Last updated: 5 July 2026
Clicked was built to make GDPR and ePrivacy compliance the default rather than a bolt-on. This page summarises how we handle EU and UK data. It complements, and does not replace, our Privacy Policy.
For visitor data, you (the site owner) are the controller and Clicked is your processor, processing only on your documented instructions. For your Clicked account data, we are the controller. See the roles section of our Privacy Policy.
Because Clicked does not store information on the visitor's device and does not identify individuals, most of our processing relies on the legitimate interest of the site owner in understanding aggregate traffic performance, with strong safeguards. You remain responsible for the legal basis of any other scripts on your site.
Clicked runs on Cloudflare, our sole infrastructure sub-processor. Visitor requests are processed at the Cloudflare edge nearest the visitor; EU visitors are processed within Cloudflare's network. We will keep an up-to-date list of sub-processors and notify account holders of material changes.
If you need a signed Data Processing Agreement (DPA) for your records, email privacy@clicked.is and we will provide one.
Because we hold effectively no visitor-level personal data, access and erasure requests are usually straightforward. Visitors should contact the site owner (controller); site owners can reach us at privacy@clicked.is and we will assist.
This page is provided for transparency and is not legal advice. Please have your own counsel confirm your obligations for your specific use.
Money-first analytics for stores and anyone buying traffic. Know what pays, skip the cookie banner.