Privacy Policy
Privacy Policy
This policy explains how clicked.bio collects, uses, and shares information when you create an account, publish a portal, or visit a portal page.
Scope
clicked.bio is owned and operated by Papagoose LLC. This policy covers our website, the portal editor, and public portal pages hosted by clicked.bio. References to "clicked.bio," "we," "us," and "our" mean Papagoose LLC and its operation of the service. The data controller for personal information collected through clicked.bio is Papagoose LLC.
Account holders who create and manage portals, audience forms, and integrations.
People who view public portals, click links, or submit audience capture forms.
Information we collect
We collect only what is needed to operate the platform. The specific data depends on how you use clicked.bio.
- Account data: email address, password hash, account roles, and basic settings.
- Portal content: portal name, bio, avatar/cover images, links, blocks, posts, and custom domain settings.
- Audience submissions: email, name, consent status, and any lead fields a portal owner configures (for example company, budget, or project brief).
- Analytics metadata: page views, clicks, device type, and referrer URL for portal analytics.
- Reports: content report reason, optional note, and contact email when a report is submitted.
- Integrations: Instagram account identifiers and tokens when you connect Instagram.
- Payment metadata: when you make or receive a payment through clicked.bio, we receive limited transaction information from Stripe (transaction id, amount, currency, status, last four card digits, card brand, card country, billing zip code). We do not receive or store full card numbers, CVCs, or full card details.
- Support communications: messages you send us and any information you include.
Avoid submitting sensitive personal information in audience forms unless it is strictly necessary for your use case.
How we use information
- Provide and maintain the clicked.bio service.
- Authenticate accounts and secure access to portals.
- Render public portal pages and track aggregate performance.
- Deliver audience submissions to portal owners and provide CSV exports.
- Communicate about service updates, billing, and account notices.
- Detect abuse, protect security, and enforce acceptable use.
How we share information
We do not sell personal information for money, and we share data only as needed to operate the service. (For how third-party advertising pixels are treated as a “sale”/“sharing” under US state law, and how to opt out, see “Your US state privacy rights.”)
- With portal owners: audience capture submissions are shared with the portal owner who configured the form.
- With service providers: hosting, storage, analytics, email, and payment providers that process data for us. Our payment processor is Stripe (see "Payments and card data" below).
- With integrations: if a portal owner enables third-party advertising pixels (Meta, Google, TikTok, LinkedIn, Pinterest), those providers may receive visitor data — subject to the consent and opt‑out controls in “Cookies, local storage, and tracking.”
- For legal reasons: to comply with law, enforce our terms, or protect rights and safety.
- Business transfers: if we are involved in a merger, acquisition, or asset sale.
Service providers and sub-processors
We use a small set of vetted providers to operate the service. They process data on our behalf under contractual data-protection obligations and only as needed to provide their function. Our current providers include:
- Amazon Web Services (AWS) — cloud hosting, compute, database, and file storage (United States).
- Amazon SES — outbound transactional and campaign email.
- Cloudflare — DNS, network security, and inbound email routing.
- Stripe — payment processing and subscription billing. Stripe processes payment/card data for buyers, identity and know-your-customer (KYC) data for sellers (collected directly by Stripe during onboarding), and device/fraud-prevention signals gathered by Stripe's scripts on our payment pages (see "Payments and card data" and Stripe's privacy policy).
- PayPal — alternative checkout where a creator enables it.
- Meta / Instagram — when a portal owner connects an Instagram account.
- OpenRouter — AI features on paid tiers (for example analytics summaries and content suggestions); only the content needed to generate a result is sent, and it is not used to train third-party models on your behalf.
We may add or change providers as the service evolves and will keep this list current. A more detailed, up-to-date sub-processor list is available on request through our contact form.
For portal owners and agencies (data processing). When you use clicked.bio to collect and process the personal data of your own audience or clients, you act as the data controller and clicked.bio acts as your processor for that data. A Data Processing Addendum (DPA) covering that relationship is available on request.
Payments and card data
clicked.bio uses Stripe, Inc. ("Stripe") as its payment processor in two distinct directions: payments your visitors make to you through your portal (subject to Stripe Connect, see below) and the subscription fees you pay clicked.bio to use the service. Stripe checkout, onboarding, and card-update forms are embedded on clicked.bio pages but are served by Stripe inside Stripe-controlled frames; Stripe is responsible for collecting, processing, and storing payment-card information in both directions. (PayPal payments, where a creator offers them, are collected by PayPal on PayPal's own pages under PayPal's privacy policy.)
- We never collect or store full card numbers. When you enter your card to pay through the integrated Stripe checkout, the payment form is served by Stripe inside a secure frame embedded on our page, and that data goes directly to Stripe. clicked.bio does not see, transmit, or retain primary account numbers (PANs), CVCs, or full magnetic-stripe data.
- Card storage for future use is handled by Stripe. If you choose to save a card for future purchases or for a recurring subscription, your payment method is stored by Stripe under a customer record linked to the merchant who collected it. We retain only an opaque Stripe customer identifier for that purpose.
- Saved card management is self-serve. If you subscribed to a creator, you can view, update, or delete saved payment methods, view past invoices, and cancel active subscriptions through a Stripe Customer Portal management link the creator provides, or by contacting the creator. For your clicked.bio platform subscription, you manage your card and cancellation directly in your account dashboard — the card form there is provided by Stripe, embedded on our page.
- Stripe Connect. Creators on clicked.bio receive payments via Stripe Connect. The creator opens a Stripe-managed account during onboarding — completed in a Stripe component embedded on clicked.bio — and the identity/KYC information entered there is collected by Stripe, not clicked.bio. Funds for purchases on a creator's portal flow into that creator's Stripe account, not clicked.bio's. clicked.bio may take a platform fee on those transactions; we do not act as the merchant of record for creator sales.
- Your subscription to clicked.bio (separate from Connect). If you subscribe to a paid clicked.bio plan, that charge is processed by Stripe on clicked.bio's own Stripe account — clicked.bio is the merchant of record for your platform-subscription fee, not for your buyers' purchases. The same card-handling rules apply: card data goes directly to Stripe, never to us. Your saved payment methods for clicked.bio billing live on Stripe under a customer record we identify only by an opaque customer ID.
- SCA / 3-D Secure. For payments subject to Strong Customer Authentication (PSD2 — primarily EU/UK card payments), Stripe handles the authentication challenge. clicked.bio simply receives the success or failure result.
- Stripe scripts on our pages. To provide the embedded payment and onboarding experience, Stripe's client scripts (js.stripe.com and connect-js.stripe.com) load on pages with payment features — public portal checkout, the portal editor's payments panel, and the account dashboard. Those scripts are provided by Stripe and may collect device and usage signals directly (for example browser characteristics and interaction data) for fraud prevention and payment security, under Stripe's privacy policy. They also set the fraud-prevention cookies described in "Cookies, local storage, and tracking."
- PCI DSS. Because card data flows directly to Stripe and never touches our servers, our card-handling scope is limited to PCI DSS SAQ A controls. Stripe is a PCI-DSS Level 1 certified service provider.
- Disputes and refunds. If you dispute a charge, your bank, your card network, and Stripe handle the chargeback process. Refunds are issued by the merchant (the creator) using clicked.bio's tools, which instruct Stripe to refund your original payment method.
- Stripe's privacy policy. Stripe processes payment data under its own privacy policy at stripe.com/privacy. You should review it if you want detailed information about how Stripe handles your data.
If you want a saved payment method or a Stripe-stored customer record deleted, contact us or the creator whose portal collected it. We will instruct Stripe to detach the payment method and (if applicable) cancel any active subscriptions tied to it.
International data transfers
clicked.bio is operated from the United States, and our providers may process and store data in the United States and other countries. If you are located in the EEA, the UK, or another region that restricts cross-border data transfers, your information may be transferred to countries that may not provide the same level of data protection as your home country.
Where such transfers require additional safeguards, we rely on appropriate mechanisms such as the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum). You may request more information about these safeguards through our contact form.
Cookies, local storage, and tracking
clicked.bio uses cookies and browser local storage for a few distinct purposes. We group them below by how privacy laws treat them, and describe the controls we provide.
- Strictly necessary (always active). A session cookie keeps you signed in, and security tokens protect against fraud and cross-site request forgery. On pages with payment features, Stripe's scripts also set fraud-prevention cookies (__stripe_mid, __stripe_sid) used solely for payment security. These are required for the service to function, are not used for advertising or cross-site tracking, and therefore do not require consent.
- Preferences (functional). Local storage remembers interface choices such as theme and editor state, and your tracking-consent choice (below). These contain no advertising identifiers.
- Analytics (first-party). We record aggregate portal performance — page views, clicks, device type, and referrer — to give portal owners their dashboards. This is first-party and is not shared with advertising networks.
- Advertising / marketing tags (third-party, optional). A portal owner may add their own marketing pixels (Meta, Google, TikTok, LinkedIn, Pinterest) to their portal. Where present, those third parties may set their own cookies and receive visitor data for measurement and cross-context behavioral advertising. These are the only non-essential trackers, and they run only subject to the consent controls below.
Your tracking choices
How we handle consent for the optional advertising tags depends on where you are, and we honor browser-level privacy signals everywhere:
- EEA, UK, and Switzerland — opt‑in. Before any advertising tag loads, we show a consent banner. No non-essential tag runs unless you choose “Allow.” If you choose “Decline,” none load. You can withdraw consent at any time by clearing your browser’s site data for the page.
- United States — opt‑out. Advertising tags may run, but every portal page provides a “Do Not Sell or Share My Personal Information” control. Choosing it opts you out, stops the tags, and remembers your choice on that device.
- Global Privacy Control (GPC). If your browser or an extension sends a Global Privacy Control signal, we treat it as a valid opt‑out and do not load advertising tags — in every region. This satisfies opt‑out‑preference‑signal requirements under California and other US state laws.
- Other regions. Advertising tags, if a portal owner has added them, load by default, and GPC is still honored.
Whether any advertising pixels exist on a given portal is the portal owner’s choice. clicked.bio provides the consent and opt‑out mechanism described here on every hosted portal.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or export personal information. To make a request, send a message via our contact form.
If you are a portal owner, you control the audience data you collect and are responsible for honoring requests from your subscribers.
If you have saved a card or have an active subscription with a creator, you can manage and delete those records through a Stripe Customer Portal management link the creator provides, or by contacting the creator whose portal you transacted with. Your clicked.bio platform-subscription card and cancellation are managed directly in your account dashboard.
Instagram data deletion. If you connected your Instagram account to a clicked.bio portal and want the Instagram-derived data deleted, you can submit a deletion request directly through Instagram → Settings → Apps and Websites → clicked.bio → "Request data deletion". We process the request synchronously: tokens, imported posts and reels, and the Instagram user identifier are removed from every clicked.bio portal that had them. You can verify the status of your request at our deletion status page. The clicked.bio portal and account themselves are not affected — only the Instagram-sourced data.
Your rights in the EEA, UK, and Switzerland (GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, the GDPR (and UK GDPR / Swiss FADP) gives you rights over personal data for which clicked.bio (Papagoose LLC) is the controller. Where a portal owner is the controller of their own audience data, direct those requests to that portal owner.
- Access — confirmation of whether we process your data and a copy of it.
- Rectification — correction of inaccurate or incomplete data.
- Erasure — deletion (“right to be forgotten”) where applicable.
- Restriction — limiting how we process your data in certain circumstances.
- Portability — receiving your data in a portable, machine-readable format.
- Objection — objecting to processing based on our legitimate interests, including profiling.
- Withdraw consent — where we rely on consent (such as advertising tags), withdrawing it at any time, without affecting processing already carried out.
Legal bases. We process personal data under one or more of: performance of a contract (providing the service), our legitimate interests (securing and improving the service, and first-party analytics), your consent (non-essential advertising tags and certain communications), and compliance with legal obligations.
Complaints. You may lodge a complaint with your local data-protection supervisory authority. We’d welcome the chance to resolve your concern first via our contact form.
To exercise any of these rights, contact us through our contact form. We may need to verify your identity before acting on a request.
Your US state privacy rights
If you are a resident of California or another US state with a comprehensive privacy law (including Virginia, Colorado, Connecticut, Utah, and a growing list of others), you have rights over your personal information. The descriptions below use California (CCPA/CPRA) terminology; equivalent rights apply under the other state laws.
Categories we collect. Depending on how you use clicked.bio, we collect: identifiers (such as email and account/device identifiers), commercial information (transactions and subscriptions), internet or network activity (page views, clicks, referrer), and coarse geolocation (country-level, used for analytics and to apply the right consent controls). We collect this from you directly and automatically as you use the service, and use it for the business purposes described in “How we use information.”
“Sale” and “sharing.” We do not sell personal information for money. However, when a portal owner enables third-party advertising pixels on their portal, the resulting transfer of identifiers and internet-activity data to those advertising networks for cross-context behavioral advertising may be considered a “sale” or “sharing” under California law. You can opt out of it:
- Use the “Do Not Sell or Share My Personal Information” control shown on portal pages; or
- Send a Global Privacy Control signal from your browser, which we honor automatically.
Sensitive personal information. We do not collect or use sensitive personal information to infer characteristics, and we do not use or disclose it for purposes that would trigger a right to limit its use.
Your rights. Subject to verification, you may: know and access the personal information we hold about you; delete it; correct it; opt out of “sale”/“sharing” (above); and not be discriminated or retaliated against for exercising these rights. You may use an authorized agent to submit a request on your behalf.
How to exercise. Submit a request through our contact form. We verify your identity (typically by confirming control of the email associated with the data) before fulfilling access, deletion, or correction requests. Where a portal owner is the business that collected your data through their audience form, we refer your request to that portal owner, who is responsible for it.
Retention
We keep personal information only as long as needed for the purposes described in this policy, then delete or anonymize it. As a general guide:
- Account and portal data — for the life of your account. If you close your account, we delete or anonymize it within about 90 days, except for limited records we must keep to meet legal, tax, or accounting obligations.
- Audience submissions — until the portal owner deletes them or closes the portal. Portal owners control this data and can export or delete it at any time.
- Analytics metadata — kept on a rolling window (up to about 13 months) and then aggregated or deleted.
- Payment metadata — retained as long as required for financial and tax recordkeeping (typically up to 7 years).
- Support communications — kept as needed to handle your request and for a reasonable period afterward.
Portal owners can delete content and audience submissions at any time; for additional deletion requests, contact us.
Security
We use administrative, technical, and physical safeguards to protect information. No method of transmission or storage is 100% secure, so we cannot guarantee absolute security.
Contact
Questions about this policy can be sent to our contact form.