Privacy Policy & Data Security Schema
1.0 Data Collection Boundaries & Scope
EcoRoute processes telemetry, logistical, and organizational information strictly required to compute Greenhouse Gas (GHG) Protocol emissions balances. We apply data minimization principles to ensure only critical parameters are stored:
- Identity Infrastructure: First name, surname, email address, company name, and 2-character country code (ISO parameters) registered at signup.
- Telemetry Logs Parameters: Terrestrial vehicle mileage, flight sector records (IATA airport codes), shipping cargo weights, utility kilowatt-hours (kWh), and stationary fuel values.
- Billing Meta-Tokens: Gateway customer codes and single-use webhook tracking event keys handled natively over encrypted Paystack channels. We do not store raw credit card numbers.
2.0 Multi-Jurisdiction Legal Compliance (POPIA / GDPR)
Our data protection architecture operates securely across international administrative regulatory frameworks:
• POPIA Compliance: In accordance with the Protection of Personal Information Act of South Africa, we act as the responsible party securing all corporate profile information and operational logs.
• GDPR Compliance: For European operations, calculations matching international IEA, DEFRA, and Ember Climate matrices handle telemetry inputs without compiling unnecessary personally identifiable information (PII).
3.0 Data Retention & Automatic 90-Day Archiving Rule
We preserve your active corporate auditing logs exclusively while your licensing terms remain valid. To protect company boundaries upon subscription termination, the following lifecycle rule triggers automatically:
The 90-Day Grace Window: When a user subscription status transitions to cancelled, all historical emissions logs, custom vehicle registries, and API consumption traces are kept fully available and active for exactly 90 days. If the user does not reactivate their premium plan within this window, an automated background scheduler moves the rows to a disconnected database archive table and permanently purges active instances.
4.0 Information Sharing & B2B Cryptographic Safety
EcoRoute does not share, rent, trade, or sell historical environmental logs, delivery manifests, or corporate identity metadata to third-party advertising networks or external data brokers.
Programmatic interactions over our public REST channels are secured via isolated Bearer Token Signatures (`ecoroute_live_...`). These tokens are under the direct control of the organization administrator and can be rotated instantly from the API management console if an environment compromise is detected.