Privacy

Last updated: 13 August 2026

Kliq is a link attribution service operated by Kliq. It shortens URLs, redirects visitors to their destination, and attributes the resulting clicks, sign-ups, and revenue back to the placement that produced them. This policy explains what data the service records and how it is handled.

Who this policy covers

  • Dashboard users - members of an authorized organization who sign in to create and analyze links.
  • Link visitors - anyone who follows a Kliq short link.
  • Destination applications - systems that send identification, conversion, and revenue events through the Kliq API.

Data we collect

Account data

When you sign in we store your email address, display name, avatar URL, organization memberships, and role. Authentication is handled by Better Auth; we never store a plaintext password. Organization API keys are stored hashed and can be revoked at any time.

For every short link we store the slug, destination URL, social metadata, UTM parameters, placement context, and the parent link it inherits from.

Click data

When a short link is followed we record the timestamp, the link and sublink that were hit, the referrer, the visitor's IP address, the raw user-agent string, parsed browser/OS/device hints, and approximate geo (country, region, city) derived from the request, plus a first-party identifier written to the visitor's browser. We use the IP address and user-agent together to attach later clicks to the same customer after they identify; we do not use third-party advertising cookies.

Attribution and conversion events

Destination applications may send us a customer identifier, conversion events, and revenue amounts. We join those events to the first Kliq link the visitor touched during the 30-day attribution window. Later Kliq clicks during that window do not replace that source. The customer identifier is whatever the destination application chooses to send - typically an internal user ID, not a name or an email address.

Billing data

Stripe processes paid subscriptions, payment methods, invoices, billing addresses, and tax identifiers. Kliq stores Stripe customer and subscription identifiers plus subscription status, plan, billing period, and discounts; it never receives or stores full payment-card numbers.

Uploaded files

Preview and social images uploaded through the dashboard are stored in Cloudflare R2 and served from a public URL.

Why we process this data

We process the data above to redirect visitors reliably, to attribute clicks and revenue to the correct link, to unify a customer's click history once they identify, to produce analytics for the organization that owns the link, to authenticate and authorize dashboard users and API agents, and to detect abuse of the redirect infrastructure. We do not sell data, and we do not use it for advertising or cross-site profiling.

Cookies and local identifiers

Kliq sets two categories of first-party storage:

  • Session cookies on the dashboard, required to keep you signed in.
  • An attribution identifier on redirects, used to connect a later conversion back to the click that caused it.

Both are first-party. Clearing your browser storage removes them, and attribution simply stops resolving for that browser.

Retention

Raw click rows, including IP address and user-agent, are kept for 90 days and then deleted. Daily aggregates (without IP or user-agent) are kept for as long as the organization needs its historical reporting. Customer profile traits copied from attached clicks are kept for as long as the customer record exists. Account records are kept for as long as the account exists. Deleting an organization deletes its links, clicks, events, customers, and aggregates.

Sub-processors

Kliq runs on Convex (application database and backend), Vercel (hosting and custom short domains), Stripe (subscriptions, invoices, payments, and tax calculation), Cloudflare R2 (image storage), and Resend (transactional email). Each processes data only to provide its part of the service.

Security

Access to organization data requires an authenticated session or a valid organization API key. API keys are scoped to a single organization and can be revoked instantly. Platform administration is limited to designated internal accounts.

Your choices

Dashboard users can update or delete their account from the account settings page. Organization owners can export or delete their organization's link and analytics data. For anything else, contact us at melvyn@melvynx.com.

Changes

We will update the date at the top of this page whenever this policy changes materially, and notify organization owners by email.

Contact

Kliq melvyn@melvynx.com