Privacy Policy
Effective 26 August 2026. Last updated 26 August 2026.
This tool asks for write access to the calendar your business runs on. You are entitled to know exactly what it takes, what it keeps, and what it can never see. This page is written to be checked against the product, not to be skimmed.
Who we are
Routeline ("the Service") is operated by an independent software developer based in Singapore ("we", "us"). We are the point of contact for anything on this page: privacy@getrouteline.com. Under Singapore's Personal Data Protection Act, that address reaches the person responsible for data protection here.
The short version
- We read your Jobber jobs, visits, clients' names and tags, and your team members' names.
- We store only what is needed to show you a change and to undo it afterwards.
- We never receive your clients' email addresses, phone numbers, street addresses, invoices, payments, quotes, or job photos.
- We do not sell anything to anyone, and we run no advertising or third-party trackers.
- Disconnecting deletes your data. It is a real button, and it really deletes.
What we access in Jobber
When you connect, Jobber shows you the exact permissions we ask for and you approve them. We use them for one thing each:
| What we read or write | Why |
|---|---|
| Jobs — title, job number, type, recurrence rule, status | To list what could change and to work out the new schedule |
| Visits — start and end times, who is assigned, whether completed | To show you the before and after dates, and to write the change |
| Clients — name and tags only | So you can filter by tag and recognise the rows in the preview |
| Properties — city, state/province and country only | So you can see that the region you are changing matches what you intended |
| Team members — name and ID | So you can filter by who is assigned, and reassign work |
| Your own user record — ID and time zone | Every date on screen is computed in your Jobber time zone. Without it we refuse to plan rather than guess. |
| Write: visit times, visit assignment, job recurrence | Only after you have seen the full list and pressed confirm |
We do not request access to invoicing, quotes, requests, expenses, payments, time sheets, or client contact details. Jobber enforces this on its side: even if our code asked for them, the permissions you granted would refuse.
What we store, and for how long
| Stored | Contains | Kept until |
|---|---|---|
| Your connection | Jobber account ID and name, your time zone, your plan, and your Jobber access and refresh tokens encrypted with AES-GCM before they touch the database | You disconnect |
| Run history | For each batch you ran: the list of changes (job title, client name, before and after dates) and a snapshot of the affected visit times taken immediately before writing | You disconnect. The snapshot is what Undo restores from — it is the reason this data exists at all |
| Usage events | Counts, durations and feature names — "previewed 42 jobs", "execute failed, rate limited". Never client names, job titles or dates | Kept, but detached from your account when you disconnect, so the totals survive without pointing at anyone |
| Waitlist email | An email address, only if you typed one into the pricing box | You disconnect, or you ask us to remove it |
| Session cookie | A signed reference to your account ID. HttpOnly, Secure, SameSite=Lax. Not an analytics or advertising cookie, and we set no others | You sign out or disconnect |
Where it lives
The Service runs on Cloudflare Workers and stores data in Cloudflare D1. Cloudflare is our only infrastructure provider and our only sub-processor besides Jobber itself. We use no analytics vendor, no session recorder, no advertising network, and no external fonts or scripts — the pages here make no requests to any third-party host.
Cloudflare operates globally and may process data outside Singapore. Your Jobber data continues to live in Jobber; we hold the subset described above.
Your clients' data
Some of what we hold is personal data belonging to your customers — their names, and when their appointments are. For that data you are the controller and we are your processor: we act only on your instructions, we do not use it for any purpose of our own, we do not sell or share it, and we delete it when you disconnect. If you need a written data processing agreement, ask and we will sign one.
Deleting your data
Press Disconnect in the top bar. It does three things, in this order: tells Jobber to revoke our access, deletes your encrypted tokens, and deletes your run history. The only thing it does not do is change your schedule — work you already applied stays applied, because it is yours.
Because Undo restores from the stored snapshot, disconnecting also ends your ability to undo past runs. That is a real trade-off and we would rather say it here than surprise you.
You can also disconnect from Jobber's side, under Apps. Either way, or if you would rather just ask, write to privacy@getrouteline.com and we will confirm deletion within 30 days.
Your rights
Under the PDPA in Singapore, and under the GDPR if you are in the UK or EEA, you may ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, or withdraw your consent by disconnecting. Withdrawing consent stops the Service from working; it does not undo changes already written to your Jobber account. Send any of these requests to privacy@getrouteline.com.
If you are unhappy with how we have handled a request, you may complain to Singapore's Personal Data Protection Commission, or to your local supervisory authority in the EEA or UK.
Children
The Service is a business tool sold to businesses. It is not directed at children and we do not knowingly collect data from anyone under 16.
Security
Tokens are encrypted at rest with AES-GCM using a key held outside the database. All traffic is HTTPS. Sessions are signed and HttpOnly. We keep the permission set as small as the product allows, which is the strongest control available here: data we never fetch cannot leak.
No system is perfect. If you find a security problem, please write to security@getrouteline.com — we would rather hear it from you.
Changes
If this policy changes in a way that affects what we collect or who we share it with, we will change the date at the top and email connected accounts before it takes effect.
Routeline is an independent tool. It is not built by, affiliated with, or endorsed by Jobber Software Inc. "Jobber" is their trademark, used here only to say what this connects to.