Clickwise Deals News Merchants ENES

Clickwise Privacy Policy — v2 services

Version dated 27 September 2026. English is the canonical version.

1. Who is responsible

The controller for the processing described in this policy is SOFT DEV FZ LLC, a Free Zone Limited Liability Company licensed by the Fujairah Creative City Free Zone Authority (Media Free Zone) under licence No. 9485/2016. The address shown on its licence is: Fujairah – Twin Towers, P.O. Box 4422, Fujairah, United Arab Emirates. SOFT DEV FZ LLC operates the Clickwise brand for the services listed in section 2.

Privacy contact: privacy@hello.clickwise.net

2. What this policy covers

This policy covers:

  • the Clickwise panel at partners.clickwise.net (also reachable as panel-v2.clickwise.net), including affiliate and merchant accounts, sign-up and onboarding;
  • the public Clickwise API and MCP server under partners.clickwise.net/api/v1/ (also served as panel-v2.clickwise.net/api/v1/, including /api/v1/mcp/), the discovery files (llms.txt, /.well-known/ai-plugin.json, /.well-known/mcp.json), the public program and catalog pages, and the product feeds;
  • the Clickwise Tracker at go.clickwise.net and Clickwise redirect links under /dl/ (for example on r2.clickwise.net and share.clickwise.net), including the conversion reports ("postbacks" and pixels) they receive;
  • the emails we send and receive to run the service and to contact prospective partners.

It does not cover:

  • t.clickwise.net and the legacy Clickwise v1 platform, which have their own notice;
  • Clickwise AI Ads at ads.clickwise.net, which has its own privacy policy;
  • the websites of advertisers, affiliate networks and publishers, which process data under their own policies.

3. What data we process

3.1 Accounts, sign-up and onboarding

When you create or use an account we process:

  • Identity and login: username, first and last name, email address, and your password, which is stored as a salted hash rather than in clear text. We also keep your language, your time zone and the time of your last login and last activity.
  • Affiliates: country, postal address, legal entity type, tax identification number, website name, URL and country, and the payment details you enter: PayPal ID and name, or bank name, account holder, bank country and address, IBAN or SWIFT code and account number.
  • Merchants: company name, country, legal entity type, tax identification number, billing address, city and postcode, and the name, phone number, email address and messenger handles of the main and technical contacts.
  • Documents you upload to verify your account or tax details.
  • Sign in with Google (optional): your Google account identifier, Google email address and profile picture URL.
  • Two-factor authentication (optional): your authenticator secret; your recovery codes; and, if you choose to trust a device, a record of that device including its browser user agent.
  • Onboarding applications, including those started through our MCP server: what you or your AI agent submit (for example company name, website, contact name and email, country, business vertical, networks used, where links will be published, free-text messages and answers to our follow-up questions), the language used, and the country estimated from your IP address (section 3.7).

Our AI assistant (Google Gemini, section 5) evaluates onboarding applications and asks follow-up questions. Merchant applications can be approved or declined automatically on the basis of that evaluation. You can request human review of an automated decision by writing to privacy@hello.clickwise.net.

3.2 Public API and MCP server

For every call to a tool on our MCP server we record: the time, the tool name and method, the result status, the response time, the name of the AI client when it can be identified, your IP address, your user agent, the protocol version, a summary limited to selected request fields, a summary of the response, any error message, and the linked affiliate account or application, if there is one.

Product search and product feed tools require an affiliate API key (X-API-Key), which links those calls to the affiliate account. The request_tracked_links, request_merchant_onboarding and update_profile tools receive the kinds of data described in 3.1, for example a contact or claim email, display name, website, country and payment method.

The public program and catalog pages, llms.txt, the manifests and the product feeds describe programs and products. Visiting them produces the request logs described in 3.5. With your advertising consent, the public affiliate-program pages also load the OpenAI measurement pixel (3.4).

3.3 Tracking links, clicks and conversions

When someone follows a Clickwise tracking link on go.clickwise.net or a /dl/ link, we record a click with: a click ID; the time; the host; campaign, affiliate and link identifiers; the destination URL; any sub-ID supplied by the affiliate; the IP address as received, not truncated, masked or hashed; the browser user agent; the HTTP Referer; and, when present in the link, advertising click identifiers such as Google's gclid, gbraid and wbraid, and an external click ID.

The tracker does not store a location for the click. If a link restricts traffic by country, the /dl/ redirect looks up the country of the IP address through ipapi.co (section 3.7) to choose the route; that country is not stored with the click.

The tracker's /api/touch endpoint can create or recover a click from identifiers supplied to it. It stores the same kinds of data and does not set a cookie.

The destination website, and the affiliate networks that handle the link, receive the parameters contained in the destination URL. These can include identifiers that Clickwise adds so the sale can be attributed.

Conversion reports. When an advertiser, a network or a website reports a sale, lead or other event to us, we record the event type, order ID, amounts, commission, currency, the click ID and any Google click identifiers supplied, together with technical data about the reporting request: IP address, user agent, Referer, HTTP method, path, query parameters and request body. When the report is a pixel loaded by a browser (for example on an order-confirmation page), these technical data are those of that browser.

3.4 Cookies and similar technologies

NameWherePurposeDuration
cwclkgo.clickwise.net and hosts that serve /dl/ linksStores the click ID so a later conversion can be attributed. HttpOnly, SameSite=Lax, Secure over HTTPS. Not set on HEAD requests.Set per campaign; 30 days by default
sessionidpartners.clickwise.net / panel-v2.clickwise.net (each host separately)Keeps you signed in2 weeks (framework default)
csrftokenpartners.clickwise.net / panel-v2.clickwise.net (each host separately)Protects forms against cross-site request forgeryAbout 1 year (framework default)
cw_trusted_devicepartners.clickwise.net / panel-v2.clickwise.net (each host separately)Remembers a device you chose to trust for two-factor authentication30 days
cw_consentpartners.clickwise.net / panel-v2.clickwise.net home, sign-up and public affiliate-program pagesStores your choice in the cookie banner180 days
desk_sPartner Desk (/api/v1/partner-desk)Keeps a Partner Desk conversation session12 hours

The controller considers cwclk a network attribution cookie necessary to calculate and pay commissions. We do not ask for consent before setting it. Whether a consent gate is required in particular jurisdictions remains under legal review. A tracking redirect works without cookies or JavaScript, and your browser settings can block or delete cookies. When the ad platform checks a tracking link in the background ("parallel tracking"), a cookie set in that background request does not necessarily reach your browser.

OpenAI measurement pixel. On the affiliate and merchant sign-up pages and on the public affiliate-program pages, only when you choose to accept advertising measurement (cw_consent=all), we load OpenAI's Ads Measurement Pixel, a script hosted by OpenAI. After a successful sign-up or application, the page sends OpenAI an event name and a reference built from the internal number of the new account or application. We do not pass form fields, email addresses, names or URLs to it. Without that consent, neither the pixel script nor a request to its host is loaded. You can change your choice using the cookie settings on those pages; choosing essential cookies stops future loads and measurement events. If the pixel has already loaded, withdrawing consent reloads the page to stop it. What the script reads or stores in your browser is determined by OpenAI.

Sign in with Google. If you choose it, Google's sign-in service runs in your browser under Google's terms.

The panel home page shows a cookie banner and loads no analytics or advertising scripts. The sign-up and public affiliate-program pages also provide the consent notice and cookie settings.

3.5 Server logs

For each request to our services, our hosting provider, Google Cloud, records the IP address, user agent, full requested URL including query parameters (which can include click identifiers such as gclid), method, status, size and response time, and the Referer when the browser sends one. The tracker's own application log records the route name, not the path or query string. IP addresses are also used as keys of per-minute rate-limit counters, which expire after 60 seconds.

3.6 Emails and outreach

  • Sending. We send service emails and outreach through Resend, using the sender domain send.clickwise.net, and through the Gmail API of our Google Workspace mailboxes.
  • Delivery events. Resend reports delivery events to us: sent, delivered, opened, bounced, complaint and delayed. We store them with the message.
  • Replies and incoming mail. Mail sent to @clickwise.net addresses is delivered to a Google Workspace mailbox. Our systems read it automatically and store the sender, recipients, date, subject and body in our contact records. Google Gemini may classify or summarise it. Mail sent to certain personal mailboxes is excluded from automated reading.
  • Outreach. To find prospective merchants and publishers, we collect business contact data: company name, website or domain, contact name, business email address, country, industry, affiliate networks used, and a research summary written by our AI. Our sources are affiliate-network data, public websites, referrals, manual entry, incoming messages, Clickwise AI Ads, and the B2B contact-data providers Hunter, Apollo, Prospeo and Snov.io. We check with Bouncer whether an address can receive email. If a recipient reports our message as spam, the contact is set to "do not contact". Before any outreach is sent, the system checks that status and any recorded opt-out.
  • Privacy requests. Messages to privacy@hello.clickwise.net are received by Resend for human handling, outside the automated commercial and onboarding workflows. The panel records the sender, recipient, message identifiers, time and handling status, without fetching or retaining the message body or subject in that record. A notification containing the sender and subject is sent to the owner’s Workspace mailbox. The complete message remains in Resend for the person handling your request. Correspondence involving protected personal mailboxes is excluded from this automated intake. Resend’s shared-account inbound webhooks also notify other internally operated projects of message metadata, including sender, recipient and subject.

3.7 Language and country detection

In three cases we send your IP address to ipapi.co to find out your country: when you open the panel home page with no language in the address, when you use the sign-up and onboarding forms, and when you follow a /dl/ link that is restricted by country. We cache the result for 24 hours, keyed by IP address, or for 5 minutes if the lookup fails. For onboarding applications, the estimated country is stored with the application.

4. Why we use your data, and on what legal basis

The following bases state the position adopted by SOFT DEV FZ LLC as controller. They are not a statement that an independent legal assessment has been completed.

PurposeMain dataLegal basis
Create and run accounts, sign-in and two-factor authentication3.1, session cookiesContract and steps at your request before entering a contract
Evaluate onboarding applications, including automated evaluation3.1, 3.2, 3.7Steps at your request before entering a contract
Redirect links, record clicks, attribute conversions, calculate and reconcile commissions, and pay affiliates3.1, 3.3, cwclkContract
Security, fraud and invalid-traffic prevention, rate limiting and troubleshooting3.3, 3.5Legitimate interests: security, fraud prevention and reliable operation
Provide the API and MCP server and prevent abuse3.2, 3.5Legitimate interests: providing the API/MCP service and preventing abuse
Service emails and replies to your messages3.1, 3.6Contract; legitimate interests in handling enquiries
Outreach to prospective partners3.6Legitimate interests in B2B outreach, subject to your right to opt out
Measure our sign-up advertisingOpenAI pixel (3.4)Consent
Show the site in your language3.7Legitimate interests in making the service understandable
Accounting, tax and legal obligations, and legal claims3.1, 3.3Legal obligation for accounting and tax; legitimate interests for legal claims

5. Who receives data

Service providers

ProviderServiceData involved
Google CloudHosting: application servers, databases, cache, file storage, logs and secret storageAll data in section 3
Google WorkspaceMailboxes of clickwise.net in the Afventures Workspace and Gmail APIEmails (3.6)
Google Gemini APIEvaluation of onboarding applications, classification and summaries of emails, research on prospectsApplication data, email content, business contact data
Google Sign-InOptional sign-inYour Google identity (3.1)
ResendSending service email using send.clickwise.net, receiving privacy requests on hello.clickwise.net; delivery eventsEmail addresses, message content, delivery events
CloudflareAuthoritative DNS for clickwise.net. Traffic to the hosts in section 2 does not pass through Cloudflare's proxy.DNS lookups
Hunter, Apollo, Prospeo, Snov.ioFinding business contacts for outreachCompany names and domains we search for; to complete a result, the person's name or LinkedIn profile URL returned by the provider; the contact data they return
BouncerChecking whether an email address can receive mailEmail addresses
ipapi.coCountry from IP address (3.7)IP address
OpenAIAds measurement pixel (3.4)What the pixel collects in the browser; event name and reference

The provider-by-provider assessment of processor or independent-controller roles and the associated data processing agreements remains pending. Afventures hosts email for which SOFT DEV FZ LLC remains the controller, as an intragroup processing arrangement; its formal documentation is pending.

Payments. Affiliate payments are currently made manually through banks or PayPal. The payment provider receives the recipient and transaction details needed to make the payment.

Other recipients. The advertisers, affiliate networks and affiliates involved in a referral receive the identifiers and transaction information needed for attribution and payment. We may also disclose data where the law requires it or to establish, exercise or defend legal claims.

6. International transfers

SOFT DEV FZ LLC is established in the United Arab Emirates. Our application servers, databases, cache and file storage are in Google Cloud's europe-west1 region (Belgium). Google Cloud Logging keeps our logs in its global location. Some other providers in section 5 may process data outside the United Arab Emirates and the European Economic Area, including in the United States. Privacy mail received on hello.clickwise.net is stored by Resend in its US East (Northern Virginia) region. The assessment of each provider’s locations and applicable transfer safeguards remains pending; this policy does not claim that particular contractual safeguards have already been put in place.

7. How long we keep data

Our retention position is to keep data while your account is active and for the time required for reconciliation and accounting. There is currently no automatic deletion schedule for accounts, affiliate clicks and conversion reports, commission records, MCP call records, onboarding applications, contact records or emails. Closing an account marks it as deleted without automatically erasing associated data. Deletion and anonymisation tooling, including for click IP addresses, remains to be implemented; we do not promise a deletion deadline that the system does not enforce.

  • Server logs: 30 days.
  • Database backups: automated backups; we keep the latest 30 of the panel database and the latest 7 of the tracking database, plus 7 days of transaction logs.
  • Country lookup cache: 24 hours (5 minutes after a failed lookup).
  • Cookies: as listed in 3.4. When a cookie expires, the records on our servers are not deleted.

8. Your rights

Depending on the law that applies to you, you may have the right to access your data, correct it, delete it, restrict or object to its processing (including objecting to outreach at any time), receive it in a portable format, withdraw consent where processing relies on consent, and complain to a data protection authority. The controller’s position is that the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) applies, and that the GDPR applies to users in the European Union under Article 3(2). We have not designated an EU representative; the representative requirement and competent supervisory authorities remain pending legal advice.

To exercise these rights, contact privacy@hello.clickwise.net. We may ask for reasonable information to confirm your identity before acting on a request. Please do not send passwords, payment details or unnecessary identity documents. Records held by an advertiser or network may need a separate request to that organisation. We will respond within one month of receiving your request. This response commitment does not mean that all records are automatically erased within that period; accounting obligations may require us to retain some records.

9. Security

Passwords are stored as salted hashes. Two-factor authentication is available for accounts. Authenticator secrets are stored encrypted; a secret saved before encryption was introduced is converted the next time it is used. In production, session and CSRF cookies are only sent over HTTPS. Service credentials are kept in Google Cloud Secret Manager.

10. Changes to this policy

When our processing changes, we will update this policy and its date. This version reflects the implementation reviewed on 27 September 2026.

Clickwise affiliate intelligence · JSON API · llms.txt · Privacy policy