Privacy Policy
Version 1.3, last updated September 18, 2026. What we collect, why we have it, how long it stays, and how to get it back or have it deleted.
1. Overview
Trucker Route ("we", "our", "the app") is a real-time road hazard and weather map for truck drivers, available as an iOS app and at trucker-route.com. The operator of the site decides what is collected here and is responsible for it.
Most of the site asks nothing of you. The map, the state pages, the regulation pages and the iOS app work with no account, no email and no name. An account exists for one reason: to let a driver write a review of a company they worked for. Sections 2, 3 and 12 apply only if you create one.
Questions about this policy go to the feedback form on the About page. There is no email address to write to instead: the one this page carried until September 18, 2026 could not receive mail, so anything sent to it never reached us.
2. Accounts and Google sign-in
Sign-in is through Google. There is no password on this site, so there is no password of yours for us to hold or to lose. When you sign in, Google sends us three things, and we store all three:
- Your Google account identifier, the value Google calls
sub. It identifies your Google account to this site and to no one else. It is not your email and it does not change if you change your email. - Your email address, which we use to reach you about your own reviews and messages.
- Your display name, as Google has it. It is never shown on a review.
We do not store your Google profile picture. There is no column for it in our database and no code that asks for it. A photo is personal data we would then have to protect, export and delete, and the site has no use for one.
We ask Google for three scopes and no more: openid, email and profile. We cannot read your Gmail, your Drive, your contacts or your calendar, and we cannot post anything to your Google account.
We also keep a keyed hash of your Google account identifier. It is a one-way value: it cannot be turned back into your Google account or your email. Two jobs depend on it. It holds the rule of one review per company, and it makes a ban stick, so that a banned account cannot come back by deleting itself and signing up again. Section 12 says what happens to it when you delete your account.
Reviews are published without your name. A published review shows "Driver" or "Verified driver", the year, and what you wrote. Never your name, never your email, never a link to your Google account.
We record the date, the version of the terms you accepted, and the time of your last sign-in.
3. Reviews and the documents you attach
A review you write is stored with your account until you delete it or we remove it. Published: the review text, the ratings, the year, and the badge. Held and never published: the IP address and the browser user agent the review was sent from, and any document you attach.
You can attach a pay stub or a settlement statement to support what you wrote. Those documents have one purpose, which is to let a moderator check that you worked where you say you worked. Here is exactly what happens to them:
- Only site administrators see them. An administrator has to pass a second factor, a code from an authenticator app, before the panel opens, and has to re-enter the password before the first document of a session. Every single view is written to a moderation log with who opened what and when.
- They are encrypted before they leave our server. AES-256, with the key held by the application, not by the storage provider.
- They live in private DigitalOcean Spaces buckets in the United States. There is no public link, no CDN and no shareable URL. Not even you get one back.
- They are deleted 30 days after a review is approved, and 7 days after one is declined. Withdraw the review or delete your account and they go at once, from both buckets.
- They are never published, never shown to the company you reviewed, and never sold or shared.
Black out your Social Security number, your bank details and your home address before you upload anything. We do not need them, and a moderator should never be looking at them.
4. What the iOS app collects
When you launch the iOS app and accept the Terms of Service, we receive the following anonymous technical data:
- Anonymous device identifier, Apple's Vendor ID. It resets if the app is deleted and reinstalled, and it is never tied to your Apple ID or your identity.
- App version
- iOS version
- Device language and timezone
- Approximate location, only if you grant location permission (see section 5)
This data does not identify you and cannot be linked back to you. We use it to count how many devices are active and to see which parts of the app get used. There are no accounts in the iOS app: sign-in and reviews are on the website only.
5. Location data
The iOS app requests access to your device location to display your position on the map (the blue dot). Location permission is entirely optional and the app works fully without it.
If you grant location permission:
- Your coordinates are displayed on the map on your device.
- Your approximate location is sent to Trucker Route servers as anonymous analytics data once per app launch.
- Coordinates are stored without any personally identifiable information and cannot be used to identify you.
- Location data is kept for up to 12 months and then deleted.
You can revoke location permission at any time in iOS Settings, Privacy & Security, Location Services, Trucker Route.
Under California's CPRA, precise geolocation is "sensitive personal information." We use it only to provide the service, which means showing your position on the map and counting anonymous app launches, and never for profiling or advertising. See your Right to Limit in section 13.
We do not track where you drive. There is no route history, no trip log and no breadcrumb trail on our servers.
6. Website analytics
The website measures traffic two ways:
- Our own counter records the page path, an approximate session length and the device type (desktop or mobile). It stores a randomly generated visitor identifier in your browser's local storage, not in a cookie, and the data never leaves our servers.
- Google Analytics 4 sets first-party cookies (
_gaand_ga_H4CHBVJ02N) so we can tell returning visitors from new ones and see which pages and traffic sources are actually useful. Google receives a truncated IP address, browser and device type, an approximate city-level location derived from that IP, and the pages you view. It never receives your name, your email, or a precise GPS position, and we do not use it for advertising or cross-site ad personalization. See how Google uses information from sites that use its services, or block it with the Google Analytics Opt-out Browser Add-on.
On your first visit the site shows a cookie notice. Choosing Decline switches Google Analytics off: no analytics cookies are written, and Google gets nothing that identifies you between visits. The tag still loads and still sends Google the page you are on, your IP address and your browser type, with no cookie and no identifier that outlives the visit. In the EU and EEA, the United Kingdom, and Switzerland, analytics stays off until you actively choose Accept. To change your answer later, clear this site's data in your browser and the notice comes back.
Analytics does not run on the sign-in pages or anywhere in your account. Those pages load no Google tag and no counter of ours.
We use no fingerprinting and no cross-site tracking. Google Analytics runs on the website only. The iOS app does not include it.
7. IP addresses, user agents and server logs
Every write on this site records the IP address it came from, and some of them also record the browser user agent that sent it. This is the whole of our defence against someone with a script, and it covers the site, not just accounts: the feedback form, the poll, company card lookups, reports and reviews all record the address, and the feedback form and a review also keep the user agent. We use them to spot abuse, to enforce daily limits and to investigate a specific incident. We do not use them to build a profile of you and we never sell them.
We clear IP addresses and user agents after 90 days. A job runs through the tables and nulls the fields; the record itself stays without them. Two windows are different, and we would rather state them than bury them:
- The IP recorded when you accepted the terms of use is kept for 12 months as evidence of that acceptance. After that the IP is cleared and only the date and the version remain.
- A poll vote's IP is cleared 30 days after the poll closes.
Our web server (nginx) writes an access log line for each request: time, path, status code, referrer, user agent and IP. Those files rotate after 14 days. On the sign-in and account paths the query string is stripped before the line is written, so a sign-in token or a redirect target never lands in a log file.
Our application logs are a separate thing. No line in them holds a user agent, a session token, or the text of a review or a message, and a test in our build fails when a new line would add an email address, an IP address or a user agent. Three older lines are still exceptions and we are removing them: each records the IP address an administrator signed in from.
8. What we do not collect
Some of this is worth saying out loud:
- Your Google profile picture, or any photo of you
- Payment details. Nothing here costs money.
- Your driving history, your routes, or where you have been
- Anything about your cargo, your loads or your deliveries
- Your contacts, your photo library, or any other content on your device
- Advertising identifiers (IDFA). We run no advertising.
We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not run third-party ad or tracking scripts.
9. Cookies
| Cookie | What it does | How long |
|---|---|---|
sid | Keeps you signed in. Signed by the server, marked HttpOnly and SameSite, and readable only by the server. It holds a session identifier, not your email or your name. | 30 days for a driver account, 8 hours for an administrator |
oauth_state | Set only while a sign-in is in progress. It ties the request we sent to Google to the answer that comes back, so that a forged answer cannot sign you in to someone else's account. | 10 minutes, then deleted |
_ga, _ga_H4CHBVJ02N | Google Analytics, described in section 6. Never set if you decline the cookie notice. | Up to 2 years |
The first two are strictly necessary: without them you cannot sign in at all. We use no advertising cookies and no cross-site tracking cookies. Your browser's local storage also holds your map preferences (layers, filters, temperature unit) and the random visitor identifier from section 6. Neither is a cookie, so your browser never attaches them to a request on its own. Your map preferences stay on your device. The visitor identifier does not: the page sends it to us with the analytics beacon in section 6, with a poll vote, with a like on an article, when you accept the terms of use and with the feedback form. It is how one visitor is counted once and how one vote and one like per visitor are enforced. We clear it from a feedback message after 90 days. The other rows keep it for as long as the row itself stands, because it is the only thing that keeps that row to one per visitor.
10. Who else handles your data
Five companies process data on our behalf. Each one is listed with what stays on their side, because that is the part a privacy policy usually leaves out.
| Provider | What they do for us | What stays with them |
|---|---|---|
| Sign-in | Google knows you signed in to Trucker Route and when. We receive only the account identifier, email and display name. Privacy policy | |
| Google Analytics | Website traffic measurement | Truncated IP, device and browser type, city-level location, pages viewed. Website only, never the iOS app. Privacy policy |
| DigitalOcean | Hosting for the site, the database and the uploaded documents, in the United States | Everything the site stores, plus the database backups. A row you delete today still exists in a backup until that backup expires, which is 7 days. Backups are encrypted and are restored only to recover the site. Privacy policy |
| Resend | Sends the email we send you | A log of what was sent, to which address and when, on their servers. Privacy policy |
| Mapbox | Map tiles in the app and on the site | Your device requests tiles directly from Mapbox, so they see the request. Privacy policy |
All five run in the United States, and that is where your data is processed. If you write to us from the EEA, the United Kingdom or Switzerland, your data is transferred to the United States under the standard contractual clauses each of these providers publishes.
Road, weather and hazard data comes from public US government sources (NOAA, NWS, NASA, USGS, NIFC, FMCSA and the state DOT 511 networks). Nothing about you goes to them.
We disclose personal information outside this list only when the law requires it: a valid subpoena, a court order or a lawful government request. If we get one for a review author's identity, we tell the author, unless the law forbids us to.
11. How long we keep things
| What | How long |
|---|---|
| Account data (email, display name, Google account identifier) | Until you delete the account, then removed within 45 days |
| A review that was never published (pending, declined, withdrawn) | Until you delete it or delete your account |
| A published review | While it stands. It survives account deletion without your name attached, unless you ask for it to come down (section 12) |
| Documents attached to a review | 30 days after approval, 7 days after a decline, at once on withdrawal or account deletion |
| IP addresses and user agents | 90 days |
| The IP recorded with a terms acceptance | 12 months, then the IP alone is cleared |
| A poll vote's IP | 30 days after the poll closes |
| nginx access logs | 14 days |
| Anonymous iOS app usage data, including optional coarse location | 12 months |
| Messages and notifications in your account | Until you delete the account |
| Database backups | 7 days, then overwritten |
12. Your rights, your export and deleting your account
Wherever you live, you get the same four things from us:
- Access. Ask what we hold about you.
- Export. Settings has a "Download my data" button. It gives you one file with your account, your reviews and their history, your messages and your notifications.
- Correction. Ask us to fix anything that is wrong.
- Deletion. Settings has "Delete account". We start immediately and finish within 45 days at the outside.
Exporting, deleting, and signing out of every device all ask you to sign in with Google again first, within the last five minutes. A 30-day cookie left on a shared terminal in a truck stop or a dispatch office should not be enough to download or destroy a driver's account.
What deletion removes: your email, your display name, your Google account identifier, your last sign-in IP, your notifications and messages, every document you uploaded, in both buckets, and every review of yours that was never published. Tick "Also remove my published reviews" and those come down as well. Every session on every device ends.
What survives deletion, and why:
- Published reviews you chose to leave up. The author becomes "Former driver" and the link to you is cut. Other drivers read them and a company may have answered them. GDPR Article 17(3)(a) allows this for freedom of expression and information.
- The moderation log, which records that a decision was made, by which administrator, and when. It holds no email, no IP address and no name. GDPR Article 17(3)(e), the establishment and defence of legal claims.
- The keyed hash of your Google account identifier, but only if your account was banned, and only while the ban stands. An ordinary deleted account's hash is erased with everything else. We keep a banned one so that a ban cannot be shrugged off by deleting the account and signing up again. Lift the ban and the hash goes.
- Rows in a database backup, until that backup expires, which is 7 days.
- Email we already sent you. It is in your inbox, and in Resend's send log.
- nginx access log lines, until they rotate at 14 days.
To use any of these rights, use the buttons in Settings, or send the request through the feedback form on the About page. Sign in first if you have an account: a message sent from a signed-in browser is how we know the request is yours, and the answer waits in your account. Without an account, leave an email address in the form, because that is the only way we can answer you. We will never charge you for a request or treat you worse for making one.
If you are in the EEA or the United Kingdom, our legal bases are: performing the contract you accepted when you created an account (your account, your reviews and the email about them); our legitimate interest in a site that is not overrun by fake reviews (IP addresses, user agents, rate limits, moderation); your consent for analytics cookies and for optional email; and a legal obligation where one applies. You can withdraw consent at any time, and you can complain to your national data protection authority.
13. California Privacy Rights (CCPA, as amended by the CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you these rights over your personal information:
- Right to Know: the categories and specific pieces of personal information we have collected about you, where it came from, why we collected it, and the categories of third parties we share it with.
- Right to Correct: have us fix inaccurate personal information.
- Right to Delete: have us delete personal information we collected from you, subject to the exceptions in section 12.
- Right to Opt Out of Sale or Sharing: we do not sell or share your personal information with anyone, including for cross-context behavioral advertising, so there is nothing to opt out of. We also honor browser Global Privacy Control (GPC) signals.
- Right to Limit the Use of Sensitive Personal Information: your precise geolocation is sensitive personal information under the CPRA. We use it only to provide the service, which is showing your position on the map and counting anonymous app launches, and never for profiling or advertising. Because that is a purpose the CPRA permits, no separate "Limit" toggle is required, but you can still ask us to stop using it or delete it.
- Right to Non-Discrimination: we will not treat you differently for exercising any of these rights.
What we hold about California residents:
- Identifiers: if you have an account, your email address, display name, Google account identifier and IP address; if you use the iOS app, the anonymous Vendor ID, which is not linked to your identity.
- Internet activity: pages viewed, device and browser type, and the analytics described in section 6.
- Geolocation, sensitive personal information: precise location, only if you granted permission in the iOS app, kept up to 12 months.
- Professional or employment information: only what you choose to write in a review, and any document you attach to support it.
- Commercial information: none. We sell nothing.
To exercise your rights, send the request through the feedback form on the About page. If you have an account, signing in is how we verify it is you. For iOS app data there is no account to check, and nothing in the app shows you the Vendor ID, so send the request from Send Feedback in the app's More tab: it reaches us with that identifier attached, and that is how we find the right rows. We answer within 45 days, as the law requires.
14. Email we send you
Two kinds, and only two:
- Email about your own account. A decision on a review you wrote, a moderator's question, a reply to a message you sent, and a notice when your account is signed in from a device or address we have not seen before. These go out whatever your settings say, because they are the account doing its job. The sign-in notice is the one that matters: if it was not you, it tells you how to sign out everywhere.
- Everything else is opt-in. Turn it off in Settings, or use the unsubscribe link at the bottom of any message. That link works without signing in, and the page it opens loads no analytics, so the link itself never reaches Google.
We never sell your email address, we never rent it, and we send no advertising.
15. Children's privacy
The map, the reference pages and the iOS app are for anyone 13 or older. The app is rated 4+, and we do not knowingly collect anything from a child under 13.
An account is different. You must be 18 or older to create one and to write a review, which matches the federal minimum age for an interstate CDL.
If you believe a child has given us personal information, tell us through the feedback form on the About page and we will delete it.
16. Security
The site runs over HTTPS everywhere. There is no password here to steal, because sign-in goes through Google. Session cookies are HttpOnly and SameSite, and they are signed by the server. Uploaded documents are encrypted with AES-256 before they leave our server and sit in private buckets with no public link. The admin panel requires a second factor, and opening a document requires the password again.
No system is perfect, and we will not pretend otherwise. If a breach ever affects your personal data, we will tell you and the authorities the law names, without waiting to be asked.
17. Changes to this policy
We may update this policy. The version number and the date at the top of this page change in the same edit as the text, so you can always tell what you last read. This is version 1.3, dated September 18, 2026.
If a change matters to you, for example a new category of data or a new processor, we will say so on the site and, for account holders, by email before it takes effect. Continued use after a change means you accept the updated policy.
18. Contact
Questions about this policy, an access request, an export, a deletion, or a privacy complaint: the feedback form on the About page. The same form is behind Send Feedback in the sidebar on the map and in the iOS app under More. There is no email address to write to instead, and that is deliberate: the address this page carried until September 18, 2026 could not receive mail.
What happens after you send it. The form opens a thread and a person reads it. Sign in with Google first and the answer waits in your account, where the whole thread stays. Leave an email address in the form instead and we write back to it. Leave neither and we read what you sent but have no way to reply. We answer within 45 days, which is what the CCPA requires, and usually much sooner.
If you are in the EEA or the United Kingdom, you can also complain to your national data protection authority.