Privacy Policy

Last updated: August 30, 2026

At a glance

  • We are an e-invoicing service. Most of the personal data we hold is inside tax documents that our customers ask us to send, receive or report on their behalf.
  • We do not sell personal data, we do not run advertising, and we currently run no analytics tools on this website.
  • Our infrastructure is on Amazon Web Services in the United States. Tax documents are kept for the period the law requires — ten years for Oman — because they are legal records.
  • You can ask what we hold about you, have it corrected or deleted, or object to how we use it, by writing to privacy@goroute.ai.

1. Who we are

GoRoute.ai is operated by ClayDesk LLC, 45 Burgundy Hills Lane, Middletown, CT 06457, United States. ClayDesk LLC is the data controller for this website, for customer accounts, and for the information you send us directly.

Our e-invoicing services in the Sultanate of Oman are delivered by Union Digital Technologies SPC, an accredited service provider under the Oman Tax Authority's Fawtara programme. GoRoute operates a certified Peppol Access Point (service provider identifier POP000991).

This policy covers goroute.ai and its subdomains, the GoRoute platform, our API, and the connectors and plugins we publish. It applies together with our Terms of Service.

2. Two roles: when we decide, and when our customers do

Privacy law distinguishes between the party who decides why and how personal data is used (the controller) and the party who handles it on that party's instructions (the processor). We are both, and which one depends on the data.

2.1 Where we are the controller

We decide how to use the information you give us when you visit this website, contact us, book a call, register for an account or pay for a subscription. Sections 3 to 5 describe that.

2.2 Where we are the processor

When a customer uses GoRoute to issue, deliver, receive or report an invoice, the personal data inside that document — the names, addresses and tax identifiers of the customer's own buyers and suppliers — belongs to the customer. We process it only to carry out the customer's instruction: to build the document, validate it, transmit it over the Peppol network or to a tax authority, and keep the record for the period the law requires. Our customer is the controller of that data, and questions about it should go to them first.

3. Information we collect

3.1 When you visit this website

  • Contact form: your name, email address, company, company size, phone number if you give it, and your message. It is delivered by email to our team.
  • Booking a call: the details you enter into the scheduling page, which is provided by Cal.com.
  • Cookie consent: a record of the choice you made, described in section 8.
  • Technical data: the pages you request, your browser type and IP address, in server logs kept for 30 days.

3.2 When you hold an account

  • Your name, email address and password (stored by Amazon Cognito, which handles sign-in; we never see the password itself).
  • Your company's legal name, address, VAT or tax registration number, commercial registration number and Peppol participant identifier.
  • API keys and connector credentials you create so that your systems can talk to ours.
  • Billing details for paid subscriptions. Card payments are processed by Stripe; we receive a confirmation and the last four digits, never the full card number.
  • Records of what your account did: documents submitted, their delivery status, and administrative actions.

3.3 Documents we process on a customer's behalf

A tax invoice contains personal data whenever a party to it is an individual or a sole trader: name, address, tax identifier, email, and the goods or services bought. For business-to-consumer receipts the buyer's name and email appear only if the merchant supplies them. We also generate and store the compliance elements the law attaches to the document — invoice identifiers, verification codes and QR images — which are derived from the document's own contents.

3.4 Data from systems you connect

If you connect an accounting or ERP system — Zoho Books, Odoo, Microsoft Excel, WooCommerce, Oracle, SAP or another — we read the invoices, customers and suppliers you direct us to, and write back status and compliance data. We access these systems only under the authorisation you grant, and you can revoke it from within that system or from your GoRoute account at any time.

4. How we use it

  • To provide the service: building, validating, delivering, receiving and reporting e-invoices, and showing you what happened to them.
  • To meet legal obligations: registering participants with the Peppol network, reporting to tax authorities where a mandate requires it, and keeping tax records for the statutory period.
  • To run and secure the platform: authenticating users, preventing abuse, diagnosing faults and monitoring capacity.
  • To respond to you when you contact us, and to manage your account and billing.
  • To tell you about changes to the service or to the law that affect you. We send marketing only where you have agreed to it, and every such message can be unsubscribed from.

We do not use the contents of your invoices to profile you, to build products unrelated to your instructions, or to train models. We do not sell personal data and never have.

5. Legal bases

Where the GDPR, the UK GDPR or a similar law applies, we rely on:

  • Performance of a contract — everything needed to deliver the service you signed up for.
  • Legal obligation — tax reporting, record retention and Peppol network rules.
  • Legitimate interests — security, fault diagnosis and service improvement, balanced against your interests and never for advertising.
  • Consent — optional cookies and marketing communications. You can withdraw it at any time.

In Oman, we process personal data in accordance with the Personal Data Protection Law (Royal Decree 6/2022) and its executive regulations. In California, we act as a service provider to our customers and do not sell or share personal information for cross-context behavioural advertising.

6. Where your data is processed

Our platform runs on Amazon Web Services in the United States (us-east-1 region). That is where accounts, documents and logs are stored.

Some data necessarily leaves that estate to do its job. A document sent over the Peppol network travels to the recipient's Access Point, wherever that is. A document that a national mandate requires us to report goes to that country's tax authority — for Oman, the Oman Tax Authority. Participant identifiers are published to the Peppol SMP and SML directories so that other parties can find you, which is how the network works.

We are establishing an in-country hosting option in Oman for customers whose obligations require it. Until it is available, Omani customers' data is hosted in the United States under the safeguards in this policy and our customer agreement. If you are in the EEA or the United Kingdom, we will put Standard Contractual Clauses in place with you before processing your data.

7. Who we share it with

We share personal data only with the parties below, and only for the purpose stated. None of them may use it for their own purposes.

Party What for Where
Amazon Web ServicesHosting, storage, sign-in (Cognito) and transactional email (SES)United States
StripeCard payments for subscriptionsUnited States / EU
Cal.comScheduling calls you book with usUnited States
Google FontsDelivering the typefaces on this website; Google receives your IP address when the font files loadGlobal
YouTubeTutorial videos, embedded in privacy-enhanced mode; nothing is sent until you press playGlobal
Peppol networkSMP and SML directories, the Peppol Directory, and the recipient's Access PointWherever the recipient is
Tax authoritiesReporting documents where a national mandate requires itThe relevant country
Systems you connectYour own accounting or ERP platform, on your instructionYour provider

We will also disclose personal data where the law requires it — a court order, a lawful regulatory request, or to protect the safety of a person — and we will tell you when we are permitted to. We do not sell personal data and we do not share it with advertisers or data brokers.

8. Cookies and local storage

This website uses three categories, and you choose two of them in the banner shown on your first visit.

  • Necessary — always on. Your consent choice, your sign-in session on the platform, and the security tokens that protect forms.
  • Preferences — your theme and language, stored in your browser so the site remembers them.
  • Analytics — we run no analytics tools on this website at present. The category exists so that if we add one, it is off until you accept it.

When you make a choice we record it, so that we can show that consent was given and honour it: the choice, the version of this policy at the time, your country, your browser family, the page you were on and the site that referred you. Your IP address is not stored; a one-way salted hash of it is kept instead, which cannot be turned back into your address. The record is append-only. You can change your choice at any time from the cookie settings link in the footer, and you can ask us to delete the record.

9. How long we keep it

  • Tax documents and their compliance records: the statutory period in the relevant jurisdiction. In Oman that is ten years from the end of the tax year, and fifteen years for documents relating to real estate. These are legal records and cannot be deleted early, even at your request.
  • Account information: for as long as your account is active, and up to three years after it closes so that we can answer questions about the service you received.
  • Contact form and booking messages: until your enquiry is resolved and for a reasonable period afterwards, then deleted.
  • Server and application logs: 30 days.
  • Cookie consent records: for as long as needed to show that consent was given; deleted on request.

10. How we protect it

  • All traffic to and from the platform is encrypted in transit, and stored data is encrypted at rest.
  • Every customer's data is isolated from every other customer's inside the database itself, not only in application code, so that a mistake in one cannot expose another.
  • Documents on the Peppol network are signed and encrypted under the Peppol PKI, and every Access Point we exchange with is certified.
  • Access to production systems is limited to named staff who need it, and is logged.
  • Credentials for the systems you connect are stored encrypted and are never written to logs.

If a breach affects your personal data, we will tell you and any regulator we are obliged to notify without undue delay, and within the timeframes the applicable law sets — 72 hours of becoming aware, where the GDPR applies.

11. Your rights

Depending on where you live, you have some or all of the following rights, and we honour them for everyone regardless of location where we can:

  • Access — a copy of the personal data we hold about you.
  • Correction — fixing data that is wrong or incomplete.
  • Deletion — removing your data, except where a law requires us to keep it (see section 9).
  • Portability — receiving your data in a machine-readable form.
  • Restriction and objection — limiting or stopping particular uses.
  • Withdrawing consent — at any time, for anything that relied on it.
  • Complaint — to your data protection authority. In Oman that is the Ministry of Transport, Communications and Information Technology; in the EEA, your national supervisory authority.

Write to privacy@goroute.ai. We will confirm your identity, respond within 30 days, and never charge for a reasonable request. If your request concerns data inside an invoice that one of our customers issued, we will tell you and help you reach them, because they are the controller of that document.

12. Children

Our services are for businesses and are not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us data, contact us and we will delete it.

13. Changes to this policy

We update this policy when our services or the law change. The date at the top tells you when. For a material change we will tell account holders by email before it takes effect, and where a change alters what you consented to, the cookie banner will ask you again.

14. Contact

Privacy requests: privacy@goroute.ai
Post: ClayDesk LLC, 45 Burgundy Hills Lane, Middletown, CT 06457, United States
Oman services: Union Digital Technologies SPC, Muscat, Sultanate of Oman

Ready to Get Started?

Book a demo with our team to see how we can simplify your e-invoicing compliance.

Frequently asked questions

These answers are also published as structured data for search and answer engines.

Is GoRoute a data controller or a data processor? +
Both, depending on the data. For this website, your account and anything you send us directly, ClayDesk LLC is the controller. For the personal data inside invoices that a customer asks us to send, receive or report, the customer is the controller and GoRoute is the processor acting on their instructions.
Where is my data stored? +
On Amazon Web Services in the United States (us-east-1). Documents sent over the Peppol network travel to the recipient's Access Point, and documents a national mandate requires us to report go to that country's tax authority. An in-country hosting option for Oman is being established.
How long does GoRoute keep invoices? +
For the statutory retention period in the relevant jurisdiction, because they are legal tax records. In Oman that is ten years, and fifteen years for real-estate transactions. These cannot be deleted early, even on request. Account data is kept while the account is active and up to three years after; server logs for 30 days.
Does GoRoute use analytics or advertising cookies? +
No. GoRoute runs no analytics tools on goroute.ai at present and never runs advertising. The cookie banner offers an analytics category so that if a tool is added later it stays off until you accept it. Your consent choice is recorded with a one-way salted hash of your IP address, never the address itself.
How do I request access to or deletion of my data? +
Email privacy@goroute.ai. GoRoute will confirm your identity and respond within 30 days at no charge. Data a law requires GoRoute to keep, such as tax documents, cannot be deleted early. If your request concerns an invoice that one of GoRoute's customers issued, GoRoute will help you reach that customer, who is the controller of the document.