Privacy Policy
This policy explains what personal data DearConvert handles, why, who we share it with, and what you can ask us to do about it. We have tried to write it in plain language rather than legal fog.
- Two different roles, and why it matters
- What we collect as a controller
- Lead data we handle for our customers
- Why we use it, and our lawful bases
- Who we share it with
- Cookies and similar technologies
- International transfers
- How long we keep things
- Your rights and how to use them
- If you filled in a form on someone's page
- Security
- Children
- Changes to this policy
- Who we are and how to reach us
1. Two different roles, and why it matters
DearConvert handles personal data in two quite different situations, and the rules are different for each.
As a controller. When you sign up, pay us, email support, or read this website, we decide how that data is used. That part of the relationship is governed by this policy.
As a processor. When a visitor fills in a form on a page built with DearConvert, that lead belongs to our customer. They decide what it is for, who it goes to, and how long it lives. We only handle it on their instructions. If you are a customer, the terms covering that relationship are in our Data Processing Agreement, not this policy.
For agencies the chain has one more link: the agency is usually a processor for its own client, and we act underneath them. Our Data Processing Agreement is written to work that way.
2. What we collect as a controller
Account and profile
Your name, email address, and a securely hashed password. If you sign in with Google we receive your Google account identifier, email, name and profile picture URL. We store the organizations and workspaces you belong to and your role in each.
Content you create
The sites, pages, forms, popups and templates you build, every saved revision of them, and files you upload such as images.
Billing
Subscription plan, billing cycle, status, renewal dates, and the identifiers our payment provider gives us. We never see or store your card number. Payment details are handled entirely by PayPal.
Support and email
Messages you send us and the transactional emails we send you, such as password resets, lead notifications and usage warnings.
Technical and diagnostic
Server logs, and error reports where our error tracking is enabled. These can include IP addresses and browser details.
This website
The marketing site you are reading runs no third-party analytics or advertising trackers at all. Nothing here is profiling you.
3. Lead data we handle for our customers
When someone submits a form on a page published through DearConvert, we store, on our customer's behalf:
- Whatever the form asked for. Our customers design their own forms, so this commonly includes a name, email address and phone number, and can include anything else they choose to ask.
- A hashed IP address. We apply a one-way hash rather than storing the raw address. To be clear and not oversell it: hashed data is still personal data under data protection law, because re-identification can be possible. We hash to reduce risk, not to escape the rules.
- Technical context: browser user agent, the referring URL, and any campaign parameters such as
utm_source. - Which version of the page they saw, when the customer is running an A/B test.
We also record anonymous page activity for our customers' analytics: page views, form starts, form completions and clicks on calls to action, with hashed IPs and campaign parameters.
Customers can connect a form to their own tools, and can enable Meta's Conversions API so that conversion events are sent to Meta from our servers. When a customer turns those on, they are instructing us to send data onward, and they are responsible for having a lawful basis and giving visitors proper notice. We explain the practicalities to customers in our documentation.
4. Why we use it, and our lawful bases
| What we do | Why | Lawful basis (where GDPR applies) |
|---|---|---|
| Run your account, publish your pages, deliver your leads | To provide the service you signed up for | Performance of a contract |
| Take payment and prevent billing fraud | To get paid and keep the service running | Contract, and legitimate interests |
| Send service email such as password resets and usage warnings | So the service works and you are not surprised | Contract |
| Keep the platform secure, block spam and abuse | To protect you, us, and people who visit published pages | Legitimate interests |
| Fix bugs and improve the product | To make DearConvert work better | Legitimate interests |
| Send marketing email, if you asked for it | To tell you about the product | Consent, withdrawable at any time |
| Meet legal, tax and accounting obligations | Because we have to | Legal obligation |
We do not sell personal data, and we do not share it for cross-context behavioural advertising. We also do not use the lead data our customers collect to train models or to build our own marketing lists.
5. Who we share it with
We use a small number of service providers to run DearConvert. These are our sub-processors, and the current list, with what each one does, is published at dearconvert.com/subprocessors. In summary they cover hosting and content delivery, file storage, transactional email, payments and error tracking.
Tools you connect yourself are different. When you connect Mailchimp, Kit, Google Sheets, Slack, Loops, Zapier or your own webhook, or enable Meta's Conversions API, you are telling us to send data to a service you control under your agreement with them. Those are not our sub-processors, and what they do with the data is governed by their terms and your relationship with them.
We may also disclose data where the law requires it, to protect our rights or someone's safety, or to a buyer if the business is ever sold, in which case we would tell you first.
6. Cookies and similar technologies
Full detail is in our Cookie Policy. The short version:
- This marketing site sets no analytics or advertising cookies.
- The app uses strictly necessary cookies to keep you logged in and to protect forms against cross-site request forgery.
- Pages published by our customers may set two small first-party cookies: one to keep a visitor on the same version during an A/B test, and one to remember that a password-protected page was unlocked. Both are functional. Neither is used for advertising or tracking across sites.
- Spam protection uses a hidden honeypot field and, where the customer enables it, Cloudflare Turnstile.
7. International transfers
Our providers operate in several countries, so personal data may be processed outside the country where it was collected, including in the United States. Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses together with the UK Addendum, and we assess whether additional safeguards are needed. Customers can request our current transfer documentation at the contact address below.
8. How long we keep things
Being straight with you about where we are today:
- Account and content are kept while your account is open.
- Leads are kept until you delete them or ask us to delete them. Customers control their own lead data and can export it as CSV at any time.
- Billing records are kept as long as tax and accounting rules require.
- Backups roll off on their own schedule, so deleted data can persist in backups for a short period after deletion.
We do not yet run automatic time-based deletion of old leads or analytics events. Configurable retention is something we are building, and until it exists, deletion happens when you ask for it or when you delete the data yourself. We would rather tell you that than imply a schedule we do not have.
9. Your rights and how to use them
Depending on where you live, you may have the right to access your data, correct it, delete it, get a portable copy, object to or restrict certain processing, withdraw consent, and not be discriminated against for exercising any of it. Several jurisdictions also give you a right to appeal if we say no.
To exercise any of these, use our data request page or email team@dearconvert.com. We will respond within one month where GDPR applies and within 45 days where US state privacy laws apply, and we will tell you if we need longer. We may need to verify who you are first.
If you are in the EEA or the UK, you can also complain to your local data protection authority. We would appreciate the chance to sort it out first.
Account deletion. There is no self-serve delete button in the app yet. Email us and we will delete your account and its data, and confirm when it is done. Self-serve deletion is on our roadmap.
10. If you filled in a form on someone's page
If you submitted your details on a page built with DearConvert and you want that data corrected or deleted, the business whose page you filled in is the one in charge of it, not us. Contact them first. If you cannot reach them or you do not know who they are, send us the page address through our data request page. We will pass the request to the customer responsible, and where we are permitted to act ourselves, we will.
11. Security
We use encryption in transit, hashed passwords, hashed visitor IPs, signed internal requests between our own services, role-based access inside organizations and workspaces, and spam and bot protection on forms. Our current technical and organizational measures are described on our security page.
We do not hold a SOC 2 report or ISO 27001 certification, and we will not imply otherwise. If your procurement process needs one, tell us and we will be honest about where we are.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and any relevant authority as required by law, and where you are a customer we will notify you without undue delay so that you can meet your own obligations.
12. Children
DearConvert is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. Our Acceptable Use Policy prohibits our customers from using DearConvert forms to collect data from children. If you believe a child's data has reached us, tell us and we will delete it.
13. Changes to this policy
When we change anything material we will update the date at the top and, for significant changes, tell customers by email. Older versions are available on request.
14. Who we are and how to reach us
DearConvert is operated by Shiva Guru Balaji S, an independent software developer operating as a sole proprietor in India, from 43b/1 Poosari Thottam, Soolai, Erode 638004, Tamil Nadu, India. There is no company registration or tax registration number, because DearConvert is run by an individual rather than a company.
- Privacy and data requests: team@dearconvert.com
- General support: team@dearconvert.com
- Abuse and illegal content: see report abuse