PRIVACY POLICY FOR INCLICK
Effective Date:
August 1, 2026
Welcome to InClick (“we,” “our,” or “us”). InClick provides a
specialized, AI-powered e-commerce software platform that enables
merchants to launch and manage online stores through natural-language
dialogue (the “Services”).
This Privacy Policy explains how we collect, use, disclose, and
safeguard information when business owners (“Merchants”) register
for and use our platform, how we interact with third-party APIs
(such as Meta/Instagram), and how we handle data from end-customers
who purchase goods from stores built via InClick.
We operate in compliance with the General Data Protection Regulation
(GDPR) and the California Consumer Privacy Act /
California Privacy Rights Act (CCPA/CPRA).
1. ROLE DEFINITIONS (GDPR / CCPA)
InClick as a Data Controller:
We act as a Controller for the data of our
Merchants (e.g., your account registration
metrics, platform subscription details, and connected API
access tokens).
InClick as a Data Processor:
We act as a Processor regarding the personal data of
End-Customers buying products from our Merchants'
stores. Merchants are the Controllers of their customers' data
and are responsible for maintaining their own store privacy
policies and obtaining required buyer consents.
2. INFORMATION WE COLLECT
A. From Merchants (Platform Users)
Account Credentials:
First and last name, email address, password, or Google profile
metadata (when utilizing simplified Google Sign-In).
Meta / Instagram API Data:
If you opt to connect your Meta (Instagram) account during or
after the store creation process, we utilize the official Meta
Graph API to access your authorized profile information, account
permissions, and media catalogs. This allows us to
import your Instagram media, descriptions, and assets directly
to populate your online store's product catalog
.
We do not see, access, or store your raw social media passwords.
Merchant Billing Data:
To process monthly platform subscriptions and calculate our
performance fee (0.5% of store transaction volume), we retrieve
transaction volume totals via the Stripe API using merchant-provided
access tokens. We do not collect, view, or store your billing
profile, bank account details, or cardholder data — this
information is entered directly by you into Stripe’s own
registration and account interfaces and is governed by Stripe’s
Privacy Policy.
Shipping/Logistics API Data (e.g., Shippo):
If you connect a shipping or logistics provider such as Shippo
to your store, all account registration and data entry (including
sender/recipient addresses) occurs directly on that provider’s
platform under its own privacy policy. We store only the API
key/token you provide, which is used solely to execute shipping
actions you authorize (e.g., requesting rates, generating
labels). We do not access, copy, or store the underlying address
or shipment data held by the provider.
B. From End-Customers (Your Buyers)
Through automated integration with the merchant’s storefront,
our platform processes transactional metrics.
We do not process, collect, or store end-customers' raw financial
data (such as credit card numbers or bank details).
We only process the following transactional metadata:
Identity & Contact Info:
First and last name, email address, and phone number.
Purchase Contents:
Product identifiers, description of items purchased, and quantities.
Purchase Amount:
Total transaction value, currency, and timestamps (used strictly
to generate storefront dashboard analytics and calculate the
0.5% performance billing fee).
3. HOW WE USE THE INFORMATION
We process data based on contractual necessity, legitimate business
operations, or your explicit integration consent:
To provision and manage your InClick AI-managed merchant account.
To authenticate secure tokens required to execute automated tasks
via Meta (Instagram) APIs, including syncing
product media to your store dashboard.
To compute platform recurring subscriptions and calculate the
0.5% performance volume fee.
To compile real-time store analytics and inventory management
reports.
To protect the platform against fraud and comply with
international corporate tax and reporting obligations.
4. DATA RETENTION, DISCONNECTS, AND SECURITY
Third-Party API Compliance:
Data fetched from the Instagram Graph API is used solely to
generate your active storefront inventory. We do not sell,
rent, or lease any imported API content or profile data to
third-party data brokers.
API Revocation & Deletion:
Merchants can completely disconnect their Meta (Instagram)
integration at any time via the InClick account management panel
or by revoking permissions directly through their Instagram
Security Settings (Apps and Websites). Upon connection removal,
cached token records are deleted from our production systems
within 30 days.
Account Deletion:
You may request complete account deletion at any time by
contacting our support team.
Third-Party Payment & Shipping Tokens:
API keys/tokens for Stripe, Shippo, or similar service-provider
integrations are encrypted at rest and accessible only to
authorized platform processes. Merchants may revoke these
integrations at any time via the InClick account management panel
or directly through the third-party provider’s own settings.
Upon disconnection, the associated token is deleted from our
systems within 30 days.
5. DATA SHARING
No Commercial Data Selling:
We do not trade or sell personal data belonging to merchants or
their end-customers to third-party ad networks.
Service Providers:
We share infrastructure data securely with trusted cloud storage
and database entities (e.g., AWS, Google Cloud) operating under
severe Data Processing Agreements (DPAs).
Token-Only Third-Party Access:
InClick does not transmit, store, or share Merchant or End-Customer
personal data with payment or logistics providers such as Stripe
or Shippo. Access to these services is limited to merchant-provided
API tokens used exclusively to execute actions the merchant has
authorized. Any personal data submitted directly to these providers
is governed solely by their respective privacy policies.
6. REGULATORY RIGHTS
A. For EU/EEA Users (GDPR Compliance)
Where information is routed from the EU to servers globally, we
utilize Standard Contractual Clauses (SCCs) to maintain protection
levels. Merchants operating in the EU acknowledge that InClick acts
as a Processor for their customer lists and must reference our
service in their store’s terms.
B. For California Residents (CCPA/CPRA Compliance)
We act strictly as a "Service Provider" regarding customer purchase
records. We process transaction profiles only to maintain the
storefront application and do not exploit customer data for
cross-context behavioral marketing.
7. CONTACT US AND DATA DELETION REQUESTS
To exercise your privacy rights, file a standard data deletion
request, or ask technical integration questions, please contact us at:
Company Name:
InClick Inc.
Contact Email:
[email protected]
Business Address:
1521 Concord Pike, Ste 301 #232, Wilmington, DE 19803