How your delivery data is handled.
Your order book is a list of your customers, their addresses and when they are out. It deserves to be treated carefully. Here is how the platform is built, in plain terms, including what we do not yet have.
The basics
Four things worth knowing first.
Encrypted in transit
Every connection to the platform, the apps and the API runs over HTTPS with modern TLS. Tracking links and webhooks are no exception.
Roles and least privilege
Owners, managers, dispatchers and drivers see different things. A driver sees their own stops; permissions are set per organization rather than shared.
Separated by organization
Every order, customer, driver and report belongs to one organization, and requests are scoped to it. Your data is not pooled with another fleet’s.
Scoped API keys
Integrations use per-client keys you create and revoke yourself, with field mappings and outbound webhooks for delivery events.
Access is scoped, per organization
Every record in PrivateMile — order, customer, driver, vehicle, report — belongs to exactly one organization, and every request is checked against the organization of the person making it. Roles narrow it further: an owner sees the business, a dispatcher sees the board, a driver sees the stops assigned to them.
Customer tracking links are deliberately narrow for the same reason. A link shows one order and the driver approaching it. Nothing about your other stops, customers or routes is reachable from it.
Driver location, honestly described
The driver app reports location while a driver is on shift. That is what makes live tracking, honest ETAs and geofenced arrival detection work, and those are the features that keep customers informed and drivers from having to tap anything at the door.
It is operational data for the working day. If you have a policy about how location data is retained or who can see it, it is a fair question to ask us before you roll the app out to your team, and we will answer it specifically.
Integrations and API keys
Store connections and custom integrations authenticate with per-client keys that you create and revoke yourself, with field mappings so an integration only carries what it needs. Outbound webhooks are signed to the endpoint you configure.
If you rotate a key, do it at the end of a day rather than the start — orders arriving in neither system for two hours is the most common self-inflicted integration incident.
What we do not claim
We are not currently certified against SOC 2 or ISO 27001. Plenty of vendors imply a certification they do not hold, and we would rather be the ones who say it plainly. If your procurement requires it, tell us and we will give you a straight answer about where we are.
Reporting something
If you believe you have found a vulnerability, email distrx.io@gmail.com with enough detail to reproduce it. We will acknowledge it and keep you informed. Please do not test against another customer's organization or data.
The formal documents
The terms of service, the privacy policy and the data deletion route live in the app, and they are the binding versions. This page is the plain-English summary of how the system is built.
Where is our data stored?
On managed cloud infrastructure, encrypted in transit, with regular backups. If you have a specific residency or retention requirement, ask us before you sign up and we will tell you plainly whether we can meet it.
Who can see our delivery data?
People you invite to your organization, in the role you give them. Access is scoped per organization, and drivers see only the stops assigned to them. A customer tracking link shows one order — nothing about your other deliveries, customers or routes.
What location data do you collect from drivers?
The driver app reports location while a driver is on shift, so dispatch can track progress, ETAs stay accurate, and geofenced arrival works. It is operational data for the delivery day, not continuous monitoring of employees off duty.
Can customers delete their data?
Yes. There is a data deletion route reachable without an account, and account data can be exported or removed on request. Details are in the privacy policy.
Do you have SOC 2 or ISO 27001 certification?
We are not currently certified against those frameworks. We would rather say so directly than imply otherwise — if a formal certification is a hard requirement for your procurement, tell us and we will be straight with you about timing.
How do we report a vulnerability?
Email distrx.io@gmail.com with the details and we will acknowledge it. We would rather hear about a problem from you than from someone else.
Your next route could be the first one it plans.
Set up your fleet, import today’s orders, and watch the board come alive — most teams dispatch within the hour.
Questions first? Tell us about your delivery day — or sign in.