Privacy Policy
ConvertLens ("we", "our") is a Shopify-embedded app that audits merchant product pages for conversion-rate signals. This policy explains what data we collect, how we use it, and the choices you have.
Who we are
ConvertLens is operated by Abdul Wahhab, registered at 28 Mill Fold Gardens, Chadderton, Oldham, OL9 9FY. Contact: privacy@convertlens.app.
Data we collect from the merchant store
- Product metadata via the Shopify Admin API: product titles, descriptions, images, prices, vendor, product type, variants, status. No customer data, order data, or PII is ingested.
- Storefront page screenshots (mobile viewport, 375×812) captured via our rendering provider (ScrapingBee) and stored in Cloudflare R2.
- Audit results: scores, lens-level sub-checks, and recommendations generated from the above. Stored in our Supabase Postgres database (US-East).
- Billing events from the Shopify Billing API (subscription start/cancel/charge timestamps and amounts).
- Customer Persona (paid plans only): a written description of your ideal customer across four fields, industry / category, customer description, problem-desire-goal, and considered alternatives. The persona is generated from your own product catalogue using an AI draft you review and edit; you can also enter it manually. We retain every saved version so you can trace which persona was active at the time of any past audit. The persona contains your description of your buyer, not data about a specific real person.
Shared-link views
When a public shared-audit link (/r/{slug}) is viewed, we log the view with:
- The IP address SHA-256-hashed (first 16 hex characters). Wenever store raw IP addresses.
- The User-Agent string (truncated to 256 chars).
- The HTTP Referer header, if any (truncated to 512 chars).
- Timestamp.
These records support the view-counts and referrer breakdowns available to Growth and Pro plans.
Third-party processing
Audit content is sent to Google Gemini (model: gemini-2.5-flash) for analysis. Specifically, on each audit we transmit the rubric, the merchant's product data (title, description, prices, variants, no PII), the rendered mobile (and on Growth+ plans, desktop) screenshot, and, on paid plans where a Customer Persona has been set up, the four-field persona description so recommendations can be framed around the merchant's ideal buyer.
Persona generation itself uses the same Gemini model. We send a truncated sample of your product catalogue (titles, descriptions, product types) so the model can draft persona suggestions you then review and edit before saving. We do not send Shopify customer records, orders, or any shopper PII during persona generation.
Per Google's API terms for paid/Vertex usage, this data is not used to train Google models. We rely on this configuration; if Google changes those terms, this policy will be updated.
We additionally use Cloudflare R2 for screenshot storage, ScrapingBee for storefront rendering, Supabase for our Postgres database, and Render for hosting. All vendors are bound by their respective DPAs.
Where data lives
Supabase Postgres database: US-East (Virginia). Cloudflare R2 bucket for screenshots. Render hosting: US-East (Virginia). Gemini API: Google Cloud.
Retention
- Store data (products, audits, recommendations, screenshots) is retained for as long as the app is installed plus 30 days post-uninstall, after which Shopify's
shop/redactwebhook triggers full deletion. - Shared-link view records are pruned at 90 days (Free / Starter) or 12 months (Growth / Pro).
- Billing events are retained per accounting requirements (currently 7 years, configurable).
Your rights
- Access & export: Settings → "Download my data" produces a JSON export of everything we hold on your store.
- Erasure: Settings → "Delete account" immediately deletes your data, ahead of Shopify's 30-day window. You can also rely on Shopify's mandatory
shop/redactwebhook by uninstalling the app. - Data Processing Agreement: available on request at privacy@convertlens.app.
Shared-link privacy guarantees
A public shared-link page reveals only the audit's scores, screenshot, and recommendations. It does not reveal: your shop domain, internal product or store IDs, billing information, other audits, or any data unrelated to that single audit. Shared pages set noindex, nofollow.
Changes
We will post material changes to this policy here and update the effective date. Continued use after a change constitutes acceptance.