Legal
Privacy Policy
Rovia App is dispatch software for chauffeur operators. This explains what we hold, why, who else processes it, and how to ask for a copy or its removal.
Last updated 14 September 2026
Two different relationships
Rovia App is used by chauffeur and ground transport operators to run their businesses. That puts us in two positions at once, and which one applies changes who you should ask about your data.
- The operator is our customer. Their account, their team, their company details and their use of the product are data we hold on our own behalf. Ask us about it.
- Passengers, customers and drivers are the operator’s. When you book a ride with a company that uses Rovia App, that company decides what to collect and how long to keep it. We hold it on their behalf and act on their instructions. Ask them first — and if you cannot reach them, write to us and we will help.
What we hold
We process the following to provide the service and administer accounts. Operator records are associated with the relevant organization.
- Account and sign-in. Email address, password credentials held by our authentication provider, and any second-factor enrolment. Submitted credentials are processed for authentication through Supabase Auth. Google sign-in, when chosen, also provides identity information such as name and email.
- Business details. Company name, address, phone, email, logo, service locations, rate cards and settings.
- Customers and passengers. Name, email, phone, company, notes the operator writes, and the pickup and drop-off addresses of their journeys.
- Drivers. Name, contact details, licence details, home address, emergency contact, compliance dates, and documents the operator uploads.
- Trips and dispatch. Journey times, addresses, vehicle and driver assignment, status changes, and — where the operator has switched it on and the driver has allowed it — the driver’s live location during an active job.
- Quotes, reservations and money records. Inquiry details, amounts, dates, manual-payment method, references, invoices, refunds, driver payouts and cancellation settlements.
- Agreement records. When a customer accepts an operator’s terms or cancellation policy, we record who accepted, when, which version of the policy they saw, and the IP address and browser user-agent of the acceptance. That last part exists so the acceptance can be evidenced later; it is visible to the operator and is never shown on a public page.
- Activity log. A record of significant actions taken inside an account — who changed what, and when.
- Support and security. Support correspondence, feedback, incident records and hosting/authentication logs, which may include request times, IP addresses and browser information.
Payments during the restricted pilot
Passenger card payment collection and new SaaS subscription charges are unavailable during the restricted pilot. We keep supported invoice/manual-payment metadata and historical payment or refund records. Existing Stripe references and outcomes may remain for managing prior obligations. Please do not send card numbers through quote forms, notes or support messages.
Hosted and embedded public quote forms
These forms send inquiry details to the named transportation operator using Rovia App software. Rovia App is not the transportation provider. The form links to this policy and, when configured, the operator's HTTPS privacy-policy URL. The operator is responsible for its collection notice and handling of passenger/customer information.
Why we hold it
- To provide the product the operator signed up for.
- To send transactional email — confirmations, reminders, invoices, team invitations.
- To keep an accounting and audit record the operator, their bookkeeper and their tax authority can rely on.
- To keep evidence of what a customer agreed to, and when.
- To secure accounts and investigate misuse.
We do not sell personal data. We do not use it for advertising. We do not use it to train machine-learning models.
Who else processes it
Service providers and optional integrations process information for the purposes below. Optional integrations receive information when used, not simply because an account exists.
- Supabase — database, authentication and file storage. The Production project is hosted in the United States (AWS
us-east-1); this is not a promise that every provider's processing or support access occurs only in that region. - Vercel — application hosting, content delivery and runtime logs.
- Stripe — existing connected-account, payment and refund records where applicable. New passenger card collection and SaaS charges are disabled during the pilot.
- Resend — sending transactional email.
- Google Maps Platform — optional address lookup and journey routing, using address/place and route information needed for the requested lookup.
- Google Calendar — only if the operator connects it. Rovia App writes trips out to the calendar they choose and reads calendar-list metadata needed to select it; it does not import calendar events as trips. Disconnecting removes the active connection and stored credential from the application.
- Google sign-in — optional authentication through Google and Supabase. Google processes the sign-in request and supplies the permitted identity information.
SMS is not active during this restricted pilot. Twilio support is not a pilot SMS service.
Cookies and functional storage
During the restricted pilot, nonessential tracking is disabled: Rovia App sets no advertising, analytics or tracking cookies and does not capture marketing attribution or queue/send advertising conversions. Functional storage supports sign-in and operation. Web fonts are served from our own domain. This includes:
- Session cookies set by our authentication provider, which are what keep you signed in.
- A preference cookie remembering which company you last worked in, if you belong to more than one. It is a preference only and grants no access on its own.
- Functional preferences and device storage for remembered sessions, recent authentication and, when used, the driver's offline workflow and queued updates. Shared devices should be signed out and handled according to the operator's security rules.
How long we keep it
During an active account we retain information reasonably necessary to provide Rovia App. At termination, contact us for supported export and closure/deletion requests. Records may be retained where required or reasonably necessary for financial, security, fraud, dispute, audit or legal purposes. Financial and agreement records have retention safeguards; routine deletion is not available for every record.
Authentication access, sessions and integrations are handled through supported closure and security procedures. Organization closure is not the same as deleting a shared user account or immediately invalidating every issued access token.
Retention depends on the record's purpose and applicable obligations. Contact us for an assessment of a particular record or request. We do not promise complete immediate deletion of every historical record, free-text reference or document.
Asking for your data, or its removal
If you booked a ride with a company that uses Rovia App, that company holds your details. Ask them, and they can correct or remove them. If you cannot reach them, write to us at the address below and we will do what we can to help.
Operators can request supported anonymization of customer or driver fields and related link revocation. This does not guarantee removal from every historical document, financial record, denormalized reference or free-text field; requests need review.
Supported exports cover bookings, the customer list, payments, refunds, cancellation settlements and driver payouts as spreadsheets, subject to permissions, date ranges and row limits. They can be requested before or at closure when reasonably available. Invoices are readable and printable but have no dedicated spreadsheet export.
Depending on where you live you may have rights over your personal data under local law. We will handle any request we receive on its merits and tell you plainly what we can and cannot do. We do not claim certification under any particular privacy regime, and we would rather be accurate than impressive.
Security
Rovia App uses server-side authorization, tenant-scoped database controls, role permissions, private document storage and scoped bearer links. MFA infrastructure supports enforcement for required privileged roles when an organization policy is activated. Operators are responsible for appropriate access assignments and protecting private links.
Recovery capability is partial, not a guaranteed full database/Auth restore. We do not guarantee complete disaster recovery, a maximum data-loss window or a recovery time.
No system is perfect and we will not claim otherwise. If you believe you have found a security problem, please write to us.
Children
Rovia App is business software and is not directed at children. We do not knowingly collect data from anyone under 16 except as a passenger name entered by an operator arranging their travel.
Changes
If we change this policy we will change the date at the top. If a change materially affects operators, we will tell them by email.
Contact
Rovia App
20540 Carrey Rd
Walnut, CA 91789
United States
Write to hello@roviaapp.com for privacy inquiries, supported exports, correction/deletion requests, security concerns or account recovery.