Privacy Policy
Last updated: 2026-09-17
1. Introduction
ClickEasyLink, operated by CLICKEASY LIMITED, is a high‑performance parallel tracking and attribution platform engineered specifically for the demands of modern performance marketers, e‑commerce brands, and advertising agencies. Our infrastructure — built on Cloudflare's global edge network with D1 database synchronization — delivers millisecond‑level click processing while maintaining full compliance with the strictest data protection regulations.
This Privacy Policy explains in detail how we collect, process, and safeguard information when you visit our website and when our tracking technology processes click, impression, and conversion data on behalf of our clients. We are committed to the principles of transparency, data minimization, and purpose limitation, and our architecture is purpose‑built to meet the requirements of:
- Google's Third‑Party Click Tracking Services policy (2026)
- General Data Protection Regulation (GDPR) – EU 2016/679
- California Consumer Privacy Act (CCPA)
By using ClickEasyLink, you entrust us with your campaign data. We take that responsibility seriously and have designed every component of our system — from edge request handling to database storage — with privacy and compliance as foundational requirements, not afterthoughts.
2. Data Processing Roles
In accordance with global data protection frameworks, ClickEasyLink operates in two distinct legal capacities depending on the context of the data processing activity. This dual‑role structure is a hallmark of enterprise‑grade MarTech platforms and ensures clarity of responsibility at every stage of data handling.
2.1 Data Controller
For personal information collected directly from visitors to the clickeasylink.com website — including account registration details, contact form submissions, billing information, and general browsing data — ClickEasyLink acts as the Data Controller. In this capacity, we determine the purposes and means of processing and are responsible for ensuring that all such data is handled lawfully, fairly, and in a transparent manner.
2.2 Data Processor
For the click, impression, and conversion data that our platform processes on behalf of our clients (advertisers, affiliate marketers, and agencies), ClickEasyLink acts as a Data Processor. In this role, we process data strictly in accordance with our clients' documented instructions and the terms of our Data Processing Agreement (DPA). Our clients, as Data Controllers, bear the primary responsibility for ensuring that end‑user data is collected with appropriate legal bases and that all necessary consents have been obtained.
This separation of roles aligns with the industry standards set by leading MarTech platforms and provides our clients with the contractual clarity they need for their own GDPR and CCPA compliance programs.
3. Data Collection
When an end user interacts with a ClickEasyLink tracking link, our system automatically collects a limited set of non‑personally identifiable information necessary for accurate attribution, real‑time reporting, and fraud prevention. All data collection is performed with strict adherence to the principle of data minimization.
The following data points are captured during a click event:
-
IP address – truncated to the last octet (e.g.,
192.168.xxx.xxx) before any geolocation lookup is performed. Full IP addresses are never stored in our databases beyond the initial edge request, which is processed in volatile memory at the nearest Cloudflare data center. - User Agent (UA) – the browser, operating system, and device classification string sent by the user's browser. This is used solely for device categorization and bot detection, not for fingerprinting.
- Geolocation data – derived from the truncated IP address using the MaxMind GeoIP database. This provides country, region, and city‑level granularity, which is essential for campaign geo‑targeting analysis. No street‑level or precise GPS coordinates are ever obtained.
- Internet Service Provider (ISP) & connection type – for network‑level traffic analysis and fraud pattern detection.
- Referrer URL & landing page URL – to understand traffic sources and optimize campaign performance.
-
Timestamp – the exact UTC time of the click event, aligned to the server clock via
SET time_zone = '+00:00'to guarantee consistency across all reporting timeframes. - Custom tokens (c1–c10) – optional parameters provided by the advertiser for internal campaign segmentation. These tokens are defined and controlled entirely by the client.
For linking clicks to subsequent conversions, we employ first‑party cookies (set on the tracking domain) and server‑side tracking via a PHP include snippet placed on the advertiser's landing page. No third‑party cookies are ever set, and no data is shared with advertising networks without the client's explicit authorization.
4. Detailed Tracking Identifiers
To enable accurate cross‑platform attribution, ClickEasyLink ingests and processes advertising identifiers that are passed transparently via URL query parameters from traffic sources. These identifiers are essential for matching ad clicks to downstream conversions and for uploading offline conversion data back to the respective platforms.
The following identifiers are processed by our system:
- GCLID – Google Click Identifier (Google Ads)
- WBRAID – Web Braid ID (Google, for web conversions in post‑iOS 14 environments)
- GBRAID – Apps Braid ID (Google, for app conversion attribution)
- MSCLKID – Microsoft Click ID (Microsoft Advertising)
- FBC & FBP – Facebook Click ID and Browser ID (Meta Ads)
These identifiers are processed exclusively for the purpose of attribution — matching a specific ad click to a specific conversion event. They are never used for cross‑site user profiling, behavioral advertising, or any purpose unrelated to campaign performance measurement. All processing of these identifiers occurs at Cloudflare's global edge nodes (500+ locations), and no persistent personal identity linkage is created from them.
5. Transparency Declaration
Google Third‑Party Click Tracking Services Compliance (2026)
ClickEasyLink is architected from the ground up to meet — and exceed — the transparency requirements of Google's latest Third‑Party Click Tracking Services policy. We do not merely claim compliance; our entire tracking infrastructure is built around it.
The cornerstone of this compliance is the visible redirect parameter present in
every tracking link generated by our platform. This parameter discloses the next-hop landing page URL in plain text.
No backend logic ever hides, encrypts, or obfuscates that destination. Every link is fully auditable by advertisers,
ad platforms, and end users.
https://g.clickeasylink.com/go/campaign-slug?
redirect={lpurl}
&gclid={gclid}
&wbraid={wbraid}
&gbraid={gbraid}
&msclkid={msclkid}
In Google Ads Mode, ClickEasyLink uses a 200 OK + client‑side navigation model on Cloudflare Workers.
The visible redirect query parameter is treated as the declared next hop and is honored for navigation —
it is not overridden by a backend-only destination. This transparent disclosure supports Google's Third‑Party Click
Tracking Services requirements and helps advertisers keep the declared destination aligned with what users see.
6. Data Security
ClickEasyLink embeds security into every layer of its infrastructure — from the edge to the database — ensuring that your tracking data remains confidential, integral, and available only to those with explicit authorization.
- Cloudflare Global Edge Network – all tracking requests are processed at the nearest of 500+ data centers worldwide.
- TLS 1.3 Encryption – every tracking endpoint, API call, and dashboard session is encrypted.
- AES‑256 at Rest – all data stored in Cloudflare D1 databases is encrypted at rest.
- IP Truncation – full IP addresses are never persisted.
- Access Controls – internal access is restricted and audited.
We do not attempt to re‑identify individuals from the data we process, nor do we enrich our datasets with external personal information.
7. Data Retention Policy
We retain different categories of data for defined periods based on operational necessity and legal requirements.
- Raw Click Logs – retained for 90 days.
- Conversion Data – retained for the lifetime of the client's account.
- Bot Shield Block Logs – retained for 30 days.
- Account & Billing Information – retained for the duration of the active account plus any legally mandated retention period.
Upon account termination, all associated data is scheduled for deletion within 30 days, unless otherwise required by law.
8. API Integrations & Data Sharing
ClickEasyLink integrates with major advertising platforms to automate cost synchronization and offline conversion uploads. Data sharing is strictly limited and always initiated by the client.
Platforms we integrate with, upon client approval:
- Google Ads API
- Meta Conversions API (CAPI)
- TikTok Events API
- Google Analytics 4 (Measurement Protocol)
- Affiliate Networks via S2S postbacks
In each case, the data transmitted is limited to the conversion event and the corresponding advertising identifier. No raw click logs, IP addresses, or user‑agent strings are ever shared.
We never sell, rent, or trade tracking data to any third party.
9. Your Rights
Depending on your jurisdiction, you may be entitled to exercise the following data subject rights.
- Right of Access
- Right to Rectification
- Right to Erasure
- Right to Restrict Processing
- Right to Data Portability
- Right to Object
For End Users of Our Clients: If you clicked on a tracking link generated by ClickEasyLink and wish to exercise your rights, please contact the advertiser or affiliate who provided the link. As a Data Processor, we require the Data Controller (our client) to verify and initiate such requests.
For ClickEasyLink Account Holders and Website Visitors: Contact us at the details provided in Section 10. We will respond to all verified requests within 30 days.
10. Company Information
ClickEasyLink is a product of CLICKEASY LIMITED, a legally registered entity with full operational transparency.
CLICKEASY LIMITED
Registered in the United States of America
Registered Address
30 N Gould St Ste R
Sheridan, WY 82801
United States
Company Identifiers
EIN: 87-2900385
D‑U‑N‑S: 12-028-7394
Contact Details
Data Protection Officer
For privacy inquiries and data subject requests, please contact our DPO at the email above.
This information is also provided to Google as part of our Third‑Party Click Tracking Services certification.