ConversionCRM collects behavioral data on behalf of your workspace. We do not sell it, share it with third parties, or use it to train models. Here is exactly what we collect, how we store it, and what your users can request.
Data is encrypted in transit (TLS 1.2+) and at rest (AES-256 via Supabase). We collect only what is needed to score and stage users: page views, click events, time on page, and the email you pass to identify(). No passwords, payment card numbers, or PII beyond what you explicitly send. Data lives in the EU/US (Supabase, Vercel). You can request deletion at any time by emailing support@conversioncrm.co.
All data between your users' browsers, your backend, and ConversionCRM travels over TLS 1.2 or higher. The tracking widget, REST API, and dashboard all enforce HTTPS.
Event data, user profiles, and scores are stored in Supabase (Postgres) with AES-256 encryption at rest. Database credentials are stored in environment secrets, not in code.
The application runs on Vercel (global edge, SOC 2 Type II). The database runs on Supabase (SOC 2 Type II, ISO 27001 in progress). Both providers are reviewed annually.
Workspace data is isolated at the database row level using workspace IDs. No employee can query another workspace's data without an explicit audit trail. API keys are hashed, not stored in plaintext.
Page URL, event type (page_view / click / custom), timestamp, session ID, and workspace ID. No keystrokes, no form field values, no screenshots.
Only what you pass to identify(userId, { email }). Typically a user ID and email. No passwords, no payment data, no government IDs.
Passwords, credit card numbers, SSNs, form field contents, audio, video, or screen recordings. ConversionCRM is a behavioral signal tool, not a session replay tool.
Raw events are retained for 90 days. Computed scores and stage history are retained for the life of the workspace. You can request full deletion at any time.
ConversionCRM acts as a data processor on your behalf. You remain the data controller. We process only the data you send and only for the purpose of scoring and emailing your users.
Email support@conversioncrm.co with your workspace ID and the user's email or ID. We will delete all associated records within 30 days and confirm in writing.
We do not sell, rent, or share your workspace data or your users' data with any third party for advertising, analytics resale, or AI training purposes.
Our current sub-processors: Supabase (database), Vercel (hosting), Resend (email delivery). Full sub-processor list available on request.
To report a vulnerability, request a data deletion, or ask about our security practices, email support@conversioncrm.co. We respond to all security inquiries within 48 hours. Full privacy policy is at conversioncrm.co/legal/privacy.