← Back to NSRoute

Privacy Policy

Last updated: August 29, 2026

1. Data Controller

NSRoute is operated by:
Maciej Brys (sole proprietorship / JDG, brands: NSRoute, NoStressStudio, NSS Container)
ul. Ignacego Paderewskiego 1F/9
35-328 Rzeszow, Poland
NIP: 8133422595
Email: [email protected]
Phone: +48 884 304 081

2. What Data We Process

NSRoute processes data in two ways: locally in your browser and on our servers when you create an account.

2a. Data stored locally (browser only)

Data TypeStoragePurposeLegal Basis (GDPR)
UI preferences (language, dark mode)Browser localStorageRemember your settingsArt. 6(1)(f) — legitimate interest
Route history (last 20 routes)Browser localStorageQuick access to recent routesArt. 6(1)(f) — legitimate interest
Truck profile settingsBrowser localStorageRemember vehicle configurationArt. 6(1)(f) — legitimate interest
Current GPS position (only after the driver enables GPS for a route)Transient browser memory. If the driver separately enables live sharing, the latest point may be sent as described below.Show route progress, ETA and on-device driving aidsDevice permission controls sensor access; it is not, by itself, a GDPR legal basis.
Random Driver device credentialBrowser localStorage, separate from the account/session identifierBind at most one active Driver Trip Link to this browser installation and prevent another device or old session from changing its status or location. It is not a verified driver, carrier or vehicle identity.Operational security of the Driver Trip Link feature. The organisation using NSRoute must identify and communicate its appropriate lawful basis.
Transient Driver Trip Link capabilityCurrent tab sessionStorage only until successful claim, terminal state or expiryAllow refresh before the driver accepts the route, while removing the secret from the visible URL immediatelyOperation of the requested Driver Trip Link.
First-party visitor/test ID (nsroute_vid)Browser localStorageKeep product experiment variants stable and measure operational feature usage when enabledArt. 6(1)(f) — legitimate interest

You can delete all locally stored data at any time by clearing your browser's site data for nsroute.com.

2b. Data stored on our servers (accounts and Driver Trip Links)

When you create an account, subscribe or use a Driver Trip Link, we process the following data on Cloudflare infrastructure. The Driver Trip Links D1 database is configured with EU jurisdiction:

Data TypePurposeLegal BasisRetention
Email addressAccount identification, loginArt. 6(1)(b) — contract performanceUntil account deletion, or 24 months of inactivity (section 10)
Password (PBKDF2 hash)AuthenticationArt. 6(1)(b) — contract performanceUntil account deletion, or 24 months of inactivity (section 10)
Name (optional)PersonalizationArt. 6(1)(b) — contract performanceUntil account deletion, or 24 months of inactivity (section 10)
Subscription plan (free/pro/fleet)Feature access controlArt. 6(1)(b) — contract performanceUntil account deletion, or 24 months of inactivity (section 10)
JWT authentication tokenSession managementArt. 6(1)(b) — contract performance7 days (auto-expiry)
Driver Trip Link: exact route geometry, stops, vehicle profile, departure time and trip statusesSend a planned trip to a driver and return operational status to the dispatcher. Prices and margins are not included.Art. 6(1)(b) — contract performanceThe link is active for the expiry period selected by the dispatcher (maximum 30 days). Expired or revoked trip data is deleted after a further maximum 30-day technical retention period.
Optional Driver Trip Link live location: latest latitude, longitude, accuracy, capture time and server receipt time; anti-abuse session-start/last-write timestamps and one-way hashes of random session credentialsShow the latest driver position to the authenticated owner of that Trip Link, only after the driver explicitly starts a server-side sharing session for that trip. The application does not create a coordinate-history feature or application-level coordinate event log. Non-coordinate session metadata prevents rapid credential rotation, replay and rate-limit bypass.The organisation using NSRoute must identify and communicate an appropriate lawful basis. Browser permission alone is not a GDPR legal basis.Each accepted point replaces the preceding application record. Coordinates, accuracy, capture time and the current point's receipt time are cleared immediately when the driver stops sharing, arrives or completes the trip, or the link is revoked. Non-coordinate anti-abuse timestamps and one-way session hashes may remain on the Trip Link row until terminal status, revoke, expiry cleanup or row deletion. A point is no longer returned after it becomes stale or the link expires; a daily cleanup clears the location fields of expired links no later than its next run.
Driver device claim and route-switch metadata: one-way hash of the random device credential, trip identifier, claim timestamps, one-way hash and expiry of any pending switch challenge, and link-reissue timestamp/countEnforce one active trip per browser installation, require explicit switching and safely assign the same trip to a different driver without storing a permanent driver profile.Operational security and contract performance for the Driver Trip Link feature. The organisation using NSRoute remains responsible for its lawful instructions to drivers.The active claim and switch challenge are deleted on completion, revocation, expiry or reassignment. A switch challenge expires after five minutes. Reissue audit metadata follows the Trip Link retention period.
Account-deletion security markers: a one-way hash of the random account-generation identifier and, for legacy compatibility, a temporary one-way hash derived from the account email; a short-lived hash-keyed deletion guardPrevent stale sessions, concurrent registration and delayed edge records from recreating or inheriting data from a deleted account. These markers contain no email address, route, trip status, driver claim or location.Art. 6(1)(f) GDPR — legitimate interest in account and data security.The hash-keyed edge guard remains for at most 15 minutes. The legacy email-derived marker remains for at most 7 days. The random-generation marker remains for at most 30 days. Expired markers are removed by scheduled cleanup.
Email address and consent recordPractical tips, information about new features and PRO plan offersArt. 6(1)(a) GDPR — consent; Art. 398 Polish Electronic Communications LawPending confirmation links: 24 hours. Active consent: until withdrawal. Proof of the consent and withdrawal may then be retained only as long as necessary to demonstrate compliance or handle legal claims.

Live location is off by default and limited to one Driver Trip Link. The dispatcher cannot turn it on. The driver must use a separate, visible control that first creates a server-side location session and a dedicated credential scoped to that active trip before any point can be sent. The session lasts at most 12 hours and never beyond the link expiry. The driver may stop it at any time; stopping invalidates the session and clears its point. NSRoute does not provide hidden location tracking. Only the authenticated owner of the link can receive a fresh latest point.

The dispatcher sees the driver's capture time, but freshness is calculated from the trusted server receipt time. A missing or invalid server receipt time is not shown as live. "Latest-only" describes the NSRoute application data model; infrastructure security/request logs and recovery systems (including Cloudflare D1 Time Travel) have separate technical access and retention controls and are not provided as a route-history feature.

A Driver Trip Link and its browser-installation claim are capabilities rather than driver identity verification. Anyone who obtains an unclaimed URL may open its route while it remains valid. After the route is claimed, full-route reads and every mutation require the matching browser-installation credential; the bearer URL alone is no longer sufficient. New links place the token after #, which is not sent in HTTP requests or Referer headers, and the driver page immediately removes it from the visible address after capture. A transient copy remains only in that tab until successful claim, terminal state or expiry. Legacy path-token links may still occur in browser and infrastructure request metadata during the compatibility period. The dispatcher should send every link only to the intended driver and rotate or revoke it if it is disclosed to anyone else.

If a trip is assigned to a different driver, the dispatcher's “Change driver” action rotates the secret while keeping the same trip record. The previous link, device claim and location session stop working, and the latest point is cleared. If one phone already has another active trip, NSRoute displays a confirmation before switching; it does not reveal details of the previous trip and never switches automatically.

Mobile browsers and operating systems may pause geolocation or network updates when a page is in the background or the screen is locked. Live sharing from the web page is therefore not guaranteed to continue in the background. If updates stop, NSRoute marks the location stale and removes the live map marker; the driver may need to keep the Trip Link open in the foreground.

2c. Marketing emails and double opt-in

Marketing emails are optional and are not required to create or use an NSRoute account. The checkbox is empty by default. Its wording is: “I want to receive practical tips, information about new features and PRO plan offers from NSRoute at the email address provided. I can withdraw my consent at any time. The data controller is NoStressStudio.” The legal identity and contact details of the controller operating under the NoStressStudio brand are listed in section 1.

After you select the checkbox in NSRoute, we send a transactional confirmation message to the address provided. Marketing consent becomes active only after you open the confirmation page and explicitly confirm the choice there. The one-time confirmation expires after 24 hours. You can cancel a pending request or withdraw an active consent at any time with the same control in the app. Withdrawal does not affect access to NSRoute and does not affect the lawfulness of processing carried out before withdrawal.

Essential service messages, such as password-reset and account-security messages, are sent independently of marketing consent and contain no promotional offer.

2d. Payment data (Stripe)

When you subscribe to a paid plan, payment processing is handled by Stripe, Inc. (stripe.com). We do not store your credit card number, CVV, or full payment details on our servers. Stripe processes:

Stripe acts as an independent data controller for payment data. See: stripe.com/privacy

Legal basis: Art. 6(1)(b) GDPR — performance of contract.

3. Third-Party Services

NSRoute connects to external services. When you use these features, data is sent from your browser:

ServiceData SentPurposePrivacy Policy
OpenRouteService (ORS)GPS coordinates of waypointsHGV route calculationopenrouteservice.org/privacy
Nominatim (OpenStreetMap)Address search queriesGeocodingnominatim.org/release-docs
OpenFreeMapMap tile requests (no user data)Map displayopenfreemap.org
Google Gemini API (optional)Route context, text/voice inputAI assistant & quote parserai.google.dev/terms
Public Holiday APICountry codesHoliday driving ban checksdate.nager.at
NSRoute POI service / OpenStreetMap OverpassA search area centered on the current position, only after the driver explicitly selects “Find nearby places”Find nearby fuel stations and truck parking. This request is not sent automatically and is not exposed to the dispatcher.osmfoundation.org/wiki/Privacy_Policy
StripePayment & billing dataSubscription paymentsstripe.com/privacy
CloudflareIP address, request metadataHosting, CDN, DDoS protectioncloudflare.com/privacypolicy
Meta Platforms Ireland Limited (only after consent)Visited page URL, referrer, timestamp, browser/device data, IP address processed by Meta, and advertising identifiers or cookies created by MetaMeasure Meta advertising and determine whether a visit leads to an account registration or checkout startfacebook.com/privacy/policy
BrevoEmail address and delivery metadataTransactional messages and, only after confirmed consent, marketing emailsbrevo.com/legal/privacypolicy

4. International Data Transfers

When you use the AI assistant (Google Gemini), AI quote parser, or voice dictation (Web Speech API), your data may be transferred to Google servers in the United States. These transfers are covered by the EU-US Data Privacy Framework and Google's Standard Contractual Clauses (SCCs) pursuant to GDPR Art. 46.

Stripe may transfer payment data to the US under the EU-US Data Privacy Framework.

Other services (OpenRouteService, Nominatim) are hosted within the EU/EEA. Cloudflare serves content from the nearest edge location.

5. AI Transparency (EU AI Act)

NSRoute includes AI-powered features using Google Gemini. In compliance with the EU AI Act (Art. 50):

6. Cookies

NSRoute uses browser localStorage for preferences, route history, truck profile settings, the first-party nsroute_vid visitor/test ID described above, and your privacy choice. Cloudflare may set technical cookies (__cf_bm) for bot protection — these are strictly necessary and exempt from consent requirements under ePrivacy Directive Art. 5(3).

Meta Pixel is disabled by default. If you select “Allow measurement”, Meta may set or read advertising cookies and similar identifiers. You can refuse without losing any NSRoute functionality and can change the choice later through the “Privacy choices” control.

7. Analytics & Tracking

NSRoute uses first-party operational event analytics to understand feature usage, errors, and app reliability. These events do not include raw account email addresses. IP address and user-agent values are hashed before storage where analytics persistence is used. Operational analytics are retained for up to 90 days.

Consent-based Meta Pixel. Meta Pixel dataset 1592579329124165 loads only after your explicit consent under Art. 6(1)(a) GDPR and the applicable ePrivacy rules. It measures page views, completed account registrations and checkout starts. Our integration does not send Meta your account email, name, route, waypoints, vehicle profile, load details, quoted price or payment-card data, and does not use automatic advanced matching. Refusing or withdrawing consent does not affect access to NSRoute.

Meta Platforms Ireland Limited processes the pixel data and may transfer data outside the EEA under the safeguards described in its privacy policy, including the EU-US Data Privacy Framework and Standard Contractual Clauses where applicable. Meta determines its own retention and advertising use under its terms. Withdrawing consent prevents new Meta events from NSRoute; browser or Meta account controls may be needed to remove identifiers already stored by Meta.

Affiliate links. Ferry booking links may lead to Direct Ferries and include an affiliate identifier. NSRoute may receive a commission after a qualifying booking. NSRoute does not send your account, route, or vehicle data to Direct Ferries when rendering these links. Once you follow a link, Direct Ferries processes your visit and any booking under its own privacy and cookie policies.

8. Your Rights (GDPR Art. 15-22)

You have the following rights regarding your personal data:

To exercise any of these rights, email: [email protected]. We will respond within 30 days.

9. Account Deletion

You can delete your account and the server-side data associated with that account at any time:

The in-app deletion operation immediately removes the account's Driver Trip Links, route snapshots, trip-status events, driver claims, location sessions and latest shared point from the live application database. It then removes the account email, password hash, active sessions, subscription record and pending marketing-consent data. If the transactional trip deletion fails, authentication is kept and the operation reports a failure so it can be retried safely. Stripe retains payment records as required by tax law.

For security and edge convergence, deletion leaves only the limited markers described in section 2b: a hash-keyed guard for at most 15 minutes, a legacy email-derived hash for at most 7 days, and a hash of the random account-generation identifier for at most 30 days. They contain no email address, route, trip status, claim or location and expire automatically. A new registration using the same email receives a new random account generation and cannot recover the deleted account's routes or consent. Registration is temporarily blocked while deletion is converging, and is not completed automatically if an unresolved billing record remains.

10. Retention of Inactive Accounts

We do not keep personal data longer than we need it (GDPR Art. 5(1)(e)). If you do not sign in to your NSRoute account for 24 consecutive months, we treat the account as dormant and delete it.

Operational analytics are retained for up to 90 days regardless of account status, as described in section 7.

11. Data Security

12. Children

NSRoute is a professional tool for the trucking industry. It is not intended for use by individuals under 16 years of age.

13. Changes to This Policy

We may update this policy when adding new features. Changes will be posted on this page with an updated date. Material changes will be communicated via the app or email for registered users.

14. Contact

For privacy-related questions:
Maciej Brys (NoStressStudio)
Email: [email protected]
Phone: +48 884 304 081
Address: ul. Ignacego Paderewskiego 1F/9, 35-328 Rzeszow, Poland