Privacy Policy

Last updated September 20, 2026

Swoop IO is route planning, dispatch and proof-of-delivery software for delivery businesses. It has three surfaces: a web console for dispatchers, a driver app for iOS and Android, and public tracking pages for the people receiving deliveries. This policy explains what each one collects and why.

Two kinds of data, two different roles

Data we control. Account and workspace information you give us directly to run Swoop IO — your name, email address, and subscription status.

Data we process for you. Everything your business puts into Swoop IO about your own deliveries and drivers — recipient addresses, delivery notes, GPS breadcrumbs, proof of delivery. Your business decides what goes in and why; we hold and process it on your instructions, and we do not use it for our own purposes.

What we collect

Account data. Name and email address, plus whichever sign-in method you choose: a one-time code we email you, a securely hashed password, or — where enabled — the account identifier and email returned by Apple, Google or Microsoft. We never see or store your password in readable form, and we never receive your password for any third-party provider.

If you use Sign in with Apple and choose to hide your address, we only ever receive Apple's private-relay alias — not your real email. Apple tells us your name exactly once, when you first authorize; after that it is never sent again.

Face ID / Touch ID. If you turn on biometric unlock, the check happens entirely on your device through iOS. Your face and fingerprint data never leave your phone and are never sent to us — iOS only tells the app whether the check passed. We store a single on/off preference in your device's secure keychain.

Delivery data. The stops your workspace creates: recipient name, delivery address, phone or email where provided, time windows, package details, the barcode a stop expects, and delivery instructions — plus the contacts, templates, depots, vehicles and vehicle maintenance records your workspace keeps to plan with. Vehicle records are about vans (plate, odometer, service history), not people.

Driver location. The driver app shares a driver's location only while a route is in progress, and stops the moment the route ends. While a route is in progress this includes location in the background — when the phone is locked or the app is not on screen (for example in a cradle) — because that is what detects arrival at a stop automatically and measures time at the door without the driver having to tap. The app shows a visible indicator whenever it is tracking, and never collects location outside an active route. Breadcrumbs let dispatchers see route progress and let recipients see an accurate ETA. The same position is what records the driver's return to the depot at the end of a round, and what the app uses to measure the remaining distance along the road. A driver can turn off location permission at any time in device settings; the app keeps working, with dispatch seeing stop updates but no live position.

Turn-by-turn navigation, if a driver turns it on. By default the driver app hands navigation to the driver's own maps app, and we send nothing extra. A driver can instead turn on navigation inside the app, in Settings on their own phone. While that setting is on and a leg is being driven, the driver's position is sent continuously to Google along with the destination address, because that is what produces turn-by-turn directions — Google receives this directly and handles it under the Google Privacy Policy. We do not send Google the recipient's name, the delivery notes, or anything else about the stop. The first time a driver turns the setting on, Google asks the driver to accept its own terms; declining changes nothing about how the app works. Switching the setting off stops it, and it is off unless a driver turns it on.

Proof of delivery. Photos taken with the device camera, on-screen signatures, typed notes, scanned barcodes, and failed-delivery reasons — each captured by a driver at a stop. Because these document a delivery, a proof photo may show the exterior of the delivery location — a doorway, a porch, a package left at a home or business. The workspace decides what its drivers must capture. The app uses the camera only when a driver taps to capture proof; it does not read the device photo library. Proof images are stored in our platform's object storage and shown back only to the workspace that captured them.

Technical data. Standard server logs (IP address, timestamps, error traces) kept for security and debugging.

What we do with it

We use this data to operate the product: geocode addresses, compute and optimize routes, fetch turn-by-turn directions and live traffic for a dispatched round, show a weather forecast for each depot on the planning pages, dispatch rounds to drivers, show live progress to dispatchers, generate tracking pages and ETAs for recipients, verify and store proof of delivery, and produce your analytics. We also use it to secure accounts, provide support, and bill your subscription.

We do not sell your data, and we do not use it to train machine-learning models. We do not show you third-party advertising or share data with advertisers.

Who else touches it

Swoop IO uses a small number of subprocessors, each handling only what its job requires:

  • Google Maps Platform — route optimization, address geocoding (including bulk geocoding for spreadsheet imports), traffic-aware ETAs, turn-by-turn directions with per-stretch traffic for a dispatched round, weather forecasts, and — only where a driver has switched it on — live turn-by-turn navigation inside the driver app. Addresses and coordinates are sent to compute routes; for weather only a depot's coordinates are sent — no delivery or personal data. For in-app navigation, the driver's live position and the destination address are sent for the length of the leg, and nothing else about the stop.
  • Apple, Google and Microsoft — only if you choose to sign in with one of them (on the web console, the iOS app or the Android app). They tell us an account identifier and, unless you hide it, your email address. They never tell us your password, and we never tell them what you do inside Swoop IO.
  • Apple Push Notification service and Google Firebase Cloud Messaging — where push notifications are enabled, deliver them to the driver app (for example, "a stop was added to your route") on iOS and Android respectively. Only a device push token and the notification text are involved; the content is operational, never marketing.
  • Resend — delivers one-time sign-in codes. Your email address and the code only.
  • Twilio — recipient SMS notifications, where your workspace enables them. Recipient phone number and tracking link only.
  • Stripe — subscription billing. Payment card details go straight to Stripe and never reach Swoop IO's servers.
  • oKooka — the platform that hosts Swoop IO's accounts, database, proof-of-delivery image storage and billing integration.

Optimization and geocoding providers are configured per workspace — if you supply no keys, Swoop IO's built-in optimizer and geocoder run instead and no address data leaves our infrastructure.

We may also disclose data where the law requires it, or to protect the rights and safety of our users.

Recipient tracking pages

Tracking links (/t/…) are unauthenticated URLs containing an unguessable token, so a recipient can open one without an account. Each page shows only that one delivery, and the sending workspace controls how much it reveals — ETA only, position in queue, or live map. Tokens can be revoked by the workspace.

Deleting your account

You can permanently delete your account from Settings → Plan & billing → Delete my account in the iOS app, or by writing to us. No support ticket, no waiting.

Deleting your account also deletes any workspace where you are the only owner, including its routes, stops, proof of delivery and driver records. Workspaces that have another owner are left untouched — closing your own account should never destroy a colleague's business. This is immediate and cannot be undone.

How long we keep it

Delivery records and location breadcrumbs are retained while your workspace is active, because they are your operational and compliance record. Proof-of-delivery photos and signatures are kept for your plan's retention period 90 days on Solo, 12 months on Team and Fleet — measured from capture, and then permanently purged; a plan change never retroactively shortens the retention a record was captured under. You can delete individual records at any time from the console. When a workspace is closed we delete or irreversibly anonymize its data within 90 days, except where we must retain something to meet a legal obligation.

Sign-in codes expire after ten minutes and are stored only as a hash. Account sign-in sessions expire after 60 days; a driver device signed in with an invite code lasts up to 180 days. Any of them can be revoked at any time by signing out, and signing out of the driver app also erases anything held on that device for offline delivery.

Security

Data is encrypted in transit (TLS) and at rest. Access is scoped to your workspace and enforced at the database layer, so one workspace cannot read another's data. Passwords are hashed with bcrypt. Access to production systems is limited to staff who need it.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict processing, and to complain to a data protection authority. Most of this you can do yourself in the console; for anything else, write to us and we will respond within 30 days.

If you are a driver or a delivery recipient and your data reached Swoop IO through a business using our software, that business is the controller — contact them first, and we will support them in answering you.

Drivers: what your employer can see

We think this deserves to be said plainly. While a route is in progress — and only then — the dispatcher can see your position on the live board, including while your phone is locked or the app is in the background, along with your stop completions, the time you returned to the depot, and the proof of delivery you capture. The app shows a visible indicator the whole time it is tracking, and keeps the screen awake while a round is in progress. Outside an active route, the app does not track you. You can revoke location permission in your device settings at any time; the app will keep working, and dispatch will see stop updates without a live position.

Navigation inside the app is your switch, on your phone, and it is off until you turn it on. Turning it on sends your position to Google while you drive a leg, and Google will ask you to accept its own terms before it does anything. Turning it off puts you back to the maps app of your choice. Your employer cannot turn it on for you, and nothing about the round changes either way.

Children

Swoop IO is business software and is not directed at children. We do not knowingly collect data from anyone under 16.

International transfers

Swoop IO is operated from the United States, and our subprocessors may process data in other countries. Where required, transfers rely on Standard Contractual Clauses or an equivalent safeguard.

Changes

We will post any material change to this policy here and update the date above, and will notify workspace owners by email before a significant change takes effect.

Contact

Questions, requests or complaints: privacy@swoop-io.com.