Skip to content

Legal

Privacy Policy

This Privacy Policy explains how maxclicks lab, LLC (“maxclicks,” “we,” “us,” or “our”) collects, uses, shares, and protects personal data in connection with the maxclicks website at https://maxclicks.ai, our applications, public API, SMTP and MCP interfaces, and related services (the “Service”). It is part of, and incorporated into, our Terms of Service.

“Personal Data” means any information that identifies, or in combination with other information may identify, an individual, and any information treated as personal data or personal information under applicable privacy laws (such as the EU and UK GDPR and the California Consumer Privacy Act).

1. Our two roles: controller and processor

We handle Personal Data in two different roles, and your rights differ depending on which applies:

  • As a controller, for the account and usage data of the people who sign up for and use maxclicks (our customers and their team members). We decide how this data is used to run and improve the Service.
  • As a processor, for the data our customers load into the Service about their own contacts and end users (“Customer Data”). The customer is the controller of that data and uses maxclicks to process it on their behalf and under their instructions. If you are a contact of a maxclicks customer, that customers privacy policy governs how your data is used, and requests about your data should be directed to them.

For our processing of Customer Data as a processor, a Data Processing Addendum (DPA) is available on request and governs that processing, including the instructions, security commitments, and sub-processors described here.

2. Information we collect

Information you provide to us. When you create an account and use the Service, we collect your work email address, name, and optional profile details; your workspace and brand information (such as business name, website, logo, and address); sending configuration such as domains and senders; and the content of support and other communications you send us.

Customer Data you load into the Service. To use maxclicks you upload data about your contacts and business, which may include names, email addresses, phone numbers, custom attributes, tags, subscription and consent records, engagement statistics, objects and events, segments, email and template content, workflows, forms, and uploaded files. You determine what Customer Data you load and are responsible for having the right to do so.

Billing information. Payments are handled by Stripe. We receive limited billing details (such as plan, transactions, and the last four digits and type of card) but we do not store full payment card numbers; those are handled by Stripe.

Information collected automatically. When you use the Service we collect usage and device information, log data, IP address, and diagnostic and performance telemetry (including traces and error reports). We apply measures to reduce Personal Data in our telemetry, but some identifiers may be present. We also use cookies and similar technologies as described below.

Email engagement data. When you send email through the Service, we process delivery, bounce, complaint, open, and click events from the email infrastructure, which is how performance is measured. This data is part of your Customer Data and is processed on your behalf.

3. How we use information

  • to provide, operate, secure, and maintain the Service;
  • to process payments, manage subscriptions and Credits, and prevent fraud and abuse;
  • to render, personalize, and send the messages you create, and to report their results to you;
  • to provide support, respond to your requests, and send service and administrative communications;
  • to monitor, troubleshoot, analyze, and improve the Service and develop new features;
  • to comply with legal obligations and enforce our terms and policies.

We process Customer Data only to provide the Service and as instructed by the customer, and we do not sell Personal Data.

4. Legal bases (EEA and UK)

Where the GDPR applies to our processing as a controller, we rely on: performance of a contract (to provide the Service you signed up for); our legitimate interests (to secure, operate, and improve the Service, balanced against your rights); your consent (where we ask for it, for example certain cookies); and compliance with legal obligations.

5. AI processing (maxinja)

The Service includes AI features. When you use them, your prompts, any files you attach, and the specific space data you reference are sent to AI model providers through an AI gateway in order to generate the requested output (such as personalized email content or audience and automation logic). We do not use your Customer Data or prompts to train our own models, and we use providers commercial APIs, which under their terms do not use API inputs or outputs to train their models. We encourage you to review the providers listed below and our maxinja AI Assistant Terms for details.

6. How we share information

We share Personal Data only as described here:

  • Sub-processors that help us run the Service, under contracts that require appropriate protection (see the list below).
  • At your direction, with integrations and third-party services you connect to your space.
  • For legal and safety reasons, when required by law or to protect the rights, property, or safety of maxclicks, our customers, or others.
  • In a business transfer, such as a merger, acquisition, or sale of assets, subject to this Policy.

We do not sell your Personal Data or your Customer Data.

7. Sub-processors

We rely on a small set of trusted providers to operate the Service. The current sub-processors include:

  • Amazon Web Services for cloud infrastructure, file storage, and email delivery (SES).
  • Stripe for payment processing and billing.
  • Vercel (AI Gateway) to route AI requests to model providers.
  • AI model providers reached through that gateway, currently including Anthropic, OpenAI, Google, and xAI, to generate AI output.
  • Cloudflare for edge networking, content delivery, and DNS.
  • CAPTCHA providers (such as Cloudflare Turnstile, Google reCAPTCHA, or hCaptcha) where you enable them on your forms, using your own keys.

We may update this list as the Service evolves. A current list of sub-processors is available on request, and customers under a DPA may ask to be notified of material changes.

8. International transfers

We and our providers may process Personal Data in countries other than your own. Where we transfer Personal Data out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards such as the European Commissions Standard Contractual Clauses, together with additional measures where needed.

9. Data retention

We retain account and usage data for as long as your account is active and as needed to provide the Service, then for a reasonable period afterward to meet legal, accounting, security, and dispute-resolution needs. We process Customer Data for as long as the customer keeps it in the Service. When you delete Customer Data or close your account, we delete or de-identify the data in the ordinary course, subject to a short window for export and to records we are required or permitted to keep (for example, suppression and consent records kept for compliance, which may be stored in hashed form). Residual copies may persist in backups for a limited time before being overwritten.

10. Security

We use technical and organizational measures designed to protect Personal Data, including encryption in transit and at rest, logical isolation of each customers data, restricted and read-only database access for automated query features, hashing of authentication tokens and certain identifiers, access controls, and monitoring. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for protecting your credentials and for configuring access appropriately.

11. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to the processing of your Personal Data, to data portability, and to withdraw consent. You can exercise these rights for the account data we hold as a controller by contacting [email protected]. We will respond as required by applicable law and may need to verify your identity.

If you are a contact of a maxclicks customer, we process your data on that customers behalf. Please direct requests about your data to that customer, who is the controller; we will assist them as required. You can also unsubscribe from marketing email using the link in those messages.

12. Cookies and tracking

We use cookies and similar technologies that are necessary to sign you in and keep the Service secure, and limited analytics and performance technologies to understand and improve usage. Separately, when you send email through the Service, opens and clicks may be measured on your behalf as part of your Customer Data. You can control non-essential cookies through your browser settings; disabling necessary cookies may prevent the Service from working.

13. Childrens privacy

The Service is a business product and is not directed to children. We do not knowingly collect Personal Data directly from children. If you believe a child has provided us Personal Data, contact us and we will take appropriate steps.

14. Data breach

If we become aware of a security incident that affects Personal Data, we will respond in line with applicable law, and where we act as a processor we will notify the affected customer without undue delay so they can meet their own notification obligations.

15. Changes to this Policy

We may update this Privacy Policy from time to time. If we make a material change, we will provide notice, for example by posting the updated Policy with a new effective date or by notifying you in the Service. Your continued use of the Service after the change takes effect constitutes acceptance.

16. Contact us

For privacy questions, to exercise your rights, or to request our DPA or sub-processor list, contact us at [email protected], or by mail at maxclicks lab, LLC, 30 N Gould St, Ste R, Sheridan, WY 82801.