This Privacy Policy ("Policy") describes how Roxr Software Ltd ("Roxr", "we", "us", or "our") collects, uses, and shares information provided to us through our website clicky.com (the "Site"), and the services available through our Site ("Clicky", "Service", or "Services").

We collect information about users of our Service (our "Customers"), as well as our Customers' end users ("End Users") (collectively, "you", "your", or "yourself"). Note that Customers are also End Users, as we use our own Service to track itself. Some of the information collected may be Personal Data (defined as personal data of End Users that is processed by Roxr on behalf of Customers). Your rights regarding Personal Data are described in this Policy.

By using the Service, you agree that your information will be handled as described by this Policy, and that your usage and any disputes over privacy are subject to this Policy and our Terms of Service ("Terms") which are incorporated by reference into this Policy.


TL;DR

We value the privacy of our Customers and will not share any information about them or their traffic data with any third party for any purpose, unless required for legal reasons such as a government subpoena.

We value the privacy of End Users. By default, the Service does not log any Personal Data of End Users; IP addresses are anonymized, "Do Not Track" headers and global opt out cookies are honored, and custom data tracking is disabled (which can be used to attach extra data to a visitor, potentially including personal info such as name or email).

However, the General Data Protection Regulation ("GDPR"), a law in the European Economic Area ("EEA"), does consider our Unique ID ("UID") tracking cookie to be Personal Data, even though it does not identify who a visitor is (e.g. their real name) or reveal anything else about them. Tracking UIDs of End Users is lawful without consent as it is well within the "legitimate interests" of a web site to know how many unique visitors are visiting their site, which is best accomplished with a UID cookie.

If you are an EEA citizen, you have the legal right to access, correct, and/or delete your Personal Data. Customers may contact us directly to do so, while End Users should send their inquiries directly to our Customers.


Information we collect

We collect information about you through your use of our Service and/or from the web sites and services provided by our Customers.

From Customers

When you create an account, you provide us with a username, password, real name, and email address, as well as one or more web sites that you own and want to monitor with the Service. If you make a purchase, you provide us with your billing information such as card number and address. This information is used for the purposes of having and maintaining your account. Your email is only used for important account notifications, such as a failed payment or a subscription about to expire.

End Users

We collect information from End Users under the instruction of our Customers, under which circumstance we have no direct relationship with the End Users.
The following information is sent to our servers by default when an End User visits a Customer's web site.
  • URL & Title of pages viewed
  • URL & Title of any links that are clicked on pages viewed
  • Referrer
  • User agent
  • Browser language
  • Screen resolution
  • x/y coordinates of mouse events
  • Unique ID tracking cookie ("UID")
    The GDPR considers this to be Personal Data, even though it is randomly generated and does not identify who you are or reveal anything else about you.
    Its sole purpose is to more accurately track unique visitors.
  • IP address ("IP")
    IPs are anonymized before processing, but our Customers have the option to disable this, in which case they are considered Personal Data.
  • Custom data
    This feature can be used by a site to attach additional data to a visitor, potentially including Personal Data such as a name or email address, but it is against our Terms to log Personal Data using this feature without disclosure or (depending on "legitimate interest") consent. This feature requires a small amount of configuration and coding by Customers, so only a small percentage of Customers use it.

Per Article 6 of the GDPR, processing of UID and IP Personal Data is lawful and does not require your direct consent because it is "necessary for the purposes of the legitimate interests" of web sites using the service. These legitimate interests include but are not limited to:
  • Assembling statistics regarding the use of a web site. (Accurately counting unique visitors is a vital statistic for any web site).
  • Preventing fraud and abuse, and maintaining information security. (Full IP addresses are necessary for this type of usage). Recital 47 of the GDPR states: "The processing of Personal Data strictly necessary for the purposes of preventing fraud also constitutes a legitimate interest".

As End Users of our service, the types of information listed above are also collected about our Customers when they are using our Service. The Personal Data that we log is as follows:
  • Your UID and IP address, per the legitimate interests above.
  • Your account username, per the legitimate interests above, as well as to help with customer service needs.


How we use your information


Customers

  • To provide and maintain our Service to you.
  • To help understand how Customers use our Service on an individual and aggregate basis in order to improve it.
  • To help with customer service needs, such as troubleshooting issues that you report to us.
  • To contact you with important account notifactions, such as a failed payment or subscription about to expire.
  • Other research and analytical purposes such as Service performance, Customer behavior and retention, and common navigations through the Site.

End Users



How we share your information

We don't share your information with any third party for any purpose, unless required for legal reasons such as:
  • Meeting applicable laws, regulations, legal processes, or enforceable governmental requests.
  • Enforcing applicable Terms of Service.
  • Detecting, preventing, or otherwise addressing fraud, security, or technical issues.
  • Protecting against harm to the rights, property or safety of Roxr, our Customers, or the public as required or permitted by law.


Cookies

The following cookies are used with the Service. All cookies are first party unless otherwise noted. Session cookies (those that expire when you leave a web site) are not listed.

Customers

  • clicky_userdata -- If you check "remember me" on the login page, this cookie is set for 1 year to automatically log you in on future visits. Deleted if you manually "log out" of the Site.
  • osa -- Third party (attached to our tracking domains). Used to authenticate the on-site analytics widget when visiting your own web sites. Deleted if you manually "log out" of the Site.
  • ignore -- Third party (attached to our tracking domains). Used to ignore your own visits to your own web sites.

End Users

  • _referrer_og -- Stores external referrer for 90 days, for better long term attribution of traffic sources.
  • _utm_og -- Stores dynamic (UTM) campaign variables for 90 days, for better long term attribution of marketing efforts.
  • _custom_data_[key] -- Only set when a site is using custom data tracking and the site has flagged an End User as having fully consented to tracking Personal Data. These cookies cache certain custom data keys for 30 days so that they're attached to sessions even when a visitor is not logged in.
  • _jsuid -- Unique ID tracking cookie.
  • cluid -- Third party Unique ID tracking cookie (attached to our tracking domains). Used solely to identify the same visitor across multiple domains belonging to the same customer. The first party cookie is updated to match the third party one if both are set and the values don't match.

Customers can disable End User cookies by setting clicky_custom.cookies_disable.


Security

To the best of our ability, we protect all of our data from loss, misuse, and unauthorized access and destruction.

Secure (HTTPS) access is forced for our Site to help keep your information, including login credentials, secure in transit. You are responsible for using a strong and unique password for the Site to help keep your account secure. We are not responsbile for any unauthorized activity on your account because of lost, weak, or compromised passwords.


Personal Data rights

EEA citizens have the legal right to access, correct, and/or delete their Personal Data. EEA Customers may contact us directly to do so, while EEA End Users (with whom we we have no direct relationship) should send their inquiries directly to the Customer in question.

If we receive a request from an End User in relation to Personal Data processed for a Customer, we will advise the End User to submit their request to Customer, and Customer will be responsible for responding to such request using the tools we have provided on our Site for handling Personal Data requests. Customer agrees to use all reasonable measures to verify the identity of an End User before sharing or modifying Personal Data.

Customers can export their data using the API or the export function within any report, or delete their account using the link at the top of the user preferences page. We try to protect information from accidental or malicious deletion, so there may be delays between when you delete something and when copies are deleted from our active and backup systems.

We retain Personal Data on behalf of our Customers for as long as needed to provide our Service to them, or as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.

Our Service is not designed for children under 13. If we discover that a child under 13 has provided us with personal information, we will delete such information from our systems.


Contact us

If you have any questions about this Policy or would like to make a complaint, please contact us by email.

Roxr Software Ltd
10883 SE Main St #201
Milwaukie, OR, 97222


Changes to this Policy

This Policy is active as of the date below and is updated from time to time. We will notify you via your registered email address or a notice on this website prior to any significant changes becoming effective regarding Personal Data. You should periodically review this page for the latest information.

May 25 2018