Legal

Privacy Policy

How ClickClacks handles personal data, both yours as a customer and your visitors' when you measure them with ClickClacks.

Last updated: [Effective date]

This Privacy Policy explains what personal data [Company legal name] ("ClickClacks", "we", "us") collects, why, and what choices you have. It applies to the ClickClacks website at clickclacks.io, the ClickClacks application at app.clickclacks.io, and the ClickClacks tracker script that our customers install on their own websites and apps (together, the "Service").

1. Who we are

ClickClacks is a product analytics service. Customers add a small script to their websites and apps and use ClickClacks to understand how people move through them, with funnels, retention, experiments and heatmaps.

The Service is operated by [Company legal name], [Registered address]. You can reach us about privacy at [Contact email].

2. Our two roles

We handle personal data in two different capacities, and this policy covers both.

  • As a controller. We decide how and why we process data about the people who hold ClickClacks accounts, the people invited into them, and the people who visit this website. Sections 3 to 5 describe that processing.
  • As a processor. When a customer installs the ClickClacks tracker, we collect and store data about their visitors and users ("end users") on the customer's behalf and under the customer's instructions. The customer is the controller of that data. Sections 6 to 8 and 14 describe that processing. Our processing for customers is also governed by our data processing agreement: [Data processing agreement link].

3. Information about account holders

When you create or use a ClickClacks account, we collect:

  • Account details: your name, email address, and the credentials you choose to sign in with, which may be a password, a passkey, or one-time sign-in links and codes sent to your email address. If you turn on two-factor authentication we store what is needed to verify your second factor.
  • Profile details you add, such as a profile picture.
  • Organization and team details: the organizations, agencies and projects you create or join, your role in them, and the invitations you send or receive, including the email addresses of the people you invite.
  • Session and security information: for each signed-in session we record the IP address and browser user agent, so you can review and revoke your active sessions. We also keep records of sign-in attempts to protect accounts from abuse, and an audit log of significant actions taken inside an organization.
  • Configuration and content you create: projects, sources, reports, boards, annotations, and settings.
  • Communications: messages you send us and the emails we send you, such as sign-in links, invitations and notifications.
  • Billing information: [Describe billing data and payment processor, if and when paid plans launch].

4. Visitors to this website

When you visit clickclacks.io, our hosting provider processes standard request data, such as your IP address, browser user agent and the page requested, in order to serve the website and protect it from abuse.

If you choose a light or dark theme, your choice is remembered in your browser's local storage. It is not sent to us.

[State whether this website measures its own visitors with ClickClacks or any other analytics tool. If it does, describe it here with reference to Section 6.]

5. How we use information and our legal bases

We use the information described in Sections 3 and 4 to:

  • provide, operate and maintain the Service, including signing you in;
  • secure accounts and the Service, and detect and prevent fraud and abuse;
  • send you service messages, such as sign-in links, invitations, security alerts and notifications you have enabled;
  • respond to your requests and provide support;
  • understand and improve how the Service is used; and
  • comply with legal obligations and enforce our Terms of Service.

Where the law requires a legal basis, we rely on [Confirm legal bases, for example: performance of our contract with you; our legitimate interests in securing and improving the Service; your consent where required; and compliance with legal obligations].

We do not sell personal data. [Confirm, and add any marketing-email practices.]

6. Data we process for customers

Customers decide whether to install the tracker, on which websites and apps, and what custom events and properties to send. Depending on that setup, the tracker and our collection endpoint process the following about end users:

Collected automatically

  • Pageviews: the page path and, unless the customer turns query strings off, its query string, with sensitive parameters removed (see Section 7); the referring URL on the first page of a visit.
  • Clicks (a customer can turn these off): the kind of element clicked, its id, up to two class names, a short CSS selector, the click position, the viewport width, and up to 40 characters of the visible text of a clicked link or button.
  • Scroll depth: how far down the page someone scrolled.
  • Pseudonymous identifiers: a random person ID and a random session ID generated in the browser. A session ends after 30 minutes of inactivity. These IDs contain no personal information in themselves.
  • Request details: the country derived from the request by our hosting provider, and the browser, operating system and device type parsed from the user agent.
  • IP address: not stored by default. A customer can choose to record it for a source.

Sent by the customer

  • Custom events and properties that the customer sends, for example a "signed up" event.
  • User identifiers that the customer sends when they identify a signed-in user, and any properties attached to that call. The customer decides what identifier to use.

Heatmap page layouts

If a customer enables heatmaps, the tracker may capture the layout of a page so clicks can be drawn on top of it. Depending on the customer's setting this is either a wireframe of element positions and colours, in which text is drawn as blank bars, or a masked screenshot of the page. Section 7 explains what is masked.

Linking across a customer's domains

When a customer lists more than one domain (for example their marketing site and their app), links between those domains carry the person and session ID in a temporary _ccid URL parameter, which the tracker removes from the address bar as soon as the next page loads. This lets the customer see one journey across both domains.

We use data processed for customers only to provide the Service to that customer, as set out in our agreement with them. [Confirm any other permitted uses, such as aggregated service-improvement statistics, with counsel.]

7. Safeguards built into the tracker

  • Sensitive URL parameters are removed in the browser. Before an event leaves the browser, the tracker strips query parameters named like secrets, including code, password, pwd, auth, session, sid, signature, otp, apikey, email, phone, ssn, card and cvv, and any parameter ending in token, key or secret. The same rule applies to referrer URLs.
  • Form fields are not read. Click text is not recorded for inputs, text areas, editable regions, password fields, or anything a customer marks with data-cc-mask.
  • Heatmap screenshots are masked before upload. Form fields, embedded frames, video, canvas and any element marked data-cc-mask or data-private are replaced with grey blocks. Email addresses and digits in the remaining text are replaced with dots, and form values, placeholders, titles and image alt text are removed.
  • Allowed domains only. The tracker runs only on domains the customer has listed, and our collection endpoint rejects browser events from any other origin.
  • Known bots are filtered by default.
  • Opt-out is built in. Customers can call the tracker's opt-out function, which stops collection on the current page and deletes the IDs the tracker stored in that browser.

8. Cookies and browser storage

The ClickClacks tracker does not set cookies. It keeps its identifiers in the browser's local storage and session storage, on the customer's own domain:

NameWherePurpose
ccpLocal storageRandom person ID, so return visits can be recognised.
cciLocal storageThe user identifier the customer set when identifying a signed-in user, if any.
ccs, cclSession storageRandom session ID and the time of the last event, used to end a session after 30 minutes of inactivity.
_cc_capLocal storageRemembers which page layouts were already captured for heatmaps, so they are not captured again.

Whether these require consent depends on the law that applies to the customer and its end users. Customers are responsible for providing any notice and obtaining any consent their use of ClickClacks requires. [Counsel to confirm the position for ePrivacy / PECR and similar laws.]

The ClickClacks application at app.clickclacks.io uses cookies that are strictly necessary to keep you signed in. [List any other cookies used by the application or this website.]

9. Sharing and subprocessors

We share personal data only as follows:

  • Service providers (subprocessors) who host and operate the Service for us, under contracts that limit their use of the data. The Service runs on Cloudflare, which provides hosting, storage, email delivery and bot protection. Our current list is here: [Subprocessor list].
  • Within your organization. Other members of an organization can see data in the projects they have access to, including member names and email addresses and, depending on their role, the organization's audit log.
  • At a customer's direction, for example when a customer connects a webhook or uses an API credential to export their data.
  • For legal reasons, where we are required to by law or to protect the rights, property or safety of our users, the public or ClickClacks.
  • In a business transfer, such as a merger or acquisition, subject to this policy.

10. International transfers

Our providers may process data in countries other than your own. Where the law requires it, we rely on [Transfer mechanism, for example the EU Standard Contractual Clauses] to protect data transferred internationally. [Counsel to confirm data locations.]

11. Retention

  • Account data: kept while your account is active, then [Account data retention period].
  • Analytics data processed for customers: [Analytics data retention period], or as agreed with the customer.
  • Audit log entries: [Audit log retention period].
  • Backups and logs: [Backup and log retention period].

You can request an export of your account data and delete your account from your account settings in the application. Authorised members of an organization can also export that organization's data.

12. Security

We use technical and organizational measures designed to protect personal data. Our Security page describes them. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

13. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to the processing of your personal data, to receive it in a portable format, and to withdraw consent you have given. You may also have the right to complain to a data protection authority.

To exercise these rights for data we control, contact [Contact email]. Many of them can also be exercised directly in your account settings. We will respond within the time the law requires.

14. If a ClickClacks customer measured you

If you visited a website or app that uses ClickClacks, that business is the controller of the data collected about you, and requests about it should go to them first. If you contact us instead, we will pass your request to the relevant customer where we can identify them, and help them respond.

15. Children

The Service is not directed to children under [Minimum age], and we do not knowingly collect personal data from them for our own purposes. Customers must not use ClickClacks to measure services directed to children in breach of applicable law.

16. Changes to this policy

We may update this policy from time to time. We will post the new version here with a new "Last updated" date and, where the changes are material, tell account holders by email or in the application before they take effect.

17. Contact us

[Company legal name]
[Registered address]
[Contact email]

[Name and contact details of an EU / UK representative or data protection officer, if required.]