Privacy Policy
Effective date: 19 August 2026
Last updated: 19 August 2026
This Privacy Policy explains how Convertlyft LLC ("Convertlyft", "we", "us") handles personal information in connection with convertlyft.com and the Convertlyft service (the "Service").
An important distinction. This policy covers personal information about you — our website visitors, account holders, and prospective customers. It does not cover data collected by the Convertlyft Tag on our customers' websites about their visitors. For that data, the customer is the data controller and we act as their processor/service provider under our Data Processing Agreement ("DPA"). If you are a visitor to a website that uses Convertlyft and have questions about that site's data, please contact that website's owner.
1. What we collect
From visitors to convertlyft.com
- Technical data: IP address, device and browser type, operating system, referring URL, pages viewed, and interactions with our site.
- Cookies: we use first-party cookies only —
cvl_session(your signed-in workspace session) andcvl_account(your account token). We set no third-party cookies and no advertising cookies, needed to operate and improve our site. You can refuse cookies in your browser settings; some features may not work.
From account holders
- Account data: name, email address, password (hashed), company name, role, and preferences you set.
- Billing data (paid plans only): plan, billing address, and transaction history. Payment card details go directly to Stripe, our payment processor; we never see or store full card numbers. The free tier requires no card.
- Communications: emails, support requests, survey responses, and feedback you send us.
- Usage data: how you use the dashboard (features used, pages accessed), collected through our own Service — we use no third-party product-analytics tool on the dashboard, used to improve the product.
From third parties
We may receive limited business contact information (name, email, role) from public sources or sales/marketing service providers to reach potential customers.
What we do not collect
- We do not knowingly collect data from anyone under 18; we close such accounts when discovered.
- We do not intentionally collect sensitive or special-category data (health, biometric, genetic, religious, or similar).
- We do not sell your personal information, and we do not share it with third parties for their own advertising.
2. How we use your information
- To provide the Service (contract): operate your account, deliver dashboards and digests, provide support, send transactional and security notices, process billing.
- Legitimate interests: improve and secure the Service, prevent fraud and abuse, perform internal analytics and reporting, enforce our Terms, and send product and marketing communications where permitted (you can opt out at any time via unsubscribe links).
- Consent: where the law requires it — for example, certain marketing emails or non-essential cookies. You may withdraw consent at any time without affecting prior processing.
3. Aggregated and de-identified data
We may aggregate or de-identify information so it can no longer reasonably identify you, and use it for any lawful purpose — including research, benchmarks, and published industry studies. We do not identify customers in published studies without written consent.
4. How we share information
We share personal information only with:
- Service providers / subprocessors who process it on our behalf under contract — currently including Vercel (application hosting and delivery), Supabase (database, authentication and file storage), Stripe (payment processing for paid plans), Resend (transactional email), Pipedream (OAuth credential brokering for channels you connect), DataForSEO (search and ranking data) and OpenRouter (model routing). We use no third-party support-desk tool at this time. A current list is available at convertlyft.com/subprocessors. They may use it only to provide services to us.
- Legal and safety: government authorities or third parties where required by law, subpoena, or court order, or to protect rights, property, or safety.
- Business transfers: a buyer in connection with a merger, acquisition, or sale of assets, subject to this policy.
- With your consent, in other cases.
5. International transfers
We are based in the United Arab Emirates and our servers are located in Germany (database) and the United States (application servers). Your information may be processed in countries with different data-protection laws than yours. Where we transfer personal data from the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards, including EU Standard Contractual Clauses or the UK International Data Transfer Agreement.
6. Data retention
We keep personal information for as long as your account is active or as needed to provide the Service, and thereafter only as required by law (for example, tax and accounting records) or to resolve disputes. When we no longer need it, we delete or anonymize it; data in backups expires on the normal backup cycle.
7. Security
We use technical and organizational measures appropriate to the risk, including encryption in transit, access controls, and credential hashing. No system is perfectly secure; we cannot guarantee absolute security.
8. Your rights
Depending on your location, you may have the right to:
- access, correct, or delete your personal information;
- object to or restrict processing;
- data portability;
- withdraw consent (where processing is based on consent);
- opt out of marketing communications;
- lodge a complaint with your local supervisory authority.
Account holders can access and update most information in account settings. To exercise any right, email privacy@convertlyft.com. We respond within the period required by applicable law (typically 30 days).
California and US state residents
We act as a "business" for your account data and a "service provider" for data processed on behalf of customers. We do not sell or share personal information for cross-context behavioral advertising. You have the rights described above, including to know, delete, correct, and opt out, and the right not to be discriminated against for exercising them. Submit requests to privacy@convertlyft.com.
9. Do Not Track
We do not respond to browser Do Not Track signals; we do not permit third-party advertising trackers on our site.
10. Changes
We may update this policy and will post the new version with a revised date. For material changes, we will notify account holders by email or in-product notice. Continued use after the effective date constitutes acceptance.
11. Contact
Convertlyft LLC, Dubai, United Arab Emirates Privacy: privacy@convertlyft.com
Appendix — What the Convertlyft Tag collects on customer websites
(Included so customers can reference it in their own privacy disclosures. Processing of this data is governed by the DPA.)
When a customer installs our Tag on their website, the Tag collects, on the customer's behalf:
- Page data: URLs visited, page titles, referrer, UTM and other query parameters;
- Behavior data: clicks, scroll depth, form field interactions (field names/types, not values, where exclusion controls are used), rage-click and dead-click signals;
- Technical data: browser and device type, operating system, screen size, page load and performance timings, JavaScript errors (message, stack, page);
- Visit data: session identifiers, timestamps (validated and corrected if anomalous), entry/exit pages;
- Conversion data: purchase or lead events, including server-side events reported by the customer;
- IP addresses: processed transiently for bot filtering and coarse geolocation; they are used only in memory, as a rate-limiting and abuse-prevention key, and are not written to our database. The single exception is a public demo API credential, which records a per-address request counter; no such credential is currently issued.
By design: known bots and automation are dropped before storage; each event ID is recorded once; the website owner's own visits are marked internal and excluded by default; the Tag is read-only and cannot modify the customer's pages.
Customers are responsible for disclosing this collection to their visitors and obtaining any legally required consents, as described in our Terms of Service.