Legal
Privacy Policy
Last updated · September 12, 2026
Radar competitive observations
Radar stores public storefront captures and derived observations. Public history is delayed by three days and limited to captures from the past thirty days; immutable instant reports and explicitly published board selections have separate visibility. Connected Convertify stores and excluded domains are suppressed. Optional brand email subscriptions store your email and subscription preferences, require confirmation, and include an unsubscribe link. Abuse prevention and board-view counting use keyed, expiring network-identity hashes.
Store owners and rights holders can request exclusion or screenshot removal through our Radar removal process.
Introduction
Convertify (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our A/B testing and analytics platform for Shopify stores.
By using Convertify, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our service.
Information we collect
Merchant information
When you connect your Shopify store to Convertify, we collect:
- Account information (name, email address)
- Shopify store domain and access credentials
- Store data including products, orders, themes, and templates
- Order information including prices, discounts, shipping costs, and COGS
- Customer journey data and UTM parameters for attribution
Visitor information
When visitors interact with stores using Convertify, we collect:
- Unique visitor identifiers (cookies)
- Device type, browser information, and user agent
- UTM parameters and traffic source information
- Page views, cart events, and checkout events
- Test assignment data and variation interactions
- Behavioral signals (clicks, scroll depth, and session activity) for heatmaps and replay
- IP addresses (for device detection and fraud prevention)
Ad-platform data
When you connect your advertising accounts (Meta, Google Ads, TikTok, or Klaviyo), we collect:
- Campaign names and spend data
- Account identifiers and access tokens
- UTM parameters for attribution matching
How we use your information
We use the collected information to:
- Provide and maintain our A/B testing and analytics services
- Assign visitors to test variations and track their interactions
- Calculate accurate profit metrics (GMPV) by attributing ad spend
- Generate AI-powered Shopify Liquid code for test variations
- Provide statistical analysis using Bayesian methods
- Display analytics dashboards with segmented data
- Sync campaign spend data from connected ad platforms
- Send notifications about test results and system updates
- Improve our services and develop new features
- Detect and prevent fraudulent activity
Data storage and security
We implement appropriate technical and organizational security measures:
- All access tokens are encrypted using AES-256 encryption before storage
- Data is stored securely in PostgreSQL databases hosted on Supabase
- All API communications use HTTPS/TLS encryption
- Authentication is managed through Supabase Auth with industry-standard practices
- HMAC verification is used for all webhook requests from Shopify
- Access to merchant data is restricted to authorized personnel only
However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.
Third-party services
Convertify relies on the following sub-processors and third-party services:
- Shopify: accessing store data and managing themes
- Supabase: authentication and database hosting
- Vercel: application hosting and deployment
- Tinybird: the analytics warehouse for behavioral and event data
- OpenAI & Anthropic: AI-powered code generation (code and prompts only; no customer PII)
- Meta (Facebook/Instagram) Marketing API: campaign spend synchronization
- Google Ads API: campaign spend synchronization (when connected)
- Klaviyo: campaign and flow synchronization (when connected)
- TikTok: ad-platform connection (where enabled)
These services have their own privacy policies addressing how they use information. We encourage you to review them.
Data retention
We retain information for as long as necessary to provide our services and comply with legal obligations:
- Merchant account data is retained while your account is active
- Test data and analytics are retained for historical reporting
- Visitor tracking data is retained for attribution analysis
- Order data is retained for GMPV calculations
When you delete your account, we will delete or anonymize your personal information within 30 days, except where we are required to retain it for legal or compliance purposes.
Your rights
Depending on your location, you may have the following rights regarding your personal information:
- Access: request a copy of the personal information we hold about you
- Correction: request correction of inaccurate or incomplete information
- Deletion: request deletion of your personal information
- Restriction: request restriction of processing of your information
- Portability: request transfer of your information to another service
- Objection: object to our processing of your information
- Withdraw consent: where we rely on consent to process your information
To exercise these rights, please contact us at the email address below.
GDPR compliance (EU users)
If you are located in the European Economic Area (EEA), we process your personal information under these legal bases:
- Contract: processing necessary to provide our services
- Legitimate interests: analytics, fraud prevention, and service improvement
- Consent: where you have given explicit consent
- Legal obligation: compliance with applicable laws
CCPA compliance (California users)
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected, used, shared, or sold
- Right to delete personal information held by us
- Right to opt out of the sale of personal information (we do not sell your information)
- Right to non-discrimination for exercising your CCPA rights
Children’s privacy
Convertify is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you become aware that a child has provided us with personal information, please contact us and we will take steps to delete it.
Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of changes by posting the new policy on this page and updating the “Last updated” date. Changes are effective when posted on this page.
Data Processing Agreement
For merchants who require a Data Processing Agreement (DPA) for GDPR compliance, please contact us at the email below. We will provide a DPA outlining our obligations as a data processor and your rights as a data controller.
Contact us
If you have questions about this Privacy Policy or our data practices, contact us:
- Email: [email protected]
- Website: useconvertify.com
- Response time: we aim to respond to all privacy requests within 30 days
See also our Terms of Service.