PRIVACY NOTICE

Last updated: July 2026

1. Introduction

1.1 Who we are

This Privacy Notice explains how “Routeon” ( also  the “Company”, “we”, “us” or “our” in this Privacy Notice), collects, holds, processes, uses, discloses, transfers and protects personal data in the context of providing our services. We value your privacy and are committed to protecting and processing your personal information responsibly.

For personal data that Routeon collects and processes for its own purposes, Routeon determines the purposes and essential means of the processing and acts as the party responsible for that personal data.

The legal term used to describe this role may differ depending on the applicable law and may include “controller”, “data user”, “business” or another equivalent term.

For questions about this Privacy Notice, our personal data practices or your privacy rights, contact via  support@routeon.io.

1.2 Data processing covered by this Privacy Notice

This Privacy Notice applies to personal data processed in connection with:

  1. our URL shortening, custom-branded link, link-management, link-in-bio, QR-code and analytics products;
  2. our SMS routing and messaging platform, including the administrative dashboard and application programming interfaces;
  3. our transactional and bulk email routing and transmission services, including email delivery interfaces, domain authentication support, delivery reporting and email campaign analytics; 
  4. customer registration, verification and account administration;
  5. subscriptions, contracts, billing and payments;
  6. customer support and business communications; and
  7. the operation, security and improvement of our products and services.

Together, these are referred to as the “Services”.

1.3 Relationship with other documents

This Privacy Notice should be read together with:

  • our Terms of Service;
  • our Acceptable Use Policy;
  • any applicable order form or service agreement;
  • any applicable Data Processing Agreement or data processing terms; and
  • our Cookie Notice.

2. Our role in processing

The Services are provided on a business-to-business basis.

They are intended only for companies and other legal entities, organisations or individuals acting on behalf of a business or in a professional or commercial capacity.

A person who creates an account or uses the Services represents that they: 

  • are authorised to act on behalf of the relevant Client; and
  • will comply with the Terms of Service and Acceptable Use Policy.

We do not provide the Services to minors. A person must not register or use the Services unless they have reached the age of legal majority under the law applicable to them. We do not knowingly collect account registration data directly from minors.

2.1 Data user or data controller 

Routeon acts as the data user or controller where we determine the purposes for which, and the manner in which, personal data is processed.

This principally applies to personal data relating to:

  • Clients and prospective Clients;
  • representatives and authorised users of Clients;
  • business partners, resellers and suppliers;
  • persons who contact our support, commercial, legal or finance teams; and
  • persons who receive Routeon’s own business communications.

Certain information associated with the use of the Services may also be processed by Routeon for our own operational purposes, including:

  • account and platform security;
  • prevention of fraud, spam, phishing and abuse;
  • billing and usage calculation;
  • network and service-performance monitoring;
  • troubleshooting;
  • compliance with legal and regulatory obligations;
  • compliance with telecommunications-provider requirements;
  • investigation of suspected violations;
  • enforcement of our Terms of Service and Acceptable Use Policy; and
  • establishment, exercise or defence of legal claims.

For example, message-routing or link-interaction data may be processed on behalf of a Client to provide the requested service, while limited associated logs may be processed by Routeon for security, billing and abuse-prevention purposes.

This data is referred to in this Privacy Notice as “Clients’ Data”.

2.2 Personal data processed on behalf of Clients

When a Client uses the Services, it may submit, transmit, store or generate personal data relating to its customers, end users, message recipients, subscribers, website visitors or other individuals (“Client Customer Data”).

Depending on the applicable law, the Client acts as the data user, controller or other organisation responsible for Client Customer Data. Routeon acts as the Client’s contracted data processor or service provider and processes Client Customer Data in accordance with the Client’s instructions, the applicable agreement and the relevant Data Processing Agreement or data processing terms.

The Services are not designed for the processing of sensitive data. Clients and authorised users must not submit, upload, transmit, store or otherwise process Sensitive Data through the Services unless Routeon has expressly authorised the processing in writing and any applicable legal, contractual and security requirements have been satisfied.

This restriction does not apply to identity, verification or compliance information expressly requested by Routeon through an authorised process or designated secure channel.

Routeon processes Client Customer Data only as reasonably necessary to:

  • provide, operate, maintain, secure and support the Services;
  • route and deliver messages and provide link, QR-code and analytics functionality;
  • follow the Client’s lawful instructions;
  • calculate usage and charges;
  • detect and investigate fraud, spam, phishing, abuse and security threats;
  • comply with applicable law and valid legal requirements; and
  • enforce the Terms of Service and Acceptable Use Policy.

Where Routeon processes information associated with Client Customer Data for its own security, billing, legal-compliance or abuse-prevention purposes, Routeon is responsible for that processing in accordance with applicable law.

Where a Client uses the Email Services, Client Customer Data may include recipient email addresses, sender information, email subject lines and content, message identifiers, delivery information, bounce and complaint information, unsubscribe information and email engagement data, such as email opens and link clicks, where the relevant analytics functionality is enabled.

Routeon processes this data on behalf of the Client to route and transmit emails, provide delivery reporting, process delivery failures and complaints, support domain authentication and provide email campaign analytics.

Client is responsible for:

  • ensuring that it is lawfully entitled to collect Client Customer Data, provide it to Routeon and instruct Routeon to process it;
  • providing individuals with all privacy and marketing notices required by applicable law;
  • obtaining and maintaining any required consent, permission or other lawful authority;
  • responding to privacy requests and complaints relating to the Client’s processing;
  • determining the purpose, content, sender details and recipients of SMS, email and other Client communications;
  • determining the content, recipients, sender details and purpose of email communications;
  • ensuring that recipient contact lists have been collected and are used lawfully;
  • providing legally required unsubscribe or opt-out mechanisms;
  • honouring unsubscribe requests, objections and complaints;
  • ensuring that the Client is authorised to use the relevant sending domain;
  • configuring or authorising the configuration of SPF, DKIM and DMARC records, with technical support from Routeon where applicable;
  • complying with applicable privacy, telecommunications, electronic-messaging, direct-marketing and anti-spam requirements; and
  • complying with the Terms of Service and Acceptable Use Policy.

Routeon does not use Client recipient lists, Client-created SMS content or Client-created email content to send Routeon’s own marketing communications, create advertising profiles concerning recipients or market third-party products to them.

Subject to the applicable agreement and law, Routeon may generate aggregated or de-identified service-usage information where that information cannot reasonably be used to identify a Client, recipient or other individual. Routeon may use such information for security, analytics, capacity planning, service reporting and improvement of the Services and will not attempt to re-identify the individuals concerned.

Individuals whose personal data has been submitted to Routeon by a Client should normally direct privacy requests to that Client. Routeon will assist the Client with such requests as required under the applicable agreement or law.

This Privacy Notice does not replace the Client’s own privacy notice. Clients are responsible for explaining their processing of Customer Data to the individuals concerned.

3. Categories of data we collect and purposes of processing

The personal data we collect depends on your relationship with us and how you use the Services.

3.1 Account and business contact data

This category may include:

  • name;
  • business email address and telephone number;
  • employer or organisation;
  • job title and business role;
  • username, account identifier, authentication information;
  • designated technical, finance and commercial contacts; and
  • communication preferences.

We use this data to onboard you, communicate with you, manage our business relationships and provide access to the Services, to provide information about Services, features, events and related business-to-business technology products.

3.2 Verification and compliance data

Where required for Client onboarding, risk management or legal compliance, this category may include:

  • identity documents;
  • proof of address;
  • company registration documents;
  • registered-office information;
  • ownership and control information;
  • beneficial ownership information;
  • sanctions-screening results;
  • fraud-prevention information; and
  • other KYC, KYB, AML or compliance information.

We use this data to verify Clients and their representatives, to assess fraud, sanctions and compliance risks, prevent unlawful or prohibited use of the Services and comply with legal or regulatory requirements.

3.3 Contract, subscription and payment data

This category may include:

  • Client and contracting-party details;
  • order and subscription information;
  • selected service plan;
  • contract and negotiation records;
  • billing address;
  • invoices and tax information;
  • payment status;
  • account balance and usage records;
  • transaction references;
  • refund and dispute information; and
  • cryptocurrency wallet and transaction information, where cryptocurrency payments are supported.

We use this data to prepare, enter into and perform contracts, administer trials and subscriptions, process payments and refunds, maintain accounting and tax records; and resolve contractual or payment disputes.

Payment credentials may be collected directly by a payment provider. We may receive limited information such as the payment status, payment method and transaction reference.

3.4 Support and communications data

This category may include:

  • enquiries and correspondence;
  • support tickets;
  • problem descriptions;
  • screenshots and files;
  • technical information provided for troubleshooting;
  • records of proposed or completed solutions; and
  • communications with our support, commercial, finance and legal teams.

We use this data to respond to enquiries, provide technical and customer support, investigate and resolve problems, monitor service quality, and improve our support processes.

You should not include unnecessary personal data, sensitive data or confidential third-party information in support requests.

3.5 Service usage and analytics data

This category may include:

  • features used;
  • Dashboard activity;
  • API activity;
  • subscription and traffic volumes;
  • message-delivery statistics;
  • link and QR-code usage statistics;
  • service configuration;
  • date and time of activities;
  • performance and diagnostic information;
  • email transmission and delivery statistics;
  • delivery failures and bounce information;
  • unsubscribe and complaint information;
  • sender-domain authentication status; and
  • email open and link-click statistics, where analytics are enabled.

We use this data to provide the Services, provide usage and delivery reports, calculate fees, monitor service performance, troubleshoot technical issues, understand how the Services are used,improve the functionality and usability of the Services and create aggregated or de-identified business statistics.

3.6 Technical, security and website data

This category may include:

  • IP address;
  • browser and device information;
  • operating system;
  • login and session records;
  • authentication events;
  • security and audit logs;
  • error and diagnostic records;
  • cookies and similar identifiers;
  • suspected fraud, spam, phishing, bot or abuse indicators.

We use this data to operate and secure our Platform and Dashboard, to detect unauthorised access, prevent fraud, spam, phishing and other misuse, diagnose errors, investigate issues, and comply with legal and regulatory requirements.

4. Sources of personal data 

We may collect personal data  from the following sources, depending on your relationship with us and the Services you use:

  • directly from you, including when you create or administer an account, enter into a contract, use our Platform or Dashboard, make a payment, complete a verification process, or communicate with us;
  • from the Client or organisation you represent, including from an account owner or another authorised user who creates an account for you, designates you as a contact, or grants you access to the Services;
  • automatically through your use of our website and Services, including through cookies, server logs, security logs, Dashboard activity and similar technologies;
  • from service providers involved in our relationship with you, such as payment providers, identity or business-verification providers, fraud-prevention providers and telecommunications or routing providers, where relevant to the Services; and
  • from business partners or publicly available business sources, where relevant to an existing or prospective business relationship and permitted by applicable law.

We collect information from a particular source only where it is reasonably necessary for the purposes described in this Privacy Notice.

Where you provide us with personal data relating to another person, you are responsible for ensuring that you are authorised to provide that information and, where required, that the person has received appropriate privacy information.

8. Mandatory and optional personal data

Where we ask you to provide personal data, we will indicate whether the requested information is mandatory or optional.

Personal data may be mandatory where it is reasonably necessary to:

  • verify your identity, authority or eligibility as a Client representative or authorised user, where verification is required;
  • enter into or perform an agreement with the Client;
  • provide access to a requested Service or feature;
  • process payments and administer billing; or
  • respond to a support request or other enquiry submitted by you.

If you do not provide mandatory personal data, we may be unable to:

  • create or maintain the relevant account;
  • verify your identity or authority;
  • enter into or perform the relevant agreement;
  • provide the requested Service or feature;
  • process a payment or transaction; or
  • respond fully to your request.

All other personal data is provided voluntarily unless we inform you otherwise at the time of collection. If you do not provide optional information, this will not generally affect the Client’s access to the Services, although a particular optional feature, request or communication may not be available.

Providing personal data for Routeon’s direct-marketing purposes is voluntary and  subject to your consent. Refusing to provide such data  will not affect the Client’s contractual relationship with Routeon or access to the Services.

Certain technical, usage, security and transaction data may be generated or collected automatically when the website or Services are used. 

9. With whom we share personal data

We disclose personal data only where reasonably necessary for the purposes described in this Privacy Notice, where we are authorised to do so, or where disclosure is required or permitted by law.

Recipients of data may include:

  • service providers supporting hosting, infrastructure, security, authentication, payments, billing, customer support, communications, analytics and business verification;
  • telecommunications, messaging and email-delivery providers, including mobile network operators, SMS aggregators, email-routing providers, mailbox providers and other providers involved in transmitting and delivering Client communications; 
  • professional advisers, including lawyers, auditors, accountants, tax advisers, consultants and insurers;
  • entities within our corporate group, where necessary for administration, support, security, finance, compliance or operation of the Services;
  • courts, regulators, law-enforcement bodies and other competent authorities, where disclosure is required or permitted by law or necessary to respond to valid legal process; and
  • parties involved in a corporate transaction, such as prospective buyers, investors, successors and their advisers, subject to appropriate confidentiality safeguards.

We do not sell personal data or provide it to third parties for their own direct-marketing purposes.

Where a service provider processes personal data on our behalf, we use contractual or other appropriate measures to require it to:

  • process the data only for agreed purposes and in accordance with our instructions;
  • maintain appropriate confidentiality and security;
  • protect the data against unauthorised or accidental access, processing, loss, erasure or use; and
  • retain the data only for as long as necessary.

10. Marketing

Where applicable law requires consent, we will not use personal data for direct marketing unless:

  • we have notified the you of our intention to use the data for direct marketing;
  • we have identified the kinds of personal data to be used;
  • we have identified the classes of products or services to be marketed;
  • we have provided a channel through which the individual can communicate consent or an indication of no objection; and
  • we have received the required consent or indication of no objection.

Where necessary, we will obtain this consent through a separate registration, subscription or marketing-consent mechanism.

You may ask us at any time, and without charge, to stop using your personal data for direct marketing by:

  • using the unsubscribe link in a marketing email; or
  • contacting us at  support@routeon.io.

Clients are independently responsible for the legality of all SMS, email and other marketing or communications campaigns conducted through the Services, including obtaining any required consent or other lawful authority, providing appropriate notices and opt-out mechanisms, and honouring unsubscribe requests and objections. 

11. Cross-border  data transfers

We operate internationally. Personal data may therefore be transferred to, stored in or accessed from countries outside the country in which the relevant individual is located.

Where appropriate, we use contractual, technical and organisational measures designed to protect personal data transferred or accessed internationally.

These measures may include:

  • contractual confidentiality and data-protection obligations;
  • due diligence concerning service providers;
  • information-security requirements;
  • access restrictions;
  • encryption;
  • data minimisation;
  • audit or review rights; and
  • recognised contractual transfer safeguards where required by applicable law.

12. Data retention

We retain personal data only for as long as necessary to fulfil the purpose for which it was collected or a directly related purpose, or as otherwise required or permitted by applicable law.

The periods for which we retain Clients’ data  depend on factors including:

  • the nature and purpose of the data;
  • the duration of our relationship with the Client;
  • applicable contractual, legal, regulatory, tax and accounting requirements;
  • relevant limitation periods;
  • security, fraud-prevention and dispute-resolution needs;and
  • backup and disaster-recovery cycles.

Clients’ data  may be retained after the end of a Client relationship where necessary to comply with legal obligations, maintain financial or transaction records, resolve complaints or disputes, investigate fraud or security incidents, enforce our agreements, or establish, exercise or defend legal claims.

Where Routeon processes Customer Data on behalf of a Client, we retain it in accordance with the applicable agreement, the Client’s lawful instructions, the selected account configuration and available retention settings.

We may retain limited information associated with Clients Customer Data for our own billing, security, fraud-prevention, compliance or legal purposes where permitted by applicable law. In such cases, Routeon is responsible for that retention.

When personal data is no longer required, we take all practicable steps to securely delete, destroy or irreversibly anonymise it.

13. Data security

We implement technical and organisational measures designed to protect personal data. Depending on the nature of the personal data and the Services, these measures may include:

  • role-based and least-privilege access controls;
  • authentication controls;
  • encryption in transit and, where appropriate, at rest;
  • network and infrastructure protections;
  • logging and monitoring;
  • vulnerability management;
  • secure backup and recovery processes;
  • incident-response procedures;
  • personnel confidentiality obligations;
  • security and privacy training; and
  • contractual security requirements for service providers.

No online service, network or storage system can be guaranteed to be completely secure.

Clients and authorised users are responsible for:

  • keeping login credentials confidential;
  • protecting API keys and authentication tokens;
  • managing account permissions;
  • securing their own devices, systems and integrations;
  • configuring the Services appropriately; and
  • promptly notifying us of suspected unauthorised access or security incidents.

14. Cookies and similar technologies

We may use cookies, local storage and similar technologies for:

  • authentication;
  • maintaining user sessions;
  • account and platform security;
  • remembering settings;
  • operating the Services;
  • fraud and abuse prevention;
  • service and website analytics;
  • performance monitoring; and
  • marketing where permitted by law.

Where required by applicable law, we will request consent before using non-essential cookies or similar technologies.

You may control cookies through:

  • your browser settings;
  • any cookie-management controls that we provide; and
  • the choices described in our Cookie Notice.

15. Your Privacy Rights

Privacy and data protection rights differ depending on the country, territory or state in which an individual is located and the law applicable to the processing.

  • Right of access – to obtain a copy of your personal data and understand how it is used.
  • Right to rectification – to correct any inaccurate or incomplete data.
  • Right to erasure – to request deletion of your personal data, where permitted by law.
  • Right to restriction – to limit processing in specific cases.
  • Right to object – to certain types of processing, including direct marketing.
  • Right to data portability – to receive a copy of your data in a structured format.
  • Right to withdraw consent – at any time, where processing is based on consent.
  • Right to lodge a complaint – with a supervisory authority in your jurisdiction.

16.  Submitting a request

To exercise privacy rights,  please contact us via  support@routeon.io.

We may request information reasonably necessary to:

  • verify your identity;
  • verify the authority of your representative;
  • identify the relevant account or records;
  • understand the scope of the request;
  • determine the law applicable to the request; and
  • determine whether the data is controlled by Routeon or by a Client.

We will respond within the period required by applicable law.

Where permitted by law, we may charge a reasonable fee that is not excessive for processing a data access request.

A request may be refused or restricted where permitted by applicable law, including where:

  • the requester’s identity or authority cannot be verified;
  • insufficient information has been provided;
  • disclosure would reveal another person’s personal data;
  • disclosure would breach confidentiality obligations;
  • legal professional privilege applies;
  • an applicable statutory exemption applies; or
  • compliance is otherwise not legally required.

Where Routeon processes personal data on behalf of a Client, the Client ordinarily controls that data and is responsible for responding to privacy requests concerning it.

Where we receive a request concerning Client Customer Data, we may:

  • ask the individual to identify the relevant Client;
  • refer the individual to the Client;
  • notify the Client of the request;
  • request instructions from the Client;
  • assist the Client in responding; or
  • respond directly where required by applicable law.

We will not independently amend or delete Client Customer Data where doing so would conflict with the Client’s lawful instructions, unless applicable law requires otherwise.

17. Changes to this Privacy Notice

We may update this Privacy Notice from time to time to reflect:

  • changes to the Services;
  • changes to our personal data practices;
  • changes to legal or regulatory requirements;
  • security developments; or
  • changes to our business operations.

The updated version will be published with a revised “Last updated” date.

Where a change materially affects how we process personal data, we may provide additional notice through email or  another appropriate communication channel.