Privacy Policy
Effective: July 13, 2026
This Privacy Policy explains how Converge ("we") collects, uses, stores, and shares data. Converge is built on one principle: your data is yours. We are the pipe, not the vault.
1. What Data We Process
1.1 Account Data (you provide to us)
| Category | Details | Purpose | Retention |
|---|---|---|---|
| Account info | Email, name (or company name), password (Argon2id hashed) | Create and manage your account | Account lifetime + 30 days after deletion |
| Payment info | Card number / payment token (processed directly by Stripe/Paddle; we never store full card numbers) | Process subscription payments | Per Stripe/Paddle retention policy |
| Billing info | Billing address, invoice records | Tax compliance, invoicing | Statutory period (typically 7 years) |
1.2 Tracking Data (generated by your end users)
| Category | Details | Processing | Default retention |
|---|---|---|---|
| Click data | IP address, User-Agent, Referrer, timestamp, click ID | Record ad click source for attribution | 30 days (adjustable) |
| Conversion data | Event type (purchase/refund/add-to-cart), amount, order ID, timestamp | Send conversion events to ad platforms | Attribution window (adjustable, default 30 days) |
| CAPI user data | Email, phone, name, DOB, gender, city, postal code, country, IP, User-Agent, Facebook Click ID (fbc), Facebook Browser ID (fbp) | SHA256-hashed, then sent to Meta/TikTok official APIs for event matching. Plaintext PII is hashed and sent immediately -- never stored on disk. | Hashed + sent immediately; plaintext not retained |
| Refund adjustment data | Original conversion ID, refund amount, refund reason (optional) | Write back refund events to ad platforms, correcting conversion value | Same as linked conversion record |
1.3 Automatically Collected Technical Data
| Category | Details | Purpose |
|---|---|---|
| Service logs | API request time, endpoint path, response status code, processing time | Troubleshooting, performance monitoring, security auditing |
| Error logs | PHP error messages, stack traces (no user PII) | Bug fixes |
2. Data Storage & Security
Self-Hosted Edition
All data is stored on your own server (MySQL database). We have zero access to your data. Data security is your responsibility.
Cloud-Hosted Edition
- Data stored on MySQL 8.0 instances in DigitalOcean US data centers
- Database connections use TLS encryption
- All passwords are hashed with Argon2id (irreversible)
- CAPI user PII (email, phone, name, etc.) is SHA256-hashed before transmission; plaintext never touches disk
- IP anonymization supported (last octet zeroed). Enabling it may reduce CAPI match quality
3. Data Sharing & Third Parties
We do not sell your data or your end users' data. Data is shared only as follows:
| Recipient | Data shared | Purpose | Legal basis |
|---|---|---|---|
| Meta (Facebook CAPI) | SHA256-hashed email/phone/name + plaintext IP/UA/click ID | Conversion event matching and ad optimization | You actively configure and enable the CAPI integration |
| TikTok (Events API) | SHA256-hashed email/phone + plaintext IP/UA/click ID | Conversion event matching and ad optimization | You actively configure and enable TikTok CAPI |
| Google Ads | Aggregated conversion event type and value | Conversion tracking | You actively configure and enable |
| Stripe / Paddle | Payment token, amount, billing email | Process your payment | Contract performance (your subscription) |
| Cryptomus | USDT wallet address, amount | Process USDT payments and affiliate commission payouts | You actively choose this payment method |
Key point: we only send data to a third party when you actively configure and enable that integration. No config = no data sent.
4. Your Rights & Choices
- Access: View your account info and tracking data (via dashboard and API)
- Export: Self-hosted -- direct database export. Cloud -- CSV/API export
- Delete: Delete your account. We will erase all your data (billing records may be retained for tax compliance)
- IP anonymization: Enable in Settings; last IP octet is zeroed
- Data retention settings: Customize click data retention days and archival policy (Settings → Privacy & Attribution)
- Disable CAPI: Disable in integration settings at any time to stop sending data to ad platforms
5. End Users (your customers)
Converge is your data processor (self-hosted) or sub-processor (cloud). You are the data controller.
Your obligations:
- Provide your end users with a privacy notice about your use of tracking services (including CAPI)
- Obtain end-user consent where required (GDPR Art. 6, CCPA opt-out rights)
- Respond to end-user data subject requests (access, deletion, correction) -- you must handle these yourself; we cannot identify your end users directly
6. Data Retention
| Data type | Default | Adjustable range |
|---|---|---|
| Click data (active) | 30 days | 1-365 days |
| Click data (archived) | Not archived (0 days) | 0-3650 days |
| Conversion data | Attribution window (default 30 days) | 1-365 days |
| Account data | Account lifetime | Not adjustable |
| Billing records | Statutory period (7 years) | Not adjustable |
Data exceeding retention periods is automatically deleted. Deleted data is not recoverable.
7. Cookies & Tracking Technology
- First-party cookie: Stores click ID for attribution. Lifetime = attribution window.
- fbp/fbc cookies: If Meta CAPI is enabled, reads Meta's Facebook Browser ID and Click ID for event deduplication.
- What we do not use: No fingerprinting, no third-party tracking pixels (except those you configure), no ETag tracking.
8. International Data Transfers
Cloud edition data is stored in the United States. CAPI integrations you configure send data to: Meta (US/Ireland), TikTok (US/Singapore), Google (US). Self-hosted: data location is determined by your server location. If you are subject to GDPR and transfer data to the US: we rely on Standard Contractual Clauses (SCCs).
9. Data Breach Notification
If a data breach involving your account data occurs, we will notify you via your registered email within 72 hours. Self-hosted users must monitor their own servers.
10. Children's Privacy
The Service is not intended for children under 16. We do not knowingly collect children's data. If discovered, contact us for immediate deletion.
11. Policy Changes
Material changes will be announced via email and on the website at least 14 days in advance. Continued use means acceptance.
12. Contact
Data protection requests: privacy@converge.io
General legal: legal@converge.io