Privacy at Navio

Your information should have a clear purpose.

This statement explains what personal information Navio handles, why it is needed, who it may be shared with, and how people can ask to access or correct it.

Effective 26 July 2026
01

Scope and roles

This statement applies to the Navio website, route-planning service, driver route pages and related support and account communications. Navio is an independently operated New Zealand business serving customers in New Zealand and Australia.

Navio collects some information directly, such as account and support details. Businesses also upload job information and decide which details are made available to their users and drivers. For that customer-supplied information, Navio generally acts as a service provider handling the information on the business's instructions.

For businesses using Navio: you are responsible for ensuring that you are authorised to upload personal information, that it is relevant to the work, and that customers, staff and drivers receive any privacy notice required for your collection and use of their information.
02

Information we handle

Account and business information

  • Email address, email-verification status and account creation date.
  • Business name, account role, permissions and product settings.
  • Subscription, trial and billing status, including Stripe customer identifiers.
  • Hashed passwords and other security credentials; Navio does not store readable passwords.

Routes and job information

When a spreadsheet is opened in Navio, the file is processed in the user's browser and is not uploaded to Navio. Only the information the business selects and saves as part of a route is sent to Navio. Columns that are not selected are disregarded in the browser and are not saved by Navio.

  • Job addresses, coordinates, route sequence, dates and route configuration.
  • Information imported by a business, which may include customer names, phone numbers, instructions, quantities, references and custom job fields.
  • The fields a business chooses to make visible on a driver route.

Driver activity and operational records

  • Driver labels and browser-generated driver session identifiers.
  • Job status, completion times, issues, comments and activity history.
  • Photos, signatures, signer names and associated file details.
  • Location coordinates and accuracy information when supplied for navigation or with a signature, together with relevant device and request information.

Technical and communication information

  • IP address, browser type, user agent, session times and security records.
  • Geocoding usage records, including hashed address references and provider results.
  • Messages sent to Navio and related support correspondence.
03

How information is collected

Navio may collect personal information:

  • directly when someone creates an account, changes settings or contacts Navio;
  • from a business when it saves selected job information from a spreadsheet or another job list—the source file itself remains in the user's browser;
  • from a driver or recipient using a shared route and recording work in the field;
  • automatically when a browser connects to Navio or uses essential session features; and
  • from service providers involved in billing, email delivery, security or mapping.

Some information is necessary to create an account, build and share routes, maintain operational records or provide support. If it is not provided, the relevant Navio function may not be available.

04

How information is used

Navio uses personal information where reasonably necessary to:

  • create and administer accounts and business access;
  • import jobs, geocode addresses, build routes and provide navigation;
  • share selected route information with authorised drivers and recipients;
  • record progress, issues, photos, signatures and completed work;
  • provide customer support and important service communications;
  • operate trials, subscriptions and billing;
  • detect misuse, protect accounts and investigate security events;
  • diagnose faults and improve the reliability and usefulness of Navio; and
  • meet legal obligations and establish, exercise or defend legal claims.

Navio does not—and will not ever—sell personal information or use customer or driver information for third-party advertising.

05

Who may receive information

Information is shared only where needed to provide the service, where a customer has directed the sharing, or where disclosure is authorised or required by law.

Business users and drivers Authorised business users may access their organisation's records. Drivers see route and job fields selected for the shared driver view.
Cloudflare Used for network protection, human-verification services and storage of driver evidence such as photos and signatures.
Stripe Handles subscription checkout, card details and billing management. Navio retains account and subscription identifiers rather than full card details.
Resend Delivers account, verification, password-reset and support email where the production email service is enabled.
Google geocoding Job addresses may be sent for address matching and coordinates when geocoding is required.
Map providers Map-tile providers may receive normal browser request information and the map area requested by the user's device.

Navio may also disclose information to professional advisers, insurers, regulators, law-enforcement agencies or another party involved in a business restructure where there is a lawful basis and appropriate protection.

06

Cookies and local storage

Navio currently uses essential browser storage rather than advertising cookies. This includes secure account-session cookies, a request-protection token, a time-limited shared-route unlock cookie, and local identifiers used to keep a driver's route session consistent.

Some browser-only tools may save their working state on the device so it remains available when the page is reopened. Blocking or clearing essential cookies and storage may sign a user out, lock a shared route or prevent parts of the service from working.

07

Storage, security and overseas processing

Navio uses technical and organisational safeguards intended to protect personal information against loss, unauthorised access, misuse or disclosure. These include one-way password hashing, protected sessions, access controls, controlled route sharing, validated uploads and short-lived links for accessing driver evidence. More detail is available on the Security page.

Navio and its service providers may store or process information outside New Zealand or Australia. Where applicable privacy law requires it, Navio will take reasonable steps to use providers and arrangements that provide appropriate privacy safeguards.

No online service can promise absolute security. Customers should limit uploaded information to what is reasonably needed for the work and manage user and driver access carefully.

08

Retention and deletion

Navio keeps personal information only for as long as it is reasonably needed to provide the service, maintain required operational or financial records, resolve disputes, protect the service and meet legal obligations.

Retention can differ by record type and account plan. For example, active account information is generally needed while the account remains in use, while expired sessions and temporary security records can be removed sooner. Billing records may need to be retained for statutory accounting periods.

When information is deleted from active use, limited copies may remain temporarily in backups, logs or records that Navio must retain. Those copies remain protected and are removed or overwritten through the applicable retention process.

09

Access, correction and other requests

A person may ask Navio to confirm whether it holds personal information about them, provide access to that information, or correct information that is inaccurate. Other rights may apply depending on the person's location and the applicable law.

Navio may need to verify identity before completing a request. Where information was supplied and controlled by a customer business, Navio may refer the request to that business or work with it to respond. Access may be limited where the law allows or requires information to be withheld.

Requests can be sent to [email protected].

10

Privacy questions and complaints

Contact Navio first if you have a privacy question or believe information has been handled incorrectly. Include enough detail to identify the issue, but do not email passwords or unnecessary customer information.

Privacy contact Navio's owner is also its Privacy Officer. [email protected]

If a New Zealand privacy concern cannot be resolved, a person may contact the Office of the Privacy Commissioner. If Australian privacy law applies, information about complaints is available from the Office of the Australian Information Commissioner.

11

Changes to this statement

Navio may update this statement when the service, providers or legal obligations change. The effective date at the top of the page will be updated when a revised statement is published. Material changes may also be communicated through the service or by email where appropriate.