1. Overview and Data Controller
CiteRoute ("we," "us," or "our") provides a Generative Engine Optimization (GEO) platform, AI crawler telemetry analytics, and agent manifest tools accessible via citeroute.com. We are committed to protecting your privacy and handling your personal data in an open, transparent, and legally compliant manner.
For the purposes of applicable data protection legislation (including the General Data Protection Regulation (EU) 2016/679, the UK Data Protection Act, the California Consumer Privacy Act, and Rwandan Law No. 058/2021 relating to the protection of personal data and privacy), the Data Controller is:
CiteRoute Operations
Location: Kigali, Rwanda
Contact Email: tuyishime1angel@gmail.com
2. Information We Collect
We collect information directly from you when you register an account, interact with our services, or configure monitoring for your domains.
- Account Information: When you register an account, we collect your name, email address, hashed passwords, and profile details. If you authenticate via third-party OAuth providers (such as GitHub or Google), we receive your verified email address and public profile identifier.
- Domain Audit and Manifest Data: When you run a GEO audit or generate an agent.json manifest, we record the queried public domain name, technical metadata, structured schema, and the calculated scores.
- Telemetry and Tracking Tag Data: If you install our lightweight tracking script on your verified websites, our servers receive telemetry signals. This includes the visiting user-agent string (to identify search crawlers and AI bots), request timestamps, referrer headers, and requested URLs. We do not use fingerprinting techniques, and we do not track individuals across third-party websites.
- API Usage Data: If you use CiteRoute developer API keys, we record request volume, endpoint paths, response statuses, and rate limit metrics to protect platform stability.
- Technical and Log Data: We automatically log standard server logs, including your internet protocol (IP) address, browser type, operating system, device characteristics, and timestamped activity on our web application.
3. Payment Information and Merchant of Record
Paid subscriptions (including Pro and Agency plans) are processed through our trusted payment infrastructure partner, Lemon Squeezy, acting as our Merchant of Record.
When you purchase a subscription or initiate a checkout transaction:
- All payment transactions, credit card data, bank information, billing addresses, and tax collection (VAT, GST, sales tax) are managed directly by Lemon Squeezy in full compliance with PCI-DSS standards.
- CiteRoute does not capture, store, or have direct access to your credit card numbers or bank credentials.
- We retain only anonymized customer identifiers, subscription IDs, subscription status (for example: active, cancelled, past due), and billing renewal dates transmitted to us by Lemon Squeezy via secure webhooks.
4. Legal Bases for Processing (GDPR / Global Standards)
We process your personal data under the following recognized legal bases:
- Performance of a Contract: Processing necessary to provide the services you requested, administer your account, and manage your subscription entitlements.
- Legitimate Interests: Processing necessary to secure our platform against fraud, debug technical errors, improve algorithm accuracy, analyze aggregate platform usage, and prevent abuse.
- Compliance with Legal Obligations: Processing necessary to meet statutory financial, tax, corporate reporting, and lawful audit requirements.
- Consent: Where you have provided specific and informed consent, such as opting into marketing emails or optional notifications. You may revoke consent at any time.
5. Sub-Processors and Data Sharing
We never sell, rent, or trade your personal data. We disclose information only to service providers (sub-processors) essential to delivering our services:
| Partner / Sub-Processor | Role / Purpose | Data Handled |
|---|---|---|
| Lemon Squeezy | Merchant of Record, checkout, invoicing, tax | Payment details, billing address, tax info |
| Vercel Inc. | Cloud hosting and serverless execution | Server access logs, incoming IP addresses |
| Turso (ChiselStrike) | Managed database infrastructure | Encrypted user records, scan results, telemetry |
| Resend | Transactional email delivery | Email address, system alert payloads |
6. Cookies and Local Storage
We adhere to a strict data minimization philosophy:
- Strictly Necessary Cookies: We use an encrypted HTTP-only session cookie to maintain your authenticated login state securely.
- Functional Local Storage: We use browser local storage to save your UI preferences (such as dark mode preferences and active dashboard filters).
- Third-Party Tracking Cookies: We do not deploy invasive third-party cross-site advertising trackers or sell browsing profiles to data brokers.
7. Your Privacy Rights
Depending on your jurisdiction, you hold specific statutory rights regarding your personal information:
- Right of Access: You may request a confirmation of whether we process your data, alongside a copy of that data.
- Right to Rectification: You may request the immediate correction of inaccurate or incomplete personal information.
- Right to Erasure (Right to Be Forgotten): You may request that we permanently delete your account and associated personal data.
- Right to Data Portability: You may request an export of your account data in a structured, commonly used, machine-readable format.
- Right to Object: You may object to any data processing conducted on the grounds of legitimate interest.
To exercise any of these rights, please email us directly at tuyishime1angel@gmail.com. We respond to all verified requests within thirty (30) days without cost.
8. Data Retention and Security
We implement robust administrative, technical, and physical security measures to safeguard your personal data. All data transfers across public networks use Transport Layer Security (TLS 1.3) encryption. Passwords are salted and hashed using industry-standard bcrypt algorithms.
We retain account data for as long as your account remains active. Telemetry data and scan logs are retained in aggregate form to calculate historical benchmark scores. If you delete your account, your personal identifying records are purged from active production databases within thirty (30) days.
9. International Data Transfers
Because our platform operates globally using cloud infrastructure, your information may be transferred to and processed in servers located outside your home country. We ensure that all cross-border data transfers comply with statutory requirements, incorporating standard contractual clauses and rigorous vendor vetting.
10. Updates to This Policy
We may revise this Privacy Policy periodically to reflect technological advances, product developments, or legal updates. Any material changes will be communicated via notice on our website or through email notification to your registered address prior to becoming effective.
11. Contact Information
For questions, concerns, or requests regarding this Privacy Policy or our data handling practices, please contact us at:
CiteRoute Legal and Privacy
Email: tuyishime1angel@gmail.com
Location: Kigali, Rwanda