Privacy Policy

Last updated: October 2, 2026

1. Overview

RunSheet is operated by DerMar Consulting Group LLC (doing business as ForgeWorks), 3151 Cape Horn Rd, Unit #2092, Red Lion, PA 17356, USA ("we," "us," or "our"). RunSheet is a delivery route management platform at my-runsheet.com. This Privacy Policy explains what information we collect, how we use it, and your choices regarding your data. By using RunSheet, you agree to the practices described here.

2. Information We Collect

Account and Business Information

  • Company name and subdomain
  • Account administrator name, username, and email address
  • Driver and dispatcher names and contact information you enter
  • Billing address and payment method (handled by Stripe — we do not store full card numbers)

Operational Data

  • Customer delivery addresses, phone numbers, email addresses, and delivery instructions you upload
  • Route history, delivery timestamps, stop sequences, and driver notes
  • Proof-of-delivery photos uploaded by drivers
  • Photos of a recipient's ID, taken by drivers on deliveries that require age verification
  • Delivery status records and per-action audit log entries
  • Route templates and recurring schedule configurations

Driver Location Data

  • If the location tracking feature is active, we collect GPS coordinates (latitude and longitude) from drivers' devices while they are on an active route
  • Location data is used only to display driver position to dispatchers in real time, to show a customer the driver's position on their delivery tracking page while a delivery to them is pending on that day's active route, and to support the driver app's geofence-based arrival prompt
  • We keep only each driver's latest position: every update overwrites the previous one, so no location history is stored. Dispatchers see a position for 10 minutes after it is sent; the last position stays on file until the driver's next update
  • Drivers consent to GPS location collection when using the driver app during an active route

SMS and Customer Communications

  • If you enable SMS notifications, we collect and transmit customer phone numbers to Telnyx to deliver delivery status messages on your behalf
  • SMS opt-in is implicit when a customer's phone number is provided by you and SMS is enabled; recipients may opt out at any time by replying STOP
  • We do not use customer phone numbers for any purpose other than delivering notifications you initiate

AI-Processed Data

  • Proof-of-delivery photos may be analyzed by Anthropic's Claude AI to generate a natural-language description of the delivery
  • Driver notes may be processed by Anthropic's Claude AI to extract actionable delivery instructions
  • No personally identifiable information is deliberately included in AI prompts beyond what is necessary to generate a delivery description

Security and Access Data

  • Active login sessions (JWT identifiers, creation time, IP address, user agent) for session management
  • API key metadata (hashed key, name, creation date, last used — the raw key is never stored)
  • Webhook endpoint URLs and configuration you provide

Usage and Technical Data

  • IP addresses and device information when you access the Service
  • Log data including pages visited, actions taken, and timestamps
  • Browser type and operating system
  • Visits to our public website pages, measured with Google Analytics (see section 12)

3. How We Use Your Information

  • To provide, operate, and improve the Service
  • To process payments and manage your subscription
  • To send transactional emails (account verification, billing receipts, payment failure notices, driver daily summaries, customer delivery notifications)
  • To geocode delivery addresses and calculate optimized routes
  • To display driver locations to dispatchers during active routes
  • To generate delivery analytics and performance reports within your account
  • To transmit delivery event data to webhook endpoints you configure
  • To respond to support requests and communicate about the Service
  • To detect and prevent fraud and abuse
  • To comply with legal obligations

We do not sell your data or use it for advertising purposes.

4. Customer Delivery Notifications and Portals

RunSheet offers two optional features that involve sending information to your end customers:

  • Delivery notification emails: When enabled by your account administrator, an automated email is sent to a customer's email address when their delivery is marked complete. These emails are sent via Resend using the customer email address you have on file.
  • Customer delivery portal: Each customer record is assigned a unique, unguessable portal token. The portal URL may be shared with your customer (e.g. included in a delivery notification email) to allow them to view their recent delivery history without logging in. While a delivery to that customer is pending on that day's active route, the portal also shows the driver's latest position (up to 10 minutes old).

Both features are disabled by default. You are responsible for ensuring you have the necessary consent from your customers before enabling these features and for complying with applicable communications laws.

5. Third-Party Services

We use the following third-party services to operate RunSheet. Each has its own privacy policy governing their use of your data:

Stripe

Payment processing and subscription management. Stripe receives your billing address and payment method. We never see or store your full card number. stripe.com/privacy

Google Maps Platform

Address suggestions, geocoding, route geometry, traffic data, and business information lookup, through Google's maps.googleapis.com and other googleapis.com servers. Delivery addresses you enter are sent to Google to suggest and place addresses and to calculate coordinates and road-following routes. In the driver app, the driver's browser also sends Google the current stop's location to show a Street View photo of it. policies.google.com/privacy

Google Sign-In (optional)

If your company turns on Sign in with Google and you use it, you sign in on Google's own page (accounts.google.com). Google then sends us your name, email address and Google account ID so we can match you to your RunSheet user. policies.google.com/privacy

TomTom

Backup address lookup. If Google cannot place an address, our servers may send the address text to TomTom to find its coordinates. tomtom.com/privacy

OpenStreetMap Foundation

Map images and last-resort address lookup. The maps in the app and on the customer delivery portal load their map images from OpenStreetMap's tile servers (tile.openstreetmap.org), so your browser sends them your IP address, browser details and the map area shown (our site's address, but not the page path or portal link). If neither Google nor TomTom can place an address, our servers send the address text to OpenStreetMap's Nominatim service (nominatim.openstreetmap.org). osmfoundation.org/wiki/Privacy_Policy

Resend

Transactional email delivery. Email addresses are shared with Resend solely to deliver system emails (verification, billing, invitations, delivery notifications, driver summaries). resend.com/legal/privacy-policy

Hetzner Cloud

Server infrastructure. Your data is stored on servers located in the European Union (Falkenstein, Germany). hetzner.com/legal/privacy-policy

Cloudflare R2 and Turnstile

Object storage for proof-of-delivery photos and optional database backups (Cloudflare R2, cloudflarestorage.com). Photos are served through access-controlled API endpoints and are not publicly accessible. The sign-up page also uses Cloudflare Turnstile to keep bots out; it processes your IP address and browser signals for that check. cloudflare.com/privacypolicy

Google Analytics

Visit statistics for our public website pages (see section 12), loaded from www.googletagmanager.com. Google receives the page address without its query string, your IP address and browser details, and sets the _ga cookies. policies.google.com/privacy

Fonts and code libraries

Our pages load the Inter font from Google Fonts (fonts.googleapis.com and fonts.gstatic.com). Some signed-in pages also load open-source code libraries from the jsDelivr (cdn.jsdelivr.net) and cdnjs (cdnjs.cloudflare.com) networks: charts on the Analytics page, drag-and-drop stop ordering in the route builder and route detail, and PDF export on route detail. Your browser sends these servers your IP address and browser details when it downloads the files; no account or delivery data is sent. policies.google.com/privacy · jsdelivr.com/terms · cloudflare.com/privacypolicy

Navigation apps (driver's choice)

When a driver taps Navigate, the stop's address (or its coordinates, if it has no address) is opened in the navigation app the driver picked: Google Maps (google.com), Apple Maps (maps.apple.com) or Waze (waze.com). That app's own privacy policy then applies. apple.com/legal/privacy · waze.com/legal/privacy

Telnyx

SMS delivery for customer notifications. When SMS notifications are enabled, customer phone numbers are transmitted to Telnyx solely to deliver messages you initiate. telnyx.com/privacy-policy

Anthropic (Claude AI)

AI-powered features including proof-of-delivery photo analysis and delivery note extraction. Delivery photos and driver notes may be sent to Anthropic's API to generate natural-language descriptions. anthropic.com/legal/privacy

Shopify and webhooks (your configuration)

If you connect your Shopify store, our servers fetch its orders from your store (your-store.myshopify.com), and Shopify sends us new orders as they are placed, including customer names, delivery addresses, phone numbers and email addresses, to create delivery stops. If you configure webhooks, delivery event data (including client names and delivery status) will be transmitted to the URLs you specify. You are responsible for the privacy practices of any third-party system you connect via webhooks.

6. Data Retention

We retain your data as long as your account is active. Specific retention periods:

  • Proof-of-delivery photos: deleted automatically once they are older than your plan's photo history — Starter: 30 days, Growth: 90 days, Business: 365 days (each Extended History pack adds 30 days on Starter and Growth)
  • Routes, clients and delivery records (statuses, timestamps, notes and e-signatures): retained for the life of your account
  • Audit log entries: retained for the life of your account
  • Driver location data: only the latest position per driver is kept. It is overwritten on each update and shown to dispatchers for 10 minutes; no location history is stored
  • Age-verification ID photos: kept with the delivery stop for the life of your account. They are not covered by the proof-of-delivery photo history above and are not deleted automatically
  • Active session records: retained until the session expires or is revoked
  • Account and billing records: retained for the duration of your account plus 7 years for tax/legal compliance
  • Server logs: retained for 30 days
  • AI-generated delivery descriptions: retained as part of the delivery record, for the life of your account

Cancelling your subscription does not close your account: it moves to Starter limits, so proof-of-delivery photos older than 30 days are deleted, and the rest of your data stays available to you. When your account is closed, your operational data (routes, clients, deliveries) is kept for 30 days, so you can ask us for an export, and is then permanently deleted. To close your account or get an export, contact info@my-runsheet.com.

7. Your Customer Data

You are the data controller for customer information you upload to RunSheet (delivery addresses, phone numbers, email addresses, etc.). You are responsible for ensuring you have a legal basis to store and process that information. RunSheet processes this data only as a data processor acting on your instructions.

Your customers' delivery addresses are transmitted to Google Maps Platform for geocoding and routing. If you enable customer notifications or delivery portals, your customers' email addresses are used to send delivery status communications. You should disclose these practices to your customers if required by applicable privacy law.

8. Security

We use industry-standard security measures including:

  • Encrypted HTTPS connections for all data in transit
  • Bcrypt-hashed passwords and SHA-256-hashed API keys (raw values are never stored)
  • Tenant isolation — your data is logically separated from other accounts at the database level
  • Access-controlled photo serving — proof-of-delivery photos are only accessible to authenticated users within your account
  • Session management — you can view and revoke active login sessions from the Users page
  • HMAC-SHA256 webhook signatures to allow verification of outbound payloads

No system is perfectly secure, and we cannot guarantee absolute security of your data.

9. Your Rights

Depending on your location, you may have rights regarding your personal data, including:

  • Access to the personal data we hold about you
  • Correction of inaccurate data
  • Deletion of your account and associated personal data
  • Export of your data in a machine-readable format (CSV export available in the app)
  • Objection to certain processing activities

To exercise any of these rights, contact us at info@my-runsheet.com. We will respond within 30 days.

10. California Consumer Privacy Act (CCPA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you
  • Right to Delete: You may request deletion of personal information we have collected from you, subject to certain exceptions
  • Right to Opt-Out: We do not sell personal information. There is nothing to opt out of with respect to the sale of your data
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights

To submit a CCPA request, contact us at info@my-runsheet.com. We will verify your identity before processing the request and respond within 45 days.

11. GDPR — Rights of EU/EEA Users

If you are located in the European Union or European Economic Area, you have the following rights under the General Data Protection Regulation (GDPR):

  • Right of Access (Art. 15): Obtain a copy of your personal data and information about how it is processed
  • Right to Rectification (Art. 16): Request correction of inaccurate or incomplete personal data
  • Right to Erasure (Art. 17): Request deletion of your personal data where there is no compelling reason for continued processing
  • Right to Restriction (Art. 18): Request that we restrict processing of your personal data in certain circumstances
  • Right to Data Portability (Art. 20): Receive your personal data in a structured, machine-readable format
  • Right to Object (Art. 21): Object to processing of your personal data where we rely on legitimate interests as our legal basis
  • Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection authority

Our legal basis for processing personal data is primarily contractual necessity (providing the Service you signed up for) and legitimate interests (security, fraud prevention, service improvement). To exercise any GDPR rights, contact us at info@my-runsheet.com. We will respond within 30 days.

Please note that our server infrastructure is hosted in the EU (Hetzner, Falkenstein, Germany). Data processed by sub-processors located outside the EEA (such as Stripe, Telnyx, Google, and Anthropic in the United States) is transferred under Standard Contractual Clauses or equivalent transfer mechanisms.

12. Cookies, Analytics and Local Storage

RunSheet does not use advertising cookies. We use:

  • Google Analytics: on our public website pages (the home page, blog, docs, tour, demo, comparison and legal pages, and the sign-up, sign-in and account-recovery pages) to count visits and see which pages are used. It sets cookies such as _ga and _ga_<id> and sends Google your IP address and browser details. We send Google only the page address without its query string, so links that carry a reset, invite or sign-in code are not shared. It does not run inside the signed-in app or the customer portal. You can block it with your browser settings or Google's opt-out add-on (tools.google.com/dlpage/gaoptout); RunSheet works the same either way
  • Cloudflare Turnstile: on the sign-up page, as described in section 5
  • localStorage: We store your authentication token (JWT), language preference, and UI state (e.g., hide-completed preference) in browser localStorage. This data stays on your device and is not transmitted to any third party other than as an authorization header in API requests to our own servers
  • IndexedDB: The driver app uses IndexedDB to queue deliveries for offline submission when network connectivity is unavailable. Queued data is uploaded to our servers when connectivity is restored and deleted from local storage on successful upload
  • Session cookies: We may use session cookies for authentication state management. These expire when you close your browser or log out

The customer delivery portal uses URL-embedded tokens and does not require any login or additional cookies.

13. Children's Privacy

RunSheet is a business tool and is not directed at individuals under 18. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal information, contact us and we will delete it.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by displaying a notice in the Service. The "last updated" date at the top of this page reflects the most recent revision.

15. Contact

Questions about this Privacy Policy or your data? Contact us at info@my-runsheet.com.