Trust and Compliance

Last updated 4 October 2026

This page is the Trust and Compliance documentation referred to in our Subscription Terms and Data Processing Addendum. It sets out who processes data on our behalf and where, the security measures we have in place, how we tell customers about changes, and how to reach us.

Onroute Intelligence Inc. is a corporation incorporated in the State of Delaware, USA, with its registered office at 251 Little Falls Drive, Wilmington, Delaware 19808, USA. When an installation business uses Onroute Intelligence, it is the controller of its customers' personal data and we are its processor under the Data Processing Addendum.

Documents

Where data lives

  • Customer data (jobs, customers, certificates, photographs, messages, documents) is stored in a database and file store hosted by Supabase in London, United Kingdom.
  • Backups are held in two places: Supabase's own database backups, and an independent, write-only archive in Amazon Web Services London (eu-west-2), under a separate account, with object locking so that a backup cannot be altered or deleted before its retention period ends.
  • Application servers that run the Onroute Intelligence app, the operations console and the document renderer are hosted by Vercel in Washington DC, United States. The API gateway runs in London. Data passes through these servers while a page or document is being produced.
  • Some services run in the United States, including our AI provider, SMS delivery, geocoding and routing. Each is listed below with the data it receives.

Because some processing happens outside the United Kingdom, our Data Processing Addendum includes the UK International Data Transfer Agreement, and each sub-processor outside the UK or EEA that is not covered by an adequacy decision is bound by an appropriate transfer mechanism (DPA clause 2.2.5 and Table 2).

Sub-processors

These are the companies that process customer personal data on our behalf in providing Onroute Intelligence, including the company that provides our customer support. The list is published under clause 2.2.2 of the Data Processing Addendum.

Core platform

Sub-processorPurposeData it receivesLocation
SupabaseDatabase, authentication, file storage and the server-side functions that run the serviceAll customer data: staff accounts, customers' names, addresses, phone numbers, emails and messages, certificates, signatures, photographs and documentsDatabase and file storage: London, UK. Region for server-side functions: being confirmed
VercelHosting for the app, operations console, API gateway and customer portal; renders PDF certificates and documentsPage requests and the content of documents while they are being renderedWashington DC, US (app, operations console, document rendering); London, UK (API gateway and customer portal)
Amazon Web ServicesIndependent backup archive; storage of documents migrated from our previous systemFull copies of customer data (backups); migrated attachments, photographs and certificatesLondon, UK (eu-west-2)
GitHubRuns the nightly backup job, through which the database backup passes in transit to the archiveDatabase backup, in transit onlyBeing confirmed
UpstashRate limiting for the appIP addresses of requests, used to count themBeing confirmed
Expo (EAS Update)Delivers updates to the Onroute Intelligence mobile appUpdate checks from each device: app and platform details and the device's IP addressUS company; processing region being confirmed

Support

Our customer support is provided by people under contract to us. They work inside Onroute Intelligence's own systems, under individual named accounts, and their access is recorded in the audit log.

Sub-processorPurposeData it receivesLocation
N90 Labs LtdCustomer support, onboarding and account management: answering support requests, and viewing and, when a customer asks, amending accounts, jobs and the documents in themAny customer data held in the service, viewed as a support request requires: staff accounts, customers' names, addresses, phone numbers, emails and messages, certificates, signatures, photographs and documentsUK

Communications

Sub-processorPurposeData it receivesLocation
ResendSends all email from the service, including sign-in emails and messages to customersRecipient names and email addresses, message contentUS company; processing region being confirmed
TwilioSends and receives SMS, WhatsApp and RCS messages; registers business phone numbersCustomers' phone numbers and message content; the installer's business address for number registrationUS
MessageBird (Bird)Sends and receives SMS from an installer's existing numbersCustomers' phone numbers and message contentBeing confirmed

AI features

Sub-processorPurposeData it receivesLocation
AnthropicAI features: job summaries, answers from an installer's document library, text recognition on scanned documents, and photograph analysis in the customer portalJob messages, notes, status history and the customer's first name (summaries); library document excerpts and the question asked (library search); scanned documents (text recognition); photographs (customer portal)US

Our Data Processing Addendum (clauses 2.2.10 and 2.2.11) governs how AI providers are used. We do not use customer personal data to train any AI model in a form that identifies, or can reasonably be used to identify, an individual.

Location and addresses

Sub-processorPurposeData it receivesLocation
MapboxConverts addresses to map coordinates; displays mapsCustomer, job and engineer addresses and coordinatesUS
Google Maps PlatformRoute planning: travel times and directions between stopsCoordinates of stops (engineers' start points and job sites)US
Apple WeatherKitWeather at each stopCoordinates of job sites onlyUS
Ideal PostcodesUK address look-up as an address is typedPartial address textUK company; hosting region being confirmed
postcodes.ioConfirms the country and local authority for a postcodePostcode onlyBeing confirmed

Sign-in

Sub-processorPurposeData it receivesLocation
Google"Sign in with Google" for staff accountsSign-in identityUS

Monitoring

Sub-processorPurposeData it receivesLocation
SentryError reporting for the app, operations console, mobile app and customer portalError reports and stack traces. In the mobile app and customer portal, configured not to send user identity by defaultGermany
AxiomStorage of server logs from VercelServer log entriesFrankfurt, Germany
PostHogProduct analyticsIn the app: staff identity and named events only. Autocapture and session recording are switched off in the app because of customer data. In the customer portal: page views and events, identified by the job's short reference; session recordings, with every form input masked; and error reportsEU

Regulatory and finance submissions

These are used only when an installer chooses to make the submission.

Sub-processorPurposeData it receivesLocation
ENA Connect Direct (Energy Networks Association)Connection applications to electricity network operators and the low-carbon-technology device registerSite address, MPAN, device details, customer name, email and phoneUK
NAPITBuilding Control notificationsJob, site and customer details, including phone and emailUK
Novuna (PayByFinance)Consumer finance: checking an application and confirming goods dispatchedApplicant name and customer addressUK

Payments

Sub-processorPurposeData it receivesLocation
StripeCard payments through the customer portal's payment formCard and billing details, entered directly into Stripe's own formBeing confirmed

Card payments and subscription billing inside the Onroute Intelligence app are configured, not live. Stripe is listed here because the payment form in the customer portal is provided by Stripe.

Website

Our website at onroute.io and onrouteintelligence.ai is not part of the service we provide to customers: for the personal data it collects we are the controller, as our Privacy Policy explains. It uses these providers.

Sub-processorPurposeData it receivesLocation
VercelHosting for our websitePage requests, logged with the IP address, the page asked for and browser detailsUS
AxiomStorage of the website's request logs from VercelRequest log entries: IP address, page and browser detailsFrankfurt, Germany
ResendDelivers demonstration requests and whitepaper sign-ups to our mailbox as emailsWhat the form contains: for a demonstration request, name, company, email address, telephone number, business details and message; for a whitepaper sign-up, the email address and the paperUS company; processing region being confirmed
Google WorkspaceOur support@onroute.io mailbox, where demonstration requests, whitepaper sign-ups and emails to us are heldThe content of those requests and emailsUS company; processing region being confirmed

Not sub-processors

Some connections send data into Onroute Intelligence using the installer's own account, and the provider acts for the installer, not for us: WhatConverts lead import, and the Ohme Connect browser extension. Trackers an installer chooses to add to its own customer-portal pages (Google Tag Manager, Google Analytics, Meta Pixel, Trustpilot) are set by the installer, who is the controller for them.

Slack (operational alerts with no customer data) and healthchecks.io (heartbeat monitoring, no data) are tools we use but do not receive personal data.

Changes to sub-processors

Under clause 2.2.2 of the Data Processing Addendum we notify customers of any intended addition or replacement of a sub-processor, and a customer may object in writing within ten days of being notified. This page is updated when the change takes effect.

Security

We publish what is in place, not what we aspire to. We do not currently hold ISO 27001, SOC 2 or any other security certification, and we do not claim one. Security questionnaires are answered on request at the contact below.

Access and tenant separation

  • The database schema enforces row-level security on customer tables, so that a query can only return the rows belonging to the signed-in user's organisation. Database search functions check organisation membership before returning results, and automated tests check that the policies agree.
  • Sign-in is by email and password, or with Google. Password recovery uses a one-time code rather than a link. Multi-factor authentication is available through Google sign-in where your account has it enabled; we do not yet offer a separate authenticator step of our own.
  • Access to customer data by our support staff, including those provided by N90 Labs Ltd, is recorded in an audit log with the staff member's identity attached.

Audit trail

  • Changes made through the service are written to an audit log that users cannot edit. Job status changes and document sharing are also logged.

Application security

  • All connections use HTTPS, with HTTP Strict Transport Security.
  • The app sends a Content Security Policy, Referrer-Policy and X-Frame-Options headers.
  • Requests to the app are rate limited per IP address, with a tighter limit on authentication callbacks.
  • Third-party credentials are removed from error messages before they are logged. Regulatory scheme passwords are held encrypted in Supabase Vault and are never returned, logged or audited; the access tokens they produce are used for the submission and never stored. Access tokens are stored as SHA-256 hashes.

Analytics and error reporting

  • In the Onroute Intelligence app, analytics autocapture and session recording are switched off so that customer data is not captured.
  • In the customer portal, analytics records sessions with every form input masked, and captures errors.
  • In the mobile app and the customer portal, error reports are configured not to include user identity by default; in the mobile app, message content that could contain personal data is removed before sending.

Mobile app

  • The sign-in session, cached jobs, and queued notes, form answers and signature details are encrypted, with keys held in the device's keychain. Queued photographs, signature images and cached documents are kept as files in the app's private storage, under the device's own encryption.
  • The unsent-work queue is deleted at sign-out. On Android, the app's data is excluded from device backup.
  • Location is read once, when a signature is captured, and only if the engineer allows it. There is no background location tracking.

Backups and recovery

  • A full database backup is taken every night at 02:15 UTC to an independent AWS account in London (eu-west-2), held for 30 days under object lock in compliance mode, which prevents alteration or deletion before expiry.
  • Files are synchronised to the same archive every night at 02:45 UTC, with a weekly full reconciliation and a near-real-time push when a file is uploaded. Files are protected by object lock for 90 days after they are written and kept in the archive after that.
  • The account used for the archive can write but cannot delete. Each backup job reports to an independent monitor that alerts us if a run is missed or fails.

Data return and deletion

  • During a subscription and for 30 days after it ends, a customer can export its data (Subscription Terms clause 4.7). After that period we may delete it.
  • On termination of the Data Processing Addendum, we return or securely dispose of customer personal data at the customer's option, unless we are required by law to keep it (DPA clause 2.7).

Incidents

  • We notify customers in writing and without undue delay if we become aware of a breach of security of their personal data (DPA clause 2.2.7).

Audit

  • To demonstrate our compliance with the Data Processing Addendum, we provide the information a customer reasonably requires. Where that information alone is not reasonably sufficient, the customer may audit us, by up to two of its representatives and at its own cost, on at least one month's written notice, no more than once a calendar year, at a time convenient to us (unless a supervisory authority requires otherwise). If a third party conducts the audit, we may object to an auditor who is not suitably qualified or independent, is a competitor, or is otherwise manifestly unsuitable (DPA clause 2.2.9).

Contact

Data protection and security contact: support@onroute.io

To report a security concern, email the same address. We read every report.

Onroute Intelligence Inc., 251 Little Falls Drive, Wilmington, Delaware 19808, USA.