Route It AIPrivacy Policy

California Privacy Rights (CCPA)

California residents have rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of the sale or sharing of personal information. See section 8.2 in the full policy below, or email our privacy contact listed in the document.

PRIVACY POLICY Effective Date: July 29, 2026 Last Updated: August 11, 2026 PREAMBLE & APPLICABILITY This Privacy Policy (“Policy”) describes how Constant Strategy Group LLC, a Florida limited liability company (“Company,” “CSG,” “we,” “us,” or “our”), collects, uses, discloses, and safeguards personal data when you visit routeit.ai (the “Website”), register for an account, access our Route It AI software-as-a-service (SaaS) application, integrate our embeddable widgets or API endpoints, or otherwise interact with our automated intake services (collectively, the “Services”). By accessing or using our Services, you acknowledge that you have read, understood, and agreed to the data collection, processing, and disclosure practices described in this Policy. This Policy is expressly incorporated into and subject to our Terms of Service and any applicable Data Processing Addendum (“DPA”). If you do not agree with the practices described herein, you must immediately discontinue use of the Services and remove all platform widgets and scripts from your digital properties. SECTION 1: ROLES & DATA PROCESSING SCOPE 1.1 Data Processor / Service Provider Role (Subscriber Intake) When subscriber organizations (such as law firms, healthcare facilities, hospitality enterprises, real estate brokerages, or general commercial businesses) embed Route It AI widgets, scripts, or API endpoints on their digital properties, they capture communications from end-user leads, clients, or patients (“End-User Data”). • Subscriber as Data Controller: The subscriber organization acts as the Data Controller (or "Business" under U.S. state privacy laws) and determines the nature, scope, and purpose of End-User Data captured via our Services. • Company as Data Processor: Constant Strategy Group LLC acts strictly as a Data Processor (or "Service Provider") executing automated intake routing, transcript processing, lead classification, and intent triage on behalf of, and pursuant to the instructions of, the subscriber organization. 1.2 Data Controller Role (Direct Account Holders) Constant Strategy Group LLC acts as a Data Controller with respect to account management details, billing information, subscriber administrative choices, and platform usage telemetry collected directly from authorized business account holders and website visitors. SECTION 2: CATEGORIES OF DATA WE PROCESS We collect personal data directly from account holders, automatically via platform telemetry, and indirectly through subscriber intake tools deployed on digital properties. 2.1 Account, Billing & Verification Data (Provided Directly) • Registration & Account Information: Full name, business email address, corporate telephone number, organization name, primary business vertical (workspace_vertical), professional title, and administrative account credentials. • Billing Details & Subscription Upgrades: Billing contact names, corporate addresses, payment verification tokens, and transaction history. For mid-month tier upgrades (e.g., Pro to Elite) or custom rate approvals, transaction intents are generated via our PCI-DSS Level 1 payment processor (Stripe). We do not store full primary account numbers (PAN) or card CVVs on our servers. • Tax & Contractor Verification Records: Tax Identification Numbers (Form W-9 for U.S. entities; Form W-8BEN or W-8BEN-E for non-U.S. individuals and entities), country of tax residence, and payout logs for international contractor tracking within our Expense & Bookkeeping engine. • Support & Operational Communications: Correspondence sent to legal@routeit.ai, security@routeit.ai, or billing@routeit.ai, including support tickets, technical bug reports, and feature requests. 2.2 End-User Data & Intake Content (Multi-Vertical Capture) When an end-user interacts with a Route It AI widget or endpoint on a subscriber property, the system processes raw text prompts, form inputs, interaction metadata, and uploaded files, which may include: • Standard Contact & Professional Intake: Name, email address, phone number, geographic region, and general inquiry summaries. • Legal Sector Intake: Preliminary legal inquiry details, dispute descriptions, and case triage preferences. • Healthcare Sector Inquiries: General appointment preferences, administrative inquiry details, and scheduling requests. • Hospitality & Booking Preferences: Desired reservation dates, party sizes, stay preferences, and service inquiries. • Real Estate & Property Criteria: Household preferences, budget ranges, desired geographic regions, and property specifications. • Consent & TCPA Timestamps: Explicit opt-in timestamps, IP addresses, and TCPA/CAN-SPAM consent strings submitted by visitors when providing phone numbers or email addresses. 2.3 Technical, Telemetry & Security Metrics (Automatically Collected) • Log & Technical Metrics: IP addresses, browser specifications, operating system details, device fingerprints, access timestamps, referral URLs, API request tokens, and routing latency metrics. • Security & Authentication Telemetry: Request volume metrics, origin domain verification headers (publicEmailDomains, origin headers), failed login attempts, rate-limiting counters, and automated anti-scraping flags. • Essential Cookies & Session Tokens: Minimal, essential session storage tokens and cookies strictly necessary to maintain administrative authentication, enforce role-based access control (RBAC), ensure billing validation (assertOrgBillable), and prevent cross-site request forgery. We do not sell browsing history or utilize third-party cross-contexttracking cookies for ad networks. 2.4 Telecommunications, SMS & Voice Interaction Data (Twilio Integration) • When the Services trigger or route SMS messages, multi-media messages (MMS), or voice calls via our telecommunications infrastructure provider (Twilio, Inc.), we collect telecommunications metadata, including destination telephone numbers, sending numbers, carrier identifiers, delivery status receipts, message bodies or conversation text payloads, call duration timestamps, and voice recording transcript logs (where enabled by the subscriber organization). SECTION 3: LAWFUL PURPOSES OF PROCESSING Constant Strategy Group LLC processes personal data strictly for legitimate institutional business purposes: • Service Execution & Multi-Vertical Routing: To authenticate authorized users, execute real-time intent classification, process multi-vertical intake prompts, and route data to designated subscriber endpoints or webhooks. • Platform Security & Infrastructure Protection: To enforce billing tier locks (assertOrgBillable), detect prompt injection attacks, prevent unauthorized API scraping or reverse engineering, verify allowed domain origins, and maintain infrastructure stability. • Billing Administration & Tier Management: To process subscription fees, execute owner-approved tier upgrades, invoice usage overages, and manage account standing. • Legal Compliance & Defense: To enforce our Terms of Service, defend against legal claims (including TCPA or UPL claims), comply with judicial subpoenas, statutory recordkeeping mandates, and regulatory audits. SECTION 4: AI ARCHITECTURE, SUBPROCESSORS & NO-MODEL-TRAINING GUARANTEE 4.1 Dynamic AI Routing Disclosures The Services utilize a dynamic, artificial intelligence-agnostic orchestration pipeline. To execute real-time intake triage, summaries, and classification, raw End-User Data and system prompts are routed programmatically to specialized third-party artificial intelligence inference engines, large language model (LLM) infrastructure providers, and cloud processing subprocessors (“Third-Party Subprocessors”). 4.2 Strict No-Model-Training Guarantee WE DO NOT SELL, RENT, OR MONETIZE END-USER DATA OR SUBSCRIBER PROMPTS. Constant Strategy Group LLC contractually restricts or configures enterprise API integrations with its primary AI model inference subprocessors (including OpenAI, Anthropic, Supabase, and Vercel) to ensure that raw End-User Data, conversation transcripts, and custom prompt inputs processed through Route It AI are NOT utilized to train, retrain, or improve public, baseline, or commercial foundation AI models. 4.3 Functional Categories of Subprocessors To protect platform architecture, we disclose our subprocessor network by functional service categories: • Cloud Infrastructure & Serverless Compute Hosting: Enterprise U.S.-based cloud hosting providers that store database instances, maintain serverless functions, and host secure API gateways. • AI Model Inference Providers: Advanced foundation model vendors and natural language processing API providers that execute dynamic prompt inferences. • Database & Encrypted Storage Providers: Relational database services and encrypted cloud storage buckets used to log structured system records and conversation transcripts. • Merchant Services & Payment Processing: PCI-DSS Level 1 certified payment processing facilities that manage recurring subscription transactions and mid-month upgrades. • Telecommunications & Programmable Messaging Infrastructure: Cloud communications and CPaaS providers (such as Twilio, Inc.) utilized to route SMS notifications, execute automated phone alerts, and manage carrier delivery protocols. SECTION 5: THIRD-PARTY INTEGRATIONS & DESTINATION DISPATCHES 5.1 Intermediary Transmission Upon successful capture and processing of an intake submission, Route It AI dispatches the captured data to third-party destination endpoints, webhooks, or Customer Relationship Management (CRM) applications (such as Clio, HubSpot, Salesforce, or LawPay) explicitly configured by the subscriber organization. 5.2 Post-Dispatch Data Governance Once data is transmitted to a subscriber’s designated third-party CRM or external endpoint, the processing, storage, access control, and retention of such data are governed strictly by the privacy notices and security practices of the subscribing organization and the third-party CRM provider. Route It AI is not responsible for data governance once hand-off to the subscriber's endpoint is completed. SECTION 6: TELEPHONE CONSUMER PROTECTION ACT (TCPA) & COMMUNICATIONS CONSENT When end-users submit telephone numbers via a Route It AI widget or web form, any automated SMS alerts, voice routing, or notifications triggered through the system and transmitted via our telecommunications subprocessor (Twilio) rely on express written consent collected at the point of entry. Subscriber organizations acknowledge and agree that they are utilizing Twilio programmable infrastructure via our platform orchestration, and they remain strictly responsible for maintaining legally compliant opt-in language on their digital properties in accordance with the Telephone Consumer Protection Act (TCPA), CAN-SPAM Act, CTIA messaging guidelines, and applicable state telemarketing regulations. SECTION 7: SPECIAL DATA CATEGORIES, HIPAA & SENSITIVE PII RESTRICTIONS 7.1 No HIPAA Business Associate Relationship Without BAA Unless the Subscriber has entered into a formal, written Business Associate Agreement (BAA) executed by an authorized officer of Constant Strategy Group LLC, Route It AI is NOT configured to process Protected Health Information (PHI) under the Health Insurance Portability and Accountability Act (HIPAA). Subscriber organizations in the healthcare sector are solely responsible for ensuring their intake configurations comply with HIPAA regulations. 7.2 Strict Prohibition on Sensitive PII Public intake widgets are designed strictly for preliminary contact gathering and administrative triage. End-users and Subscribers are strictly prohibited from submitting unencrypted Social Security numbers, driver's license numbers, financial account details, credit card numbers, or sensitive medical records through public chat widgets. CSG accepts no liability for unauthorized exposure or submission of restricted sensitive data. SECTION 8: DATA DISCLOSURE & SHARING RESTRICTIONS We do not sell, rent, trade, or lease personal data to third parties. We disclose personal data only under the following strictly defined conditions: • To Authorized Subprocessors: Exclusively to the extent necessary to perform real-time model inference, database storage, payment processing, and intake routing as instructed by the subscriber organization. • Corporate Successors: In connection with, or during active negotiations of, any merger, acquisition, corporate reorganization, asset sale, or financing involving Constant Strategy Group LLC, provided the receiving party agrees to respect the confidentiality of personal data in accordance with this Policy. • Compelled Legal Disclosures & Harm Mitigation: When required by applicable law, court order, judicial subpoena, or regulatory mandate, or if we determine in good faith that disclosure is necessary to: o Comply with statutory obligations or judicial proceedings; o Enforce our Terms of Service, defend against legal liability, or investigate cyberattacks/prompt injection; or o Protect the personal safety, rights, property, or operational security of Constant Strategy Group LLC, our users, or the general public. • Direction by Data Controller: Pursuant to explicit instructions or consent provided by the subscriber organization managing the account. SECTION 9: DATA SECURITY & RETENTION PROTOCOLS 9.1 Security Architecture We maintain administrative, technical, and physical security measures designed to protect personal data against unauthorized access, destruction, loss, or disclosure. These safeguards include: • Transport Layer Security (TLS 1.3) encryption for all data in transit; • Advanced Encryption Standard (AES-256) encryption for database records at rest; • Tokenized API authentication keys and role-based access control (RBAC) isolation; and • Automated monitoring to detect unauthorized API probing, scraping, or credential misuse. While we employ enterprise-grade security standards, no method of cloud transmission or electronic storage is 100% secure, and we cannot guarantee absolute security against sophisticated malicious actors. 9.2 Retention Durations • Account & Billing Records: Retained for the duration of the active subscription term plus seven (7) years following account termination to satisfy financial auditing, tax reporting, and legal defense requirements. • End-User Data & Transcripts: Retained according to the custom retention window configured by the subscriber organization within their management dashboard, or until account closure, unless temporary retention is required for security auditing or bug resolution. • Financial & Tax Audit Records: Financial transaction records, payment instrument metadata (last 4 digits), and attached receipts logged within the Expense & Bookkeeping engine are retained in secure, soft-deleted ledgers (deleted_at) in compliance with Internal Revenue Service (IRS) Section 6001 guidelines and statutory accounting rules, even following subscription cancellation. • Security & System Telemetry Logs: Retained for a rolling window strictly necessary to maintain infrastructure security, rate-limiting, and fraud prevention metrics. SECTION 10: JURISDICTION-SPECIFIC STATUTORY PRIVACY RIGHTS 10.1 European Economic Area (EEA), UK, and Swiss Data Subjects (GDPR / UK GDPR) Where CSG acts as a Data Processor on behalf of a subscriber organization, statutory requests (Access, Rectification, Erasure, Portability) must be submitted directly to the subscriber organization (the Data Controller). For direct account data where CSG acts as Data Controller, users may exercise their rights by contacting legal@routeit.ai. 10.2 United States Consumer Privacy Rights (CCPA/CPRA, FDBR, TDPSA, VCDPA) Under U.S. state privacy frameworks (including California, Florida, Texas, Virginia, and others): • Right to Know / Access: Request categories and specific pieces of personal data collected, processing purposes, and third-party disclosures. • Right to Delete: Request deletion of personal data, subject to legal and statutory recordkeeping exceptions. • No Sale or Behavioral Advertising: CSG does not sell personal data or process personal data for cross-context behavioral advertising. • Non-Discrimination: We will never discriminate, adjust pricing, or deny services to any user for exercising their legal privacy rights. To submit a verified statutory request, email legal@routeit.ai. SECTION 11: CHILDREN’S PRIVACY & B2B LIMITATIONS The Services are designed strictly for commercial, business-to-business (B2B) use by licensed organizations and adult professionals. The Services are not directed to, and we do not knowingly collect personal data from, children or minors under the age of eighteen (18). If we learn that an individual under 18 has submitted personal data without verifiable parental consent, we will take immediate action to delete such information from our systems. SECTION 12: AMENDMENTS TO THIS POLICY Constant Strategy Group LLC reserves the right to modify or update this Privacy Policy at any time. Any changes become effective immediately upon posting the updated Policy with a revised “Last Updated” date. For material changes affecting registered subscribers, we will provide advance notice via email or through an administrative banner within the platform dashboard prior to the change taking effect. Continued use of the Services following any modification constitutes acceptance of the revised Policy. SECTION 13: CALIFORNIA CONSUMER PRIVACY ACT (CCPA / CPRA) DISCLOSURES This section applies solely to visitors, users, and consumers who reside in the State of California. Pursuant to the California Consumer Privacy Act of 2018 (CCPA) and the California Privacy Rights Act (CPRA), Constant Strategy Group LLC ("CSG", "Route It AI", "we", "us") provides the following notice regarding our data practices. 1. Personal Information We Collect: In the preceding 12 months, Route It AI has collected the following categories of personal information for business operations: o Identifiers: Name, business email address, phone number, IP address, and browser session IDs. o Commercial Information: Subscription tiers, practice area choices, and transaction history processed through Stripe. o Internet / Network Activity: Interaction history with our website, chat intake widgets, and performance metrics. o Inference & Intake Data: Contact details and qualifying responses provided voluntarily during AI chat interactions. 2. How We Use Cookies & Technical Storage: We use essential cookies and browser storage to maintain secure user sessions (via Supabase and Stripe), store chat widget state, and analyze site performance (via Sentry/telemetry). We do not run third-party cross-context behavioral advertising trackers. 3. "Do Not Sell or Share My Personal Information" Notice: Route It AI does not sell your personal information for monetary value, nor do we share your personal information with third parties for cross-context behavioral advertising. We only disclose personal information to trusted service providers (e.g., cloud database infrastructure, billing processors) under strict data processing agreements. 4. Your Privacy Rights: California residents have the following rights under the CCPA/CPRA: o Right to Know / Access: Request details on the specific personal information we have collected about you. o Right to Delete: Request the deletion of your personal data held in our systems. o Right to Correct: Request correction of inaccurate personal information. o Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights. 5. Exercising Your Rights: To exercise your California privacy rights or submit a data deletion request, please contact Constant Strategy Group LLC at our dedicated compliance point of contact or email support through our platform help widget. SECTION 14: PRIVACY CONTACT & LEGAL INQUIRIES For questions, statutory privacy requests, or regulatory inquiries regarding our data processing policies, please contact our Legal & Privacy Operations team: • Operating Legal Entity: Constant Strategy Group LLC • Software Product Line: Route It AI • Attn: Legal & Privacy Department • Legal Inquiries: legal@routeit.ai • Security & Vulnerability Reporting: security@routeit.ai • State of Incorporation: Florida, USA