Privacy Policy

Legal

Privacy Policy

Last updated: 2026-07-20

1) Who we are

Developer: RutaLive

Email: [email protected]

Website: https://rutalive.com

2) Our role — controller and processor

RutaLive is software. The delivery work itself is carried out by our customers. An Operator is a courier or delivery company that subscribes to the platform and runs its own business on it, with its own couriers, its own vehicles, its own clients and its own prices. RutaLive owns no vehicles, employs no couriers, dispatches no deliveries itself, and never takes custody of any goods.

That distinction decides who is responsible for which data. For some data we decide why and how it is processed, and we are the controller. For other data the Operator decides, and we only hold and process it on that Operator's behalf, as a processor (also called a service provider under United States state law).

This split governs the whole document. Where a later section says "we collect" or "we use" in relation to a category listed in Section 2.2, it means that we carry out that activity on the Operator's documented instructions in order to provide the platform — not that we have decided the purpose ourselves.

2.1 Where RutaLive is the controller

• Account and profile data of the operator — the person or company that registers with us directly — including name, email address, phone number, company name, role and password. For courier, client and dispatcher accounts, which an Operator creates, see Section 2.3.

• Subscription and billing data — plan, billing email, billing and tax address, payment status and subscription history.

• Support correspondence — the messages you send us and our replies.

• Marketing-website analytics and advertising measurement, as described in Section 22.

• Our own product telemetry — crash reports, performance diagnostics, aggregate usage statistics, and security, rate-limiting and abuse-prevention logs.

For these categories we determine the purposes and means of processing, and this policy is our own notice to you.

2.2 Where RutaLive is a processor for an Operator

• Order and delivery records created inside an Operator's workspace, including pickup and delivery addresses, order contents descriptions, special instructions, schedules and statuses.

• Personal data about delivery recipients and other people who never created an account — see Section 9.

• Courier location data, including the live position shown on the Operator's map — see Section 10.

• Proof of delivery — photographs, digital signatures, QR scan records, and the coordinates recorded at the moment of capture.

• Chat messages exchanged between an Operator, including the dispatcher accounts acting for it, its couriers and its clients.

• Invoices, accounting records, courier payout records, and data an Operator chooses to synchronise to its own QuickBooks Online company.

For these categories the Operator is the controller. We process them only to provide the platform to that Operator and on that Operator's instructions. We do not use them for our own purposes and do not sell them, and they are never used for advertising — see Section 14.2. If the Operator has its own privacy notice, that notice governs the Operator's use of your data; this policy describes what we do as its service provider.

2.3 Couriers, clients and dispatchers

Courier, client and dispatcher accounts are created by an Operator, not by us, and there is no self-registration for these roles in the mobile App. We act as controller for the account credentials and the security records needed to operate sign-in — for example the password hash, session records and login rate-limiting. We act as processor for everything that account then does inside the Operator's workspace.

3) Data Processing Agreement

Business customers who need a written Data Processing Agreement covering the categories in Section 2.2 can request one from us at [email protected]. Tell us the account the request relates to and the regime it needs to address, and we will send you our current form.

4) Data we collect

4.1 Data you provide

Account data: email, name, phone, company name, user role (operator, client, or courier) — collected when you create an account.

User content: photos (proof of pickup/delivery), digital signatures, chat messages, order and delivery details — only when you submit it in the App.

Support requests: messages you send to support.

Data about other people: when you create an order you supply details about the person receiving it. That data is described separately in Section 9.

4.2 Data collected automatically

Device & app info: device model, OS version, app version, language, time zone.

Usage data: screens visited, taps, session duration, crashes/performance diagnostics.

Location data (GPS): precise geolocation is collected from couriers for real-time tracking and delivery confirmation coordinates. Clients and operators may use location for address selection on the map. Location is only collected if you allow location permissions.

Background collection of courier location, when it starts and how it stops, is described in full in Section 10.2.

Analytics data: usage statistics including app interactions, screen views, engagement patterns and session data. These events are linked to your account identifier and to your role, so they are pseudonymous rather than anonymous. They also include a periodic courier location event, described in Section 10.5.

Crash reports: stack traces, device state and app state captured automatically when the app encounters an error, together with an account identifier, used to fix bugs and improve stability.

The providers we use for analytics and crash reporting are named in Section 8.

5) How we use your data

The list below describes what the platform does as a whole. Read it together with Section 2: for the categories in Section 2.1 we carry out these activities as controller and decide the purpose ourselves; for the categories in Section 2.2 we carry them out as a processor, to deliver the service the Operator has configured, and the Operator decides the purpose.

Data is used to:

• provide and maintain the App

• track courier location in real time and display it to operators

• confirm pickup and delivery with photo and signature evidence

• enable in-app chat between couriers and operators

• calculate routes and display maps

• generate order history, statistics, and reports

• send notifications about order status changes

• improve performance and user experience

• measure and optimize our advertising on Facebook and Instagram (website only, with your consent — see Section 22)

• diagnose bugs and prevent fraud/abuse

• provide customer support

• comply with legal obligations

We do not use platform data for advertising or for building marketing profiles — see Section 14.2. Beyond providing, securing and supporting the platform, the only use we make of platform data for a purpose of our own is the product telemetry described in Sections 2.1 and 10.5.

6) Legal basis (EEA/UK only)

Where we act as controller and the law requires a legal basis, we process data under these bases:

• Contract — to provide the App and courier management service

• Legitimate interests — analytics, security, improvement

• Consent — location tracking, camera access, notifications — where applicable

• Legal obligation — tax, law enforcement requests, etc.

Where we act as a processor for an Operator (Section 2.2), the legal basis for that processing is established by the Operator as controller, not by us.

7) Sharing of data

We do not sell your personal data. Data may be shared as follows:

7.1 Within the Operator's workspace

The platform is multi-tenant. Each Operator has its own workspace, and data created in it is visible to that Operator and to the dispatcher accounts the Operator has authorised, according to the permissions the Operator sets. A courier sees the orders assigned or offered to that courier. A client sees its own orders. Data is scoped to the Operator that owns it and is not shared with other Operators on the platform.

7.2 Service providers and sub-processors

We use third-party providers to operate the platform — hosting, maps and routing, push notifications, transactional email, payment processing and bot protection. They process data on our behalf under agreements. They are listed in Section 8.

7.3 Public tracking links

An Operator or client can generate a public tracking link for an order. Anyone holding that link can see limited order information without signing in. This is described in Section 9.3.

7.4 Legal & safety

We may disclose information if required by law or to protect users, the public, or our rights. Where we hold the data as a processor and are legally permitted to do so, we will inform the Operator before responding to such a request.

8) Sub-processors and third-party services

The providers below may process personal data on our behalf so that the platform can work. Each entry states what the provider does for us. We will give notice of material changes to this list so that a business customer has an opportunity to object.

• Mapbox — map display, geocoding, route rendering. On Android, Mapbox telemetry is switched off in the App by an explicit setting. On iOS that setting is not currently applied, so Mapbox may collect its own usage data there under its own terms.

• Google Maps — may be launched externally for turn-by-turn navigation at the courier's request.

• Waze — may be launched externally for navigation as an alternative to Google Maps.

• Google Firebase — we use Firebase Analytics for usage analytics, Firebase Crashlytics for crash reporting, and Firebase Cloud Messaging for push notifications. Firebase is provided by Google LLC and processes data according to Google's Privacy Policy (https://policies.google.com/privacy). Firebase Analytics events are linked to an account identifier and a role property that we set, so they are pseudonymous, not anonymous, and they are event-level rather than aggregated. They include the periodic location event described in Section 10.5. Crashlytics data includes technical diagnostic information and an account identifier. You can learn more about how Google uses data at https://firebase.google.com/support/privacy.

• Lemon Squeezy (Lemon Squeezy, LLC) — payment processor and merchant of record for paid subscription plans. Receives billing email, payment instrument details, billing/tax address, and a reference to your RutaLive account identifier. Subject to Lemon Squeezy's own privacy policy at https://www.lemonsqueezy.com/privacy.

• Resend (Resend, Inc.) — transactional email provider used to deliver email-verification codes, password-reset codes, and account-related notifications. Receives the recipient email address and the email content. Subject to Resend's privacy policy at https://resend.com/legal/privacy-policy.

• Meta Platforms Ireland Ltd / Meta Platforms, Inc. ("Meta") — the Meta (Facebook) Pixel runs on our website (not in the App) to measure advertising and build audiences for Facebook/Instagram. It loads only after you accept cookies. See Section 22 and Meta's Privacy Policy at https://www.facebook.com/privacy/policy.

• Cloudflare, Inc. — the Turnstile bot-protection challenge runs on our sign-in and registration pages to distinguish real people from automated abuse. It receives your IP address, browser and device signals, and a challenge token. Subject to Cloudflare's privacy policy at https://www.cloudflare.com/privacypolicy.

• Our hosting and infrastructure provider — operates the servers and database on which the platform runs. This provider hosts all platform data described in Sections 2.1 and 2.2, and processes it only to provide hosting to us.

• Intuit Inc. (QuickBooks Online) — where an Operator chooses to connect its own QuickBooks Online company, we send invoice, customer, vendor and payout records to that Operator's QuickBooks account and read back the results. This connection is initiated by the Operator, points at the Operator's own accounting file, and can be disconnected by the Operator at any time. Intuit processes that data under its own agreement with the Operator. Subject to Intuit's privacy policy at https://www.intuit.com/privacy.

Within the mobile App we do not track you across other companies' apps and websites for advertising purposes. On our website we use the Meta Pixel and Google advertising tools for advertising measurement, only with your consent (see Sections 14 and 22). We do not sell your personal data to advertisers.

These services may collect data as described in their own privacy policies.

9) Delivery recipients and other people without an account

A delivery platform necessarily holds personal data about people who never signed up for anything. If a parcel is being delivered to you, your details are in the system even though you have no RutaLive account. This section explains what is held, who is responsible for it, and what you can do.

9.1 What is held, and where it comes from

• Name and contact phone number of the recipient, and of the sender or contact person at the pickup point.

• Full address details, which can be granular — street, building, entrance, floor, apartment, city, region and postal code.

• Geocoded coordinates for that address, produced when the address is converted into a map position.

• Delivery instructions and notes entered by the person who created the order.

• Proof of delivery — photographs taken at the doorstep, a digital signature if one is captured, a QR scan record, and the coordinates and timestamp recorded at the moment of capture.

We do not obtain this data from you directly. It reaches us because an Operator, or a client of that Operator, entered it when creating the order, or because a courier captured proof of delivery in the App.

9.2 Who is responsible, and how to exercise your rights

The Operator whose workspace holds the order is the controller of this data. RutaLive holds it as a processor and has no independent right to alter or erase records inside an Operator's workspace.

The most direct route is therefore to contact the business that arranged your delivery — the shop, pharmacy, restaurant or courier company you dealt with. If you do not know which business that is, or you cannot reach it, write to us at [email protected] with the order number or tracking link and we will route your request as described in Section 13.4. We will tell you who the controller is unless we are legally prevented from doing so.

9.3 Public tracking links

The platform can generate a public tracking page for an order, at a web address containing an unguessable numeric token. The page is deliberately open: anyone who has the link can view it without signing in, so treat the link as you would treat the delivery details themselves.

A tracking page shows the order number, the Operator's display name, the current status and the times at which earlier statuses were reached, the pickup and delivery names, addresses and map positions, and — once a courier is assigned — the courier's name, vehicle plate and phone number. While the order is in transit it also shows the courier's live position on the map.

A tracking page does not show prices, invoices, accounting data, chat messages, proof-of-delivery photographs or signatures, internal record identifiers, or any data belonging to a different order or a different Operator.

The link is time-limited. Thirty minutes after the order reaches a final state — delivered, failed or cancelled — the link stops working and returns an expiry response instead of any order data. The courier's live position is available only while the order is actually in transit, and stops being returned as soon as the order leaves that state. The endpoint is rate-limited per IP address to frustrate anyone attempting to guess tokens.

10) Courier location data

Courier location is precise, real-time geolocation collected from a mobile device, including while the App is in the background. Several privacy regimes treat this as a special category — under the California Privacy Rights Act it is "sensitive personal information". We therefore describe it separately.

10.1 What is collected and why

We collect the device's latitude and longitude from couriers, so that the Operator can see where its couriers are on the dispatch map, so that routes and arrival estimates can be calculated, so that clients and recipients can follow an in-progress delivery, and so that the coordinates of a pickup or delivery confirmation can be recorded as evidence.

Location is collected only from couriers in the course of their work. Operators and clients may use location only for choosing an address on a map, which is a one-off action rather than continuous tracking.

10.2 Background collection and how it is signalled

Location is only collected if the courier grants location permission to the App at the operating-system level. Collection begins when a signed-in courier opens the courier map screen, and continues, including while the App is in the background, for as long as that screen remains open. It is not conditional on an order being in progress: a courier who has the map open with permission granted is being located whether or not they currently hold an assignment.

Collection stops when the courier leaves the map screen, signs out, closes the App, or withdraws the location permission in the device's operating-system settings. Nothing is sent to our servers while collection is stopped.

On Android, background collection runs as a foreground service, which means the operating system displays a persistent notification for as long as collection continues, so the courier can see at a glance whether tracking is on. That notification is worded in terms of delivery tracking and is shown whenever collection is running, including at times when no delivery is actually in progress.

10.3 How a courier can stop it

A courier can stop location collection by leaving the map screen, by signing out of the App, by closing the App, or by withdrawing the location permission in the device's operating-system settings at any time. Withdrawing the permission stops collection immediately; it will also prevent the map and route features from working, and the Operator may not be able to assign work that depends on them. Whether location sharing is a condition of the courier's engagement is a matter between the courier and the Operator, not between the courier and RutaLive.

10.4 What is stored, and for how long

We do not build a continuous location history. Our servers store the courier's current position, the immediately preceding position, and the time of the last update, each overwritten by the next update. There is no stored trail of everywhere a courier has been. Separately, and by design, the coordinates recorded at the moment a pickup or delivery is confirmed are stored as part of that order's proof-of-delivery record and are retained with the order, as described in Section 11.

Courier location data is not used to infer characteristics about a courier. Beyond the product-telemetry event described in Section 10.5, it is used only to provide the dispatch, routing, tracking and proof-of-delivery features described above. It is never disclosed for advertising — see Section 14.2.

10.5 Location in our product telemetry

We have to disclose one further flow, because it is not covered by the description above. When the App obtains a position fix, it also sends a product-telemetry event to our analytics provider, Google Firebase Analytics, containing the latitude, longitude and accuracy of that fix and the time it was taken. The event is throttled to at most one every five minutes per device, and it is linked to the account identifier we set in the analytics provider, so it is pseudonymous rather than anonymous. It is generated from the same position lookup used by the App generally, which means it can be produced for an operator or a client choosing an address on a map, not only for a courier.

This event exists so that we can see aggregate usage of the platform by region. It is our own telemetry, so for this flow we act as controller rather than as the Operator's processor, and Google Firebase acts as our processor under its terms, which are linked in Section 8. It is not used for advertising, is not sold, is not shared for cross-context behavioural advertising or targeted advertising, and is not used to profile any individual.

We describe this flow here rather than leave it undisclosed. It can be prevented at any time by withdrawing the location permission from the App, which stops all location collection as described in Section 10.3. If you have questions about it, write to [email protected].

11) Data retention

We keep data only as long as it is needed for the purpose it was collected for, or for as long as the law requires. Because responsibility is split between us and the Operator (Section 2), retention works differently for different categories.

11.1 Data we control

• Account and profile data: kept while the account exists, and deleted when the account is deleted.

• Billing and subscription records: kept for as long as needed to administer the subscription, and afterwards for the period required by tax and accounting law. Our payment processor keeps its own transaction records under its own policy.

• Support correspondence: kept while it is needed to handle the matter and to keep a record of what was decided.

• Analytics and crash-report data: held by our analytics and crash-reporting provider and retained for the period configured in that provider's console, which we set to the shortest period that still lets us investigate a recurring fault. We do not keep a separate copy of these events ourselves. If you need the exact period currently in force, write to [email protected] and we will tell you.

• Website visit records: retained for 90 days; aggregate daily visit counts are kept for about a year.

• Server performance metrics: retained for 48 hours.

• Data cached locally on your device: cleared when you uninstall the App.

11.2 Data an Operator controls

Order records — including addresses, recipient details, proof-of-delivery photographs, digital signatures, the coordinates captured with them, and chat messages — are the Operator's business records. They are retained for as long as the Operator's workspace exists. Individual orders and their proof-of-delivery photographs cannot be deleted item by item through the App's own interface, because an Operator's order history is also its invoicing, accounting and dispute-evidence record. They are removed when the Operator's account and workspace are deleted.

We cannot decide on our own initiative to delete data in this category, because we do not control it. If you want an individual order record erased, the request has to reach the Operator — see Sections 9.2 and 13.4. Where an Operator instructs us in writing to delete specific records it controls, we carry out that deletion on its behalf.

11.3 Retention after deletion

Deleting an account is not always the end of every record. We may retain limited data after deletion where we have to: invoices and payment records needed to satisfy tax and accounting obligations, records needed to establish, exercise or defend a legal claim, and minimal records needed to show that a deletion request was made and honoured. Anything retained on this basis is kept only for as long as that reason lasts, is limited to what the reason requires, and is not used for any other purpose.

Two further points, so that this is complete. Where an account is terminated rather than deleted on request, we will for thirty (30) days after termination provide a copy of the account data on written request, as described in our Terms of Service, before removing it. And deleted data may persist in routine encrypted backups for a limited period until those backups are overwritten in the ordinary cycle; during that period it is not restored, accessed, or used for any purpose.

12) Your rights and choices

Depending on your region, you may have rights to:

• access your data

• correct your data

• delete your data

• object or restrict processing

• data portability

• withdraw consent (where processing is based on consent)

• withdraw cookie and advertising consent on our website at any time, and manage ad personalisation with Meta and Google — see Section 22.3 for how

• not be discriminated against for exercising any of these rights — we will not deny you the service, charge you a different price, or give you a lower quality of service because you made a privacy request

• complain to your national data protection authority, supervisory authority or privacy regulator, in addition to or instead of contacting us

How to make a request, and how quickly we answer, is set out in Section 13.

13) How to make a request, and how we respond

13.1 How to reach us

• Email: [email protected] with the subject "Privacy Request". Tell us what you want and which account or order it concerns.

• Account deletion: you can request permanent deletion of your account at https://rutalive.com/delete-account by entering your email and password. The form verifies your credentials and creates a deletion request, which our team then reviews and carries out. You may alternatively email [email protected] with the subject "Account Deletion". Deletion is not instantaneous — see Section 13.3 for the deadlines that apply, and Section 11.3 for what may survive deletion.

13.2 Verifying who you are

We have to be reasonably certain that a request comes from the person it concerns, because acting on a fraudulent request would itself be a privacy breach. For account holders, we verify by confirming control of the registered email address, and for account deletion by requiring the account password. For a person who has no account — a delivery recipient, for example — we ask for enough detail to match the request to a specific record, such as an order number or tracking link, and we do not ask for more identifying information than the request needs. If we cannot verify a request to a reasonable degree of certainty, we will say so rather than act on it, and we will explain what would let us proceed. Verifying you does not create a new data set: information supplied only to verify a request is used only for that and is not retained afterwards for other purposes.

13.3 Deadlines

• Under the GDPR and UK GDPR: we respond without undue delay and within one month of receiving the request. That period can be extended by up to two further months where the request is complex or where several requests have been received; if we extend, we tell you within the first month and explain why.

• Under the CCPA/CPRA and comparable United States state laws: we confirm receipt within ten business days and respond substantively within forty-five calendar days, extendable once by a further forty-five days where reasonably necessary, with notice to you of the extension and the reason.

• Under PIPEDA in Canada: we respond within thirty days, with any extension permitted by that statute notified to you.

• Under Quebec Law 25: we respond within thirty days.

Where more than one of these applies, we apply whichever is shortest.

13.4 Requests routed to an Operator

If your request concerns data an Operator controls (Section 2.2) — an order record, a delivery address, a proof-of-delivery photograph, a chat message, the location coordinates recorded with a pickup or delivery confirmation — we are not the right decision-maker, and acting alone would mean overriding our customer's control of its own records. Approach the Operator that holds your data: for a courier or dispatcher this is the company you work for; for a client this is the courier company that services you; for a recipient this is the business that arranged your delivery.

Write to us anyway if you do not know who that is or cannot get a response. We will identify the responsible Operator, forward your request to it without undue delay, tell you that we have done so, and give the Operator the technical assistance it needs to act. We will not simply drop your request because we are the processor rather than the controller.

13.5 Authorised agents

You may use an authorised agent to make a request on your behalf where the applicable law allows it. We will ask the agent for written proof of authorisation signed by you, and unless the agent holds a valid power of attorney we may also contact you directly to confirm that you authorised the request and to verify your identity as described in Section 13.2.

13.6 If we refuse, and how to appeal

If we decline a request in whole or in part, we will tell you why, and what you can do next. Under the United States state privacy laws that provide for it, you may appeal that decision by replying to our response or writing to [email protected] with the subject "Privacy Appeal". We will review the appeal and inform you in writing of the outcome, with reasons, within the period the applicable state law allows — forty-five days in the states that set that period. If we deny the appeal, we will tell you how to lodge a complaint with your state Attorney General or other competent authority.

Wherever you are, you may also complain directly to your data protection authority, supervisory authority or privacy regulator — in Canada, the Office of the Privacy Commissioner of Canada or, in Quebec, the Commission d'acces a l'information. You do not have to come to us first.

14) United States state privacy rights

This section applies if you are a resident of a United States state with a comprehensive consumer privacy law, including California, and states such as Virginia, Colorado, Connecticut, Utah, Texas, Oregon and Montana whose laws grant broadly similar rights. Terms such as "personal information", "sale", "share", "targeted advertising" and "sensitive personal information" have the meanings given in the applicable statute.

14.1 Categories collected, purposes and recipients

• Identifiers — name, email address, phone number, account identifier, IP address. Collected to create and secure accounts, to operate deliveries and to communicate with you. Disclosed to our hosting provider, email provider, payment processor and bot-protection provider.

• Commercial information — subscription plan, billing history, orders placed and delivered, invoices and payout records. Collected to charge for the service and to run the Operator's business. Disclosed to our hosting provider, payment processor and, where an Operator connects it, that Operator's QuickBooks Online account.

• Precise geolocation — courier position and the coordinates captured with proof of delivery. Collected to dispatch, route, track and evidence deliveries, and — in the throttled telemetry event described in Section 10.5 — to measure aggregate regional usage. Disclosed to our hosting provider, to our maps and routing provider, and, for that telemetry event only, to our analytics provider. Treated as sensitive personal information, and covered by Section 10 and Section 14.3.

• Visual and electronic information — proof-of-delivery photographs, digital signatures and chat messages. Collected to evidence deliveries and to let an Operator, its couriers and its clients communicate. Disclosed to our hosting provider.

• Internet and device activity — device model, operating system, app version, language, time zone, screens visited, session data, crash and performance diagnostics, and website browsing on rutalive.com. Collected to operate, secure, debug and improve the service and, on the marketing website only and only with consent, to measure advertising. Disclosed to our analytics, crash-reporting and, for the website, advertising providers.

• Professional information — role, company name, vehicle plate and payout terms for couriers. Collected to operate the Operator's workspace. Disclosed to our hosting provider.

• Inferences — we do not build consumer profiles reflecting preferences, characteristics, behaviour, aptitudes or intelligence.

Our sources are you, the Operator or client who created an order, the courier's device, and your device or browser. Section 8 names the recipients.

14.2 Whether we sell or share personal information

We do not sell personal information for money, and we never have.

We must be precise about "sharing", because these statutes define it broadly. On our marketing website at rutalive.com, and only after you accept advertising cookies in our banner, the Meta Pixel and the Google Ads tag transmit identifiers and browsing activity to Meta and Google to measure our advertising and build advertising audiences. Under the CPRA that disclosure is capable of constituting "sharing" for cross-context behavioural advertising, and under other state laws "targeted advertising". Rather than argue the point, we treat it as such and give you the corresponding controls.

The opt-out is the cookie banner itself. If you decline, no advertising tags load and nothing is transmitted. If you previously accepted, you can withdraw consent as described in Section 22.3. We honour Global Privacy Control and comparable browser opt-out preference signals where the law requires us to.

Nothing in the platform itself is sold or shared in this sense. Order records, recipient details, courier location, proof-of-delivery photographs and signatures, chat content and accounting data are never disclosed for advertising, never transmitted to advertising networks, and never used to build advertising audiences. There is no advertising tracking of any kind inside the mobile App.

We do not knowingly sell or share the personal information of consumers under sixteen years of age.

14.3 Sensitive personal information

The only sensitive personal information we handle in volume is precise geolocation, collected from couriers as described in Section 10. We use it to provide the dispatch, routing, tracking and proof-of-delivery features that the service consists of, to keep the service secure, to resolve disputes about whether a delivery took place, and — in the throttled telemetry event described in Section 10.5 — to measure aggregate usage of the platform by region. We do not use or disclose it to infer characteristics about anyone, and we do not sell it or share it for cross-context behavioural advertising or targeted advertising.

The telemetry use in Section 10.5 goes beyond what is strictly necessary to perform the service, so we do not claim that the right to limit the use of sensitive personal information is without effect here. If you are a resident of a state that grants that right and you wish to exercise it, write to [email protected] using the process in Section 13. The collection also stops entirely if the location permission is withdrawn from the App, as described in Section 10.3.

Account passwords and authentication tokens are also sensitive by nature. They are used only to sign you in and to keep your session secure, never for any other purpose.

14.4 Your rights, and how to use them

Subject to the law of your state, you may request to know what personal information we hold and how it is used, obtain a copy in a portable form, correct inaccurate information, delete your information, opt out of sale, sharing or targeted advertising, limit the use of sensitive personal information, and appeal a refusal. You will not be discriminated against for exercising any of them.

Use the channels and follow the process in Section 13. Where the information you are asking about sits inside an Operator's workspace we act as that Operator's service provider, and Section 13.4 explains how your request is routed.

15) Canada — PIPEDA and Quebec Law 25

This section applies if you are in Canada. It supplements, and does not replace, the rest of this policy.

15.1 Meaningful consent

We rely on your consent to collect, use and disclose personal information, except where the law permits or requires us to act without it. Consent is meant to be meaningful, so we describe our purposes in plain language at the point they matter rather than burying them: the App asks for location permission and explains what it is for, the cookie banner asks before any advertising tag loads, and this policy sets out each purpose in Section 5. Where information is sensitive — precise geolocation in particular — collection is subject to express consent given through the operating-system permission prompt, rather than to implied consent. Where we act as a processor for an Operator, that Operator is responsible as controller for establishing the legal basis for the processing and we act on its instructions; where we act as controller, including for the telemetry described in Section 10.5, we rely on that express permission and on our own legitimate interest in operating and improving the service.

We do not require you to consent to collection beyond what is necessary to provide the service as a condition of supplying it.

15.2 Withdrawing consent

You can withdraw consent at any time, subject to legal and contractual restrictions and to reasonable notice. Withdraw location consent in your device settings, notification consent in your device settings, and cookie consent as described in Section 22. Withdraw more broadly by writing to [email protected]. We will tell you what withdrawing will mean in practice before we act on it, because some withdrawals make parts of the service impossible to provide — a courier app without location cannot show a route or confirm a delivery position.

15.3 Access and correction

You may ask whether we hold personal information about you, ask for access to it and for an account of how it has been used and to whom it has been disclosed, and ask us to correct it if it is inaccurate or incomplete. Under Quebec Law 25 you may also request that computerised personal information you provided be communicated to you in a structured, commonly used technological format. Use Section 13; the deadlines in Section 13.3 apply.

15.4 Cross-border storage and processing

Your personal information may be stored and processed outside Canada, including in the United States and in Europe, by us and by the providers listed in Section 8. While it is outside Canada it is subject to the laws of the country where it is held, and it may be accessible to the courts, law enforcement and national security authorities of that country under their law. We disclose this so that your consent is informed, and we use contractual protections with our providers as described in Section 17. If you would like to know more about how we assess these transfers, write to [email protected].

15.5 Breach reporting

Where a breach of security safeguards involving personal information under our control creates a real risk of significant harm to an individual, we will report it to the Office of the Privacy Commissioner of Canada and notify affected individuals as soon as feasible, and will notify any other organisation that may be able to reduce the risk of harm. We keep records of breaches as PIPEDA requires. Quebec confidentiality incidents are handled in the same way, with notification to the Commission d'acces a l'information where the incident presents a risk of serious injury. Section 19 describes the process generally.

16) Children's privacy

RutaLive is a business tool for courier and delivery companies. It is not directed to children, it is not marketed to children, and it has no feature intended for use by a child. Courier, client and dispatcher accounts are created by an Operator rather than by self-registration, and Operator accounts are opened by businesses.

We do not knowingly collect personal information from a child under 13. If we learn that we have collected personal information from a child under 13 without verifiable parental consent, we will delete it promptly, as required by the United States Children's Online Privacy Protection Act. Our Terms of Service in any event require every account holder to be at least 16.

In the EEA and the UK, where processing relies on consent, national law may set a digital-consent age as low as 13. That national age governs the validity of consent, but it does not lower the contractual age floor: our Terms of Service require every account holder to be at least 16, and we do not knowingly permit an account below that age anywhere.

Delivery recipients are a separate case: an order may name a young person as the person receiving a parcel, because the sender entered those details. We do not collect that information from the child, and we hold it as the Operator's processor. If you are a parent or guardian and believe a child's data has been provided to us, write to [email protected] and we will delete it or, where the record belongs to an Operator, route the request as described in Section 13.4.

17) International transfers

Your data may be processed outside your country, by us and by the providers listed in Section 8. Where the law requires it, we rely on appropriate safeguards for those transfers, including contractual protections such as Standard Contractual Clauses, and, where a provider is certified under it, the EU-U.S. Data Privacy Framework. For transfers out of Canada, see Section 15.4. If you would like more detail about the safeguards applying to a particular transfer, write to [email protected].

18) Security

We use technical and organisational measures appropriate to the risk. The measures actually in place include the following.

• Transport encryption — all communication between the App, the website and our servers travels over encrypted connections (HTTPS and WSS).

• Password hashing — account passwords are never stored in readable form. They are stored as bcrypt hashes with a per-password salt, and are compared without ever being decrypted, because hashing cannot be reversed.

• Secure token storage on your device — authentication tokens are held in the operating system's encrypted secure storage rather than in ordinary application storage.

• Role-based access control — requests to the authenticated parts of the platform are authenticated and then checked against the role they belong to, and dispatcher accounts are further restricted by the individual permissions the Operator grants them. A small number of endpoints are deliberately public and are secured differently: the public order-tracking page, which is protected by an unguessable token, an expiry and per-IP rate limiting, the website visit beacon, and the Public API, which is authenticated by a customer-issued API key rather than by a user role.

• Tenant scoping — queries are scoped to the Operator that owns the data, so that one Operator's workspace is not readable from another's.

• Session invalidation — a courier signing in on a new device invalidates the previous session, so an old or abandoned device cannot continue to act on the account.

• Encrypted third-party credentials — access and refresh tokens for an Operator's connected QuickBooks Online account are encrypted before they are written to our database, using a key held in the server environment rather than in the database.

• Abuse controls — rate limiting on authentication and on public endpoints, including the public tracking endpoint, and a bot-protection challenge on sign-in and registration.

• Unguessable public identifiers — the token in a public tracking link is randomly generated rather than derived from any record identifier, so links cannot be constructed by guessing an order number.

No method of transmission or storage is perfectly secure, and we do not claim otherwise. We do not currently hold a third-party security certification such as SOC 2 or ISO 27001, and this policy makes no such claim. If security is a procurement requirement for you, write to [email protected] and we will tell you where we actually stand rather than pointing at a badge.

19) Personal data breaches

If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to personal data, we will act without undue delay to contain and investigate it.

Where the affected data belongs to an Operator's workspace, we will notify that Operator without undue delay after becoming aware, because the Operator is the controller and the notification duty to regulators and individuals is theirs. We will give them the information they need to meet that duty, including what happened, which categories of data and roughly how many records are affected, the likely consequences, and what we have done about it.

Where we are the controller, we will notify the competent supervisory authority or regulator where the law requires it and within the deadline the law sets, and we will notify affected individuals directly, without undue delay, where the breach is likely to result in a high risk to their rights and freedoms or where the applicable law otherwise requires it. Canadian reporting obligations are described in Section 15.5.

We will not withhold notice to protect our own reputation.

20) Automated decision-making and profiling

We do not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing. There is no automated credit, employment, insurance, eligibility, pricing-discrimination or account-termination decision in the platform, and no profiling of individuals for advertising.

Some features are automated, and we describe them plainly so that the statement above can be checked rather than taken on trust. The platform calculates a delivery price from the pricing rules the Operator has configured — package type, distance, weight, zone and surcharges — which is arithmetic applied to the Operator's own tariff, not an assessment of a person. It suggests which orders could be combined into one trip, by comparing routes and detour distance. It can offer available orders to couriers for self-selection, and can rank stops into an efficient sequence. In each case the output is a suggestion or a calculation, generated automatically and not reviewed by RutaLive personnel before it is displayed. The decision that follows is human: an order is assigned to a courier by an Operator or dispatcher who decides, or by a courier who chooses to accept it. A human decides whether an order is assigned and whether it is accepted.

Where an Operator uses data from the platform to make decisions about a courier or a client, that decision is the Operator's, taken under its own responsibility as controller, and any rights you have in respect of it are exercised against the Operator. If we ever introduce a feature that makes a significant decision by automated means alone, we will describe it here, explain the logic and consequences, and provide the safeguards the law requires, including human review.

21) Payments and subscriptions (data shared with our payment processor)

21.1 Payment processor

Subscription payments for the Service are processed by our merchant of record, Lemon Squeezy (Lemon Squeezy, LLC). When you initiate a subscription, the following information is transmitted to Lemon Squeezy solely for the purpose of completing the transaction and managing the subscription thereafter:

• billing email address;

• payment instrument details (collected and stored exclusively by Lemon Squeezy — we never receive, view, or store full card numbers);

• billing address and tax-relevant information required by applicable VAT/sales-tax regulations;

• a reference to your RutaLive account identifier, used to associate the payment with your account.

Lemon Squeezy acts as the merchant of record and is responsible for issuing invoices, remitting applicable VAT/sales tax, and processing chargebacks, in accordance with its own privacy policy and terms of service available at https://www.lemonsqueezy.com. The contractual consequences of a chargeback as between you and RutaLive are governed by our Terms of Service.

The commercial terms of subscriptions — tiers, prices, billing cycles, automatic renewal, cancellation, downgrade and refunds — are not a privacy matter and are set out in our Terms of Service at https://rutalive.com/terms-of-service.

22) Cookies, the Meta (Facebook) Pixel and Google tools (website)

This section applies to our website at rutalive.com. The mobile App does not use these cookies, the Pixel, or the Google tools described below. For how these tools interact with United States state privacy law, see Section 14.2.

22.1 Cookies we use

• Strictly necessary — needed for the site to work and to remember your cookie choice. These do not require consent.

• Analytics & advertising — set by the Meta Pixel (see 22.2) and by Google Analytics 4 / Google Ads (see 22.5). These cookies are set ONLY after you accept them in our cookie banner.

22.2 Meta (Facebook) Pixel

We use the Meta Pixel (provided by Meta Platforms Ireland Ltd and Meta Platforms, Inc., "Meta") to measure the effectiveness of our advertising and to build audiences for Facebook and Instagram campaigns. When loaded (after consent), the Pixel may collect your IP address, browser and device information, the pages you view, and certain actions you take (for example: viewing a page, clicking "Book a demo", clicking "Get Started" on a paid plan, and completing registration). This information is shared with Meta and processed under Meta's Privacy Policy at https://www.facebook.com/privacy/policy. For Pixel data, RutaLive and Meta act as independent controllers and, where applicable, joint controllers.

22.3 Consent and how to withdraw it

The Meta Pixel does not load until you choose "Accept" in our cookie banner. Google Analytics 4 and Google Ads run in Google's "consent mode" and remain cookieless until you accept (see 22.5). If you choose "Decline", the Pixel is not loaded and no analytics or advertising cookies are set. The legal basis for these cookies is your consent.

You can withdraw consent at any time by clearing the cookies/site data for rutalive.com in your browser (the banner then appears again), and you can manage ad personalisation in your Meta account settings. Declining or withdrawing consent does not affect the functioning of the site.

22.4 International transfer of Pixel data

Meta may process this data in the United States and other countries. Such transfers rely on appropriate safeguards, including the EU-U.S. Data Privacy Framework and/or Standard Contractual Clauses, as described in Meta's Privacy Policy.

22.5 Google Analytics 4 and Google Ads

We use Google Analytics 4 (site usage statistics) and Google Ads conversion tracking (measuring the effectiveness of our advertising), provided by Google Ireland Ltd and Google LLC ("Google"). These tools run in Google's "consent mode": until you choose "Accept" in our cookie banner, they operate without cookies and send only aggregated, cookieless signals. Analytics and advertising cookies (such as _ga and _gcl_au) are set only after you accept. Once enabled, these tools may collect your IP address, browser and device information, the pages you view, and conversion events (for example, completing registration). This information is processed under Google's Privacy Policy at https://policies.google.com/privacy. You can manage ad personalisation at https://adssettings.google.com. Google may process this data in the United States and other countries; such transfers rely on appropriate safeguards, including the EU-U.S. Data Privacy Framework and/or Standard Contractual Clauses.

23) Changes to this policy

We may update this policy. We will change the "Last updated" date and may notify you in-app if changes are significant. Where a change materially affects how we handle data we process on an Operator's behalf, we will notify affected business customers as described in Section 8.

24) Contact

Email: [email protected]

Privacy requests: [email protected] with the subject "Privacy Request" — see Section 13.

Data Processing Agreement requests: [email protected] — see Section 3.

© 2026 RutaLive. All rights reserved.
Menu
How it works Pricing Blog About FAQ
Get the app Android iOS Windows
Login Sign up

Available on desktop

Signing in and managing deliveries works on the desktop version of RutaLive. Open rutalive.com on your computer to continue.

Cookies & privacy

We use cookies for analytics and to improve your experience. See our Privacy Policy.