1. Who is the data controller
| Name | Cliencer LLC |
| Entity type | Limited liability company (LLC) organized under the laws of the State of Wyoming, USA |
| Contact email | info@cliencer.com |
| Data rights | info@cliencer.com |
Cliencer LLC acts as data controller for the personal data of its registered users (“businesses”). With respect to the end customers of those businesses (“players” or “influencers”), Cliencer LLC acts as data processor on behalf of the business, following its instructions.
Cliencer LLC operates globally. We have users in Argentina, Mexico, and other countries. We apply a uniform privacy standard aligned with the most protective regulations (GDPR, CCPA) and we respect the specific rights granted by the law of your country of residence.
To exercise any right, request clarification, or report an incident, write to info@cliencer.com. We respond within 10 business days.
2. Who this policy applies to
This policy applies to you if:
- You signed up on the Cliencer mobile app or on cliencer.com to manage a business.
- You created games, prizes, coupons, campaigns, or business profiles on the platform.
- You contracted a paid subscription through Cliencer.
If you only participated in a game as a customer of a business that uses Cliencer, your primary relationship is with that business. You can ask that business to exercise your rights on your behalf, or write to us directly and we will forward your request.
3. What data we collect
We collect only the data needed for the platform to work and to meet legal obligations. We group them into eight categories.
3.1. Account and profile data
When you create an account or edit your business profile, we store:
- First and last name.
- Email.
- Phone (optional).
- Business name, industry, address, and coordinates.
- Business logo and other images you upload (prize photos, banners, etc.).
- Account preferences (language, time zone, settings).
Purpose: identify you, grant access to the platform, display your business info to your customers, and let you manage campaigns.
3.2. Authentication and session data
- Session tokens (JWT) stored securely on the device using the OS keystore (iOS Keychain / Android Keystore, via
expo-secure-store). - Biometric authentication state (if you enabled it). Biometrics are validated locally on your device; we never receive or store your biometric data.
- Temporary access codes sent by email.
Purpose: keep your session open securely and let you sign in without a password.
3.3. Usage and behavior data
While you use the app, we record product events (e.g., “you created a game”, “you shared a prize”, “you opened screen X”) along with event properties such as the game ID or the plan type.
These events are processed via Amplitude. They do not include the content of what you type or sensitive data: they are aggregated usage metrics.
Purpose: understand how the product is used, detect UX issues, improve features, and prioritize the roadmap.
3.4. Device identifiers
- Internal device identifier generated by the OS.
- Push notification token (issued by Apple APNs or Google FCM, managed by OneSignal).
- Device type, model, OS version, and app version.
- IDFA / Advertising ID (iOS only): collected only if you explicitly accept the App Tracking Transparency prompt. If you decline, we do not collect it.
Purpose: send you relevant push notifications, diagnose device-specific errors, and, for IDFA, show more relevant Cliencer advertising in other apps.
3.5. Payment data
If you sign up for a paid plan, your card data is processed directly by Stripe. Cliencer never sees or stores your full card number or CVV.
We do store:
- Your Stripe customer ID.
- The last 4 digits and card brand (e.g., “Visa ****4242”).
- Subscription, invoice, and payment history.
- Billing details (company name, tax ID, fiscal address) if you entered them.
Purpose: process your subscription, issue receipts, and meet tax obligations.
3.6. Location data
We access location only if you explicitly grant permission through the OS. We use it to:
- Show shared prizes from nearby businesses in the prize network.
- Auto-complete your business address when you register it (via Google Places; autocomplete uses the text you type, without sending your user ID).
You can revoke this permission at any time from your OS settings. The app keeps working; you just stop seeing location-based features.
3.7. Camera, microphone, and files
- Camera: the app requests camera access to scan QR codes (e.g., to validate a coupon). Images captured for QR are processed in memory, not stored or transmitted to our servers.
- Microphone: the permission is declared to meet Android camera API requirements, but we never record audio.
- Files / gallery: when you upload a logo or prize image, the file is sent to our Cloudflare R2 storage and associated with your business.
3.8. Technical and error data
When an error occurs in the app, we send a report to Sentry with:
- The error stack trace.
- OS version, device model, and app version.
- The minimum state needed to reproduce the error (e.g., which screen you were on).
Sentry is configured to not send personally identifiable information (PII) in event bodies.
4. How we use your data (purposes and legal basis)
| Purpose | What we do | Legal basis |
|---|---|---|
| Service delivery | Create your account, authenticate you, store your businesses/games/prizes, run the platform. | Contract performance. |
| Transactional communications | Send access codes, confirmations, payment alerts, operational notices by email or push. | Contract performance. |
| Billing and tax compliance | Issue and keep receipts, report to tax authorities. | Legal obligation applicable to Cliencer LLC (US tax law) and to each jurisdiction where services are provided. |
| User support | Answer your questions, troubleshoot reported issues. | Contract performance and legitimate interest. |
| Product improvement | Analyze aggregated usage, detect bottlenecks, prioritize improvements. | Legitimate interest, balanced against your rights. |
| Security and anti-fraud | Detect suspicious access, block abuse attempts, protect the platform. | Legitimate interest and legal obligation. |
| Optional marketing | Send product news or promotions. | Consent (you can unsubscribe anytime). |
| Ad tracking (iOS) | Use IDFA to measure campaigns or show more relevant Cliencer ads. | Explicit consent via ATT. |
If at any time you withdraw your consent for purposes that depend on it, we will stop processing that data for that purpose. This does not affect the lawfulness of processing done before the withdrawal.
5. Who we share data with
We do not sell your data. We share it only with providers that help us run the service, and only with the information strictly necessary.
| Provider | Use | Data shared | Location |
|---|---|---|---|
| Stripe | Payment processing and subscriptions. | Email, name, card data (handled by Stripe, we don't see it). | USA |
| Twilio SendGrid | Transactional email delivery. | Recipient email and name, email content. | USA |
| OneSignal | Push notifications and segmentation. | Push token, external ID (your user ID), segmentation tags. | USA |
| Amplitude | Product analytics. | Usage events and user properties (user ID, plan, country). | USA |
| Sentry | Error tracking. | Stack traces, device model, OS and app version. No PII. | USA |
| Cloudflare R2 | File storage (logos, prize images). | Files you upload. | Global network |
| Render.com | Backend hosting. | All platform data, in transit and at rest. | USA |
| MongoDB Atlas | Primary database. | All platform data. | USA |
| Google Places | Address autocomplete. | The text you type in the search field. | USA |
| Apple APNs / Google FCM | Push notification delivery. | Device token and push content. | USA |
We sign Data Processing Agreements (DPAs) with providers that allow it, and we choose vendors with recognized security standards (SOC 2, ISO 27001, and equivalents).
We may also share data when required by a competent authority in legal proceedings, when necessary to protect the platform's or people's safety, or in the context of a corporate operation (merger, acquisition, reorganization). In the last case, we will notify you before your data becomes subject to a different privacy policy.
6. International transfers
Cliencer LLC is incorporated in the United States and most of our providers operate from there. If you are located outside the US (for example, in Argentina, Mexico, or the European Union), your data is transferred and processed in the US.
For these transfers we apply, as applicable:
- Standard Contractual Clauses approved by the European Commission, incorporated by reference in provider agreements, when the user is located in the European Economic Area or in countries that require SCCs.
- Adequacy decisions where recognized by local authorities (AAIP in Argentina, INAI in Mexico, European authorities, etc.) with respect to the US.
- Additional technical measures: in-transit encryption (TLS 1.2+), at-rest encryption in databases, and role-based access control.
If you are in a jurisdiction whose authority does not recognize the US as an adequate country, you may request that we not transfer your data by writing to info@cliencer.com. We will evaluate the request on a case-by-case basis; that may mean we cannot provide the service fully.
7. How long we keep data
| Data type | Retention period |
|---|---|
| Active account data | While the account is active. |
| Data after deletion request | 30-day grace period (see section 8), then anonymization. |
| Billing records | As required by tax obligations applicable to Cliencer LLC (US, typically 7 years) and by each user jurisdiction when applicable. |
| Technical logs | Up to 90 days. |
| Operational backups | Up to 30 days from the last copy. |
| Anonymized / aggregated data | Indefinitely (no longer identifying). |
8. Account deletion and user rights
8.1. How to delete your account
From the app, go to Settings → My account → Delete my account. When you confirm, the following happens:
- Your account is marked for deletion and scheduled for 30 days later.
- During those 30 days the account is inactive, but data still exists. If you sign in again within that period, the account is automatically reactivated and deletion is canceled.
- If you have an active Stripe subscription, it is canceled when you confirm deletion so you are not charged for new periods.
- After 30 days, a daily automated process (2 AM, Argentina time) anonymizes your account: the email is replaced with a value like
deleted_xxx@removed.cliencer.com, the name is changed to “Usuario eliminado”, phone and push tokens are cleared, and the businesses you managed are archived. - Historical games, prizes, and coupons are not deleted in order to preserve the integrity of your end customers' results, but they are disconnected from any personally identifiable information about you.
- Invoices and tax receipts are kept for the period required by law (10 years), per section 7.
When executing the deletion, we also disconnect your account from OneSignal (push notifications) so you stop receiving them. Some analytics (Amplitude) and email (SendGrid) services are not auto-purged. If you want your data deleted from those services too, email info@cliencer.com and we'll coordinate the removal manually (or you can do it directly through each provider's public form).
8.2. Your rights
You have the right, at any time, to:
- Access: request a copy of the personal data we hold about you.
- Rectification: correct inaccurate or outdated data.
- Deletion: request that we delete your data, subject to legal exceptions (e.g., retention of billing data).
- Objection: object to processing based on legitimate interest or marketing.
- Portability: receive your data in a structured, commonly used format (e.g., JSON or CSV).
- Withdrawal of consent: when processing is based on your consent, you can revoke it.
- File a complaint with the data protection authority of your country. For example: AAIP in Argentina (Law 25.326, argentina.gob.ar/aaip), INAI in Mexico (LFPDPPP, home.inai.org.mx), your national data protection authority in the EU/EEA, or the California Privacy Protection Agency if you reside in California.
To exercise any of these rights, email info@cliencer.com with the subject “Data Rights” indicating what you want to exercise. We will respond within 10 business days. We may ask for identity verification before sharing personal data.
9. Information security
We apply technical and organizational controls to protect your data.
Technical measures
- End-to-end encrypted communications via TLS 1.2 or higher.
- At-rest encryption in the database and file storage.
- Session tokens stored in the OS secure storage (Keychain / Keystore) via
expo-secure-store, never in plain text. - Optional local biometric authentication.
- Credential hashing with industry-standard algorithms.
- Secret management with environment variables isolated per environment and periodic rotation.
- Continuous error and anomaly monitoring (Sentry + infrastructure logs).
Organizational measures
- Least-privilege access: the team accesses only the data strictly necessary for their role.
- Audit logs for administrative access to sensitive data.
- Security reviews before every major release.
- Periodic evaluation of critical providers.
No system is 100% impenetrable. If we detect a security incident affecting your personal data, we will notify you through available channels (in-app, email) and comply with applicable reporting obligations.
10. Minors
To create a business account on Cliencer you must be 18 or older. We do not knowingly collect minors' data as account holders.
If a business runs games that may reach minors among their end customers, that business is responsible for complying with the applicable minor-protection regulations in their jurisdiction. If we detect that a minor's data was uploaded improperly, we will delete it as soon as we become aware.
11. Cookies and similar technologies
The mobile app does not use cookies in the traditional sense. It uses secure local storage (expo-secure-store and AsyncStorage) to store your session and preferences on the device.
The cliencer.com website does use first- and third-party cookies for authentication, analytics, and marketing. Details are shown in the website's cookie banner and governed by this same policy.
12. Push notifications
If you accept push notifications, we may send you alerts about:
- Account and subscription status.
- Game results and customer activity in your campaigns.
- Product news and recommendations.
You can disable them at any time from your OS settings or the app.
13. App Tracking Transparency (iOS)
On iOS, when you first launch the app the system shows Apple's official prompt “Allow Cliencer to track your activity across other companies' apps and websites?”.
- If you accept: we use the IDFA to measure our own marketing campaigns and show more relevant Cliencer ads.
- If you decline: we do not collect IDFA. The rest of the app works exactly the same.
You can change your decision anytime from Settings → Privacy & Security → Tracking.
14. Changes to this policy
We may update this policy when we add new features, change providers, regulations change, or we improve data handling. For material changes, we will notify you at least 15 days in advance via:
- An in-app banner.
- An email to the address registered on your account.
The current version is always available at cliencer.com/privacy. The date at the start of the document shows when it was last updated.
15. Contact
If you have questions, complaints, or want to exercise any of your rights:
- Email: info@cliencer.com
- Web: cliencer.com
- Suggested subject: “Privacy” or “Data Rights”
We respond within 10 business days. If you don't receive a response or are not satisfied, you can file a complaint with the data protection authority of your country (for example, AAIP in Argentina, INAI in Mexico, your national DPA in the EU/EEA, or CPPA in California).