FlexRoute

Security

What we do to protect your data, stated plainly — including the parts we don't control.

How FlexRoute is built

Your route data stays on your phone

Stops, addresses, depot and home locations are held in your device's local storage. There is no FlexRoute database of driver routes, so there is no central store of delivery addresses to breach.

No passwords to steal

FlexRoute has no password system. Free use needs no account at all. Subscribers sign in with a short-lived code sent to their email, so there's no password database and nothing to reuse if another service is breached.

We never touch your card

Payment details are entered on Stripe's own checkout and never reach FlexRoute's servers. We store only your email and whether your subscription is active.

Encrypted in transit

All traffic runs over HTTPS. The app refuses to run on any domain other than flexrouteapp.com, so a cloned copy on another host won't function.

Backend requests are origin-checked

Our scanning and address-lookup functions reject requests that don't come from FlexRoute itself. This stops third parties from running billed services in your name and protects the shared rate limits the app depends on.

What we don't claim

Being straight with you is more useful than a wall of badges:

What you can do

Reporting a vulnerability

If you've found a security problem, we want to hear about it, and you won't get a hostile response.

Security reports
flexrouteapp@gmail.com

Please include what you found, how to reproduce it, and what an attacker could do with it. We'll acknowledge within 3 business days, tell you our assessment and a rough fix timeline, and let you know when it's resolved. We're happy to credit you publicly if you'd like.

What we ask: give us reasonable time to fix an issue before disclosing it publicly. Don't access, modify or delete data belonging to other drivers. Don't run attacks that degrade the service for people trying to work. Test against your own account and data only.

FlexRoute is a solo project with running API costs and no security budget, so we can't offer paid bounties. What we can offer is a fast, respectful response, public credit, and an actual fix.

If something goes wrong

If a breach ever affects your data, we'll tell affected users by email, publish what happened here, and notify regulators where the law requires it. We won't quietly sit on it.