Effective August 3, 2026
Privacy Policy
Router.taxi (“Router,” “we,” “us,” or “our”) is a Belweave product that compares transportation options and lets people and their authorized agents continue to provider handoff or supported commerce flows. This policy explains what Router handles, why, when it reaches other services, and where our control ends.
1. Scope and limits of this policy
This policy applies to Router's websites and PWA, account and developer surfaces, REST API, MCP server, messaging agent, native clients, private Android provider vaults, and related support. It does not govern a ride provider, financial provider, messaging carrier, agent application, app store, linked site, or other third party. Their policies apply to their processing. A link, deep link, integration, or displayed mark does not make Router responsible for that party.
2. Information we collect
Account and contact information
Clerk processes sign-up, authentication, session, name, email, profile, and account identifiers. If you connect Messages, we process the phone number or messaging handle, Linq chat identifier, service type, link status, and delivery identifiers needed to associate the conversation with your Router account.
During the invite-only beta, we also process access-request email addresses, Clerk user identifiers, display names, request sources and timestamps, review status, and internal review notes. We use this information to prevent duplicate requests, assess and provision beta capacity, contact applicants, and enforce access decisions. Creating or authenticating a Clerk identity does not itself grant access.
Routes, quotes, and trip activity
We process pickup and destination text or coordinates, route metrics, requested time, budget, accessibility or product preferences, provider options, live and estimated prices, selected tiers, handoff links, attempted actions, provider outcomes, timestamps, and trip history. We may retain sanitized screenshots or structured evidence from quote and checkout attempts when needed to show what occurred, investigate a failure, or support an authorized transaction.
Device location is optional and requested only after you invoke a location feature. You can enter addresses instead. Precise location, routes, and inferred travel patterns may be sensitive information.
Provider connections and private Android vaults
When you connect a supported ride account, Router may store encrypted access or refresh tokens, scopes, external account identifiers, expirations, and connection events. For providers connected through a private Android vault, the provider and Google app sessions reside in an isolated Box-hosted Android environment assigned to your Router account. We store vault, device, template, lifecycle, health, and job identifiers in order to start, stop, restore, stream, and use that environment at your direction.
Sign-in fields, one-time codes, and the streamed app interface pass through infrastructure needed to operate the remote device. Router is designed not to ask you to submit provider passwords in ordinary Router web forms, but we cannot represent that remote-computing operators, provider apps, operating-system services, network services, or a compromised endpoint are technically incapable of processing what appears in or is entered into the streamed session.
Messages and agent requests
Linq processes inbound and outbound iMessage, RCS, or SMS content and delivery metadata. Router stores the linked handle, conversation state, recent request context, webhook processing state, and the information needed to answer and prevent duplicate actions. If you use the API or MCP server, we process the request body, scopes, and results associated with the account whose credential was used.
For natural-language ride requests, Router may send the message text to OpenAI to extract a structured pickup, destination, and budget. Router requests that this OpenAI response not be stored by the API and uses deterministic application logic to validate prices and actions. OpenAI may still process limited request and abuse-monitoring data under its applicable terms and policies.
When a private Android quote screen stalls, Router may send OpenAI a reduced screenshot and sanitized accessibility text to classify a small set of recovery states. Router blocks this feature on sign-in, password, one-time-code, recovery-code, human-verification, and payment screens; requests non-storage by the API; and does not give OpenAI a device credential or authority to tap arbitrary controls. A Router worker validates any suggested recovery against its allowlisted, deterministic actions. Route labels and visible provider information may still appear in an eligible screenshot.
Commerce and payment information
Prava processes approval sessions, payment mandates, and one-time payment credentials. Router may process and retain the purchase description, authorized ceiling, currency, provider, session and order identifiers, transaction reference, approval status, checkout result, and sanitized evidence. When an authorized checkout requires a one-time credential, Router may transmit that credential to the assigned Android executor for transient entry into the provider app. Router is designed not to log or display full credential values, but the payment service, executor, provider, and their infrastructure necessarily process data needed for the attempted transaction.
Developer, device, and operational data
Clerk creates and verifies scoped bearer API keys; Router stores key identifiers, prefixes, scopes, creation and last-use times, rate-limit counters, and audit events. We also process pseudonymized IP hashes, user-agent strings, request paths and methods, Vercel request identifiers, timestamps, device capabilities and push tokens, job results, error codes, diagnostic logs, security events, and support communications. Never place secrets in route labels, agent prompts, or support messages.
Browser and PWA storage
Router and Clerk use cookies or similar storage for authentication, fraud prevention, preferences, and core operation. The PWA may store recent route labels and app-shell or map assets in local storage and browser caches so the interface remains useful offline. Live provider quotes and active comparisons are session-only and are not restored after a reload. Anyone with access to your browser profile or unlocked device may be able to see locally stored route history. You can clear saved routes in Router or clear all site data through browser or operating-system settings.
3. How we obtain and use information
We use the categories above to:
- authenticate users, devices, agents, and scoped API requests;
- resolve routes and compare, refresh, rank, and present prices;
- maintain provider connections and user-isolated device state;
- send messages and execute actions the user or authorized agent requests;
- create approvals, attempt checkout, and produce transaction evidence;
- prevent misuse, enforce limits, debug failures, and secure Router;
- provide support and improve reliability, accessibility, and UX; and
- meet legal obligations and protect users, Router, Belweave, and others.
Depending on the context and applicable law, our legal bases may include performing a contract, taking steps you request, consent, legitimate interests in operating and securing the service, and legal obligations. You may withdraw consent where processing depends on it, without affecting earlier lawful processing.
4. When information is disclosed
We disclose information only as reasonably needed for the purposes described here, including to:
- Clerk for authentication and developer credentials; Neon for application data; Vercel for hosting, delivery, and logs; and Box or other approved device infrastructure for private Android vaults;
- Linq and telecommunications networks for messaging, OpenAI for optional request interpretation, and Esri, OpenStreetMap/OSRM, and map-tile providers for address and route functions;
- Prava and relevant payment networks for authorized commerce, and ride providers for live pricing, handoff, or checkout;
- an agent or application you authorize with your API key, Clerk session, device enrollment, or messaging account;
- professional advisers, authorities, or counterparties when reasonably necessary for law, safety, fraud prevention, a dispute, or a corporate transaction, subject to appropriate safeguards.
Address lookup and route requests made directly from the web app may expose your IP address and the submitted location to Esri or OSRM. Opening a provider handoff may send pickup, destination, locale, product preference, and referral parameters to that provider.
5. Sale, advertising, and aggregation
Router does not sell personal information and does not share it for cross-context behavioral advertising as those terms are commonly defined in U.S. state privacy laws. We do not use third-party ad trackers. We may create aggregated or de-identified statistics that cannot reasonably be linked to a person and use or disclose them for operations, research, and product improvement. We will not attempt to re-identify data treated as de-identified except to test safeguards.
6. Retention and deletion
Retention depends on purpose, sensitivity, account status, technical constraints, contractual requirements, and law. We retain account and connection records while the account or feature is active; trip, messaging, audit, payment-status, and security records for as long as reasonably needed to provide support, prevent abuse, document authorized actions, or resolve disputes; and backups and provider logs until they expire through ordinary cycles. A deletion request may not immediately erase data from backups, third-party systems, or records we must keep for legal, fraud-prevention, security, or dispute purposes.
Disconnecting a provider removes or disables Router's active connection, but does not delete the provider's own account or data. Stopping a private Android vault preserves its state for later use; it is not the same as deleting the vault. Contact us if you want the associated Router-controlled vault record scheduled for deletion.
7. Security and its limitations
We use measures intended to protect data, including TLS in transit, restricted production access, scoped and revocable credentials, hashed API and handoff secrets, encryption for stored provider tokens and sensitive URLs, isolated Android environments, webhook signature verification, rate limits, and audit records. Controls vary by service and development stage. No product, encryption method, remote device, mobile network, browser, or third-party integration is completely secure. We cannot guarantee that information will never be intercepted, accessed, corrupted, lost, or disclosed.
You help protect your information by securing your phone, email, provider accounts, Clerk session, and API keys; limiting agent scopes; reviewing approvals; and promptly revoking anything exposed. A bearer API key generally authorizes the holder to act within its scopes.
8. Your privacy choices and rights
You can decline optional location access, clear PWA storage, revoke API keys, unlink Messages, disconnect supported providers, stop using a private Android vault, or complete a ride directly with a provider. Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, objection, or an appeal, and to receive information about disclosures. We will verify requests and may deny or limit them where law permits. We will not discriminate against you for exercising an applicable right.
An authorized agent may submit a request where permitted, but we may require proof of authority and direct identity confirmation. Because Router currently does not sell personal information or use it for cross-context behavioral advertising, an opt-out signal such as GPC does not change those practices. If they change, we will update this policy and honor legally required controls.
9. U.S. focus, children, and international processing
Router currently focuses on the United States and is not directed to children under 13. We do not knowingly collect personal information from a child under 13; contact us if you believe that occurred. Ride and payment providers may impose a higher minimum age. Our providers and users may process information in the United States and other countries whose laws differ from yours. Where required, we use an appropriate legal mechanism for cross-border transfers.
10. Changes and contact
We may update this policy as Router changes. We will post the revised policy and effective date and provide additional notice when required. Privacy questions and requests can be sent to privacy@router.taxi. General support is available at support@router.taxi.
