Skip to content

Legal

Privacy policy

This is a draft and requires legal review before launch. It was written to be honest and usable rather than to be comprehensive, and it has not been checked by a solicitor. It is not in force, because the service is not yet being sold.

If you are relying on this for a real decision, write to [email protected] and ask us where it stands.

Last updated . A UK company is being incorporated to operate this product

What QubeRoute collects, why, where it is kept, and what you can ask us to do about it. Written to be read rather than to be complete, though we have tried to make it both.

1. Who is responsible

QubeRoute is in the process of being incorporated as a UK limited company. Until that is complete there is no company to name, and the founder of QubeRoute is the data controller personally. This page will be updated with the company name, registered number and registered office as soon as they exist, and we will say so on this page rather than changing it quietly. Write to [email protected] with anything about this policy, including a request to exercise your rights.

2. Where your data is

In the United Kingdom. The database is in London and it is the only place customer data is stored. Every service we add has to be able to process data in the UK or EU, or we do not use it. The current list is at /legal/sub-processors.

3. What we collect about you, as a customer

  • Your name and email address, because an account needs to belong to somebody and we have to be able to send you a password reset.
  • A hash of your password. Not your password — we cannot recover it, only check one you give us against the hash.
  • Your two-factor secret, encrypted, if you switch it on.
  • Session records, so you can be signed out everywhere when you change your password. These hold a hash of the session token, a hash of the address you signed in from, and your browser’s user agent string.
  • An audit log of security-relevant actions: sign-ins, failed sign-ins, password and address changes, key creation and revocation, and membership changes.
  • What you enter about your apps — names, bundle identifiers, Team IDs and link configuration.

4. What we collect about the people who follow your links

This is the part that matters most, because those people never agreed to anything with us.

  • We never store an IP address. An IP address is personal data under UK GDPR. We need to tell one visitor from another for rate limiting and click counting; we do not need to know who they are. Addresses are salted and hashed the moment they arrive and the raw value is never written to disk — not in a log file, not in an error report, not in a trace.
  • No cross-site tracking. We set no advertising identifiers, run no third-party trackers, and build no profile of anyone across sites or apps.
  • When somebody follows a link we record which link it was, roughly when, the platform, and the country where a network has already told us. That is what a click count is made of.
  • We may write one random value onto that person’s clipboard, and doing so replaces whatever was on it. This happens only for customers who have switched clipboard matching on, only on the way to an app store, and the value identifies nothing about the person — it is a random token that names a click. Their device will ask them before any app reads it back, and they can refuse. We never read a clipboard from a web page, and the app SDK discards anything that is not our own token without sending it, logging it or reporting it. How clipboard matching works, in full.

5. Why we are allowed to (lawful basis)

  • Contract — running the account you asked us for.
  • Legitimate interests — keeping the service secure and working: rate limiting, the audit log, and preventing abuse. We have weighed this against the interests of the people involved, which is why addresses are hashed rather than stored.
  • Legal obligation — accounting records, once there is anything to account for.

We do not rely on consent for any of the above, because none of it is optional to the service. There is no marketing email to opt out of, because we do not send any.

6. How long we keep it

  • Account data — while the account is open, and then until you ask us to erase it.
  • Sessions and emailed links — sessions expire after 30 days; verification links after 24 hours; password reset links after one hour. Expired records are removed.
  • Audit log — kept, because a security log you can delete is not a security log. It holds hashes rather than addresses.
  • Deleted apps and links — see the terms. Links keep resolving for a grace period, currently 90 days, so a printed link does not break the moment an account is tidied up.

7. Your rights

Under UK GDPR you can ask us to:

  • give you a copy of your personal data;
  • correct anything wrong;
  • erase it;
  • restrict or object to how we use it;
  • hand it to you in a portable form.

Write to [email protected]. We will respond within one month. There is no charge.

Two honest limits. We cannot erase what we never had — there is no raw IP address to give you or delete. And we cannot release an app’s link host for reuse, because doing so would send other people’s existing links into a stranger’s app; the host is not personal data and is retained.

Erasure is currently handled by hand, by writing to us. A button in the dashboard is not built yet.

8. Complaints

If you think we have handled your data badly, please tell us first — we would rather fix it. You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority, at ico.org.uk.

9. Changes

We will post changes here and update the date at the top. For anything that materially changes what we do with your data, we will email you.