Trust and Compliance
Last updated 4 October 2026
This page is the Trust and Compliance documentation referred to in our Subscription Terms and Data Processing Addendum. It sets out who processes data on our behalf and where, the security measures we have in place, how we tell customers about changes, and how to reach us.
Onroute Intelligence Inc. is a corporation incorporated in the State of Delaware, USA, with its registered office at 251 Little Falls Drive, Wilmington, Delaware 19808, USA. When an installation business uses Onroute Intelligence, it is the controller of its customers' personal data and we are its processor under the Data Processing Addendum.
Documents
- Subscription Terms (UK, September 2026)
- Service Level Agreement (UK, September 2026)
- Data Processing Addendum (UK, edition of 2 September 2026)
- Privacy Policy
- Cookie Policy
Where data lives
- Customer data (jobs, customers, certificates, photographs, messages, documents) is stored in a database and file store hosted by Supabase in London, United Kingdom.
- Backups are held in two places: Supabase's own database backups, and an independent, write-only archive in Amazon Web Services London (eu-west-2), under a separate account, with object locking so that a backup cannot be altered or deleted before its retention period ends.
- Application servers that run the Onroute Intelligence app, the operations console and the document renderer are hosted by Vercel in Washington DC, United States. The API gateway runs in London. Data passes through these servers while a page or document is being produced.
- Some services run in the United States, including our AI provider, SMS delivery, geocoding and routing. Each is listed below with the data it receives.
Because some processing happens outside the United Kingdom, our Data Processing Addendum includes the UK International Data Transfer Agreement, and each sub-processor outside the UK or EEA that is not covered by an adequacy decision is bound by an appropriate transfer mechanism (DPA clause 2.2.5 and Table 2).
Sub-processors
These are the companies that process customer personal data on our behalf in providing Onroute Intelligence, including the company that provides our customer support. The list is published under clause 2.2.2 of the Data Processing Addendum.
Core platform
| Sub-processor | Purpose | Data it receives | Location |
|---|---|---|---|
| Supabase | Database, authentication, file storage and the server-side functions that run the service | All customer data: staff accounts, customers' names, addresses, phone numbers, emails and messages, certificates, signatures, photographs and documents | Database and file storage: London, UK. Region for server-side functions: being confirmed |
| Vercel | Hosting for the app, operations console, API gateway and customer portal; renders PDF certificates and documents | Page requests and the content of documents while they are being rendered | Washington DC, US (app, operations console, document rendering); London, UK (API gateway and customer portal) |
| Amazon Web Services | Independent backup archive; storage of documents migrated from our previous system | Full copies of customer data (backups); migrated attachments, photographs and certificates | London, UK (eu-west-2) |
| GitHub | Runs the nightly backup job, through which the database backup passes in transit to the archive | Database backup, in transit only | Being confirmed |
| Upstash | Rate limiting for the app | IP addresses of requests, used to count them | Being confirmed |
| Expo (EAS Update) | Delivers updates to the Onroute Intelligence mobile app | Update checks from each device: app and platform details and the device's IP address | US company; processing region being confirmed |
Support
Our customer support is provided by people under contract to us. They work inside Onroute Intelligence's own systems, under individual named accounts, and their access is recorded in the audit log.
| Sub-processor | Purpose | Data it receives | Location |
|---|---|---|---|
| N90 Labs Ltd | Customer support, onboarding and account management: answering support requests, and viewing and, when a customer asks, amending accounts, jobs and the documents in them | Any customer data held in the service, viewed as a support request requires: staff accounts, customers' names, addresses, phone numbers, emails and messages, certificates, signatures, photographs and documents | UK |
Communications
| Sub-processor | Purpose | Data it receives | Location |
|---|---|---|---|
| Resend | Sends all email from the service, including sign-in emails and messages to customers | Recipient names and email addresses, message content | US company; processing region being confirmed |
| Twilio | Sends and receives SMS, WhatsApp and RCS messages; registers business phone numbers | Customers' phone numbers and message content; the installer's business address for number registration | US |
| MessageBird (Bird) | Sends and receives SMS from an installer's existing numbers | Customers' phone numbers and message content | Being confirmed |
AI features
| Sub-processor | Purpose | Data it receives | Location |
|---|---|---|---|
| Anthropic | AI features: job summaries, answers from an installer's document library, text recognition on scanned documents, and photograph analysis in the customer portal | Job messages, notes, status history and the customer's first name (summaries); library document excerpts and the question asked (library search); scanned documents (text recognition); photographs (customer portal) | US |
Our Data Processing Addendum (clauses 2.2.10 and 2.2.11) governs how AI providers are used. We do not use customer personal data to train any AI model in a form that identifies, or can reasonably be used to identify, an individual.
Location and addresses
| Sub-processor | Purpose | Data it receives | Location |
|---|---|---|---|
| Mapbox | Converts addresses to map coordinates; displays maps | Customer, job and engineer addresses and coordinates | US |
| Google Maps Platform | Route planning: travel times and directions between stops | Coordinates of stops (engineers' start points and job sites) | US |
| Apple WeatherKit | Weather at each stop | Coordinates of job sites only | US |
| Ideal Postcodes | UK address look-up as an address is typed | Partial address text | UK company; hosting region being confirmed |
| postcodes.io | Confirms the country and local authority for a postcode | Postcode only | Being confirmed |
Sign-in
| Sub-processor | Purpose | Data it receives | Location |
|---|---|---|---|
| "Sign in with Google" for staff accounts | Sign-in identity | US |
Monitoring
| Sub-processor | Purpose | Data it receives | Location |
|---|---|---|---|
| Sentry | Error reporting for the app, operations console, mobile app and customer portal | Error reports and stack traces. In the mobile app and customer portal, configured not to send user identity by default | Germany |
| Axiom | Storage of server logs from Vercel | Server log entries | Frankfurt, Germany |
| PostHog | Product analytics | In the app: staff identity and named events only. Autocapture and session recording are switched off in the app because of customer data. In the customer portal: page views and events, identified by the job's short reference; session recordings, with every form input masked; and error reports | EU |
Regulatory and finance submissions
These are used only when an installer chooses to make the submission.
| Sub-processor | Purpose | Data it receives | Location |
|---|---|---|---|
| ENA Connect Direct (Energy Networks Association) | Connection applications to electricity network operators and the low-carbon-technology device register | Site address, MPAN, device details, customer name, email and phone | UK |
| NAPIT | Building Control notifications | Job, site and customer details, including phone and email | UK |
| Novuna (PayByFinance) | Consumer finance: checking an application and confirming goods dispatched | Applicant name and customer address | UK |
Payments
| Sub-processor | Purpose | Data it receives | Location |
|---|---|---|---|
| Stripe | Card payments through the customer portal's payment form | Card and billing details, entered directly into Stripe's own form | Being confirmed |
Card payments and subscription billing inside the Onroute Intelligence app are configured, not live. Stripe is listed here because the payment form in the customer portal is provided by Stripe.
Website
Our website at onroute.io and onrouteintelligence.ai is not part of the service we provide to customers: for the personal data it collects we are the controller, as our Privacy Policy explains. It uses these providers.
| Sub-processor | Purpose | Data it receives | Location |
|---|---|---|---|
| Vercel | Hosting for our website | Page requests, logged with the IP address, the page asked for and browser details | US |
| Axiom | Storage of the website's request logs from Vercel | Request log entries: IP address, page and browser details | Frankfurt, Germany |
| Resend | Delivers demonstration requests and whitepaper sign-ups to our mailbox as emails | What the form contains: for a demonstration request, name, company, email address, telephone number, business details and message; for a whitepaper sign-up, the email address and the paper | US company; processing region being confirmed |
| Google Workspace | Our support@onroute.io mailbox, where demonstration requests, whitepaper sign-ups and emails to us are held | The content of those requests and emails | US company; processing region being confirmed |
Not sub-processors
Some connections send data into Onroute Intelligence using the installer's own account, and the provider acts for the installer, not for us: WhatConverts lead import, and the Ohme Connect browser extension. Trackers an installer chooses to add to its own customer-portal pages (Google Tag Manager, Google Analytics, Meta Pixel, Trustpilot) are set by the installer, who is the controller for them.
Slack (operational alerts with no customer data) and healthchecks.io (heartbeat monitoring, no data) are tools we use but do not receive personal data.
Changes to sub-processors
Under clause 2.2.2 of the Data Processing Addendum we notify customers of any intended addition or replacement of a sub-processor, and a customer may object in writing within ten days of being notified. This page is updated when the change takes effect.
Security
We publish what is in place, not what we aspire to. We do not currently hold ISO 27001, SOC 2 or any other security certification, and we do not claim one. Security questionnaires are answered on request at the contact below.
Access and tenant separation
- The database schema enforces row-level security on customer tables, so that a query can only return the rows belonging to the signed-in user's organisation. Database search functions check organisation membership before returning results, and automated tests check that the policies agree.
- Sign-in is by email and password, or with Google. Password recovery uses a one-time code rather than a link. Multi-factor authentication is available through Google sign-in where your account has it enabled; we do not yet offer a separate authenticator step of our own.
- Access to customer data by our support staff, including those provided by N90 Labs Ltd, is recorded in an audit log with the staff member's identity attached.
Audit trail
- Changes made through the service are written to an audit log that users cannot edit. Job status changes and document sharing are also logged.
Application security
- All connections use HTTPS, with HTTP Strict Transport Security.
- The app sends a Content Security Policy, Referrer-Policy and X-Frame-Options headers.
- Requests to the app are rate limited per IP address, with a tighter limit on authentication callbacks.
- Third-party credentials are removed from error messages before they are logged. Regulatory scheme passwords are held encrypted in Supabase Vault and are never returned, logged or audited; the access tokens they produce are used for the submission and never stored. Access tokens are stored as SHA-256 hashes.
Analytics and error reporting
- In the Onroute Intelligence app, analytics autocapture and session recording are switched off so that customer data is not captured.
- In the customer portal, analytics records sessions with every form input masked, and captures errors.
- In the mobile app and the customer portal, error reports are configured not to include user identity by default; in the mobile app, message content that could contain personal data is removed before sending.
Mobile app
- The sign-in session, cached jobs, and queued notes, form answers and signature details are encrypted, with keys held in the device's keychain. Queued photographs, signature images and cached documents are kept as files in the app's private storage, under the device's own encryption.
- The unsent-work queue is deleted at sign-out. On Android, the app's data is excluded from device backup.
- Location is read once, when a signature is captured, and only if the engineer allows it. There is no background location tracking.
Backups and recovery
- A full database backup is taken every night at 02:15 UTC to an independent AWS account in London (eu-west-2), held for 30 days under object lock in compliance mode, which prevents alteration or deletion before expiry.
- Files are synchronised to the same archive every night at 02:45 UTC, with a weekly full reconciliation and a near-real-time push when a file is uploaded. Files are protected by object lock for 90 days after they are written and kept in the archive after that.
- The account used for the archive can write but cannot delete. Each backup job reports to an independent monitor that alerts us if a run is missed or fails.
Data return and deletion
- During a subscription and for 30 days after it ends, a customer can export its data (Subscription Terms clause 4.7). After that period we may delete it.
- On termination of the Data Processing Addendum, we return or securely dispose of customer personal data at the customer's option, unless we are required by law to keep it (DPA clause 2.7).
Incidents
- We notify customers in writing and without undue delay if we become aware of a breach of security of their personal data (DPA clause 2.2.7).
Audit
- To demonstrate our compliance with the Data Processing Addendum, we provide the information a customer reasonably requires. Where that information alone is not reasonably sufficient, the customer may audit us, by up to two of its representatives and at its own cost, on at least one month's written notice, no more than once a calendar year, at a time convenient to us (unless a supervisory authority requires otherwise). If a third party conducts the audit, we may object to an auditor who is not suitably qualified or independent, is a competitor, or is otherwise manifestly unsuitable (DPA clause 2.2.9).
Contact
Data protection and security contact: support@onroute.io
To report a security concern, email the same address. We read every report.
Onroute Intelligence Inc., 251 Little Falls Drive, Wilmington, Delaware 19808, USA.