6. Security & Compliance
Data security
Encryption in transit. The dashboard, the Univooz Go app, the public API and the live connection use HTTPS and secure WebSockets (TLS).
Encryption at rest. The database, the cache and the file storage run on managed cloud services in USA & EU. The providers encrypt the storage volumes at rest.
Passwords. Univooz stores passwords as bcrypt hashes. Nobody at Univooz can read a password. A password has at least 8 characters. A password reset link comes by email and expires.
Sessions. A dashboard session uses a short-lived access token (24 hours) and a refresh token (7 days). Univooz rotates the refresh token on each use and stores only its hash. The driver app uses a separate token system with the same rules. A driver password reset signs out every device.
Access control. Every team member has one of three roles:
Role | Can do |
|---|---|
Owner | Everything, including billing, plan changes and team management. Cannot be removed. |
Admin | Team management, routes, driver earnings, exports and driver account deletion. Cannot remove other admins or the owner. |
User | Daily operations. No billing and no team management. |
Drivers have separate accounts for the Univooz Go app only. They have no dashboard access.
Data separation. Every record belongs to one organization. A business sees only the orders it created. A fleet sees only the orders in its zones. A driver sees only the routes assigned to that driver.
API keys and webhooks. Univooz stores API keys as hashes and shows the full key one time. The dashboard shows the prefix and the last four characters. Keys can expire and can be revoked. Rate limits apply per organization. Every webhook delivery carries an HMAC-SHA256 signature with a timestamp, so your server can verify the sender and reject replays. Test and live webhooks use separate endpoints and secrets.
Files. Proof-of-delivery photos, driver documents and profile pictures are stored in a private bucket. The platform gives access only through signed links that expire: 15 minutes for an upload and 60 minutes for a download.
Payments. Stripe processes all payments. Card numbers never reach Univooz servers. Public tracking links. Each order tracking link contains a token bound to that order. The tracking endpoint is rate limited per visitor.
Backups. The database provider keeps automatic backups. The Univooz team also takes its own encrypted database dumps [BACKUP SCHEDULE].
Monitoring. The driver app reports crashes to Sentry, hosted in the EU. The app sends no personal data with a crash report.
2. Compliance
Legal entity. Univooz is a trading name of MaxTech Solutions. MaxTech Solutions is the data controller for account data, driver data and website analytics. It is the data processor for the order and recipient data that business clients upload. The Privacy Policy describes both roles. GDPR. Users in the EEA and the UK can request access, correction, deletion, restriction and portability of their personal data. Send the request to info@maxtech.solutions. Delivery recipients contact the business that shipped the order, because Univooz processes that data on the instruction of the business.
Certifications. Univooz is not ISO 27001 certified. We follow the practices described on this page and in the Privacy Policy.
App store rules. The Univooz Go app offers in-app account deletion, as Apple and Google require. The app collects location only while the driver is clocked in.
3. Privacy and data handling
What we collect. Account and contact data of team members. Branch, customer and order data that a business enters. Driver profile, vehicle, compliance documents, earnings and shift data. Driver location during a shift. Proof-of-delivery photos. Technical logs.
What we do with it. We use the data to run deliveries, to show live status to the business, the fleet and the recipient, to calculate driver earnings and to bill the subscription. We do not sell personal data. We do not use it for advertising.
Retention.
Data | Kept for |
|---|---|
Proof-of-delivery photos | 30 days after delivery, then deleted |
Live driver position | 5 minutes in a cache, only while clocked in |
Team invitations | 7 days |
System logs | Up to 30 days |
Orders and events | For the life of the account, or as the business instructs |
Driver account | Until deletion completes. Then we remove identifiers, documents and photos and keep a pseudonymized work record for the legal retention period |
Driver account deletion. A driver requests deletion in the app under Settings. The app shows a case reference. The fleet owner or admin completes the deletion within 30 days. The driver can withdraw the request while it is pending. Business clients and website visitors request deletion at info@maxtech.solutions.
Sub-processors.
Provider | Purpose |
|---|---|
Railway | API hosting, PostgreSQL database, Redis cache |
Amazon Web Services (S3) | File storage |
Stripe | Subscriptions and invoices |
Resend | Transactional email |
Google Maps Platform | Address lookup and route distances |
Expo push service, Apple, | Push notifications to the driver app |
Sentry (EU) | Crash reports from the driver app |
Incident response
If we detect a security incident, we do these steps:
Contain. We revoke affected credentials and block the access path.
Investigate. We find the cause and the scope of the incident.
Notify. We inform the affected organizations by email. Where GDPR requires it, we notify
the supervisory authority within 72 hours.Fix. We correct the cause and update this page if the measures change.
If you see unusual activity on your account, send an email to info@maxtech.solutions.
Best practices for users
• Use a strong password that you do not use on other sites.
• Give each team member an own account. Invite them from the Team page. Do not share alogin.
• Remove team members who leave the company.
• Give the "User" role by default. Give "Admin" only to people who manage the team.
• Store API keys and webhook secrets in a secret manager. Create a new key and revoke the old one when a developer leaves.
• Sign in only at app.univooz.com. Univooz emails come from noreply@univooz.com. Do not enter your password on other pages.
• Drivers: keep the device operating system updated, keep location and notification permissions on during shifts, and sign out on a shared device.
