Skip to content
Clics privacy-friendly cookieless web analytics documentation
Esc
navigateopen⌘Jpreview
On this page

Clics security and compliance overview for vendor reviews

Copy page

Security and compliance overview

Find Clics privacy, data policy, DPA, and terms for vendor security reviews: cookieless analytics designed with GDPR, CCPA, and PECR in mind.

Clics publishes privacy and legal documents on clics.dev. Most compliance and security review questions can be answered from those pages without contacting support.

For a single place to start vendor reviews, use this overview together with the linked policies.

Where to find the relevant documents

These pages on clics.dev are the source of truth. Prefer them over paraphrases elsewhere.

How Clics is typically classified in security reviews

Clics is privacy-first web analytics: no analytics cookies on visitors, no cross-site tracking, and measurement designed around aggregated trends rather than identifying individuals. Because of that positioning, teams often treat Clics as a lower-risk analytics vendor in GDPR-oriented reviews compared with cookie-heavy suites.

Typical reasons it falls into that category:

  • No analytics cookies on visitor browsers for standard measurement, so many sites can skip an analytics cookie banner
  • Designed with GDPR, CCPA, and PECR in mind for cookieless traffic measurement (see the Data Policy)
  • No cookies, no persistent visitor IDs for long-term profiling as described in the Data Policy; daily session resolution uses a hashed approach without storing raw IP or full User-Agent in event payloads
  • You own your site analytics data; Clics does not sell it for advertising
  • A DPA is published for customers covering processor responsibilities

Always verify details against the current legal pages. Product marketing and this docs overview do not replace counsel or your own DPIA.

What we collect (summary)

The Data Policy lists the analytics data points (for example page URL, referrer, browser, OS, device type, country). Query parameters are discarded except campaign-style params such as ref and utm_*. Country is derived from IP; the IP itself is not stored in analytics event payloads.

Subprocessors

Operational providers are listed in the Data Policy and DPA. Categories include application backend, edge/network, analytics storage, payments, authentication, and transactional email (for example Convex, Cloudflare, Tinybird, Stripe, WorkOS, Resend). Confirm the live list on those pages before a vendor review.

Security questionnaires

If your organization requires a vendor security review:

  1. Read the Data Policy, Privacy Policy, and DPA first
  2. Map questionnaire items to those documents
  3. Email contact@clics.dev only for questions that are not already answered, and include the specific unanswered items

Was this page helpful?