Privacy Policy
Last updated: August 31, 2026
This Privacy Policy explains how Clakta LTDA ("Clakta", "we", "us", or "our"), collects, uses, shares, and protects personal information.
Clakta is an analytics platform built to help businesses understand their website, users, and marketing performance. Our customers use Clakta to measure what visitors do on their sites, track conversions, and connect results back to the campaigns and ads that drive them.
This Policy applies to:
- our website at https://www.clakta.com and any page that links to this Policy;
- the Clakta application, APIs, and Documentation; and
- our sales, marketing, support, and event activities.
It is part of, and should be read together with, our Terms of Use, our Data Processing Agreement, and our Subprocessors list.
Summary of key points
We act in two different roles. For our own account holders, prospects, and website visitors, we decide how personal information is used — we are the controller. For the visitor and customer data that our customers collect through Clakta on their own websites, our customers decide how it is used, and we only act on their instructions — we are the processor (in Brazil, the operador). Section 2 explains the difference, and it determines who you should contact about your data.
We do not sell personal information, and we do not use our customers' data to build advertising profiles or cross-site audiences of our own.
Analytics data is minimized by design. Clakta offers a cookieless measurement mode, hashes identifiers before transmitting them to advertising platforms, and lets customers configure IP handling, retention, and consent behavior.
Where your data lives. When a team is created, the customer chooses whether its project data is stored in the European Union or the United States; that choice is permanent and cannot be changed later. Account, billing, and support records are always held in the United States, our team accesses both regions from Brazil, and some service providers operate elsewhere — so we use approved transfer mechanisms when data crosses borders (Section 9).
Your rights. Depending on where you are, you may have rights to access, correct, delete, port, or object to the processing of your personal information (Section 11). Write to [email protected] to exercise them.
1. Who this Policy is for
This Policy describes how we handle personal information about:
- Account holders and their users — people who register for, administer, or use a Clakta account;
- Prospects and website visitors — people who visit clakta.com, request a demo, subscribe to our communications, or contact us;
- Applicants and partners — people who apply for a role with us or work with us commercially; and
- End users of our customers' websites — visitors to and customers of the sites where Clakta's tracking technology is installed. For this group we act only as a processor; see Sections 2, 4, and 12.
Clakta is a business tool. We do not offer the Services to individuals for personal, family, or household purposes, and we treat contact information about account holders as relating to them in their professional capacity.
2. Our two roles: controller and processor
2.1 Clakta as controller
We act as controller — the party that determines the purposes and means of processing — for personal information about our account holders, their users, our prospects, our website visitors, and our applicants and partners. Sections 3 and 5 to 11 describe that processing. Requests about this data go to [email protected].
2.2 Clakta as processor
When a customer installs Clakta's tracking technology on its own website, or connects its advertising, e-commerce, or payment accounts to Clakta, that customer decides what data is collected, why, and for how long. We process it only on the customer's documented instructions, under our Data Processing Agreement. In Brazil we are the operador and the customer is the controlador; under the GDPR we are the processor and the customer is the controller.
If you are a visitor to a site that uses Clakta and you want to exercise your rights over that data, contact the operator of that site. Its privacy notice governs the collection. We will assist that operator in responding to you, but we generally cannot identify you from the data alone, and we are not permitted to act on it without the operator's instructions. Section 12 explains what you can do directly.
3. Information we collect as a controller
3.1 Information you provide
- Account and contact details — name, business email, phone number, job title, company name, and the country or region you operate in.
- Credentials — username and password, multi-factor authentication settings, and, where you sign in through a third-party identity provider, the identifiers that provider shares with us.
- Billing information — billing name and address, tax identifiers, plan and subscription details, invoices, and payment history. Full payment card numbers are collected and stored by our payment processor, not by us; we receive only limited details such as the card brand, expiry, and last four digits.
- Support and correspondence — the content of tickets, emails, chats, and calls with our support and sales teams, including any attachments or screenshots you send.
- Marketing and event information — your communication preferences, responses to surveys, and registrations for demos, webinars, and events.
- Testimonials and case studies — any content you agree to have published, together with your name, role, and company.
- Recruitment information — where you apply for a role with us, your CV and the information in your application.
3.2 Information we collect automatically
When you visit clakta.com or use the Clakta application, we automatically collect:
- Device and connection data — IP address, browser type and version, operating system, device type, screen and language settings, and time zone;
- Log and usage data — pages and screens viewed, features used, dates and times of access, referring pages, search terms used within the product, requests made to our APIs, response times, and error and crash reports;
- Security data — authentication events, sign-in locations, API key usage, and records used to detect abuse and fraud; and
- Marketing attribution data about our own site — the campaign, referrer, or link that brought you to clakta.com, collected in accordance with Section 7.
3.3 Information from third parties
We may receive information from:
- identity and authentication providers, when you use them to sign in;
- payment processors, confirming the status of a payment;
- our own service providers, such as support, email, and infrastructure tools; and
- publicly available sources and business data providers, such as company registries and professional networks, used to check business details and to inform business-to-business outreach where permitted.
3.4 Sensitive information
We do not seek, and ask you not to send us, sensitive personal information — such as data revealing health, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, genetic or biometric data, or data concerning sex life or sexual orientation. Our Terms of Use prohibit uploading such data to the Services.
4. Information we process on behalf of our customers
The following categories are processed under our customers' instructions. What is actually collected depends on how each customer configures Clakta — in particular its tracking mode and its consent management settings — and on the consent choices made by its visitors.
4.1 Event and behavioral data
Page and screen views, sessions, referrers, entry and exit pages, on-site events and custom events, timestamps, session duration, and interactions defined by the customer as conversions.
4.2 Technical and device data
Truncated or hashed IP address (depending on the customer's configuration), user agent, browser and operating system, device type, screen size, language, and approximate geographic location derived at country, state, or city level from the IP address. We do not collect precise GPS location.
4.3 Campaign and attribution data
UTM parameters and other campaign tags, referrer URLs, landing page URLs, and advertising click identifiers passed by advertising platforms (for example fbclid, gclid, and ttclid). These identifiers are what allow a later order to be connected back to the ad that produced the click.
4.4 Identifiers
Depending on the mode the customer selects, a first-party cookie identifier, a locally stored identifier, or a server-derived, rotating, non-persistent identifier used in cookieless mode. Customers may also send their own internal identifiers, such as a user ID or order ID.
4.5 Commercial and order data
Order identifiers, order value, currency, products, quantities, discounts, refunds, order status, and the timing of a purchase, retrieved from the customer's store, checkout, or payment platform.
4.6 Contact data used for advertising signals
Where a customer enables server-side conversion APIs, contact details such as an email address or phone number may be used to match a conversion with the advertising platform. These values are hashed with SHA-256 before transmission, and we transmit them only to the platforms the customer has connected and instructed us to send them to.
4.7 Data retrieved from Connected Platforms
Campaign, ad set, ad, creative, spend, impression, click, and platform-reported conversion data retrieved from the advertising, e-commerce, CRM, and payment accounts that a customer connects, using the permissions that customer grants.
4.8 What we do not do with this data
We do not sell it. We do not use it to build advertising profiles, cross-site audiences, or identity graphs of our own. We do not disclose one customer's data to another customer. We use it to provide, secure, support, and operate the Services for that customer, and — in aggregated and de-identified form that cannot reasonably be linked back to a customer, user, or visitor — to improve the Services, produce benchmarks, and prepare research and educational material, as described in our Terms of Use.
5. How we use personal information
As a controller, we use personal information to:
- provide and operate the Services — create and authenticate accounts, deliver features, maintain sessions, and keep the platform running;
- bill and administer subscriptions — process payments, issue invoices, apply plan limits, and manage renewals and cancellations;
- provide support — respond to tickets, troubleshoot problems, and communicate about incidents;
- send service communications — notify you about changes to the Services, our policies, security matters, usage thresholds, weekly summaries, and other administrative topics;
- secure the platform — authenticate access, detect and investigate abuse, fraud, and security incidents, enforce our Terms of Use, and maintain audit logs;
- improve and develop the Services — analyze how features are used, diagnose errors, run internal research and testing, and design new functionality;
- market our products — send commercial communications where permitted, measure the performance of our own campaigns, and run events, subject to your choices in Section 11;
- meet legal obligations — comply with tax, accounting, and other legal requirements, and respond to lawful requests from authorities; and
- establish, exercise, or defend legal claims, including in connection with disputes, audits, and corporate transactions.
6. Legal bases for processing
Where the GDPR, the UK GDPR, or Brazil's LGPD applies to our processing as a controller, we rely on the following bases:
| Purpose | Legal basis (GDPR / UK GDPR) | Legal basis (LGPD) |
|---|---|---|
| Providing the Services, account management, billing | Performance of a contract (Art. 6(1)(b)) | Execution of a contract (Art. 7, V) |
| Support and service communications | Performance of a contract; legitimate interests (Art. 6(1)(b), (f)) | Execution of a contract; legitimate interests (Art. 7, V and IX) |
| Security, abuse and fraud prevention, audit logging | Legitimate interests (Art. 6(1)(f)) | Legitimate interests; protection of credit (Art. 7, IX and X) |
| Product improvement and analytics on our own site | Legitimate interests; consent where cookies require it (Art. 6(1)(f), (a)) | Legitimate interests; consent (Art. 7, IX and I) |
| Marketing communications and advertising cookies | Consent, or legitimate interests for business-to-business outreach where permitted (Art. 6(1)(a), (f)) | Consent; legitimate interests (Art. 7, I and IX) |
| Tax, accounting, and other legal duties | Legal obligation (Art. 6(1)(c)) | Compliance with a legal or regulatory obligation (Art. 7, II) |
| Legal claims and disputes | Legitimate interests; establishment of legal claims (Art. 6(1)(f), Art. 9(2)(f)) | Regular exercise of rights in proceedings (Art. 7, VI) |
Where we rely on legitimate interests, we have assessed that our interest in operating, securing, and improving a business analytics service does not override the rights and freedoms of the people concerned. You may ask us for information about that assessment, and you may object as described in Section 11.
Where we act as a processor, the legal basis for the underlying collection is determined by the customer, not by us.
7. Cookies and similar technologies on our website
We use cookies and similar technologies on clakta.com and in the Clakta application for the following purposes:
- Strictly necessary — authentication, session management, load balancing, security, and remembering your cookie choices. These cannot be turned off.
- Functional — remembering interface preferences such as language, currency, time zone, and dashboard layout.
- Analytics — understanding how our own site and product are used so that we can improve them.
- Marketing — measuring the performance of our own campaigns and, where applicable, showing our ads on third-party platforms.
Where required by law, we ask for consent before setting non-essential cookies, and you can change or withdraw your choice at any time through the cookie settings on our site. You can also configure your browser to block or delete cookies, though some parts of the Services may then not work properly.
We do not currently respond to browser "Do Not Track" signals, as there is no agreed standard. Where required by applicable law, we honor Global Privacy Control (GPC) signals as opt-out requests for the relevant categories.
8. When and with whom we share personal information
We share personal information only as described below. We do not sell personal information.
- Service providers (subprocessors). Cloud hosting and infrastructure, database and storage services, error monitoring and logging, email delivery, customer support tooling, payment processing, and analytics. They act on our instructions under written contracts that require confidentiality and appropriate security. The current list is published at https://www.clakta.com/legal/subprocessors, and customers can subscribe to notifications of changes as described in the Data Processing Agreement.
- Connected Platforms, on our customers' instructions. Where a customer enables an integration, we transmit the data that customer configures to that platform — for example, hashed conversion signals to Meta, Google, or TikTok. Once received, those platforms process the data as independent controllers under their own terms and privacy policies. We are not responsible for what they do with it.
- Other users of the same account. Data within a Project is visible to the account's users according to the roles and permissions the account administrator sets.
- Professional advisors — lawyers, auditors, accountants, and insurers, where necessary and under a duty of confidentiality.
- Authorities and legal process. Where required to comply with applicable law, a valid legal request, or a court order, or where necessary to protect our rights, safety, or property, or those of our customers or others. We assess each request and, unless legally prohibited, notify the affected customer.
- Corporate transactions. In connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to appropriate confidentiality protections. We will notify affected customers if such a transaction results in a material change to how their data is handled.
- Aggregated and de-identified data, which cannot reasonably be used to identify any person, customer, or visitor, and which is not personal information.
9. Data residency and international transfers
9.1 Choosing a region
The region is chosen when a team is created, during onboarding, under Data region. Every project belongs to a team and inherits its team's region; there is no per-project setting. A team's current region is shown under Team settings → General.
A team's region cannot be changed afterwards. There is no migration path and no support request that can move an existing team. A customer that needs its data in the other region must create a new team there and set it up from scratch — new projects, a reinstalled tracking script, and reconnected advertising and sales platforms. Historical data does not transfer.
There are no region-specific domains: the app is always at www.clakta.com and the API at api.clakta.com, and we route each request to the correct region internally.
A full breakdown of what is held in each location is published in our documentation at Data storage location.
If a customer selects the United States region for data relating to people in the European Economic Area, the United Kingdom, or Brazil, that is the customer's decision as controller. The customer is responsible for assessing that transfer under the law that applies to it and for describing it in its own privacy notice; we make the transfer mechanisms in Section 9.6 available to support it.
9.2 What is stored in the team's region
Everything belonging to a project is stored in the team's region:
- projects and their settings, including currency, tracking mode, attribution model, and retention;
- orders, including totals, status, currency, line items, expenses, and the tracking context attached to each sale;
- customers, including the name, email, phone, address, and identifiers sent with an order or through an identify call;
- products and the per-product analytics derived from orders;
- analytics events — page views, clicks, scrolls, form submissions, e-commerce events, identify calls, and the sessions built from them, including IP address, the geolocation derived from it, user agent, referrer, and advertising click identifiers;
- tracking sources, their allowed domains, and their auto-tracking settings;
- connected Meta, Google, and TikTok ad accounts, including the encrypted OAuth credential and the campaign, ad set, ad, and spend data synced from them;
- Assistant conversations, messages, and the action items generated from them;
- dashboard presets, custom event definitions, and per-project member access; and
- the activity log recording changes to projects.
9.3 What is always stored in the United States
Clakta runs a single control plane in the United States. It holds the records that identify users and route requests, and it does not hold the project data listed in Section 9.2. Regardless of the region a team selects, the following is stored in the United States:
- user accounts — name, email, password hash, passkeys, linked Google, Apple, or SAML identities, and active sessions;
- team and billing records — team name, slug, logo, plan, billing identifiers, plan limits, SSO configuration, invitations, memberships, and roles;
- API keys and OAuth applications;
- Assistant usage counters used for billing (totals only — the conversations themselves stay in the team's region);
- the routing directory, which records the region that owns each project and tracking source and, so that our ingestion endpoint can accept an event without querying a regional database, also carries the project slug, the hostnames allowed to send events, and the project's tracking mode;
- sales platform connections — the encrypted credentials and webhook secrets for Shopify, Stripe, Kiwify, and other connected platforms (the orders those connections produce are written to the team's region);
- product feedback submitted from inside the app; and
- support conversations — anything shared with us in a support ticket or chat.
Customers in the European Union region should account for this when assessing their own transfers: choosing the EU region keeps project data in the EU, but the account, billing, and support records above are held in the United States in either case.
9.4 Shared services
A few components are not region-specific: team logos and user avatars are stored in a single global object store; incoming events pass briefly through a shared ingestion queue before being written to the team's regional analytics store, and are not retained in the queue once processed; and invitations, verification links, and alerts are delivered by our email provider, which operates from the United States.
9.5 Access from other countries
Clakta is operated from Brazil. Our personnel access both regions, under least-privilege controls and logging, to run, secure, support, and troubleshoot the Services. Some of our subprocessors also operate outside the selected region; the list at https://www.clakta.com/legal/subprocessors identifies where each one processes data. This remote access is itself an international transfer and is covered by the mechanisms in Section 9.6.
Where a customer instructs us to send data to a Connected Platform — for example, hashed conversion signals to Meta, Google, or TikTok — that platform receives and stores the data wherever it operates, under its own terms. The residency setting does not constrain those platforms, and we do not control where they process the data.
9.6 Transfer mechanisms
When personal information is transferred out of the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision — including to Brazil, which has no EU adequacy decision, and to the United States where the recipient is not certified under an applicable framework — we rely on the European Commission's Standard Contractual Clauses, with the UK Addendum or the Swiss variant where applicable, together with supplementary technical and organizational measures such as encryption, pseudonymization, access logging, and a policy of challenging overbroad government requests.
When personal information is transferred out of Brazil, we rely on the mechanisms permitted by Articles 33 to 36 of the LGPD, including standard contractual clauses adopted by the ANPD and contractual guarantees with the recipients.
You may request a copy of the relevant safeguards by writing to [email protected].
10. How long we keep information
| Category | Typical retention |
|---|---|
| Account and profile data | For the life of the account, then up to 12 months after closure |
| Billing records and invoices | As required by tax and accounting law, typically 5 to 10 years |
| Support tickets and correspondence | Up to 3 years after resolution |
| Security and audit logs | 6 to 24 months, depending on the log type |
| Marketing contact data | Until you opt out, or after a period of inactivity |
| Analytics and attribution data processed for customers | For the retention period configured by the customer under its plan; on account termination, available for export for 30 days and then deleted in accordance with the Data Processing Agreement |
Customers set their own retention window per project — see Data retention — and can reduce what is collected in the first place through tracking modes and consent management.
Where we are required to keep information longer by law, or need it to establish, exercise, or defend legal claims, we retain it for that period and restrict processing to those purposes. When we no longer need personal information, we delete it or irreversibly anonymize it. Data may persist in backups for a limited period before being overwritten on the normal backup cycle.
11. Your rights and choices
Depending on where you are located, you may have some or all of the following rights over personal information for which we are the controller:
- Confirmation and access — to know whether we process your data and to receive a copy of it;
- Correction — to have incomplete, inaccurate, or outdated data corrected;
- Deletion — to have your data deleted, subject to legal retention duties;
- Anonymization, blocking, or deletion of data that is unnecessary or excessive, or processed in breach of the LGPD;
- Portability — to receive your data in a structured, machine-readable format, or have it transmitted to another provider where technically feasible;
- Objection and restriction — to object to processing based on legitimate interests, or to ask us to restrict processing while a request is assessed;
- Withdrawal of consent — at any time, without affecting processing carried out before the withdrawal;
- Information about sharing — to know with which public and private entities we have shared your data;
- Information about the consequences of refusing consent; and
- Review of automated decisions, where applicable (see Section 15).
How to exercise them. Write to [email protected]. We will respond within the period required by applicable law — generally 30 days under the GDPR (extendable by two further months for complex requests) and 15 days for simple access requests under the LGPD. We may need to verify your identity before acting, and we will not charge a fee unless a request is manifestly unfounded or excessive.
Marketing. You can unsubscribe from marketing emails using the link in any message or by writing to [email protected]. We will still send service and administrative messages related to your account.
Complaints. You may lodge a complaint with a supervisory authority: in Brazil, the Autoridade Nacional de Proteção de Dados (ANPD); in the EEA, your national data protection authority; in the UK, the Information Commissioner's Office. We would appreciate the chance to address your concern first.
US state privacy rights. If you are a resident of California, Colorado, Connecticut, Virginia, or another state with a comprehensive privacy law, you may have rights to know, access, correct, delete, and obtain a portable copy of your personal information, and to opt out of the sale or sharing of personal information and of targeted advertising. We do not sell personal information or share it for cross-context behavioral advertising in the sense of those laws. You may exercise these rights, including through an authorized agent, at [email protected], and you will not be discriminated against for doing so.
12. If you are a visitor to a website that uses Clakta
If you visited a website where Clakta is installed, that website's operator — not Clakta — decides what is collected and why. To exercise your rights over that data, contact the operator and consult its privacy notice. We will support the operator in responding to you.
In most configurations, we do not hold information that would let us identify you by name from the analytics data alone. To help us locate records, an operator may need to supply an identifier such as an order reference.
You can also, at any time:
- reject or withdraw consent to analytics and marketing cookies through the consent banner on the site you are visiting, where one is presented;
- block or delete cookies and site data through your browser settings;
- use browser tracking protection, private browsing, or extensions that block analytics requests; and
- send a Global Privacy Control signal, which we honor as an opt-out request where applicable law requires it.
Where the site operator has enabled a privacy-friendly tracking mode, Clakta does not store an identifier on your device and works from a rotating, server-derived value that is not designed to follow you across sites or over long periods.
13. Security
We maintain technical and organizational measures appropriate to the risk, including encryption in transit (TLS) and at rest, hashing of identifiers transmitted to advertising platforms, role-based access control, multi-factor authentication for administrative access, network isolation, logging and monitoring, least-privilege access for our personnel, vendor security review, backup and recovery procedures, and an incident response process.
No system is completely secure. If we become aware of a personal data breach, we will notify affected customers and the relevant authorities as required by applicable law and by our Data Processing Agreement. You are responsible for keeping your credentials confidential and for using strong authentication; tell us at [email protected] if you believe your account has been compromised.
14. Children
The Services are intended for businesses and are not directed at children or adolescents. We do not knowingly collect personal information from anyone under 18 as a controller. Our Terms of Use prohibit customers from using the Services to collect data from children and adolescents or from properties directed at them. If you believe we hold such data, write to [email protected] and we will delete it promptly.
15. Automated decision-making and AI features
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing.
Clakta includes AI-assisted features, including an assistant that answers questions about a customer's data and can, with that customer's explicit approval, make changes within their account. Prompts and the data needed to answer them may be processed by the subprocessors listed at https://www.clakta.com/legal/subprocessors. We do not use customer data to train publicly available foundation models, and our agreements with AI providers prohibit them from using data submitted through our Services to train their models. Model output may be inaccurate and should be reviewed before it is relied upon.
We also use automated systems for security purposes, such as detecting abusive traffic and fraudulent signups. Where such a system restricts an account, a person reviews the decision on request.
16. Changes to this Policy
We may update this Policy from time to time. The "Last updated" date at the top shows when it last changed. If we make material changes, we will notify account holders by email or through an in-product notice before the changes take effect. Continued use of the Services after that date means you accept the updated Policy. We keep previous versions available on request.
17. Language
This Policy is drafted in Portuguese (Brazil), which is its official version. Any version in another language, including this one, is a convenience translation, and in the event of divergence the Portuguese (Brazil) version at https://www.clakta.com/legal/privacy prevails. This mirrors Section 17.8 of our Terms of Use.
18. How to contact us
If you have any questions, concerns, or requests regarding this Privacy Policy or your privacy, please contact us at [email protected].