RUTA by Empiryx Tech
Privacy Policy Data Deletion

Legal

Privacy Policy

Effective date: August 24, 2026  ·  Applies to the RUTA Lead Management System, operated by Empiryx Tech

In short: RUTA stores the account, lead, and Meta (Facebook/Instagram) integration data a business needs to run its own sales pipeline. We do not sell personal data, and Meta data obtained through the Lead Ads integration is used only to deliver that feature to the business that connected it.

On this page

  1. 1. Who we are
  2. 2. Scope of this policy
  3. 3. Information we collect
  4. 4. Meta Platform Data specifically
  5. 5. How we use information
  6. 6. Legal basis for processing
  7. 7. How information is shared
  8. 8. Data retention
  9. 9. Data security
  10. 10. International data transfers
  11. 11. Your rights and choices
  12. 12. Cookies and similar technologies
  13. 13. Children's privacy
  14. 14. Changes to this policy
  15. 15. Contact us

1. Who we are

RUTA is a lead management system ("RUTA", "the System", "we", "us") built and operated by Empiryx Tech ("Empiryx", "we"). RUTA is used by businesses ("Tenants", "Customers", "you") to capture, route, and follow up on sales leads — including leads received through a connected Meta (Facebook/Instagram) Lead Ads account.

This policy explains what data RUTA collects, why, how it is used and protected, and the choices available to Tenants, their staff, and the individuals whose leads pass through the system.

Empiryx Tech is the data controller for account and platform-level data described below. Where a Tenant uses RUTA to collect and manage its own customers' or leads' personal data, that Tenant acts as the data controller for that lead data, and Empiryx Tech acts as its data processor/service provider.

2. Scope of this policy

This policy covers:

  • The RUTA web application (dashboard, pipeline, forms, settings) used by Tenant staff.
  • RUTA's Meta OAuth integration ("Connect Meta"), which lets a Tenant link its Facebook Page, Instagram professional account, and ad account to automatically receive Lead Ads submissions.
  • Public lead-capture forms a Tenant publishes through RUTA.
  • Backend infrastructure (database, queue, and webhook processing) that stores and moves this data.

It does not cover third-party websites or services a Tenant may link to from within RUTA, or Meta's own platforms — Meta's use of data is governed by Meta's Privacy Policy and the Meta Platform Terms.

3. Information we collect

3.1 Account & company data

When a business signs up for RUTA, we collect company details (name, industry, company size, timezone) and, for each staff member: full name, email address, a securely hashed password, assigned role/permissions, and (where multi-branch is used) branch assignment. We also record basic session metadata — IP address, user agent, and login/session timestamps — to keep accounts secure and support "sign out everywhere."

3.2 Lead & customer data

RUTA stores the leads a Tenant captures, whether they arrive automatically from Meta Lead Ads or are entered manually by Tenant staff. This may include: full name, email address, phone number, the answers submitted on a lead form, pipeline/status information, notes added by staff, assigned owner, follow-up dates, and any custom fields the Tenant's industry template defines (for example, budget or preferred location for a real-estate Tenant).

3.3 Technical & log data

We keep processing logs for each lead event (received, queued, processed, retried, failed) and the raw payload of inbound Meta webhook events, so that a lead is never silently lost and support issues can be diagnosed. These records are retained for operational and audit purposes.

4. Meta Platform Data specifically

When a Tenant clicks "Connect Meta" and authorizes RUTA through Facebook Login, we receive and store the following on that Tenant's behalf, strictly to power the integration they set up:

DataSourcePurpose
Meta user ID & display nameFacebook Login (OAuth)Identify who connected the account; shown on the Integrations screen
Long-lived access token (Page & user)OAuth grantAuthenticate ongoing calls to the Meta Graph API on the Tenant's behalf; encrypted at rest, never exposed in the product UI or API responses
Facebook Page(s), Instagram professional account(s), ad account(s)Graph API, after connectionLet the Tenant choose which Page/Instagram account/ad account to use for lead capture
Campaign, ad set, and ad names/IDsGraph API syncAttribute each lead to the ad that generated it
Lead form questions and IDsGraph API syncLet the Tenant map Meta's form questions to RUTA's lead fields
Individual lead submissions (name, email, phone, form answers)Meta's leadgen webhookCreate and route the actual lead inside the Tenant's pipeline — this is the core purpose of the integration

How this data is used and not used:

  • Meta Platform Data is used exclusively to provide the lead-capture and CRM functionality the connecting Tenant requested — never to advertise to, profile, or build audiences from the Tenant's leads for any other business, and never sold or licensed to third parties.
  • Access tokens are encrypted at rest and used only for server-to-server calls to Meta's Graph API required by the features described above.
  • A Tenant can disconnect Meta at any time from Settings → Integrations → Meta, which revokes RUTA's access and stops any further use of that connection's tokens.
  • See our Data Deletion Instructions for how to request removal of Meta-sourced data.

5. How we use information

  • Provide the service: create accounts, store and organize leads, run the sales pipeline, sync Meta campaigns/forms, and deliver leads from Meta's webhook into a Tenant's dashboard in real time.
  • Reliability: detect and retry failed webhook deliveries, prevent duplicate leads, and reconcile missed events.
  • Security: authenticate users, detect suspicious activity, and enforce tenant isolation so one company can never see another's data.
  • Support & communication: respond to support requests and send operational notices about the account or the Meta connection (for example, if reauthorization is needed).
  • Improve the product: understand aggregate usage patterns to fix bugs and prioritize features. We do not use Tenant lead data to train third-party AI models.

6. Legal basis for processing

Where data protection law (such as the EU/UK GDPR) applies, we process personal data on the following bases: performance of our contract with the Tenant (providing the RUTA service), the Tenant's own legitimate interests in managing its sales pipeline, our legitimate interest in keeping the service secure and reliable, and, for the Meta integration specifically, the consent/authorization a Tenant gives through the Facebook Login OAuth flow. Where a Tenant is itself the controller of its leads' personal data, that Tenant is responsible for having its own valid legal basis for collecting and processing that data (for example, through consent captured on its lead forms or ads).

7. How information is shared

We do not sell personal data. We share information only in the following circumstances:

  • With Meta, as required for the integration to function (for example, subscribing a Page to leadgen webhooks) — governed by Meta's own Platform Terms and Developer Policies.
  • With infrastructure sub-processors that host and run RUTA: Vercel (application hosting), Neon (Postgres database), and Upstash (queueing/caching). Each processes data solely to provide their respective infrastructure service to us and is bound by its own data processing terms.
  • Within a Tenant's own account, data is visible to that Tenant's authorized staff according to their assigned role and permissions — never to other Tenants.
  • Legal requirements, if required to comply with a valid legal process, or to protect the rights, property, or safety of Empiryx Tech, our users, or others.
  • Business transfers, in the event of a merger, acquisition, or asset sale, subject to this policy continuing to apply to previously collected data.

8. Data retention

We retain account and lead data for as long as a Tenant's account is active, plus a reasonable period afterward to allow for account recovery, comply with legal obligations, resolve disputes, and enforce agreements. Meta access tokens are deleted or invalidated promptly when a Tenant disconnects the Meta integration. Raw webhook payloads and processing logs are retained for operational/audit purposes and are periodically reviewed for cleanup. A Tenant or individual may request earlier deletion — see Data Deletion Instructions.

9. Data security

  • All traffic to and from RUTA is encrypted in transit (HTTPS/TLS).
  • Meta access tokens and other secrets are encrypted at rest before being stored in our database — they are never stored or displayed in plaintext.
  • Every database row is scoped to a specific Tenant, and every query is tenant-isolated, so one company's data is never visible to another.
  • Access within a Tenant's account is governed by role-based permissions, and passwords are stored using one-way hashing, never in plaintext.
  • No method of transmission or storage is 100% secure; we work to protect your data but cannot guarantee absolute security.

10. International data transfers

RUTA's infrastructure providers (Vercel, Neon, Upstash) may process and store data in data centers located in different countries than where a Tenant or its leads are based. Where required by applicable law, we and our sub-processors rely on appropriate safeguards (such as standard contractual clauses) for any such cross-border transfer.

11. Your rights and choices

Depending on your location, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. If you are a lead or customer whose data was submitted through a Tenant's RUTA-connected form or ad, please contact that business directly first, as they control your data; if you're unsure which business that is, contact us at the email below and we will help route your request. If you are a Tenant or a member of a Tenant's staff, you can access and update most of your data directly within RUTA, or contact us for anything you can't change yourself. See our dedicated Data Deletion Instructions page for how to request deletion specifically.

12. Cookies and similar technologies

RUTA uses strictly necessary cookies/local storage to keep you signed in (session and authentication tokens) and to remember basic preferences. We do not use third-party advertising or cross-site tracking cookies.

13. Children's privacy

RUTA is a business tool and is not directed at, or knowingly used to collect personal data from, children. If you believe a child's personal data has been submitted to us (for example, through a lead form), please contact us and we will take appropriate steps to delete it.

14. Changes to this policy

We may update this policy from time to time to reflect changes to RUTA or applicable law. We will update the "Effective date" above when we do, and, for material changes, take reasonable steps to notify Tenant administrators.

15. Contact us

Questions about this policy, or a request relating to your personal data, can be sent to:

Empiryx Tech
Email: empiryxtech@gmail.com

This page is a template describing RUTA's data practices as implemented in the product; it is provided for informational purposes and does not constitute legal advice. We recommend having it reviewed by qualified legal counsel for your specific jurisdiction and business before relying on it as your final, published policy.  ·  Data Deletion Instructions