Privacy Policy
Last updated: August 1, 2026
This Privacy Policy describes how FoundryEdge LLC d/b/a Roadara ("we", "us", or "our") collects, uses, and discloses your information when you use our Service (the Roadara web application and related services) and tells you about your privacy rights.
By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. This Policy should be read together with our Terms of Service.
Supported Service Area
The Service is offered and supported in the United States only. It is directed at users located in the United States. We do not market or design the Service as a product for residents outside that area. If you use the Service from outside the United States, this Policy still describes how we handle Personal Data, including the legal-bases language for EEA/UK users and California privacy rights below, but that does not change the geographic support scope in our Terms.
Interpretation and Definitions
Definitions
- Account: A unique account created to access the Service.
- Company (also referred to as "we", "us", or "our"): FoundryEdge LLC d/b/a Roadara.
- Personal Data (or "Personal Information"): Any information that relates to an identified or identifiable individual.
- Router Device: A Peplink (or similar) router you connect to the Service.
- Service: The Roadara web application, including site awareness, trip planning, weather and map features, Peplink router connection features, billing, and related support.
- Usage Data: Data collected automatically, such as IP address, browser type, pages visited, and device information.
- You: The individual or entity using the Service.
Information We Collect
Account and contact information
When you create or use an Account, we may collect:
- Email address
- Account credentials (handled by our authentication provider; we do not store your password in plaintext)
- Support communications you send to us (for example, to hello@roadara.com)
Billing and subscription information
If you purchase a paid Plan, we (and our payment processor) may process:
- Stripe Customer identifiers and subscription identifiers
- Subscription status and billing period metadata
- Limited payment-related metadata needed to manage Checkout, Customer Portal, and entitlement access
We do not store full payment card numbers on our servers. Card data is handled by Stripe.
Router Device and connection data
If you use Peplink-related features, we may collect and store:
- Router connection settings you provide (for example, hostname or IP, protocol, port, and related preferences)
- Router session state needed to call your Router Device on your behalf
- WAN status, cellular signal metrics, carrier / SIM information, and related telemetry retrieved from your Router Device
- Optional router configuration backups you choose to download or store through the Service
- API / proxy audit logs of router-related requests made through the Service
Location information
Depending on how you use the Service, we may process location-related data from one or more of these sources (priority and availability depend on your mode and settings):
- Router GPS — coordinates reported by a connected Router Device when available
- Device GPS — coordinates from your End-User Device browser/OS geolocation when you opt in
- Manual entry — a location you enter yourself
Location may be associated with features such as maps, weather, hazards, trip planning, speed tests, WAN logs, or carrier analysis sessions. Approximate (low-confidence) device GPS may be indicated in the product so you can refine it manually.
Map, weather, and third-party feature data
When you use map, weather, air quality, hazard, geocoding, or similar features, we may send necessary request parameters (such as coordinates or place queries) to third-party APIs and may cache limited responses to improve performance and control costs. We may also display map tiles from third-party tile providers in the browser.
Usage Data
We collect Usage Data automatically when you use the Service. This may include:
- IP address
- Browser type and version
- Pages or app surfaces visited and approximate time spent
- End-User Device information
- Feature usage needed to enforce Plan limits (for example, per-feature counters)
Cookies and similar technologies
We use cookies and similar technologies for essential functionality such as authentication/session management and security. See Website Analytics below for how we measure website usage (cookieless Vercel Web Analytics — separate from essential cookies).
How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Create aggregated, de-identified datasets about real-world mobile connectivity and coverage, and use them to improve the Service and to develop and improve other products and services offered by FoundryEdge LLC, including our API platform
- Authenticate you and manage your Account
- Connect to Router Devices you authorize and display related status and analytics
- Process payments and manage subscriptions and entitlements
- Communicate with you about the Service, updates, billing issues, and support (including transactional email)
- Enforce Plan limits and prevent abuse
- Detect and prevent fraud or security incidents
- Comply with legal obligations
Aggregated coverage and connectivity data
If you leave contribution enabled, measurements you run in the Service — such as speed test results, latency and jitter, the general area where the test was taken, and an estimate of the network operator — may be combined with measurements from other users to create aggregated, de-identified datasets about real-world mobile connectivity and coverage. These datasets help us show measured coverage alongside modeled coverage from public sources, and may also be used to develop and improve other products and services offered by FoundryEdge LLC, including our API platform.
How we protect this data
- Your location is reduced to a general area before it is stored for this purpose. We do not retain your precise coordinates for aggregated coverage use.
- The time of the measurement is also recorded only approximately, and the measured values are rounded.
- Contributed measurements are not linked to your Account or to any identifier that we can trace back to you.
- We do not publish or provide access to individual measurements. Only aggregated statistics are used.
- The network operator estimate is derived from the IP address of your request at the time of the measurement. We do not store your IP address for this purpose. This estimate can be inaccurate — for example on carrier-grade NAT, mobile virtual network operators, Wi-Fi, satellite, or VPN connections — and we record how confident the estimate is so it is not treated as fact.
Your choices, and their limits
- You can turn contribution on or off at any time in Settings → Privacy.
- Turning it off stops all future contribution immediately.
- Because contributed measurements are de-identified and not linked to you, we cannot identify or remove your past contributions from aggregated datasets. Data already contributed before you turn contribution off remains part of those datasets.
- Measurements you saved before we introduced this feature are never included.
Legal Bases for Processing (EEA/UK Users)
The Service is directed at users in the United States (see Supported Service Area above). If you are nonetheless located in the European Economic Area (EEA) or the United Kingdom and use the Service, we process your Personal Data under the following legal bases:
- Performance of a contract: To provide the Service, manage your Account, connect authorized Router Devices, and process payments.
- Legitimate interests: To secure, maintain, and improve the Service, prevent fraud and abuse, and enforce our terms — provided these interests are not overridden by your rights. This includes creating aggregated, de-identified connectivity datasets to improve coverage information and our products. You may object at any time by turning contribution off in Settings.
- Consent: Where we rely on your consent (for example, browser geolocation opt-in or certain communications), you may withdraw it at any time.
- Legal obligation: To comply with applicable laws, such as tax, accounting, and recordkeeping requirements.
Sharing of Personal Information
We may share your Personal Data with:
Service providers (sub-processors)
Third parties that help us operate the Service. Current core sub-processors include:
- Vercel — Application hosting and related edge/platform infrastructure
- Supabase — Database, authentication, and related backend services
- Stripe — Payment processing, Checkout, and Customer Portal (may use a Stripe account shared with other FoundryEdge products; Roadara charges are scoped to your Roadara Account)
- Resend — Transactional email delivery for Roadara product mail and Supabase Auth mail via the sending domain
mail.roadara.com(may use a Resend account shared with other FoundryEdge products; Roadara mail is scoped by From address / tags) - Cloudflare — Bot detection on authentication surfaces (Turnstile, when enabled), client-side speed measurements against Cloudflare’s measurement endpoints, and connection-health latency probes to those endpoints that run periodically when automatic checks are enabled. Each discloses your IP address (and timing) to Cloudflare; these probes are not a maps/weather-style API call.
These providers may process your information only on our behalf and under contractual obligations consistent with this Privacy Policy. This list may change as our service providers evolve.
We may also use additional third-party APIs for maps, geocoding, weather, air quality, hazards, or similar features when you use those parts of the Service. Those providers receive only the data needed to fulfill the request (for example, coordinates).
Website Analytics
We use Vercel Web Analytics to understand how people use the Roadara website and web application (for example, which pages are visited and from which referrers). This helps us improve navigation, performance, and content.
Vercel Web Analytics is privacy-oriented:
- It does not use cookies for analytics.
- It does not store IP addresses.
- Visitors are identified only by a short-lived hash derived from the request; that hash is discarded after 24 hours and is not used to track a person across days or across websites.
- Only aggregated, non-identifying data is retained (page paths, referrers, approximate city-level location, device type, browser, and operating system).
Before any analytics data is sent, we filter the event in your browser. We remove sensitive information that may appear in page URLs — such as authentication tokens, one-time login codes, session-related parameters, email addresses, and similar identifiers. On sign-in and other account authentication pages, we strip all query-string data from the URL included in the analytics event (the page path may still be recorded). Product data such as speed tests, router telemetry, and precise location history is not sent through Vercel Web Analytics; that data is handled separately under this Privacy Policy and our own systems.
You can opt out of this website analytics collection by setting a local preference in your browser (localStorage key va-disable to 1), or via a future Settings control if we add one. Opting out does not affect core Roadara functionality.
For more detail on Vercel’s practices, see Vercel’s Web Analytics privacy documentation.
Affiliates
Companies under common control with us (including other FoundryEdge products), where needed to operate shared infrastructure such as billing or email accounts — still limited to providing the Service to you.
Business transfers
In connection with a merger, acquisition, or sale of assets.
Legal requirements
When required by law, legal process, or to protect our rights, safety, or property, or that of others.
We do not sell your Personal Information, and we do not "sell" or "share" it for cross-context behavioral advertising as those terms are defined under applicable U.S. state privacy laws.
Data Retention
We retain your Personal Data only for as long as necessary to fulfill the purposes described in this Privacy Policy, including:
- Account information: For the duration of your account plus a reasonable period after closure (typically up to 24 months), unless a longer period is required.
- Router telemetry, speed tests, WAN logs, and similar operational records: For as long as needed to provide the Service and for a reasonable period afterward for support, security, and product improvement, unless you delete associated data earlier where the product allows.
- Financial and transaction records: Up to 10 years where needed to comply with tax and accounting requirements.
- Email suppressions (for example, bounce or complaint records): For as long as needed to honor suppression and protect deliverability.
- Aggregated, de-identified coverage data: Retained indefinitely. Because it is not linked to you and cannot be attributed to an individual, it is not subject to account-based deletion.
We may retain data longer when required by law, to resolve disputes, or for security purposes.
Data Security
We implement reasonable security measures to protect your Personal Data, including encrypted transport (HTTPS) for the Service and access controls on our systems. However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security. You are responsible for securing your Router Device credentials and local network.
Data Breach Notification
In the event of a data breach that affects your Personal Data, we will notify you and the relevant authorities as required by applicable law, without undue delay. Our notification will describe, to the extent known, the nature of the breach and the steps we are taking in response.
Your Privacy Rights
Depending on your location, you may have rights to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict certain processing
- Request data portability
- Withdraw consent at any time, where processing is based on consent (without affecting the lawfulness of processing before withdrawal)
- Lodge a complaint with your local data protection or supervisory authority
To exercise these rights, please contact us at hello@roadara.com. We will respond within the timeframes required by applicable law. We will not discriminate against you for exercising any of these rights.
California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know the categories and specific pieces of Personal Information we collect, use, and disclose;
- Request deletion of your Personal Information, subject to legal exceptions;
- Correct inaccurate Personal Information;
- Opt out of the "sale" or "sharing" of Personal Information — though, as noted above, we do not sell or share your Personal Information; and
- Not be discriminated against for exercising your privacy rights.
The categories of Personal Information we collect are described in the Information We Collect section, and the purposes for which we use them are described in How We Use Your Information. You may exercise these rights, or use an authorized agent to do so, by contacting us at hello@roadara.com. We may need to verify your identity before fulfilling your request.
Precise geolocation is treated as sensitive personal information under California law. We use it to provide the location-based features you request. We do not retain precise geolocation for aggregated coverage datasets — location is reduced to a general area before it is stored for that purpose — and you can turn contribution off at any time in Settings.
International Transfers
Your information may be processed in the United States or other countries where we or our service providers operate. We take appropriate steps to ensure adequate protection when transferring data internationally.
Children's Privacy
Our Service is not directed to anyone under the age of 18. We do not knowingly collect personal information from anyone under 18.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date. If we introduce a versioned acceptance flow, we may also ask you to re-accept material updates before continuing to use the Service.
Contact Us
If you have any questions about this Privacy Policy, you can contact us:
- By email: hello@roadara.com
- By website: https://roadara.com