Branch Router
Terms of Service  ·  Home

Privacy Policy

Last updated: August 5, 2026

This Privacy Policy explains how Reserve Dev Co., a Texas corporation (“we”, “us”, or “our”), which operates Branch Router, collects, uses, and shares information when you use branchrouter.com, app.branchrouter.com, and related services (the “Service”).

The short version. We do not sell personal information. We do not use your configurations or signal history to trade for our own account. We do not store your full card number. We do store two sensitive things you should understand before signing up: the destination webhook URLs (and optional custom payloads) you configure so we can forward messages (Section 2), and a log of the signals that pass through the Service (Section 2). Sections 6 and 7 explain how long we keep them and how we protect them.

Support and privacy contact: support@branchrouter.com

1. Who we are

Branch Router is a trade automation platform that helps users coordinate multi-signal alerts and route trade instructions to systems they already use. It is operated by Reserve Dev Co., a corporation organized under the laws of the State of Texas.

For the purposes of the EU and UK General Data Protection Regulation (“GDPR”), Reserve Dev Co. is the controller of information collected through our website, marketing, and account administration. With respect to the signal payloads and routing configurations you submit and control, we act as a processor on your behalf, handling that data only as needed to operate the Service.

2. Information we collect

We may collect:

What we do not collect. Please do not send us brokerage or bank passwords, Social Security or taxpayer ID numbers, government ID images, account statements, health or biometric data, precise geolocation, or any special category data under GDPR Article 9. If you submit any of these by accident, email support@branchrouter.com and we will delete it. We may infer approximate country from IP address for tax, sanctions screening, and security purposes, but we do not collect precise location.

3. How we use information

Access to your signal logs and configurations by our personnel is limited to troubleshooting, security, and abuse investigation, and that access is logged.

We do not use your signal payloads, routing configurations, or signal history to train third-party generative AI models. Where we use AI-assisted tooling internally, we do so under agreements that prohibit the vendor from training on our data. We also do not use your configurations or signal history to trade for our own account.

We do not use automated decision-making that produces legal or similarly significant effects. Automated rules may flag an account for security review, but a person reviews any resulting suspension.

4. How we share information

We share information only as needed to run the Service, including with:

These providers process data on our behalf under written agreements that limit their use of it to providing services to us. We maintain a current list of subprocessors; to be notified of changes, email support@branchrouter.com.

Once data is transmitted to a destination you configured, it is governed by that platform’s privacy policy and terms, not ours. Review their policies before connecting them.

We do not sell personal information, and we do not share it for targeted advertising or cross-context behavioral advertising. We may disclose information if required by law, to protect rights and safety, or in connection with a business transfer. Where we are legally permitted to do so, we will try to notify you before disclosing your data in response to a government or legal request.

We may publish aggregated or de-identified statistics — for example, total signals routed per month — but never in a form that reveals your individual strategy logic or trading activity.

5. Cookies and similar technologies

We use essential cookies and local storage for authentication, session management, and preferences. We do not use advertising trackers on the marketing site for third-party ad networks. We do use analytics cookies to understand how the site and application are used and which marketing sources bring visitors. Third-party content we embed, such as YouTube videos, may set its own cookies when you interact with it.

Where required by law, we ask for consent before setting non-essential cookies. You can also block or delete cookies in your browser, though essential cookies are required for the Service to work. We do not respond to browser Do Not Track signals, as no common standard exists, but we honor the Global Privacy Control (GPC) signal where applicable law requires it.

6. Data retention

We keep personal information only as long as we need it for the purposes described here, then delete or de-identify it.

DataRetention period
Account and profile dataLife of the account, then deleted or de-identified within 30 days of account closure
Routing configurationsLife of the account, then deleted within 30 days of account closure
Signal activity logs90 days rolling, unless your plan specifies a longer window or you request earlier deletion
Destination webhook URLs and custom payloadsUntil you remove the destination or close your account; deleted within 30 days of account closure (may remain in backups up to the backup retention period below)
Billing and transaction records7 years, as required by tax and accounting law
Support correspondence24 months after resolution
Security and audit logs12 months
Marketing contact dataUntil you unsubscribe, plus a suppression record kept indefinitely so we can honor your opt-out
BackupsDeleted data may persist in encrypted backups for up to 35 days before rotation

We may keep information longer where the law requires it, or where it is necessary to establish, exercise, or defend a legal claim — for example, if a dispute about a routed signal is pending or reasonably anticipated.

7. Security

We use industry-standard measures such as encrypted transport (HTTPS), hashed account passwords, and access controls. Our measures also include encryption at rest for databases and backups where provided by our hosting stack, role-based and logged access to customer data, multi-factor authentication on administrative and infrastructure accounts, rate limiting and request validation on webhook endpoints, and routine dependency patching.

Transmitted payloads. Optional custom webhook payloads and recorded signal request bodies are protected with an additional application-layer encryption key. That key is loaded from an external secrets source (environment, mounted secret file, or cloud secrets manager) and is not stored in the same database as the ciphertext. In the product UI those payloads are masked by default and can be revealed only after you re-authenticate with your account password. Operational logs redact destination URLs to a display name plus a truncated tail and do not write full transmitted payload bodies.

What you should do: use a strong unique password; treat your webhook URLs as secrets and never post them in screenshots, forum threads, Discord channels, or video tutorials; prefer destination platforms that issue scoped or rotatable webhook URLs; rotate destination URLs periodically and immediately after any suspected exposure; and set hard risk limits at your broker independently of Branch Router.

No method of transmission or storage is completely secure, and we cannot guarantee that unauthorized access will never occur.

Breach notification. If we become aware of a breach affecting your personal information, we will notify you and any applicable regulator as required by law, without undue delay. If a breach could involve destination webhook URLs, we will notify affected customers promptly. Rotate or replace those destination URLs immediately on receiving any such notice.

8. Your choices and rights

Depending on your location, you may have rights to access, correct, export, or delete personal data, or to object to certain processing. Regardless of where you live, you can access and correct your account information in the Service, delete your account, unsubscribe from marketing email, and disconnect any destination — which removes the stored webhook URL for it.

Legal bases (EEA, UK, and Switzerland)

PurposeLegal basis
Providing the Service, account administration, billingPerformance of a contract
Security, fraud prevention, abuse detection, service improvementLegitimate interests
Marketing email and non-essential cookiesConsent, withdrawable at any time
Tax, accounting, and sanctions recordkeepingLegal obligation
Establishing, exercising, or defending legal claimsLegitimate interests

If you are in the EEA, UK, or Switzerland you also have the right to restrict processing, to data portability, to object to processing based on legitimate interests, and to lodge a complaint with your local data protection authority or the UK Information Commissioner’s Office. We ask that you contact us first so we can try to resolve the matter.

California residents

You have the right to know what personal information we collect, use, disclose, and retain; to access a copy of it; to delete it; to correct inaccuracies; to opt out of sale or sharing for cross-context behavioral advertising; to limit the use of sensitive personal information; and not to be discriminated against for exercising these rights.

We do not sell personal information and do not share it for cross-context behavioral advertising. In the preceding 12 months we collected the categories described in Section 2 — identifiers, commercial information, internet and network activity, and account access credentials — for the purposes in Section 3, and disclosed them for business purposes to the categories of recipients in Section 4. We treat destination webhook URLs and related routing settings as sensitive personal information when they can be used to access your connected systems, and we use them only to provide the Service, never to infer characteristics about you. We offer no financial incentives in exchange for personal information.

Other U.S. states

Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, and other states with comprehensive privacy laws have rights to access, correct, delete, and obtain a portable copy of their personal information, and to opt out of targeted advertising, sale, and certain profiling. We do not conduct targeted advertising, sale, or qualifying profiling. If we deny your request, our response will explain how to appeal, and we will respond to an appeal within the time your state’s law allows.

How to make a request

Email support@branchrouter.com from the address on your account. We will verify your identity — usually by confirming control of that email address, with additional verification for deletion requests — and we will not use verification information for any other purpose. We respond within 30 days, extendable to 90 days for complex requests with notice to you, and free of charge unless a request is excessive or repetitive. You may use an authorized agent with proof of authorization.

We may keep some information after a deletion request where the law requires it or where we need it to defend a legal claim — most often billing records and a suppression record so we do not email you again. Deleting your Branch Router data does not delete data already transmitted to a destination platform or broker; contact those providers separately.

9. International transfers

We may process data in the United States and other countries where we or our providers operate. By using the Service, you understand that your information may be transferred to jurisdictions that may have different data-protection laws than your own.

Where we transfer personal information out of the EEA, UK, or Switzerland, we rely on appropriate safeguards including the European Commission’s Standard Contractual Clauses, together with the UK Addendum or IDTA where applicable, plus technical measures such as encryption in transit and at rest. Email support@branchrouter.com for a copy of the relevant transfer mechanism.

10. Children’s privacy

The Service is intended only for individuals 18 years of age or older and is not directed to children. We do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it and close the account. If you believe a minor has provided us information, contact support@branchrouter.com.

11. Changes

We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the “Last updated” date. For material changes we will give account holders at least 30 days’ notice by email or through a prominent notice in the Service, and where applicable law requires your consent we will obtain it. Continued use of the Service after changes take effect means you accept the updated policy. Prior versions are available on request.

12. Contact

Reserve Dev Co. (operator of Branch Router)
Questions about privacy and rights requests: support@branchrouter.com
Website: https://branchrouter.com
App: https://app.branchrouter.com