Last updated: 13 August 2026
Kliq is a link attribution service operated by Kliq. It shortens URLs, redirects visitors to their destination, and attributes the resulting clicks, sign-ups, and revenue back to the placement that produced them. This policy explains what data the service records and how it is handled.
When you sign in we store your email address, display name, avatar URL, organization memberships, and role. Authentication is handled by Better Auth; we never store a plaintext password. Organization API keys are stored hashed and can be revoked at any time.
For every short link we store the slug, destination URL, social metadata, UTM parameters, placement context, and the parent link it inherits from.
When a short link is followed we record the timestamp, the link and sublink that were hit, the referrer, the visitor's IP address, the raw user-agent string, parsed browser/OS/device hints, and approximate geo (country, region, city) derived from the request, plus a first-party identifier written to the visitor's browser. We use the IP address and user-agent together to attach later clicks to the same customer after they identify; we do not use third-party advertising cookies.
Destination applications may send us a customer identifier, conversion events, and revenue amounts. We join those events to the first Kliq link the visitor touched during the 30-day attribution window. Later Kliq clicks during that window do not replace that source. The customer identifier is whatever the destination application chooses to send - typically an internal user ID, not a name or an email address.
Stripe processes paid subscriptions, payment methods, invoices, billing addresses, and tax identifiers. Kliq stores Stripe customer and subscription identifiers plus subscription status, plan, billing period, and discounts; it never receives or stores full payment-card numbers.
Preview and social images uploaded through the dashboard are stored in Cloudflare R2 and served from a public URL.
We process the data above to redirect visitors reliably, to attribute clicks and revenue to the correct link, to unify a customer's click history once they identify, to produce analytics for the organization that owns the link, to authenticate and authorize dashboard users and API agents, and to detect abuse of the redirect infrastructure. We do not sell data, and we do not use it for advertising or cross-site profiling.
Kliq sets two categories of first-party storage:
Both are first-party. Clearing your browser storage removes them, and attribution simply stops resolving for that browser.
Raw click rows, including IP address and user-agent, are kept for 90 days and then deleted. Daily aggregates (without IP or user-agent) are kept for as long as the organization needs its historical reporting. Customer profile traits copied from attached clicks are kept for as long as the customer record exists. Account records are kept for as long as the account exists. Deleting an organization deletes its links, clicks, events, customers, and aggregates.
Kliq runs on Convex (application database and backend), Vercel (hosting and custom short domains), Stripe (subscriptions, invoices, payments, and tax calculation), Cloudflare R2 (image storage), and Resend (transactional email). Each processes data only to provide its part of the service.
Access to organization data requires an authenticated session or a valid organization API key. API keys are scoped to a single organization and can be revoked instantly. Platform administration is limited to designated internal accounts.
Dashboard users can update or delete their account from the account settings page. Organization owners can export or delete their organization's link and analytics data. For anything else, contact us at melvyn@melvynx.com.
We will update the date at the top of this page whenever this policy changes materially, and notify organization owners by email.
Kliq melvyn@melvynx.com