Legal
Privacy Policy
What Cliux collects about you, why, who else processes it, how long it is kept, and how to have it deleted.
Last updated 5 min read
On this page
Who we are and what this covers
Cliux is operated as a public beta by its founder as a sole operator. The company (Cliux Teknoloji Ltd. Şti.) is in formation and is not yet registered, so no company registration, MERSIS or tax number can be given here yet. This page will name the registered entity as soon as there is one.
This policy covers the Cliux website, the console where you build and run a site, and what the platform stores about the visitors of a site you publish. It does not cover what you, as a site owner, choose to collect from your own visitors through your forms and store; for that you are the controller and you owe them a notice of your own. Where this policy says "you", it means an account holder unless it says visitor.
What we collect
Things you give us:
- Your name and email address, when you create an account.
- Billing details, which go to Stripe; Cliux never sees a card number.
- Everything you put into a site: pages, images, files, products, posts, form settings.
- Messages you send through the contact form.
Things the platform records on its own:
- Server logs with the IP address, browser and page of each request, kept for operating and securing the service.
- Console actions that other people on your account can see in the activity log (who published, who invited whom).
- On a published site: the form submissions, orders, bookings, comments and chat messages your visitors send you, stored on your behalf.
The marketing site runs no analytics. The console runs none either. A published site's first-party analytics counts visits for its owner without a cookie; see the cookie policy for exactly what is stored in a browser.
How we use it
To run the service you signed up for: sign you in, save your work, publish your site, take your visitors' orders and bookings and hand them to you, send you the mail the product sends (sign-in codes, order and booking notices, notifications you switched on), charge the plan you chose, and answer you when you write.
To keep the service safe: rate limits, spam checks on forms, fraud checks on payments, and the logs above. To meet legal obligations: tax and accounting records, and lawful requests from authorities.
We do not sell personal data, we do not build advertising profiles, and we do not send marketing email.
Who else processes it
Cliux runs on a small number of providers. Each one sees only what its job needs.
| Provider | What it does for you | What reaches it |
|---|---|---|
| Clerk | Sign-in and account security for the console | Your name, email address and sign-in events |
| Stripe | Payments: your plan, and what your visitors pay you through your own Stripe account | Billing details and card numbers, which never reach Cliux |
| Uploadthing | Storage for the images and files you upload | The files themselves |
| Resend | Transactional email: sign-in codes, order and booking mail, notifications you switch on | The recipient address and the message |
| Hostinger | The server the platform and your published sites run on | Everything the platform stores |
| Backblaze B2 | Off-site copies of the nightly database backup, and a weekly mirror of the uploaded files | The whole database, encrypted before it leaves the server, and copies of your files |
| Sentry | Error reports from the platform | Stack traces, which can carry the page address and your account id |
If a site owner adds a Google Analytics or Meta Pixel id to their own site, that tracker loads on their published pages only after a visitor accepts the site's consent banner, and it is governed by that site owner's notice and the tracker's own terms, not by this policy.
How long we keep it
- Account and site data: for as long as the account exists.
- Form submissions: for as long as the site owner sets per form; a form with a retention window deletes older submissions once a day.
- Server logs: a short rolling window on the server.
- Backups: the database is backed up nightly; the last fourteen nightly copies are kept on the server and an encrypted copy of each is kept off the server, and uploaded files are mirrored off the server weekly. A deletion is complete when the copies holding the row or the file have aged out.
Deleting your data
You can delete a site, or a whole agency and everything under it, from the console yourself. There is no button yet that deletes your account and your name and email address with it: write to us through the contact form and we delete them by hand and tell you when it is done.
If you want a copy of your sites first, say so in the same message. There is no self-service export of a whole site yet; we send you one.
How it is protected
Traffic is encrypted in transit. Your console sign-in is handled by Clerk; the passwords your site's members and shared-preview visitors set are hashed with argon2id. Every action that touches a site's data passes an authorisation check, and an automated scan of the codebase refuses a change that skips one. The security page says the rest, including what we do not have.
Your rights
Depending on where you live you may have the right to:
- see the personal data we hold about you and get a copy;
- have it corrected or deleted;
- object to or restrict how it is processed;
- withdraw a consent you gave;
- complain to your data protection authority.
If you are in the EU or the EEA, the GDPR page sets these out in full. To exercise any of them, use the contact form and choose "Help with my site".
Contact and changes
Privacy questions and requests go through the contact form. There is no separate data protection office and no postal address to give yet: Cliux is one person, and the form reaches them directly. We answer within a month.
When this policy changes, the date at the top changes. If a change reduces your rights, account holders are emailed before it takes effect.