KavaRoutes · Policies
Privacy policy
How KavaRoutes handles information when you visit the website, create a business account, or use the workspace.
Effective and last updated:
Who this policy covers
KavaRoutes is a US-based, unincorporated software business serving non-emergency medical transportation providers in all 50 states. In this policy, “KavaRoutes,” “we,” and “us” refer to the business operating the KavaRoutes website and software.
This policy covers our public website, business accounts, and information handled through the workspace and connected driver tools. The service is intended for US businesses. A transportation provider using KavaRoutes is responsible for the passenger and workforce information it supplies, including required notices, permissions, and instructions about that information. Passengers and employees should also consult their provider’s privacy notice.
Information we handle
- Account information. Business name, email address, account identifiers, verification and membership status, trial dates, and account activity. Authentication providers process the credentials you enter. If you choose a supported Google or Microsoft sign-in option, we receive information needed to authenticate your business account.
- Business records. Information your business enters or uploads, such as client contact details, pickup and drop-off addresses, trip and appointment details, transportation requirements, driver and vehicle assignments, trip progress, costs, and invoice records.
- Driver information. Where the relevant tools are enabled, driver account details, itineraries, inspection records, signatures, and location updates. Location collection depends on the enabled workflow and device permissions.
- Technical information. IP addresses, browser and device information, request timestamps, security events, diagnostic logs, website usage measurements, session records, and device keys used to protect sign-in.
- Support and checkout information. Messages you send us and information needed to handle your request. Checkout is currently in testing; test flows can generate payment-provider customer and subscription identifiers. Payment forms are hosted by the payment provider.
Provide only information needed for your work. Do not include passenger medical details in website contact messages or support email.
How information is used
We use information to create and authenticate accounts, maintain business access, provide dispatch and routing workflows, manage trials and account status, respond to support requests, and diagnose and improve service operation. We also use technical information to prevent abuse, investigate security incidents, and protect accounts.
Routing and geocoding requests use the addresses or coordinates needed to calculate the requested route or location. Account-related communications may include verification, password reset, security, and service messages.
Customer trip data is used to provide and improve services for customers. We keep client records private and limit access to authorized users and providers supporting those services. We do not sell personal information, share it for targeted advertising, or send marketing emails.
Cookies and browser storage
Sign-in uses session cookies and browser storage, including a device key that helps bind a session to your browser. Browser storage also supports account flows and preferences. Cloudflare provides website analytics and security processing; network providers may use cookies or similar mechanisms for security.
You can manage cookies, site storage, and location permissions in your browser or device settings. Clearing or blocking sign-in storage may sign you out or prevent account features from working. Use “Sign out all devices” in your account when you need to revoke existing business sessions.
Retention and security
Information is retained as needed to provide the service, maintain business records, address support or security issues, and meet applicable legal obligations. Retention varies by record type and purpose. Closing an account or requesting deletion may require coordination with the business controlling its records; legal obligations and backup copies can affect deletion.
We use safeguards including encrypted connections, access controls, and session revocation. No system can guarantee complete security. Keep devices and account credentials secure, and contact us promptly if you suspect unauthorized access.
Your choices and requests
Contact [email protected] to request access to, correction of, deletion of, or an export of information associated with your account. We may need to verify your identity and authority over the records before acting. Do not send passwords, session cookies, or passenger medical records with your request.
If you are a passenger or employee whose information was entered by a transportation provider, contact that provider first. We can help identify the appropriate request process without disclosing another business’s records. Rights and exceptions depend on applicable law; where available, you may also ask us to review a denied request.
Business accounts are intended for adults acting for their organizations. We do not offer accounts to children under 18. Records about a minor passenger may be supplied by an authorized transportation provider as part of its work.
Contact and updates
For privacy questions or account requests, email [email protected]. We will publish changes here with an updated date. If a change materially affects how we handle account information, we will provide an appropriate notice through the service or account contact information.