← Back to Routling

Privacy Policy

Last updated: August 1, 2026

This policy explains what Routling collects, why, and what you can do about it. It covers both the website and the Routling desktop application.

Who we are

Routling is a product of COTORCEANU RADU PERSOANĂ FIZICĂ AUTORIZATĂ, a sole trader registered in Romania and trading as Routling, which is the data controller for the purposes of the GDPR.

Registered officeStrada Col. Ion Buzoianu, Nr. 88, Municipiul Buzău, Județul Buzău, Romania
Tax identification (CUI)50849763
Trade register numberF2024015145004
EUIDROONRC.F2024015145004
Emailr.cotorceanu@gmail.com

We have not appointed a Data Protection Officer, and are not required to.

What we collect

Waitlist

Your name and email address, plus an optional use case and referral source. Used only to notify you about Routling's launch.

Purchases

When you buy a licence we record your email address, name, the amount and currency paid, and the payment status. We never see or store your card details - those are handled entirely by Stripe.

Licences and machine activation

Each licence is bound to the computers it is activated on. To do this the desktop application sends a machine identifier to our server when you activate or deactivate a seat.

This identifier is not your hardware serial number, and it is not reversible. The application reads the identifier Windows assigns to your installation, combines it with a fixed Routling salt, hashes it with SHA-256, and sends only the first 32 characters of that hash. The underlying Windows value never leaves your computer, and the hash cannot be turned back into it or used to identify your hardware. If that value cannot be read, the application instead generates a random identifier and stores it in %APPDATA%\Routling.

The machine identifier is also sent when the application checks for updates, so that staged rollouts reach the same machines consistently rather than flipping between "update available" and "up to date".

Accounts and sign-in

Signing in to manage your licence uses an emailed one-time code. We store your email address, a hash of the sign-in code, and a hash of your session token. Neither the code nor the session token is stored in a form that could be replayed if the database were read.

IP addresses

We record the IP address of sign-in requests, and keep it briefly, purely to rate-limit them. Without this limit the sign-in endpoint could be used to test which email addresses belong to customers. It is not used for analytics, profiling, or advertising.

Data that stays on your computer

Some things the application stores are never sent to us, and are listed here only so you know where they are:

Uninstalling Routling and deleting %APPDATA%\Routling removes all of it.

What we do not collect

Routling contains no analytics, tracking, telemetry, or advertising of any kind. The desktop application does not report your audio devices, routing configuration, usage patterns, or any file on your computer. The website sets no tracking cookies - the only cookie is the sign-in session cookie, which exists solely to keep you signed in.

Legal basis

DataPurposeBasis
Waitlist name & emailLaunch notificationConsent
Download email addressProviding the download and, where you asked for it, product newsConsent
Newsletter subscriptionSending news and product updates about RoutlingConsent
Purchase recordsDelivering and supporting your licenceContract
Machine identifierEnforcing licence seat limitsContract
Account & session dataLetting you manage your licenceContract
Sign-in IP addressesPreventing abuse and customer enumerationLegitimate interest
Invoice recordsTax and accounting obligationsLegal obligation

Who we share it with

We do not sell your data or use it for advertising. We share it only with the service providers needed to run Routling:

ProviderReceivesWhy
StripeEmail, name, billing address, payment details, tax ID if givenPayment processing. Stripe is the merchant of record for your purchase and handles tax collection and remittance.
CloudflareData stored in our database; IP addresses in transitHosting, database, and file storage
ResendEmail address and message contentSending licence keys and sign-in codes

Each of these processes data on our behalf under its own terms. Stripe and Resend are US-based and rely on the EU Standard Contractual Clauses for transfers out of the EEA. We may also disclose data where legally required.

Cookies

The website sets a single cookie, and only after you sign in: a session cookie holding a random token, which keeps you signed in. It is strictly necessary for the account area to work, so it needs no consent banner. There are no advertising, analytics, or tracking cookies. Signing out deletes it.

Where it is stored

Our database and file storage run on Cloudflare infrastructure. Payment and email data is additionally held by Stripe and Resend as described above.

How we protect it

Sign-in codes and session tokens are stored only as hashes, so reading the database would not yield a working code or a usable session. All traffic to the site and the licensing API uses HTTPS. Card details never reach our systems. Administrative access is restricted to a fixed list of addresses held in configuration rather than in the database, so no database write can grant itself admin rights.

Automated decision-making

We do not carry out profiling or automated decision-making that produces legal or similarly significant effects, within the meaning of Article 22 GDPR. Licence checks are a simple comparison against your seat limit.

How long we keep it

Marketing emails

If you opted in when downloading Routling or buying a licence, we send you occasional news and product updates. Every one of those emails carries an unsubscribe link that works in one click, without signing in, and takes effect immediately. Your email client's own unsubscribe button works too.

If you no longer have one of our emails, use the unsubscribe page (also linked in the site footer). Enter your address and we email you the one-click link. We send the link rather than acting on the form directly so that nobody can remove someone else's address by typing it in.

Unsubscribing stops marketing email only. You will still receive the emails that are part of the service itself - your licence key and sign-in codes - because those are not marketing and are not something we can withhold while you have an account.

Your rights

If you are in the EEA or the UK you have the right to access, correct, export, or delete your data, to object to or restrict processing, and to withdraw consent at any time. Email r.cotorceanu@gmail.com and we will respond within 30 days.

Deleting your data yourself

You can erase your data without waiting for us, on the delete my data page. Enter your address and we email you a confirmation link; the link shows exactly what will be removed before anything happens. We send a link rather than acting on the form directly so that nobody can delete someone else's account by typing their address into it.

If you hold a Routling Pro licence, erasure deletes it. The licence is identified by your email address, so removing that address deactivates the key. It cannot afterwards be reactivated, reissued, or refunded. If you only want to stop marketing email, unsubscribe instead - that leaves your licence untouched.

One thing is kept: your purchase record. EU and Romanian accounting law requires us to retain invoice records, and Article 17(3)(b) of the GDPR disapplies the right to erasure where we have such a legal obligation. We minimise what remains - your email address on that record is replaced with a one-way code, and your name is deleted, so our copy no longer identifies you.

Data held by our processors

The deletion described above covers our own database. Two of the providers listed above keep their own records, on their own retention schedules, and deleting your data here does not clear theirs:

If you want your data erased from those services as well, you can contact them directly, or email us and we will pass the request on and confirm the outcome to you. Either way we will act within 30 days.

You also have the right to complain to your local data protection authority - in Romania, the ANSPDCP.

Children

Routling is not directed at children under 16, and we do not knowingly collect their data.

Changes

If this policy changes materially we will update the date above and, where the change affects you, notify licence holders by email.

Contact

Any privacy question, or to exercise any right above: r.cotorceanu@gmail.com.

Terms of Service