Privacy Policy

Effective Date: February 1, 2026

This Privacy Policy explains how StickyCTAs, a DBA of Moonlight Marketing Agency LLC ("we," "us," or "our"), collects, uses, and protects your personal information when you use StickyCTAs (stickyctas.com). We are committed to protecting your privacy and being transparent about our data practices.

1. Information We Collect

1.1 Account Information

When you create an account, we collect:

  • Your email address (used for authentication and communication).
  • Your name (if provided).
  • Organization or company name.
  • Account credentials (passwords are securely hashed and never stored in plain text).

1.2 Usage and Widget Data

As you use our platform, we collect:

  • Widget configurations (colors, text, layout, action button settings).
  • Contact information you enter for your widgets (e.g., your email, phone number, links) — this is used solely to configure your widget.
  • Usage activity within the dashboard (widgets created, edited, activated).
  • Google Analytics 4 Measurement IDs (if provided by you for your own tracking).

1.3 Technical Information

We automatically collect certain technical data, including:

  • IP address.
  • Browser type and version.
  • Device type and operating system.
  • Pages visited and time spent on the platform.
  • Log data for debugging and monitoring purposes.

1.4 Billing Information

When you subscribe to a paid plan, billing is processed through Stripe. We do not store your credit card or payment details directly. Stripe collects and secures payment information on your behalf in accordance with PCI-DSS standards.

2. How We Use Your Information

We use the information we collect for the following purposes:

  • To create and manage your account and provide access to our Service.
  • To process payments and manage your subscription.
  • To deliver and render your CTA widgets on your website.
  • To send you transactional emails (e.g., account confirmation, password resets, billing receipts).
  • To communicate important updates, security notices, or changes to our Service.
  • To monitor and improve the performance and security of our platform.
  • To debug issues and provide technical support.
  • To comply with legal obligations.

3. Cookies and Tracking

We use cookies and similar tracking technologies to enhance your experience on our platform. Specifically:

  • Session cookies: Used to maintain your logged-in state within the dashboard.
  • Authentication tokens: Used by Supabase to securely authenticate your identity.
  • Analytics cookies (_ga, _gid): Set by Google Analytics 4, used to measure site usage and understand how visitors interact with stickyctas.com. The _ga cookie persists for up to 2 years to distinguish unique users; the _gid cookie lasts 24 hours to distinguish users within a single session.

Analytics for measurement only: We use Google Analytics solely for site measurement and performance monitoring. We do not use analytics data for advertising, remarketing, or behavioral targeting. Your widget visitors are not tracked by StickyCTAs across other websites. You may control cookie behavior through your browser settings or by using Google's opt-out tools; however, disabling cookies may affect platform functionality.

4. How We Share Your Information

We do not sell, trade, or rent your personal information to third parties.

We may share your information in the following limited circumstances:

  • Service Providers: We share information with third-party providers who assist us in operating the Service, such as Vercel (application hosting and delivery), Supabase (database and authentication), Stripe (payment processing), Resend (transactional email delivery, including account verification, subscription confirmations, and trial reminders), and Google (analytics and search indexing via Google Analytics 4 and Google Search Console). These providers are bound by confidentiality obligations.
  • Legal Requirements: We may disclose information if required by law, court order, or government regulation.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.
  • With Your Consent: We will not share your information for any other purpose without your explicit consent.

5. Support and Troubleshooting

When you contact our support team, we may need to access your widget configurations, account details, or other information to diagnose and resolve issues. The following applies to any data shared during the support process:

  • We will only use shared information strictly for the purpose of troubleshooting and resolving your issue.
  • We do not share support data with any parties outside of our organization.
  • We recommend that you avoid sharing sensitive end-user data when contacting support. If possible, use a staging environment or remove personal information before providing access.
  • We cannot be held responsible for any loss of private information from data or sites shared with our support team. Please ensure you maintain appropriate backups.

6. Data Storage and Security

Your data is stored securely using industry-standard practices:

  • Application Hosting: The StickyCTAs platform is hosted on Vercel. Visitor requests, IP addresses, and request logs are processed by Vercel's infrastructure as part of serving the application.
  • Database: Hosted on Supabase with Row Level Security (RLS) policies ensuring that each organization can only access its own data.
  • Authentication: Managed by Supabase Auth with secure token-based sessions.
  • Payment Data: Handled exclusively by Stripe, which is PCI-DSS compliant. We never store payment card information.
  • Encryption: Data is encrypted in transit via HTTPS and at rest.

While we take all reasonable measures to protect your data, no system is 100% secure. We will notify you promptly in the event of a confirmed data breach.

7. Data Retention

We retain your personal information for as long as your account is active or as necessary to provide the Service. Upon account termination:

  • Your widget data and account information will be retained for 30 days.
  • After 30 days, your data will be permanently deleted from our systems.
  • Billing records may be retained longer as required by applicable tax or financial regulations.

8. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: View the personal information we hold about you.
  • Correction: Request corrections to inaccurate or incomplete data.
  • Deletion: Request deletion of your account and associated data.
  • Portability: Request a copy of your data in a machine-readable format.
  • Opt-Out: Opt out of non-essential communications (note: transactional emails cannot be disabled).

To exercise any of these rights, please contact us via the information provided in Section 12 below. We will respond to your request within 30 days.

9. CCPA Privacy Rights (California Residents)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):

  • The right to know what personal data we have collected about you, including the categories of personal data, the specific pieces of data collected, the categories of sources from which we collected the data, and the purposes for which we collected the data.
  • The right to request deletion of any personal data we have collected about you, subject to certain exceptions required by law.
  • The right to opt out of the sale of your personal data. Please note: we do not sell personal data as defined by the CCPA.
  • The right to non-discrimination for exercising your CCPA rights.

To exercise any of these rights, please contact us at stickyctas@moonlightmarketingagency.com. We will respond to your request within 45 days.

10. GDPR Data Protection Rights (EU Residents)

If you are a resident of the European Union, you are entitled to the following data protection rights under the General Data Protection Regulation (GDPR):

  • Right to access: You may request copies of your personal data. We may charge a small fee for this service.
  • Right to rectification: You may request that we correct any inaccurate personal data or complete any incomplete data we hold.
  • Right to erasure ("right to be forgotten"): You may request that we delete your personal data, under certain conditions.
  • Right to restrict processing: You may request that we restrict the processing of your personal data, under certain conditions.
  • Right to object: You may object to our processing of your personal data, under certain conditions.
  • Right to data portability: You may request that we transfer your personal data to another organization or directly to you, under certain conditions.

To exercise any of these rights, please contact us at stickyctas@moonlightmarketingagency.com. We will respond to your request within 30 days. If you believe we have not complied with applicable data protection laws, you have the right to lodge a complaint with your local data protection authority.

11. Children's Privacy

Our Service is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us immediately and we will take steps to delete it.

12. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

StickyCTAs

A DBA of Moonlight Marketing Agency LLC

1209 Mountain Rd Pl NE STE R

Albuquerque, NM 87110

Email: stickyctas@moonlightmarketingagency.com

Website: stickyctas.com

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by sending an email or posting a notice on the Service. Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated policy.