Privacy Policy
Last updated: July 7, 2026
This policy has not been reviewed by an attorney. If your use involves sensitive, regulated, or high-stakes data, consult a lawyer before relying on these disclosures.
1. What data we collect
RouteReady collects the minimum data needed to operate the platform.
Account data
- Email address (required to create an account, used for alerts and billing).
- Encrypted password hash — stored by Supabase Auth. We never see your plaintext password.
- Subscription status, plan tier, and billing dates received from Stripe.
Company profile data
- Company name, vehicle types, service area, and license numbers you enter voluntarily.
- This data is used to personalize AI-generated outreach drafts and bid recommendations.
Operational data you upload or enter
- Driver and fleet data:Driver names, CDL numbers, certification expiration dates, vehicle VINs, and related records you enter into the Fleet & Drivers module. This data is stored in our database under your account and is not shared with third parties except as described in the Subprocessors section.
- Documents: Insurance certificates, W-9 forms, and other files you upload to the Document Vault, stored in Supabase Storage under a private bucket accessible only to your account.
- Contacts: District transportation contacts you enter — names, titles, email addresses, and notes.
- Bid outcomes and contracts: Records you create about bids you submitted, won, or lost, and related contract values.
- IFB documents: PDF files you upload to the IFB Parser are sent to Anthropic for processing and are not stored by RouteReady after parsing.
Usage data
- Aggregated page views and feature usage tracked by Vercel Analytics. No personally identifiable information, no session recording, no behavioral profiling.
2. How we use your data
- To operate the RouteReady platform and deliver the features you use.
- To send bid alert emails, renewal reminder emails, and transactional messages you have opted into by creating an account.
- To generate AI-assisted content (outreach drafts, IFB summaries, Q&A responses, bid next-steps, daily briefs) using your company profile, contact data, fleet records, and uploaded documents as context. See Section 3 for details on AI processing.
- To process billing and manage your subscription through Stripe.
- To enforce feature gating — checking which plan features your account can access — server-side only.
- To detect and prevent abuse, fraud, or security incidents on the platform.
We do not sell your personal data. See Section 8 for the analytics and advertising tools RouteReady uses on the public marketing site.
3. AI processing and your data
Several features — IFB parsing, outreach drafting, Ask RouteReady, bid next-steps, and daily brief — send data to Anthropic's Claude API to generate responses.
What is sent to Anthropic: Prompts sent to Claude may include your company name, vehicle types, service area, contact names, district names, bid details, driver certification data, fleet records, and excerpts of IFB documents you upload. This data is included as context so Claude can generate relevant, personalized output.
Anthropic's data use: Data sent to Anthropic is subject to Anthropic's Privacy Policy. RouteReady uses the API with prompts-not-used-for-training defaults as provided by Anthropic's API terms for business customers.
AI outputs are not guarantees: All AI-generated content — outreach drafts, IFB summaries, bid insights, contract predictions — may contain errors, omissions, or inaccuracies. You are responsible for reviewing and verifying all AI-generated content before using it in a bid submission or business decision. Contract intelligence predictions are estimates based on public historical data, not official procurement schedules.
4. Subprocessors
We share data only with the vendors listed below, solely to operate the service.
| Vendor | Purpose | Data sent |
|---|---|---|
| Supabase | Database, authentication, file storage | All structured data and uploaded files |
| Stripe | Payment processing and subscription management | Email, billing details, subscription status |
| Resend | Transactional email delivery | Email address, alert content |
| Anthropic | AI content generation (Claude API) | Company profile, bid details, document excerpts (see Section 3) |
| Vercel | Hosting, serverless functions, cron jobs, analytics | Request logs, aggregated usage (no PII in analytics) |
| Apify | Scraper infrastructure for bid discovery | No user data sent — scraper runs are isolated |
| Google Analytics | Marketing-site traffic analytics (public pages only) | Page views, referrer, approximate location — see Section 8 |
| Meta Pixel | Marketing-site advertising measurement (public pages only) | Page views, browser identifiers — see Section 8 |
| Apollo.io | Company-level visitor identification for sales follow-up (public pages only) | Company/organization inferred from browsing — see Section 8 |
We do not use PostHog or session-replay tools (such as Hotjar or FullStory) that record on-page behavior. None of the vendors above receive data from the authenticated dashboard, CRM, or admin tools — see Section 8 for the marketing-site tools specifically.
5. Data retention
We retain your data as long as your account is active and for a period afterward as described below.
- Active accounts: All data retained for the life of the subscription.
- Cancelled subscriptions: Account data is retained for 30 days after cancellation. During this window you can export your data or reactivate. After 30 days, account and associated records are scheduled for deletion.
- Deleted accounts: We permanently delete your account data within 30 days of a deletion request. Stripe transaction records may be retained longer to satisfy financial and tax obligations.
- IFB documents: PDFs uploaded to the IFB Parser are not stored after parsing is complete. They are transmitted to Anthropic and discarded.
- Driver and certification data: Stored as long as your account is active. Deleted within 30 days of an account deletion request.
- Uploaded documents (Document Vault): Stored in a private Supabase Storage bucket. Deleted when you delete them or when your account is deleted.
- Rate limit logs: Purged after 7 days automatically.
6. Data security (MA 201 CMR 17.00)
RouteReady is operated from Massachusetts and may handle personal information about Massachusetts residents. We maintain a written information security program consistent with the requirements of 201 CMR 17.00.
- Encryption in transit: All connections use HTTPS/TLS. No plaintext transmission of personal data.
- Encryption at rest: Data stored in Supabase (hosted on AWS) uses AES-256 encryption at rest.
- Tenant isolation: Row-level security (RLS) is enabled on all tables containing user data. Each operator can only access their own records. The service-role key is backend-only and never exposed to clients.
- Access controls: Admin and staff tools require an authenticated staff account with the appropriate role — there is no shared admin password or secret key. No shared or guest credentials exist for production data.
- Authentication: Passwords are hashed by Supabase Auth (bcrypt). Session tokens are stored in HttpOnly cookies.
- No API keys in frontend: Only the Supabase anonymous key (which is subject to RLS) is exposed to the browser. Service keys and Stripe secret keys are server-side only.
- Uploaded files: Stored in private Supabase Storage buckets. Accessed only via short-lived signed URLs. Executable file types are not accepted.
If you believe a security vulnerability exists, please report it to support@routereadyma.com. We will respond within 48 hours.
7. Your rights
You may exercise any of the following rights by using the in-app tools at Settings → Privacy & Data or by emailing support@routereadyma.com.
- Export: Request a JSON export of all data associated with your account, including your profile, bids, contacts, fleet records, and contract tracking data.
- Correction: Update or correct your account data at any time through Settings.
- Deletion: Request deletion of your account and all associated data. Your account will enter a 30-day grace period during which you can export your data. After 30 days, deletion is permanent.
- Email opt-out: You can disable bid alert emails and renewal reminders from Settings → Alerts at any time.
We will respond to requests within 30 days. We may need to verify your identity before processing a deletion request.
Massachusetts residents have rights under 201 CMR 17.00 regarding the security of their personal information held by businesses. If you believe your personal information has been compromised, contact us immediately at support@routereadyma.com.
9. Children
RouteReady is a business-to-business software platform intended for adults operating transportation businesses. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, contact us at support@routereadyma.com and we will delete the account.
10. Changes to this policy
We will notify active users by email at least 14 days before any material change to this policy takes effect. The “Last updated” date at the top of this page reflects the most recent revision. Continued use after the effective date constitutes acceptance of the updated policy.
11. Contact
For privacy questions, data requests, or to report a security concern:
- Email: support@routereadyma.com — include “Privacy” in the subject line.
- In-app: Settings → Privacy & Data
RouteReady is operated by an individual sole proprietor. A registered business entity and formal DPO designation are planned. Until then, all privacy inquiries are handled directly by the founder at the email above.