Privacy Policy
Last updated: 20 August 2026
The short version
We never receive your clients’ names, addresses or visit times. Everything you type into the scheduler stays in your own browser. It is not uploaded, not stored on our servers, and not something we could hand over, lose in a breach, or read if we wanted to.
What we do hold is your own account: an email address, your subscription status, and anonymous usage counts.
Overview
GeoRoutes ("we", "us", "our") provides route planning and scheduling software for community health and care teams. This policy explains what information we collect when you use georoutes.co.uk, how we use it, and the choices available to you.
Your clients' and staff details stay on your device
The staff, clients, postcodes, visit times and generated schedules you enter are held only in the browser you entered them in, using a storage area called IndexedDB. They are never transmitted to us and we have no way to access them.
This applies to every account, free and Pro alike. Paying for Pro raises your limits and unlocks features; it does not move your data onto our servers.
There are two practical consequences worth understanding. Your data does not sync between devices or browsers — a schedule built on your laptop is not on your phone. And if you clear your browsing data, the information is gone, because there is no copy elsewhere to restore from. Use the export option in Settings to keep a backup and to move to a new machine.
Because we never receive this information, we are not a “processor” of it under UK GDPR. You remain the controller of your clients’ data throughout, and you do not need a data processing agreement with us in order to use GeoRoutes.
What we do collect
Account information. When you create an account we collect your email address and authentication details via our identity provider, Supabase.
Payment information. Subscription payments are processed by Stripe. We do not store your card details — Stripe provides us with a customer and subscription reference so we can manage your plan.
Usage counts. When a schedule is generated we record how many staff and appointments were involved and how long it took, so we can tell whether the scheduler is working. These records contain no names, no addresses and no postcodes.
Error reports. If something breaks, your browser sends us the error message and the page it happened on so we can fix it. The part of a web address after a “#” is removed before the report is stored, because that is where a shared round travels.
Travel times between postcodes. To avoid asking our routing provider the same question repeatedly, we keep a table of how long it takes to travel between two postcodes. It records the pair of postcodes, the distance and the duration — and nothing about who asked or when. Entries are deleted automatically after a month without use.
Sharing a round with a carer
When you send a carer their round for the day, the visits are encoded into the web link itself, after the “#” symbol. Browsers never send that part of a link to a server, so the round travels from your device to theirs without passing through us. There is no copy on our systems.
Two things follow from that. Anyone holding the link can open it, so send it only to the person doing the round. And because there is no server-side record, a link cannot be withdrawn once sent — issue a fresh one each day rather than relying on an old one expiring.
Cookies and analytics
Cookies. We use cookies to keep you signed in and to remember your preferences. These are necessary for the service to work and are not used for advertising. GeoRoutes shows no advertising and sets no advertising cookies.
Analytics. We use Google Analytics to count page visits and see which pages are read. In the UK, the EEA and Switzerland we ask before it stores anything: until you accept, it runs with storage denied and sets no cookie or identifier on your device. If you decline, or ignore the banner, it stays that way and the site works identically — we simply count less precisely. You can change your answer at any time using the Cookie settings link in the footer.
Analytics is switched off entirely on the page that displays a carer’s round, so that a shared round is never measured.
We do not use Google Analytics for advertising. The advertising permissions in the tag are refused permanently and are never enabled by accepting analytics.
How we use information
- To provide, operate, and maintain the scheduling service.
- To calculate travel times from the postcodes your browser sends to our routing provider. Only postcodes are sent — never names or addresses.
- To process subscription payments and manage your plan via Stripe.
- To communicate with you about your account or changes to our service.
Who we share information with
We share information with the following providers solely to operate the service:
- Supabase — authentication, our own account records, and website content.
- Stripe — subscription billing and payment processing.
- OpenRouteService — travel-time calculation from postcodes alone.
- postcodes.io — checking that a UK postcode exists when you enter one.
- Google Analytics — page-visit counts, storing nothing on your device unless you accept.
- Cloudflare — hosting and content delivery, plus traffic measurement performed at their network rather than in your browser, which sets nothing on your device.
None of these providers receives your clients’ names or addresses, because we never have them to pass on.
Retention
We retain your account record for as long as your account is active. Usage counts and error reports are kept while they remain useful for diagnosing problems. Cached travel times between postcodes are deleted after a month without use.
Your scheduling data has no retention period here because we never hold it. It remains on your device until you delete it, and removing your account does not remove it — clear it from the browser, or use Settings to clear it directly.
Your rights
You may request access to, correction of, or deletion of the personal data we hold about you by emailing us at the address below. You can change your account password at any time from the Account page, and manage or cancel your subscription from the billing portal linked there.
For your scheduling data, these rights sit in your hands rather than ours: export it, correct it or delete it yourself from Settings, at any time and without asking us.
If you are unhappy with how we have handled your personal data, you can complain to the Information Commissioner’s Office at ico.org.uk.
Children
GeoRoutes is a business scheduling tool and is not directed at children. We do not knowingly collect information from anyone under 16.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
Contact
Questions about this policy or your data can be sent to support@georoutes.co.uk.
See also our Terms of Service.
