← Back to ClearRoute

Privacy Policy

Effective: June 5, 2026

Terms of Service PCI DSS Compliance

ClearRoute LLC ("ClearRoute," "we," "us") operates a payment routing SaaS. This Privacy Policy explains how we collect, use, and protect information about you when you use our website and service at myclearroute.polsia.app (the "Service").

1. Information We Collect

1.1 Account Information

When you register, we collect:

  • Name and email address
  • Bcrypt-hashed password
  • Billing name and address (processed by Stripe)
  • Stripe customer and subscription IDs

1.2 PSP Configuration Data

When you configure a Payment Service Provider, you submit:

  • PSP name and provider type
  • PSP API keys and credentials (encrypted at rest)
  • Performance thresholds and routing weight preferences

1.3 Transaction and Routing Data

When you use the routing service, we process and store:

  • Transaction IDs and amounts
  • Selected PSP, routing cost, and latency for each decision
  • Routing agent decision logs (scores, reasons, outcomes)
  • Routing logs are scoped to your customer_id and are not accessible to other users

We do not store full card numbers, CVV, or cardholder names. These data elements, if present in transaction metadata, are handled exclusively by your PSP and are not retained by ClearRoute.

1.4 Technical Data

When you visit our website, we collect:

  • IP address (retained 90 days)
  • Browser type and version
  • Pages visited and timestamp
  • Unique visitor identifier (stored in localStorage)

1.5 Payment Data

All payment processing is handled by Stripe. ClearRoute does not store, process, or have access to your payment card numbers, CVV, or Stripe API keys. Stripe's privacy policy applies to payment data: stripe.com/privacy.

2. How We Use Information

We use collected information to:

  • Provide, operate, and improve the routing service
  • Authenticate you and manage your account
  • Process billing and manage subscriptions via Stripe
  • Generate routing logs and analytics for your dashboard
  • Detect and respond to security incidents
  • Comply with legal obligations

3. Data Retention

We retain data as follows:

Data Type Retention Period
Account information Until account deletion + 90 days
Transaction routing logs 12 months from date of routing decision
PSP credentials Until PSP removed from account + 30 days
Website visitor analytics 90 days
Billing records 7 years (tax compliance)
Security logs 1 year

Upon account deletion, we delete all personal data within 90 days except billing records (retained 7 years per tax law) and as required for legal holds.

4. Data Sharing

We do not sell, rent, or trade your personal data. We share data only in these cases:

  • PSP Integrations: Your PSP API keys and transaction data are shared with your configured PSPs to execute routing decisions.
  • Stripe: Billing and subscription data is shared with Stripe for payment processing.
  • Service Providers: We use infrastructure providers (Render, Neon PostgreSQL) to host the service. These providers are contractually bound to protect your data.
  • Legal Requirements: We may disclose data if required by law, court order, or governmental regulation, or if disclosure is necessary to protect our rights, safety, or the public.

5. Data Security

We implement the following security measures:

  • All data in transit encrypted via TLS 1.2+
  • PSP API keys encrypted at rest (AES-256)
  • Passwords hashed with bcrypt (cost factor 12)
  • Role-based access control — all routes are customer_id scoped; cross-account access is structurally impossible
  • PCI DSS compliance as described in our PCI DSS statement
  • Annual security review

6. Cookies and Tracking

We use one functional first-party cookie:

  • Session cookie: Stores an encrypted session identifier for authentication. Expires when you log out or after 7 days of inactivity.

We also use a first-party analytics beacon (localStorage-based) to track unique visitors to our website. This does not track individual behavior across sessions and is not used for advertising.

You may disable cookies in your browser; the site will still function but you will need to re-authenticate on each session.

7. Your Rights

Depending on your jurisdiction, you may have the following rights:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate data.
  • Deletion: Request deletion of your account and data (subject to billing record retention requirements).
  • Portability: Request your data in a structured, machine-readable format.
  • Object to processing: Opt out of certain uses (note: some processing is required to provide the service).

To exercise any of these rights, email privacy@clearroute.app. We respond to all verifiable requests within 30 days.

8. International Data Transfers

Data is stored in Neon PostgreSQL (AWS us-east-1). If you are located outside the United States, your data will be processed in the US. We rely on standard contractual clauses approved by the European Commission for any cross-border transfers of EU resident data.

9. Children's Privacy

The Service is not intended for users under 18. We do not knowingly collect personal data from children.

10. Changes to This Policy

We may update this Privacy Policy periodically. Changes will be posted at /legal/privacy. For material changes, we will notify you via the email associated with your account 30 days before the change takes effect.

11. Contact

ClearRoute LLC
Email: privacy@clearroute.app
Website: myclearroute.polsia.app
Note: This Privacy Policy is a template and has not been reviewed by legal counsel. It should be reviewed and customized by a qualified attorney before ClearRoute enters into binding agreements with paying customers. Legal entity formation is pending.