Legal

Privacy Policy

Last updated: 2026-04-25

1. Who we are

Clap Digital ("Clap", "we", "us") is a web development and software business operating from Dubai, United Arab Emirates. This policy covers clapdigital.co and the Clap Radar product (the "Service"). Contact us at contact@clapdigital.co.

2. What we collect

When you use the marketing site we collect minimal analytics (page views, country-level location, anonymised device info) via Google Analytics, Microsoft Clarity, and Meta Pixel.

When you sign up for Clap Radar we collect:

  • Account data: email address, and (if you sign in with Google) your Google profile name, profile photo, and Google account ID.
  • Site data: URLs of websites you connect to Radar, audit results, screenshots and HTML snapshots of your sites generated during audits, and the patches Radar's AI generates and you publish.
  • Billing data: if you subscribe to a paid plan, Stripe processes your payment. We store your Stripe customer ID and subscription metadata; we never store your card number.
  • Usage data: what you do inside Radar (audits run, AI sessions, patches published) so we can apply tier limits and improve the product.
  • Communications: emails you send us, support requests, and the messages you send to Radar's AI assistant.

3. How we use it

We use the data above to:

  • Operate the Service (run audits, generate AI patches, publish overlays to your sites, send transactional email).
  • Authenticate you and protect your account.
  • Bill paid subscriptions and prevent fraud.
  • Improve Radar's accuracy and performance. We do not train third-party AI models on your private data.
  • Send service updates and (with your consent) occasional marketing email. You can unsubscribe from marketing email at any time.

4. Who we share it with (sub-processors)

We use the following infrastructure providers to run the Service. They process data on our behalf under contractual data-protection terms:

  • Supabase — database and authentication (USA / EU regions).
  • Vercel — application hosting and serverless compute (USA / EU regions).
  • Stripe — payments and subscription billing (USA, Ireland).
  • Resend — transactional email delivery (USA, EU).
  • Groq — large-language-model inference for the AI builder (USA). Prompts and code-generation context are sent to Groq for the duration of each request and are not retained for model training.
  • Google PageSpeed Insights API and Google Chrome UX Report — performance audits (Google, USA).
  • Google OAuth — optional sign-in (Google, USA).
  • Cloudflare — CDN and edge security.

We do not sell personal data. We do not share data with advertisers beyond the anonymised analytics described in section 2.

5. How long we keep it

  • Account data is kept for as long as your account is active, plus 30 days after deletion to allow recovery.
  • Audit results are kept according to your tier (free: 30 days; paid: up to 12 months).
  • Edit-mode AI sessions auto-expire 15 minutes after creation.
  • Chatbot usage records are kept for 90 days.
  • Billing records are kept for 7 years to meet tax and accounting obligations.

6. Your rights

You can at any time:

  • Access, correct, or export your account data from inside Radar (Settings → Account).
  • Delete your account, which removes your account record, connected sites, audit history, and AI sessions. Email us at contact@clapdigital.co if the in-app option doesn't cover everything you need.
  • Withdraw consent for marketing email via the unsubscribe link in any marketing message.
  • Lodge a complaint with a data-protection authority. We are based in the UAE; if you reside in the EU, UK, or another jurisdiction with a data-protection authority, you may contact that authority directly.

7. Cookies

We use a small number of strictly-necessary cookies for authentication and session management, and analytics cookies (Google Analytics, Microsoft Clarity, Meta Pixel) to understand how the site is used. You can disable analytics cookies through your browser settings.

8. International transfers

Some of our sub-processors are based outside the UAE (notably the USA and EU). Where required, we rely on standard contractual clauses or equivalent safeguards approved by the relevant data-protection authority.

9. Security

We protect data with TLS in transit, encryption at rest where supported by our infrastructure, hashed credentials, hashed deploy tokens, content-security-policy headers, rate limiting, and a documented incident-response process. No system is perfectly secure; if you discover a vulnerability, please email contact@clapdigital.co with the subject "Security report".

10. Children

The Service is not directed at children under 16 and we do not knowingly collect personal data from them.

11. Changes to this policy

We will post changes to this page and update the "last updated" date. Material changes will also be communicated by email to active account holders.

12. Contact

Questions, requests, or complaints: contact@clapdigital.co.