RoutePOV

Privacy notice

This notice explains what personal data RoutePOV collects, why, who it is shared with, and what rights you have. It is written to meet Articles 13 and 14 of the UK GDPR.

Last updated 27 July 2026

01Who we are

RoutePOV is a tool for approved driving instructors to build and share practice driving routes with their pupils. RoutePOV is the data controller for the personal data described in this notice, and the service is operated from the United Kingdom.

For anything in this notice, including a request to exercise your rights, contact privacy@routepov.com. We will tell you who is answering and, if you ask, the registered details of the controller.

We have not appointed a Data Protection Officer. We are not required to: we are not a public authority, and our processing is neither large-scale monitoring nor large-scale processing of special category data.

02Instructors: what we hold and why

An instructor account is the only account RoutePOV has. Everything below is data you give us directly.

DataWhy we hold itLawful basis
Email addressSign-in. We use passwordless sign-in links, so the address is the credential.Contract (Art. 6(1)(b))
School name, town or city, region, vehicle typeShown to your pupils on a shared route, and used to set sensible defaults in the route builder.Contract (Art. 6(1)(b))
A default map position for your areaCentres the map when you start a new route. This is a place you chose, not a tracked location.Contract (Art. 6(1)(b))
The routes you create: titles, map points, hazard notes, addressesThe service itself. Notes are free text, so please do not write anything about a pupil that you would not want them to read.Contract (Art. 6(1)(b))
A count of how many times each published route has been openedSo you can see whether a pupil looked at the route. It is a number on the route, not a record of who opened it.Legitimate interests (Art. 6(1)(f)): letting you see your own content is being used.

If you use the "use my location" button when searching for a place, your browser asks your permission and then sends that position to our server once, so it can be turned into a street name. We do not store it unless you go on to save it as part of a route or profile, and we never track your position in the background.

03Learners and supervising drivers: what we do not hold

Opening a private route link — the kind an instructor sends a pupil — does not create an account and does not ask you for anything. Specifically, RoutePOV does not read your device's location on a shared route, does not ask for your name or email, and does not use any analytics or advertising tracking.

Two exceptions, both of which are things you choose to do. If the route has an access code, entering it sets one cookie on your device recording that you got it right, so you are not asked again; it holds no personal data and expires after 30 days. And if you sign in to drive a route from our public directory, we hold your email address for that account and nothing else — the same basis as row one of the table above. You can ask us to delete it at any time.

The route simulation runs entirely from the route your instructor saved. The speed shown on screen is the playback speed of that simulation, not your real speed.

Three things do happen when you open a link. A counter on the route goes up by one, which tells your instructor the route was opened but not who opened it. Our servers see your IP address, as any web server does. And we record that the route was opened, so we can tell how many different people opened it rather than how many times it was refreshed.

That last record deliberately does not identify you. Instead of your IP address we store a one-way scrambled version of it, and the recipe for scrambling changes every day — so two visits on the same day count as one person, and tomorrow the same device is unrecognisable. We cannot turn it back into an IP address, and neither can anyone who obtained a copy of our database. It is not linked to your name or email, because on a private route we hold neither.

If we ever add a feature that reads your real location, it will be off until you switch it on, it will show a clear indicator while it is active, and it will switch itself off again when you close the page. Many learners are 17, so the Age Appropriate Design Code applies to this service and those are its requirements.

04Technical data everyone generates

DataWhat we do with itLawful basis
IP addressHeld briefly in memory to count requests per minute against our map and routing providers, so one caller cannot exhaust the free quotas everyone shares. The address itself is not written to our logs and not stored in our database.Legitimate interests (Art. 6(1)(f)): keeping the service available.
Which pages were opened, and whenWe record that a route was opened, driven or downloaded, so an instructor can see whether their pupils are using what they made. Signed-out visitors are counted using the one-way daily identifier described in section 3, never an IP address or a cookie. Nothing is stored on your device to do this, and no third party is involved.Legitimate interests (Art. 6(1)(f)): telling instructors whether the thing they built is being used.
Server event logsWhen an upstream map or routing provider fails, we log the event, the provider and the failure reason. These lines carry no personal data by design.Legitimate interests (Art. 6(1)(f)): diagnosing faults.
Sign-in cookiesKeep an instructor signed in between pages.Strictly necessary, so no consent banner is required under PECR reg. 6(4).

We use no third-party analytics, no advertising, and no tracking cookies of any kind. Our own usage counting, in the row above, stores nothing on your device and sends nothing to anyone else — which is why there is no cookie banner: PECR reg. 6 governs storing or reading information on your device, and we do neither for this.

If that ever changes we will ask for your consent first, which means a cookie banner, and this notice will be updated before it happens.

05Who else processes this data

We do not sell personal data and we do not share it for marketing. We use the following providers to run the service.

ProviderWhat it doesWhere
SupabaseDatabase, sign-in and the emails that carry sign-in linksLondon, United Kingdom (eu-west-2)
VercelApplication hosting and serverless functionsWashington, DC, United States (iad1)
Photon (komoot)Turns a search term or a map point into a street addressGermany
OSRM (FOSSGIS)Works out the road path between the points on a routeGermany
OpenFreeMapMap tilesEuropean Union
EsriSatellite imagery tilesUnited States
ResendSends our marketing emails and reports whether they were delivered, opened or clickedUnited States

Map, address and routing providers receive coordinates in order to answer. They receive those coordinates from our servers rather than from your browser, so they do not see your IP address, and the coordinates are places on a route rather than a person's location.

Where a provider is outside the UK, the transfer is covered as follows. Providers in Germany and elsewhere in the European Economic Area rely on the UK adequacy regulations that cover the EEA, so no additional safeguard is needed. Providers in the United States rely on the UK Extension to the EU–US Data Privacy Framework where that provider is certified under it, and otherwise on the International Data Transfer Addendum to the European Commission's standard contractual clauses.

You can ask us which mechanism applies to a particular provider, and we will tell you. Supabase, which holds the database and your account, is in London, so the data that identifies you does not leave the UK at rest.

06Marketing emails

We hold a list of email addresses belonging to people who subscribed to updates from us, and we use it to tell them about RoutePOV. If you have never subscribed to anything of ours, you are not on it.

For every address on that list we record the lawful basis for contacting you, where the address came from and when you subscribed. We do that so the answer to “why are you emailing me?” is a record rather than a recollection, and we will tell you what that record says about you if you ask.

The lawful basis is your consent, under regulation 22 of the Privacy and Electronic Communications Regulations, except where an address is marked as belonging to a corporate subscriber and is used for business marketing under our legitimate interests. An address with no recorded basis is never sent anything: that rule is enforced by the query that selects who to email, not by a setting somebody could change.

You can stop the emails at any time and we do not ask why. Every message carries a one-click unsubscribe link, and your email software's own unsubscribe button works too. Either one takes effect immediately. You can also simply reply and ask.

When you unsubscribe we keep your email address on a do-not-contact list indefinitely, and nothing removes it. That is the only way to guarantee a future import cannot put you back on the list: we have to remember who asked us to stop in order to honour it.

We record whether a message was delivered, opened and whether its links were clicked. We use that to stop emailing people who are not reading, and to spot a broken send before it reaches everyone. We do not use it to build a profile of you, and no decision about you is made from it.

07How long we keep things

Your account, profile and routes are kept until you delete them or ask us to close your account, at which point they are deleted from the live database within 30 days. Deleting a route immediately stops its share link working.

Records of which pages were opened are kept for 400 days and then deleted automatically. They are about behaviour rather than identity, so keeping them indefinitely would be a liability rather than an asset, and nothing we do with them looks back further than a year.

Marketing contacts are kept until you unsubscribe or ask us to delete you. The do-not-contact list itself is kept indefinitely and deliberately, for the reason given in the section above. The record that a particular message was sent to a particular address is also kept, because it is the evidence that the send was lawful at the time.

Backups taken before a deletion are overwritten on our provider's normal cycle. Rate-limiting counters live in memory for one minute and are never written to disk. Server event logs are kept by our hosting provider for a limited period on its standard retention.

08Your rights

Under the UK GDPR you can ask us to:

  • give you a copy of the personal data we hold about you;
  • correct anything inaccurate;
  • delete it, where we have no overriding reason to keep it;
  • restrict how we use it while a dispute is resolved;
  • send it to you, or another provider, in a portable format, where we rely on contract as the basis;
  • stop processing based on legitimate interests, where your rights outweigh ours.

Write to privacy@routepov.com. We will respond within one month. There is no charge unless a request is manifestly unfounded or excessive.

If you are not satisfied with how we have handled your data, tell us and we will put it right. You also have the right to complain to the supervisory authority for data protection in the UK, and doing so does not depend on raising it with us first.

09Automated decisions and required data

We do not make any decision about you by automated means, and we do no profiling.

Providing an email address is necessary to have an instructor account, because it is how you sign in. Everything else in your profile is optional, though the service is less useful without it. Learners are asked for nothing at all.

10Changes

If we change how we use personal data we will update this page and change the date at the top. Where a change is significant we will tell instructors by email before it takes effect.