EfiRoute

Privacy Policy

Last updated: June 14, 2026

At EfiRoute, we process personal data lawfully, securely, and transparently. This policy applies to all users of our web platform, API service, and courier mobile application.

1. Data Controller

The data controller is EfiRoute. Contact: info@efiroute.com

2. Data We Collect

Identity and contact details: Name, surname, email address, phone number, and company information collected during account creation and login.

Precise location data: The courier mobile app collects real-time GPS coordinates (latitude/longitude) throughout an active delivery task and transmits them to our servers. Location tracking is active only for the duration of the task; it stops automatically when the task is completed or the app is closed. Background location permission is used solely during active tasks.

Voice recordings: Push-to-talk (PTT) voice notes recorded via the in-app chat feature are uploaded to Google Cloud Storage and shared only with the relevant chat participants.

Photos and media: Photos shared as delivery proof or chat attachments are uploaded to Google Cloud Storage.

Messages: In-app chat messages (text and media) are stored on our servers and visible only to task participants (courier and dispatcher).

Payment and financial information: Subscription and payment data processed via Stripe. Sensitive payment details such as card numbers or CVV are never transmitted to EfiRoute servers; they are handled directly by Stripe.

Device and technical data: IP address, device model, OS version, app version, and error logs collected to maintain service health and for debugging.

Usage data: Anonymous or pseudonymous statistics on feature usage frequency, processed to improve the product.

3. Purposes of Processing

Service delivery: Route optimization, real-time courier tracking, delivery notifications, and customer management.

Communication: Password reset, system notifications, and support requests via the Postmark email service.

Payment management: Processing subscriptions and usage fees via Stripe, generating invoices.

Security and compliance: Preventing unauthorized access, detecting misuse, and fulfilling legal obligations.

Error tracking and performance: Detecting errors via Sentry and monitoring system performance.

Product development: Analyzing usage statistics to design new features and improve existing ones.

4. Legal Basis (GDPR)

Contract performance (Art. 6/1/b): Processing necessary for the core functions of the service (location tracking, chat, delivery management).

Legitimate interests (Art. 6/1/f): Error tracking, security, and fraud prevention.

Legal obligation (Art. 6/1/c): Tax, accounting, and audit requirements.

Explicit consent (Art. 6/1/a): Non-essential marketing communications and analytics cookies.

5. Third-Party Service Providers

Google Cloud Platform: Server infrastructure, Route Optimization API, Maps services, and media storage (Cloud Storage). Data is processed in EU/US data centers.

Stripe: Payment processing and subscription management. Stripe's own privacy policy applies.

Postmark: Email delivery (password reset, notifications).

Sentry: Error tracking and performance monitoring. Logs are minimized to avoid containing personal identifiers.

Firebase (Google): Mobile app distribution and push notification infrastructure.

Data Processing Agreements (DPA) are in place with all service providers. Data is never shared with third parties for marketing or advertising purposes.

6. Retention Periods

Account data: Retained while the account is active. Upon account deletion, personal data is anonymized or deleted within 30 days.

Location history: Location records for completed delivery routes are retained for 90 days, then automatically deleted.

Voice notes and photos: Permanently deleted within 30 days after the related task or chat is removed.

Payment records: Retained for 10 years to meet tax and accounting obligations.

Error logs: Retained for 30 days.

7. Data Security

All data in transit is encrypted with TLS 1.2+. Stored data is protected with AES-256 encryption.

Access authorization is managed using role-based access control (RBAC); employees can only access data required for their role.

To report security vulnerabilities: info@efiroute.com

8. App Permissions (Mobile)

Precise location (ACCESS_FINE_LOCATION / ACCESS_BACKGROUND_LOCATION): Required for real-time tracking during active delivery tasks.

Camera (CAMERA): Used to capture delivery proof photos.

Microphone (RECORD_AUDIO): Used for PTT voice note recording.

Notifications (POST_NOTIFICATIONS): Used for task assignment and message alerts.

Storage (READ_EXTERNAL_STORAGE, API ≤ 32): Used for media selection on Android 12 and below only.

9. Your Rights

Right of access: Learn what data we process about you.

Right to rectification: Request correction of inaccurate or incomplete data.

Right to erasure ("right to be forgotten"): Request deletion of your data (subject to legal retention obligations).

Right to restriction: Stop certain processing activities.

Right to data portability: Receive your data in a machine-readable format.

Right to object: Object to processing based on legitimate interests.

Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time.

To request account deletion: efiroute.com/account-deletion or info@efiroute.com

EU/EEA users may lodge a complaint with the data protection authority in their country.

10. Cookies

Our web platform uses essential cookies for session management. Analytics or marketing cookies are only activated with your explicit consent.

11. Children's Privacy

Our service is not directed at individuals under 16. We do not knowingly collect data from such individuals. If data is collected inadvertently, contact info@efiroute.com.

12. Policy Changes

Significant changes to this policy will be communicated via email or in-app notification. The current policy is always available at efiroute.com/privacy-policy.

13. Contact

For privacy requests: info@efiroute.com

Account deletion: efiroute.com/account-deletion

legal.termsOfUse·legal.privacyPolicy·legal.accountDeletion·legal.dataDeletion·