Home/Security
Trust & Security

Your users' data is not our product

ConversionCRM collects behavioral data on behalf of your workspace. We do not sell it, share it with third parties, or use it to train models. Here is exactly what we collect, how we store it, and what your users can request.

The short version

Data is encrypted in transit (TLS 1.2+) and at rest (AES-256 via Supabase). We collect only what is needed to score and stage users: page views, click events, time on page, and the email you pass to identify(). No passwords, payment card numbers, or PII beyond what you explicitly send. Data lives in the EU/US (Supabase, Vercel). You can request deletion at any time by emailing support@conversioncrm.co.

Infrastructure

How data is stored and protected

Encryption in transit

All data between your users' browsers, your backend, and ConversionCRM travels over TLS 1.2 or higher. The tracking widget, REST API, and dashboard all enforce HTTPS.

Encryption at rest

Event data, user profiles, and scores are stored in Supabase (Postgres) with AES-256 encryption at rest. Database credentials are stored in environment secrets, not in code.

Hosting infrastructure

The application runs on Vercel (global edge, SOC 2 Type II). The database runs on Supabase (SOC 2 Type II, ISO 27001 in progress). Both providers are reviewed annually.

Access controls

Workspace data is isolated at the database row level using workspace IDs. No employee can query another workspace's data without an explicit audit trail. API keys are hashed, not stored in plaintext.

What we collect

Exactly what ConversionCRM tracks

Behavioral events

Page URL, event type (page_view / click / custom), timestamp, session ID, and workspace ID. No keystrokes, no form field values, no screenshots.

User identity

Only what you pass to identify(userId, { email }). Typically a user ID and email. No passwords, no payment data, no government IDs.

What we do NOT collect

Passwords, credit card numbers, SSNs, form field contents, audio, video, or screen recordings. ConversionCRM is a behavioral signal tool, not a session replay tool.

Retention

Raw events are retained for 90 days. Computed scores and stage history are retained for the life of the workspace. You can request full deletion at any time.

Compliance

GDPR and privacy practices

GDPR data processing

ConversionCRM acts as a data processor on your behalf. You remain the data controller. We process only the data you send and only for the purpose of scoring and emailing your users.

Data deletion requests

Email support@conversioncrm.co with your workspace ID and the user's email or ID. We will delete all associated records within 30 days and confirm in writing.

No third-party data selling

We do not sell, rent, or share your workspace data or your users' data with any third party for advertising, analytics resale, or AI training purposes.

Sub-processors

Our current sub-processors: Supabase (database), Vercel (hosting), Resend (email delivery). Full sub-processor list available on request.

Contact

Security questions or concerns

To report a vulnerability, request a data deletion, or ask about our security practices, email support@conversioncrm.co. We respond to all security inquiries within 48 hours. Full privacy policy is at conversioncrm.co/legal/privacy.

Privacy Policy Terms of Service Contact us