Click2Pop OÜ
Last updated: 03/08/2026 (3rd of August 2026)
Version: v03082026
Your privacy matters to us. This Privacy Policy explains how Click2Pop OÜ collects, uses, stores, shares, and protects personal data when you access or use our website, platform, and related services.
This Privacy Policy applies globally. Where local law provides additional rights, those rights apply alongside this policy.
By using our services, you acknowledge that you have read and understood the Privacy Policy.
1. Who we are
Data Controller
Click2Pop OÜ
Registration number: 17423354
Registered address: Harju Maakond, Tallinn, Lasnamäe linnaosa, Lõõtsa tn 5-11, 11415
Email: [email protected]
Click2Pop acts as data controller for the personal data it collects and processes in connection with operating our services and acting as Merchant of Record.
Click2Pop has not appointed a Data Protection Officer (DPO).
2. Scope of this policy
This Privacy Policy applies to personal data relating to:
- Website visitors
- Buyers of digital products
- Sellers using Click2Pop services
- Support contacts
- Marketing subscribers
This policy does not apply to third-party websites, tools, or services that are linked or used independently by Sellers.
3. Roles and data responsibility
Click2Pop
Click2Pop acts as data controller for personal data processed for:
- Operational and security
- Transaction facilitation as Merchant of Record
- Payments, refunds, and disputes (in coordination with payment providers)
- Tax, accounting, and regulatory compliance
- Seller onboarding and verification
- Customer support
Click2Pop is responsible only for the personal data it collects and processes within the Click2Pop platform and services.
Sellers
Sellers act as independent data controllers for any personal data they collect outside the Click2Pop platform, including through:
- Their own websites
- Their own marketing activities
- Their own communities or tools
Click2Pop is not responsible for Seller data practices outside the platform.
Payment providers and verification partners
Payment providers and identity verification services act as independent data controllers or processors, depending on the function performed.
They process personal data under their own privacy frameworks and legal obligations, including fraud prevention, AML/KYC, and sanctions compliance.
4. Personal data we collect
A. Data you provide directly
Depending on your role, we may collect and process:
- Name
- Email address
- Contact details
- Seller authentication information (magic links)
- Billing and invoicing information
- Tax and identity data for Seller onboarding and verification
- Communications with support
- Seller-submitted content metadata
Buyers do not create user accounts.
B. Data collected automatically
When you access our website or services, we may collect and process:
- IP address
- Device identifiers
- Browser type and version
- Operating system
- Pages visited and usage patterns
- Timestamps and interaction logs
- Error and crash data
This data may constitute personal data when combined with other identifiers.
C. Transaction and compliance data
As Merchant of Record, Click2Pop processes:
- Purchase history
- VAT and invoicing data
- Refund and chargeback records
- Fraud and risk indicators
Payment method details are processed by payment providers, not stored directly by Click2Pop where avoidable.
5. Why we process personal data
We process personal data to:
- Operate and secure our services
- Facilitate purchases and digital content access
- Process payments, refunds, and disputes
- Calculate, collect, and report applicable taxes
- Onboard and verify Sellers
- Prevent fraud and abuse
- Provide customer support
- Comply with legal and regulatory obligations
- Improve platform performance and reliability
We do not sell personal data.
6. Legal bases for processing (GDPR)
Where the GDPR applies, we rely on the following legal bases:
Performance of a contract
To provide services and complete transactions
Legal obligation
Tax law, accounting requirements, consumer protection, Anti Money Laundering (AML) / Know Your Customer (KYC), fraud prevention
Legitimate interests
Security, fraud prevention, service improvement
Consent
Marketing communications and optional features
You may withdraw consent at any time.
7. Seller onboarding and verification
Seller onboarding and identity verification data are collected to comply with:
- Legal and regulatory obligations
- Payment provider requirements
- Fraud and risk prevention
Providing this data is mandatory for Sellers who wish to use Click2Pop services.
8. International users and global compliance
Click2Pop operates globally.
Depending on your location, additional rights may apply, including under:
- GDPR (EU/EEA)
- UK GDPR
- California privacy laws
- Other applicable local laws
We apply a baseline data protection standard aligned with GDPR worldwide. Where local law requires a higher standard, we comply with that law.
9. International data transfers
Personal data may be processed outside your country of residence.
Where required, we implement appropriate safeguards, including:
- EU Standard Contractual Clauses
- Adequacy decisions
- Contractual, organizational, and technical protections
10. Data retention
We retain personal data only as long as necessary to fulfill the purpose for which it was collected:
- Buyer transaction data: as required by tax and accounting law
- Seller account data: while the Seller relationship exists and as required by law
- Compliance and verification data: per regulatory obligations
- Support communications: as needed to resolve issues
Applicable law requires the following minimum retention periods:
- Invoice, payment and tax records: retained for 10 years;
- KYC & AML records: retained for at least 5 years after the business relationship ends;
- General usage data: retained for up to 2 years for analytics and security purposes;
- Marketing data: retained until consent is withdrawn.
Data may be anonymized or aggregated where possible.
11. Security measures
We apply technical and organizational measures to protect personal data, including:
- Access controls
- Encryption in transit and at rest
- Secure hosting
- Limited access on a need-to-know basis
- Monitoring and incident response procedures
12. Sharing of personal data
We may share personal data with:
- Payment providers
- Identity verification services
- Hosting and infrastructure providers
- Professional advisors
- Regulatory authorities where required by law
- Successors in the event of a merger, acquisition, or asset transfer
We do not authorize third parties to use personal data for unrelated purposes.
13. Cookies and tracking
We use cookies and similar technologies for:
- Core website and platform functionality
- Security and fraud prevention
- Analytics and performance
- User preferences
Details about cookies and consent management are set out in our Cookie Policy.
14. Your rights
Subject to applicable law, you may have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion
- Restrict processing
- Object to processing
- Data portability
- Withdraw consent
Some rights may be limited where we must retain data by law.
To exercise your data rights, email [email protected].
15. Marketing communications
You receive marketing communications only where permitted by law or with consent.
You may opt out at any time.
Transactional and legally required communications are not subject to opt-out.
16. Children's data
The platform is not intended for people under 18.
We do not knowingly collect personal data from children.
If we become aware that a person under the age of 18 has provided us with data, we will delete it immediately.
17. Data breaches
If a personal data breach occurs, we will:
- Investigate promptly
- Notify authorities where required
- Inform affected individuals where legally necessary
18. Complaints
If you believe your data protection rights have been violated:
- Contact us first at [email protected]
- You may also lodge a complaint with your local data protection authority or the Estonian Data Protection Inspectorate
19. Changes to this policy
We may update this Privacy Policy to reflect:
- Legal or regulatory changes
- Service updates
- Operational requirements
Updates will be published.
Material changes will be communicated where required by law.
20. Contact
For privacy-related questions or requests:
Email: [email protected]
Controller: Click2Pop OÜ
21. Related documents and policies
This Privacy Policy should be read together with the following documents, which form part of the Click2Pop legal framework:
- Terms of Service
- Seller Agreement
- Refund and Dispute Policy
- Cookie Policy
Each document governs a specific aspect of Click2Pop.
In case of conflict:
- Mandatory law prevails
- Payment provider requirements prevail
- The Seller Agreement prevails (where applicable)
- The Refund and Dispute Policy prevails for refund and dispute matters
- The Terms of Service apply
- This Privacy Policy applies