Operator: Social Synergy AI, trading as HeavyRoutes, ABN 14 921 514 624
Business address: 17 Phar Lap Parade, Karalee QLD 4306, Australia
Privacy contact: info@socialsynergy.io
1. Who we are and what this policy covers
HeavyRoutes develops heavy-vehicle route planning, navigation and transport operations software. The public website currently collects expressions of interest for an Australian owner-driver pilot. Fleet and dispatch features are a separate development track; the descriptions below apply where the relevant service is available and used. This policy explains how the operator identified above (“we”, “us” and “our”) handles personal information through heavyroutes.com, our mobile app, dispatch portal and related support and account services.
It covers website visitors, people registering pilot interest, account holders, owner-drivers, organisation contacts and people whose information is entered into the platform, including customers and delivery recipients. Not every type of information described below is collected from every person. Collection depends on the features used and information supplied.
If you use HeavyRoutes through an employer, fleet operator or other organisation, that organisation also makes decisions about the operational information it collects and uses. Its privacy and workplace notices apply to its activities. This policy describes our handling of that information and does not replace those notices or reduce our own obligations.
2. Information we collect
- Pilot expressions of interest: Name, email address, general operating region, usual truck or combination and phone platform (iPhone, Android or both/undecided). Optional information includes setup details, main type of work, current navigation tool and the planning difficulty you describe. The EOI asks for your phone platform, not your phone number.
- Account and contact details: Name, email address, authentication and account identifiers, organisation membership and role, invitation details, profile image where supplied, registration path, and records of terms acceptance and the privacy version presented. Passwords are handled through our authentication service.
- Enquiries and support: Contact details and correspondence. In-app support includes your selected topic, subject, description, replies, request reference, status and timestamps. Optional app diagnostics are described in section 3. Email correspondence may include attachments you choose to send; the website EOI and current in-app support form do not ask for file attachments.
- Truck, trailer and road setup records: Equipment names and registrations, truck and trailer construction, body/work types, rear couplings, axle details, unit dimensions and tare weight. Road setups link the selected truck, trailers and dollies in order with load details, complete dimensions, operating mass and the setup selected for routing. This can include concrete trucks, livestock bodies, vehicle carriers, B-doubles, road trains and other arrangements.
- Driver and fleet records: In relevant organisation workflows: driver name, phone number, licence number and expiry, status and notes where entered, fleet identifiers and equipment assignments. These are not fields in the website pilot EOI.
- Jobs and customer records: Customer and site contacts, addresses and coordinates, pickup and delivery details, assigned drivers, job references, instructions, status changes and timestamps.
- Routes and location: Address searches, route origins, destinations and stops, saved routes and places, precise GPS position, heading, speed, accuracy and time where collected, navigation progress, arrival events, off-route events and related trip records.
- Navigation audio: Navigation instruction and preview text, including road names, distances and warnings; generated audio; saved voice preferences; and local records of offline samples you confirm hearing, including the selected voice and sample/confirmation times. Instruction text can reveal trip context.
- Delivery and incident evidence: Recipient names, signatures, photographs, delivery location and time, damage notes, incident locations, descriptions, status history and other material submitted in those workflows.
- Plan, payment and administration records: Plan, seat and feature entitlements, route-request usage, subscription status, billing contact details, payment and invoice references, payment status, billing correspondence and records of administrative actions. Stripe processes payment-method and transaction information when you pay for the Services.
- Technical and device information: IP address and request information, browser or device information available to our services, session identifiers, diagnostic and security logs, error information, app preferences and push-notification tokens where enabled.
The website pilot EOI does not request vehicle registrations, precise routes, GPS location, licence documents or payment information. Avoid adding these to optional free-text fields unless they are necessary for a later enquiry we discuss with you.
Photographs and free-text reports can reveal information about other people and can contain sensitive information, such as health information about an injury. Please avoid including unnecessary personal or sensitive information. Where sensitive information is necessary, we will obtain consent or rely on another basis permitted by applicable law. A delivery signature is collected as evidence of receipt.
3. How information reaches us
We collect information directly when you register, use features, communicate with us, grant device permissions or upload material. We also receive it from your organisation and authorised users who create driver, customer, site, job, incident or delivery records.
Website pilot enquiries
The EOI asks for enough information to contact you about pilot suitability and availability. Optional fields are marked and can be left blank. Registering interest does not create an app account, confirm a pilot place or subscribe you to marketing.
The website supports two clearly labelled enquiry paths:
- Direct submission, when available: choosing Send saves the original details and a private recovery reference in this tab’s session storage before sending them to our website. We store the submitted enquiry in our Supabase database with its reference, receipt date, privacy version presented and team-email status. A saved receipt confirms this database record, separately from email delivery. A background worker passes the enquiry to the configured email-delivery service for info@socialsynergy.io. Email acceptance does not prove inbox arrival or that the team has read it. This enquiry record is not an app account.
- Prepared email: the page prepares enquiry text for you to send through your own email app. Opening or copying that text does not submit it to HeavyRoutes. Your email provider may handle a draft under its own settings and privacy practices; we receive the enquiry when you send it and it is delivered. A copy of the text is placed on your device clipboard only if you choose Copy enquiry text.
The website does not save an EOI draft on our server as you type. A request can finish after your browser’s wait ends. The saved reference supports checking and retrying the original enquiry without creating another record. Its private recovery token is used to check the receipt; the database stores a hash of that token, and status responses do not return your submitted details. Keep the reference if you need help; do not send us the private token. After a confirmed receipt is saved locally, the tab’s recovery copy contains the reference, token and receipt instead of the original form details.
Hosting and security systems also process ordinary request information. The direct-submission endpoint uses shared 15-minute limits, including a temporary identifier derived from a verified network address using a server secret. Where the address cannot be verified, requests share a conservative limit. These counters are separate from enquiry records and general hosting logs; expired counters are removed when another new enquiry is processed.
Natural navigation voice
Where natural navigation voice is available and enabled, the app sends instruction text through our authenticated speech service to OpenAI to generate an AI voice. Connected prompt preparation can send instructions before they are played. This feature sends text, not microphone recordings. The relay sends that text and fixed voice settings to OpenAI; it does not attach your HeavyRoutes account access token or separate GPS, customer or job-record fields. The instruction text itself can still reveal locations or operational context.
Natural voice is enabled in new audio settings. You can turn it off in Navigation and voice to use the phone's device voice. Device-voice availability, downloads and processing depend on the operating system and selected speech engine. Turning natural voice off does not clear previously downloaded prompts or establish deletion of processing records already held by a provider. Offline and sync provides separate controls for downloaded audio.
In-app support and optional diagnostics
Where in-app support is available, you review a request or reply and choose Send while online. Unsent support drafts and cached conversations are stored on the phone for the relevant account; saving a draft is not submission. Sent requests and replies are stored in the support service and can be followed in My requests.
Basic app diagnostics are optional and off by default. The displayed diagnostics contain app version, build, platform and operating-system version. They do not include precise location, route history, device identifiers, passwords or account access tokens. You can send a support request without adding these diagnostics. Information you type into the message yourself is still included, so keep unnecessary personal or customer details out of it.
Road or map reports use a separate workflow and can include the location and route context shown for that report. Their upload state is separate from an unsent support draft.
Some information is generated through use of the Services, including navigation events, usage counts and technical logs. Routing and mapping providers return information needed to fulfil searches and route requests. Device and notification services provide technical information needed to deliver enabled features.
You can usually browse the public website without identifying yourself. You may make a general enquiry anonymously or under a pseudonym where practicable. We need sufficient information to create an account, confirm authority, investigate a specific issue or provide operational features. If you do not provide information needed for a feature, we may be unable to provide that feature or resolve your request.
4. Location information and fleet visibility
The mobile app uses precise location for features such as positioning on a route, navigation, rerouting, detecting arrival at a job site, recording delivery or incident locations, and showing operational progress.
Foreground location may be used while viewing a route, navigating or using arrival-detection features. With background permission, active navigation can continue receiving location while the app is in the background or the phone is locked. Background navigation tracking is designed to stop when active guidance ends. Device settings, operating-system behaviour and the app version affect delivery of updates.
Location information can be associated with your account, route, job and organisation. Where the relevant features and permissions are enabled, authorised organisation users can view current or last-reported position, progress and related trip or event records. A last-reported position may remain visible after new updates stop. Operational records can also be used in the organisation's reports.
You can change location permissions in your device settings and end active guidance in the app. Denying background permission limits guidance when the app is not visible; denying location may prevent navigation and arrival features. Turning off permissions or uninstalling the app does not delete information already uploaded.
Your organisation should explain when it expects location features to be used, who can access the information and how it uses it. Contact your organisation about its workplace monitoring arrangements, and contact us about our handling of the information. Permission granted to a phone is not a substitute for any separate workplace notice or consent required by law.
5. Why we use personal information
We use personal information as reasonably needed to:
- Review pilot interest, contact you about suitability and availability, and understand the equipment and planning needs described in your enquiry.
- Create and authenticate accounts, manage invitations, permissions and organisation access, and record the terms presented and accepted.
- Provide route searches, navigation, job assignment, fleet visibility, delivery evidence, incident review and other features you or your organisation use.
- Provide support, respond to enquiries and communicate about account, billing, security and service matters.
- Administer plans, measure agreed usage, maintain business records and resolve disputes.
- Monitor reliability, investigate errors, prevent unauthorised access and misuse, and maintain or improve the Services.
- Meet legal obligations and respond to lawful requests.
Where practical, we use aggregated or de-identified information for service statistics and improvement. Information is not treated as de-identified if a person can still reasonably be identified from it.
We do not use a privacy-policy acknowledgement as consent to every possible use. If a new purpose requires consent or another notice under applicable law, we will obtain that consent or provide that notice before proceeding.
6. Who can receive information
Your organisation and operational users
Information may be available to people with access to the relevant organisation and workflow, including administrators, dispatchers, fleet managers and assigned drivers. Access depends on the type of record and available permissions. Your organisation may export or share operational records with its customers, recipients or other people under its own arrangements. It is responsible for explaining those further uses.
Private in-app support requests are available to the requesting user and authorised HeavyRoutes support personnel. Other members of the same organisation do not gain access to those private conversations merely through organisation membership. Information you independently share or forward is subject to the recipient’s own handling.
People and providers supporting HeavyRoutes
Our authorised personnel and service providers may handle information for hosting, authentication, data storage, route planning, mapping, notifications, support, security and administration. Providers receive information relevant to the functions they perform. For example:
- Supabase: Authentication, account and operational databases, submitted website pilot enquiries and delivery receipts, uploaded evidence and profile storage, and related application services.
- Vercel and Railway: Website/portal and API hosting respectively; relevant requests, application processing and technical logs.
- HERE and TomTom: Configured routing and geocoding services receive relevant addresses or coordinates and vehicle/load parameters needed to answer a request. Providers are used according to the enabled service and fallback configuration.
- OpenAI: Where natural navigation voice is used, processes the instruction or preview text and voice settings sent by our speech service to produce audio. Text can include road names, distances and warnings. Generated audio returns through our service to the app.
- PTV: Configured restriction services receive map-area or tile requests corresponding to areas being checked. This is distinct from uploading a complete job or delivery record.
- Device map services: Depending on platform and app build, Apple or Google native maps process requests needed to display maps. Builds with Mapbox enabled instead use Mapbox for map display and supported downloads. These services may receive map areas, network/device information and location-related requests according to the feature and permissions.
- Expo and device push services: Where remote notifications are enabled, notification tokens and message content are processed to deliver notifications, including through the relevant Apple or Google delivery service.
- Google and configured email-delivery services: Google hosts our email, including sender and recipient addresses, message contents and attachments in enquiries, support and other correspondence. Where direct pilot submission is enabled, the configured email-delivery service also processes the submitted enquiry to send it to our inbox.
- Stripe: Processes payments and related transactions, including relevant contact and billing details, payment-method information, transaction amounts and payment status. Its handling of information is described in the Stripe Privacy Policy.
Only providers used in your deployment or feature receive the relevant information. Independent websites, app stores and device services have their own privacy policies. Their policies do not replace our responsibility for information we handle or disclose.
Other disclosures
We may disclose information to professional advisers or relevant authorities where reasonably necessary for legal obligations, a dispute, or a permitted response to a serious threat. If the business is restructured or transferred, information may be disclosed where necessary for that transaction, subject to applicable law and appropriate confidentiality and privacy safeguards. We may also share information at your direction or with your consent.
7. Overseas handling
HeavyRoutes's application database is hosted in Japan, in the Asia Pacific region. Website and API request processing can also take place outside Australia, including in the United States for website functions. Some service providers or their authorised personnel may process or access information in additional countries. Hosting location alone does not determine all email, payment, mapping, speech, notification or support processing locations. Natural-voice processing uses OpenAI; the application database location does not establish where speech requests are processed.
Overseas locations include Japan for application hosting. Stripe describes international transfers that can include the United States and India in its Privacy Policy. Other provider processing and support locations depend on the service and provider arrangements. Contact us for information about the providers and locations relevant to your information.
We take reasonable steps required by applicable law in selecting and managing overseas recipients, including appropriate contractual and security arrangements. Contact us for further information about the arrangements relevant to your information. This policy does not ask you to waive protections that apply to overseas disclosure.
8. Cookies, local storage and communications
Our Cookies Policy explains cookies and browser storage on the public website, its current tracking inventory and your browser choices.
The public website includes the pilot EOI, email contact links and illustrated demonstrations. The enquiry paths are explained in section 3. Website help searches, topic choices and demo selections run in the page; we do not send those search terms or choices to an audience-analytics service. Ordinary hosting and security logs may still be generated when you browse or submit a request.
Before you choose Send, the public pilot form keeps working entries in the page. Direct submission then uses this tab’s session storage for recovery as described in section 3. It can survive a reload; closing the tab or clearing browser data may remove it, and browser session restoration can retain it longer. Clear this tab’s enquiry copy removes only that browser record. It does not cancel an earlier request, withdraw interest or delete server, email, log or backup copies. A failed browser save prevents a new direct submission until the original can be saved and checked; the prepared-email option remains available. Your browser or email provider may separately retain autofill information, restored pages or mail drafts according to your settings.
The signed-in portal uses session cookies or related browser storage to maintain authentication. The mobile app stores session information, preferences, downloaded or cached information and queued actions on the device to support its features. This includes saved help preferences, unsent support/report drafts and cached support conversations where those features are used. Truck setup and new-trip forms do not store recoverable drafts; unfinished entries are discarded when you close the setup or start a new trip. Queued road reports and other offline entries may be synchronised when connectivity returns. In-app support drafts require you to send them; simply saving a draft does not queue it for automatic delivery. Shared devices should be managed so other people cannot access account or operational information.
Downloaded natural prompts and their local records are stored for the original service, account and workspace. Audio preferences are stored for the account and service on the phone. Confirmed offline-voice samples have a separate local record; a recent confirmation describes what you confirmed hearing at that time and does not guarantee later playback. Older shared audio or records whose owner cannot be verified are retained without being adopted for another account. Their explicit clearance controls explain when removal affects every account on that phone. Clearing local audio does not establish deletion of provider-side processing records.
During verified local account removal, a temporary navigation cleanup record stores the original service and account, trip index records, and file names, sizes and checksums. It allows interrupted removal to resume while new, changed or unidentified trip records remain held for review. The cleanup record is removed after the identified navigation files and indexes are removed. This does not establish deletion of server, exported or backup copies.
Website analytics and advertising: We do not use website audience-analytics tools or advertising tracking pixels. We use operational logs, usage records and authentication storage as described in this policy to run and secure the Services. Stripe's payment services may use their own cookies or similar technologies for payment functionality and security, as described in the Stripe Privacy Policy.
Profile edit recovery keeps the original name, phone number, photo reference, optional owned photo copy and save receipt on the device for the original service and account. Reopening reads this recovery record without automatically submitting it. Clear local profile change removes its personal recovery details and owned photo copy after confirmation, while retaining a minimal cleared reference to prevent a delayed response restoring them. It does not cancel or undo a server request. Removing a photo reference from your profile does not establish deletion of uploaded files, processing records or backups; server retention and account deletion remain subject to section 9.
You can use your browser's cookie controls, although blocking required session storage can prevent sign-in. Device settings control permissions for location, camera, photo access and notifications. Denying a permission may limit the related feature. Push notifications may display information on a lock screen, depending on your device settings.
If we send promotional emails or messages, we will do so with the consent or other permission required by law, identify ourselves and provide a usable unsubscribe method. You can also contact info@socialsynergy.io to opt out. An enquiry or account registration does not automatically enrol you in unrelated marketing. Necessary service, security and billing messages may continue after a marketing opt-out.
9. Security and retention
We take reasonable steps appropriate to the information and risks to protect personal information against misuse, interference, loss and unauthorised access, modification or disclosure. The Services use authentication and organisation/role access controls, and uploaded evidence is held in access-controlled storage. No internet service or device can be guaranteed completely secure.
We retain personal information associated with your account while the account remains active, only for as long as needed for the purposes described in this policy.
Original job requests and acceptance receipts can remain after the job itself is deleted, so the original account can check an interrupted update without submitting it again. These records can include the original job and route references, reported time and location, notes, proof references and checked route details. Deleting a job or clearing its local update does not establish deletion of these server records or uploaded files. They remain subject to the account-deletion commitment and limited legal-retention exception below. Access to an original receipt does not restore a deleted job or provide access to another account's receipt.
Account deletion: When you delete your HeavyRoutes account, we delete the personal information associated with that account seven days after account deletion. This includes account details, location and trip records, associated delivery and incident evidence, and account-related correspondence and logs held by us. The seven-day period also applies to copies held on our behalf, including stored files and backups. An organisation's account deletion applies to the personal information held for that organisation's account.
The exception is information we are required by law to retain, such as particular tax or transaction records. We retain only the information required, restrict its use to the relevant legal purpose, and delete it when that requirement ends. This exception does not authorise keeping unrelated location or delivery information longer.
Stripe may retain certain payment records to meet its own legal obligations. Deleting your HeavyRoutes account does not override those obligations or delete a separate account you hold directly with Stripe. See Stripe's explanation of data deletion and legal retention.
For pilot enquiries and other correspondence from people without an account, we keep the information only while it is needed to handle the enquiry and related follow-up, unless law requires retention. We retain a minimal reference and withdrawal receipt to prevent a retry from recreating removed enquiry details; enquiry deletion also requires review of email, log and backup copies. You can ask us to stop pilot follow-up or delete your EOI by emailing info@socialsynergy.io. We will assess and respond to a deletion request as described in section 10. Prepared drafts in your own email app or clipboard remain under your control and your provider’s settings. Copies that an organisation or another recipient has independently exported are subject to that recipient's own responsibilities and privacy practices.
Ending navigation, signing out, uninstalling the app or cancelling a subscription does not by itself delete your account or start the seven-day period. Contact us using the details below if you need help deleting your account. Request any information you need before account deletion; an export request does not automatically extend the deletion period.
If a data incident occurs, we will assess it and notify affected people and regulators where required by applicable law.
10. Access, correction and deletion requests
You can update information through available profile and organisation settings. You can also contact info@socialsynergy.io to request access to or correction of personal information we hold about you, request account closure or deletion, withdraw pilot interest, or ask about our use of your information.
We may ask for reasonable evidence of identity or authority before providing information or changing records. Please describe the information or account concerned. Do not send unnecessary identity documents with an initial request.
We will respond within a reasonable period and within any deadline required by law. Access requests and correction requests are assessed under applicable law. If a permitted charge for providing access is proposed, we will explain it in advance. We do not charge to lodge an access request or to request correction. If we decline a request in whole or part, we will explain the reason, unless legally prevented, and available complaint options.
Where a request concerns records managed for an organisation, we may coordinate with that organisation or direct you to it for matters it controls. This does not prevent you from making a request to us about information we hold. Account deletion follows the seven-day period in section 9, subject to the specific legal retention exception explained there. We will explain any applicable exception and the action we take.
Removing a user's organisation access is different from deleting that user's account. Deleting a user's account does not delete other users' accounts or unrelated organisation information. Personal information associated with the deleted account remains subject to section 9. Uninstalling the app does not make a deletion request or cancel an organisation's subscription.
11. Privacy complaints
Contact info@socialsynergy.io with the details of your concern and the outcome you seek. We will acknowledge the complaint, investigate the relevant circumstances and aim to provide a substantive response within 30 days. If more time is needed, we will explain why and provide an update.
If you are not satisfied, or we have not responded within 30 days, you may contact the Office of the Australian Information Commissioner, where the matter falls within its jurisdiction. Information about lodging a complaint is available at OAIC privacy complaints. Other regulators or remedies may apply depending on the issue and your location.
12. Children and changes to this policy
HeavyRoutes's operational services are intended for people using them in a transport or business context and are not directed at children. Contact us if you believe a child has provided personal information without appropriate authority so we can assess the circumstances and take suitable action.
We will publish updates to this policy with a new effective date and version. We will take reasonable steps to notify affected users about material changes. An update does not by itself authorise a new use for which consent is required. You can request a copy of this policy, including in another accessible format, using the contact details above.