Last updated: 16 September 2026
The repository does not identify the Velo.Route operating legal entity, public privacy contact, or physical address. Those details must be confirmed before this policy is published for production use.
1. Scope
Velo.Route is transport management and visibility software for client businesses, transport providers, their authorised managers, drivers, and passengers. This policy describes how information is processed through the Velo.Route web and mobile applications.
A business or transport provider may have separate responsibilities for the transport service it arranges or performs. This policy does not replace that organisation's own privacy notices or obligations.
2. Information Velo.Route processes
The information processed depends on the role and features used. The current product implementation may process the following categories.
- Account and access information: names, email addresses, phone numbers where supplied, account roles, organisation membership, and authentication-related account data.
- Business and provider information: business or transport-provider names, contact details, relationships between businesses and providers, and account setup information.
- Driver and vehicle information: driver contact details, driver assignments, vehicle information, licence and verification fields, home-address and document-reference fields where submitted for verification.
- Passenger information: names, contact details, pickup and drop-off addresses, related coordinates, and optional emergency-contact information where supplied.
- Operational trip information: route requests, trips, stops, assignments, pickup and drop-off events, timestamps, status updates, notifications, and operational records.
3. Location and live trip data
Velo.Route processes location information to support live transport operations. The mobile driver workflow obtains current device location when a driver starts a trip and when the driver records trip-stop actions. It can publish the active driver's coordinates, movement state, accuracy, and the time of the update for the assigned trip.
Active location is made available to the authorised client business, transport provider, and passengers connected to that trip. Where a passenger trip-share feature is enabled, a time-limited share may also expose the relevant live trip location. Live driver-location entries are cleared when the trip is ended by the current implementation.
Pickup and drop-off addresses can be geocoded into coordinates for route planning and trip operations. Location signals, GPS accuracy, device connectivity, mapping data, and estimated arrival times can be incomplete or inaccurate and should be treated as operational information rather than a guarantee.
4. How information is used
Velo.Route uses information to:
- create and secure accounts and role-based access;
- connect client businesses and transport providers for transport operations;
- create, assign, operate, and record routes, vehicles, drivers, passengers, trips, and stops;
- show relevant live trip, location, and journey-status information;
- send account setup, password-reset, and in-product operational notifications when those services are configured; and
- maintain operational records, investigate issues, and protect the reliability and security of the service.
5. Role-based access
Velo.Route uses authenticated, role-aware workspaces. Access to business, provider, driver, passenger, and trip information is intended to be scoped by the user's role, organisation relationship, and trip assignment. Not every user has access to all information in the platform.
Organisations using Velo.Route are responsible for assigning access appropriately and for ensuring that the people they invite have a legitimate reason to view the information made available to them.
6. Service providers used by the product
The current application uses Firebase services for authentication, Cloud Firestore data, Realtime Database live data, and Cloud Functions. It can use Google Maps Platform for address geocoding and map-related route information. Email delivery can use a configured SMTP provider or Firebase's password-reset flow.
These services process information only as needed to provide the product features configured for a deployment. Their own terms and privacy documentation apply to their services.
7. Retention and deletion
The current repository does not publish a fixed retention schedule for every data category. Live trip-location entries are used during active trips and are cleared by the trip-end workflow. Durable trip, stop, and operational records may be retained for the operation and reporting needs of the business or provider using the platform.
Passenger accounts include a profile-deletion workflow that removes the account's profile and related live/share data according to the current implementation. A deployment should define and document retention periods for operational records, location history, and verification information before production use.
8. Security
Velo.Route uses authenticated access, role-aware permissions, and server-side workflows for important operational actions. These measures reduce the risk of inappropriate access, but no service can guarantee absolute security. Users and organisations must protect account credentials and promptly report suspected unauthorised access to their administrator.
9. Your privacy choices and requests
Depending on applicable law and the relationship with the business or transport provider using Velo.Route, a person may ask to access, correct, delete, or object to the handling of their personal information. Start with the designated administrator of the business or transport provider that arranged your access or transport.
A verified public Velo.Route privacy contact is not configured in this repository. That channel should be added before production so people can raise requests that cannot be handled by their organisation administrator.
10. Policy updates and contact
Velo.Route may update this policy when product features or data practices change. The updated version should display a revised effective date on this page.
For now, use your business or transport-provider administrator for account and transport-data questions. Before public launch, add the Velo.Route legal entity details and a verified privacy contact method to this policy.