The short version
This box is a summary. The full notice below is the one that counts. If anything here seems to conflict with the full notice, the full notice controls.
We count people. We do not need to know who they are. Our counting service produces tallies: how many people are in a space, and when. Counting does not collect names or anything else that identifies a person.
If a venue scans your ID, the venue holds that data, not us. ID scanning is an optional add-on that a venue turns on. The scan records live in a database that belongs to that venue. We host it and secure it. We do not read it, and we do not use it for our own purposes. To see, correct or delete your scan record, ask the venue. We help the venue respond.
The only thing CLICR itself receives is a headcount. What reaches us is how many people came in and went out, and when, from the taps our counting app records. Nothing from an ID scan comes to us: not a name, not a birth date, not an ID number, not even an age range.
A venue may see age ranges from its own scans, in its own database. Where its state allows it, a venue can turn on a report that groups its own scans into age ranges (for example, 21 to 24) by entrance and time. That report lives in the venue's database, is built from a date of birth the venue already holds, and is not sent to us.
We collect ordinary business information from venue customers and staff. Names, work emails, roles, login details, billing details and how the app is used. We use it to run the service, support you, bill you and keep the platform secure.
We do not sell personal information, and we do not use scan data for advertising or marketing. If that ever changes, we will update this notice first and give you a way to opt out.
Everyone gets the same rights, wherever you live. You can ask what we have about you, ask us to correct or delete it, get a copy, and appeal if we say no. Email legal@clicrapp.com.
Questions? legal@clicrapp.com, or CLICR, LLC, 240 Kent Ave, Brooklyn, NY 11249.
1. Who we are and what this notice covers
CLICR, LLC ("CLICR," "we," "us") makes an occupancy counting and venue analytics platform. Venues use our apps and small counting devices to keep track of how many people are inside. Venues can also add an ID scanning feature that helps door staff check IDs.
This notice explains what personal information we collect, how we use it, who we share it with, how long we keep it, and what choices and rights you have. It is written for four groups of people:
Venue account holders: the businesses (and the people at those businesses) that sign up for CLICR and accept our Terms and Conditions.
Users: door staff, managers and other people who use the CLICR apps under a venue's account.
Website visitors: anyone who visits clicrapp.com.
Patrons: people who visit a venue that uses CLICR. If you are a patron, the sections that matter most to you are Section 4 (ID scanning) and Section 7 (your rights).
If you are a venue account holder, this notice works together with our Terms and Conditions at clicrapp.com/terms, including the ID Scanning Addendum (Exhibit A). Where this notice and the Terms differ about a venue's rights in its own data, the Terms control.
This notice does not cover the websites, apps or practices of venues themselves, or of other companies we link to. Each venue is responsible for its own privacy practices, including its own signage and notices at the door.
2. Information we collect
Here is what we collect, grouped by who you are. "Collect" includes information you give us, information created when you use our services, and information we receive from others.
2.1 Venue account holders
| What | Examples | Where it comes from |
|---|---|---|
| Business and contact details | Business name, venue name and address, liquor licensee name, owner or manager name, work email, phone | You, when you sign up or update your account |
| Account and login details | Username, email, password (stored in hashed form), role, account settings, Terms version accepted and when | You, and our systems when you accept the Terms |
| Billing details | Plan, billing history, the last four digits and expiration of a payment card, billing address, tax exemption certificate if you give us one | You and our payment processor. We do not store full card numbers; our payment processor does. |
| Configuration and Venue Data | Areas, occupancy limits, device assignments, counting and occupancy records, reports | Created as you use the service |
| Support and communications | Emails, in-app messages, support requests | You |
2.2 Users (venue staff who use the apps)
| What | Examples | Where it comes from |
|---|---|---|
| Identity and login | Name, work email, role (for example, counter, manager, owner), password (hashed), the venue and account you belong to | You or your venue's account owner |
| Device and app data | Device type and operating system, app version, device identifiers, IP address, time zone, language | Your device, when you use the app |
| Usage and activity | Taps and counts you enter, pages and features used, log-in times, scans performed (the fact of a scan, not its contents) | Created as you use the app |
| Diagnostics | Crash reports and performance data | Your device. Diagnostics are configured so they do not include ID data or on-screen ages (see Section 4). |
2.3 Website visitors
| What | Examples | Where it comes from |
|---|---|---|
| Device and browsing data | IP address, browser type, device type, pages viewed, time on page, referring site | Your browser, and cookies or similar tools described in Section 6 |
| Information you send us | Name, email, business name and message when you fill in a form, book a demo, or email us | You |
2.4 Patrons
Counting. Our counting service keeps a tally of people entering and leaving. It does not record who you are. Venue staff tap a count; no camera, microphone, phone signal or other identifier is used to count you.
ID scanning. If a venue has turned on ID scanning and scans your ID, a small set of fields from your ID is saved in that venue's own database. Section 4 explains exactly what is collected, who is responsible for it, how long it is kept, and how to ask about it.
What CLICR receives. From the venues we serve, CLICR itself receives only counts: how many people entered and left each area and when, recorded from taps in our counting app. We call this "Count Data." It contains no name, date of birth, ID number, age, patron identifier, scan identifier or anything else from an ID scan, and it is not produced from scans at all.
Venue Analytics. Where its state allows it, a venue can turn on a report inside its own database that groups the venue's own scans into age ranges (for example, 21 to 24) by entrance and time window. The age range is worked out from the date of birth the venue already holds as one of the four permitted fields. The report belongs to the venue, stays in the venue's database, is shown only on the venue's own dashboard, and is not sent to, used by or licensed to CLICR. No gender, zip code or any other attribute is read from your ID for it, in any state.
2.5 Information we do not collect
As of the effective date of this notice, and unless a venue turns on a feature covered by a separate, clearly labeled notice, we do not collect: photos or images of IDs; the full barcode or machine-readable data on an ID; biometric data such as face geometry or fingerprints; health information; or the location of any device or person. If we introduce a feature that changes any of this, we will update this notice before the feature is turned on.
3. How we use information
We use the information described above to:
Provide the service: run the counting apps, dashboards and reports; sync devices; host each venue's data; authenticate users; and provide the ID scanning feature to venues that buy it.
Support and communicate with you: answer questions, send service and security notices, and tell you about changes to the Terms or this notice.
Bill and manage accounts: process payments through our payment processor, manage plans and device leases, and keep records we are required to keep.
Keep the platform secure: detect and prevent fraud, abuse and security incidents; enforce our Terms; and log access to sensitive records.
Improve and develop the service: understand how features are used, fix bugs, and build new features. We use Count Data (Section 2.4) and de-identified usage data for this, never scan records or anything derived from them.
Build crowd-intelligence products: use Count Data to show how busy venues and neighborhoods are over time. Count Data is a headcount and nothing more; it does not identify any person, and we will not try to combine it with anything that could.
Meet legal obligations: respond to lawful requests, protect our rights, and comply with laws that apply to us.
What we do not do with scan data. We do not use scan data for advertising, marketing, surveys or solicitations; to profile patrons; to enrich other data sets; or to train models. We do not sell it, rent it, or share it between venues or between businesses. These limits come from our Terms and from state ID-scanning laws, and they apply to venues that use the feature as well as to us.
Marketing to businesses. We may send venue account holders and prospects emails about CLICR products and features. Every marketing email includes a way to unsubscribe. We do not send marketing to patrons based on scan data.
4. ID scanning at venues: what patrons should know
This section is written for patrons, but venues should read it too, because it describes what venues have agreed to in our Terms.
4.1 Who is responsible
The venue decides whether to scan IDs, what to do with the results, whom to place on its ban list, and how long to keep records (within the limits below). In privacy-law terms, the venue is the "controller" or "business" for scan data, and we are its "processor" or "service provider." We host the venue's database, keep it secure, and act only on the venue's instructions. We do not have a standing way to read patron records, and that is enforced by technical access controls, not just by policy. Every access to identifying records is logged.
4.2 What is collected
The scanner reads the barcode on your ID and keeps only the fields the venue's state allows, up to a maximum of four: name, date of birth, ID number, and expiration date. Nothing else on your ID is saved, including your address, photo, height, eye color or sex marker. The raw barcode data is not stored anywhere, including in logs or crash reports.
In some states the venue is allowed to keep fewer than four fields, or none at all. The current rules for each state are published at clicrapp.com/enabled-jurisdictions. In New York, for example, licensed venues may record only the four fields listed above (N.Y. Alcoholic Beverage Control Law § 65-b(7)(b)), and may use them only to verify age and support the legal defense the statute provides. In Georgia, a venue may not scan your ID without your prior knowledge and consent (O.C.G.A. § 40-5-120(5)); the venue must post a sign and tell you before scanning, and you may ask for a visual check instead.
Your exact age may appear briefly on the scanner screen to help staff. It is not saved, logged or sent to us. Gender, zip code and every other field on your ID are not read or saved in any state.
4.3 Why it is collected
Venues use ID scanning to check that an ID is valid and that the holder is old enough to enter or be served, to help prevent identity fraud, and, where the venue has turned it on and the state permits it, to check whether a person is on that venue's own ban list. A ban list entry is created by venue staff from what they saw at the time of an incident, with a stated reason and an expiry date; it is not created from your scan record. When an ID is scanned, the name and date of birth just read from it are compared, on the device, against the venue's list. If they match, staff see the name, date of birth and "banned," and a manager confirms before anyone is refused entry. The venue's stored scan records and your ID number are not used for that check. Ban lists belong to the individual venue; there is no shared ban list across venues or across businesses, and we do not operate one.
4.4 How long it is kept
Unless the venue chooses a shorter period, ordinary scan records are deleted after 21 days. The venue can shorten that. Where its state gives the venue a legal defense based on a scan record, the venue may choose a longer period for the four permitted fields, up to the ceiling shown for its state at clicrapp.com/enabled-jurisdictions, and must record why. Ban list entries are kept for one year by default; a venue may set a longer period, up to five years, unless its state requires less. Some states require shorter periods (for example, seven days in Utah) or do not allow retention at all, and in those states the shorter rule wins automatically. Expired records become unreadable at expiry and are permanently deleted on a schedule. Where a state gives a venue a legal defense based on a scan record, the venue may choose to keep the minimum record needed for that defense for the period shown for that state at clicrapp.com/enabled-jurisdictions.
4.5 Where it is kept and who can see it
Scan records live in a database dedicated to the venue's business, hosted by us in the United States and encrypted in transit and at rest with a key specific to that business. Within a business that operates more than one venue, each venue's scan records are tagged to that venue's liquor license and are not visible to its sister venues. Only venue staff with the right role can see patron or ban records. We do not sell, rent or disclose scan records to anyone, except where a law compels us to; in that case we tell the venue first where the law allows.
4.6 Your choices and rights about scan data
To ask what a venue holds about you, to correct it, or to have it deleted, contact the venue. Its contact details should be on the sign at the door. If you are not sure who to contact, email us at legal@clicrapp.com with the venue name and the date of your visit; we will pass your request to the venue within five business days and help the venue respond. We give venues the tools to find, export, correct and delete individual records. Because Count Data contains nothing that identifies you, it cannot be found or deleted by person. A venue's age-range report (Section 2.4) is built from the venue's own records and is the venue's to manage.
5. How we share information
We share personal information only in these situations:
Within your own account. Venue account owners and managers can see the Users, settings and Venue Data for the venues they manage. A business that operates several venues sees each venue's counting data in its account. Scan records, however, stay partitioned by venue as described in Section 4.5.
Service providers. Companies that host our infrastructure, process payments, send email, provide analytics and crash reporting, and help us support customers. They may use personal information only to provide their service to us, and they must protect it at least as well as this notice requires. A current list of the providers that handle scan data is available on request to legal@clicrapp.com.
Professional advisers. Lawyers, accountants and insurers, under confidentiality duties.
Legal and safety. When a law, court order or lawful government request requires it; to enforce our Terms; or to protect the rights, safety or property of CLICR, our customers or others. For scan data, we give the venue notice where the law allows.
Business transfers. If CLICR is involved in a merger, acquisition, financing or sale of assets, personal information may be transferred as part of that transaction. We will require the recipient to honor this notice or give you notice and a choice before using your information differently.
With your direction. When you ask us to share something, or agree to it.
We do not sell personal information. We also do not share personal information for cross-context behavioral advertising, and we have not done so in the past 12 months. Count Data, which is a headcount and identifies no person, may be shared or published, including in future crowd-intelligence products.
6. Cookies, analytics and "Do Not Track"
Our website and apps use cookies and similar tools to keep you logged in, remember settings, measure traffic and find errors. These tools are analytics and crash-reporting services; we do not use advertising pixels or tools that follow you across other companies' websites, and we do not sell or share information collected by them. We do not currently allow third parties to collect information about your online activity across other websites over time for their own purposes.
You can block or delete cookies in your browser settings; some parts of the site may not work as well if you do. We treat a Global Privacy Control signal from your browser as a request to opt out of any sale or sharing of your personal information.
7. Your privacy rights
We give the same rights to everyone, no matter which state or country you live in. Some of these rights are required by law in certain states, such as the California Consumer Privacy Act; we offer them to everyone because it is simpler and fairer. You can:
Know and access. Ask whether we have personal information about you, and receive the specific pieces we hold, the categories, where we got them, why we use them, and who we shared them with.
Correct. Ask us to fix inaccurate personal information.
Delete. Ask us to delete your personal information. We may keep what we need to complete a transaction, keep the service secure, meet a legal duty, or defend a legal claim, and we will tell you if we do.
Take it with you. Receive a copy of the information you gave us in a portable, commonly used format.
Opt out of sale, sharing and targeted advertising. We do not sell or share personal information for these purposes today. If that changes, we will add an opt-out link here first.
Limit use of sensitive information. We do not use sensitive personal information for anything other than providing the service. If that changes, we will add a way to limit it here first.
Not be treated differently. We will not deny you service, charge you a different price or give you a different quality of service because you exercised a privacy right.
Appeal. If we decline a request, you may appeal by replying to our decision. A different person will review it and respond within 45 days. If you are still not satisfied, you may contact your state attorney general.
7.1 How to make a request
Email legal@clicrapp.com with "Privacy request" in the subject line, or write to CLICR, LLC, Attn: Privacy, 240 Kent Ave, Brooklyn, NY 11249. Venue account holders and Users can also make requests by emailing us from the email address on the account; as export and deletion controls are added to account settings, they can be used instead.
We will confirm we received your request within 10 business days and respond within 45 days. If we need more time, we will tell you why and take up to 45 more days. We do not charge for requests unless they are clearly excessive or repetitive, and we will explain before charging anything.
7.2 Verifying who you are
To protect your information, we need to be reasonably sure a request comes from you. For account holders and Users, we will usually ask you to confirm from the email address on the account. For others, we may ask for a few pieces of information that match what we already hold. We will not ask you to create an account, and we will not ask for a copy of your government ID unless there is no other reasonable way to verify a request about ID data.
7.3 Authorized agents
You may have someone else make a request for you. We will ask for proof that you gave them permission, and we may confirm your identity directly with you.
7.4 Requests about scan data
Scan records belong to the venue that scanned you. Section 4.6 explains how to reach the venue and how we help. If the venue does not respond, tell us and we will follow up with it.
7.5 State-specific notes
California residents. The categories of personal information we have collected in the past 12 months are the ones described in Section 2. They are collected for the purposes in Section 3 and disclosed for business purposes to the categories of recipients in Section 5. We have not sold or shared personal information as those terms are defined in California law, and we have no actual knowledge that we sell or share the personal information of anyone under 16. This section, together with Sections 2, 3 and 5, is our notice at collection. Rights requests are handled as described in Section 7.1.
Residents of other states with privacy laws. The rights above are the same rights those laws describe, and we follow the same process for everyone, including the right to appeal.
Nevada residents. We do not sell covered information as defined in Nevada law. You may still send us a request under Section 7.1 to be recorded as opting out of any future sale.
8. How long we keep information
| Information | How long |
|---|---|
| Venue account, User and billing records | For as long as the account is open, and then for the time we need to close out billing, resolve disputes and meet legal record-keeping duties (generally up to seven years for financial records). |
| Venue Data (counts, occupancy, reports) | While the subscription is active. After a paid subscription ends or downgrades, Venue Data from the paid term is available for export for 30 days and may then be deleted. |
| Scan records (ordinary) | Default 21 days; the venue may shorten but not lengthen; shorter where a state requires it. See Section 4.4. |
| Ban list entries | Default one year; the venue may set up to five years unless its state requires less. |
| Venue Database after the ID scanning add-on ends | Available for export for 30 days, then deleted, except a statutory-defense record the venue elects to keep as described in Section 4.4. |
| Count Data (headcounts received by CLICR) | Kept indefinitely. It is a headcount and identifies no person. |
| Venue Analytics (age-range report in the venue's database) | Set by the venue within its database; not held by CLICR. |
| Website analytics and logs | Analytics: no longer than 26 months. Server logs: no longer than one year. |
| Support emails and messages | Up to three years after the matter is closed, or longer if needed for a legal claim. |
| Privacy request records | Two years, as required by California regulations, in a form that is not used for any other purpose. |
9. How we protect information
We maintain reasonable administrative, technical and physical safeguards designed to protect personal information, appropriate to the size of our business and the sensitivity of the data, consistent with the New York SHIELD Act (N.Y. Gen. Bus. Law § 899-bb). These include encryption in transit and at rest, venue-specific encryption keys for scan data, role-based access controls, logging of access to identifying records, personnel training, monitoring and testing of key controls, and secure disposal. No system is perfectly secure, and we cannot promise that unauthorized access will not occur. If a security incident affects your personal information, we will notify the venue and any affected people as the law requires. Venues are responsible for keeping their own login credentials confidential and for controlling which staff can see patron records.
10. Children
Our services are built for businesses and for venues that generally admit adults. We do not knowingly collect personal information from children under 13, and we do not direct our services to them. If you believe a child under 13 has given us personal information, email legal@clicrapp.com and we will delete it.
11. Where information is stored
We operate in the United States and store information on servers located in the United States. Our services are intended for venues in the United States. If you use them from somewhere else, you understand that your information will be processed in the United States.
12. Changes to this notice
We will update this notice when our practices change or the law requires it. We will post the new version at clicrapp.com/privacy with a new "last updated" date and keep an archive of prior versions. If a change materially affects how we use personal information we already hold, we will tell venue account holders by email and in-app notice at least 30 days before it takes effect, and where the law requires it we will ask for consent before using information in a new way. Continued use of the service after a change takes effect means you accept the updated notice; if you do not, you may close your account as the Terms describe.
13. How to contact us
CLICR, LLC
Attn: Privacy
240 Kent Ave, Brooklyn, NY 11249
For billing questions: billing@clicrapp.com. For general support: hello@clicrapp.com.
Annex A. App Store and Google Play data disclosure map
This annex maps the disclosures in this notice to the data categories used in Apple's App Privacy "nutrition label" (App Store Connect) and Google Play's Data safety form. It is published so that what we declare to the app stores and what we say here are the same. Apple App Review Guideline 5.1.1(i) requires the privacy policy linked in App Store Connect and inside the app to identify what data is collected, how it is collected and all uses, to confirm that third parties receiving the data protect it equally, and to explain retention, deletion and how a user can revoke consent or request deletion. Sections 2, 3, 5, 7 and 8 above do that.
Engineering completes the App Store and Play forms from the SDKs and permissions in the shipped build, and checks each entry against this table before submission. Under Apple's rules, data that passes through the app to our servers counts as "collected" even when we process it only for the venue, so scan data must be declared.
| Apple category / Google data type | Collected? | Data | Linked to the user? | Used for tracking? | Purpose(s) |
|---|---|---|---|---|---|
| Contact Info / Personal info | Yes | Name, work email, phone (account holders and Users) | Yes | No | App functionality; account management; customer support |
| Identifiers / Device or other IDs | Yes | User ID, account ID, device identifier | Yes | No | App functionality; analytics; security |
| Financial Info / Financial info | No (not collected by the app) | Venues pay on the web, not in the app. Card data is collected by our payment processor on the web checkout; the app shows only the billing contact and plan. | n/a | No | n/a |
| Usage Data / App activity | Yes | Feature and page interactions, counts entered, scan events (fact of a scan, not contents) | No. Analytics events carry no user or account identifier (Privacy Policy rule). | No | Analytics; app functionality; product improvement |
| Diagnostics / App info and performance | Yes | Crash logs, performance data | No | No | App functionality (stability) |
| Location / Location | No | The apps do not request device location. | n/a | No | n/a |
| Sensitive Info or Other Data / Personal info (government ID) | Yes, when the venue uses ID scanning | Up to four fields parsed from a government ID: name, date of birth, ID number, expiration date. Transmitted to the venue's database; not read or used by CLICR. Raw barcode payload is not stored. Engineering selects the closest Apple category at submission; Apple lists no stand-alone government-ID category. | Yes (to the patron, within the venue database) | No | App functionality (age verification and venue ban-list check on the venue's behalf) |
| Other Data / Other | Yes | Count Data: in/out headcounts by area and time, from counter-app taps; no identifiers and nothing from scans | No | No | Analytics; product improvement; crowd-intelligence products |
| Health & Fitness, Contacts, User Content (photos), Browsing History, Search History, Purchases (in-app), Biometrics, Photos or videos, Audio, Calendar, Messages | No | Not collected | n/a | n/a | n/a |
Tracking. We do not use data from the app to track users across other companies' apps or websites, and we do not use the Apple advertising identifier or request App Tracking Transparency permission.
Data deletion in the app. Apple and Google both require an in-app path to request account deletion for apps that allow account creation. Users can request deletion from account settings or by emailing legal@clicrapp.com; account owners should also be able to delete User accounts they created. The in-app deletion path must exist before submission (Apple Guideline 5.1.1(v)); until account settings include export and deletion, requests are handled by email.
Annex B. Venue signage templates
Under the ID Scanning Addendum, each venue must post a conspicuous sign at every scanning point and remains responsible for the sign's legal sufficiency in its state. These templates are a starting point. Text in brackets is filled in by the venue. Print at a size legible from where patrons queue; 12-point type is not enough for a sign. The sign should match the state configuration on the Enabled Jurisdictions schedule.
B-1. General sign (states with no consent requirement, four-field configuration)
WE SCAN IDs AT THIS DOOR
To check that IDs are valid and that guests are old enough to enter, our staff may scan the barcode on your government-issued ID.
What is saved: only your name, date of birth, ID number and the ID's expiration date. Nothing else on your ID is saved. No photo is taken.
Why: to verify age and ID validity, to prevent identity fraud, and to check our own ban list. Scan data is not used for marketing, is not sold, and is not shared with other venues.
How long: scan records are deleted after [21] days. Ban list entries are kept for [one year].
Your rights: to see, correct or delete your record, contact [VENUE NAME] at [EMAIL / PHONE].
Scanning is provided by CLICR, which hosts our records and does not read them. CLICR's privacy notice: clicrapp.com/privacy.
B-2. Georgia sign (consent required before scanning, O.C.G.A. § 40-5-120(5))
Georgia makes it a misdemeanor to scan another person's license or ID card without that person's prior knowledge and consent. Post this sign at every scanning point and have staff confirm consent before each scan using the device prompt. A patron who declines is checked visually instead.
ID SCANNING WITH YOUR CONSENT
Georgia law requires your knowledge and consent before we scan your ID. Please read this before you hand over your ID.
If you agree, our staff will scan the barcode on your ID to check that it is valid and that you are old enough to enter.
What is saved if you agree: your name, date of birth, ID number and the ID's expiration date. Nothing else. No photo is taken.
Why: to verify your age and ID, to prevent identity fraud, and to check our own ban list. Scan data is not used for marketing, is not sold, and is not shared with other venues.
How long: scan records are deleted after [21] days. Ban list entries are kept for [one year].
Your choice: you may decline the scan. If you decline, our staff will check your ID by looking at it instead.
Your rights: to see, correct or delete your record, contact [VENUE NAME] at [EMAIL / PHONE].
Scanning is provided by CLICR, which hosts our records and does not read them. CLICR's privacy notice: clicrapp.com/privacy.
Device prompt (Georgia). Before each scan the app should display: "Georgia law requires the guest's consent to scan. Has the guest read the sign and agreed to the scan?" with buttons Guest agreed – scan and Guest declined – visual check. The tap and its timestamp are recorded as the consent record; the app should record a visual-check outcome without capturing any ID data.
B-3. New York sign (four-field configuration under ABC Law § 65-b)
Use the B-1 general sign in New York, with two edits: add the sentence "Under New York law, scan information may be used only to verify age and may not be sold or shared," and delete any reference to demographic or analytics use. Do not reference a ban-list check unless the venue has turned that feature on, and do not reference age-range reporting, which is not available to New York venues.