Privacy Policy
UseClick.io is built with privacy at its core. Read our Privacy Policy to understand how we protect your data.
1. Introduction
Welcome to UseClick.io ("we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our link shortening and analytics platform (the "Service"). We are committed to protecting your privacy and ensuring transparency about our data practices.
For your account, billing and support data, useClick is the controller. When you use useClick to track clicks on your links, measure your website, run a Link in bio page or collect email addresses, you are the controller of your visitors' data and we process it on your behalf under our Data Processing Addendum (DPA), using the providers on our subprocessor list.
2. Information We Collect
Personal Information:
- Email address (for account creation and authentication)
- Password (encrypted and securely stored)
- Profile information you voluntarily provide
- Payment information (processed securely through Stripe)
Link and Usage Data:
- Original URLs you shorten through our service
- Custom slugs and link metadata
- Click analytics data including timestamps and referrer URLs
- Cryptographically hashed visitor fingerprints (SHA-256) for unique visitor counting
- We do NOT collect or store: IP addresses or full user agent strings
Analytics Information (Privacy-First Approach):
- Geographic location: Country, region/state, and city (e.g., "United States, California, San Francisco") - derived from IP address but IP address itself is NOT stored
- Parsed device data: Browser type (e.g., "Chrome"), operating system (e.g., "Windows"), and device type (e.g., "Mobile") - we do NOT store full user agent strings
- Language preference: Browser language setting (e.g., "en-US")
- Visitor hash: a shortened SHA-256 hash used only to count unique visitors. For link clicks it is built from the browser signature, language and time zone and contains no IP address. For website analytics it also uses the IP address in memory and the current date, so it changes every day; the IP address itself is never stored
- Essential cookies only: Authentication cookies for logged-in users - no third-party tracking cookies or analytics cookies
Our Privacy-First Commitment:
- No IP address storage: We NEVER collect or store IP addresses in our database
- City-level geolocation: We collect country, region, and city for analytics, but IP addresses are never stored
- Minimal data collection: We only collect what's essential for link analytics functionality
- No full user agent storage: We parse and store only browser, device, and OS - not the full user agent string
- No cross-site tracking: No advertising cookies, tracking pixels or cross-site trackers
3. How We Use Your Information
- Provide and maintain our link shortening and analytics services
- Process payments and manage your subscription
- Generate analytics reports and insights for your shortened links
- Authenticate users and protect against unauthorized access
- Communicate with you about your account and service updates
- Improve our service quality and develop new features
- Comply with legal obligations and prevent abuse
- Provide customer support and respond to inquiries
4. Information Sharing
We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:
- Service Providers: With providers who help us run the service: Supabase (database, Frankfurt, Germany), Vercel (application hosting, USA), Cloudflare (CDN, edge redirects and bot protection), Sentry (error monitoring and replays of a sample of sessions with page text masked, EU data region), Resend (email delivery), Google (Safe Browsing link checks and website icons on Link in bio pages, fetched by our server; bio page fonts are self-hosted), Stripe (payments) and Crisp (support chat in the dashboard). Our own marketing pages are measured with useClick's own cookieless website analytics and a self-hosted Plausible Analytics instance. The full list, with the data each provider receives, its location and the transfer safeguard, is on our subprocessor list.
- Legal Requirements: When required by law or to protect our rights and prevent illegal activities
- Business Transfers: In connection with any merger, acquisition, or sale of assets
- Consent: With your explicit consent for specific purposes
5. Data Security
We implement industry-standard security measures to protect your information:
- Encryption in transit (HTTPS/TLS) for the website, dashboard, API and redirects
- Secure authentication with hashed passwords and a bot check on sign-in and sign-up
- Row Level Security in the database, so each account can only read its own data
- API keys stored only as SHA-256 hashes, with rate limits per plan
- Access controls and principle of least privilege
- Error monitoring with Sentry in its EU data region
6. Data Retention
We retain your information for as long as necessary to provide our services and comply with legal obligations:
- Account information: Until you delete your account (available in Account Settings)
- Link data: Deleted immediately when you delete your account
- Click and website analytics data: Kept for the retention window of your plan, then deleted automatically: Free 30 days, Starter 12 months, Growth 24 months, Pro and Business 3 years
- Payment records: As required by financial regulations (typically 7 years) - maintained separately for legal compliance only
Automatic Data Deletion:
A job runs every day at 3:00 AM UTC and permanently deletes click and page-view records that are older than the retention window of the account's plan. Website analytics queries are also limited to that window on the server. This keeps storage in line with the GDPR storage limitation principle.
Account Deletion:
You can delete your account at any time from your Account Settings. Account deletion is immediate and permanent. All your links, click data, and account information will be permanently deleted. Payment records are retained separately for 7 years as required by financial regulations. If you need assistance with account deletion, contact us at [email protected].
7. Your Rights
You have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you
- Correction: Update or correct inaccurate personal information
- Deletion: Request deletion of your personal information (subject to legal requirements)
- Portability: Export your data in a machine-readable format
- Opt-out: Unsubscribe from marketing communications
- Account Deletion: Delete your entire account and associated data
8. Cookies and Tracking
We take a privacy-first approach to cookies and tracking:
- Essential cookies only: We use only authentication cookies required for logged-in users to maintain their session. These cookies are necessary for the service to function and cannot be disabled.
- No analytics cookies: We do NOT use cookies for analytics or tracking purposes. All analytics are collected server-side without browser cookies.
- No advertising or tracking cookies: We do NOT use advertising cookies or tracking pixels (no Google Analytics, Facebook Pixel, etc.). Our marketing pages count visits with useClick's own cookieless website analytics (the same script our customers use; no IP address is stored) and a self-hosted, cookieless Plausible Analytics instance. The dashboard and your visitors' pages are not measured.
- Support chat: Inside the dashboard, the Crisp support chat widget stores its own session data in your browser so that your conversation continues across pages. It is not loaded on our public pages or on short links.
- No cookie banner: We do not set advertising or tracking cookies, so our public pages do not show a cookie consent banner.
Technical details: Authentication cookies are set by our sign-in provider (Supabase Auth), are scoped to our domain only, and are removed when you log out.
9. International Data Transfers
EU Data Hosting: Our database, including all link, click and website analytics data, is hosted by Supabase in Frankfurt, Germany.
Providers outside the EU: Our application is hosted by Vercel Inc., a US company, and Cloudflare, Inc. (USA) serves requests from its worldwide edge network. Resend (email), Google and Stripe are also US companies or have US parents. Sentry stores error data in its EU region. Requests can therefore be processed outside the EU, for example while a click is redirected.
We transfer personal data outside the EU only with a safeguard under Chapter V GDPR: the European Commission's adequacy decision for the EU-US Data Privacy Framework (Article 45 GDPR) for certified companies, and Standard Contractual Clauses (Article 46 GDPR). The safeguard for each provider is listed on our subprocessor list.
10. Children's Privacy
Our service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. For significant changes, we may provide additional notice.
12. Contact Information
If you have any questions about this Privacy Policy or our data practices, please contact us at:
Email: [email protected]Website: https://useclick.io
Response Time: We aim to respond to all privacy inquiries within 48 hours.
