Privacy Policy
Effective July 17, 2026 · Last updated July 20, 2026
This Privacy Policy describes how Route Impact ("Route Impact," "we," "us") collects, uses, and shares information when you use the Route Impact application and related services (the "Service"). The Service is built for businesses — independent FedEx Ground contracted service providers — and this policy covers both account holders and the personal information contained in documents customers upload.
1. Information we collect
1.1 Account information
When you sign in (via Google Sign-In or email/password through Firebase Authentication), we collect your name, email address, and authentication identifiers. If you subscribe, our payment processor (Stripe) collects billing details; we receive subscription status and billing metadata but never store full card numbers.
1.2 Customer business data you upload
The Service analyzes documents and data you choose to upload or connect, which may include:
- FedEx settlement statements and related schedules
- Contracts, rate cards, and contract offers
- Payroll and compensation data (which may include driver and employee names, pay rates, and hours)
- Profit & loss statements and business transaction data
- Fleet and vehicle records
- Documents you add to your workspace library
You control what you upload. Personal information about your employees or contractors contained in these documents is collected on your behalf and processed to provide the Service to you; you are responsible for having the right to provide it (Terms §3.3).
1.3 Usage information
We collect log and usage data: pages and features used, analysis runs, device/browser type, IP address, and approximate location derived from it. We use Google Analytics (Firebase Analytics) for aggregate usage measurement.
1.4 Communications
If you contact support or reply to our emails, we keep the correspondence. Email digest interactions (delivery, unsubscribe) are tracked to honor your preferences.
2. How we use information
- Provide the Service: parse and analyze uploaded documents, run settlement audits, compute earnings trends, generate reports and AI-assisted advisory responses, deliver email digests and alerts.
- AI processing: portions of the Service send relevant Customer Data to our AI provider (Anthropic) to generate analyses and chat responses. Under our commercial agreement with Anthropic, API data is not used to train their models.
- Operate the business: billing, account management, support, service announcements.
- Improve the Service: debugging, usage analysis, feature development, and creation of anonymized Aggregated Data (Section 5).
- Security and legal: fraud prevention, enforcing our Terms, complying with law.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
3. How we share information
We share information only with:
- Service providers (subprocessors) who process it for us under contract:
- Google LLC — cloud hosting, database, file storage, authentication, analytics (Firebase / Google Cloud Platform, US)
- Anthropic, PBC — AI model API for analysis and advisory features (US)
- Stripe, Inc. — payment processing and billing (US)
- Postmark (ActiveCampaign, LLC) — transactional email delivery, including weekly digests (US)
- Brevo (Sendinblue Inc. / Sendinblue SAS) — customer relationship management and marketing email (US/EU)
- Third parties at your direction — if you ask us, in writing or through an in-product action, to share your data with a third party you designate (for example, your accountant, consultant, insurance broker, or lender). Their use of the data is governed by your relationship with them.
- Professional advisers and authorities where required by law, legal process, or to protect rights, safety, or the integrity of the Service.
- A successor entity in a merger, acquisition, or asset sale, in which case this policy continues to apply to previously collected data until amended per Section 10.
Within your organization, data you upload is visible to the users you authorize. Route Impact staff access customer accounts only for support, billing, or security purposes, and such access is logged.
This section lists our current subprocessors. We will update it before engaging a new subprocessor that processes Customer Data, and material changes are announced as described in Section 10.
4. Cookies and similar technologies
We use cookies and browser storage for sign-in sessions, preferences, and analytics. Blocking them may break sign-in.
5. Anonymized aggregate data
We create statistics aggregated across multiple customers and anonymized so they cannot reasonably identify any customer, individual, or contracted service area — for example, average revenue per stop among similarly sized operations. Benchmarks are computed only over cohorts of at least 8 organizations, so no customer's data can be singled out or re-identified. We use this Aggregated Data to operate, improve, and market the Service, including customer-facing benchmarking features. We may also license or share Aggregated Data with third parties — for example, industry partners such as insurers, lenders, consultants, or research organizations — provided it remains subject to the same anonymization and minimum-cohort protections at all times (Terms §7). Aggregated Data is not personal information and may be retained after account deletion. We never license or sell identifiable Customer Data or personal information.
6. Data retention and deletion
- Customer Data is retained while your account is active.
- You can delete individual analyses and documents at any time in the app.
- On account closure or verified request, we delete Customer Data within 30 days, except billing/tax records, minimal legal compliance records, and Aggregated Data (Section 5). System backups containing deleted data roll off within a further 30 days.
- Usage and log data (Section 1.3) is retained for a limited period — operational logs for roughly 30 days and aggregate analytics for up to 14 months — and support correspondence for as long as needed to resolve and document the matter.
7. Security
Data is encrypted in transit (TLS) and at rest (Google Cloud default encryption). Access is restricted by role-based permissions and organization-level isolation enforced in application code and in database and file-storage security rules; staff administrative actions are audit-logged. No system is perfectly secure. If we become aware of unauthorized access to or disclosure of your data, we will notify affected customers without undue delay, in addition to any notification required by applicable law (see Terms §10.3).
8. Your rights and choices
Depending on your jurisdiction, you may have rights to access, correct, delete, or export personal information, and to object to or restrict certain processing. To exercise these rights, contact us at the address below; we will verify and respond within the legally required period.
- Employees/contractors of our customers: your employer or contracting company controls the documents containing your information. We will direct requests concerning that data to them and assist in fulfilling them.
- Email preferences: digests can be downgraded (weekly → monthly) or turned off via the unsubscribe link in every digest; transactional and legal notices may still be sent.
9. Children
The Service is for business use by adults. We do not knowingly collect information from anyone under 18, and we delete it if discovered.
10. International transfers and changes
We operate from the United States and process data there. If you use the Service from elsewhere, you consent to processing in the US.
We may update this policy; material changes will be announced by email or in-app notice at least 30 days before taking effect.
11. Contact
Route Impact
Privacy contact: support@routeimpact.ai