Privacy Policy
Last updated 24 August 2026
This sits alongside our terms of service, which govern the rest of the relationship.
Who is responsible
Controller
Veezio Solutions s.r.o., Nové sady 988/2, Staré Brno, 602 00 Brno, Czech Republic, company number 23746068, is the controller of the personal data described here, within the meaning of Regulation (EU) 2016/679 (GDPR).
Write to help@routee.link with anything about your data. We answer within 30 days, as the GDPR requires, and usually much sooner.
We have not appointed a data protection officer: our processing does not meet the thresholds in Article 37 that would require one. The address above reaches the people who make these decisions.
Two kinds of people
Creators hold an account, shorten links and are paid a share of what those links earn. Visitors open a Routee link and may buy a pass. The data we hold differs a lot between the two, so this policy treats them separately.
What we collect
If you are a creator
| Data | Why | Legal basis |
|---|---|---|
| Email address, and a name if you give one | Signing you in, and everything we have to tell you about your account and your money | Contract, Art. 6(1)(b) |
| Google account identifier, if you sign in with Google | Recognising you on the next sign-in | Contract, Art. 6(1)(b) |
| Passkey public key and its signature counter | Signing you in without a password | Contract, Art. 6(1)(b) |
| Sessions: an identifier, an expiry, and when it was created | Keeping you signed in and letting you revoke a session | Contract, Art. 6(1)(b) |
| Your links, and the statistics they produce | Running the service and showing you what your links did | Contract, Art. 6(1)(b) |
| Billing details for payouts: legal name, address, company registration number, VAT number | Issuing the self-billed invoice that settles your payout | Legal obligation, Art. 6(1)(c) |
| Bank account or crypto wallet, encrypted at rest | Paying you | Contract, Art. 6(1)(b) |
| Earnings, payouts, invoices, chargebacks | Accounting, and being able to show what happened to money | Legal obligation, Art. 6(1)(c) |
If you are a visitor
| Data | Why | Legal basis |
|---|---|---|
| Email address, once you buy a pass | Sending your receipt, letting you restore access, and telling you before a renewal is charged | Contract, Art. 6(1)(b) |
| Your pass: which plan, when it renews, whether it is active | Deciding whether a link opens for you | Contract, Art. 6(1)(b) |
| Stripe customer and subscription identifiers | Charging the card you gave Stripe and letting you manage the membership | Contract, Art. 6(1)(b) |
| Payments: amount, currency, country, and Stripe's payment identifier | Accounting, and paying the creator their share | Legal obligation, Art. 6(1)(c) |
| Each visit to a Routee link: time, country, referring site, browser and device string, and whether the link opened | Showing the creator how their links perform, and spotting fraud | Legitimate interests, Art. 6(1)(f) |
| A keyed hash of your IP address | Counting a visitor once and catching abuse, without reading the address itself | Legitimate interests, Art. 6(1)(f) |
| The IP address a link was opened from, for 180 days | Answering a card dispute - the person's bank asks us to show the service was used, and from where | Legitimate interests, Art. 6(1)(f) |
| A report you send about a link, and what you wrote in it | Acting on it, and keeping a record of what we decided | Legal obligation, Art. 6(1)(c) |
What we never hold
Card numbers. Payment details go straight to Stripe and never reach our servers; we see only the last state of a payment and identifiers that point back into Stripe.
Your IP address beyond 180 days. Link opens carry the address for that window, because a card dispute is argued on where and when a service was used; after it the address is erased and only the keyed hash remains, which cannot be turned back into an address without a key we do not store beside it. Nothing else we keep holds a raw address.
Passwords. There are none - you sign in with a one-time code, a passkey, or Google.
Cookies
The two we set
routee_session keeps a creator signed in. It is set only after you sign in, lasts 30 days, and is HTTP-only.
routee_pass tells us your pass is yours when you open a link. It is set only after you buy a pass, lasts 400 days, and is HTTP-only.
Both are strictly necessary to deliver something you asked for, so under Section 89(3) of Act No. 127/2005 Coll. and Article 5(3) of Directive 2002/58/EC they do not need consent.
Nothing else is kept on your device unless you allow it. A link you paste before signing up waits in local storage until your account exists, and is deleted the moment it is used; the id that tells two open tabs apart lives in memory and is gone when the tab closes; your answer to the question below is remembered in local storage so we stop asking.
The one we ask about
We advertise on X, and we would like to know which of those ads bring people here. Measuring that means letting X store a cookie on your device, which is not necessary for anything you asked us for - so we ask first, and nothing is loaded until you say yes. Refusing changes nothing about how the site works.
The question is only ever put on our own pages. A paywall never asks it, and never loads anything belonging to X.
You can take the answer back whenever you like, from the link in the footer. It is one click, in the same place, as giving it. Withdrawing does not undo measuring that already happened.
Legal basis: your consent, under Section 89(3) of Act No. 127/2005 Coll. and Article 5(3) of Directive 2002/58/EC, and Article 6(1)(a) GDPR.
What we measure without asking
We count page views through Vercel Web Analytics. It sets no cookies and stores nothing on your device: visitors are told apart by a hash made from the request itself, which is discarded after 24 hours, and it holds no identifier that could follow you to another site. Because nothing is stored on or read from your device, it is outside what Section 89(3) asks consent for.
Who else processes it
Processors
| Who | What they do | Where |
|---|---|---|
| Stripe Payments Europe, Ltd. | Takes the payment, stores the card, runs the billing portal, handles disputes | EU, with transfers to the US under Standard Contractual Clauses |
| Resend (Plus Five Five, Inc.) | Delivers our transactional email | EU region, with transfers to the US under Standard Contractual Clauses |
| Google Ireland Ltd. | Verifies who you are when you choose to sign in with Google | EU/US, Standard Contractual Clauses |
| Vercel Inc. | Serves the site and counts page views without cookies or device storage | US, Standard Contractual Clauses |
| X Corp. | Measures which of our ads brought somebody here - only if you allow it | US, Standard Contractual Clauses |
Public registries
When a creator gives us a VAT number, we check it against VIES, run by the European Commission, and for Czech numbers against ARES, run by the Czech Ministry of Finance. Only the number itself is sent. These are public authorities acting on their own account, not our processors.
What creators can see about visitors
A creator sees masked email addresses - two characters and the domain, never the whole address - along with country, plan, what the pass paid and when. They cannot see the full address, the IP hash, or anything about links that are not theirs. This is deliberate: the visitor's contract is with us, and their address is not the creator's to hold.
Nobody else
We do not sell personal data, we do not share it for advertising, and we do not hand it to anyone beyond the parties above except where a court or an authority with jurisdiction requires it, or where we have to defend a legal claim.
How long we keep it
Retention
| Data | Kept for |
|---|---|
| Accounting records: payments, earnings, payouts, invoices, chargebacks | 10 years from the end of the accounting period, as Section 31 of Act No. 563/1991 Coll. and Section 35 of the VAT Act require |
| Creator account and links | Until you close the account; the account is then anonymised rather than deleted, because the accounting records above point at it |
| Pass and subscription records | As long as the pass is live, then with the payment records it belongs to |
| Visit statistics, including the IP hash | 26 months, then deleted |
| Sign-in codes, passkey challenges, restore links | Minutes - they expire and are consumed on first use |
| Sessions | 30 days, or until you sign out |
| Bank and wallet details | Until you remove them, or the account closes with nothing left to pay |
| Reports about links | 3 years, so a pattern of abuse stays visible |
Closing a creator account
Closing an account replaces the email address with an unusable placeholder, removes the name, deletes sessions, passkeys and payout details, and archives the links. The original address is kept encrypted in a separate record, so that a tax or regulatory check can still be answered - it is not readable in the ordinary running of the service.
What survives is the accounting trail, which the law does not let us delete on request.
Your rights
What you can ask for
Access to what we hold about you, correction of anything wrong, deletion where nothing obliges us to keep it, restriction of processing while a dispute is resolved, a machine-readable copy of what you gave us, and objection to anything we do on the basis of legitimate interests.
Where processing rests on legitimate interests - the visit statistics and the IP hash - you can object at any time and we will stop unless we can show compelling grounds that override your interests.
Write to help@routee.link. We do not charge for this and we do not make you prove anything beyond that you control the address in question.
If we get it wrong
Complain to the Czech data protection authority: Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Prague 7, uoou.gov.cz. If you live in another EU country, your own authority can take the complaint instead.
Automated decisions
We take no decisions about you by automated means that produce legal effects or similarly significant effects. Fraud checks can hold a payout for review, but a person decides what happens to it.
Security and changes
How it is protected
Everything travels over TLS. Bank accounts, crypto wallets and the email addresses of closed accounts are encrypted at rest with AES-256-GCM. IP addresses are stored as keyed hashes, apart from the 180-day dispute window on link opens, and are readable there only by the people who run the service. Sessions can be revoked and die with the record behind them. Access to the production database is limited to the people who run the service.
If a breach is likely to be a risk to you, we tell the authority within 72 hours and tell you without undue delay, as Articles 33 and 34 require.
Children
Routee is not for people under 16 and we do not knowingly collect their data. If you believe a child has given us data, write to help@routee.link and we will remove it.
Changes
We may update this policy. Where a change affects what we do with data we already hold, we say so before it takes effect. The date at the top always tells you which version you are reading.
Veezio Solutions s.r.o. · Nové sady 988/2, Staré Brno, 602 00 Brno · IČO 23746068 · DIČ CZ23746068 · help@routee.link