convertlyft
How it works Pricing Sign in
Start free

Privacy Policy

Effective date: 19 August 2026
Last updated: 19 August 2026

In plain words: This policy covers you — people who visit convertlyft.com or hold an account with us.

From visitors we collect technical data such as IP address, browser type and pages viewed, and we set first-party cookies only — no third-party or advertising cookies.

From account holders we also collect what you give us (name, email, company, the messages you send) and how you use the dashboard. We do not sell any of it. To ask a question or exercise a right, email privacy@convertlyft.com.

This Privacy Policy explains how Convertlyft LLC ("Convertlyft", "we", "us") handles personal information in connection with convertlyft.com and the Convertlyft service (the "Service").

An important distinction. This policy covers personal information about you — our website visitors, account holders, and prospective customers. It does not cover data collected by the Convertlyft Tag on our customers' websites about their visitors. For that data, the customer is the data controller and we act as their processor/service provider under our Data Processing Agreement ("DPA"). If you are a visitor to a website that uses Convertlyft and have questions about that site's data, please contact that website's owner.


1. What we collect

From visitors to convertlyft.com

  • Technical data: IP address, device and browser type, operating system, referring URL, pages viewed, and interactions with our site.
  • Cookies: we use first-party cookies only — cvl_session (your signed-in workspace session) and cvl_account (your account token). We set no third-party cookies and no advertising cookies, needed to operate and improve our site. You can refuse cookies in your browser settings; some features may not work.

From account holders

  • Account data: name, email address, password (hashed), company name, role, and preferences you set.
  • Billing data (paid plans only): plan, billing address, and transaction history. Payment card details go directly to Stripe, our payment processor; we never see or store full card numbers. The free tier requires no card.
  • Communications: emails, support requests, survey responses, and feedback you send us.
  • Usage data: how you use the dashboard (features used, pages accessed), collected through our own Service — we use no third-party product-analytics tool on the dashboard, used to improve the product.

From third parties

We may receive limited business contact information (name, email, role) from public sources or sales/marketing service providers to reach potential customers.

What we do not collect

  • We do not knowingly collect data from anyone under 18; we close such accounts when discovered.
  • We do not intentionally collect sensitive or special-category data (health, biometric, genetic, religious, or similar).
  • We do not sell your personal information, and we do not share it with third parties for their own advertising.

2. How we use your information

  • To provide the Service (contract): operate your account, deliver dashboards and digests, provide support, send transactional and security notices, process billing.
  • Legitimate interests: improve and secure the Service, prevent fraud and abuse, perform internal analytics and reporting, enforce our Terms, and send product and marketing communications where permitted (you can opt out at any time via unsubscribe links).
  • Consent: where the law requires it — for example, certain marketing emails or non-essential cookies. You may withdraw consent at any time without affecting prior processing.

3. Aggregated and de-identified data

We may aggregate or de-identify information so it can no longer reasonably identify you, and use it for any lawful purpose — including research, benchmarks, and published industry studies. We do not identify customers in published studies without written consent.

4. How we share information

We share personal information only with:

  • Service providers / subprocessors who process it on our behalf under contract — currently including Vercel (application hosting and delivery), Supabase (database, authentication and file storage), Stripe (payment processing for paid plans), Resend (transactional email), Pipedream (OAuth credential brokering for channels you connect), DataForSEO (search and ranking data) and OpenRouter (model routing). We use no third-party support-desk tool at this time. A current list is available at convertlyft.com/subprocessors. They may use it only to provide services to us.
  • Legal and safety: government authorities or third parties where required by law, subpoena, or court order, or to protect rights, property, or safety.
  • Business transfers: a buyer in connection with a merger, acquisition, or sale of assets, subject to this policy.
  • With your consent, in other cases.

5. International transfers

We are based in the United Arab Emirates and our servers are located in Germany (database) and the United States (application servers). Your information may be processed in countries with different data-protection laws than yours. Where we transfer personal data from the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards, including EU Standard Contractual Clauses or the UK International Data Transfer Agreement.

6. Data retention

We keep personal information for as long as your account is active or as needed to provide the Service, and thereafter only as required by law (for example, tax and accounting records) or to resolve disputes. When we no longer need it, we delete or anonymize it; data in backups expires on the normal backup cycle.

7. Security

We use technical and organizational measures appropriate to the risk, including encryption in transit, access controls, and credential hashing. No system is perfectly secure; we cannot guarantee absolute security.

8. Your rights

Depending on your location, you may have the right to:

  • access, correct, or delete your personal information;
  • object to or restrict processing;
  • data portability;
  • withdraw consent (where processing is based on consent);
  • opt out of marketing communications;
  • lodge a complaint with your local supervisory authority.

Account holders can access and update most information in account settings. To exercise any right, email privacy@convertlyft.com. We respond within the period required by applicable law (typically 30 days).

California and US state residents

We act as a "business" for your account data and a "service provider" for data processed on behalf of customers. We do not sell or share personal information for cross-context behavioral advertising. You have the rights described above, including to know, delete, correct, and opt out, and the right not to be discriminated against for exercising them. Submit requests to privacy@convertlyft.com.

9. Do Not Track

We do not respond to browser Do Not Track signals; we do not permit third-party advertising trackers on our site.

10. Changes

We may update this policy and will post the new version with a revised date. For material changes, we will notify account holders by email or in-product notice. Continued use after the effective date constitutes acceptance.

11. Contact

Convertlyft LLC, Dubai, United Arab Emirates Privacy: privacy@convertlyft.com


Appendix — What the Convertlyft Tag collects on customer websites

(Included so customers can reference it in their own privacy disclosures. Processing of this data is governed by the DPA.)

When a customer installs our Tag on their website, the Tag collects, on the customer's behalf:

  • Page data: URLs visited, page titles, referrer, UTM and other query parameters;
  • Behavior data: clicks, scroll depth, form field interactions (field names/types, not values, where exclusion controls are used), rage-click and dead-click signals;
  • Technical data: browser and device type, operating system, screen size, page load and performance timings, JavaScript errors (message, stack, page);
  • Visit data: session identifiers, timestamps (validated and corrected if anomalous), entry/exit pages;
  • Conversion data: purchase or lead events, including server-side events reported by the customer;
  • IP addresses: processed transiently for bot filtering and coarse geolocation; they are used only in memory, as a rate-limiting and abuse-prevention key, and are not written to our database. The single exception is a public demo API credential, which records a per-address request counter; no such credential is currently issued.

By design: known bots and automation are dropped before storage; each event ID is recorded once; the website owner's own visits are marked internal and excluded by default; the Tag is read-only and cannot modify the customer's pages.

Customers are responsible for disclosing this collection to their visitors and obtaining any legally required consents, as described in our Terms of Service.

Product How it works Product The agent Live demo SEO audit Funnel audit Pricing CRO consultant alternative API
Legal Privacy Terms DPA Subprocessors
Company Convertlyft LLC, Dubai, UAE Hosted on Vercel (United States); database on Supabase (Germany) privacy@convertlyft.com legal@convertlyft.com
convertlyftConvertlyft LLC · Dubai, UAE