomes, and the receipt or refund records needed for its purchase and support.
- Native app merchant and recipient in a store-review or approved local program — receive only the accepted delivery's current progress and driver position, plus the proof status needed to follow, receive, support, or resolve that delivery, as described in section 1B.
5. How Long We Keep Data (Retention)
We keep data only as long as needed. The fixed windows below describe records that have automated database expiry or cleanup rules across the general SaaS product and the Routella Driver marketplace app.
We keep Florida Partners data only while it is needed to operate the participant account and accepted jobs, secure the service, keep accurate agreement and money records, answer refunds or disputes, and meet accounting, tax, fraud, safety, or other legal duties. When a participant closes an account or asks for deletion, Routella deletes or de-identifies eligible account and profile data. Some job, acceptance, payment, refund, dispute, receipt, tax, fraud, security, and audit records must remain where deletion would conflict with an existing transaction, another participant's record, or a legal duty. Routella does not promise one fixed period for all of those different records. Routella account deletion does not delete information Stripe independently must retain; requests about Stripe-held data must also follow Stripe's privacy process.
- Driver GPS location: 24 hours.
- Error logs: 14 days. When an account is permanently deleted, Routella may keep a separate privacy-minimized diagnostic summary for 14 days after closure so the owner team can understand a service failure that immediately preceded deletion. That summary contains only fixed error and action codes, timestamps, plan and billing-state codes, interface language, and coarse account-age/activity buckets. It does not contain names, email addresses, phone numbers, customer or driver details, addresses, coordinates, message content, raw requests, URLs, IP addresses, user-agent strings, stack traces, or the deleted workspace, and it expires automatically.
- Webhook delivery history: 30 days.
- Cron run records: 60 days.
- Public tracking-page view logs (with the IP stored only as a hash): 90 days.
- Sign-in events: 180 days.
- Personal-data access audit log: 365 days.
- Customer notification history and order-import history: 2 years.
- Orders, manual orders, and completed rounds: 5 years, or until the merchant deletes them, whichever is sooner.
- Saved recipient delivery preferences: kept only while the current versioned permission remains active. They stop being applied if that permission is missing or outdated, and the recipient can delete the saved row immediately from the signed tracking page; merchant account deletion also removes it.
- Private recipient delivery chat: the original message and its English, Spanish, and Hebrew copies stay with the exact account-bound delivery leg only while needed for that delivery, participant support, safety, a dispute, or another legal duty. Eligible chat rows are removed when the owning account is deleted. Replacing the assigned driver or rotating the recipient's signed tracking access removes the prior room before a new participant can use it. A completed or otherwise terminal delivery makes the existing thread read-only rather than allowing new messages.
- Shopify privacy-request records: kept up to 7 years for compliance evidence.
- Merchant account data: kept while the account is active; deleted within 30 days of account closure, except legal/billing records that law requires us to keep for up to 7 years.
6. Your Privacy Rights and How to Use Them
Depending on where you live, you have rights over your personal data. Email support@routella.app to ask for access, correction, export, deletion, restriction, objection, or another right that applies. For the general SaaS product, an end customer or merchant-managed driver should contact the merchant controller first and Routella, LLC will assist it. Routella Partners merchants and independent drivers may contact Routella directly for the marketplace records Routella controls. A recipient may contact the merchant that supplied the delivery details or Routella support, and Routella will route and answer the parts for which each party is responsible.
For a Facebook or Instagram conversation in a business's Routella MCP inbox, contact that business first or email support@routella.app so Routella can route the request. An authorized business administrator may request disconnection, export, or deletion of eligible stored conversations and profiles as explained in the Meta Business Messaging Privacy Notice linked above. Disconnecting the business account does not by itself delete its existing inbox history.
Core rights (GDPR, UK GDPR, PIPEDA, LGPD and similar): access a copy of your data; correct inaccurate data (merchants can correct most data directly in the dashboard); delete your account and associated data; export your data in machine-readable JSON; restrict or object to non-essential processing; and withdraw consent at any time for anything based on consent (withdrawing does not affect processing already done). Note that under the Australian Privacy Principles, erasure and portability are not standalone rights, but access and correction are.
General-SaaS drivers specifically: you can ask to access or delete your data through the merchant that added you, or by emailing us. General-SaaS location is tracked only while a delivery round is active and is deleted within 24 hours. Your merchant should inform you of this tracking as part of your relationship.
Recipients who chose the optional saved delivery preference can see and edit the exact preferred window and safe-spot note on their signed tracking page. Withdrawing is as direct as giving permission: choose Delete saved preferences on that same page. Future deliveries from that merchant then stop using the saved preference.
Florida Partners drivers in the current controlled web pilot specifically: this pilot statement does not apply to the Routella Driver mobile app described in the next paragraph. The controlled web pilot does not collect live location and remains subject to its accepted Florida documents. You may use the account export and deletion controls or email support. Deletion can be limited for an accepted job or for payment, dispute, fraud, tax, security, and legal records that still must be kept. Contact Stripe separately for identity, bank, payout, or other data Stripe controls.
Routella Driver store-review or approved-program drivers specifically: while you choose to be online, the native app may use foreground precise location to find nearby work; background location is used only while you are online with an active delivery and expires within 24 hours. You may use the permanent deletion control in Routella Driver, visit /delete-account if you cannot use the app, or email support. Deletion can be limited for an accepted job or for payment, dispute, fraud, tax, security, and legal records that still must be kept.
We do not make decisions about individuals by purely automated means that produce legal or similarly significant effects. General-SaaS route optimization and auto-dispatch are operational aids a merchant can override. Current Florida vehicle modes use saved declarations without routine Routella vehicle-document review. Routella gives no acceptance-rate penalty and requires human review before a harmful permanent account decision.
- California (CCPA/CPRA): you have the right to know what we collect, to delete, to correct, to opt out of “sale” or “sharing”, to limit use of sensitive personal information, and not to be discriminated against for exercising rights. We do not sell personal information. We do not use end-customer, recipient, cargo, document, payment, refund, or dispute data for advertising. With optional Marketing consent, a fixed broad Florida Partners vehicle or business category and Jacksonville or Tampa market may be used for a relevant Routella ad as described in sections 1A and 7. Advertising cookies and this narrow category event may count as “sharing” for cross-context behavioral advertising under CPRA — you can opt out using the “Do Not Sell or Share My Personal Information” or “Cookie settings” link at the bottom of this page (which lets you decline the Marketing category), and we honor the Global Privacy Control (GPC) browser signal as a valid opt-out. Categories we collect map to: identifiers, commercial information, geolocation (driver location; delivery coordinates), and internet/website-activity data for site visitors. You may use an authorized agent to submit a request.
- Shopify-installed merchants: we implement the three mandatory Shopify privacy webhooks — customers/data_request, customers/redact, and shop/redact. Each is HMAC-verified and audit-logged. Data requests are collected and emailed to the merchant within 30 days; redaction requests are processed promptly.
- Right to complain: if you are unhappy with our response, you can complain to your local supervisory authority — for example an EU/EEA data protection authority, the UK ICO, the Office of the Australian Information Commissioner (OAIC), the Office of the Privacy Commissioner of Canada (OPC), or Brazil’s ANPD.
7. Cookies, Website Analytics, and Advertising
Essential cookies are always used for authentication and session management. Public delivery tracking pages may store a delivery token in your browser’s local storage so a recipient does not have to re-enter it on refresh.
Non-essential analytics and advertising tools load only with your consent, managed through our cookie consent banner, split into two separate categories. Decline a category and those tools do not load. You can change your choice at any time using the “Cookie settings” link at the bottom of this page (or any Routella legal page); clearing site data for routella.app and reloading also re-opens it.
Analytics category: Google Analytics 4 and Google Tag Manager measure how visitors use our site. Google Analytics 4 has Google Signals enabled, which lets visitors who are signed in to a Google account with Ads Personalization on be deduplicated across devices and contribute to aggregated, anonymized demographic/interest reports; Routella receives only aggregated reports, never the underlying identity. When a consenting visitor signs up or upgrades, we may send a SHA-256 hash of their email to Google so it can match the conversion to an ad click — only the irreversible hash is sent; the raw email never leaves Routella. We have also linked Google Search Console, which uses search-query data Google already holds. We also use two session-replay tools, both loading only after analytics consent is granted. Microsoft Clarity records our public marketing and funnel pages in full detail; every other page — the app dashboard and customer/driver token pages — is captured only as a fully masked view (layout and clicks, no readable text or typing), and Clarity does not run inside the Shopify-embedded admin. PostHog (hosted in the EU) records our public marketing and funnel pages and the signed-in app — it does not load on customer/driver token pages or inside the Shopify-embedded admin. On the public marketing and funnel pages, which contain no end-customer or account data, it records in full detail (like Microsoft Clarity); the moment a visitor signs in, and everywhere in the signed-in app, its recordings are masked in the browser before anything leaves your device: every input and all personal data — end-customer and driver details — are blanked, while general interface text (menus, buttons, labels, error messages) stays visible, so what we can watch is which screens an account visits, where they click, and where they get stuck — never anyone's personal data. PostHog also records frustration signals (rapid repeated clicking, clicks that produce no response); these events carry only page addresses and element positions, never page content or typed text. Both session-replay tools mask form inputs on every page, and when you are signed in they are tagged with your account's user ID and email so our support can locate a specific account's sessions; logged-out visitors are recorded anonymously and are not tagged with any identity. Neither tool receives end-customer order data.
Marketing category: Google Ads Consent Mode (ad_storage), the Meta Pixel, and the TikTok Pixel measure advertising performance. If a Florida Partners driver saves a vehicle type, or a Florida Partners merchant saves a broad business type, Routella may send Meta or TikTok only that fixed category plus the saved Jacksonville or Tampa market so the person can see a more relevant Routella ad. The event contains no address, ZIP, business name, vehicle plate, phone, email, cargo text, recipient fact, payment fact, or user identifier. These providers do not receive end-customer order data for advertising. The Meta and TikTok pixels do not run inside the Shopify-embedded admin, and none of these tools load on preview or local builds — only on the production routella.app site.
To opt out of everything: decline the categories in the banner. To opt out of Google Signals specifically: turn off Ads Personalization at adssettings.google.com. To opt out of Google Analytics on every site: install Google’s official Analytics Opt-out Browser Add-on. California residents can also rely on the Global Privacy Control signal, which we honor.
8. International Data Transfers
Routella, LLC is a United States company, and Routella and its providers can process personal data in the United States, the EU/EEA, the United Kingdom, and other countries needed to provide the selected service. Personal data can therefore be stored or processed outside the place where it was collected. Routella and each independent provider are responsible for the transfer mechanism required for the data they control.
For EEA personal data transferred to a country without an applicable adequacy decision, we use the European Commission's 2021 Standard Contractual Clauses — controller-to-processor or processor-to-processor as the actual route requires — supported by a transfer assessment and supplementary measures where needed. We do not claim that Routella, LLC itself is covered by an adequacy decision unless a current, specific legal mechanism supports that claim.
For UK personal data transferred to a country without adequacy, we use the UK International Data Transfer Addendum to the EU Standard Contractual Clauses. We apply equivalent Swiss provisions where Swiss data is involved.
Delivering an SMS or WhatsApp message inherently routes it through carrier infrastructure in the recipient’s own country — this is unavoidable to reach that recipient.
9. Security
We use technical and organizational measures appropriate to the risk. No system can be guaranteed perfectly secure, but the measures below are real and in place. A fuller description is on our Security and Compliance page (/security).
- Encryption in transit: HTTPS / TLS 1.2 or later on all endpoints, including merchant connections, sub-processor calls, and customer tracking pages.
- Encryption at rest: AES-256 on the primary database and backups, plus an additional AES-256-GCM field-level encryption layer specifically on connected-store credentials, using a separately managed key. The application refuses to start in production if that key is missing.
- Passwords: hashed with bcrypt (cost factor 12); a minimum 10-character policy requiring letters and digits, with common passwords rejected; password-reset tokens are stored as SHA-256 hashes.
- Sign-in: optional passwordless one-time email code; sign-in endpoints are rate-limited and inputs are coerced to block injection.
- Logging: sign-in events and reads of personal-data records are audit-logged with timestamp, hashed IP, and user agent.
- Minimization by design: tracking-page and access logs store a hashed IP, not a raw IP. In a Routella Driver store-review or approved local program, location auto-expires after 24 hours, background location is limited to the period when the driver is online with an active delivery, and notification payloads omit earnings, payout and account status, suspension reasons, deadlines, route areas, precise addresses, contact details, and order contents. The current controlled Florida paid pilot remains limited as stated in section 1A.
- We commit to notifying affected merchants of a confirmed personal-data breach without undue delay and within 72 hours of becoming aware.
- Some operational measures (environment separation, backup restore testing, staff access reviews) are described on the Security page.
10. Children
Routella is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16. Merchants are responsible for ensuring any end-customer or driver data they enter has a lawful basis, including any data relating to minors. If we learn we hold a child’s data without a lawful basis, we delete it.
11. Changes to This Policy
We may update this Policy. Each version carries a “last updated” date and a version label. We communicate material changes by email and an in-app notice before they take effect, and where the law requires fresh consent we will ask for it again.
12. Contact and Data Protection
Controller and processor contact: Routella, LLC, a Delaware limited liability company operating Routella at routella.app.
Public business address: 131 Continental Dr, Suite 305, Newark, DE 19713, United States.
For privacy inquiries, data-subject or consumer rights requests, or to report a suspected incident: email support@routella.app or call the Routella business line at +44 7756 988088.
We have not appointed a statutory Data Protection Officer because we assess we are not required to under GDPR Article 37.
Routella, LLC operates both Routella services. The role-specific local Partners explanation takes priority for the marketplace scope it covers. The English version of this document is authoritative; any translation is provided for convenience only. Related documents: Terms · Privacy · DPA · Acceptable Use · Security. Questions: support@routella.app
Privacy controls: Cookie settings · Do Not Sell or Share My Personal Information