Privacy Policy
Last updated: August 2026 · GDPR / AVG compliant
01.Legal basis & controller identification
ROUT is operated as an independent developer infrastructure project by an individual creator, established in Brussels, Belgium (EU). The creator acts as the data controller for all processing described here. The architecture is zero-trust by design: local execution first, data minimisation throughout, and absolute transparency about what leaves your device.
Contact channel for all privacy matters: contact@rout.be. Statutory response timeline: we answer data subject requests within one calendar month, in line with Article 12 GDPR.
Primary supervisory authority: Gegevensbeschermingsautoriteit (GBA) / Autorité de protection des données (APD), Drukpersstraat 35, 1000 Brussels, Belgium.
02.Static QR codes — absolute zero-data architecture
Static QR codes are compiled and generated entirely client-side, inside your browser's local sandbox. Payload contents — URLs, vCards, Wi-Fi keys, IBAN strings — never touch ROUT servers, are never intercepted, and generate zero server-side logs or residual telemetry. Nothing is uploaded, so there is nothing for us to store, disclose, or lose.
03.Dynamic routing, short links & anonymous analytics
- Contractual necessity (Art. 6(1)(b) GDPR): we process destination URLs solely to execute the redirects you requested.
- Legitimate interest (Art. 6(1)(f) GDPR): collection of coarse, strictly anonymised scan metadata — timestamp, country-level geolocation, and device category family.
- Strict privacy guarantees: full visitor IP addresses are never logged or stored. Visitor browser fingerprinting is explicitly disabled. Advertising profiling and cross-site tracking are fundamentally omitted.
- Transport-layer transparency: while browser-based QR generation is 100% local and zero-knowledge, dynamic link and profile hub resolution (rout.id / rout.be) necessarily passes through network nodes. Standard transport metadata (IP address, User-Agent) is processed in-memory strictly for real-time routing and immediate DDoS mitigation, with zero long-term retention and no advertising fingerprinting.
- Data lifecycle: scan analytics are tied directly to the lifecycle of the dynamic link — purging or deleting a link instantly erases its aggregated statistics.
04.Authentication, user accounts & OAuth federation
- Account data: email addresses, secure password hashes (where applicable), and user profile configurations.
- External SSO handlers: when authenticating via external identity providers (such as GitHub, Google, Apple, GitLab, or a custom OIDC provider), ROUT securely ingests only the necessary baseline identifiers — email and display name — for active session maintenance.
- Identity / payment decoupling: sovereign profile management (WebAuthn passkeys, custom OIDC via Keycloak or Authentik) is kept strictly separate from regulated fiat payment gateways (SEPA, PayPal, Venmo). Financial verification data is processed independently by PCI-DSS compliant providers and is never joined to your decentralised identity records.
- Session integrity: essential authentication state is maintained via isolated secure cookies and local storage tokens. Zero commercial tracking pixels or third-party analytics scripts exist on authenticated endpoints.
05.Custom domains & infrastructure routing
When end-users route traffic through custom domains linked to ROUT, core proxy and routing metadata are handled strictly for high-precision redirection and SSL termination. Visitor IP tracking on custom domain zones is disabled to preserve user sovereignty.
06.Programmatic access, API keys & rate limiting
API interactions generate minimal technical access logs — timestamp, endpoint URI, response status, and rate-limiting counters — retained exclusively for infrastructure security, defence against DDoS attacks, and API stability enforcement.
07.Micro-payments, verification fees & financial data
Financial transactions for account verification or premium routing tiers are processed securely through certified, PCI-DSS compliant third-party payment gateways. ROUT does not store raw credit card credentials, IBAN mandates or other sensitive financial instruments on its own infrastructure.
Strict separation: the billing record required by accounting law lives in a distinct processing context from your handle, passkeys and published profile data. Regulated payment identity is never merged into, exported with, or used to enrich sovereign identity records.
08.Sovereign infrastructure & hosting (EU)
All user state and relational configurations are stored within European Economic Area (EEA) data centres on managed PostgreSQL infrastructure, under a strict Data Processing Agreement (DPA) featuring encryption in transit and at rest.
Residency commitment: primary databases, automated backups and routing proxies all operate inside the EEA. No production personal data is replicated to jurisdictions subject to extraterritorial surveillance frameworks such as the US CLOUD Act.
09.Enforceable data subject rights (GDPR Chapter III)
Engineered for absolute digital sovereignty.
Generate high-precision, zero-tracking QR codes instantly.
Open Generator