Privacy Policy
Last updated: August 20, 2026
Introduction
RoutelyOS ("we," "our," or "us") operates the RoutelyOS field service management platform at routelyos.com. This Privacy Policy explains how we collect, use, disclose, and safeguard information when a franchise business, its field workers, or its end customers use the platform. RoutelyOS is business-to-business software — most data we process belongs to the franchise accounts we serve, who are themselves responsible for their own customers' data under their agreement with us.
Information We Collect
Franchise account data: business and contact information, job and scheduling records, pricing configuration, and payment/payout details processed through Stripe.
Field worker data: name, contact information, equipment and skill configuration, and — when completing a job — device GPS location, used only to verify job completion against the job site and never tracked outside active job workflows.
End-customer data (on behalf of a franchise): name, contact information, service address, and payment details submitted through a franchise's booking flow. This data is controlled by the franchise; RoutelyOS processes it as a service provider.
Job photographs (on behalf of a franchise): before-and-after images of an end customer's property, captured by field workers to evidence the work performed. Stored in a private bucket and served only through short-lived signed URLs. Publishing any of them requires an explicit end-customer decision recorded per job; RoutelyOS defaults that decision to no and provides no way for a franchise to override it in bulk. Like other end-customer data, these are controlled by the franchise and processed by RoutelyOS as a service provider.
Automatically collected: device information, browser type, IP address, and interaction data, collected for security (rate limiting, abuse prevention) and product analytics.
How We Use Data
To operate dispatch, scheduling, routing, and payment workflows; to verify job completion; to process worker payouts and customer payments; to secure the platform against abuse; to communicate service updates; and to comply with legal obligations.
Subprocessors
RoutelyOS relies on the following subprocessors, each bound by its own data protection terms:
Supabase — database, authentication, and file storage, with row-level security enforced on every table.
Stripe — payment processing and worker payouts (Stripe Connect). Card details are never stored on our servers.
Twilio — SMS notifications, with STOP/START opt-out honored platform-wide.
Resend / SendGrid — transactional email.
Sentry — error monitoring, used to catch and fix bugs, not to profile individual users.
Google (Gemini API) — the AI features described below. Text we send for processing is not used to train Google's models under the paid API terms.
Vercel — application hosting and aggregate web analytics.
Google Analytics — usage analytics, loaded only after you accept cookies. Analytics and advertising storage are denied by default until consent is given.
We do not sell personal information to third parties.
AI and Automated Processing
Parts of RoutelyOS use AI to draft text and summarise operational data. The model provider is Google (Gemini API); we do not run our own models.
What gets sent. When a worker emails a time-off request, the content of that message is sent to the model so the reply can refer to what they actually wrote. AI is also used to summarise business metrics, score inbound leads, suggest pricing, and draft marketing copy — those run on operational data such as job and quote records.
What it does not decide. AI does not make the approval decision on a time-off request, and it cannot change one. The decision is computed in code before any model is called, and the reply must contain the matching status text or the system discards the AI draft and sends a fixed template instead. If the model is unavailable, the template is used.
Human review. A manager can review and override any AI-assisted outcome. To ask which of your data has been processed this way, or to request that it not be, contact us using the details below.
Data Retention
Operational data (jobs, schedules, payments) is retained for as long as a franchise account is active and as needed to meet tax and legal recordkeeping obligations. A franchise may request deletion of its account data; some records may be retained longer where required by law (e.g. financial transaction records).
Data Security
Every database table is protected by row-level security scoped to the owning franchise. Data is encrypted in transit (TLS) and at rest. Stripe webhooks are cryptographically verified. Access to production systems is limited to authorized personnel.
Your Rights
Depending on your jurisdiction and your relationship to the platform (franchise account holder, field worker, or end customer of a franchise), you may have the right to access, correct, or request deletion of your personal data. If you are an end customer of a franchise using RoutelyOS, please contact that franchise directly first — they control your data as the merchant of record. Otherwise, contact us using the information below.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated "Last updated" date.
Contact Us
Questions about this Privacy Policy can be sent to support@routelyos.com