Draft. Written from what this site and Clickfall actually do, and waiting for legal review before launch.
Data processing
Last updated 2 October 2026
When you use Clickfall on your site, you are the controller of your visitors' data and we are your processor. We sign a data processing agreement with every client before any data is processed. This page summarises how the system works, so your legal team knows what they're agreeing to.
What we process
- Counted: page views and visit details with nothing identifying. No IP address, no browser identity string, no raw identifier.
- Observed: journeys and replay for visitors who said yes, linked to a random identifier issued only after that yes.
- Customers: if you connect your payments, orders and customers, with email addresses encrypted and only ever compared as one-way hashes.
Where it lives
Collection runs on your own subdomain. Your data is stored in databases created in the EU jurisdiction, under UK data law, kept apart from every other client's.
What leaves
Only what you switch on. Conversions are sent to an ad platform only for visitors who said yes to ads, only while you have that platform turned on, and only with a hashed email, never a raw one. Declined or modelled data is never sent.
Who else is involved
Cloudflare runs Clickfall's servers and databases as our sub-processor.
Erasure
A person can be erased from every table with one button in your hub, or from a public form on your privacy page. Today that erasure also reaches Meta; it reaches each other ad platform as that platform's connection ships.
Get the agreement
Founding clients receive the agreement with their founding terms. To read it first, email hello@clickfall.co.uk.