The rest of this page explains each of those points precisely, including exactly which companies receive which data.
FlexRoute is an independent route-optimisation tool operated by a single developer. You can reach us at flexrouteapp@gmail.com or through our contact page.
FlexRoute is not affiliated with, endorsed by, or connected to Amazon.com, Inc. or any of its subsidiaries. We are not affiliated with any delivery platform.
Most of what you put into FlexRoute never leaves your phone. The following are saved in your browser's local storage so the app still works the next time you open it:
We cannot read any of this remotely. You can erase all of it at any time using Settings → Clear app data, or by clearing site data for FlexRoute in your browser or Android app settings. Uninstalling the app also removes it.
Some features can't work without sending data to an outside service. Here is the complete list.
| Data | Goes to | Why |
|---|---|---|
| Addresses you type or scan |
Photon (Komoot), Nominatim (OpenStreetMap Foundation), U.S. Census Geocoder, and Google Maps — only if you supply your own API key | To convert a written address into map coordinates, and to suggest addresses as you type |
| Map coordinates for your stops |
OSRM routing service | To calculate real driving times and produce the optimised order |
| Screenshots or PDFs you scan |
Google Cloud Vision, for server-side scanning | To read the addresses printed in the image |
| Your email address | Resend (delivers the code), Stripe (payment records) | Only if you buy a subscription — to send your sign-in code and link your purchase |
| Payment details | Stripe only | To process payment. These never touch FlexRoute's servers. |
| IP address and basic request logs |
Netlify, our host | Standard server logs, security and abuse prevention |
Depending on your device, scanning happens either entirely on your phone or on our server. When it happens on the server, the image is sent to Google Cloud Vision, the text is extracted, and the image is discarded when the request finishes. FlexRoute does not save your screenshots, and does not store them in any database.
Scanned screenshots typically contain delivery addresses and package numbers. Please avoid uploading images containing information you don't want processed — you can always add stops by typing them instead.
If you tap Use GPS to detect location, your browser asks for permission and FlexRoute uses those coordinates once to fill in your starting point. We don't track you in the background, we don't log your movements during a shift, and we don't record where you drive. Declining the permission only means you type your depot address instead.
To be direct with you: delivery addresses and your home address are personal information. FlexRoute is built so that this data stays on your device wherever possible, but geocoding and routing genuinely require sending addresses to the mapping services listed above. Any tool that turns an address into a route must do this. What we can promise is that we don't store them server-side, don't attach them to your identity, and don't sell or share them for advertising.
FlexRoute is usable with no account at all. If you subscribe, we ask for an email address and send you a six-digit sign-in code. We store that email and a short-lived code so we can confirm it's you and check whether your subscription is active. The code expires shortly after it's issued.
We use your email only to: deliver sign-in codes, confirm your subscription status, and reply if you contact support. We don't send marketing email.
Subscriptions are handled by Stripe. Card numbers are entered on Stripe's own checkout page and are never transmitted to or stored by FlexRoute. We keep only your email and whether your subscription is currently active.
Because most of your data is on your own device, the fastest way to exercise most rights is Settings → Clear app data, which is immediate and complete.
For anything we hold server-side — realistically, your email and subscription record — you can ask us to show it to you, correct it, delete it, or send you a copy. Email flexrouteapp@gmail.com and we'll respond within 30 days.
If you're in the UK or the European Economic Area, the GDPR gives you these rights plus the right to object to processing and to complain to your national data protection authority. Our lawful bases are: performance of a contract, for delivering the service you asked for; legitimate interests, for security and abuse prevention; and consent, for optional device location.
If you're in California, the CCPA gives you rights to know, delete, correct, and opt out of sale or sharing. We do not sell or share personal information, and we never have.
FlexRoute is a tool for working delivery drivers and is not directed at children. We don't knowingly collect information from anyone under 13 (or under 16 in the EEA/UK). If you believe a child has provided us information, contact us and we'll delete it.
Traffic to FlexRoute is encrypted over HTTPS. Payments are isolated at Stripe. Our backend functions reject requests that don't originate from our own domain, which limits third parties from running up our billed services in your name.
No system is perfectly secure. If you find a vulnerability, please tell us at flexrouteapp@gmail.com before disclosing it publicly — we'll respond quickly and credit you if you'd like.
Our providers — Netlify, Stripe, Google, Resend, and the mapping services — operate servers in several countries, including the United States. Using FlexRoute means your data may be processed outside your home country under those providers' own safeguards.
If we change how FlexRoute handles data, we'll update this page and move the "last updated" date at the top. For changes that meaningfully affect your privacy, we'll show a notice in the app. Continuing to use FlexRoute after a change means you accept the updated policy.
Questions about privacy, or a request about your data:
flexrouteapp@gmail.com · Contact page