Routee

Privacy Policy

Last updated 19 August 2026

This sits alongside our terms of service, which govern the rest of the relationship.

Who is responsible

Controller

Veezio Solutions s.r.o., Nové sady 988/2, Staré Brno, 602 00 Brno, Czech Republic, company number 23746068, is the controller of the personal data described here, within the meaning of Regulation (EU) 2016/679 (GDPR).

Write to help@routee.link with anything about your data. We answer within 30 days, as the GDPR requires, and usually much sooner.

We have not appointed a data protection officer: our processing does not meet the thresholds in Article 37 that would require one. The address above reaches the people who make these decisions.

Two kinds of people

Creators hold an account, shorten links and are paid a share of what those links earn. Visitors open a Routee link and may buy a pass. The data we hold differs a lot between the two, so this policy treats them separately.

What we collect

If you are a creator

DataWhyLegal basis
Email address, and a name if you give oneSigning you in, and everything we have to tell you about your account and your moneyContract, Art. 6(1)(b)
Google account identifier, if you sign in with GoogleRecognising you on the next sign-inContract, Art. 6(1)(b)
Passkey public key and its signature counterSigning you in without a passwordContract, Art. 6(1)(b)
Sessions: an identifier, an expiry, and when it was createdKeeping you signed in and letting you revoke a sessionContract, Art. 6(1)(b)
Your links, and the statistics they produceRunning the service and showing you what your links didContract, Art. 6(1)(b)
Billing details for payouts: legal name, address, company registration number, VAT numberIssuing the self-billed invoice that settles your payoutLegal obligation, Art. 6(1)(c)
Bank account or crypto wallet, encrypted at restPaying youContract, Art. 6(1)(b)
Earnings, payouts, invoices, chargebacksAccounting, and being able to show what happened to moneyLegal obligation, Art. 6(1)(c)

If you are a visitor

DataWhyLegal basis
Email address, once you buy a passSending your receipt, letting you restore access, and telling you before a renewal is chargedContract, Art. 6(1)(b)
Your pass: which plan, when it renews, whether it is activeDeciding whether a link opens for youContract, Art. 6(1)(b)
Stripe customer and subscription identifiersCharging the card you gave Stripe and letting you manage the membershipContract, Art. 6(1)(b)
Payments: amount, currency, country, and Stripe's payment identifierAccounting, and paying the creator their shareLegal obligation, Art. 6(1)(c)
Each visit to a Routee link: time, country, referring site, browser and device string, and whether the link openedShowing the creator how their links perform, and spotting fraudLegitimate interests, Art. 6(1)(f)
A keyed hash of your IP address - never the address itselfCounting a visitor once and catching abuse, without holding an identifier we do not needLegitimate interests, Art. 6(1)(f)
A report you send about a link, and what you wrote in itActing on it, and keeping a record of what we decidedLegal obligation, Art. 6(1)(c)

What we never hold

Card numbers. Payment details go straight to Stripe and never reach our servers; we see only the last state of a payment and identifiers that point back into Stripe.

Your raw IP address in any record we keep. Our servers necessarily see it in transit, as every web server does, but what we store is a keyed hash of it. Without the key, which is not stored alongside the data, the hash cannot be turned back into an address.

Passwords. There are none - you sign in with a one-time code, a passkey, or Google.

Cookies

The two we set

routee_session keeps a creator signed in. It is set only after you sign in, lasts 30 days, and is HTTP-only.

routee_pass tells us your pass is yours when you open a link. It is set only after you buy a pass, lasts 400 days, and is HTTP-only.

Both are strictly necessary to deliver something you asked for, so under Section 89(3) of Act No. 127/2005 Coll. and Article 5(3) of Directive 2002/58/EC they do not need consent. We set no advertising cookies, no analytics cookies, and nothing that follows you to another site.

Who else processes it

Processors

WhoWhat they doWhere
Stripe Payments Europe, Ltd.Takes the payment, stores the card, runs the billing portal, handles disputesEU, with transfers to the US under Standard Contractual Clauses
Resend (Plus Five Five, Inc.)Delivers our transactional emailEU region, with transfers to the US under Standard Contractual Clauses
Google Ireland Ltd.Verifies who you are when you choose to sign in with GoogleEU/US, Standard Contractual Clauses

Public registries

When a creator gives us a VAT number, we check it against VIES, run by the European Commission, and for Czech numbers against ARES, run by the Czech Ministry of Finance. Only the number itself is sent. These are public authorities acting on their own account, not our processors.

What creators can see about visitors

A creator sees masked email addresses - two characters and the domain, never the whole address - along with country, plan, what the pass paid and when. They cannot see the full address, the IP hash, or anything about links that are not theirs. This is deliberate: the visitor's contract is with us, and their address is not the creator's to hold.

Nobody else

We do not sell personal data, we do not share it for advertising, and we do not hand it to anyone beyond the parties above except where a court or an authority with jurisdiction requires it, or where we have to defend a legal claim.

How long we keep it

Retention

DataKept for
Accounting records: payments, earnings, payouts, invoices, chargebacks10 years from the end of the accounting period, as Section 31 of Act No. 563/1991 Coll. and Section 35 of the VAT Act require
Creator account and linksUntil you close the account; the account is then anonymised rather than deleted, because the accounting records above point at it
Pass and subscription recordsAs long as the pass is live, then with the payment records it belongs to
Visit statistics, including the IP hash26 months, then deleted
Sign-in codes, passkey challenges, restore linksMinutes - they expire and are consumed on first use
Sessions30 days, or until you sign out
Bank and wallet detailsUntil you remove them, or the account closes with nothing left to pay
Reports about links3 years, so a pattern of abuse stays visible

Closing a creator account

Closing an account replaces the email address with an unusable placeholder, removes the name, deletes sessions, passkeys and payout details, and archives the links. The original address is kept encrypted in a separate record, so that a tax or regulatory check can still be answered - it is not readable in the ordinary running of the service.

What survives is the accounting trail, which the law does not let us delete on request.

Your rights

What you can ask for

Access to what we hold about you, correction of anything wrong, deletion where nothing obliges us to keep it, restriction of processing while a dispute is resolved, a machine-readable copy of what you gave us, and objection to anything we do on the basis of legitimate interests.

Where processing rests on legitimate interests - the visit statistics and the IP hash - you can object at any time and we will stop unless we can show compelling grounds that override your interests.

Write to help@routee.link. We do not charge for this and we do not make you prove anything beyond that you control the address in question.

If we get it wrong

Complain to the Czech data protection authority: Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Prague 7, uoou.gov.cz. If you live in another EU country, your own authority can take the complaint instead.

Automated decisions

We take no decisions about you by automated means that produce legal effects or similarly significant effects. Fraud checks can hold a payout for review, but a person decides what happens to it.

Security and changes

How it is protected

Everything travels over TLS. Bank accounts, crypto wallets and the email addresses of closed accounts are encrypted at rest with AES-256-GCM. IP addresses are stored only as keyed hashes. Sessions can be revoked and die with the record behind them. Access to the production database is limited to the people who run the service.

If a breach is likely to be a risk to you, we tell the authority within 72 hours and tell you without undue delay, as Articles 33 and 34 require.

Children

Routee is not for people under 16 and we do not knowingly collect their data. If you believe a child has given us data, write to help@routee.link and we will remove it.

Changes

We may update this policy. Where a change affects what we do with data we already hold, we say so before it takes effect. The date at the top always tells you which version you are reading.

Veezio Solutions s.r.o. · Nové sady 988/2, Staré Brno, 602 00 Brno · IČO 23746068 · DIČ CZ23746068 · help@routee.link