Privacy Policy
This policy explains, in plain terms, what personal data the operator of tryclew.io collects, why, and what you can ask us to do with it. It covers the website, the dashboard and the widget, and it includes what we store in your browser and what we do with data we hold for our customers.
1. Scope
1.1. This policy covers tryclew.io and getclew.io: the website, the dashboard, the API and the widget.
1.2. It does not cover the sites of our customers, where the widget is installed. There the customer decides what is collected and why, and you should read that site's own privacy notice.
1.3. tryclew.ru is a separate installation for Russia with its own database and its own policy. No data is transferred between the two.
2. What we collect
If you visit the website: the necessary cookies and browser storage described in section 4, and the request data every browser sends (IP address, page, time, browser type). We do not keep web-server access logs; the IP address is used in memory to limit how often requests can be made. If, and only if, you accept analytics in the cookie banner, our analytics provider also receives a pseudonymous browser id, the pages you viewed, an approximate location, and device and referrer information. While you are signed in to the dashboard it then also receives pseudonymous account parameters — our internal user and account ids (never your email or name), the role and company size you chose to tell us, your plan, usage counts, the domain names of your sites and the type of payment method (never card details) — and page titles, which in the tour editor include the tour's name. When you finish signing up it also receives where you came from: the path of the first page of your visit without its query, the domain name of the referring site without its page address, the campaign utm_* tags from the link and which "start free" button you pressed. We keep the same facts on your account; they come from our own first-party record, described under Necessary in section 4.
If you create an account: your email address, your password (kept only as a salted hash, never in readable form), your role, the role in your company and the company and team size if you choose to tell us, the company or site name you give us, the addresses of the sites where you install the widget, session tokens, a log of changes made in the account, your interface language, and a record that you accepted these documents (time, versions, IP address). If you signed up through a referral link (Terms, section 12), we keep the link's code, the date of the visit and which account referred you; to catch self-referrals we compare sign-in IP addresses, stored only as an irreversible hash. The account that referred you sees only the sign-up date and the status of yours — never your email or name. If you use a promo code (Terms, section 13), we keep which code, when, and what it added. If you send a customer story, we keep the company or product name, the website, your role, the story, the quote, the logo and screenshot you add, and your email address for follow-up questions only if you tick that we may contact you; we publish only what you allowed us to publish, and only after we have read it.
If you write to us: your email address, your name if you give it, and the content of the message. Through "Found a bug? Need help?" in the dashboard or "Found a mistake?" on the website we receive the kind of message and its text, optionally what you expected and a screenshot (dashboard only), and the technical context the form attaches and shows you before you send it: the page or dashboard section without its query, the id of the tour open in the editor, your browser type and version, window size, interface language, your account and site ids, your plan and the app version. We keep an email address only if you tick that we may reply to it (in the dashboard, your account email). We never attach tour texts or the data of our customers' visitors. The IP address is used in memory to limit how often the form can be sent and is not stored with the message; the forms set no cookies. Through "Chat with us" in the dashboard we keep the conversation with your account — your messages, any screenshot you attach and our replies — with the dashboard section you were in and your plan; the messages are delivered to our team through a messaging service, and our replies come back to the dashboard. A conversation is kept while your account exists, like other support requests.
If you ask for the guide: through the "2026 guide" form on the website we receive your email address, your tick that we may store it to give you the guide and, only if you tick the second box, that we may send you occasional product news; the page and language the form was sent from (without its query), the time, and our own record of where your visit came from (the clew_attr cookie below). The guide opens right on the page; the form sends no email, and today we send no newsletters at all. If you later create an account with the same email, we note that the guide led to a sign-up. We never create an account for you from this form. The IP address is used in memory to limit how often the form can be sent and is not stored.
Through the widget on a customer's site: a random, anonymous visitor id and tour events (which tour and step, event type, A/B variant, element, page address, time), plus the names of the user properties the site passes. Property values stay in the visitor's browser. The IP address is used to limit request rates and is not stored with events.
We do not ask for sensitive data (such as health, biometric or political data), we do not sell personal data, we do not share it for advertising, and we do not make decisions about people by automated means alone.
3. Why we use it
- To run your account and provide the Service — sign-in, your sites, your tours and their statistics.
- To keep the Service secure — rate limiting, abuse prevention and the account audit log.
- To answer you — support and service notices.
- To give you the guide you asked for — and to see whether it led to a sign-up; with your separate, optional consent, to send you occasional product news (we send none today).
- To show that you accepted these documents — the acceptance record.
- To understand how the website is used — website analytics, only if you accept them in the cookie banner. You can withdraw that at any time: Cookie settings
We use your data for these purposes only. We do not use the data our customers collect through the widget for our own purposes, and we do not combine data of different customers.
5. Where it is stored, and who else sees it
5.1. The Service's database and servers are in Amsterdam, the Netherlands (EU).
5.2. Besides us, data is handled by the providers we need to run the Service: a hosting provider for the servers and the database, a website analytics provider (only after you accept analytics, and never for the data our customers collect through the widget), a mail provider for the messages you send us, an online spreadsheet service in which we may keep a copy of support requests and guide requests to track them, and a messaging service through which chat messages from the dashboard reach our team and our replies are sent. They handle the data on our instruction and only as far as it is needed to run the Service. The Service takes no online payments on this site today; if that changes, the payment provider will be described here before the first payment is taken. We also disclose data to authorities where the law requires it.
5.3. Some services we use receive no personal data at all: search-engine verification (a tag on our own pages), search-engine notification of new pages (public page addresses only), and our source-code and deployment tooling (no database access). Fonts are served from our own servers.
6. Data we hold for our customers
When the widget runs on a customer's site, the customer decides what is collected and why, and we handle that data only on their instruction and only to provide the Service — showing tours, targeting, A/B tests and completion statistics. We keep it confidential, protect it with the measures in section 8, do not use it for our own purposes and do not combine data of different customers. If the customer's account is deleted, the data is erased after the 30-day restore window and backups are overwritten on rotation. We tell the customer promptly about any security incident affecting their data and help them answer requests from their visitors.
Email forms. A customer may add an email form to a popup on their site. What a visitor types there and sends after ticking the consent box — the email address, and a name if the form asks for it — is stored with the page address (without its query), the A/B variant, the consent wording shown and the date. We keep it apart from the analytics events, show it only to the customer's account and never use it to email anyone ourselves. The customer is the one collecting it: getting and recording the visitor's consent, linking to their own privacy policy, sending any emails and honouring unsubscribes are the customer's responsibility.
7. How long we keep it
Account data is kept while the account exists and for 30 days after it is deleted, so that a deletion can be undone. Sessions expire after 30 days. Acceptance records are kept for a few years after the account is closed, so that we can show what was agreed. Tour events are kept for up to 180 days. Email-form submissions are kept for the customer until they delete the popup, the site or the account, up to the newest 10,000 per site. Support messages are kept for a few years after the last message. A guide request is kept until you withdraw your consent, and for no more than 3 years. Analytics data is kept according to the analytics provider's retention setting and its cookies expire on their own.
Backups are made when the Service is updated, are kept on the same servers and are overwritten on rotation, so deleted data can remain in a backup until it is overwritten.
8. Security
HTTPS everywhere; passwords stored only as salted hashes; role-based access inside an account and isolation between customers; an audit log; a staff console with its own sign-in, two-factor authentication and its own audit trail; rate limiting; backups.
9. Your choices and requests
9.1. You can ask us for a copy of your data, ask us to correct it, or ask us to delete your account and its data. Write to hello@getclew.io from your account email address and we will answer within one month.
9.2. You can withdraw the consent you gave in the guide form, and the consent to product news, at any time by writing to hello@getclew.io with the email you used; we delete the request within 30 days. You can withdraw your analytics consent at any time: Cookie settings You can also delete or block cookies in your browser; sign-in and some features will then stop working.
9.3. Depending on where you live you may have further rights and may be able to complain to a local data-protection authority.
9.4. If you are a visitor of a customer's site, please contact that site's owner. We pass on any request we receive and help the owner answer it.
10. Children
The Service is made for businesses and is not directed at children under 16. We do not knowingly collect their data.
11. Contact and changes
Questions, requests and deletion: hello@getclew.io.
We may update this policy. The date and version at the top change, and material changes are announced by email or in the dashboard.