RouteMe Privacy Policy
1. Introduction
RouteMe, Inc. (“RouteMe,” “we,” “us,” or “our”) provides a browser-based indoor navigation and wayfinding platform used by hospitals, clinics, campuses, and other facilities (“Venues”). This Privacy Policy explains what information we collect, how we use and share it, and the choices and rights available to you when you use our website (routeme.ai), our web-based navigation application, our Partner API, and related services (collectively, the “Services”).
A core design principle of RouteMe is data minimization. Because the Services run in your web browser without a downloaded app and without proprietary tracking hardware installed in facilities, we are able to provide wayfinding while collecting substantially less information than many navigation products. In many deployments, you can receive a complete route without providing us any information about who you are.
This Policy applies to information we handle as a business for our own purposes. Where we process information on behalf of a healthcare Venue as its service provider or HIPAA business associate, additional terms apply — see Section 4.
2. Information We Collect
What we collect depends on how you use the Services.
2.1 Information You Provide Directly
- Destination selections and searches. When you search for or select a destination within a Venue (for example, a department, clinic, or amenity), we process that selection to display the corresponding route.
- Contact and support information. If you contact us — for support, sales inquiries, or feedback — we collect the information you choose to provide, such as your name, email address, organization, and the contents of your message.
- Account and credential information. For administrative users and API partners, we collect registration details such as name, work email address, organization, role, and authentication credentials.
2.2 Information Collected Automatically
- Device and browser information. When you open the Services, we automatically receive technical information from your browser, such as browser type and version, operating system, device type, screen dimensions, language settings, and IP address.
- Usage information. We collect information about how the Services are used, such as the routes generated, pages viewed, features used, session duration, referring links (for example, whether a session originated from a QR code, a direct link, or a portal integration), and interaction events. Where feasible, usage analytics are collected in aggregated or de-identified form.
- Approximate location from IP address. Like most web services, we automatically receive your IP address, which may indicate your approximate geographic area (such as city or region). We do not otherwise determine or track your physical position, with one optional exception: the parking and arrival feature described in Section 3, which uses your device location only with your permission.
- Cookies and similar technologies. We use cookies, local storage, and similar technologies as described in Section 8.
2.3 Information Received from Third Parties
- Venue-supplied information. Venues provide us the facility data needed to power wayfinding — floor plans, department names, room and destination identifiers, accessibility attributes, and operating details. This is facility information, not personal information, although department names may reveal the nature of services at a destination.
- Integration data you authorize. If you launch RouteMe from an integrated patient portal (such as Epic MyChart) and complete the portal's authorization flow (SMART on FHIR / OAuth 2.0), we read a limited set of information needed to route you to your appointment: your upcoming appointment details (date and time, status, and a reference to its location), the corresponding facility location record (its name, facility location identifier, and building address), and the patient identifier the portal provides as part of the authorized launch. We request only read-only scopes limited to appointment and location information, and we do not request access to clinical records. This lookup is performed entirely on RouteMe's servers; access tokens and appointment information are never sent to your browser. The information is used once, at launch, to resolve your appointment's location to a RouteMe destination, and is then discarded. Only the resolved destination (which contains no patient or appointment information) is used to display your route. In simpler “link-based” integrations, no patient or appointment data is transmitted to RouteMe at all; the link itself encodes only a destination.
2.4 Information We Do Not Collect
Unless described above or required for a specific feature you choose to use, RouteMe does not:
- Require you to create an account, provide your name, or identify yourself to receive directions;
- Access your device's contacts, photos, microphone, or camera (other than momentary camera use by your own device to scan a QR code, which occurs outside our Services);
- Use your location for indoor navigation, or track your position inside any facility. Indoor routes never involve positioning: we do not determine or track your position via GPS, installed beacons, Wi-Fi triangulation, Bluetooth, or any other means, and we do not deploy positioning hardware in facilities. The only location permission the Services ever request is for the optional parking and arrival map feature described in Section 3, and declining it does not affect wayfinding;
- Collect medical records, diagnoses, treatment information, or clinical data. The appointment details described in Section 2.3 (appointment time and status, location, and the associated patient identifier), processed transiently and only in portal integrations you authorize, are the full extent of health-related information we handle. We do not request or receive any other clinical FHIR resources.
3. How RouteMe Navigation Works
RouteMe does not use your location to provide indoor directions. Routes are delivered as pre-produced, edited route videos with visual guidance overlays that show the path from a facility entry point to your selected destination.
- No indoor positioning of any kind. Indoor wayfinding never determines, requests, or tracks your physical position. No GPS, beacon, Wi-Fi, Bluetooth, or other positioning technology is used for routing, on your device or in the facility.
- How your route is selected. A route video is chosen based on your destination selection and, where applicable, the fixed entry point associated with the link or QR code you used (for example, a specific entrance or kiosk). That entry point is a property of the link itself, prepared in advance by the Venue and RouteMe; it tells us which pre-produced video to display, not where you are.
- Optional parking and arrival maps. Where a Venue deployment offers parking or arrival information, the Services may display an outdoor map powered by Google Maps and, if you grant your browser's location permission, use your device location to show your position relative to parking areas or driving directions. This is the only feature that uses your device location. Location data used for this feature is processed during your session and shared with Google as the map provider, whose handling of that data is governed by Google's own privacy policy. We do not use it for indoor routing, store it after your session, or use it to track your movements. You can decline or revoke the permission at any time in your browser or device settings, and declining does not prevent you from receiving parking information for the facility generally or from using wayfinding.
- No movement profiles. RouteMe does not build profiles of any individual's movements. Indoor navigation involves no positioning data at all, and outdoor map location is used transiently as described above. The only navigation-related records are the route requests described in Section 2.2.
4. Health Information and HIPAA
Many RouteMe Venues are healthcare providers. The fact that you navigated to, or had an appointment at, a particular department could reveal sensitive information. We treat this category of data with heightened care.
- The only PHI pathway. The authorized patient-portal integration described in Section 2.3 is the only circumstance in which RouteMe receives protected health information (“PHI”). All other uses of the Services, including QR-code, kiosk, and link-based navigation, involve no patient identity or appointment information at all.
- Transient handling. When you launch RouteMe from an authorized portal integration, appointment and location information and the associated patient identifier are held in server memory only for the duration of that lookup, used to select your route destination, and then discarded. This PHI is not written to durable storage, and PHI content and patient identifiers are excluded from system logs. To meet HIPAA audit-control requirements, we record that an access occurred (for example, timestamp, resource type, and outcome) without including PHI in the log entry.
- Business associate relationships. Because RouteMe reads appointment information on behalf of HIPAA-covered Venues, even transiently, RouteMe acts as a business associate of each such Venue. A Business Associate Agreement (“BAA”) is executed with the Venue before any PHI flows in that environment, and RouteMe processes PHI solely as permitted by that BAA and by HIPAA. Subcontractors that can access PHI (such as our cloud hosting provider) operate under their own subcontractor BAAs. In the event of a conflict between this Policy and an applicable BAA with respect to PHI, the BAA controls.
- Minimum necessary. The integration requests only read-only appointment and location scopes, performs one lookup per launch, and discards the data after use. We do not request access to clinical records, problem lists, medications, or other clinical FHIR resources, and we make no secondary use of appointment data for analytics, marketing, or product telemetry.
- No advertising use. We do not use destination selections, appointment-related data, or any health-adjacent information for advertising, and we do not sell or share such information for cross-context behavioral advertising.
- Anonymous use remains available. Nothing in our Services requires patients to identify themselves to receive directions within a facility.
5. How We Use Information
We use the information described above to:
- Provide the Services — resolve your selected destination, display the corresponding route video and directions, show optional parking and arrival maps where offered, and operate integrations you have authorized;
- Operate and administer deployments — authenticate administrative and API users, manage Venue configurations, measure usage of the Services (such as route and user counts, in aggregated and anonymized form) for Venue reporting and billing, and provide customer support;
- Maintain safety and security — detect, investigate, and prevent fraud, abuse, unauthorized access, and violations of our Terms; enforce rate limits; and protect the integrity of the Services;
- Improve the Services — analyze usage patterns (in aggregated or de-identified form wherever feasible) to improve routing quality, identify facility data errors (such as frequently abandoned routes suggesting an outdated map), and develop new features. Appointment data received through portal integrations is excluded from this purpose: it is used solely to select your route destination and is not used for analytics, telemetry, or product improvement;
- Communicate with you — respond to inquiries, provide service announcements, and, for business contacts who have opted in where required, send information about our products;
- Comply with law — meet legal, regulatory, and contractual obligations, including obligations under BAAs with healthcare Venues.
We do not use personal information for automated decision-making that produces legal or similarly significant effects about you.
6. How We Share Information
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We share information only in the following circumstances:
- With the Venue you are navigating. Venues receive aggregated, anonymized analytics and usage overviews about the use of RouteMe in their facilities (for example, most-requested destinations, route volumes, user counts, and peak usage times) to improve wayfinding and facility operations and to support billing under their agreements with us. Where a Venue is the HIPAA covered entity for whom we process PHI, disclosures to that Venue are governed by the applicable BAA.
- With service providers. We use vetted vendors to operate the Services — such as cloud hosting and infrastructure providers, error monitoring, analytics, and customer support tooling. Service providers may access information only to perform services for us, under contractual confidentiality and data-protection obligations, and (where PHI is involved) under subcontractor BAAs.
- With third parties at your direction. When you authorize an integration (such as a patient portal), information flows between RouteMe and that third party as you have directed through the applicable consent flow.
- For legal reasons. We may disclose information if we believe in good faith that disclosure is required by law, subpoena, or legal process; necessary to protect the rights, property, or safety of RouteMe, our users, or the public; or necessary to detect or prevent fraud or security issues. Where permitted, we will attempt to notify affected Venues or users of legal demands for their information.
- In corporate transactions. If RouteMe is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to this Policy's commitments and, for PHI, the requirements of applicable BAAs and HIPAA.
- Aggregated and de-identified data. We may use and share information that has been aggregated, anonymized, or de-identified such that it can no longer reasonably identify you or any Venue's confidential information, including publicly and to demonstrate the Services' value to prospective Venues. We commit not to attempt to re-identify de-identified data. Appointment data received through portal integrations is discarded after route resolution and is not incorporated into aggregated statistics.
7. Data Retention
We retain information only as long as necessary for the purposes described in this Policy, and our retention practices reflect our data-minimization design:
- Anonymous navigation sessions. Route and session data from anonymous use is retained in identifiable form (e.g., associated with an IP address) only for the period needed for security and operational logging — 90 days — after which it is deleted or de-identified.
- Integration data. Appointment and location information received through an authorized portal integration is held in server memory only for the launch in which it is read, is discarded once your route destination is resolved, and is never written to durable storage or included in log content. What persists after the lookup is the resolved RouteMe destination (which contains no PHI) and a non-PHI audit record that an access occurred. OAuth access tokens are held server-side only, expire within the validity period set by the authorizing platform (typically one hour), and are not renewable; we do not request refresh tokens or offline access.
- Account and API records. Administrative and partner account information is retained for the life of the account plus the period required for legal, audit, and contractual purposes.
- Support communications. Retained as needed to resolve your inquiry and for reasonable recordkeeping.
- Legal holds. We may retain information longer where required by law, litigation hold, or contractual obligation.
When retention periods end, we delete or irreversibly de-identify the information.
8. Cookies and Similar Technologies
The Services use a limited set of cookies and browser storage technologies:
- Strictly necessary. Session management, security (such as protecting against cross-site request forgery), load balancing, and remembering your in-session state (such as your current route). These are required for the Services to function.
- Functional. Remembering preferences such as language or accessibility settings.
- Analytics. Understanding aggregate usage of the Services. Where analytics cookies are used, we configure them to minimize identifiability (for example, IP truncation) where the tooling permits.
We do not use advertising or cross-site tracking cookies. You can control cookies through your browser settings; blocking strictly necessary cookies may prevent the Services from functioning. Where required by applicable law, we present a consent mechanism for non-essential cookies. The Services do not currently respond to browser “Do Not Track” signals, but we honor Global Privacy Control (“GPC”) signals where applicable law requires.
9. Data Security
We implement administrative, technical, and physical safeguards designed to protect information against unauthorized access, alteration, disclosure, or destruction, including:
- Encryption of data in transit (TLS 1.2 or higher) and at rest;
- OAuth 2.0 with PKCE (S256) and exact-match redirect URI validation for third-party authorization flows, with all tokens and health-record lookups confined to our backend so that access tokens never reach the browser, and industry-standard authentication for administrative and API access;
- Read-only integration scopes with no write access to any connected health record system;
- Role-based access controls and the principle of least privilege for internal access;
- Logging and monitoring of production systems;
- Vendor security review and contractual data-protection requirements for service providers;
- Secure development practices and periodic security assessments.
No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify affected parties and regulators as required by applicable law and, for PHI, in accordance with the HIPAA Breach Notification Rule and applicable BAAs. Suspected vulnerabilities may be reported to legal@routeme.ai.
10. Your Privacy Rights and Choices
10.1 Choices Available to Everyone
- Anonymous use. You may use core wayfinding features without identifying yourself.
- Browser location (parking maps only). The only feature that requests your device location is the optional parking and arrival map (Section 3). You control that permission in your browser or device settings and may decline or revoke it at any time without affecting wayfinding. Indoor navigation never requests your location.
- Integration authorization. You may decline or revoke third-party integration authorizations (for example, through your patient portal's connected-apps settings). Revocation stops future data sharing.
- Communications. You may opt out of non-essential emails using the unsubscribe link in any such message.
10.2 Rights Under U.S. State Privacy Laws
Depending on your state of residence (including California, Colorado, Connecticut, Virginia, Texas, and other states with comprehensive privacy laws), you may have the right to:
- Know / access the personal information we have collected about you;
- Delete personal information we hold about you, subject to legal exceptions;
- Correct inaccurate personal information;
- Portability — receive a copy of your personal information in a usable format;
- Opt out of “sales,” “sharing” for cross-context behavioral advertising, and certain profiling (note: RouteMe does not sell or share personal information in these senses);
- Non-discrimination for exercising your rights.
To exercise these rights, contact us as described in Section 15. We will verify your request using reasonable means and respond within the timeframe required by applicable law. You may designate an authorized agent to submit requests on your behalf where permitted. If we decline a request, you may appeal by replying to our response, and we will explain the appeal outcome; you may also contact your state Attorney General.
Important limitation: Where the information you seek is PHI processed on behalf of a healthcare Venue, your rights are exercised through that Venue (the HIPAA covered entity), and we will refer your request to the appropriate Venue and support its response as required by our BAA.
10.3 GDPR / UK GDPR (If Applicable)
If you are in the European Economic Area, United Kingdom, or Switzerland, and to the extent the GDPR or UK GDPR applies to our processing:
- Legal bases. We process personal data on the bases of: performance of a contract or steps at your request (providing routes and features you invoke); legitimate interests (securing and improving the Services, in a manner minimally intrusive to your rights); consent (optional device location for parking maps, non-essential cookies, and integrations you authorize); and legal obligation (compliance requirements).
- Your rights. You may request access, rectification, erasure, restriction, portability, and objection to processing based on legitimate interests, and you may withdraw consent at any time without affecting prior processing. You may lodge a complaint with your supervisory authority.
- Controller/processor roles. For anonymous public use of the Services, RouteMe generally acts as a controller. Where we process data on behalf of a Venue under contract, we act as a processor, and requests should be directed to the Venue as controller; we will assist accordingly.
- International transfers. Where personal data is transferred outside your jurisdiction, we rely on appropriate safeguards such as Standard Contractual Clauses.
11. International Users
The Services are operated from the United States, and information is processed and stored in the United States and other jurisdictions where our service providers operate. Privacy laws in these jurisdictions may differ from those in your home jurisdiction. By using the Services, you understand that your information will be processed as described in this Policy and subject to the safeguards described above.
12. Children's Privacy
The Services are wayfinding tools intended for general audiences and are not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided personal information to us, please contact us and we will delete it. Children visiting a Venue may follow directions displayed on a parent's or guardian's device without providing any information to RouteMe.
13. Third-Party Links and Services
The Services may contain links to Venue websites, patient portals, and other third-party properties, and may embed third-party services such as Google Maps for the optional parking and arrival feature. This Policy does not apply to third-party services, and we are not responsible for their privacy practices. Google's handling of information in connection with embedded maps, including device location you choose to share, is governed by Google's privacy policy. We encourage you to review the privacy policies of any third-party service you use, including your patient portal provider, whose handling of your health information is governed by its own policies and by your healthcare provider's notices.
14. Changes to This Policy
We may update this Policy from time to time. When we do, we will revise the “Last Updated” date above and, for material changes, provide additional notice within the Services or by other reasonable means (and obtain consent where required by law). Your continued use of the Services after an update constitutes acceptance of the revised Policy, except where consent is legally required.
15. Contact Us
For privacy questions, requests, or complaints:
RouteMe, Inc.
Attn: Privacy
390 N Orange Avenue, Suite 2300
Orlando, FL 32801
Email: legal@routeme.ai
Web: https://routeme.ai
If your question concerns health information related to a specific healthcare facility, we may need to coordinate with, or refer you to, that facility's privacy office, and we will tell you if that is the case.
Appendix A — Summary of Categories Collected (for U.S. State Law Disclosures)
| Category | Examples | Collected? | Source | Purpose | Disclosed To |
|---|---|---|---|---|---|
| Identifiers | IP address; email (support/admin users only) | Yes | You; automatic | Service operation, security, support | Service providers |
| Internet/network activity | Session logs, routes generated, referral source | Yes | Automatic | Service operation, improvement, security | Service providers; Venues (aggregate only) |
| Geolocation | Approximate area inferable from IP; optional device location for parking/arrival maps only (with permission; shared with Google as map provider; not used for indoor navigation) | Limited | Automatic; you (with permission) | Service operation, security; parking map display | Google (map provider, parking feature only); not otherwise disclosed in identifiable form |
| Health-adjacent data | Appointment time/status, appointment location, and patient identifier (authorized portal integrations only; held in memory transiently and discarded after route resolution) | Limited | Third party you authorize | Route generation only | Governed by BAA with Venue; not retained |
| Professional information | Organization, role (admin/API users) | Yes | You | Account administration | Service providers |
| Sensitive personal information | See health-adjacent above | Limited | Third party you authorize | Route generation only; no inference or advertising use | Governed by BAA |
| Biometric, financial, education data | — | No | — | — | — |
Retention: See Section 7. Sale/Sharing: None.