Data and Privacy
How CleanClicks handles your data, your visitors' data, and privacy compliance.
How CleanClicks handles your data, your visitors' data, and privacy compliance.
First-Party Data Architecture
CleanClicks operates as a first-party data processor. All tracking data flows through your own subdomain (cleanclicks.yourdomain.com), which means:
- No third-party cookies. CleanClicks uses first-party cookies only.
- No cross-site tracking. Data is scoped to your domain.
- No data resale. Your conversion data is never shared with other CleanClicks customers, sold, or used for any purpose other than relaying it to the ad platforms and analytics tools you connect.
CleanClicks also provisions a dedicated GA4 property that it owns and operates on your behalf under service-provider terms. It is used for first-party, server-side measurement and is separate from your own primary GA4 property, which your existing analytics stack continues to populate untouched.
By default, CleanClicks measures visitors in the United States only (a US-only geo allowlist). You can add other countries or turn geo filtering off in Configuration > Traffic Filters.
What Data Is Collected
From Visitors
| Data | Purpose | Storage |
|---|---|---|
| Session ID | Track visitor across pages | First-party cookie, 90-day retention |
| Click IDs (gclid, fbclid, etc.) | Ad attribution | First-party cookie, 90-day retention |
| UTM parameters | Campaign attribution | First-party cookie, 90-day retention |
| IP address | Geo classification + bot detection | Used in real time; not kept in long-term identity records |
| User agent | Device classification, bot detection | Used in real-time, not stored |
| Page URL | Trigger matching | Processed, not stored separately |
| Email (when provided) | Cross-platform matching | SHA-256 hashed in the browser (the raw email never leaves the browser); the hash is stored in the email-to-click-ID map for 90 days |
From Ecommerce
| Data | Purpose |
|---|---|
| Order ID | Deduplication |
| Order total / currency | Revenue reporting |
| Product details | Product-level conversion tracking |
| Customer email | Hashed for cross-platform matching |
Data Retention
| Data Type | Retention Period |
|---|---|
| Conversion events | 90 days |
| Email-to-click-ID mapping | 90 days |
| Failed event retries | 90 days |
| Traffic analytics | 90 days |
| Conversion audit log | 180 days |
| Advertising click ID / visitor ID cookies | Up to 1 year |
| Session cookie (cc_sid) | 30 minutes |
| Deduplication records | 24 hours |
| Ad platform OAuth tokens | 30 days |
After the retention period, data is automatically purged. There is no "keep forever" option.
Hashing and Encryption
- Customer emails are SHA-256 hashed before being sent to any ad platform. The raw email is never shared with third parties.
- Ad platform credentials (OAuth tokens, API keys) are encrypted at rest using AES-256-GCM with per-customer encryption keys.
- API keys are stored as SHA-256 hashes. The raw key is shown once at creation and never stored.
CCPA and opt-out behavior
When a visitor opts out (via Global Privacy Control, a CleanClicks opt-out cookie, or your consent platform's "reject" applied through the WordPress plugin's consent bridge), CleanClicks stops sending that visitor's data to advertising platforms:
- Meta, TikTok, LinkedIn, and Microsoft Advertising receive nothing.
- Google Ads conversions are limited to privacy-preserving signals with the advertising click identifiers removed, so they cannot be tied to the visitor.
- First-party website analytics continue as measurement only. Google Analytics receives the activity as first-party measurement, with the advertising signals (ad personalization and ad-user-data) set to denied.
- Personal identifiers are stripped for every platform: hashed email, IP address, user agent, geo, and device type are removed from opted-out events.
CleanClicks does not transmit Limited Data Use or limited-data-use flags. The previous LDU pathway was removed on 2026-05-29 so that opted-out visitors are dropped before dispatch rather than sent under a restriction flag.
GPC (Global Privacy Control)
CleanClicks honors GPC in real time, before any data is transmitted. The tracking script reads the browser's navigator.globalPrivacyControl signal, and the CleanClicks edge worker also honors the Sec-GPC request header and the CleanClicks opt-out cookie directly. A GPC signal is treated as a valid opt-out under California law. On WordPress, the plugin additionally integrates with the WP Consent API to detect GPC and consent-management platforms.
GDPR
GDPR-specific features (consent gates, TCF 2.2 integration, right-to-erasure) are on the roadmap but not yet available. For EU-focused businesses, consult your legal team about compliance requirements with the current feature set.
Data Residency
Conversion data is processed globally across CleanClicks infrastructure. If your business requires data to remain in a specific geographic region, contact helpdesk@cleanclicks.io to discuss options.
Your Obligations
As a CleanClicks customer, you are responsible for:
- Disclosing tracking in your privacy policy. Your site's privacy policy should mention the use of first-party tracking technology for conversion measurement.
- Respecting visitor consent. If your jurisdiction requires consent for tracking (GDPR, ePrivacy), implement a consent mechanism on your site.
- Managing ad platform compliance. Each ad platform has its own data processing terms. Ensure your use of those platforms complies with their policies.
Accessing or Deleting Your Data
To request data export or deletion, contact helpdesk@cleanclicks.io. Account data (profile, configuration) can be exported or deleted on request.
For visitor data: because visitor data is stored as hashed identifiers with 90-day retention, specific visitor records automatically expire. For urgent deletion requests, contact support.
CleanClicks Privacy Policy
The full CleanClicks privacy policy is available at cleanclicks.ai/privacy-policy. The terms of service are at cleanclicks.ai/terms.
Related: Plan Comparison | Traffic Filters