Skip to content
Legal

Privacy Policy

Version 1 · Effective 7 July 2026

Data controller: Convertfy S.L., Urb. La Giralda 8, 11300 La Línea de la Concepción (Cádiz), Spain Contact: privacy@convertfy.io (data protection enquiries)

1. Who we are and how to read this policy

Convertfy provides a conversion-recovery service for online gaming, sweepstakes and casino operators (“operators”). Our service has two parts: a back-office dashboard that operators sign in to, and an embeddable script (the “SDK”) that operators install on their own websites.

We process personal data in two distinct roles, and your rights and our obligations differ depending on which applies:

  • As a data controller, for the personal data of the operator staff who create and use Convertfy accounts. We decide why and how that data is processed. Section 3 covers this.
  • As a data processor, for the data the SDK collects from visitors on an operator’s website. The operator is the controller of that data and decides the purposes; we process it on their documented instructions under a Data Processing Agreement (DPA). Section 4 covers this.

If you are a website visitor and have questions about data collected on an operator’s site, the operator is your primary point of contact as the controller. We will assist them in responding to your request (see Section 8).

2. Summary of our privacy posture

We have deliberately built the SDK to minimise data:

  • No cookies and no persistent visitor identifiers. The SDK sets no cookies and writes nothing durable to a visitor’s device. A frequency cap uses only sessionStorage, which the browser clears at the end of the session.
  • No cross-site tracking and no profiles. We do not build advertising profiles and do not sell personal data.
  • Coarse, not precise. Location is derived to country / region / city level from the connection’s IP address; we do not use GPS or store the IP address itself.
  • Aggregation where possible. Heatmap and content-experiment data is aggregated at the point of collection and holds no per-person record.

This summary is provided for clarity and does not replace the detail below.

3. Operator account data (Convertfy as controller)

When a member of an operator’s team creates or uses a Convertfy account, we process:

Data Examples Source
Identity & contact Name, email address, profile image Provided via our authentication provider
Organisation Organisation name, role/membership Provided on sign-up
Account & usage Sign-in events, settings, content you create (campaigns, experiments, trackers) Generated by your use
Technical IP address, browser/device data, log data Collected automatically

Purposes and legal bases (EU GDPR Art. 6 / UK GDPR):

  • To provide and secure the service, and authenticate sign-in: performance of a contract.
  • To operate, maintain, troubleshoot and improve the service, and to keep it secure against abuse: legitimate interests.
  • To comply with legal, tax and regulatory obligations: legal obligation.
  • To send service and, where permitted, product communications: legitimate interests or consent where required.

Authentication and identity management are handled by Clerk (see Sub-processors).

Retention: account data is kept for the life of the account and for up to 24 months after closure, unless a longer period is required by law.

4. Visitor data collected by the SDK (Convertfy as processor)

The following is collected on operator websites on behalf of, and on the instructions of, the operator, who is the controller. We process it under our DPA. Operators are responsible for providing notice to, and obtaining any required consent from, their visitors (see Section 9).

4.1 Campaign interaction events

When the SDK shows an overlay and a visitor interacts with it, we record an event (impression, click, dismiss, or game completion) with:

  • the event type, and the campaign and operator it relates to;
  • device type (desktop/mobile), browser and operating system (derived from the User-Agent string);
  • coarse geolocation (country, and where available region and city) derived from the IP address by our hosting provider’s edge network. The IP address itself is not stored, only the derived location;
  • page URL and referrer of the page where the event occurred, and the browser language.

Each event is a single record. It contains no cookie, no persistent identifier, and nothing that singles out an individual visitor across sessions or sites.

4.2 Conversion data

If the operator uses our conversion tracking, their server (or, where enabled, their website) reports registrations and deposits attributed to a Convertfy campaign. This includes:

  • the operator’s own identifier for the user (an opaque/pseudonymous id chosen by the operator; operators may hash it before sending);
  • for deposits, the amount and currency and a transaction reference;
  • the attributed campaign and, where an operator runs a control group or a content experiment, a group or variant label derived from a session value.

This is the most sensitive category we handle. We treat the user identifier as opaque and do not attempt to resolve it to a named individual.

4.3 Content experiments (A/B tests)

Where an operator runs an A/B test on a page, the SDK shows each visitor one version of the tested content, chosen from a random session-scoped value, and records aggregate counters only: how many times each version was shown and how many times the tested elements were clicked, per day and device type. These counters carry no visitor identifier and no per-person record.

4.4 Heatmap data

Where an operator enables heatmaps for a specific page, the SDK collects, in aggregate form:

  • counts of clicks per on-page element and the click position within that element;
  • how far down the page visitors scrolled (in bands);
  • where enabled by the operator, value-free form-interaction statistics (which field a visitor stopped at), never the contents of any field; password fields and fields marked to be ignored are skipped entirely.

Optionally, an operator may capture a structural snapshot of a page’s layout (via a dashboard tool) so heatmaps can be drawn over a copy of the page. Form input values are masked out of these snapshots and are never stored.

Heatmap data carries no visitor identifier and is stored as counters, not as a per-person trail.

4.5 Retention of visitor data

Visitor data is retained per the operator’s documented instructions and our DPA, for no longer than 14 months unless the operator instructs otherwise or the law requires.

5. Cookies and similar technologies

The SDK does not set cookies. It uses browser sessionStorage for strictly functional purposes only: capping how often an overlay is shown in a session, and a random, session-scoped value used to keep the visitor’s experience consistent within that session (for control groups and content experiments). These values are cleared when the browser session ends and are not shared across sites.

The back-office dashboard uses cookies that are strictly necessary for sign-in and security (set by our authentication provider).

6. Who we share data with (sub-processors)

We use a small number of vetted infrastructure providers (“sub-processors”) to run the service. Each is bound by a contract with data-protection and security obligations. The current list, with each provider’s role and location, is maintained at /subprocessors.

We do not sell personal data and do not share it for third-party advertising.

7. International data transfers

Convertfy is established in Spain. Several of our infrastructure sub-processors are located in the United States. Where personal data is transferred out of the EEA / UK, we rely on appropriate safeguards: the EU Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum, and/or the sub-processor’s certification under the EU-U.S. Data Privacy Framework, together with supplementary measures where needed. Details are in the DPA and the Sub-processors list.

8. Your rights

Depending on your location, you may have rights to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to withdraw consent. California residents have rights under the CCPA/CPRA, including to know, delete, correct, and opt out of “sale”/“sharing” (we do neither).

  • Operator account data: contact us at privacy@convertfy.io.
  • Visitor data collected on an operator’s site: the operator is the controller; please contact them. If you contact us, we will refer you to the operator and assist them in responding without undue delay.

You also have the right to lodge a complaint with a supervisory authority. In Spain this is the Agencia Española de Protección de Datos (AEPD, www.aepd.es); in the UK, the Information Commissioner’s Office (ICO).

9. Operators’ responsibilities

Operators that install the SDK are independent controllers of their visitors’ data and are responsible for:

  • providing a clear privacy notice to their visitors that discloses the use of Convertfy as a third-party provider and the categories of data described in Section 4 (a suggested clause is provided on the Sub-processors page);
  • establishing a lawful basis and obtaining any consent required in their jurisdiction before the SDK processes visitor data; and
  • entering into our DPA.

10. Security

We protect data in transit with HTTPS/TLS and enforce HTTPS (HSTS). Access to operator data in the dashboard is scoped to each organisation. We apply access controls, least-privilege practices and security headers across the application. No method of transmission or storage is completely secure, but we work to protect personal data using appropriate technical and organisational measures.

11. Children

The service is intended for operators in age-restricted industries and is not directed to children. We do not knowingly process the personal data of children.

12. Changes to this policy

We may update this policy from time to time. Material changes will be notified to operators through the service or by email, and the version number and effective date above will be updated.

13. Contact

Convertfy S.L. Urb. La Giralda 8, 11300 La Línea de la Concepción (Cádiz), Spain Email: privacy@convertfy.io