Privacy Policy
Data controller and scope
The controller of Personal Data for the Cliqly service is CLIQLY, a sole proprietorship with its registered address at Golf Island, Jl. Rukan Beach Boulevard No. 75 & 76, Jl. Concerto Beach Blvd, Kamal Muara, Jakarta Utara 14470.
This policy covers two different groups of people:
- Account holders — people who sign up, sign in and use the Cliqly dashboard or API.
- Link visitors — people who click a short link created by an account holder. A visitor has no Cliqly account and generally never deals with us directly.
For link-visitor data, the account holder is the controller and Cliqly is the processor acting on their instructions. For the account holder’s own data — email address, name, subscription history — Cliqly is the controller.
What we collect from account holders
| Data | What for |
|---|---|
| Name and email address | Creating an account, signing in, and sending service and billing notices. |
| Password | Stored as a hash that cannot be reversed. We never hold your password in readable form. |
| Sign-in sessions | A coarse device label (for example “Chrome on macOS” — no version, no device model) and a truncated IP address: /24 for IPv4 or /48 for IPv6, truncated before it is stored. Enough for you to recognise your own sessions, not enough to track anyone. |
| Billing data | Subscription history, invoices, and — so we can show them back to you — the card brand, the last four digits and the expiry month and year. A full card number never reaches our systems. |
| Content you create | Destination URLs, slugs, titles, tags, domains, targeting rules, QR configuration and uploaded logos. |
| Correspondence | Emails you send us and our replies to them. |
What we collect from link visitors
Each time a short link is opened we record one click event. This is everything it contains:
- The time of the click, and which link and domain were opened.
- A fingerprint of the IP address — not the address itself. See below.
- Coarse location: country code, country name, region code and city name. No coordinates, no street address, no GPS data.
- Device type (mobile, desktop, tablet or bot), the operating system name and the browser name — with no version numbers.
- The referring host name, and the full referrer URL (truncated at 2,048 characters).
- The campaign parameters
utm_source,utm_mediumandutm_campaignwhen present on the URL. - Which A/B variant was served, and the HTTP status code returned.
What we technically never store
- Raw IP addresses — there is no column for one in our database.
- The raw User-Agent — it is parsed into device type, operating system and browser, then discarded. A full User-Agent string is a high-entropy fingerprint and we do not keep it.
- The language header (
Accept-Language) — not stored. - The visitor’s network operator / ASN — used momentarily to tell bots from humans, then discarded.
How location is determined
From a GeoIP database held on our own servers — DB-IP Lite, licensed under CC BY 4.0. A visitor’s IP address is not sent to anyone for this, and no outbound network request is made while location is determined. Accuracy is limited to city level and is often wrong — we present it as an estimate, not as a fact.
How “human” clicks are told from bot clicks
Purely from matching the User-Agent string and the origin network (known data centres). There is no device fingerprinting, no JavaScript challenge, no cookie and no behavioural analysis. The label is a best guess, not a certainty.
One technical disclosure
A raw IP address passes briefly through our internal queue before its fingerprint is computed and the address is discarded. That queue is not reachable from the internet and is not included in file backups.
Purposes and lawful basis
| Purpose | Basis (PDP Law / GDPR) |
|---|---|
| Providing the service you signed up for | Performance of a contract — PDP Law Art. 20(2)(b); GDPR Art. 6(1)(b) |
| Charging subscriptions and issuing invoices | Performance of a contract, and a legal tax obligation — GDPR Art. 6(1)(b) and 6(1)(c) |
| Click analytics for the link owner | The link owner’s legitimate interest in measuring their distribution channels, balanced against minimising visitor data — GDPR Art. 6(1)(f) |
| Preventing fraud, phishing and abuse | A legitimate interest in protecting visitors and domain reputation — GDPR Art. 6(1)(f) |
| Email verification for free subdomains | A legitimate interest in preventing bulk account creation — GDPR Art. 6(1)(f) |
| Complying with lawful requests from authorities | A legal obligation — GDPR Art. 6(1)(c) |
We do not sell personal data, do not exchange it with third parties for marketing, and carry out no automated decision-making that produces legal effects for link visitors.
How long data is kept
| Data | Retention |
|---|---|
| Raw click events (including the IP fingerprint and the full referrer URL) | 90 days |
| Daily rollups: click counts per day per link, by country, city, device, operating system, browser, referring host and UTM parameter | Indefinitely. They contain counts only — no IP fingerprint, no referrer URL, and nothing that points at an individual. |
| Webhook delivery records (which contain the payload) | 30 days |
| Account, link and domain data | For as long as the account is active |
| Data after an account is deleted | Permanently deleted after a 30 calendar day grace period. Free subdomains are released back to the public at that point. |
| Invoices and payment records | Kept for as long as tax and bookkeeping rules require, even after the account is closed. |
| Abuse tickets and evidence | 2 years |
Worth noting: the daily rollups carry location down to city level. After 90 days the region level disappears with the raw clicks, while country and city survive as counts.
Third parties that process data
This list is complete. There are no other recipients.
| Party | What they receive |
|---|---|
| Paddle (payment processor and merchant of record) | Your name, email address and the payment details you enter directly on Paddle’s own checkout. Card data does not pass through us at all. Paddle acts as merchant of record and its processing is governed by its own privacy policy. Where Stripe is configured instead, the same applies to Stripe. |
| Infrastructure and hosting — CLIQLY uses the providers listed on the Contact page | They hold all service data on their servers, under confidentiality and security agreements. |
| A URL safety-checking service | When safety checking is enabled, a link’s destination URL is submitted to be checked against threat lists. No visitor data is sent with it. |
| Your own webhook endpoint | If you configure one, we send your account’s events to the address you specify. We never send per-visitor click data to a webhook. |
| Law enforcement | Only on a request that is lawful under the law that binds us, and only to the extent of data we actually hold. |
Some of the providers above may process data outside Indonesia. For such transfers we require an equivalent level of protection as set out in Article 56 of the PDP Law and — for visitors in the European Union — standard contractual clauses under GDPR Chapter V.
Security
- All traffic runs over HTTPS with automatically renewed certificates.
- Passwords are stored as hashes, never in readable form.
- The session cookie is marked
HttpOnlyandSecure, and holds a random identifier rather than your identity. - API keys are shown once at creation and can be revoked instantly from the dashboard.
- Sign-in attempts are rate-limited to blunt password-guessing attacks.
- No system is completely secure. In the event of a personal data breach we notify you and the competent authority as the PDP Law requires, within 3 × 24 hours of becoming aware of it.
Your rights
Under Indonesia’s Law No. 27 of 2022 on Personal Data Protection — and, if you are in the European Union or the European Economic Area, under the GDPR — you have the right to:
- Know what personal data we process about you, and for what purpose.
- Obtain a copy of your personal data in a machine-readable format.
- Correct data that is inaccurate or incomplete.
- Request deletion of your personal data, so far as that does not conflict with retention obligations under tax and bookkeeping rules.
- Withdraw consent, where processing is based on consent.
- Restrict or object to particular processing.
- Lodge a complaint with the competent supervisory authority.
How to exercise your rights
Send your request to privacy@cliqly.dev from the email address registered on your account. We answer within 30 calendar days of receiving it. If the request comes from a different address we will ask you to verify your identity first — not to make it difficult, but because handing account data to the wrong person is itself a breach.
For link visitors
If you clicked a Cliqly link and want your click data deleted, there is a limitation we have to state honestly: we do not store your IP address, so we have no way of finding which clicks were yours. That inability follows directly from not storing an identifier for you, and we regard it as a protection rather than a shortcoming. All raw clicks delete themselves after 90 days.
If you received a Cliqly link you believe is a scam or spam, report it to abuse@cliqly.dev. Reports are answered within 24 hours.
Children’s data
The Cliqly service is not intended for children under 18, and we do not knowingly collect a child’s personal data. If you become aware that a child has created an account without a parent or guardian’s consent, tell us at privacy@cliqly.dev and we will delete the account and its data.
Changes to this policy
This policy can change — when we add a third-party processor, for instance, or alter a retention period. The current version is always on this page, with a “Last updated” date at the top.
Material changes — a new category of data collected, a new recipient, or a longer retention period — are announced by email at least 30 calendar days before they take effect.
Contacting us about privacy
- Questions and data-rights requests: privacy@cliqly.dev
- General support: support@cliqly.dev
- Link abuse reports: abuse@cliqly.dev
- Post: CLIQLY, Golf Island, Jl. Rukan Beach Boulevard No. 75 & 76, Jl. Concerto Beach Blvd, Kamal Muara, Jakarta Utara 14470
- Telephone: +62 823-1036-3626