Security and compliance overview
Find Clics privacy, data policy, DPA, and terms for vendor security reviews: cookieless analytics designed with GDPR, CCPA, and PECR in mind.
Clics publishes privacy and legal documents on clics.dev. Most compliance and security review questions can be answered from those pages without contacting support.
For a single place to start vendor reviews, use this overview together with the linked policies.
Where to find the relevant documents
- Data Policy: what visitor analytics data Clics collects, why, and how it is handled
- Privacy Policy: how Clics handles data related to account holders and the service
- Data Processing Agreement (DPA): GDPR processor obligations that apply to Clics customers
- Terms of Use: contractual terms for using Clics
These pages on clics.dev are the source of truth. Prefer them over paraphrases elsewhere.
How Clics is typically classified in security reviews
Clics is privacy-first web analytics: no analytics cookies on visitors, no cross-site tracking, and measurement designed around aggregated trends rather than identifying individuals. Because of that positioning, teams often treat Clics as a lower-risk analytics vendor in GDPR-oriented reviews compared with cookie-heavy suites.
Typical reasons it falls into that category:
- No analytics cookies on visitor browsers for standard measurement, so many sites can skip an analytics cookie banner
- Designed with GDPR, CCPA, and PECR in mind for cookieless traffic measurement (see the Data Policy)
- No cookies, no persistent visitor IDs for long-term profiling as described in the Data Policy; daily session resolution uses a hashed approach without storing raw IP or full User-Agent in event payloads
- You own your site analytics data; Clics does not sell it for advertising
- A DPA is published for customers covering processor responsibilities
Always verify details against the current legal pages. Product marketing and this docs overview do not replace counsel or your own DPIA.
What we collect (summary)
The Data Policy lists the analytics data points (for example page URL, referrer, browser, OS, device type, country). Query parameters are discarded except campaign-style params such as ref and utm_*. Country is derived from IP; the IP itself is not stored in analytics event payloads.
Subprocessors
Operational providers are listed in the Data Policy and DPA. Categories include application backend, edge/network, analytics storage, payments, authentication, and transactional email (for example Convex, Cloudflare, Tinybird, Stripe, WorkOS, Resend). Confirm the live list on those pages before a vendor review.
Security questionnaires
If your organization requires a vendor security review:
- Read the Data Policy, Privacy Policy, and DPA first
- Map questionnaire items to those documents
- Email contact@clics.dev only for questions that are not already answered, and include the specific unanswered items
Related
- Billing: plans, events, trial vs paid API access
- Team: workspace roles and access
- Installation Guides: cookieless tracker setup