Privacy Policy
Last updated: May 26, 2025
1. Introduction
True Conversions ("we," "our," or "the Service") is a server-side conversion tracking middleware operated for marketing agencies and their clients. This Privacy Policy describes how we collect, use, store, and protect information when you use our platform.
2. Information We Collect
We collect the following categories of information:
- Account Information: When you register, we collect your name, email address, and agency name to create and manage your account.
- Conversion Event Data: We receive conversion event data via webhooks from your CRM systems (e.g., RD Station, ActiveCampaign, Pipedrive). This data may include email addresses, phone numbers, names, transaction values, and advertising click identifiers (gclid, fbclid).
- Usage Data: We collect standard log data such as IP addresses, browser type, and pages visited to maintain and improve the Service.
3. How We Use Information
- To provide and operate the conversion tracking and routing services.
- To normalize and hash personally identifiable information (PII) before transmitting it to advertising platforms (Google Ads, Meta).
- To display analytics and match rate reporting within your dashboard.
- To communicate with you about your account, billing, and service updates.
4. Data Processing & Security
All personally identifiable information (emails, phone numbers, names) is hashed using SHA-256 before being transmitted to any third-party advertising platform. Raw PII is stored temporarily for processing purposes and is accessible only to the agency account that owns the data. Credentials and tokens for third-party platforms are encrypted at rest using AES-256 encryption.
5. Third-Party Services
We integrate with the following third-party services as directed by you:
- Google Ads — for Enhanced Conversion uploads.
- Meta (Facebook) — for Conversions API event delivery.
- Stripe — for payment processing and billing.
- Supabase — for authentication and data storage.
Data is shared with these platforms only when you explicitly configure an integration and connect your advertising account.
6. Data Retention
Conversion event data is retained for the duration of your active subscription. Upon account deletion or subscription cancellation, your data will be permanently deleted within 30 days. You may request earlier deletion by contacting us.
7. Your Rights
You have the right to access, correct, or delete your personal data at any time through your account settings or by contacting us. If you are located in the European Economic Area or Brazil, you have additional rights under the GDPR or LGPD, respectively, including the right to data portability and the right to withdraw consent.
8. Contact
For questions or concerns about this Privacy Policy, please contact us at privacy@trueconversions.com.