Ghostery Plans and Products Privacy Policy

Effective Date: November 20, 2019 

I. Introduction

The Ghostery Plans and Products (“GPP”) are owned by Cliqz International GmbH (“Cliqz” or “Company”), which is headquartered at Arabellastrasse 23, 81925 Munich, Germany. The Company, as the responsible body under the German Data Protection Law, takes the protection of your personal data very seriously and will always offer you the GBE and its functionality with your privacy in mind.

We also recognize that the GPP are popular because people want to be informed and empowered. We share the belief that privacy, when done right, is empowering, and that is why privacy is central to the GPP and new functionality that we may add. Therefore, we only collect data to build our products for the benefit of our users and we believe that we as a company should never have any personal data (“Personal Data) about our users unless they affirmatively provide it to us.

The core functionality of the GPP is to inform users what third-party tracking technologies (“Trackers”) are tracking them on any given website or device application so individuals can exercise personal control over that activity by blocking them for a cleaner, faster, safer browsing experience and use of their own devices.

II. Basis to Collect and Use Personal Data

There is no obligation on your part to provide your Personal Data. However, if you do, we have a legitimate interest to collect and use it, namely so we can provide products or services, or complete a transaction with you.

III. Notion of Personal Data

Personal Data means any information concerning the personal or material circumstances of an identified or identifiable individual such as name and age. Non-personal data are all data that cannot be used to identify an individual, such as statistics about usage of a website.

IV. What Personal Data are collected

User Account: When you create a user account, we will collect the following Personal Data: name, email address.

Many GPP users had previously requested the ability to open accounts so they can receive product information and also take advantage of new functionality, certain Ghostery products, and higher tiers of service. You are not required to open a user account in order to use the Ghostery Product Extension (GBE) with the Basic plan service tier. If you choose to open a user account in this case, you can do so either when you download the GBE, or any other time through the GBE settings. At any time you can deactivate your user account, at which time you will no longer have access to the services that a user account offers.

IP-Address: We do not differentiate between static or dynamic IP addresses – that is driven at the user level – but please see the Security section below to learn more about the security measures we take to protect data – including your IP-address – that the GBE collects.

V. How Personal Data are used

The use of the GPP Personal Data that we collect when you open an account is used for: (i) syncing your GPP settings across browsers and devices, (ii) serving as your login credentials, and (iii) communicating directly to you through your email address in order to give you information about our products, services, updates and upgrades (in certain cases for a fee).

IP-addresses are solely collected for geolocation purposes but only on Zip Code level or above (for example city, county, continent) to improve the GBE. We never store IP addresses.

VI. Collection of Non-Personal Data

When you download the Ghostery Browser Extension and Ghostery Insights products, they collect on an ongoing basis the following data: web browser, operating systems, and opt-in settings to share Tracker information with the Company, when an installation, upgrade, or uninstallation occurs, and whether the extension is active or engaged by you.

The use of the aforementioned non-personal data is limited to: (i) communicating through the CMP (see VII.) – since we don’t have your name or email address – in order to share product information or updates and Company news, (ii) for internal analytical purposes such as accurately counting the number of browser extension downloads, (iii) providing the services of the Ghostery Start Tab, which may include sharing of the non-personal data with other Cliqz products you have installed, locally on your device, or (iv) surveying our users from time to time.

When using Ghostery Midnight, if errors occur within the Midnight application while in use, or if the application crashes or causes other applications to break or crash, non-personal data about the error(s) will be generated to help us identify the cause of the error so that we can fix it in a future update. These error reports (“crash logs” or “logs”) contain information such as the state of the application, operating system, and device at the time of the crash; other application names and data (depending on subscription plan); data about websites visited while Midnight is active (depending on subscription plan); and error information. No personal data is collected, and nothing in these logs can be used to personally identify the user. These logs are collected and saved locally on the user’s device, and, upon release of Midnight, are not automatically sent to Ghostery. If Ghostery will start collecting these logs, we will ask for your permission in doing so.

VII. The Consumer Messaging Platform (“CMP”)

The CMP is used from time to time as a way for us to effectively and generically communicate to our users, while still honoring their privacy. The CMP is automatically turned on, but you can easily turn it off by going to the GBE options page and following the instructions provided. If you turn off the CMP, you can still use the GPP, but you won’t receive any generic communications from us.

VIII. Offers

Offers, also known as Ghostery Rewards, is turned on by default and allows companies to show relevant marketing offers to users based upon an algorithm we created that anonymously determines intent and therefore particular commercial offers that may be of interest to you. This new functionality does not rely upon collected Personal Data and you can opt out of it at any time.

IX. Human Web

We developed a technology called Human Web, which is turned on by default, and creates anonymous group models that power the private quick-search, anti-tracking and anti-phishing technologies featured in the Cliqz products and will be soon be featured in the GPP.

Data Collection: In order for Human Web to function we automatically collect non-private URLs, search queries along with search engine results pages, suspicious URLs that could potentially be phishing websites, information related to safe and unsafe trackers, and information related to the prevalence and performance of Trackers.

Data Use: The data that we collect so Human Web can work is anonymized, aggregated and transmitted through the Human Web Proxy Network and used to improve the search, anti-tracking and anti-phishing features in the Cliqz browser.

For further information please go to https://cliqz.com/whycliqz/human-web.

X. Virtual Private Network (“VPN”)

For the VPN technologies we provide, we use a trusted third party provider. This service is operated by FoxyProxy LLC. Note that FoxyProxy is legally obliged to NOT log any personal data – including explicit or implicit network identifiers. FoxyProxy’s services cannot read message content (as it is encrypted).  No data is logged except bandwidth use.  That information is collected in order manage network performance.  We do not collect or store any IP address information.

XI. Data Processing Abroad

Although the Company is located in Germany, it partly operates out of the United States. The data we collect, personal or otherwise, are located on servers based in the United States. If you are accessing or using GPP from the European Union or other regions with laws governing data collection and use that may differ from U.S. law, please note that you may be allowing the collection or transferring of your personal data in or to the U.S. However, we have a strong data privacy framework in place to ensure an adequate level of protection for your Personal Data.

XII. Data Retention

If you deactivate your user account, the Company retains the collected Personal Data if and for as long as it may be required by law (for example to fulfill retention periods prescribed by law) or judicial order. The Company will use this personal data only for those purposes and retains it only as long as prescribed by law. After that the Personal Data will be deleted.

XIII. Data Portability & Erasure

In compliance with the GDPR, the Company provides features available in the product menu that allow users to easily download and delete the Personal Data associated with their user accounts.  If users choose to download their information, it will be downloaded as a machine-readable CSV file and will include their name, email address, and your account settings and preferences.  If users choose to delete their account, all Personal Data associated with the account will be completely and permanently deleted from the Company servers.

XIV. Security

The Company has reasonable and appropriate technical, physical and administrative safeguards in place for a company of our size and complexity to protect the data that is collected. Some of the specific security measures we take include instantly hashing the origination IP addresses using very strong encryption technology to protect your privacy, whereupon the collected IP addresses and user agent information is destroyed. In addition, to further preserve your security, the GPP do not collect any information on URLs beyond the path query string.

XV. Contacting the Company

At any time the user has the right to object any use of his personal data and can do so by writing to the Company at the physical address provided in the beginning of the document or by emailing the Company at privacy@ghostery.com If you object will be necessary to prove that you are the owner of the account. The Company has the right to answer your inquiry electronically. Please contact for this and all other inquiries, comments or concerns about these practices by email at privacy@ghostery.com.

XVI. Changes to Privacy Policy

We may occasionally change this Privacy Policy and when we do, we will also revise the “Effective Date” at the top of the Privacy Policy. If we make any material changes to our Privacy Policy, we will inform you via the CMP and, if you opened an account and gave us your email address, then we will also try to contact you through the email address you provided about those material changes. Ultimately, however, it is your responsibility to periodically review this Privacy Policy to stay informed about our data practices and any changes to them. Your continued use of the GBE constitutes your agreement to this Privacy Policy and any changes to it.

XVII. Payments & Subscriptions

We are offering paid subscriptions to use the GPP with a variety of features. There are several subscriptions at different prices charged on a recurring monthly or yearly basis, depending your preference.

We use the payment services provider (PSP) Stripe. If you pay our subscription fees through this service, it is necessary that you enter some personal data (name, address, contact data, GPP login data, financial information). Stripe acts as a data controller and not on our behalf as a processor. We pull some of this information into our product so you can more easily review your subscription, but we do this using the Stripe API and we do not store any of this information ourselves. For further information see Stripes privacy policy: https://stripe.com/de/privacy.

To calculate the appropriate regional VAT/GST/sales tax for each payment, we use the service Avalara. To calculate the applying taxes Avalara needs some personal data (country, postal code). This is the only information Avalara receives. Based on the postal code, Avalara determines how much tax should be charged and recorded via Stripe.

Stripe will use the Avalara API to calculate a regional VAT/GST/sales tax based on the users’ postal code and then returns the amount of tax that needs to be accounted for on that transaction. Stripe will charge the appropriate amount, tax included, and Avalara will record the amount of tax collected and in which region so that we can report those taxes to the regional governing body. For further information see the privacy policy of Avalara: https://www.avalara.com/us/en/legal/privacy-policy.html.