Privacy Policy
Who we are
Our website address is: https://www.instaroute.com.
InstaRoute is a B2B SaaS platform for transportation providers. We serve verified business contacts only.
Comments
When visitors leave comments on the site, we collect the data shown in the comments form, along with the visitor’s IP address and browser user agent string to help spam detection.
Media
If you upload images to the website, avoid uploading images with embedded location data (EXIF GPS).
Driver App Users: The Driver App requests access to your device’s camera solely to capture vehicle images for required safety checks and DVIR (Driver Vehicle Inspection Report) forms.
Photos taken are used only for vehicle safety verification, are securely stored, and are never shared with third parties.
Cookies
If you leave a comment, you may opt-in to saving your name, email address, and website in cookies (lasts one year).
Temporary cookies are set on the login page to confirm browser support and are discarded when you close your browser.
Login cookies expire in two days (or two weeks if you select “Remember Me”). Log out to remove cookies.
Embedded Content
Articles may contain embedded content (videos, images, articles) from other sites, which may collect data and use cookies.
Text Messaging (SMS) Policy
We contact verified transportation businesses via SMS for legitimate service communication only, following initial email contact or business inquiry.
Reply STOP to opt out anytime. InstaRoute does not sell or share mobile data for marketing.
“No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All other categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.”
Data Sharing
If requesting a password reset, your IP is included in the reset email.
We do not sell or share user data for marketing.
Google User Data
InstaRoute lets a transportation company connect its business mailbox so trip requests, manifests, and customer replies can be worked inside the InstaRoute unified inbox. Connecting a Google account grants InstaRoute access through Google’s consent screen, and you can revoke that access at any time from your Google Account permissions page.
What we access. With your permission, we access the messages, threads, and labels in the connected mailbox, together with the basic Google profile information (name and email address) of the account that authorized it. We access only the mailbox you connect.
How we use it. We use this access solely to provide InstaRoute features: displaying mail in the unified inbox, marking messages read or unread, organizing and filing threads, drafting and sending replies on your behalf, and extracting trip details such as pickup times, addresses, flight numbers, and passenger names from incoming reservations and manifests so they can become trips.
Automated processing. Extracting trip details relies on automated processing, including artificial intelligence services acting as our data processors. This processing exists only to deliver the features described above. We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models.
Service providers. We use Nylas, Inc. as our email infrastructure provider. Nylas acts as our data processor and connects to Google on our behalf under contract. We do not sell Google user data, and we do not transfer it to others except to provide the features you requested, to comply with applicable law, or as part of a merger or acquisition after giving notice.
Data protection. InstaRoute uses HTTPS/TLS to protect data in transit. Google mailbox data stored by InstaRoute is held in Google Cloud Firestore, which encrypts stored data at rest. Google OAuth access and refresh tokens are managed by our email infrastructure provider, Nylas; InstaRoute does not store those Google tokens. InstaRoute stores only the associated grant identifier, while its Nylas credentials are kept in Google Secret Manager and made available only to server-side services. Access to inbox data is limited to authenticated dispatchers, managers, and administrators belonging to the same customer organization. Direct client access to OAuth configuration and direct client writes to inbox data are blocked. OAuth connection requests use signed, expiring, single-use state to prevent tampering and replay.
Human access. InstaRoute personnel do not read your Google user data except with your explicit consent, such as when you request support, to comply with applicable law, or where necessary for security purposes such as investigating abuse.
Retention and deletion. Message content synchronized into InstaRoute is retained while the mailbox stays connected and the account remains active. Disconnecting the mailbox ends all further access. To request deletion of data already synchronized, contact support@instaroute.com.
Limited Use. InstaRoute’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Data Retention
Comments and metadata are retained indefinitely.
Business contact registration/submissions are retained for ongoing communication unless requested otherwise.
Your Rights
You may request an export or deletion of your personal information by contacting: support@instaroute.com
Data Transfers
Visitor comments may be checked automatically for spam.
Analytics and automation tools help measure engagement and outreach; no sensitive/personal data is shared externally.
InstaRoute Driver App Privacy
InstaRoute Driver App respects your privacy.
This application requests access to the device’s camera only to complete inspection forms with vehicle images.
Photos are used exclusively for safety verification and DVIR purposes.
No images or personal data are shared with third parties. All collected information is securely stored and used only for vehicle safety requirements.