Privacy Policy
Last updated: August 23, 2026
RouteMonkey ("the Company", "we", "us", "our") turns a day's delivery orders into an optimised driving route. This policy explains what personal data we collect, why, how long we keep it, and what rights you have over it — under UK GDPR and the Data Protection Act 2018.
It covers two different groups of people, because the app handles two different kinds of personal data:
- Account holders — the business (and its drivers) who sign up to use RouteMonkey. For this data, RouteMonkey is the data controller.
- Delivery recipients — the account holder's own customers, whose name, address and contact details are imported (from a spreadsheet, QuickBooks or Xero) so a route can be planned and, optionally, a tracking link sent. For this data, the account holder is the data controller and RouteMonkey acts only as a data processor on their instructions. If you are a delivery recipient with a question about your data, please contact the business that arranged your delivery in the first place — they control what is held and for how long; we simply process it on their behalf. You can always stop delivery emails yourself via the unsubscribe link in any message we send you.
Definitions
- Account means a registered RouteMonkey account (company admin or driver).
- Company, referred to as "we", "us" or "our", refers to RouteMonkey, UK.
- Delivery Recipient means a person an account holder delivers to, whose details appear on a round.
- Personal Data is any information relating to an identified or identifiable individual.
- Service refers to the RouteMonkey website and driver app.
- Service Provider means a third party that processes data on our behalf so we can run the Service.
- You means whichever of the two groups above applies to you.
Data We Collect
Account holders and drivers
When you register, or when your company admin creates a driver login for you, we hold:
- Email address, and password (stored as a salted hash — we never see or store it in plain text)
- Your depot/company details you enter, such as address and round settings
- If you connect QuickBooks or Xero: an OAuth access/refresh token for that connection (never your QuickBooks or Xero password, which we never see)
- Basic technical/usage data such as IP address and browser type, collected automatically by the web server and used only for security and diagnostics
Delivery recipients
To plan and run a round, an account holder's own customer data flows through the Service. Depending on how they get their orders in, this can include:
- Name, delivery address, and (if supplied) email address and phone number
- Geographic coordinates for the address — either resolved automatically (see Google Maps, below) or placed by hand by an admin or driver
- Order/line details relevant to the delivery (what's being delivered), and any delivery note or standing instruction ("round the back", access details, etc.)
- Delivery status: whether and when a stop was completed, and any outcome note the driver recorded
- If notifications are enabled for the account: an unsubscribe/tracking token so a "your delivery is on its way" link and live van position can be shown to that one recipient, and a record of which notification categories they've opted out of
We never sell this data, and it is never used for advertising or shown to anyone other than the account holder who delivers to that person and (in the one-stop tracking view) the recipient themselves.
Cookies
The Service uses one cookie: a strictly-necessary session cookie that keeps you signed in. We do not use analytics, advertising or tracking cookies, and we do not use tracking pixels in the emails we send.
How We Use Personal Data
- To provide the Service — planning routes, running the driver app, showing delivery status.
- To manage your account — sign-in, password resets, and (for company admins) managing drivers and settings.
- To send delivery updates — an optional "on its way" email/tracking link to the delivery recipient, sent only if the account holder has notifications switched on and the recipient hasn't opted out of that category.
- For security and fraud prevention — detecting abuse, rate-limiting, and keeping accounts and rounds separated from one another.
- To respond to support requests you send us directly.
We do not use Personal Data for marketing, do not sell or rent it, and do not share it with "business partners" for promotional purposes. It is disclosed only to the Service Providers below, where required by law, or with your explicit consent.
Who We Share Data With
We use a small number of third-party services to run RouteMonkey. Each only receives the minimum data it needs to do its job:
- Google Maps Platform — resolves a written address into coordinates (geocoding) when one hasn't already been placed by hand. This is a transfer of an address string outside the UK/EEA to Google in the US, covered by Google's standard contractual clauses. Successful lookups are cached (typically 30 days) to avoid re-sending the same address repeatedly; failed lookups are cached for a shorter period (typically 7 days) so they're retried once Google's data improves.
- Intuit QuickBooks / Xero — if an account holder connects one of these, we read their invoice/customer data to build a round, using an OAuth token they authorise and can revoke at any time.
- Our mail server (self-hosted, on infrastructure separate from the app) — sends account emails (password resets, etc.) and, if enabled, delivery notification emails.
- Our routing engines (VROOM/OSRM) — self-hosted by us, process delivery coordinates to calculate an optimised route. No personal data beyond coordinates is sent, and nothing is shared with a third party here.
We do not otherwise sell, rent, or share Personal Data with third parties, except where required by law or to protect our legal rights (for example, responding to a valid request from a court or regulator).
Business Transfers
If the Company were involved in a merger, acquisition or asset sale, Personal Data may be transferred as part of that transaction. We would provide notice before your Personal Data becomes subject to a different privacy policy.
Retention
We keep Personal Data only as long as it's needed for the purposes above:
- Account holder data is kept for as long as the account is active, and deleted (across every table and file store we hold) if the account is closed.
- Delivery recipient records are automatically forgotten after a period of inactivity that each account holder controls (24 months by default; some may set it shorter, longer, or — rarely — to never expire). Forgetting means forgetting: nothing is kept back, including notification preferences, so a recipient who returns after that window starts as a new record.
- Tracking links stop working automatically a set number of days after the round they belong to, whether or not the recipient is later forgotten.
- Uploaded spreadsheets and exported files are working files, automatically deleted after around 90 days.
- Historical rounds (which stops were delivered, when) are kept as part of the account holder's own records, subject to the same account-level retention.
Your Rights
Under UK GDPR you have the right to:
- Be informed about how your data is used (this policy)
- Access the Personal Data we hold about you
- Have inaccurate data corrected
- Have your data erased ("the right to be forgotten")
- Restrict or object to certain processing
- Receive your data in a portable format
- Complain to the Information Commissioner's Office (ICO) if you believe your data has been mishandled
Account holders can access and correct most of their own data from within the Service, and can permanently delete their account and everything tied to it from their account settings. Delivery recipients can stop delivery emails at any time via the unsubscribe link in any message we send, or by asking the business that arranged their delivery — as noted above, that business controls their data and is best placed to action access or erasure requests; we will assist them in fulfilling one if asked.
Security
We take reasonable technical measures to protect Personal Data, including encryption in transit (HTTPS/TLS) and access controls limiting who can see what. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Children's Privacy
The Service is not directed at, and does not knowingly collect Personal Data from, anyone under 13. If you believe a child has provided us with Personal Data, please contact us and we will remove it.
Changes to this Policy
We may update this Privacy Policy from time to time, and will update the "Last updated" date above when we do. Material changes will be flagged on this page.
Contact Us
Questions about this policy, or a request relating to your Personal Data:
- Email: hello@routemonkey.uk