Anti·Click

Privacy

What is collected on each click, why it is lawful to collect, and every third party that receives any of it.

Draft — not yet in force

The sections describing what data is collected and who receives it are accurate: they are written from the code and there is a test that keeps them in step with it. The items below are facts about the business rather than the software, so they are left visibly blank instead of filled with plausible-looking defaults — a wrong governing-law clause is worse than a missing one. This draft still needs legal review.

What this service is

Anti-Click detects fraudulent clicks on paid advertising. A site owner installs a snippet on the pages their ads land on, and for each click the service records technical information about the request and scores how likely it is to be automated or fraudulent.

The site owner is the controller of that data. Anti-Click processes it on their instructions. If you are a visitor to a site running the snippet and want your data removed, the site owner is who to ask — they can reach us and we will act on their request.

What is collected on each click

The list below is the complete set of fields the snippet sends or the edge derives. Nothing else is collected, and no cookie is set by the snippet.

  • IP address, and a hash of it used for repeat-click counting
  • Country, derived at the edge from the connection
  • User-Agent string
  • Referrer and landing URL
  • Ad click identifier (gclid, msclkid or fbclid) and campaign name, when the landing URL carries one
  • Screen dimensions, timezone and language
  • A non-cryptographic hash of a rendered canvas, used only to tell one browser profile from another
  • Time between the page loading and the first interaction
  • Signals that a browser is automated, such as the WebDriver flag

What is deliberately not collected

No form contents, no keystrokes, no mouse tracking, no page content, and no cross-site identifier. The canvas hash distinguishes browser profiles within one site's traffic; it is not a stable identity and is not shared between sites.

The snippet reads no cookies and writes none. It sends one request per click and does nothing else.

Why this is lawful to process

An IP address is personal data. The basis relied on is the legitimate interest of the site owner in not paying for fraudulent advertising clicks, which is a narrow and well-established purpose. The data is used for that purpose and no other — it is not profiled, enriched, sold or used for advertising.

Whether legitimate interest is the right basis in a given jurisdiction depends on where the site owner and their visitors are, which is one of the things a lawyer needs to confirm for this page.

Who else receives it

Only the processors below, each for one purpose. Several are optional and receive nothing at all unless the site owner enables that feature.

  • Cloudflare — Hosting, the edge network, the database and the queue. Receives: Everything the service stores, because it is the infrastructure it runs on.
  • ipinfo.io — Deciding whether a visitor's IP belongs to a VPN, a datacenter or Tor. Receives: The visitor's IP address.
  • Google Ads — Adding flagged IP addresses to a campaign's exclusion list, when connected. Receives: Flagged IP addresses and the campaign they are excluded from.
  • Stripe — Subscriptions, payment and invoices. Receives: The account email and whatever payment details the customer gives Stripe directly.
  • Google (sign-in) — Signing in with a Google account, when the account holder chooses that instead of an email link. Receives: The account email and Google's verification that it belongs to them.
  • Resend — Sign-in links and billing notices. Receives: The account email.
  • Plausible — Comparing flagged traffic against overall traffic, when configured. Receives: Aggregate page-view counts, no visitor identifiers.

How long it is kept

This section cannot be completed honestly yet: the service currently keeps click records indefinitely. There is no retention job.

That is a gap, not a policy, and it is tracked as work to do rather than described here as though it were a decision. A retention period has to be set and implemented before this page can state one.

Your rights

Access, correction, erasure, restriction, objection and portability, exercised through the site owner who collected the data. A site owner can export their own fraud log as CSV at any time from the dashboard.