Privacy Policy
Effective July 17, 2026 · Last updated September 6, 2026
This Privacy Policy describes how Route Impact ("Route Impact," "we," "us") collects, uses, and shares information when you use the Route Impact application and related services (the "Service"). The Service is built for businesses — independent FedEx Ground contracted service providers — and this policy covers both account holders and the personal information contained in documents customers upload.
1. Information we collect
1.1 Account information
When you sign in (via Google Sign-In or email/password through Firebase Authentication), we collect your name, email address, and authentication identifiers. If you subscribe, our payment processor (Stripe) collects billing details; we receive subscription status and billing metadata but never store full card numbers.
1.2 Customer business data you upload or connect
The Service analyzes documents and data you choose to upload or connect, which may include:
- FedEx settlement statements and related schedules
- Contracts, rate cards, and contract offers
- Payroll and compensation data (which may include driver and employee names, pay rates, and hours)
- Profit & loss statements and business transaction data
- Fleet and vehicle records
- Documents you add to your workspace library
If you install the Route Impact browser extension, it collects these same business records directly from the FedEx and dispatch portals you are signed into — from your own browser session, at your direction — and sends them to your Route Impact account. The extension stores a Route Impact sign-in credential on your device so it can write to your account; it never receives, sees, or stores your FedEx or other portal credentials. You can disconnect it at any time from the extension itself, which stops all further collection.
If you connect QuickBooks Online, we read your accounting records directly from Intuit using your authorization. The connection is read-only: we never create, change, or delete anything in your QuickBooks company. We read your chart of accounts, profit-and-loss figures, deposits and payments, your individual expense and purchase transactions (including credit-card, cash and check spend), vendor and bill records, and your company's accounting preferences (such as whether you keep your books on a cash or accrual basis) — the records needed to show your real costs beside your FedEx revenue instead of estimating them. Because a chart of accounts and its transactions describe an entire business, this may incidentally include entries that are personal rather than operational; Section 2 explains how mapping lets you exclude those.
We never receive, see, or store your Intuit username or password. Authorization uses OAuth, which gives us a revocable token limited to reading accounting data, and we store that token encrypted (Section 7). You can disconnect at any time, either in Route Impact or from inside QuickBooks; disconnecting revokes our access immediately and stops all further collection.
You control what you upload and what you connect. Personal information about your employees or contractors contained in these documents is collected on your behalf and processed to provide the Service to you; you are responsible for having the right to provide it (Terms §3.3).
1.3 Usage information
We collect log and usage data: pages and features used, analysis runs, device/browser type, IP address, and approximate location derived from it. We use Google Analytics (Firebase Analytics) for aggregate usage measurement.
1.4 Communications
If you contact support or reply to our emails, we keep the correspondence. Email digest interactions (delivery, unsubscribe) are tracked to honor your preferences.
2. How we use information
- Provide the Service: parse and analyze uploaded documents, run settlement audits, compute earnings trends, generate reports and AI-assisted advisory responses, deliver email digests and alerts.
- AI processing: portions of the Service send relevant Customer Data to our AI provider (Anthropic) to generate analyses and chat responses. Under our commercial agreement with Anthropic, API data is not used to train their models. Voice conversations additionally use Google Cloud Speech-to-Text to transcribe what you say and ElevenLabs to speak the reply aloud; the no-training commitment described here is specific to Anthropic, and Section 3 lists every provider involved.
- Operate the business: billing, account management, support, service announcements.
- Improve the Service: debugging, usage analysis, feature development, and creation of anonymized Aggregated Data (Section 5).
- Security and legal: fraud prevention, enforcing our Terms, complying with law.
We do not sell personal information for money, and we never use Customer Data — your settlements, payroll, documents, or anything else you upload — for advertising.
We do use advertising cookies on our public marketing pages to show ads to people who have visited us, on services such as Facebook, Instagram, YouTube, and Google. Several state privacy laws classify this as “sharing” personal information for cross-context behavioral advertising, and we describe it that way rather than relying on a narrower reading. It is limited in two ways that we enforce in code, not just in policy: it applies only to the public pages listed in Section 4, and never to any page you reach after signing in. See Section 4 for how to opt out.
3. How we share information
We share information only with:
- Service providers (subprocessors) who process it for us under contract:
- Google LLC — cloud hosting, database, file storage, authentication, analytics, document text extraction, and speech-to-text transcription for voice conversations (Firebase / Google Cloud Platform, US)
- Anthropic, PBC — AI model API for analysis and advisory features (US)
- ElevenLabs Inc. — text-to-speech for spoken replies in voice conversations (US). It receives the text of the reply being spoken, which can include figures drawn from your operation data. It does not receive your uploaded documents.
- Stripe, Inc. — payment processing and billing (US)
- Postmark (ActiveCampaign, LLC) — transactional email delivery, including weekly digests (US)
- Brevo (Sendinblue Inc. / Sendinblue SAS) — customer relationship management and marketing email (US/EU)
- Advertising partners who receive limited page-visit information from our public marketing pages so we can show ads to people who have visited the site:
- Meta Platforms, Inc. — Facebook and Instagram advertising (US)
- Google LLC — Google Ads and YouTube advertising (US)
- Third parties at your direction — if you ask us, in writing or through an in-product action, to share your data with a third party you designate (for example, your accountant, consultant, insurance broker, or lender). Their use of the data is governed by your relationship with them.
- Professional advisers and authorities where required by law, legal process, or to protect rights, safety, or the integrity of the Service.
- A successor entity in a merger, acquisition, or asset sale, in which case this policy continues to apply to previously collected data until amended per Section 10.
Within your organization, data you upload is visible to the users you authorize. Route Impact staff access customer accounts only for support, billing, or security purposes, and such access is logged.
This section lists our current subprocessors. We will update it before engaging a new subprocessor that processes Customer Data, and material changes are announced as described in Section 10.
Intuit Inc. is deliberately not in the subprocessor list above. Intuit is a source we read from at your direction, not a provider that processes your data for us: connecting QuickBooks sends your accounting records to Route Impact, and we do not send your Route Impact data — settlements, payroll, documents or analyses — to Intuit. Your use of QuickBooks itself remains governed by your own agreement with Intuit.
4. Cookies and similar technologies
We use cookies and browser storage for sign-in sessions, preferences, and analytics. Blocking them may break sign-in.
Advertising cookies. On our public marketing pages only — the home page, sign-in page, /listings, /teardown, /checklist, /tools, /white-glove, the blog, and these Terms and Privacy pages — we also load advertising tags from Meta and Google. These let us show ads to people who have already visited, and let us tell whether an ad led to a sign-up.
These tags are not loaded on any page you reach after signing in. Your dashboard, earnings, finance, labor, fleet, workspace, advisor, billing, settings, analysis results, and the data room load no advertising tag at all.
How to opt out. Any of these works:
- Turn on Global Privacy Control in your browser or extension. We read it and load no advertising tag when it is set.
- Block third-party cookies, or use any tracker-blocking extension. Nothing about the Service depends on advertising cookies.
- Adjust ad personalization directly at the source — Meta’s Ad Preferences, and Google’s My Ad Center.
Opting out does not change what the Service does or what you can see.
5. Anonymized aggregate data
We create statistics aggregated across multiple customers and anonymized so they cannot reasonably identify any customer, individual, or contracted service area — for example, average revenue per stop among similarly sized operations. Benchmarks are computed only over cohorts of at least 8 organizations, so no customer's data can be singled out or re-identified. We use this Aggregated Data to operate, improve, and market the Service, including customer-facing benchmarking features. We may also license or share Aggregated Data with third parties — for example, industry partners such as insurers, lenders, consultants, or research organizations — provided it remains subject to the same anonymization and minimum-cohort protections at all times (Terms §7). Aggregated Data is not personal information and may be retained after account deletion. We never license or sell identifiable Customer Data or personal information.
6. Data retention and deletion
- Customer Data is retained while your account is active.
- You can delete individual analyses and documents at any time in the app.
- On account closure or verified request, we delete Customer Data within 30 days, except billing/tax records, minimal legal compliance records, and Aggregated Data (Section 5). System backups containing deleted data roll off within a further 30 days.
- Disconnecting QuickBooks revokes our access immediately and deletes the stored authorization token. Accounting data already read is kept and stops updating, so your history and any analysis built on it survive the disconnection; wherever we show it, we show the date it was last read. You can delete it at any time, and it is deleted with the rest of your Customer Data on account closure.
- Usage and log data (Section 1.3) is retained for a limited period — operational logs for roughly 30 days and aggregate analytics for up to 14 months — and support correspondence for as long as needed to resolve and document the matter.
7. Security
Data is encrypted in transit (TLS) and at rest (Google Cloud default encryption). Authorization tokens for connected accounting services are additionally encrypted by us with a dedicated, automatically rotated key held in Google Cloud Key Management Service, so that reading them requires both database access and a separate decryption permission; each token is cryptographically bound to the organization it belongs to and cannot be used under another. Only the account owner can connect or disconnect an accounting service, and both actions are audit-logged. Access is restricted by role-based permissions and organization-level isolation enforced in application code and in database and file-storage security rules; staff administrative actions are audit-logged. No system is perfectly secure. If we become aware of unauthorized access to or disclosure of your data, we will notify affected customers without undue delay, in addition to any notification required by applicable law (see Terms §10.3).
8. Your rights and choices
Depending on your jurisdiction, you may have rights to access, correct, delete, or export personal information, and to object to or restrict certain processing. To exercise these rights, contact us at the address below; we will verify and respond within the legally required period.
- Employees/contractors of our customers: your employer or contracting company controls the documents containing your information. We will direct requests concerning that data to them and assist in fulfilling them.
- Email preferences: digests can be downgraded (weekly → monthly) or turned off via the unsubscribe link in every digest; transactional and legal notices may still be sent.
9. Children
The Service is for business use by adults. We do not knowingly collect information from anyone under 18, and we delete it if discovered.
10. International transfers and changes
We operate from the United States and process data there. If you use the Service from elsewhere, you consent to processing in the US.
We may update this policy; material changes will be announced by email or in-app notice at least 30 days before taking effect.
11. Contact
Route Impact
Privacy contact: support@routeimpact.ai