PRIVACY POLICY FOR INCLICK
Effective Date: August 1, 2026
Welcome to InClick (“we,” “our,” or “us”). InClick provides a specialized, AI-powered e-commerce software platform that enables merchants to launch and manage online stores through natural-language dialogue (the “Services”).
This Privacy Policy explains how we collect, use, disclose, and safeguard information when business owners (“Merchants”) register for and use our platform, how we interact with third-party APIs (such as Meta/Instagram), and how we handle data from end-customers who purchase goods from stores built via InClick.
We operate in compliance with the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA).
1. ROLE DEFINITIONS (GDPR / CCPA)
InClick as a Data Controller: We act as a Controller for the data of our Merchants (e.g., your account registration metrics, platform subscription details, and connected API access tokens).
InClick as a Data Processor: We act as a Processor regarding the personal data of End-Customers buying products from our Merchants' stores. Merchants are the Controllers of their customers' data and are responsible for maintaining their own store privacy policies and obtaining required buyer consents.
2. INFORMATION WE COLLECT
A. From Merchants (Platform Users)
Account Credentials: First and last name, email address, password, or Google profile metadata (when utilizing simplified Google Sign-In).
Meta / Instagram API Data: If you opt to connect your Meta (Instagram) account during or after the store creation process, we utilize the official Meta Graph API to access your authorized profile information, account permissions, and media catalogs. This allows us to import your Instagram media, descriptions, and assets directly to populate your online store's product catalog . We do not see, access, or store your raw social media passwords.
Merchant Billing Data: To process monthly platform subscriptions and calculate our performance fee (0.5% of store transaction volume), we retrieve transaction volume totals via the Stripe API using merchant-provided access tokens. We do not collect, view, or store your billing profile, bank account details, or cardholder data — this information is entered directly by you into Stripe’s own registration and account interfaces and is governed by Stripe’s Privacy Policy.
Shipping/Logistics API Data (e.g., Shippo): If you connect a shipping or logistics provider such as Shippo to your store, all account registration and data entry (including sender/recipient addresses) occurs directly on that provider’s platform under its own privacy policy. We store only the API key/token you provide, which is used solely to execute shipping actions you authorize (e.g., requesting rates, generating labels). We do not access, copy, or store the underlying address or shipment data held by the provider.
B. From End-Customers (Your Buyers)
Through automated integration with the merchant’s storefront, our platform processes transactional metrics. We do not process, collect, or store end-customers' raw financial data (such as credit card numbers or bank details). We only process the following transactional metadata:
Identity & Contact Info: First and last name, email address, and phone number.
Purchase Contents: Product identifiers, description of items purchased, and quantities.
Purchase Amount: Total transaction value, currency, and timestamps (used strictly to generate storefront dashboard analytics and calculate the 0.5% performance billing fee).
3. HOW WE USE THE INFORMATION
We process data based on contractual necessity, legitimate business operations, or your explicit integration consent:
To provision and manage your InClick AI-managed merchant account.
To authenticate secure tokens required to execute automated tasks via Meta (Instagram) APIs, including syncing product media to your store dashboard.
To compute platform recurring subscriptions and calculate the 0.5% performance volume fee.
To compile real-time store analytics and inventory management reports.
To protect the platform against fraud and comply with international corporate tax and reporting obligations.
4. DATA RETENTION, DISCONNECTS, AND SECURITY
Third-Party API Compliance: Data fetched from the Instagram Graph API is used solely to generate your active storefront inventory. We do not sell, rent, or lease any imported API content or profile data to third-party data brokers.
API Revocation & Deletion: Merchants can completely disconnect their Meta (Instagram) integration at any time via the InClick account management panel or by revoking permissions directly through their Instagram Security Settings (Apps and Websites). Upon connection removal, cached token records are deleted from our production systems within 30 days.
Account Deletion: You may request complete account deletion at any time by contacting our support team.
Third-Party Payment & Shipping Tokens: API keys/tokens for Stripe, Shippo, or similar service-provider integrations are encrypted at rest and accessible only to authorized platform processes. Merchants may revoke these integrations at any time via the InClick account management panel or directly through the third-party provider’s own settings. Upon disconnection, the associated token is deleted from our systems within 30 days.
5. DATA SHARING
No Commercial Data Selling: We do not trade or sell personal data belonging to merchants or their end-customers to third-party ad networks.
Service Providers: We share infrastructure data securely with trusted cloud storage and database entities (e.g., AWS, Google Cloud) operating under severe Data Processing Agreements (DPAs).
Token-Only Third-Party Access: InClick does not transmit, store, or share Merchant or End-Customer personal data with payment or logistics providers such as Stripe or Shippo. Access to these services is limited to merchant-provided API tokens used exclusively to execute actions the merchant has authorized. Any personal data submitted directly to these providers is governed solely by their respective privacy policies.
6. REGULATORY RIGHTS
A. For EU/EEA Users (GDPR Compliance)
Where information is routed from the EU to servers globally, we utilize Standard Contractual Clauses (SCCs) to maintain protection levels. Merchants operating in the EU acknowledge that InClick acts as a Processor for their customer lists and must reference our service in their store’s terms.
B. For California Residents (CCPA/CPRA Compliance)
We act strictly as a "Service Provider" regarding customer purchase records. We process transaction profiles only to maintain the storefront application and do not exploit customer data for cross-context behavioral marketing.
7. CONTACT US AND DATA DELETION REQUESTS
To exercise your privacy rights, file a standard data deletion request, or ask technical integration questions, please contact us at:
Company Name: InClick Inc.
Contact Email: [email protected]
Business Address: 1521 Concord Pike, Ste 301 #232, Wilmington, DE 19803