Privacy policy
This site sets no cookies, runs no analytics and loads nothing from third-party servers. What follows is the complete account of the personal data we do handle, and how to have it removed.
The short version. We collect nothing until you choose to send it. If you complete the fit check or the scorecard, we store your answers and your contact details so a consultant can reply, we delete them after 24 months, and you can have them erased sooner by sending one email. There are no cookies, no tracking pixels, no advertising and no data sales.
1. Who is responsible for your data
The data controller for this website is:
- The U-Shaped House LLC, trading as ClicAuto
- 1925 Grand Ave Ste 129 PMB 83841, Billings, MT 59102, United States
- Email: contact@clicauto.com
For any question about this policy or to exercise your rights, email the address above with “Privacy” in the subject line. We answer within 30 days, and usually within five working days.
Representative in the European Union
Our processing of personal data relating to people in the European Economic Area is limited to business contact details and business context that visitors submit voluntarily. It is occasional, involves no special category data and no large-scale monitoring, which is the exemption set out in Article 27(2) of the GDPR. We have therefore not appointed an Article 27 representative. If the nature or scale of our processing changes, this section will be updated before that happens. You can exercise every right described in section 11 directly with us, in English or French.
2. What this policy covers
This policy covers clicauto.com and its subpages, including the AI fit check
on the home page and the readiness scorecard. It applies the European General Data
Protection Regulation (GDPR) and, where relevant, the UK GDPR to all visitors, regardless
of where they are located.
It does not cover third-party sites you may reach from here — a scheduling page, a review platform, a social network — each of which has its own policy. Section 13 covers data we handle inside a paid client engagement, which is governed by a separate agreement.
3. What we collect
Nothing, until you act
Simply reading this site transmits no personal data to us beyond what any web server necessarily receives to deliver a page (section 3.4). We load no external fonts, no analytics, no social widgets, no advertising scripts and no embedded video.
3.1 The AI fit check
The fit check is a six-question conversation. Your answers stay in your browser until you reach the final step, tick the consent box and submit. At that point we receive:
- your answers to the six business questions (role, team size, where time goes, hours lost, timing, budget range);
- your name and email address, and your company name if you choose to give it;
- the recommendation and score the tool produced from your answers;
- the fact that you consented, the moment you did, and the version of this policy in force;
- how many seconds the exchange took, the page URL, and the referring website if your browser sent one — which tells us which channel brought you here;
- a salted one-way hash of your IP address, used only to stop the form being abused. It cannot be turned back into your IP address.
We do not store your browser's user-agent string. If you abandon the fit check before submitting, we receive nothing at all.
3.2 The readiness scorecard
The scorecard scores ten answers in your browser and shows the result without asking for anything. Only if you then request the detailed read-out do we receive your email address along with those answers and your score, on the same basis as above.
3.3 Direct contact
If you email us or book a call, we hold whatever you put in that message or booking, for as long as needed to deal with it and to keep a record of our business correspondence.
3.4 Server logs
Our hosting provider records technical access logs — IP address, date and time, the file requested, the response status and the user agent — as every web server does. These are generated and controlled by the host for security and troubleshooting. We do not use them to build profiles and do not combine them with form submissions.
4. Why we use it, and on what legal basis
| What we do | Why | Legal basis |
|---|---|---|
| Store your fit check or scorecard submission | So we can prepare and send you a relevant answer | Consent — Art. 6(1)(a) |
| Reply to you by email and, if you ask, quote for work | To take steps at your request prior to a contract | Pre-contractual necessity — Art. 6(1)(b) |
| Send an internal alert when an enquiry arrives | So enquiries are answered in hours, not days | Legitimate interest — Art. 6(1)(f) |
| Rate-limit the form and check a hidden anti-bot field | To keep the endpoint from being abused as a spam relay | Legitimate interest — Art. 6(1)(f) |
| Record which website referred you | To know which channels work, in aggregate | Legitimate interest — Art. 6(1)(f) |
| Keep business correspondence and invoices | Accounting and legal record-keeping obligations | Legal obligation — Art. 6(1)(c) |
We never use your data for advertising, we never sell or rent it, and we do not add you to a mailing list. If you want to hear from us again after we've answered, you have to ask.
5. Scoring and profiling — how the tools work
Both the fit check and the scorecard calculate a score from your answers and use it to suggest which of our services fits, or to tell you that none of them do. We think you should know exactly how that works:
- the calculation runs entirely in your browser, in plain JavaScript, on the answers you selected;
- it uses no external data source, no credit reference, no enrichment service and no data bought from anyone;
- the hours and monetary figures shown are arithmetic on your own estimates, assuming half the hours you identify are recoverable at a blended rate of $45 an hour. They are illustrative, not a forecast;
- the score influences nothing except which service we suggest and how quickly we follow up.
This is not automated decision-making that produces legal effects or similarly significant effects on you within the meaning of Article 22 of the GDPR. Every enquiry is read by a person before any reply is sent, and no price, refusal or condition is ever applied to you by the tool alone. You are free to disagree with the output — telling us so is often the most useful thing in the first call.
7. Who receives your data
Nobody buys it, nobody rents it and there is no advertising network involved. Data is accessible to our own consultants who need it to answer you, and to the following service providers:
| Provider | Role | What it receives | Location |
|---|---|---|---|
| OVH SAS | Web hosting, storage of submissions, email mailbox | Everything described in section 3 | France (EU) |
| Telegram | Instant internal alert that an enquiry arrived | Reference code, score, business answers and the suggested service. No name, no email address, no company name. | Outside the EEA |
| Calendly LLC | Meeting scheduling, only if you click “book a call” | Whatever you enter on their booking page | United States |
The alert channel is deliberately blind: it tells us that a qualified enquiry exists and what it is about, while your identity travels only to our EU-hosted mailbox and our EU server. We may also disclose data where we are legally required to, or to establish or defend a legal claim.
8. Transfers outside the European Economic Area
We are a company established in the United States, so our own access to enquiry data is a transfer outside the EEA. Two consequences follow, and we would rather state them plainly than bury them:
- Storage stays in the EU. The website, the submission archive and the mailbox are hosted by OVH in France. Data is not copied to US infrastructure as a matter of course.
- Access happens from where we work. Our consultants read enquiries from Europe, and our company is US-registered. Where a transfer to the United States occurs, we rely on the European Commission's Standard Contractual Clauses or, for the providers that are certified, the EU–US Data Privacy Framework, together with technical measures such as minimising what is sent to non-EU services at all.
US law does not offer identical protection to EU law, and you may have fewer avenues of redress against a US recipient than against an EU one. Our answer to that is to send as little as possible: this is why the instant alert channel carries no identifying data, and why we ask for a name, an email and nothing more.
You can request a copy of the safeguards we rely on at any time.
9. How long we keep it
| Data | Kept for |
|---|---|
| Fit check and scorecard submissions | 24 months, then deleted automatically |
| Anti-abuse rate-limit counters (hashed IP) | One hour |
| Email correspondence | Up to 3 years after our last exchange |
| Contracts, invoices and accounting records | As required by applicable tax and company law, typically 7 years |
| Server access logs | As set by our host, typically a few months |
clicauto.fitcheck browser storage |
Until you close the tab |
Deletion of submissions is enforced by the application itself, not by a reminder in someone's calendar: each new submission removes archive files that have passed the 24-month window.
10. Security
- The whole site is served over HTTPS with HTTP Strict Transport Security.
- A Content Security Policy restricts what the browser is allowed to load and execute.
- Submissions are stored outside the public web root and the directory is additionally denied at server level.
- The form endpoint accepts requests only from our own domain, caps request size, rate-limits by hashed IP address and rejects submissions without consent.
- IP addresses are salted and hashed rather than stored.
- Access to the archive is limited to the people who need it.
No system is perfect. If you believe you have found a vulnerability, please tell us at contact@clicauto.com before disclosing it publicly; see also security.txt. If a breach ever affects your rights, we will notify the competent supervisory authority within 72 hours and tell you directly where the regulation requires it.
11. Your rights
If you are in the EEA or the UK, the GDPR gives you the following rights. We extend them to every visitor regardless of location, because operating two standards would be harder than doing it properly once.
- Access — a copy of the personal data we hold about you (Art. 15).
- Rectification — correction of anything inaccurate (Art. 16).
- Erasure — deletion of your data (Art. 17). For a fit check submission this is immediate and unconditional.
- Restriction — a freeze on processing while a dispute is resolved (Art. 18).
- Portability — your data in a machine-readable format (Art. 20). We hold submissions as JSON and will send you yours as such.
- Objection — to processing based on legitimate interest (Art. 21).
- Withdrawal of consent — at any time, without affecting the lawfulness of what happened before (Art. 7(3)).
To exercise any of these, email contact@clicauto.com. Quoting the reference code from our reply, or the email address you used, is enough for us to find your record — we will not demand identity documents for a routine request. There is no charge, and we reply within 30 days.
12. Complaints
If you think we have handled your data badly, tell us first — most issues come down to something we can fix the same day.
You also have the right to lodge a complaint with a data protection supervisory authority, in the EEA member state of your habitual residence, your place of work, or where the alleged infringement took place. In the United Kingdom the authority is the Information Commissioner's Office. A directory of European authorities is published by the European Data Protection Board. Using this route does not require you to contact us first.
13. Data inside client engagements
When we work on a paid engagement, we frequently touch systems that contain personal data belonging to our client's own customers or staff. In that context the client is the controller and we act as a processor on their instructions. That relationship is governed by the engagement contract and, on request, a data processing agreement — which we will sign as a matter of course for any engagement touching personal data.
Our standing rules for that work:
- we ask for the minimum access needed, and prefer test or anonymised data whenever it will do;
- we document which third-party AI services process what, before anything is connected to them;
- we do not submit client data to a model that trains on it, unless the client asks for that in writing;
- access credentials are handed back or revoked at the end of the engagement;
- we tell clients when a workflow they want would, in our view, breach the GDPR — including when that costs us the work.
If you are an individual whose data was processed inside such an engagement, your rights are exercised against our client as controller. Contact us and we will point you to them.
14. Children
This is a business-to-business service and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has sent us personal data, email us and it will be deleted.
15. Changes to this policy
Each version of this policy carries a version identifier, and the version in force at the moment you consented is stored with your submission. This means we can always tell you exactly what you agreed to, rather than pointing at whatever the page says today.
If we change anything material, we will update the version and effective date at the top of this page. Where a change requires it, we will ask for fresh consent instead of relying on the old one.
Questions about any of the above: contact@clicauto.com.