Privacy
What is collected on each click, why it is lawful to collect, and every third party that receives any of it.
Draft — not yet in force
The sections describing what data is collected and who receives it are accurate: they are written from the code and there is a test that keeps them in step with it. The items below are facts about the business rather than the software, so they are left visibly blank instead of filled with plausible-looking defaults — a wrong governing-law clause is worse than a missing one. This draft still needs legal review.
- Legal entity name and registered address
- Country of establishment, which decides the governing law and the data-protection regime
- A contact address for privacy requests, and whether a DPO or EU representative is required
- The refund and cancellation window offered
- Whether the service is offered to consumers as well as businesses, which changes the mandatory withdrawal rights
What this service is
Anti-Click detects fraudulent clicks on paid advertising. A site owner installs a snippet on the pages their ads land on, and for each click the service records technical information about the request and scores how likely it is to be automated or fraudulent.
The site owner is the controller of that data. Anti-Click processes it on their instructions. If you are a visitor to a site running the snippet and want your data removed, the site owner is who to ask — they can reach us and we will act on their request.
What is collected on each click
The list below is the complete set of fields the snippet sends or the edge derives. Nothing else is collected, and no cookie is set by the snippet.
- IP address, and a hash of it used for repeat-click counting
- Country, derived at the edge from the connection
- User-Agent string
- Referrer and landing URL
- Ad click identifier (gclid, msclkid or fbclid) and campaign name, when the landing URL carries one
- Screen dimensions, timezone and language
- A non-cryptographic hash of a rendered canvas, used only to tell one browser profile from another
- Time between the page loading and the first interaction
- Signals that a browser is automated, such as the WebDriver flag
What is deliberately not collected
No form contents, no keystrokes, no mouse tracking, no page content, and no cross-site identifier. The canvas hash distinguishes browser profiles within one site's traffic; it is not a stable identity and is not shared between sites.
The snippet reads no cookies and writes none. It sends one request per click and does nothing else.
Why this is lawful to process
An IP address is personal data. The basis relied on is the legitimate interest of the site owner in not paying for fraudulent advertising clicks, which is a narrow and well-established purpose. The data is used for that purpose and no other — it is not profiled, enriched, sold or used for advertising.
Whether legitimate interest is the right basis in a given jurisdiction depends on where the site owner and their visitors are, which is one of the things a lawyer needs to confirm for this page.
Who else receives it
Only the processors below, each for one purpose. Several are optional and receive nothing at all unless the site owner enables that feature.
- Cloudflare — Hosting, the edge network, the database and the queue. Receives: Everything the service stores, because it is the infrastructure it runs on.
- ipinfo.io — Deciding whether a visitor's IP belongs to a VPN, a datacenter or Tor. Receives: The visitor's IP address.
- Google Ads — Adding flagged IP addresses to a campaign's exclusion list, when connected. Receives: Flagged IP addresses and the campaign they are excluded from.
- Stripe — Subscriptions, payment and invoices. Receives: The account email and whatever payment details the customer gives Stripe directly.
- Google (sign-in) — Signing in with a Google account, when the account holder chooses that instead of an email link. Receives: The account email and Google's verification that it belongs to them.
- Resend — Sign-in links and billing notices. Receives: The account email.
- Plausible — Comparing flagged traffic against overall traffic, when configured. Receives: Aggregate page-view counts, no visitor identifiers.
How long it is kept
This section cannot be completed honestly yet: the service currently keeps click records indefinitely. There is no retention job.
That is a gap, not a policy, and it is tracked as work to do rather than described here as though it were a decision. A retention period has to be set and implemented before this page can state one.
Your rights
Access, correction, erasure, restriction, objection and portability, exercised through the site owner who collected the data. A site owner can export their own fraud log as CSV at any time from the dashboard.