↓ Skip to main content

Privacy Policy

Last updated: July 29, 2026

This Privacy Policy explains how RedirRocks (“RedirRocks”, “we”, “us”, or “our”) collects, uses, shares, and protects information in connection with our redirect-management platform, websites, and related services (together, the “Service”).

This Privacy Policy is a notice describing how we handle personal information; it is not a contract, and our processing does not depend on your “acceptance” of it. Where we rely on your consent for a specific activity (such as analytics cookies), we ask for it separately, and you can withdraw it at any time.

Who we are
#

RedirRocks is operated by Tech Forge Rocks LLC. We provide a platform that lets customers create and manage rules that redirect web traffic to different destinations based on conditions such as location, device, and how a visitor arrived.

For most of the information described below, the account holder (our customer) is the data controller and RedirRocks acts as a data processor that handles visitor request data on the customer’s behalf and according to their instructions.

Information we collect
#

Information you provide
#

  • Account information — your name, email address, password, and organization or team details when you register.
  • Redirect configuration — the domains, source paths, targets, and conditions you set up as part of your rules.
  • Billing information — where you subscribe to a paid plan, billing details are collected and processed by our payment provider (see How we share information). We do not store full payment card numbers.
  • Communications — messages you send us, such as support requests or feedback.

Information collected automatically
#

  • Usage and device data — information about how you use the dashboard, including browser type, device type, pages viewed, and actions taken. We use PostHog, our product analytics provider, to help collect and analyze this information.
  • Log data — server logs that may include IP addresses, request timestamps, and referring pages.
  • Cookies and similar technologies — used to keep you signed in and to remember preferences (see Cookies).

Visitor request data (processed for our customers)
#

When a visitor’s request passes through a customer’s configured domain, the Service evaluates it against that customer’s rules. To do so, we may process request attributes such as approximate location (derived from IP address), device type, request headers, query parameters, cookies, and the time of the request. This data is used to determine the correct redirect and is processed on behalf of the customer who owns the rule.

How we use information
#

We use the information we collect to:

  • Provide, operate, and maintain the Service;
  • Evaluate redirect rules and route traffic to the correct destination;
  • Create and manage your account and authenticate you;
  • Process payments and manage subscriptions;
  • Respond to your requests and provide customer support;
  • Send you service-related communications, such as security alerts and account notices;
  • Monitor and improve the performance, reliability, and security of the Service;
  • Detect, prevent, and address fraud, abuse, or technical issues; and
  • Comply with legal obligations.

Our legal bases (EEA/UK)#

Where the EU or UK GDPR applies, we rely on the following legal bases:

  • Performance of a contract — to create and manage your account, provide the Service, evaluate redirect rules, and process payments.
  • Legitimate interests — to secure, maintain, and improve the Service, prevent fraud and abuse, and send service-related communications, balanced against your rights and freedoms.
  • Consent — to set analytics cookies and to send any non-essential marketing. You may withdraw consent at any time without affecting prior processing.
  • Legal obligation — to comply with applicable laws and respond to lawful requests.

Where we act as a processor on a customer’s behalf (for visitor request data), the customer is responsible for establishing the legal basis for the processing they instruct.

Cookies and similar technologies
#

We use cookies and similar technologies to operate the dashboard, keep you signed in, and remember your preferences (such as light or dark appearance). You can control cookies through your browser settings, but disabling them may affect how the Service works. For a full list of the cookies we use and how to manage or change your consent, see our Cookie Policy.

We do not use the dashboard to serve third-party advertising.

How we share information
#

We do not sell your personal information. We share information only in the following circumstances:

  • Service providers (sub-processors) — with vendors who help us operate the Service, who may only use the information to perform services for us under contract. These currently include Stripe (payment processing and subscription billing), Resend (transactional email such as receipts and account notices), PostHog (product analytics), Amazon Web Services (cloud hosting and infrastructure for the redirect engine), and Cloudflare (website hosting, content delivery, and network security).
  • Legal and safety — when required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of RedirRocks, our users, or others.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction.
  • With your direction — when you instruct us to share information or make it available through your use of the Service.

Third-party destinations
#

The Service redirects visitors to destinations that our customers configure. Those destination websites are operated by third parties and are governed by their own privacy policies. We are not responsible for the content or privacy practices of destination sites.

Data retention
#

We retain personal information for as long as your account is active or as needed to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. In particular:

  • Server and request logs (including IP addresses and request metadata) are retained for 30 days, after which they are deleted or aggregated.
  • Account information is deleted within 90 days after you close your account, unless a longer period is required to comply with our legal obligations, resolve disputes, or enforce our agreements.

Security
#

We use technical and organizational measures designed to protect information against unauthorized access, loss, or misuse. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.

International data transfers
#

We and our sub-processors may process and store information in the United States and other countries, which may have data-protection laws different from those where you live. Where we transfer personal information out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards — principally the European Commission’s Standard Contractual Clauses (with the UK International Data Transfer Addendum where applicable) — together with additional measures where needed. You can request more information about these safeguards using the contact details below.

Your rights and choices
#

Depending on where you live, you may have rights regarding your personal information, including the right to:

  • Access the personal information we hold about you;
  • Correct inaccurate information;
  • Delete your information;
  • Object to or restrict certain processing;
  • Receive a copy of your information in a portable format;
  • Withdraw consent where processing is based on consent; and
  • Lodge a complaint with your local data-protection or supervisory authority.

To exercise these rights, contact us using the details below. If you are an end visitor whose data was processed as part of a customer’s redirect rules, please contact that customer (the data controller) directly; we will assist them as their processor.

Children’s privacy
#

The Service is not directed to children under the age of 16, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will take appropriate steps to delete it.

Changes to this policy
#

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Service after changes take effect means you accept the updated policy.

Contact us
#

If you have questions about this Privacy Policy, or to exercise your rights, contact us at:

  • Email: privacy@redir.rocks
  • Entity: Tech Forge Rocks LLC
  • Mailing address: PMB 1701, 1000 Brickell Ave, Ste 715, Miami, FL 33131, United States

(The terms governing your use of the Service, including governing law, are in our Terms of Service.)