<?xml version="1.0" encoding="UTF-8"?>
<!--
  Only the pages a stranger can open and that are worth indexing.

  Everything behind ProtectedRoute is left out because it 302s to the sign-in
  page for a crawler, and /track/ is left out on purpose: those URLs carry a
  secret in the path and are disallowed in robots.txt, sent noindex by the page,
  and refused by the API. Listing one here would undo all three at once.

  Deliberately absent too: /driver-register, /driver-reset and /staff-register.
  They are public, but they are meaningless without a token in the query string
  and index as an error state.

  Hosts must match the canonical origin in Caddyfile and the <link rel=canonical>
  in index.html — the apex, not app. or www., both of which 302 here.
-->
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <url>
    <loc>https://gethitchlink.com/</loc>
    <changefreq>weekly</changefreq>
    <priority>1.0</priority>
  </url>
  <url>
    <loc>https://gethitchlink.com/registration</loc>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://gethitchlink.com/business-register</loc>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://gethitchlink.com/login</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://gethitchlink.com/support</loc>
    <changefreq>monthly</changefreq>
    <priority>0.4</priority>
  </url>
  <url>
    <loc>https://gethitchlink.com/terms</loc>
    <changefreq>yearly</changefreq>
    <priority>0.3</priority>
  </url>
  <url>
    <loc>https://gethitchlink.com/privacy</loc>
    <changefreq>yearly</changefreq>
    <priority>0.3</priority>
  </url>
  <url>
    <loc>https://gethitchlink.com/refund</loc>
    <changefreq>yearly</changefreq>
    <priority>0.3</priority>
  </url>
</urlset>
