C Converge

Privacy Policy

Effective: July 13, 2026

This Privacy Policy explains how Converge ("we") collects, uses, stores, and shares data. Converge is built on one principle: your data is yours. We are the pipe, not the vault.

1. What Data We Process

1.1 Account Data (you provide to us)

CategoryDetailsPurposeRetention
Account infoEmail, name (or company name), password (Argon2id hashed)Create and manage your accountAccount lifetime + 30 days after deletion
Payment infoCard number / payment token (processed directly by Stripe/Paddle; we never store full card numbers)Process subscription paymentsPer Stripe/Paddle retention policy
Billing infoBilling address, invoice recordsTax compliance, invoicingStatutory period (typically 7 years)

1.2 Tracking Data (generated by your end users)

CategoryDetailsProcessingDefault retention
Click dataIP address, User-Agent, Referrer, timestamp, click IDRecord ad click source for attribution30 days (adjustable)
Conversion dataEvent type (purchase/refund/add-to-cart), amount, order ID, timestampSend conversion events to ad platformsAttribution window (adjustable, default 30 days)
CAPI user dataEmail, phone, name, DOB, gender, city, postal code, country, IP, User-Agent, Facebook Click ID (fbc), Facebook Browser ID (fbp)SHA256-hashed, then sent to Meta/TikTok official APIs for event matching. Plaintext PII is hashed and sent immediately -- never stored on disk.Hashed + sent immediately; plaintext not retained
Refund adjustment dataOriginal conversion ID, refund amount, refund reason (optional)Write back refund events to ad platforms, correcting conversion valueSame as linked conversion record

1.3 Automatically Collected Technical Data

CategoryDetailsPurpose
Service logsAPI request time, endpoint path, response status code, processing timeTroubleshooting, performance monitoring, security auditing
Error logsPHP error messages, stack traces (no user PII)Bug fixes

2. Data Storage & Security

Self-Hosted Edition

All data is stored on your own server (MySQL database). We have zero access to your data. Data security is your responsibility.

Cloud-Hosted Edition

3. Data Sharing & Third Parties

We do not sell your data or your end users' data. Data is shared only as follows:

RecipientData sharedPurposeLegal basis
Meta (Facebook CAPI)SHA256-hashed email/phone/name + plaintext IP/UA/click IDConversion event matching and ad optimizationYou actively configure and enable the CAPI integration
TikTok (Events API)SHA256-hashed email/phone + plaintext IP/UA/click IDConversion event matching and ad optimizationYou actively configure and enable TikTok CAPI
Google AdsAggregated conversion event type and valueConversion trackingYou actively configure and enable
Stripe / PaddlePayment token, amount, billing emailProcess your paymentContract performance (your subscription)
CryptomusUSDT wallet address, amountProcess USDT payments and affiliate commission payoutsYou actively choose this payment method

Key point: we only send data to a third party when you actively configure and enable that integration. No config = no data sent.

4. Your Rights & Choices

5. End Users (your customers)

Converge is your data processor (self-hosted) or sub-processor (cloud). You are the data controller.

Your obligations:

6. Data Retention

Data typeDefaultAdjustable range
Click data (active)30 days1-365 days
Click data (archived)Not archived (0 days)0-3650 days
Conversion dataAttribution window (default 30 days)1-365 days
Account dataAccount lifetimeNot adjustable
Billing recordsStatutory period (7 years)Not adjustable

Data exceeding retention periods is automatically deleted. Deleted data is not recoverable.

7. Cookies & Tracking Technology

8. International Data Transfers

Cloud edition data is stored in the United States. CAPI integrations you configure send data to: Meta (US/Ireland), TikTok (US/Singapore), Google (US). Self-hosted: data location is determined by your server location. If you are subject to GDPR and transfer data to the US: we rely on Standard Contractual Clauses (SCCs).

9. Data Breach Notification

If a data breach involving your account data occurs, we will notify you via your registered email within 72 hours. Self-hosted users must monitor their own servers.

10. Children's Privacy

The Service is not intended for children under 16. We do not knowingly collect children's data. If discovered, contact us for immediate deletion.

11. Policy Changes

Material changes will be announced via email and on the website at least 14 days in advance. Continued use means acceptance.

12. Contact

Data protection requests: privacy@converge.io

General legal: legal@converge.io