Privacy Policy
Meridian ("we", "us") gives you a public homepage and Meridian links that can either route each visitor to the right destination based on rules you set — a website, a native app, or a page you build that can collect input — or serve a page you build, and it remembers who has visited before. This policy explains what we collect, why, and the control you have over it.
Who is responsible for your data
For your account and how the Service runs, Meridian is the data controller. For the visitor data and captured inputs collected through the links and pages you build, you are the controller and Meridian acts as your processor — you are responsible for having a lawful basis to collect it and for your own privacy notices to your visitors.
What we collect
- Account — authentication is handled by Clerk (your email and/or social login). We store your chosen handle, your Clerk user id, your plan, and account timestamps.
- Content you create — links, routing rules, page content, and settings.
- Visitor data on your links — when someone opens one of your links we process their IP address (used transiently to derive approximate country/region/timezone and to rate-limit; we do not store the full IP as precise location), device type, referrer, UTM parameters, language, timestamps, and a visitor id held in a first-party cookie — or, when that cookie is absent, derived from a device fingerprint (a keyed one-way hash of the IP and browser) so a returning visitor can still be recognized. That id is a one-way hash and cannot be reversed back to the IP. From these signals a per-visitor summary is available to the link owner — visit count, first and last seen, the source they arrived from, and whether they are new or returning.
- Captured inputs — values visitors submit to your pages (for example an email address via a capture or gate block), stored as lead data you can read and export.
Cookies
We use a first-party cookie named mv to recognize a returning visitor so your memory-based routing works; it holds a visitor id — a one-way keyed hash, not personal details or the raw IP. When the cookie is absent, that id is instead derived from a device fingerprint (a keyed hash of IP and browser), so returning visitors are still recognized. Clerk sets cookies needed to keep you signed in. We do not use third-party advertising cookies.
How we use it
- To operate routing, analytics, and page features you configure.
- To secure the Service (rate limiting, abuse prevention).
- To provide and bill your plan.
Who we share it with
We use a small number of processors: Clerk (authentication), Polar (payments — your card details are handled by Polar and never reach Meridian), Fly.io (hosting and, if you connect a custom domain, its TLS certificate), and your configured email/SMTP provider if you enable capture emails. Geolocation is derived from a local database, not shared with a third party. We do not sell personal data.
Retention
Account and content data are kept until you delete them or close your account. Deleting a link removes its associated visitor records and captures. Backups may persist for a limited period before rotation.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your data. Email support@meridianrouter.com and we will respond. Visitors exercising rights over captured data should contact the owner of the link, who controls it.
Children
The Service is not directed to children under 13 (or the minimum age in your country), and we do not knowingly collect their data.
Changes
We may update this policy; we will change the "last updated" date above and, for material changes, take reasonable steps to notify you.