1. Worldwide scope and data controller
Clicks & Go is a technology price-comparison platform operating worldwide. This policy applies to everyone who uses the service, in any country. The data controller is the operator of Clicks & Go. Privacy contact: info@clicks-and-go.com. Depending on where you live, you are additionally protected by local frameworks such as the GDPR (European Union) and UK GDPR, the CCPA/CPRA (California, USA), the LGPD (Brazil), Law 25.326 (Argentina), PIPEDA (Canada) or equivalent laws. Nothing in this policy limits the rights those laws grant you.
2. Data we collect
We collect only what is needed to run the service: If you create an account: • Email (required: it is your account identifier) • Name and profile picture (if your sign-in provider — Google, Microsoft or Facebook — shares them) • Phone and city (optional, if you fill them in your dashboard) • Preferred language and preferred catalog country • Your favorites and price alerts Automatically during a visit: • Approximate country, derived from your IP address. The IP is used in transit only for this derivation and is NOT stored. Only the country code (e.g. "US") is persisted, to show you your region's catalog, currency and deals. • Session cookie (only if you sign in). We do NOT collect: postal address, payment or card data (purchases happen at the stores, never on Clicks & Go), biometric data, or sensitive categories of information (health, religion, orientation, political or union affiliation).
3. How we use data (purposes and legal bases)
• Authenticate your session and maintain your account — legal basis: performance of the service contract. • Show your region's catalog, currency and deals — legal basis: legitimate interest in a relevant service. • Send the price alert you yourself configured — legal basis: performance of the requested service. • Send you a sign-in magic link when you request it — legal basis: performance of the service. • Security, fraud and abuse prevention — legal basis: legitimate interest. We do NOT use your data for: selling or renting it to third parties, third-party personalized advertising, or automated decisions with legal effects on you. The scores you see on the site (deal score) rate products, never people.
4. Signing in with Google, Microsoft or Facebook (OAuth)
If you choose to sign in with Google, Microsoft or Facebook, that provider transmits to us your account identifier, your email and — depending on the provider — your name and profile picture, under the provider's own privacy policy. We store only that minimal data. We get no access to your contacts, files, posts or any other content of those accounts. You can revoke access at any time from your provider's security settings.
5. Affiliate links
Clicks & Go participates in affiliate programs (e.g. Amazon Associates, Awin, CJ Affiliate, MercadoLibre). When you click "Buy" you are redirected to the official store through our /out gateway. That redirect does NOT transfer your personal data to the store: the store simply receives the visit, as with any link. We may earn a commission if you complete a purchase, at no extra cost to you. The purchase relationship (payment, shipping, warranty, returns) is exclusively between you and the store.
6. Cookies and similar technologies
We use strictly necessary cookies only: • Session cookie (NextAuth) — keeps you signed in. Expires after 30 days or on sign-out. • Theme/language preference cookie, where applicable. We do NOT use advertising cookies, cross-site tracking or third-party pixels. That is why we show no cookie-consent banner: essential cookies are exempt from consent in most jurisdictions. If this ever changes, we will request prior consent where the law requires it.
7. Who we share data with (processors)
We do not sell or trade your data. To operate we use providers that process data on our behalf under their own protection commitments: • Google Cloud Platform (USA) — platform hosting and encrypted database. • Resend — transactional email delivery (sign-in links and price alerts). • Google, Microsoft and Facebook — only if you choose to sign in with them. The system's internal technical telemetry (agent metrics and operational logs) contains no personal data of yours. We may disclose data if a valid law or court order requires it, limited to the minimum required.
8. International transfers
Our servers are operated by Google Cloud Platform in the United States. If you live outside the USA, your data is transferred there to provide the service. These transfers rely on the lawful mechanisms applicable to your region (for example, Standard Contractual Clauses and the EU–US Data Privacy Framework, of which Google is a participant).
9. Security
• Encryption in transit (TLS/HTTPS) across the whole site and encryption at rest in the database. • No passwords: access is via OAuth providers or single-use email links, eliminating password-theft risk. • Internal access to data limited by least privilege, with keys managed in a secrets manager. • Zero-trust architecture between the system's internal components. No system is infallible: if we detect a security breach affecting your data, we will notify you within the timeframes of the law applicable to your region.
10. Data retention
• Account data: for as long as the account is active. • If you request account deletion: we erase your personal data within at most 30 days, except what the law obliges us to keep (and only for that legal period). • Sessions expire automatically after 30 days. • The per-visit derived country code is not linked to your identity if you have no account.
11. Your rights (all regions)
Wherever you live, we grant you at minimum these rights over your data: • Access: know what data we hold about you and get a copy. • Rectification: correct inaccurate data. • Erasure: delete your account and data ("right to be forgotten"). • Portability: receive your data in a structured, commonly used format. • Objection and restriction of processing, where applicable. • Withdraw consent at any time, without affecting prior lawfulness. • No discrimination for exercising these rights (CCPA). Also: we do not sell or "share" personal data within the meaning of the CCPA/CPRA, so there is nothing to opt out of. To exercise them: write to info@clicks-and-go.com from your account email. We respond within 30 days (or any shorter period your law requires). You may also complain to your country's data protection authority (e.g. your EU Supervisory Authority, the ICO in the UK, the ANPD in Brazil, the AAIP in Argentina).
12. Children
Clicks & Go is not directed at children under 16 and we do not knowingly collect data from minors. If a parent or guardian finds that a minor created an account, write to info@clicks-and-go.com and we will delete it immediately.
13. "Do Not Track" and GPC signals
Since we do not track users across sites nor sell data, the effect of Do Not Track or Global Privacy Control signals is already guaranteed by default for all visitors.
14. Changes to this policy
We may update this policy. For significant changes we will notify you by email (if you have an account) or with a prominent notice on the site, with reasonable advance. The "last updated" date at the top always reflects the current version. Using the service after changes take effect implies acceptance, without prejudice to rights that cannot be waived under your local law.