Legal
In short: RUTA stores the account, lead, and Meta (Facebook/Instagram) integration data a business needs to run its own sales pipeline. We do not sell personal data, and Meta data obtained through the Lead Ads integration is used only to deliver that feature to the business that connected it.
On this page
RUTA is a lead management system ("RUTA", "the System", "we", "us") built and operated by Empiryx Tech ("Empiryx", "we"). RUTA is used by businesses ("Tenants", "Customers", "you") to capture, route, and follow up on sales leads — including leads received through a connected Meta (Facebook/Instagram) Lead Ads account.
This policy explains what data RUTA collects, why, how it is used and protected, and the choices available to Tenants, their staff, and the individuals whose leads pass through the system.
Empiryx Tech is the data controller for account and platform-level data described below. Where a Tenant uses RUTA to collect and manage its own customers' or leads' personal data, that Tenant acts as the data controller for that lead data, and Empiryx Tech acts as its data processor/service provider.
This policy covers:
It does not cover third-party websites or services a Tenant may link to from within RUTA, or Meta's own platforms — Meta's use of data is governed by Meta's Privacy Policy and the Meta Platform Terms.
When a business signs up for RUTA, we collect company details (name, industry, company size, timezone) and, for each staff member: full name, email address, a securely hashed password, assigned role/permissions, and (where multi-branch is used) branch assignment. We also record basic session metadata — IP address, user agent, and login/session timestamps — to keep accounts secure and support "sign out everywhere."
RUTA stores the leads a Tenant captures, whether they arrive automatically from Meta Lead Ads or are entered manually by Tenant staff. This may include: full name, email address, phone number, the answers submitted on a lead form, pipeline/status information, notes added by staff, assigned owner, follow-up dates, and any custom fields the Tenant's industry template defines (for example, budget or preferred location for a real-estate Tenant).
We keep processing logs for each lead event (received, queued, processed, retried, failed) and the raw payload of inbound Meta webhook events, so that a lead is never silently lost and support issues can be diagnosed. These records are retained for operational and audit purposes.
When a Tenant clicks "Connect Meta" and authorizes RUTA through Facebook Login, we receive and store the following on that Tenant's behalf, strictly to power the integration they set up:
| Data | Source | Purpose |
|---|---|---|
| Meta user ID & display name | Facebook Login (OAuth) | Identify who connected the account; shown on the Integrations screen |
| Long-lived access token (Page & user) | OAuth grant | Authenticate ongoing calls to the Meta Graph API on the Tenant's behalf; encrypted at rest, never exposed in the product UI or API responses |
| Facebook Page(s), Instagram professional account(s), ad account(s) | Graph API, after connection | Let the Tenant choose which Page/Instagram account/ad account to use for lead capture |
| Campaign, ad set, and ad names/IDs | Graph API sync | Attribute each lead to the ad that generated it |
| Lead form questions and IDs | Graph API sync | Let the Tenant map Meta's form questions to RUTA's lead fields |
| Individual lead submissions (name, email, phone, form answers) | Meta's leadgen webhook | Create and route the actual lead inside the Tenant's pipeline — this is the core purpose of the integration |
How this data is used and not used:
Where data protection law (such as the EU/UK GDPR) applies, we process personal data on the following bases: performance of our contract with the Tenant (providing the RUTA service), the Tenant's own legitimate interests in managing its sales pipeline, our legitimate interest in keeping the service secure and reliable, and, for the Meta integration specifically, the consent/authorization a Tenant gives through the Facebook Login OAuth flow. Where a Tenant is itself the controller of its leads' personal data, that Tenant is responsible for having its own valid legal basis for collecting and processing that data (for example, through consent captured on its lead forms or ads).
We retain account and lead data for as long as a Tenant's account is active, plus a reasonable period afterward to allow for account recovery, comply with legal obligations, resolve disputes, and enforce agreements. Meta access tokens are deleted or invalidated promptly when a Tenant disconnects the Meta integration. Raw webhook payloads and processing logs are retained for operational/audit purposes and are periodically reviewed for cleanup. A Tenant or individual may request earlier deletion — see Data Deletion Instructions.
RUTA's infrastructure providers (Vercel, Neon, Upstash) may process and store data in data centers located in different countries than where a Tenant or its leads are based. Where required by applicable law, we and our sub-processors rely on appropriate safeguards (such as standard contractual clauses) for any such cross-border transfer.
Depending on your location, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. If you are a lead or customer whose data was submitted through a Tenant's RUTA-connected form or ad, please contact that business directly first, as they control your data; if you're unsure which business that is, contact us at the email below and we will help route your request. If you are a Tenant or a member of a Tenant's staff, you can access and update most of your data directly within RUTA, or contact us for anything you can't change yourself. See our dedicated Data Deletion Instructions page for how to request deletion specifically.
RUTA is a business tool and is not directed at, or knowingly used to collect personal data from, children. If you believe a child's personal data has been submitted to us (for example, through a lead form), please contact us and we will take appropriate steps to delete it.
We may update this policy from time to time to reflect changes to RUTA or applicable law. We will update the "Effective date" above when we do, and, for material changes, take reasonable steps to notify Tenant administrators.
Questions about this policy, or a request relating to your personal data, can be sent to:
Empiryx Tech
Email: empiryxtech@gmail.com