1 Information We Collect
We collect two primary categories of data: Merchant Account Data (from you, our user) and Website Visitor Data (from your store's visitors, processed on your behalf).
A. Merchant Account Data
When you register, subscribe, or use our Service, we may collect:
- Identity & Contact Data: Name, email address, company name, and billing address.
- Account & Technical Data: Passwords (hashed), API keys, integration tokens (e.g., Shopify, Klaviyo), and IP addresses used to access the GenConvert dashboard.
- Billing Data: Payment information is processed securely by our third-party payment processors (e.g., Paddle, Polar). We do not store full credit card numbers on our servers.
B. Website Visitor Data (Processed on Your Behalf)
To provide AI-powered popup generation, behavioral targeting, and analytics, our embed script collects specific technical and behavioral data from your website visitors. This includes:
- Technical & Device Data: Browser type (via User-Agent), device type (Mobile, Tablet, or Desktop based on screen width), and approximate country (via browser language).
- Behavioral & Interaction Data: Scroll depth, time on page, exit intent signals (detected via mouse movements or touch gestures), pages viewed during a session, and popup interactions (views, clicks, dismissals, conversions).
- E-commerce & Contextual Data: Shopping cart status and total value (read directly from Shopify cart objects or your store's DOM), product metadata and pricing (extracted from page schema), referrer URL, and UTM parameters.
- Identifiers & Local Storage: We use Local Storage and Session Storage (functioning similarly to cookies) to generate anonymous visitor IDs, track session history, remember user preferences, and prevent popup fatigue.
Note: Under GDPR and the ePrivacy Directive, you (the merchant) are the Data Controller of this visitor data, and GenConvert acts strictly as the Data Processor.
2 How We Use Your Information
We use the collected data for the following purposes:
- Behavioral Segmentation & AI Triggering: We analyze visitor behavior to dynamically categorize them into segments (e.g., "first-time visitor," "high-value customer," "cart abandoner"). This allows our AI to trigger the most effective popup at the exact right moment.
- Service Delivery: To generate, cache, and display personalized popups, and to integrate with your e-commerce and email marketing platforms.
- Billing & Usage Tracking: To accurately track pageviews and form submissions. Our ClickHouse analytics database acts as the immutable source of truth for calculating your monthly plan usage and billing.
- AI Model Guardrails: To ensure our Large Language Models (LLMs) generate copy strictly based on your configured brand tone and approved offers, without hallucinating unauthorized discounts.
- Communication: To send you service updates, usage warnings (e.g., at 75% of your plan limit), and technical support responses.
3 Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), we process personal data based on the following legal grounds:
- Contractual Necessity: Processing is necessary to fulfill our Terms of Service and provide the features you requested.
- Legitimate Interests: To improve our Service, ensure security, and prevent fraud, provided these interests are not overridden by your data protection rights.
- Consent: For the placement of Local Storage, Session Storage, and cookies on your website visitors' devices. You (the merchant) are responsible for obtaining this consent via your own cookie consent banner before our script activates.
4 Data Sharing and Third-Party Subprocessors
We do not sell, trade, or rent your personal data or your visitors' data to third parties. We only share data with trusted subprocessors who assist us in operating the Service, all of whom are bound by strict Data Processing Agreements (DPAs).
Our current subprocessors include:
Hosting & Infrastructure
AWS, Vercel
Database & Caching
MongoDB, Upstash/Redis, ClickHouse
AI Processing
OpenAI (no model training on your data)
Payments
Paddle, Polar
5 International Data Transfers
GenConvert is headquartered in Finland. However, some of our subprocessors (e.g., AWS, OpenAI) may process data in countries outside the EEA, such as the United States. When we transfer data internationally, we ensure it is protected by relying on the European Commission's Standard Contractual Clauses (SCCs) or by verifying that the destination country has an adequacy decision.
6 Data Retention
We retain your data only as long as necessary to fulfill the purposes outlined in this policy:
- Active Accounts: Merchant account data and visitor analytics are retained as long as your account is active.
- Cancelled Accounts: Upon cancellation, your campaign configurations and historical analytics data are retained for 30 days to allow for data export or account reactivation. After 30 days, this data is permanently and securely deleted from our systems.
- Visitor Local Storage: Data stored in the visitor's Local Storage (e.g., popup history, visitor ID) is automatically cleared when the visitor clears their browser cache, or via our script if they revoke consent.
7 Security Measures
We implement robust technical and organizational measures to protect your data, aligned with our 3-tier architecture:
- Encryption: All data in transit is encrypted via HTTPS/TLS.
- Access Controls: Strict role-based access controls ensure only authorized GenConvert personnel can access systems.
- Architecture Security: We use distributed Redis locks to prevent concurrent processing errors, and ClickHouse's immutable ledger ensures billing and event data cannot be tampered with.
8 Your Data Protection Rights (GDPR)
If you are a resident of the EEA, you have the following rights regarding your personal data:
Right to Access
Right to Rectification
Right to Erasure
Right to Restriction
Right to Data Portability
Right to Object
To exercise any of these rights, please contact us at support@genconvert.com. We will respond to your request within 30 days.
10 Children's Privacy
Our Service is a B2B platform directed exclusively at businesses and professionals. We do not knowingly collect personal data from children under the age of 16.
11 Updates to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, or legal requirements. We will notify you of any material changes via the email address associated with your GenConvert account.
12 Governing Law and Contact Information
This Privacy Policy is governed by the laws of Finland. Any disputes arising from this policy will be resolved exclusively in the competent courts of Finland.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Data Protection team at:
📧 Contact our Data Protection team
support@genconvert.com