Privacy Policy
Last updated: September 9, 2026
1. Information We Collect
We collect information you provide directly when you create an account, including your name, email address, company name, and business address. When you use our route optimization features, we process appointment addresses to calculate drive times via the Google Maps API. We do not sell your personal information to third parties.
2. How We Use Your Information
We use your information to provide and improve our scheduling and route optimization services, communicate with you about your account, and send service-related notifications. These account and trial messages are transactional and do not depend on marketing consent. If you separately choose to receive product updates and early-access news, we also use your email for those marketing messages. You can withdraw that consent at any time using the unsubscribe link in a marketing email or by contacting us. Location data is used solely for calculating drive times and optimizing appointment routes. Connected calendar account data and Google user data are used only as described in Section 5 below.
3. Data Storage and Security
Your data is stored securely using industry-standard encryption. We use Supabase for authentication and data storage, with all data encrypted at rest and in transit. We retain your data for as long as your account is active or as needed to provide our services.
4. Third-Party Services
We integrate with third-party services including Google Maps (route calculations), Google Calendar and Google Meet (the Google features described below), Microsoft Graph (Outlook and Microsoft 365 provider-calendar connections), Stripe (payment processing), Mindbody (appointment syncing), Resend (transactional email delivery), Klaviyo (marketing-consent records and opted-in product updates), OpenAI (optional meeting-intelligence processing), and Attio (optional customer-relationship management). Each service has its own privacy policy governing its use of your data. We only share the minimum data necessary for the requested integration to function.
5. Connected Calendar and Google User Data
Provider calendar connections
When a service provider chooses to connect Google Calendar or Microsoft Calendar through a private Smartroute setup link, we receive the provider's connected-account identifier and email address and an OAuth credential. We create a dedicated calendar named “Smartroute — [business name]” and use it to create, update, cancel, and delete that provider's assigned Smartroute appointment events. Those events may include the appointment date and time, customer or group name, customer email and phone number, services, notes, time zone, service address, and assigned-provider names. The business that invited the provider can see the connected email address and connection status, but cannot browse the connected calendar account through Smartroute.
For Google, the permission is limited to secondary calendars created by Smartroute and does not let Smartroute read or modify the provider's primary calendar or other existing calendars. Microsoft's delegated calendar permission may authorize broader calendar access at the Microsoft platform level. Smartroute limits its provider-calendar operations to the dedicated secondary calendar it creates and does not use this feature to read or modify existing calendars.
Smartroute Meeting Intelligence
A separate, founder-controlled integration uses read-only Google Calendar and Google Meet access for the dedicated Smartroute demo workflow. When enabled, Smartroute first matches a completed Google Meet session to the exact scheduled demo event. It then reads the meeting's participant details and Google-generated transcript to create protected meeting evidence and customer follow-up. Full meeting recordings remain with Google and are not stored by Smartroute. If separately enabled, transcript text may be processed by OpenAI to produce evidence-backed customer-relationship suggestions. Derived information, including participant and contact details, Company attributes, Deal fields, follow-up notes, next steps, and tasks, may be sent to Attio. This integration does not modify Google calendars, meetings, recordings, or accounts.
Storage, sharing, and removal
Provider-calendar OAuth credentials are encrypted at rest and retained until the provider calendar is disconnected. Disconnecting removes the stored credential and stops future updates. The dedicated calendar and events already created in the connected Google or Microsoft account remain until the account owner deletes them. The Meeting Intelligence OAuth credential is kept as a restricted deployment secret. If Meeting Intelligence is activated, transcript evidence is retained to provide and audit customer follow-up. When automated retention is enabled, raw transcript text is redacted after the configured period. You may request deletion as described below.
We do not sell connected calendar account data or Google user data or use it for advertising. We share it only with service providers necessary to deliver the requested features; for security or legal reasons; or, with your explicit consent, to provide another prominent user-facing feature you request. Smartroute's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You may review that policy on Google's website. You may revoke Google access from your Google Account or Microsoft access from your Microsoft Account at any time, or contact us using the address below.
6. Your Rights
You may request access to, correction of, or deletion of your personal data at any time by contacting us. You can export your data from the application settings. Upon account deletion, we will remove your personal data within 30 days, except where retention is required by law.
7. Contact Us
If you have questions about this privacy policy or our data practices, please contact us at support@smart-route.app.