Skip to content

Security and privacy

Security and privacy for your customer list.

Your customer list is the business. Here is how RouteVerde keeps it separate from every other business, who can see it, where card numbers go, and how you take all of it with you.

Your data is yours.

You and your team see your customers. We don't sell them or share them.

  • Your customer list, records and invoices belong to your business. We hold them to run the app for you.
  • We don't sell your data, we don't use it for advertising, and there are no ad trackers or third-party analytics scripts. You decide whether we may learn anything from how you use the app.
  • Owners and admins can export everything, any time, at no charge.

Each business is walled off.

Separation is enforced by the database, not just by the screens on top of it.

  • Every table in the database has row level security turned on. Each row carries the business it belongs to, and the database itself refuses to show or change rows from any other business.
  • The app reaches the database only through those same rules, so a bug in a screen cannot read past them.
  • Automated tests set up two businesses and check, table by table, that one cannot see, change or add anything in the other.

Who can see what.

Your team, by role

Owners and admins
Manage the team, run imports, and export everything.
Office and dispatchers
Use the office app for the day to day work. They cannot manage the team, run imports or export everything.
Technicians
Work their stops in the tech app. They cannot publish or reorder routes, see imports or read the change history.
Your customers
Sign in to the portal and see only their own visits, invoices and payments.

Changes to your team, plans, spray records, agreements, invoices and payments are written to a change history that nobody can edit or delete.

The people who run RouteVerde

Our own console shows each business's size against its plan and the health of the system: email queues, payments, imports and errors. It cannot read your customers' names, contact details or message content. That limit is set in the database, not only in the console.

Signing in to it takes a second step from an authenticator app, and every action taken there is recorded in a log that can only be added to.

Outside services, and what each one gets

A few services help run the app. Each receives only what it needs. The full list, with where each one runs, is on our subprocessors page, and we post changes there at least 30 days before a new one receives customer data.

Supabase (Database, sign-in and file storage)
All business data. Always.
Netlify (Hosting the app)
Request logs (IP address, pages requested). Always.
Inngest (Scheduled background jobs)
Job ids, no customer details. Always.
Resend (Sending email)
Recipient email, message content. When email is on.
Google Maps Platform (Finding addresses on the map)
Street addresses only. No names, phone numbers or notes. When address lookup is on.
OpenFreeMap (Street map tiles)
The viewer's IP address and the map area viewed. When the street map is on.
Anthropic (AI route plans)
Stop numbers, service types, time windows, distances and notes with numbers, phone numbers and emails removed. No names or addresses. When someone asks for an AI plan.
Stripe (Card and bank payments)
Payment details entered in Stripe's own form; customer name and email for receipts. When payments are connected.

Payments.

  • Card and bank numbers only ever go into Stripe's own secure pages, never through us.
  • Payments go straight to your own Stripe account. We add no fee on top of your customers' payments.
  • An invoice is marked paid only from Stripe's signed notice that the money came through.

Sign-in.

No passwords to forget, and a second step for the accounts that can do the most.

  • Your team signs in with a 6-digit code sent to their email. There is no password to reuse or leak.
  • Owners and admins also sign in with a code from an authenticator app on their phone.
  • Your customers get a portal sign-in link by email. It is random, works once, and expires after 20 minutes.
  • Every connection uses HTTPS, and the site tells browsers to always use it.

AI with less data.

The AI route plan reads notes like "dog out until noon" to order a day's stops. It only runs when someone asks for it, and you still see a preview and decide.

What the AI sees

  • Stop numbers (S1, S2 and so on), not customer names
  • Service type, time on site and arrival window
  • Rough positions in kilometres from your office, not street addresses or map coordinates
  • Access notes, with phone numbers, email addresses and number codes taken out

Customer names, street addresses and phone numbers are never sent to it.

If you leave.

Being able to leave is part of the deal from day one.

  • One export file holds every table as CSV and JSON, your customer list ready to import anywhere, your pesticide application records as a PDF per month, and all photos, signatures and documents.
  • Cancel any month. After you cancel, you have 30 days to export. Then we delete your data, except what the law requires us to keep.
  • We keep daily backups once your account holds real customer records.

Documents.

The written commitments behind this page.

Report a security issue: email RouteKeep@proton.me.

Bring your customer list over.

Start from your own export, check every row, and undo for 7 days. See how switching works or see the pricing.