Routly.

Privacy policy

This site sets no cookies, runs no analytics and has no tracking pixels. The only personal data it processes is what you type into the contact form.

Last updated 16 August 2026

1. Who is responsible

The controller for any personal data described here is:

Asset Track Sp. z o.o.
ul. Marszalkowska 115/338
00-102 Warszawa, Poland

KRS 0001072405 · NIP 5252982554 · REGON 527071236

privacy@theassettrack.com

Routly is a product of Asset Track. We have not appointed a Data Protection Officer, because the scale and nature of this processing does not require one under Art. 37 GDPR. Write to the address above and a person will answer.

2. What this site collects

Two things, and nothing else. There is no cookie banner on this site because there is nothing to consent to: no analytics, no advertising, no session cookies, no local storage.

The contact form

Your name, work email and the fleet size you select, plus anything you write. You give it deliberately; nothing is collected in the background.

Server logs

Our hosts record the usual: IP address, user agent, the URL requested and the time. We do not read these routinely and do not connect them to anyone.

What the demo collects

Nothing. demo.routly.app has no accounts, no sign-up and no database — it runs on generated data held in your browser for the length of the visit.

What Routly itself collects

Also nothing, and this is the point of the product. Routly is self-hosted: your vehicles, trips and positions live in databases you run, on infrastructure you control. We have no access to them, no telemetry back-channel and no way to read them. If you buy a commercial licence and ask us to help with the deployment, we touch your systems only for as long as that engagement lasts and under a separate agreement.

3. Why we are allowed to

  • Consent — Art. 6(1)(a). You submit the contact form. You can withdraw it at any time by writing to privacy@theassettrack.com.
  • Contract — Art. 6(1)(b). Once we are working together, to do the work.
  • Legitimate interest — Art. 6(1)(f). Keeping the servers up and secure.
  • Legal obligation — Art. 6(1)(c). Invoices and accounting records.

4. Who else sees it

Three companies, each doing one job. We do not sell personal data, we do not share it for advertising, and there is no fourth party.

ProcessorWhat forWhat they get
Vercel Inc.
United States
Hosting for routly.appServer logs: IP address, user agent, requested URL
EU Standard Contractual Clauses
Formspree, Inc.
United States
Delivery of the contact formWhatever you type into the form: name, work email, fleet size
EU Standard Contractual Clauses
Cloudflare, Inc.
United States and EU edge
Hosting for demo.routly.appServer logs only — the demo has no accounts and stores nothing
EU Standard Contractual Clauses

All three are in the United States, so your data leaves the European Economic Area. Each transfer rests on the European Commission's Standard Contractual Clauses. Authorities get data only where a law obliges us, and we will tell you unless that law forbids it.

5. How long it is kept

WhatHow longWhy
Contact form enquiries24 months from the last exchangeSo we can pick up a conversation you started
Email correspondence24 months from the last exchangeSame
Customer and licence recordsContract term plus 5 yearsPolish accounting and tax law
Web server logsAs kept by the host, under 30 daysSecurity and fault diagnosis

6. Your rights

Write to privacy@theassettrack.com and we answer within one month, as Art. 12(3) requires. Exercising any of these is free.

  • Access (Art. 15) — Ask what we hold about you and get a copy.
  • Rectification (Art. 16) — Have anything wrong or incomplete corrected.
  • Erasure (Art. 17) — Have it deleted, unless the law requires us to keep it.
  • Restriction (Art. 18) — Have us stop processing it while a dispute is resolved.
  • Portability (Art. 20) — Receive it in a machine-readable format.
  • Objection (Art. 21) — Object to processing we base on a legitimate interest.
  • Withdraw consent (Art. 7(3)) — Withdraw it at any time, without affecting what came before.

7. If we get it wrong

Tell us first and we will fix it. You also have the right under Art. 77 to complain directly to the Polish supervisory authority:

Urząd Ochrony Danych Osobowych (UODO)
ul. Stawki 2, 00-193 Warszawa, Poland
uodo.gov.pl

8. Security

The site is served over TLS and holds no database of its own — there is no store of personal data on it to breach. Form submissions live in Formspree and in our mailbox, both behind multi-factor authentication. If a breach ever affects you, we notify the authority within 72 hours and you without undue delay, as Art. 33 and 34 require.

9. Changes

The date at the top is the last change. Anything that alters what we collect or who receives it will be reflected here before it takes effect, and this page is versioned in the same repository as the site, so the history is auditable.