Privacy Policy
Last updated July 2026
This Privacy Policy explains how ConversionLens (“ConversionLens”, “we”, “us”) collects, uses, shares, and protects information when you use our website and application (the “Service”). By using the Service you agree to this Policy.
Review needed: Confirm the legal entity name, registered address, and the data-protection contact (and EU/UK representative, if required) before launch.Information we collect
We collect the following categories of information:
- Account information. When you sign in, our authentication provider collects your email address and basic profile details.
- Audit inputs. The store URLs you submit and the figures you provide (such as average order value and monthly sessions) used to produce estimates.
- Audit data. Publicly accessible pages we crawl on the stores you audit, including screenshots and technical measurements, and the findings we generate.
- Connected-store data. If you connect a first-party integration (for example a commerce platform), we access the data you authorize to produce measured insights.
- Usage information. Standard log and device data, and product-usage events used to operate and improve the Service.
How we use information
- To provide, maintain, and improve the Service and generate your reports.
- To authenticate you, secure your account, and prevent abuse.
- To communicate with you about the Service, including service and security notices.
- To comply with legal obligations and enforce our terms.
Legal bases for processing
Where applicable law (such as the GDPR) requires it, we process personal data on the bases of performance of a contract, our legitimate interests in operating the Service, your consent, and compliance with legal obligations.
Review needed: Confirm the legal bases and lawful-processing summary with counsel for your operating jurisdictions.How we share information
We do not sell your personal information. We share information with service providers (subprocessors) who process it on our behalf under contract, and when required by law or to protect rights and safety. Our subprocessors include providers for authentication, application hosting, database storage, file/object storage, AI analysis, and payment processing.
Review needed: Publish and maintain the definitive list of subprocessors (name, purpose, location) and keep it current; confirm each has a data-processing agreement in place.Data retention
We retain information for as long as your account is active or as needed to provide the Service, then delete or anonymize it, subject to legal, accounting, or reporting requirements.
Review needed: Confirm concrete retention periods per data category.Security
We use administrative, technical, and organizational measures designed to protect information, including encryption in transit and access controls. No method of transmission or storage is completely secure.
International transfers
Your information may be processed in countries other than where you live. Where required, we rely on appropriate safeguards for such transfers.
Review needed: Confirm transfer mechanisms (e.g. Standard Contractual Clauses).Your rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal data, and to object to or restrict certain processing. To exercise these rights, contact us using the details on our Contact page.
Cookies
We use cookies and similar technologies that are necessary to run the Service (for example, to keep you signed in) and to understand product usage.
Review needed: Add a cookie table and, if you serve the EU/UK, a consent mechanism for non-essential cookies.Children
The Service is not directed to children and is intended for business use.
Changes to this Policy
We may update this Policy from time to time. Material changes will be posted here with an updated “Last updated” date.
Contact
Questions about this Policy? Reach us via our Contact page.