ROUTEFLOW
Privacy Policy
Effective date: September 17, 2026
Last updated: September 17, 2026
RouteFlow (“RouteFlow,” “we,” “us,” or “our”) operates the RouteFlow platform — a multi-tenant software-as-a-service application for wholesale distributors that manages orders, delivery routes, invoices, payments, a buyer portal, and driver/operator mobile apps (collectively, the “Service”). This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the choices available to you.
This policy applies to the RouteFlow marketing website (routeflow.info), the RouteFlow web dashboard and buyer portal, and the RouteFlow mobile app for drivers and operators.
If you are a customer, driver, or other end user of a business that uses RouteFlow (a “Tenant”), please also see “Our role: controller vs. processor” below — in most cases the Tenant, not RouteFlow, controls how your information is used, and you should direct privacy requests to them first.
Who we are
Operator: Routeflow Solutions LLC, a Wyoming limited liability company (“RouteFlow”), 10701 Corporate Dr Ste 190, Stafford, TX 77477
General contact: hello@routeflow.info
Security / vulnerability reports: security@routeflow.info
Website: https://www.routeflow.info
Our role: controller vs. processor
RouteFlow is a B2B platform. Businesses (“Tenants”) sign up for RouteFlow to run their own distribution operations, and their staff invite or add their own customers (buyers) and drivers into the system.
Where RouteFlow is a processor. For data that Tenants put into the Service about their own customers, buyers, drivers, orders, invoices, and deliveries, the Tenant is the data controller and RouteFlow acts only as a data processor (or “service provider”), processing that data solely to provide the Service under our agreement with the Tenant. If you are a customer, buyer, or driver of a RouteFlow Tenant and have a question or request about your personal data, please contact that business directly; we will assist them in responding as required by applicable law.
Where RouteFlow is a controller. For data about the Tenant’s own account — account holders, billing contacts, staff user accounts, subscription and payment records, support communications, and marketing-site visitors — RouteFlow is the data controller and this policy describes our own practices directly.
Information we collect
Information Tenants and their users provide
- Account & staff data: name, email, phone, role, password (hashed), tenant/company name.
- Customer (buyer) records: business name, contact name, email, phone, delivery address, order history, pricing tier, and communications entered by the Tenant or by the buyer through the buyer portal.
- Driver data: name, contact info, assigned routes/vehicles, and — while an active delivery route is in progress — real-time and route-history location data (see “Location data” below).
- Order, route, and delivery data: orders, line items, delivery stops, route sequencing, proof-of-delivery (POD) photos, signatures, and delivery notes.
- Financial data: invoices, credit notes, vendor bills, payment records (including post-dated check details where a Tenant uses that feature), and billing history. Card payments are processed by Stripe; RouteFlow does not store full card numbers.
- Uploaded files: product images, receipts, supplier statements/invoices, and other documents Tenants upload to the Service.
- Support & communications: messages sent to hello@routeflow.info or security@routeflow.info, or through in-app support/notification features.
- Demo booking requests: if you book a product walkthrough on routeflow.info, we collect your name, email, company, optional phone number and notes, your selected meeting time and time zone, and your IP address. See “Demo booking requests” below for how this is stored and scheduled.
Information collected automatically
- Usage & device data: IP address, browser/device type, pages viewed, and actions taken in the web dashboard and mobile app, collected for security, debugging, and service-reliability purposes.
- Cookies (web): RouteFlow’s web app uses a small number of strictly necessary cookies to keep you signed in and route you to the correct portal (e.g., an authentication-presence cookie and a “last portal used” cookie). These cookies do not track you across other websites. We do not currently use third-party advertising or analytics cookies.
- Location data (mobile, drivers only): while a driver is actively running a delivery route, the RouteFlow mobile app collects device location — including in the background while the route is in progress — so dispatch/operators can see live route progress, sequence stops, and confirm deliveries. Location is not collected outside of an active route, and is not collected from customer/buyer or operator (non-driver) accounts. Drivers can disable location sharing in their device settings, which will prevent live tracking from functioning.
- Camera & photos (mobile): the mobile app requests camera access to scan product barcodes and to photograph receipts, supplier bills, product images, and proof-of-delivery. It requests photo-library access so users can attach existing photos (e.g., receipts) instead of taking a new one. Camera/photo access is used only for these in-app features; RouteFlow does not access your device’s photo library or camera outside of an explicit in-app action.
Information from third parties
- Google Sign-In: if you sign in with Google, we receive your name, email address, and Google account ID from Google to create or authenticate your RouteFlow account.
- Optional CRM sync (per-Tenant): a Tenant may connect a third-party CRM — currently GoHighLevel — to sync contact and opportunity records (name, email, phone, tags, notes, deal/opportunity status) between that CRM and RouteFlow. This is off by default and controlled entirely by the Tenant.
- Optional data import (per-Tenant): a Tenant may import historical business data from a source system (for example, Zoho CRM) when onboarding onto RouteFlow.
How we use information
We use the information described above to:
- provide, operate, and maintain the Service (accounts, orders, routing, invoicing, payments, notifications);
- authenticate users and secure accounts;
- optimize delivery routes (delivery stop addresses/coordinates are sent to our routing engine — see “Sub-processors” — solely to compute route sequencing and ETAs);
- process payments and manage subscriptions and billing;
- send transactional communications (order confirmations, invoices, password resets, route notifications);
- provide customer support and respond to inquiries sent to hello@routeflow.info or security@routeflow.info;
- detect, investigate, and prevent fraud, abuse, and security incidents;
- comply with legal obligations (e.g., tax and accounting records); and
- improve the reliability and performance of the Service.
We do not sell personal information, and we do not use Tenant, customer, or driver data to serve third-party advertising.
Sub-processors and service providers
We share information with the following categories of service providers, each of which processes data on our behalf and only as needed to provide the Service. This list reflects what the RouteFlow codebase and infrastructure actually use as of this document’s last-updated date above.
| Provider | Purpose | Data involved |
|---|---|---|
| Railway (United States) | Application hosting, PostgreSQL database, Redis cache | All Service data described above |
| Stripe | Subscription billing and payment processing | Billing contact info, subscription/plan data, payment tokens (not full card numbers) |
| Sign-In authentication; Google Maps (route/map display); Firebase Cloud Messaging (push notifications); Google Calendar (internal scheduling of demo-booking meetings, via a RouteFlow-owned service account) | Name/email/account ID (Sign-In); delivery addresses/coordinates (Maps); device push token (FCM); demo-booking contact details placed on RouteFlow’s internal calendar event | |
| Google Workspace (primary) | RouteFlow’s primary platform transactional email delivery (order confirmations, invoices, password resets, demo-booking confirmations, etc.), sent through RouteFlow’s own Google Workspace mailbox via SMTP; also hosts RouteFlow’s own business inboxes | Recipient email address, email content, and the contents of messages sent to our business inboxes |
| Resend (fallback) | Fallback platform transactional email delivery, used automatically only when RouteFlow’s Google Workspace SMTP is not configured | Recipient email address and email content |
| OpenRouteService (ORS) | Route optimization engine | Delivery stop addresses/coordinates, sent solely to compute optimized route sequencing |
| Cloudflare R2 / Railway volume storage | File storage for uploaded documents and images | Product images, receipts, supplier statements, proof-of-delivery photos |
| Anthropic (Claude API) | Optional AI-assisted scanning of supplier statements/invoices, when a Tenant enables this feature | Uploaded supplier statement/document images and extracted line-item data |
| GoHighLevel | Optional per-Tenant CRM sync (off by default) | Contact/opportunity name, email, phone, tags, notes |
| Zoho CRM | Optional per-Tenant data import source during onboarding | Historical business records imported by the Tenant |
| Sentry | Optional error monitoring, when configured | Technical error/crash data; may incidentally include portions of application state at time of error |
We may add or change sub-processors as the Service evolves; material changes will be reflected in an updated version of this policy.
Coming soon: connecting your own email account (“Connect Gmail/Outlook”)
RouteFlow is building an optional feature that lets a Tenant admin connect their own Gmail or Microsoft 365/Outlook mailbox so that customer-facing emails (like invoices and order notifications) are sent from the Tenant’s own address instead of RouteFlow’s. When this feature is live and a Tenant chooses to use it:
- RouteFlow requests only a send-only permission — Google’s
gmail.sendscope or Microsoft Graph’sMail.Sendpermission. RouteFlow cannot read, search, or otherwise access the contents of your mailbox, inbox, or any other email in your account. - RouteFlow uses this permission only to send the specific transactional emails the Tenant’s business generates through RouteFlow (e.g., invoices, order confirmations).
- The connection’s access/refresh tokens are stored encrypted at rest and are never logged or displayed after the initial connection.
- Disconnecting the mailbox immediately and permanently deletes the stored tokens from RouteFlow’s systems.
Google API Services User Data Policy — Limited Use disclosure
RouteFlow’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In substance, this means RouteFlow:
- limits its use of data obtained through Google API scopes to providing or improving the user-facing features described above;
- does not transfer that data to third parties except as needed to provide or improve those features (with consent), for security purposes, to comply with law, or as part of a merger/acquisition (with notice);
- does not allow humans to read that data except with explicit user consent, for security purposes, to comply with law, or on an aggregated and anonymized basis for internal operations; and
- does not use that data to serve advertisements (including retargeting or interest-based advertising), and does not use it to determine creditworthiness or for lending purposes.
Demo booking requests (marketing site)
The “Request a demo” scheduler on routeflow.info lets a visitor book a walkthrough meeting directly. When you submit a booking, we collect and store in RouteFlow’s own database: your name, email address, company name, phone number (optional), notes on what you’d like covered (optional), your selected date/time and time zone, the marketing page you booked from, and your IP address (used to prevent abuse of the booking system).
To schedule the meeting internally, RouteFlow creates an event on RouteFlow’s own Google Calendar (via a RouteFlow-owned service account, not your Google account), containing your name, company, contact email/phone, and notes so our team can prepare. Your email address is not added as a Google Calendar attendee/invitee — Google does not send you a calendar invite, and no Google account of yours is involved. Your booking confirmation, and any reschedule/cancellation link, is emailed to you directly by RouteFlow.
The confirmation email contains a link that lets you reschedule or cancel your own booking; RouteFlow stores only a one-way cryptographic hash of that link’s token, not the token itself, so the token cannot be recovered from our database.
Demo booking records are retained for 12 months unless you become a RouteFlow Tenant, in which case ordinary account data retention applies (see “Data retention” below).
Data retention
- We retain Tenant account and operational data (orders, invoices, routes, uploaded documents, etc.) for as long as the Tenant’s subscription is active, plus 30 days to allow account recovery, and as needed to satisfy tax, accounting, and legal recordkeeping obligations.
- Driver location data collected during a delivery route is retained for 90 days and used only for route history and delivery confirmation.
- We retain marketing-site inquiries and support communications for up to 24 months.
- We delete or anonymize personal information when it is no longer needed for the purposes described in this policy, or sooner upon a valid deletion request (see “Your rights and choices” below).
Your rights and choices
Depending on your location and relationship to RouteFlow, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing.
- If you are a customer, buyer, or driver of a Tenant: please contact that business directly — they control your data and are best positioned to fulfill your request. We will support them in doing so.
- If you are a Tenant account holder, staff user, or website visitor contacting RouteFlow directly: email hello@routeflow.info with your request. We will respond within 30 days and may need to verify your identity before acting on the request.
- You can also access and update most of your account information directly within the RouteFlow web dashboard, buyer portal, or mobile app settings.
If you are located in the European Economic Area, the United Kingdom, Switzerland, California, or another jurisdiction with its own data-protection law, you may have additional rights under that law — for example, the right to lodge a complaint with your local data protection authority, or California’s right to know, delete, or opt out of the sale or sharing of personal information. As noted above, RouteFlow does not sell personal information. To exercise any of these rights, contact hello@routeflow.info.
Data security
We use industry-standard safeguards to protect information, including encryption of sensitive data at rest (e.g., stored third-party credentials and connected-mailbox tokens), encrypted connections (TLS) in transit, and access controls scoped per Tenant. No method of transmission or storage is 100% secure. If you discover a potential security vulnerability, please report it to security@routeflow.info — see our Security Policy for our responsible-disclosure process.
International data transfers
RouteFlow’s infrastructure is hosted in the United States (via Railway). If you access the Service from outside the United States, your information will be transferred to and processed in the United States. Where required, we rely on the European Commission’s Standard Contractual Clauses (or an equivalent lawful transfer mechanism) to safeguard personal information transferred from the EEA, UK, or Switzerland to the United States.
Children’s privacy
The Service is a business tool intended for use by adults acting on behalf of a business. RouteFlow is not directed to children, and we do not knowingly collect personal information from anyone under the age of 18. If you believe a child has provided us with personal information, please contact hello@routeflow.info so we can delete it.
Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice (such as an in-app notice or email to Tenant account holders). Your continued use of the Service after a change takes effect constitutes acceptance of the updated policy.
Governing law
This Privacy Policy is governed by the laws of the State of Wyoming, USA, without regard to its conflict-of-laws principles. Any dispute arising out of or relating to this Privacy Policy will be brought exclusively in the state or federal courts located in Wyoming, USA, and you consent to the personal jurisdiction of those courts.
Contact us
Questions about this Privacy Policy or our data practices:
- Email: hello@routeflow.info
- Security reports: security@routeflow.info
- Mail: 10701 Corporate Dr Ste 190, Stafford, TX 77477