Privacy policy
Veesie is a ClickForest product. This privacy policy explains which personal data we process, why, and what rights you have. Version 1.1, effective from 11 September 2026.
1. Data controller
The data controller for Veesie is:
Manon BV (trading as ClickForest)
Zwarte Leeuwstraat 78A, 2820 Bonheiden, Belgium
Company number / VAT: BE 0549.803.522
Email: hello@veesie.com
Website: veesie.com
2. Which personal data do we process?
| Category | Examples | Source |
|---|---|---|
| Account data | Email address, name, hashed password | You provide them yourself at registration |
| Organization data | Company name, chosen plan, onboarding status | Created at first login |
| Service usage | Clients, prompts, run results, AI answers, tokens, cost per call | Generated by using Veesie |
| Billing | Payment reference, Stripe customer ID | Via Stripe Checkout (only on a paid plan) |
| Technical data | IP address for rate limiting (not stored, except for chat conversations: see the row below), browser session token | Automatically via Cloudflare Workers |
| Trial hash | SHA-256 hash of the email address | Created on completing onboarding (see section 5) |
| Chat conversations | Your questions and the assistant's answers, the IP address, and for the dashboard chat your email address | When you use the chat on the website or in the dashboard |
We process no special categories of personal data (such as health data, political opinions or biometric data).
3. Purposes and legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Delivery of the service (dashboard, runs, analytics) | Art. 6(1)(b): performance of the contract |
| Authentication and session management | Art. 6(1)(b): performance of the contract |
| Billing and subscription management | Art. 6(1)(b) + Art. 6(1)(c): legal obligation (accounting law) |
| Email notifications about runs and alerts | Art. 6(1)(b): performance of the contract |
| Anti-abuse: preventing repeated free trials | Art. 6(1)(f): legitimate interest (see section 5) |
| Internal operational statistics (cost, usage) | Art. 6(1)(f): legitimate interest |
| Chat assistant: answering questions, preventing abuse and improving the answers | Art. 6(1)(f): legitimate interest |
4. Retention periods
| Data | Retention period |
|---|---|
| Account data, clients, prompts, run results | As long as your account is active. After deletion: erased immediately (cascade). |
| Invoice data | 7 years (legal accounting retention obligation) |
| Trial hash (SHA-256) | Indefinite (see section 5 for explanation and right to object) |
Operational cost logs (usage_events) | 12 months, then deleted automatically |
Chat conversations (chat_logs) | 6 months, then deleted automatically |
5. Trial history: SHA-256 anti-abuse hashing
trial_history). This is a pseudonymous, non-reversible fingerprint. The original email address cannot be recalculated from this hash.Why?
Veesie offers a free trial on sign-up. Without a measure, a user could delete their account and sign up again with the same email address to get a new free trial. The hash registration prevents this abuse: on a new sign-up we check whether the hash already exists. If so, the new trial starts immediately as expired.
Legal basis
Art. 6(1)(f) GDPR: legitimate interest. Our interest is the commercial integrity of the trial model and preventing systematic abuse. We weigh this against your privacy interest: the hash is pseudonymous (not directly identifiable), the email address itself is not stored, and its only function is binary detection (has this address ever had a trial: yes/no).
Objecting (Art. 21 GDPR)
You can object at any time to the processing of your trial hash via hello@veesie.com. We assess your request within 30 days. If the objection is well-founded, we delete the hash from trial_history.
6. Recipients and subprocessors
| Subprocessor | Function | Location |
|---|---|---|
| Supabase (Postgres + Auth) | Database, authentication | EU (Frankfurt) |
| Cloudflare (Workers) | Application hosting, edge processing | Global network: a request runs through the data centre closest to the visitor, which for European visitors is normally in Europe. Cloudflare, Inc. (US), based on SCCs |
| Resend | Transactional email (notifications, reports) | EU region |
| Stripe | Payment processing (only on a paid plan) | Ireland (EU) |
| Sentry | Error monitoring (error tracking) | EU (Frankfurt, Germany) |
| Google Analytics 4 | Website statistics for the public website. Without your consent it runs without cookies, and never inside the dashboard | US (Google LLC), based on SCCs |
| Microsoft Clarity | Usage analysis of the public website: heatmaps and recordings of mouse movement and clicks. Without your consent it runs without cookies, and never inside the dashboard | US (Microsoft Corporation), under SCCs |
| OpenAI, Anthropic, Google, Perplexity | LLM calls (prompts are sent to the providers) | US / EU (depending on the provider). Answers are stored in the EU DB. |
| DataForSEO | Measuring Google AI Overviews (your questions are sent to Google as a search query) | EU (Estonia), with sub-processors partly in the US, based on SCCs |
| Inngest | Running the measurements (queue, retries and the intermediate results of each step) | US (Inngest Inc, AWS servers in the US) |
Note on LLM providers: the prompts you configure in Veesie are forwarded to the relevant AI providers for processing. They usually contain no personal data (they are questions about your brand, not about people). Do check that your prompts themselves contain no personal data.
We never share personal data with third parties for marketing or profiling purposes.
Role with customer data: you are responsible for the lawfulness of the data you enter into Veesie. For personal data you provide as a customer and that we process on your behalf, we may act as a processor within the meaning of the GDPR. A data processing agreement is available on request via hello@veesie.com.
7. International transfers
The core data (account, clients, results) is stored in the EU (Supabase Frankfurt). LLM calls go to providers outside the EU (including OpenAI and Anthropic in the US). Google Analytics 4 and Microsoft Clarity, which run on the public website only (without cookies until you consent, and never inside the dashboard), also process data in the US. These transfers happen on the basis of the Standard Contractual Clauses (SCCs) offered by the relevant providers. In addition, Inngest runs the measurements on AWS servers in the US: during a measurement, your questions, your brand name and website, the names of your competitors and the generated recommendations also pass through it.
8. Your rights
Under the GDPR you have the following rights:
- Access (Art. 15): you can request which data we hold about you.
- Rectification (Art. 16): have incorrect data corrected.
- Erasure (Art. 17): delete your account and all associated data. You do this yourself via Dashboard, Settings, Delete account, or by email.
- Restriction (Art. 18): have processing temporarily restricted.
- Portability (Art. 20): request a copy of your data in machine-readable format. You can do this yourself via Dashboard, Settings, Privacy (JSON export).
- Objection (Art. 21): object to processing based on legitimate interest (including the trial hash).
Send your request to hello@veesie.com. We respond within 30 calendar days.
You also have the right to lodge a complaint with the Belgian Data Protection Authority (DPA).
9. Cookies and tracking
Strictly necessary cookies (no consent required): a session cookie for authentication (Supabase Auth) and security cookies from Cloudflare and Cloudflare Turnstile (bot protection on the sign-up and contact pages). We also set a cookie holding only the language you arrived in (nl, en or fr), so that an account you create starts in that language. It contains no identifier and is not shared with anyone.
Analytics cookies: for website statistics we use Google Analytics 4 and Microsoft Clarity, and both run on the public website only, never inside the dashboard. Without your consent both measure without cookies: Google Analytics then provides only aggregated, estimated figures, and Clarity uses a separate identifier per page view, so we cannot tell that different visits come from the same person. Clarity records anonymous mouse movement, clicks and scrolling so we can see where visitors get stuck. If you do consent, both may set cookies and follow a visit across several pages. If you withdraw your choice, that stops again and Clarity deletes its cookies. We do not do remarketing and do not build advertising profiles.
Advertising measurement: if you reach our site via an ad, the URL contains a click identifier (Google calls it gclid, gbraid or wbraid). If you consent, we keep it for up to 90 days in a cookie of our own and link it to your organisation once you sign up. That tells us which ad led to a customer, without following you across other websites. If you decline, we do not store that identifier. Once we actually advertise, Google may, with your consent, also set its own advertising cookies for that same measurement; as long as no campaigns are running, that does not happen.
10. Google user data (Analytics connection)
If you connect your Google Analytics account to Veesie, we read only the data of the property you select, through the Google Analytics API. We request read-only access (analytics.readonly). We use that data for a single purpose: showing how many visitors your website receives from AI tools such as ChatGPT, Perplexity and Claude.
What we store: the email address of the Google account you connect with, the selected property ID, and Google's access tokens. Those tokens are stored encrypted (AES-256-GCM). We also keep a copy of the requested report for up to fifteen minutes, so your dashboard does not have to call Google on every page view. We do not retrieve or store data about individual visitors.
What we do not do: we do not sell this data, do not use it for advertising, do not share it with third parties, and do not use it to train AI models. No one at Veesie reads it, except when you ask for support or the law requires it. Veesie's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Revoking access: the Disconnect button on the Traffic page in your dashboard ends the connection, after which we immediately delete the stored tokens and the cached report. You can also revoke access directly with Google, through your Google account's security settings.
11. How we protect your data
We take appropriate technical and organisational measures to protect your data, as required by Art. 32 GDPR. For sensitive data, such as your password and the access tokens of your Google account, the following applies in particular:
- Encrypted in transit: all traffic to veesie.com runs over HTTPS (TLS). We send a Strict-Transport-Security header with a two-year lifetime and are on the HSTS preload list, so browsers never connect unencrypted.
- Encrypted at rest: sensitive fields in our database, including the access and refresh tokens of your Google Analytics connection, are encrypted with AES-256-GCM (authenticated encryption). If that data is tampered with, decryption fails. The key is kept outside the database, as a secret with our hosting provider.
- Passwords: your password is stored hashed by Supabase Auth and is never readable to us. A password change is confirmed with a one-time code we send to your email address, so a stolen session alone is not enough to take over your account.
- Separation between customers: every organisation sees only its own data. This is enforced twice, with Row Level Security at database level and with ownership checks in every server action of the application.
- Limited internal access: our internal admin pages sit behind an additional access layer and are limited to a fixed list of addresses. Access to production data is restricted to those who need it for maintenance or support.
- Keeping as little as possible: from your Google Analytics we retrieve aggregated report figures only, never data about individual visitors. We keep that report for at most fifteen minutes. When you disconnect, we delete the access tokens and the stored report immediately and completely.
- The connection itself: the OAuth flow uses a signed state (HMAC-SHA256) bound to your session that expires after ten minutes, so nobody can set up a connection on your behalf. We request read access only, never write permissions.
- Infrastructure: the core data is held at Supabase in Frankfurt (EU) and the application runs on Cloudflare. Both providers are certified to SOC 2 and ISO 27001 for their infrastructure. Sign-up and contact forms are protected against bots with Cloudflare Turnstile.
If we identify a data breach that poses a risk to your rights and freedoms, we report it to the Belgian Data Protection Authority within 72 hours and inform you where the GDPR requires it. A fuller description of our measures is on our security page.
12. Changes
For material changes to this policy we send an email notification to all active users and update the date at the top. Minor editorial changes are made without separate notice.
13. Contact
For questions, requests or complaints about privacy: hello@veesie.com.
Back to veesie.com