Privacy Policy
How we collect, use, and protect your data
Data Controller
Redirections ("we", "us", "our") operates the redirections.app platform. We are the data controller for the personal data processed through our service.
For any privacy-related inquiries, contact us at privacy@redirections.app.
What Data We Collect
Account Data
When you create an account, we collect data through our authentication provider (Clerk): your email address, name, and profile image. Functional copies of this data are maintained in our database for service operation such as team member display and audit logs.
Usage Data
We collect activity logs related to your use of the platform, including actions performed (rule creation, deployments, settings changes) and associated timestamps.
Communication Data
If you contact us through the enterprise contact form, we collect your email address, name, company name, and message content.
Technical Data
- PostHog analytics: cookieless by default; cookies set only with your explicit consent. Hosted in EU (Frankfurt).
- Cloudflare edge metrics: country and region-level data for performance monitoring. City-level data is omitted for EU visitors.
Third-Party Processors
We share data with the following processors to deliver our service:
| Processor | Purpose | Location | Safeguards |
|---|---|---|---|
| Clerk | Authentication | US | Standard Contractual Clauses (SCCs) |
| PostHog | Analytics | EU (Frankfurt) | EU hosting |
| Cloudflare | CDN & edge computing | Global | EU-compliant measures |
| Resend | Transactional email | EU | EU hosting |
| Stripe | Billing & payments | US | Standard Contractual Clauses (SCCs) |
Legal Basis for Processing
| Basis | Applies To |
|---|---|
| Consent | Analytics cookies (PostHog tracking with cookies) |
| Contract | Service delivery, account management, billing |
| Legitimate interest | Security monitoring, audit logs, abuse prevention |
| Legal obligation | Billing records retention, tax compliance |
How We Use Your Data
- Operating and maintaining the redirect management service
- Authenticating your identity and managing your account
- Processing payments and managing your subscription
- Analyzing usage patterns to improve the service (with consent for cookie-based analytics)
- Maintaining security and preventing abuse
- Providing customer support
- Sending transactional emails (account notifications, billing receipts)
Data Retention
| Data Type | Retention Period |
|---|---|
| Account data | Duration of account + 30 days after deletion |
| Analytics data | 1 year |
| Billing records | 7 years (legal obligation) |
| Enterprise leads | 2 years |
| Audit logs | Duration of account + 30 days |
Your Rights (GDPR)
Under the General Data Protection Regulation, you have the following rights regarding your personal data:
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: request correction of inaccurate personal data.
- Right to erasure: request deletion of your personal data.
- Right to restriction: request that we limit processing of your data.
- Right to data portability: receive your data in a structured, machine-readable format.
- Right to object: object to processing based on legitimate interest.
- Right to withdraw consent: withdraw consent for analytics cookies at any time via the cookie banner.
- Right to lodge a complaint: file a complaint with your local data protection supervisory authority.
To exercise any of these rights, contact us at privacy@redirections.app. We will respond within 30 days.
International Data Transfers
- Clerk and Stripe process data in the US under Standard Contractual Clauses (SCCs).
- PostHog processes data within the EU (Frankfurt).
- Cloudflare processes data globally with EU-compliant data protection measures.
Security
We implement appropriate technical and organizational measures to protect your personal data, including encryption of data in transit (TLS), access controls, and regular security reviews.
Contact
For privacy-related inquiries or to exercise your data rights, contact us at privacy@redirections.app. We aim to respond within 30 days of receiving your request.
Changes to This Policy
We may update this privacy policy from time to time. Material changes will be communicated through the service or by email. The updated policy will be effective as of the date indicated at the top of this page.