Legal

RouteMe Privacy Policy

1. Introduction

RouteMe, Inc. (“RouteMe,” “we,” “us,” or “our”) provides a browser-based indoor navigation and wayfinding platform used by hospitals, clinics, campuses, and other facilities (“Venues”). This Privacy Policy explains what information we collect, how we use and share it, and the choices and rights available to you when you use our website (routeme.ai), our web-based navigation application, our Partner API, and related services (collectively, the “Services”).

A core design principle of RouteMe is data minimization. Because the Services run in your web browser without a downloaded app and without proprietary tracking hardware installed in facilities, we are able to provide wayfinding while collecting substantially less information than many navigation products. In many deployments, you can receive a complete route without providing us any information about who you are.

This Policy applies to information we handle as a business for our own purposes. Where we process information on behalf of a healthcare Venue as its service provider or HIPAA business associate, additional terms apply — see Section 4.

2. Information We Collect

What we collect depends on how you use the Services.

2.1 Information You Provide Directly

2.2 Information Collected Automatically

2.3 Information Received from Third Parties

2.4 Information We Do Not Collect

Unless described above or required for a specific feature you choose to use, RouteMe does not:

3. How RouteMe Navigation Works

RouteMe does not use your location to provide indoor directions. Routes are delivered as pre-produced, edited route videos with visual guidance overlays that show the path from a facility entry point to your selected destination.

4. Health Information and HIPAA

Many RouteMe Venues are healthcare providers. The fact that you navigated to, or had an appointment at, a particular department could reveal sensitive information. We treat this category of data with heightened care.

5. How We Use Information

We use the information described above to:

  1. Provide the Services — resolve your selected destination, display the corresponding route video and directions, show optional parking and arrival maps where offered, and operate integrations you have authorized;
  2. Operate and administer deployments — authenticate administrative and API users, manage Venue configurations, measure usage of the Services (such as route and user counts, in aggregated and anonymized form) for Venue reporting and billing, and provide customer support;
  3. Maintain safety and security — detect, investigate, and prevent fraud, abuse, unauthorized access, and violations of our Terms; enforce rate limits; and protect the integrity of the Services;
  4. Improve the Services — analyze usage patterns (in aggregated or de-identified form wherever feasible) to improve routing quality, identify facility data errors (such as frequently abandoned routes suggesting an outdated map), and develop new features. Appointment data received through portal integrations is excluded from this purpose: it is used solely to select your route destination and is not used for analytics, telemetry, or product improvement;
  5. Communicate with you — respond to inquiries, provide service announcements, and, for business contacts who have opted in where required, send information about our products;
  6. Comply with law — meet legal, regulatory, and contractual obligations, including obligations under BAAs with healthcare Venues.

We do not use personal information for automated decision-making that produces legal or similarly significant effects about you.

6. How We Share Information

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We share information only in the following circumstances:

  1. With the Venue you are navigating. Venues receive aggregated, anonymized analytics and usage overviews about the use of RouteMe in their facilities (for example, most-requested destinations, route volumes, user counts, and peak usage times) to improve wayfinding and facility operations and to support billing under their agreements with us. Where a Venue is the HIPAA covered entity for whom we process PHI, disclosures to that Venue are governed by the applicable BAA.
  2. With service providers. We use vetted vendors to operate the Services — such as cloud hosting and infrastructure providers, error monitoring, analytics, and customer support tooling. Service providers may access information only to perform services for us, under contractual confidentiality and data-protection obligations, and (where PHI is involved) under subcontractor BAAs.
  3. With third parties at your direction. When you authorize an integration (such as a patient portal), information flows between RouteMe and that third party as you have directed through the applicable consent flow.
  4. For legal reasons. We may disclose information if we believe in good faith that disclosure is required by law, subpoena, or legal process; necessary to protect the rights, property, or safety of RouteMe, our users, or the public; or necessary to detect or prevent fraud or security issues. Where permitted, we will attempt to notify affected Venues or users of legal demands for their information.
  5. In corporate transactions. If RouteMe is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to this Policy's commitments and, for PHI, the requirements of applicable BAAs and HIPAA.
  6. Aggregated and de-identified data. We may use and share information that has been aggregated, anonymized, or de-identified such that it can no longer reasonably identify you or any Venue's confidential information, including publicly and to demonstrate the Services' value to prospective Venues. We commit not to attempt to re-identify de-identified data. Appointment data received through portal integrations is discarded after route resolution and is not incorporated into aggregated statistics.

7. Data Retention

We retain information only as long as necessary for the purposes described in this Policy, and our retention practices reflect our data-minimization design:

When retention periods end, we delete or irreversibly de-identify the information.

8. Cookies and Similar Technologies

The Services use a limited set of cookies and browser storage technologies:

We do not use advertising or cross-site tracking cookies. You can control cookies through your browser settings; blocking strictly necessary cookies may prevent the Services from functioning. Where required by applicable law, we present a consent mechanism for non-essential cookies. The Services do not currently respond to browser “Do Not Track” signals, but we honor Global Privacy Control (“GPC”) signals where applicable law requires.

9. Data Security

We implement administrative, technical, and physical safeguards designed to protect information against unauthorized access, alteration, disclosure, or destruction, including:

No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify affected parties and regulators as required by applicable law and, for PHI, in accordance with the HIPAA Breach Notification Rule and applicable BAAs. Suspected vulnerabilities may be reported to legal@routeme.ai.

10. Your Privacy Rights and Choices

10.1 Choices Available to Everyone

10.2 Rights Under U.S. State Privacy Laws

Depending on your state of residence (including California, Colorado, Connecticut, Virginia, Texas, and other states with comprehensive privacy laws), you may have the right to:

To exercise these rights, contact us as described in Section 15. We will verify your request using reasonable means and respond within the timeframe required by applicable law. You may designate an authorized agent to submit requests on your behalf where permitted. If we decline a request, you may appeal by replying to our response, and we will explain the appeal outcome; you may also contact your state Attorney General.

10.3 GDPR / UK GDPR (If Applicable)

If you are in the European Economic Area, United Kingdom, or Switzerland, and to the extent the GDPR or UK GDPR applies to our processing:

11. International Users

The Services are operated from the United States, and information is processed and stored in the United States and other jurisdictions where our service providers operate. Privacy laws in these jurisdictions may differ from those in your home jurisdiction. By using the Services, you understand that your information will be processed as described in this Policy and subject to the safeguards described above.

12. Children's Privacy

The Services are wayfinding tools intended for general audiences and are not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided personal information to us, please contact us and we will delete it. Children visiting a Venue may follow directions displayed on a parent's or guardian's device without providing any information to RouteMe.

13. Third-Party Links and Services

The Services may contain links to Venue websites, patient portals, and other third-party properties, and may embed third-party services such as Google Maps for the optional parking and arrival feature. This Policy does not apply to third-party services, and we are not responsible for their privacy practices. Google's handling of information in connection with embedded maps, including device location you choose to share, is governed by Google's privacy policy. We encourage you to review the privacy policies of any third-party service you use, including your patient portal provider, whose handling of your health information is governed by its own policies and by your healthcare provider's notices.

14. Changes to This Policy

We may update this Policy from time to time. When we do, we will revise the “Last Updated” date above and, for material changes, provide additional notice within the Services or by other reasonable means (and obtain consent where required by law). Your continued use of the Services after an update constitutes acceptance of the revised Policy, except where consent is legally required.

15. Contact Us

For privacy questions, requests, or complaints:

If your question concerns health information related to a specific healthcare facility, we may need to coordinate with, or refer you to, that facility's privacy office, and we will tell you if that is the case.


Appendix A — Summary of Categories Collected (for U.S. State Law Disclosures)

Category Examples Collected? Source Purpose Disclosed To
Identifiers IP address; email (support/admin users only) Yes You; automatic Service operation, security, support Service providers
Internet/network activity Session logs, routes generated, referral source Yes Automatic Service operation, improvement, security Service providers; Venues (aggregate only)
Geolocation Approximate area inferable from IP; optional device location for parking/arrival maps only (with permission; shared with Google as map provider; not used for indoor navigation) Limited Automatic; you (with permission) Service operation, security; parking map display Google (map provider, parking feature only); not otherwise disclosed in identifiable form
Health-adjacent data Appointment time/status, appointment location, and patient identifier (authorized portal integrations only; held in memory transiently and discarded after route resolution) Limited Third party you authorize Route generation only Governed by BAA with Venue; not retained
Professional information Organization, role (admin/API users) Yes You Account administration Service providers
Sensitive personal information See health-adjacent above Limited Third party you authorize Route generation only; no inference or advertising use Governed by BAA
Biometric, financial, education data No

Retention: See Section 7. Sale/Sharing: None.