1. Who we are
CLView ("we", "us", "our") is a client dashboard operated by AppanDesign, a digital studio based in New Jersey, United States. This policy explains what information CLView handles and the control you have over it.
We've written it in plain English on purpose. If anything is unclear, email [email protected] and a real person will explain it.
2. Who this policy covers
CLView handles data about two different groups of people, and the rules are different for each:
- Our clients — business owners who have a CLView login. We decide how this data is handled, so we are the "data controller" for it.
- Visitors to our clients' websites — people whose activity is recorded by the CLView tracking script installed on a client's site. Here the client is the data controller and CLView is the "processor" acting on their instructions. We only handle that data to provide the dashboard to that client.
Sections 3, 5 and 6 are about client data. Section 4 is about website visitors. Section 14 is written specifically for visitors.
3. Information our clients give us
When you sign up for a CLView dashboard we collect:
- Your name, business name, email address and phone number
- Your business website address
- Your login password, stored only as a one-way bcrypt hash — we cannot read it, and neither can anyone who obtains the database
- Notification and report preferences you set
- Standard web server access logs generated when you use the dashboard. Like every web server these include the connecting IP address; they are kept for 90 days for security and debugging, then deleted. They are not loaded into the application or shown to anyone.
Billing is arranged directly with AppanDesign outside the dashboard. CLView does not store card numbers or bank details.
4. Website visitor tracking
This is the part most policies bury, so we'll be direct about it. CLView gives clients a small JavaScript file (t.js) that they install on their own website. When someone visits a page carrying that script, CLView records:
| What | Why |
|---|---|
| Page address & title | To show the client which pages bring in business |
| Referring site | To attribute a visit to Google, a directory, an ad, and so on |
Campaign tags (utm_source, utm_medium, utm_campaign) | To attribute leads to a specific marketing campaign |
| Browser user agent, device type, screen width | To report desktop vs. mobile performance |
| Session ID & visitor ID | Random identifiers stored in cookies, so repeat visits and multi‑page journeys can be joined together |
| Contact form submissions | Name, email, phone, message and requested service — delivered to the client as a lead |
| Clicks on phone and email links | To count calls and email enquiries generated by each page |
What the script does not do
- It does not store your IP address. Visitor IP addresses are never written to our database — not for analytics, not for location, not for anything
- It does not record keystrokes, mouse movement or screen replays
- It does not follow visitors across other websites — data collected on one client's site is never mixed with another's
- It does not build advertising profiles, feed ad networks, or share anything with data brokers
- It does not read cookies or storage set by anyone other than CLView
Form contents are recorded because that is the entire point of lead tracking — a business needs to receive the enquiry sent to it. Visitors should not enter sensitive information (health details, government ID numbers, card numbers) into a website contact form, and our clients are told not to request it.
5. Connected Google accounts
Clients can optionally connect a Google account so the dashboard can display their own business data. This is entirely voluntary and can be disconnected at any time.
We request read access to only two things:
- Google Business Profile — your reviews, ratings, and profile performance figures such as searches, map views, website clicks and call taps
- Google Search Console (read‑only) — clicks, impressions, average position, and the search queries and pages for the website you own
We store the access and refresh tokens Google issues so the dashboard can refresh this data on a schedule. Tokens are stored on our server, are never shared, and are deleted when you disconnect. You can also revoke CLView's access at any time from your Google account permissions page.
CLView's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google data solely to display it back to you inside your own dashboard and reports. We do not transfer it to others, do not use it for advertising, and do not allow humans to read it except with your explicit permission, for security purposes, or where required by law.
6. Automated site scans
To produce performance and security scores, CLView periodically checks our clients' public websites:
- The page address is sent to Google PageSpeed Insights, which returns speed and Core Web Vitals scores
- We make ordinary requests to the site to read its security response headers and TLS certificate
- We check that the site is reachable, for uptime monitoring
These checks only ever touch publicly available pages — the same information any visitor's browser receives.
7. How we use data
We use the information described above only to:
- Operate the dashboard, reports and notifications a client signed up for
- Deliver leads and call alerts to the business that earned them
- Answer support requests
- Detect abuse, spam, fraud and security threats
- Keep backups and diagnose faults
- Meet legal obligations such as tax records and lawful requests
We do not sell personal data, and we do not share it with advertisers, data brokers or any other party for marketing. We never have, and the business does not depend on it.
8. AI processing
CLView includes an AI assistant that can summarise leads and answer questions about a dashboard. It runs on a self‑hosted open‑source model on AppanDesign's own hardware.
- Data sent to the assistant never leaves our infrastructure
- It is not sent to OpenAI, Anthropic, Google or any other third‑party AI provider
- It is never used to train any public model
- Prompts and responses are not retained beyond your session unless you save them
9. Where data lives
All CLView data is stored on a server that AppanDesign owns and administers in New Jersey, United States. It is:
- Reachable only through an encrypted Cloudflare tunnel, with no directly exposed ports
- Served over TLS end to end
- Backed up nightly to encrypted storage
- Monitored for uptime and security events
CLView runs as a single application with one database. Every record is tied to a client ID, and the application enforces on every request that a signed‑in user can only reach rows belonging to their own account. Clients cannot see, query or export one another's leads, analytics or reports.
10. Third‑party services we use
CLView depends on a deliberately short list of outside services. Here is all of it, and what each one receives:
| Service | What it receives |
|---|---|
| Cloudflare | DNS, TLS termination and DDoS protection. Sees traffic metadata, including visitor IP addresses, in transit. |
| Google APIs | Read‑only Business Profile and Search Console data you authorise, plus public page addresses sent for PageSpeed scoring. |
| Gmail SMTP | Outbound transactional email — lead alerts, reports, password resets. |
| Twilio | Optional SMS lead alerts. Receives the mobile number to notify and the alert text. |
| Google Fonts | Serves the typefaces used by this website. |
That is the complete list. CLView carries no Meta pixel, no Google Tag Manager, no advertising SDKs, no behavioural analytics platform and no session‑replay tooling.
12. How long we keep data
| Data | Retention |
|---|---|
| Client account data | For as long as the account is active |
| Leads and call records | Lifetime of the account, unless deleted sooner by the client |
| Page views and analytics | 25 months, after which raw rows are removed and only totals are kept |
| Monthly report snapshots | Lifetime of the account |
| Server and error logs | 90 days |
| Encrypted backups | 30 days on a rolling basis |
| Google access tokens | Until you disconnect, then deleted |
| Billing and tax records | 7 years, as required by US law |
If an account is closed we keep the data for 30 days so it can be exported, then delete it from live systems within 60 days. It leaves the backups as those backups age out.
13. Your rights
Wherever you live, we offer everyone the same rights:
- Access — get a copy of what we hold about you
- Correct — fix anything inaccurate
- Export — receive your leads and analytics in a portable format
- Delete — have your data erased
- Object or restrict — tell us to stop a particular use
- Withdraw consent — disconnect Google, or remove the tracking script, at any time
To use any of these, email [email protected] from the address on your account. Most requests are answered within 7 days, and all within 30. We will never charge you for it or make you argue for it.
We do not discriminate against anyone for exercising these rights, and we do not use personal data for automated decisions that have legal effects.
14. If you visited a website that uses CLView
If you filled in a form or called a business whose site runs our script, your details were sent to that business — they are the ones who decide how it is used. CLView stores and displays it for them.
You can:
- Contact the business directly to have your enquiry deleted — they can remove it from their dashboard themselves
- Email us at [email protected] and we will locate the record and pass the request on, or action it ourselves where we are permitted to
- Clear your cookies, which removes the visitor and session identifiers described in section 11
- Use a tracker blocker or your browser's Do Not Track setting — our script is a plain first‑party file and standard blocking tools will stop it loading
15. If you're a CLView client
When you install our tracking script on your website you become the data controller for your visitors' information, and you are responsible for telling them about it. That means you must:
- Publish a privacy policy on your own site describing the analytics and lead tracking, the cookies it sets, and how long you keep enquiries
- Obtain consent where the law requires it — for example a cookie banner for visitors in the UK, EU or EEA
- Honour access and deletion requests from your own customers, and tell us if you need help fulfilling one
- Not place the tracking script on pages that collect health, financial or other special‑category information
Email [email protected] and we'll send you a ready‑made paragraph covering the CLView script that you can paste straight into your website's privacy policy.
16. Security
Measures we actually have in place:
- Passwords stored as bcrypt hashes, never in readable form
- TLS on every connection, with plain HTTP requests redirected to HTTPS
- Session cookies set HttpOnly, Secure and SameSite to resist theft and cross‑site abuse
- All database access through prepared statements, to prevent SQL injection
- Every dashboard request re‑checks that the signed‑in user owns the records being requested
- The server sits behind Cloudflare with no directly exposed ports, and is patched and monitored
No system is perfectly secure. If a breach ever affects your data we will tell affected account holders within 72 hours of confirming it, explain exactly what was involved, and tell you what to do about it.
17. Children
CLView is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child's information has reached us, email [email protected] and we will delete it promptly.
18. Changes to this policy
If we make a material change — new data collected, a new third party, a new purpose — we will email every active account holder at least 30 days before it takes effect. Small clarifications and typo fixes are simply posted here with a new "last updated" date.
Previous versions are available on request.
19. Contact us
Questions, concerns, or a request about your data:
- Email — [email protected]
- Post — AppanDesign, New Jersey, United States
A person reads every one of these, usually the same day.