Data controller: Convertfy S.L., Urb. La Giralda 8, 11300 La Línea de la Concepción (Cádiz), Spain Contact: privacy@convertfy.io (data protection enquiries)
1. Who we are and how to read this policy
Convertfy provides a conversion-recovery service for online gaming, sweepstakes and casino operators (“operators”). Our service has two parts: a back-office dashboard that operators sign in to, and an embeddable script (the “SDK”) that operators install on their own websites.
We process personal data in two distinct roles, and your rights and our obligations differ depending on which applies:
- As a data controller, for the personal data of the operator staff who create and use Convertfy accounts. We decide why and how that data is processed. Section 3 covers this.
- As a data processor, for the data the SDK collects from visitors on an operator’s website. The operator is the controller of that data and decides the purposes; we process it on their documented instructions under a Data Processing Agreement (DPA). Section 4 covers this.
If you are a website visitor and have questions about data collected on an operator’s site, the operator is your primary point of contact as the controller. We will assist them in responding to your request (see Section 8).
2. Summary of our privacy posture
We have deliberately built the SDK to minimise data:
- No cookies and no persistent visitor identifiers. The SDK sets no cookies and
writes nothing durable to a visitor’s device. A frequency cap uses only
sessionStorage, which the browser clears at the end of the session. - No cross-site tracking and no profiles. We do not build advertising profiles and do not sell personal data.
- Coarse, not precise. Location is derived to country / region / city level from the connection’s IP address; we do not use GPS or store the IP address itself.
- Aggregation where possible. Heatmap and content-experiment data is aggregated at the point of collection and holds no per-person record.
This summary is provided for clarity and does not replace the detail below.
3. Operator account data (Convertfy as controller)
When a member of an operator’s team creates or uses a Convertfy account, we process:
| Data | Examples | Source |
|---|---|---|
| Identity & contact | Name, email address, profile image | Provided via our authentication provider |
| Organisation | Organisation name, role/membership | Provided on sign-up |
| Account & usage | Sign-in events, settings, content you create (campaigns, experiments, trackers) | Generated by your use |
| Technical | IP address, browser/device data, log data | Collected automatically |
Purposes and legal bases (EU GDPR Art. 6 / UK GDPR):
- To provide and secure the service, and authenticate sign-in: performance of a contract.
- To operate, maintain, troubleshoot and improve the service, and to keep it secure against abuse: legitimate interests.
- To comply with legal, tax and regulatory obligations: legal obligation.
- To send service and, where permitted, product communications: legitimate interests or consent where required.
Authentication and identity management are handled by Clerk (see Sub-processors).
Retention: account data is kept for the life of the account and for up to 24 months after closure, unless a longer period is required by law.
4. Visitor data collected by the SDK (Convertfy as processor)
The following is collected on operator websites on behalf of, and on the instructions of, the operator, who is the controller. We process it under our DPA. Operators are responsible for providing notice to, and obtaining any required consent from, their visitors (see Section 9).
4.1 Campaign interaction events
When the SDK shows an overlay and a visitor interacts with it, we record an event (impression, click, dismiss, or game completion) with:
- the event type, and the campaign and operator it relates to;
- device type (desktop/mobile), browser and operating system (derived from the User-Agent string);
- coarse geolocation (country, and where available region and city) derived from the IP address by our hosting provider’s edge network. The IP address itself is not stored, only the derived location;
- page URL and referrer of the page where the event occurred, and the browser language.
Each event is a single record. It contains no cookie, no persistent identifier, and nothing that singles out an individual visitor across sessions or sites.
4.2 Conversion data
If the operator uses our conversion tracking, their server (or, where enabled, their website) reports registrations and deposits attributed to a Convertfy campaign. This includes:
- the operator’s own identifier for the user (an opaque/pseudonymous id chosen by the operator; operators may hash it before sending);
- for deposits, the amount and currency and a transaction reference;
- the attributed campaign and, where an operator runs a control group or a content experiment, a group or variant label derived from a session value.
This is the most sensitive category we handle. We treat the user identifier as opaque and do not attempt to resolve it to a named individual.
4.3 Content experiments (A/B tests)
Where an operator runs an A/B test on a page, the SDK shows each visitor one version of the tested content, chosen from a random session-scoped value, and records aggregate counters only: how many times each version was shown and how many times the tested elements were clicked, per day and device type. These counters carry no visitor identifier and no per-person record.
4.4 Heatmap data
Where an operator enables heatmaps for a specific page, the SDK collects, in aggregate form:
- counts of clicks per on-page element and the click position within that element;
- how far down the page visitors scrolled (in bands);
- where enabled by the operator, value-free form-interaction statistics (which field a visitor stopped at), never the contents of any field; password fields and fields marked to be ignored are skipped entirely.
Optionally, an operator may capture a structural snapshot of a page’s layout (via a dashboard tool) so heatmaps can be drawn over a copy of the page. Form input values are masked out of these snapshots and are never stored.
Heatmap data carries no visitor identifier and is stored as counters, not as a per-person trail.
4.5 Retention of visitor data
Visitor data is retained per the operator’s documented instructions and our DPA, for no longer than 14 months unless the operator instructs otherwise or the law requires.
5. Cookies and similar technologies
The SDK does not set cookies. It uses browser sessionStorage for strictly
functional purposes only: capping how often an overlay is shown in a session, and a
random, session-scoped value used to keep the visitor’s experience consistent within
that session (for control groups and content experiments). These values are cleared
when the browser session ends and are not shared across sites.
The back-office dashboard uses cookies that are strictly necessary for sign-in and security (set by our authentication provider).
6. Who we share data with (sub-processors)
We use a small number of vetted infrastructure providers (“sub-processors”) to run the service. Each is bound by a contract with data-protection and security obligations. The current list, with each provider’s role and location, is maintained at /subprocessors.
We do not sell personal data and do not share it for third-party advertising.
7. International data transfers
Convertfy is established in Spain. Several of our infrastructure sub-processors are located in the United States. Where personal data is transferred out of the EEA / UK, we rely on appropriate safeguards: the EU Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum, and/or the sub-processor’s certification under the EU-U.S. Data Privacy Framework, together with supplementary measures where needed. Details are in the DPA and the Sub-processors list.
8. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to withdraw consent. California residents have rights under the CCPA/CPRA, including to know, delete, correct, and opt out of “sale”/“sharing” (we do neither).
- Operator account data: contact us at privacy@convertfy.io.
- Visitor data collected on an operator’s site: the operator is the controller; please contact them. If you contact us, we will refer you to the operator and assist them in responding without undue delay.
You also have the right to lodge a complaint with a supervisory authority. In Spain this is the Agencia Española de Protección de Datos (AEPD, www.aepd.es); in the UK, the Information Commissioner’s Office (ICO).
9. Operators’ responsibilities
Operators that install the SDK are independent controllers of their visitors’ data and are responsible for:
- providing a clear privacy notice to their visitors that discloses the use of Convertfy as a third-party provider and the categories of data described in Section 4 (a suggested clause is provided on the Sub-processors page);
- establishing a lawful basis and obtaining any consent required in their jurisdiction before the SDK processes visitor data; and
- entering into our DPA.
10. Security
We protect data in transit with HTTPS/TLS and enforce HTTPS (HSTS). Access to operator data in the dashboard is scoped to each organisation. We apply access controls, least-privilege practices and security headers across the application. No method of transmission or storage is completely secure, but we work to protect personal data using appropriate technical and organisational measures.
11. Children
The service is intended for operators in age-restricted industries and is not directed to children. We do not knowingly process the personal data of children.
12. Changes to this policy
We may update this policy from time to time. Material changes will be notified to operators through the service or by email, and the version number and effective date above will be updated.
13. Contact
Convertfy S.L. Urb. La Giralda 8, 11300 La Línea de la Concepción (Cádiz), Spain Email: privacy@convertfy.io