Effective 5 October 2026
Privacy Policy
What Convwatch collects, why, and what it deliberately never collects.
Who is responsible
Convwatch is operated by Viktor Shataev, an individual entrepreneur registered in Georgia, who is the controller for the personal data described here. Contact: hello@convwatch.com.
Convwatch is built to keep personal data to a minimum. The monitoring data that customers' systems send us is technical metadata, not data about people.
What we collect and why
| Data | Why | Legal basis | Kept for |
|---|---|---|---|
| Waitlist: email, and optionally company, role, ad platforms and a note you write | To invite you and ask about your setup | Consent (you submit the form) | Until you ask us to delete it, or 24 months |
| Waitlist abuse protection: a one-way hash of your IP address with a salt that changes daily, and your browser's user-agent | To stop spam and repeated submissions | Legitimate interest | As long as the waitlist entry |
| Account: name, work email, company, Slack webhook address you configure | To run your account and send your alerts | Contract | While the account is open, then up to 30 days |
| Monitoring metadata from the SDK: platform, account and conversion action IDs, event counts, error codes, request IDs, timings | To provide the service | Contract | Up to 90 days, depending on plan |
| Billing: handled by Paddle (see below). We receive your name, email, country, plan and payment status, not your card details | To manage your subscription | Contract; legal obligation for records | As long as tax law requires |
| Messages you send us | To reply | Legitimate interest | Up to 24 months |
What we do not collect
We do not collect the personal data inside your conversion uploads: no click identifiers, emails, phone numbers, names, addresses or IP addresses of your users. The SDK does not send them, and the service rejects any report that appears to contain them. We do not ask for or store your advertising-platform credentials.
Cookies and tracking
convwatch.com sets no cookies and runs no analytics or advertising trackers. Pages load fonts from Google Fonts, so your browser sends your IP address to Google when you open them.
Who we share data with
- DigitalOcean hosts the service on servers in Singapore.
- Paddle (Paddle.com Market Ltd) is our reseller and Merchant of Record. When you buy a plan, Paddle collects and processes your payment and billing data as an independent controller under its own privacy notice.
- Slack receives the alert messages you ask us to send to your workspace.
- Google serves the web fonts used on our pages.
We do not sell personal data and do not share it for advertising. We may disclose data if the law requires it.
International transfers
Our servers are in Singapore. If you are in the UK, the EU or another country with transfer rules, your data is transferred outside it. We rely on the safeguards our providers offer for such transfers, such as standard contractual clauses.
Your rights
You can ask us to access, correct, delete or export your personal data, to restrict or object to its use, and to withdraw consent at any time (for example, to leave the waitlist). Write to hello@convwatch.com; we answer within 30 days. You can also complain to your data protection authority, for example the ICO in the UK or the supervisory authority in your EU country.
Security
Data is sent over HTTPS. API keys are stored only as hashes. Access to the servers is limited to the operator. No system is perfectly secure; if a breach affects your personal data, we will tell you and the relevant authority as the law requires.
Children
Convwatch is a business tool and is not meant for anyone under 18.
Changes
We will post any change here with a new effective date, and email account holders about significant changes.