Legal

Privacy Policy

What Cliux collects about you, why, who else processes it, how long it is kept, and how to have it deleted.

Last updated 5 min read

On this page

Who we are and what this covers

Cliux is operated as a public beta by its founder as a sole operator. The company (Cliux Teknoloji Ltd. Şti.) is in formation and is not yet registered, so no company registration, MERSIS or tax number can be given here yet. This page will name the registered entity as soon as there is one.

This policy covers the Cliux website, the console where you build and run a site, and what the platform stores about the visitors of a site you publish. It does not cover what you, as a site owner, choose to collect from your own visitors through your forms and store; for that you are the controller and you owe them a notice of your own. Where this policy says "you", it means an account holder unless it says visitor.

What we collect

Things you give us:

  • Your name and email address, when you create an account.
  • Billing details, which go to Stripe; Cliux never sees a card number.
  • Everything you put into a site: pages, images, files, products, posts, form settings.
  • Messages you send through the contact form.

Things the platform records on its own:

  • Server logs with the IP address, browser and page of each request, kept for operating and securing the service.
  • Console actions that other people on your account can see in the activity log (who published, who invited whom).
  • On a published site: the form submissions, orders, bookings, comments and chat messages your visitors send you, stored on your behalf.

The marketing site runs no analytics. The console runs none either. A published site's first-party analytics counts visits for its owner without a cookie; see the cookie policy for exactly what is stored in a browser.

How we use it

To run the service you signed up for: sign you in, save your work, publish your site, take your visitors' orders and bookings and hand them to you, send you the mail the product sends (sign-in codes, order and booking notices, notifications you switched on), charge the plan you chose, and answer you when you write.

To keep the service safe: rate limits, spam checks on forms, fraud checks on payments, and the logs above. To meet legal obligations: tax and accounting records, and lawful requests from authorities.

We do not sell personal data, we do not build advertising profiles, and we do not send marketing email.

Who else processes it

Cliux runs on a small number of providers. Each one sees only what its job needs.

ProviderWhat it does for youWhat reaches it
ClerkSign-in and account security for the consoleYour name, email address and sign-in events
StripePayments: your plan, and what your visitors pay you through your own Stripe accountBilling details and card numbers, which never reach Cliux
UploadthingStorage for the images and files you uploadThe files themselves
ResendTransactional email: sign-in codes, order and booking mail, notifications you switch onThe recipient address and the message
HostingerThe server the platform and your published sites run onEverything the platform stores
Backblaze B2Off-site copies of the nightly database backup, and a weekly mirror of the uploaded filesThe whole database, encrypted before it leaves the server, and copies of your files
SentryError reports from the platformStack traces, which can carry the page address and your account id

If a site owner adds a Google Analytics or Meta Pixel id to their own site, that tracker loads on their published pages only after a visitor accepts the site's consent banner, and it is governed by that site owner's notice and the tracker's own terms, not by this policy.

How long we keep it

  • Account and site data: for as long as the account exists.
  • Form submissions: for as long as the site owner sets per form; a form with a retention window deletes older submissions once a day.
  • Server logs: a short rolling window on the server.
  • Backups: the database is backed up nightly; the last fourteen nightly copies are kept on the server and an encrypted copy of each is kept off the server, and uploaded files are mirrored off the server weekly. A deletion is complete when the copies holding the row or the file have aged out.

Deleting your data

You can delete a site, or a whole agency and everything under it, from the console yourself. There is no button yet that deletes your account and your name and email address with it: write to us through the contact form and we delete them by hand and tell you when it is done.

If you want a copy of your sites first, say so in the same message. There is no self-service export of a whole site yet; we send you one.

How it is protected

Traffic is encrypted in transit. Your console sign-in is handled by Clerk; the passwords your site's members and shared-preview visitors set are hashed with argon2id. Every action that touches a site's data passes an authorisation check, and an automated scan of the codebase refuses a change that skips one. The security page says the rest, including what we do not have.

Your rights

Depending on where you live you may have the right to:

  • see the personal data we hold about you and get a copy;
  • have it corrected or deleted;
  • object to or restrict how it is processed;
  • withdraw a consent you gave;
  • complain to your data protection authority.

If you are in the EU or the EEA, the GDPR page sets these out in full. To exercise any of them, use the contact form and choose "Help with my site".

Contact and changes

Privacy questions and requests go through the contact form. There is no separate data protection office and no postal address to give yet: Cliux is one person, and the form reaches them directly. We answer within a month.

When this policy changes, the date at the top changes. If a change reduces your rights, account holders are emailed before it takes effect.

  • Why Cliux?
  • Freeform canvas
  • Ten business cores
  • Phone layout, derived
  • Your own domain
  • Developer mode