# Privacy Policy

**Last updated:** November 13, 2025

This Privacy Policy explains how **Routerra Anatolii Trubin** ("we", "us") collects, uses, discloses, and safeguards personal information when you use our web application and mobile applications (collectively, the "Services"). If you do not agree, please do not use the Services. Contact us at [info@routerra.io](mailto:info@routerra.io).

## Summary of key points

- We collect the data you provide (e.g., email), **precise location while using the app** (mobile), microphone input (opt-in), camera/photos you choose, files you select, purchase/diagnostic data, and analytics/usage data.
- Processors include Clerk (auth), RevenueCat (mobile subscriptions), Mapbox & Google Maps (maps), **Hotjar** (web analytics, heatmaps & session replay), **Tawk.to** (web live chat), **Sentry** (error monitoring), PostHog (analytics & optional session replay on web and mobile - hosted in US), and Bugsnag (crash reporting on mobile).
- We collect device identifiers (Android ID, device fingerprints) via PostHog, Bugsnag, RevenueCat, and Clerk for analytics, crash reporting, purchase validation, and authentication.
- **Website cookies:** Our website uses cookies only for analytics purposes. By continuing to browse after seeing our cookie notice, you consent to analytics cookies.
- You control device permissions (mobile) and can disable optional analytics (PostHog) in Settings → Analytics. However, crash/error reporting (Bugsnag on mobile, Sentry on web/server) is always active to maintain app stability and cannot be disabled. We do not sell personal data.
- Your data may be processed outside your country with appropriate safeguards (e.g., Standard Contractual Clauses for EEA/UK). PostHog data is stored in the United States.
- **Data retention:** Session recordings (90 days), analytics events (12 months), active account data (while account is active), deleted account data (30 days to full deletion).

## 1. What information do we collect?

### Information you provide

- **Account & Contact:** email, password or OAuth identity (via Clerk), support messages (incl. via live chat).
- **User content:** photos/files you select (e.g., attachments to route stops), route names/notes.

### Information collected automatically

- **Usage & analytics:** screens, interactions, performance (web via cookies/SDKs; mobile via SDKs).
- **Session replay:** on _web_ via Hotjar (heatmaps & replay); on _mobile_ optionally via PostHog Session Replay. Sensitive fields are masked where supported; you can disable PostHog analytics/replay via in-app Settings.
- **Diagnostics & errors:** crash reports, stack traces, device/OS, device identifiers, app version (Bugsnag on mobile; Sentry on web/server). These diagnostics are always active and cannot be disabled as they are essential for app stability and security.

## 2. How do we use your information?

- **Provide the Services** (routing, navigation, subscriptions) — _GDPR:_ Contract (Art. 6(1)(b)).
- **Authenticate & secure accounts** — Contract; Legitimate interests (security, fraud prevention).
- **Process purchases/subscriptions** (mobile) — Contract; Legal obligation (tax/records).
- **Analytics & product improvement (PostHog, Hotjar)** — Legitimate interests; where required, Consent (e.g., Hotjar on web; PostHog session replay on mobile; analytics cookies on web). You can disable PostHog analytics in mobile app Settings.
- **Error/crash monitoring & debugging (Bugsnag, Sentry)** — Legitimate interests; Legal obligation (maintaining app security). This is always active and cannot be disabled.
- **Communications** (service/support messages) — Contract; Legitimate interests.
- **Compliance** — Legal obligations.

## 3. When and with whom do we share data?

Processors acting on our behalf include:

- **Clerk** — authentication & accounts (web & mobile).
- **RevenueCat** — in-app purchases & subscription status (mobile).
- **Mapbox** / **Google Maps** — maps/tiles, geocoding, navigation (web & mobile as applicable).
- **Hotjar** — web analytics, heatmaps & session replay (web only).
- **Tawk.to** — live chat widget & chat transcripts (web only, initiated by you).
- **Sentry** — web/server error monitoring; PII is minimized/scrubbed.
- **PostHog** (
+ Session Replay) — product analytics (web & mobile).
- **Bugsnag** — crash reporting (mobile).
- **Hosting & CDN** — cloud infrastructure and content delivery.

## 4. Cookies, SDKs, and tracking

### Web Application Cookies

Our web application (app.routerra.io) uses cookies for analytics and essential functionality.

### Your Rights

Under GDPR and applicable data protection laws, you have the following rights:

### Right to Access

You can request access to the personal data we hold about you.

### Right to Rectification

You can request correction of inaccurate personal data.

### Right to Erasure ("Right to be Forgotten")

You can request deletion of your personal data.

**For Web Application (app.routerra.io):**
- Open Settings in the web application
- Navigate to **General → Cookie Settings**
- Adjust your preferences for Analytics & Performance and Support & Chat cookies

**For Mobile App:**
- Open the mobile app and go to **Settings → Analytics**
- Toggle off **Analytics** and/or **Session Replay**
