ClearRoute LLC ("ClearRoute," "we," "us") operates a payment routing SaaS. This Privacy Policy explains how we collect, use, and protect information about you when you use our website and service at myclearroute.polsia.app (the "Service").
1. Information We Collect
1.1 Account Information
When you register, we collect:
- Name and email address
- Bcrypt-hashed password
- Billing name and address (processed by Stripe)
- Stripe customer and subscription IDs
1.2 PSP Configuration Data
When you configure a Payment Service Provider, you submit:
- PSP name and provider type
- PSP API keys and credentials (encrypted at rest)
- Performance thresholds and routing weight preferences
1.3 Transaction and Routing Data
When you use the routing service, we process and store:
- Transaction IDs and amounts
- Selected PSP, routing cost, and latency for each decision
- Routing agent decision logs (scores, reasons, outcomes)
- Routing logs are scoped to your customer_id and are not accessible to other users
We do not store full card numbers, CVV, or cardholder names. These data elements, if present in transaction metadata, are handled exclusively by your PSP and are not retained by ClearRoute.
1.4 Technical Data
When you visit our website, we collect:
- IP address (retained 90 days)
- Browser type and version
- Pages visited and timestamp
- Unique visitor identifier (stored in localStorage)
1.5 Payment Data
All payment processing is handled by Stripe. ClearRoute does not store, process, or have access to your payment card numbers, CVV, or Stripe API keys. Stripe's privacy policy applies to payment data: stripe.com/privacy.
2. How We Use Information
We use collected information to:
- Provide, operate, and improve the routing service
- Authenticate you and manage your account
- Process billing and manage subscriptions via Stripe
- Generate routing logs and analytics for your dashboard
- Detect and respond to security incidents
- Comply with legal obligations
3. Data Retention
We retain data as follows:
| Data Type |
Retention Period |
| Account information |
Until account deletion + 90 days |
| Transaction routing logs |
12 months from date of routing decision |
| PSP credentials |
Until PSP removed from account + 30 days |
| Website visitor analytics |
90 days |
| Billing records |
7 years (tax compliance) |
| Security logs |
1 year |
Upon account deletion, we delete all personal data within 90 days except billing records (retained 7 years per tax law) and as required for legal holds.
4. Data Sharing
We do not sell, rent, or trade your personal data. We share data only in these cases:
- PSP Integrations: Your PSP API keys and transaction data are shared with your configured PSPs to execute routing decisions.
- Stripe: Billing and subscription data is shared with Stripe for payment processing.
- Service Providers: We use infrastructure providers (Render, Neon PostgreSQL) to host the service. These providers are contractually bound to protect your data.
- Legal Requirements: We may disclose data if required by law, court order, or governmental regulation, or if disclosure is necessary to protect our rights, safety, or the public.
5. Data Security
We implement the following security measures:
- All data in transit encrypted via TLS 1.2+
- PSP API keys encrypted at rest (AES-256)
- Passwords hashed with bcrypt (cost factor 12)
- Role-based access control — all routes are customer_id scoped; cross-account access is structurally impossible
- PCI DSS compliance as described in our PCI DSS statement
- Annual security review
6. Cookies and Tracking
We use one functional first-party cookie:
- Session cookie: Stores an encrypted session identifier for authentication. Expires when you log out or after 7 days of inactivity.
We also use a first-party analytics beacon (localStorage-based) to track unique visitors to our website. This does not track individual behavior across sessions and is not used for advertising.
You may disable cookies in your browser; the site will still function but you will need to re-authenticate on each session.
7. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate data.
- Deletion: Request deletion of your account and data (subject to billing record retention requirements).
- Portability: Request your data in a structured, machine-readable format.
- Object to processing: Opt out of certain uses (note: some processing is required to provide the service).
To exercise any of these rights, email privacy@clearroute.app. We respond to all verifiable requests within 30 days.
8. International Data Transfers
Data is stored in Neon PostgreSQL (AWS us-east-1). If you are located outside the United States, your data will be processed in the US. We rely on standard contractual clauses approved by the European Commission for any cross-border transfers of EU resident data.
9. Children's Privacy
The Service is not intended for users under 18. We do not knowingly collect personal data from children.
10. Changes to This Policy
We may update this Privacy Policy periodically. Changes will be posted at /legal/privacy. For material changes, we will notify you via the email associated with your account 30 days before the change takes effect.
11. Contact
Note: This Privacy Policy is a template and has not been reviewed by legal counsel. It should be reviewed and customized by a qualified attorney before ClearRoute enters into binding agreements with paying customers. Legal entity formation is pending.