Privacy Policy

How RoutePress, LLC handles information in RoutePress — both for the agency staff who sign in and for the riders who read the pages you publish. The short version: staff accounts hold the little we need to run and bill the service, and rider pages carry no accounts, no analytics, and no advertising.

Effective July 26, 2026

1. What this policy covers

This policy applies to the RoutePress marketing site, the agency dashboard, and the route pages and system maps we render for your riders.

It describes two very different groups. Agency staff hold accounts, so we hold information about them. Riders hold nothing: viewing a route page requires no account, no app, and no consent banner, because we do not collect anything about the people who read it.

2. Information we collect from agency staff

  • Account details — your email address, a password (stored only as a hash, by our authentication provider, never in a form we can read), and the name you give at onboarding.
  • Agency details — your agency name, logo, and the settings you choose: colors, fare tables, service alerts, template choices.
  • Team records — who belongs to your agency account and their role, plus the email address an invite link was created for.
  • Your transit data — the GTFS feed URL you connect, the feed archives we download from it, the badge images you upload, and the links you give us to printable PDFs you host yourself. This is agency data, not personal data, and it is normally published by you already.
  • Billing details— your plan, subscription status, and the identifiers our payments provider gives us. Payment card numbers are entered on the provider's own page and never reach our servers.
  • Operational logs — our hosting provider records requests to our servers, including IP address and browser user-agent, to keep the service running and secure.
  • Preview requests — if you ask us for a preview from our website without holding an account, we keep the GTFS feed URL and the email address you gave us, the feed we download from that URL, and the page we build from it. We use the email to send you the preview and to follow up about it. Tell us to stop and we will.

3. What we collect from riders: nothing

Route pages and system maps are readable by anyone, with no sign-in. We do not set cookies on them, we do not run analytics or advertising scripts on them, we do not fingerprint devices, and we do not build profiles of the people who read your schedules.

Two honest caveats, because a rider's browser does make requests we do not control the destination of:

  • Map tiles. The basemap behind your route maps is fetched by the rider's own browser from a third-party tile service, so that service sees the request, including the rider's IP address.
  • Web fonts. The page's typeface is fetched the same way, from Google Fonts, with the same consequence.

Both are named in the table below. Neither receives anything about the rider beyond what any web request carries, and neither receives anything from us.

4. How we use information

We use what we collect only to run the service you are paying for:

  • To render and host your route pages, system map, and embeds.
  • To keep your feed current — checking your GTFS URL on a schedule and re-importing it when it changes.
  • To authenticate you, keep you signed in, and scope every read to your own agency.
  • To bill your subscription and answer billing questions.
  • To answer support requests you send us.
  • To protect the service — rate limits, abuse prevention, and diagnosing outages. Rate limits count requests per agency account, except on the public preview-request form, which has no account behind it and is counted per network address instead.
  • To follow up, once, about a preview you asked us to build. If you tell us not to contact you again, we record that and we stop.

We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use your data or your feed to advertise to anyone.

5. Who else touches the data

We use a small number of service providers to operate RoutePress. Each one gets only what its job requires:

ProviderRoleWhat reaches it
VercelApplication hosting and content deliveryRequests to our servers, including IP address and browser user-agent, in operational logs
SupabaseDatabase, authentication, and file storageAccount email and password hash, agency and team records, GTFS feed archives, uploaded logos and badge images
StripePayments and subscription billingBilling contact and payment details, entered on Stripe's own form and never stored by us
OpenFreeMapRider-facingBasemap tiles drawn behind your route mapsA rider's browser requests map tiles directly, so their IP address reaches this service
Google FontsRider-facingWeb fonts — every rider page loads its typeface from this serviceA rider's browser requests the font files directly, so their IP address reaches this service

We may also disclose information if the law requires it, or to protect the rights and safety of our users or the public. If a legal request covers your agency's data, we will tell you unless we are prohibited from doing so.

6. Your data stays yours

Your GTFS feed, your branding, and your uploaded documents belong to your agency. We read them to generate rider-facing pages and for nothing else. We do not resell your feed, license it onward, or fold it into a product other agencies buy.

7. How long we keep it

  • Account, agency, and billing records: for as long as your account is open.
  • Feed archives: the current feed, plus what we need to serve your pages. Disconnecting or replacing a feed deletes the stored archive.
  • Operational logs: for a limited period at our hosting provider, as part of normal server operation.
  • Billing records: for as long as tax and accounting rules require, even after an account closes.
  • Preview requests: kept until you ask us to delete them. Nothing about a preview expires on its own — the link, the feed we downloaded, and your email address stay until someone removes them.

Ask us to close your account and delete your data and we will do it within 30 days. Copies can survive briefly in our providers' routine backups before those expire.

8. Security

  • All traffic is served over HTTPS.
  • Passwords are hashed by our authentication provider; we never see or store the plaintext.
  • Every database read is scoped to your own agency by row-level security, so one agency cannot read another's rows even in the event of an application bug.
  • Feed archives live in a private storage bucket, never a public URL. Published route pages are served through a token you control, and you can unpublish at any time.
  • Administrative keys are server-side only and are never shipped to a browser.

No service can promise perfect security, and we hold no third-party security certification today. If we ever learn of a breach affecting your information, we will tell you promptly.

9. Your choices and rights

Whatever state you are in, you can ask us to show you what we hold about you, correct it, or delete it. Email hello@getroutepress.com and a person will answer.

California residents have specific rights under the CCPA to know what is collected, to delete it, to correct it, and not to be discriminated against for asking. Two of those answers are easy for us: we do not sell personal information, and we do not share it for cross-context behavioral advertising.

10. Children

RoutePress is a tool for transit agencies, not a service directed at children, and we do not knowingly collect personal information from anyone under 13. Riders of any age can read the pages you publish without giving us anything at all.

11. Changes to this policy

If we change how we handle information, we will update this page and move the effective date above. Material changes will be sent to account holders by email.

12. Contact us

Questions about privacy, or a request about your own information: hello@getroutepress.com. See also our Terms of Service and Accessibility Statement.