Privacy Policy of ClickMeMaybe

Last updated: 3 September 2026

This Privacy Policy explains how personal data is processed in connection with ClickMeMaybe (clickmemaybe.com, hereinafter the "Service") — a SaaS tool that lets website owners add widgets (pop-ups, sticky bars, floating CTAs, social proof, countdowns, callback and exit-intent forms) to their own websites by pasting a short JavaScript snippet, and collect leads (e.g. email address, phone number, message) from visitors of those websites. It covers two groups of people: (1) Users — owners of accounts in the Service, and (2) Visitors — people who interact with widgets displayed on Users' websites. The Policy is drafted in line with Regulation (EU) 2016/679 (General Data Protection Regulation — "GDPR").

1. Data Controller and Processor — who is responsible for what

The operator of the Service is Michał Woźniak operating under the business name HEXGRID Michał Woźniak, registered office: ul. Bagienna 36C, 70-772 Szczecin, Poland, registered in the Central Registry and Information on Business Activity (CEIDG) of the Republic of Poland, Tax ID (NIP): 9552112428, REGON: 320190228, email: hello@clickmemaybe.com (hereinafter "HEXGRID" or "we").

Users' data (account holders): HEXGRID is the data controller of the data of people who register an account, pay for a plan, contact us or visit clickmemaybe.com.

Visitors' data (leads collected by widgets): the controller is the User — the owner of the website on which the widget is displayed. That User decides which data is collected and why. HEXGRID processes this data only on the User's behalf and instructions as a data processor (Article 28 GDPR) — we store it, display it in the User's panel and send notifications to the User. A data processing agreement is available on request at hello@clickmemaybe.com. If you are a Visitor and want to exercise your rights regarding data you submitted through a widget, contact the owner of the website in the first instance; you may also write to us and we will forward your request to the relevant User.

2. Contact with the Controller

3. Data protection matters

HEXGRID has not appointed a Data Protection Officer (it is not required for the scale of our activity). All data protection questions and requests should be sent directly to us:

Email: hello@clickmemaybe.com
Address: HEXGRID Michał Woźniak, ul. Bagienna 36c, 70-772 Szczecin
Phone: +48 537 357 057

4. Personal Data Security

We apply technical and organisational measures appropriate to the risk: encrypted connections (TLS), password hashing, access control to servers and the administration panel, regular backups, server logging and monitoring, and the principle of minimum necessary access. The Service is hosted on servers located in the European Union. We process personal data in accordance with the GDPR and Polish data protection law, including the Act of 10 May 2018 on the Protection of Personal Data.

5. Purposes, Legal Bases and Retention Periods

Below we list each purpose of processing together with the scope of data, legal basis, retention period and whether providing data is voluntary:

a) Creating and maintaining a User account
Scope: name, email address, password (stored as a hash), interface language, time zone, account settings, plan and usage limits. If you sign in with an external provider (e.g. Google), we receive only the basic public profile data (name, email address). Legal basis: Article 6(1)(b) GDPR (performance of the account agreement). Retention: for the life of the account and after its deletion until the expiry of claims (3 years). Voluntary, but required to have an account.
b) Providing the Service — websites, widgets, snippet and leads
Scope: domains of websites added by the User, configuration and content of widgets, statistics of widget displays and interactions, and leads submitted by Visitors (typically email address, phone number, name, message content, page URL, time of submission, technical data such as browser type and approximate location derived from IP). Legal basis for Users' data: Article 6(1)(b) GDPR. Visitors' data is processed on behalf of the User (see section 1) — the legal basis is determined by the User. Retention: leads are stored for as long as the User keeps them in the panel or until the account is deleted; after account deletion they are erased within 30 days (backups — up to 90 days).
c) Payments, subscriptions and billing
Payments are handled by <strong>Paddle</strong> (Paddle.com Market Ltd, London, UK), acting as Merchant of Record — the seller of record on the transaction. Paddle collects payment details, calculates and collects taxes and issues invoices/receipts. <strong>Card or bank details never reach HEXGRID.</strong> From Paddle we receive: email address, country, name/company details given at checkout, plan and price, transaction and subscription identifiers, payment status. Legal basis: Article 6(1)(b) GDPR (performance of the agreement) and Article 6(1)(c) GDPR (accounting obligations). Retention: for the life of the agreement and then as required by tax law (5 years from the end of the tax year). Paddle's own privacy policy is available at paddle.com/legal/privacy.
d) Service notifications
Scope: email address, name, content of notifications (e.g. a new lead, plan limit reached, billing events, security alerts). Legal basis: Article 6(1)(b) GDPR — these messages are necessary to deliver the Service. Retention: for the life of the account. Some notifications can be switched off in account settings.
e) Newsletter and marketing communication
Scope: email address, name (optional). Legal basis: Article 6(1)(a) GDPR (consent) and — for existing customers — Article 6(1)(f) GDPR (legitimate interest in direct marketing of our own services). Retention: until you unsubscribe or object. Entirely voluntary; each message contains an unsubscribe link.
f) Support, inquiries and complaints
Scope: name, email address, message content, account details necessary to resolve the case, optionally phone number. Legal basis: Article 6(1)(b) GDPR (contract), Article 6(1)(c) GDPR (consumer-law obligations regarding complaints) and Article 6(1)(f) GDPR (communication with people who contact us). Retention: until the case is closed and then until the expiry of claims.
g) AI features (widget generation with AI credits)
Scope: text prompts and widget settings you enter when using AI features. This content is sent to our AI model provider (Anthropic) to generate the result and is not used by us to train models. Do not enter personal data of third parties in prompts. Legal basis: Article 6(1)(b) GDPR. Retention: the generated result is stored as part of your widget; we do not keep prompts in separate logs.
h) Tax and accounting obligations
Scope: name, address, tax ID, transaction data (received from Paddle). Legal basis: Article 6(1)(c) GDPR. Retention: 5 years from the end of the calendar year in which the tax payment deadline fell. Providing data is a statutory requirement.
i) Establishing, asserting or defending claims
Scope: account data, transaction data, correspondence and other data necessary to prove or defend a claim. Legal basis: Article 6(1)(f) GDPR (legitimate interest). Retention: until the expiry of claims (as a rule 3 years).
j) Analytics of clickmemaybe.com (Google Analytics)
Scope: pages visited, time of visit, approximate location, device and browser type, entry source, pseudonymous client identifier. Google Analytics is loaded <strong>only after you consent</strong> in the cookie banner (Klaro). Legal basis: Article 6(1)(a) GDPR (consent), withdrawable at any time via the cookie settings. Retention: up to 14 months in Google Analytics.
k) Server administration and security
Scope: IP address, date and time of request, requested URL, browser and operating system information, error data — recorded automatically in server logs for clickmemaybe.com and for the widget delivery endpoints. Legal basis: Article 6(1)(f) GDPR (security, abuse prevention, ensuring the Service works). Retention: logs are kept for up to 90 days, unless needed as evidence in ongoing proceedings.

6. Automated decision-making and profiling

We do not make decisions based solely on automated processing that would produce legal effects for you or similarly significantly affect you. We do not profile Users or Visitors for marketing purposes. Widgets configured by Users may display content based on simple technical rules (e.g. time on page, exit intent, scroll depth, whether a widget was already closed) — these rules run in the Visitor's browser and are defined by the User.

7. Recipients of Personal Data

Personal data may be disclosed to the following categories of recipients, only to the extent necessary for the given purpose:

  1. Hosting provider — servers located in the European Union on which the Service and its database run
  2. Paddle.com Market Ltd — payment processing, tax handling and invoicing as Merchant of Record
  3. Email delivery provider — sending account, notification and support emails
  4. Anthropic — AI model provider used for AI widget generation (prompt content only, when you use AI features)
  5. Google LLC — Google Analytics on clickmemaybe.com (only after consent) and Google sign-in (if you choose it)
  6. Accounting firm and tax advisors — bookkeeping and tax compliance
  7. Legal advisors — when necessary to pursue or defend claims
  8. Public authorities — where disclosure is required by law (e.g. tax authorities, law enforcement)

8. Transfers outside the European Economic Area

The Service itself is hosted in the EU. Some of our providers may process data outside the EEA:

Paddle.com Market Ltd (United Kingdom) — the UK is covered by a European Commission adequacy decision (Article 45 GDPR).
Google LLC (United States) — Google Analytics and Google sign-in. Google participates in the EU-US Data Privacy Framework (Article 45 GDPR); Standard Contractual Clauses apply in addition.
Anthropic, PBC (United States) — AI model provider. Transfers are based on the EU-US Data Privacy Framework and/or Standard Contractual Clauses approved by the European Commission (Article 46(2)(c) GDPR).

9. Your rights

Every person whose personal data we process has the following rights under the GDPR:

  1. Right of access (Article 15 GDPR) — to obtain confirmation whether we process your data and, if so, a copy of it together with information about the purposes, categories, recipients and retention period.
  2. Right to rectification (Article 16 GDPR) — to have inaccurate data corrected and incomplete data completed. Users can edit most account data directly in the panel.
  3. Right to erasure — "right to be forgotten" (Article 17 GDPR) — to have your data deleted where one of the grounds in Article 17(1) GDPR applies. Users can delete their account, together with all websites, widgets and leads, from the account settings.
  4. Right to restriction of processing (Article 18 GDPR) — in the cases set out in Article 18(1) GDPR.
  5. Right to data portability (Article 20 GDPR) — to receive the data you provided to us in a structured, commonly used, machine-readable format. Users can export their leads from the panel.
  6. Right to object (Article 21 GDPR) — to processing based on Article 6(1)(f) GDPR, in particular to direct marketing.
  7. Right to withdraw consent (Article 7(3) GDPR) — at any time, without affecting the lawfulness of processing carried out before withdrawal (e.g. analytics cookies — via the cookie settings; newsletter — via the unsubscribe link).
  8. Right to lodge a complaint (Article 77 GDPR) — with the supervisory authority: the President of the Personal Data Protection Office (Prezes UODO), ul. Stawki 2, 00-193 Warsaw, Poland (uodo.gov.pl), or the supervisory authority of your habitual residence.

To exercise your rights, write to hello@clickmemaybe.com or to our registered address. We respond without undue delay, no later than within one month of receiving the request. If your request concerns data you submitted through a widget on a User's website, we will forward it to that User (the controller) and support them in handling it.

10. Cookies and browser storage

On clickmemaybe.com we use:

Essential cookies (our own) — session cookie, CSRF protection token, "remember me" cookie and the interface language/theme preference. They are required for logging in and for the Service to work and cannot be disabled. Lifetime: end of session or up to 1 year.

Consent management (Klaro) — a cookie/storage entry that remembers your choices in the cookie banner. Lifetime: up to 1 year.

Google Analytics — statistics cookies (_ga, _ga_*) loaded only after you click "accept" in the banner. Lifetime: up to 2 years. You can change or withdraw your choice at any time via the "Cookie settings" link in the footer.

On Users' websites (the widget snippet) — the ClickMeMaybe script does not set tracking cookies. It uses the browser's localStorage/sessionStorage only to remember technical state, e.g. that a widget has been closed or a form submitted (so it is not shown again) or the end time of a countdown. The website owner (User) is responsible for informing their visitors about the widget and for obtaining any consents required on their website.

You can also manage cookies in your browser settings; blocking essential cookies will prevent you from logging in to the Service.

11. Final Provisions

We may update this Privacy Policy when the law, our providers or the Service's features change. Users will be notified of material changes by email or in the panel at least 7 days before they take effect. Matters not covered here are governed by the GDPR and Polish data protection law. This version of the Privacy Policy applies from 3 September 2026.

In short — who is the controller: Your ClickMeMaybe account, payments, support and visits to clickmemaybe.com: HEXGRID is the controller. Data that visitors enter into widgets on a customer's website: the customer (website owner) is the controller and HEXGRID is the processor acting on their instructions. A data processing agreement is available on request at hello@clickmemaybe.com.

Stop guessing. Start converting.

Install in 5 minutes. Publish your first widget today.

Start Free Now