Privacy Policy

    Version 2026-08-19 · Last updated August 2026

    This policy covers two different groups: customers who hold a ClickCues account, and reviewers and site visitors whose data is captured when a customer installs the widget on their website. Where the answer differs for those groups, this policy says so.

    1. Who is responsible

    The service is provided by ClickCues. Privacy contact: support@clickcues.com, or via our contact page.

    For your account data, ClickCues is the controller.

    For the feedback, screenshots and reviewer data captured through your widget installation, you are the controller and ClickCues is your processor. You decide where the widget runs and what pages it can photograph. Your obligations as controller are set out in the Acceptable Use Policy.

    2. What we collect

    CategoryExamplesSourceLawful basis
    Account dataName, email address, hashed password, avatar, project namesYouContract
    Billing dataSubscription tier, billing period, Stripe customer and subscription identifiers, invoice history. Card numbers are held by Stripe and never reach ClickCues.You, via StripeContract
    Feedback contentComment text, title, priority, annotations, file attachmentsReviewers on your siteYour instructions as controller
    ScreenshotsAn image of the page at the moment feedback was submitted, plus the pinned elementWidget captureYour instructions as controller
    Page contextPage origin and path only. Query strings, URL fragments and URL-embedded credentials are removed before storage.Widget captureYour instructions as controller
    Technical contextBrowser and OS name, viewport size, recent JavaScript error messages (scrubbed for tokens and emails), element selector. Error capture can be switched off per project in Project Settings.Widget captureLegitimate interests: making feedback actionable
    Reviewer identityName and email, only if the reviewer chooses to type them. Both fields are optional.ReviewerConsent
    Service logsIP address, request metadata, correlation identifiers, security and audit eventsAutomaticLegitimate interests: security and abuse prevention
    Marketing-site analyticsPseudonymous page and event data on clickcues.comAutomaticLegitimate interests

    3. What the widget does not collect

    • No session replay, no continuous recording, no keystroke logging. Nothing is captured until a reviewer presses submit.
    • Password fields, payment card fields, embedded Stripe/PayPal/Braintree frames, and any element the site owner tags with data-clickcues-ignore are masked with an opaque block before the screenshot is taken.
    • Values typed into form inputs are never read.
    • The widget sets no advertising or cross-site tracking cookies.

    What the widget can still capture, and you should plan for: a screenshot photographs everything else visible on the page. If a reviewer submits feedback from inside a logged-in area, the screenshot will include whatever real data was on screen. Authenticated path segments such as/customers/48211/invoices are stored, because only the query string is removed. Free text a reviewer types can contain anything, including data they should not have pasted.

    4. AI processing

    Feedback text is sent to Google Gemini, accessed through the Lovable AI Gateway, to generate a clearer title, description, severity and repro steps.

    Screenshots, file attachments, reviewer name and reviewer email are never sent to the model provider. Free text is scrubbed for credentials, tokens and email addresses before transmission. Your data is not used to train any model.

    The full boundary, including the exact field list, is documented in the AI Transparency Notice, which also explains how to switch AI enrichment off for your workspace.

    5. How we use data

    • To operate the service and store your projects, feedback and screenshots.
    • To send transactional email: authentication, feedback alerts, storage warnings, billing notices.
    • To enforce plan limits, storage quotas, rate limits and single-session concurrency.
    • To detect and investigate abuse and security incidents.
    • To produce aggregate, non-identifying usage statistics.

    We do not sell personal data, and we do not share it for cross-context behavioural advertising.

    6. Cookies and site analytics

    The ClickCues application uses strictly necessary cookies for authentication and interface preferences only.

    The public marketing site loads Google Tag Manager and Google Analytics for aggregate traffic measurement. Microsoft Clarity and the LinkedIn Insight Tag were removed in August 2026 and are no longer loaded on any page. Full detail is in the Cookie Policy.

    7. Who we share data with

    We share data only with the subprocessors listed on the Subprocessors page, each under contract and only for the stated purpose. We may also disclose data where legally required, or to protect the rights and safety of users, after assessing whether the request is valid and narrowly scoped.

    8. International transfers

    ClickCues and its subprocessors are predominantly located in the United States. If you are in the UK, EEA or Switzerland, your data is transferred internationally under the Standard Contractual Clauses, with the UK Addendum where applicable.

    9. Retention

    DataRetention
    Active account and project dataFor as long as the account is active
    Deleted tasks and projectsRecoverable from Trash for 30 days, then permanently deleted
    Screenshots and attachmentsDeleted with their parent task; inactive projects are compressed after 90 days
    Closed account dataPermanently deleted within 30 days of account deletion
    Billing recordsRetained as long as required by tax and accounting law, typically seven years
    Security, audit and error logsUp to 12 months
    Legal acceptance recordsRetained for the life of the account plus six years, as evidence of agreement

    10. Security

    Data is encrypted in transit (TLS 1.2 or higher) and at rest. Access to customer data is controlled by row-level security policies at the database layer; storage buckets are private and served through short-lived signed URLs. Feedback content is sanitised before rendering. Administrative access is restricted and audited.

    ClickCues is not SOC 2, ISO 27001, HIPAA or PCI DSS certified, and does not claim to be. Card data is handled entirely by Stripe, which is PCI DSS compliant. Further detail is on the Security page.

    11. Your rights

    Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing, to data portability, and to withdraw consent. UK and EEA residents may also lodge a complaint with their supervisory authority. California residents may request disclosure and deletion, and may opt out of sale or sharing, although we do neither.

    You can export your data and close your account from Settings. For anything else, email support@clickcues.com. We respond within 30 days and do not charge for the first request in a 12-month period.

    If you are a reviewer whose data was captured through a customer's widget, contact the website operator first, since they control that data. If you cannot reach them, contact us and we will route your request. See the widget privacy notice.

    12. Children

    ClickCues is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child's data has been captured, contact us and we will delete it.

    13. Breach notification

    Where a personal data breach is likely to result in a risk to individuals, we will notify affected customers without undue delay and, where we act as processor, in time for you to meet your own 72-hour regulatory obligation.

    14. Changes

    Material changes are announced by email to account holders and by bumping the version number shown at the top of this page. Continued use after the effective date constitutes acceptance.