This policy explains what personal data ECOM FR LLC processes when you visit convrail.com or use Convrail, why, with whom it is shared, and your rights. We wrote it to be read, not skimmed: the short version is that customer emails and phone numbers are hashed before we store or send anything, this website sets no cookies of its own, and you can reach us at privacy@convrail.com.
1. Who is responsible
For data about you as a merchant or visitor of this website, ECOM FR LLC is the controller. For data about your store's customers that we process to provide the Service, you (the merchant) are the controller and we act as your processor, on your instructions and under the terms of service. A data processing agreement is available on request.
2. Data about you (merchant, website visitor)
| Data | Why | Retention |
|---|---|---|
| Store domain, platform, currency, account email | Operate the Service, reach you about alerts and changes | While the store is connected; deleted on uninstall or request |
| Platform access token, OpenAI pixel ID and API tokens, SFTP credentials | Act on your behalf toward Shopify, WooCommerce and OpenAI | Encrypted with AES-256-GCM; deleted on uninstall or request |
| Contact form: name, email, store URL, platform, message | Answer your request | Deleted on request once the exchange is closed |
| Early-access form: email, language, page of origin | Send you the install link | Deleted on request or once early access ends |
| Hashed IP address on form submissions | Abuse prevention | Same as the form entry |
This website uses no analytics, no advertising tags and sets no cookies of its own. Fonts are loaded from Google Fonts, which receives your IP address to serve the files; see Google’s privacy policy for that processing.
3. Data about your customers (processed for you)
| Data | Origin | Notes |
|---|---|---|
Conversion events: type, timestamp, page URL, oppref click identifier, IP address, user agent | Browser pixel and order webhooks | IP and user agent are sent to OpenAI for matching, as their API expects |
| SHA-256 hashes of customer email and customer ID | Order webhooks | The clear values are hashed on receipt and never stored |
| Orders: ID, amount, currency, line items, landing URL, referrer | Order webhooks | Used for attribution and the dashboard |
| Consent state | Pixel | Declined visitors are recorded as skipped and never sent |
An automated guard inspects every payload before it leaves our infrastructure and refuses to send anything containing an email address, a phone number or a forbidden personal-data key. Platform deletion webhooks (customer redaction, store redaction) are honored: we purge the matching events by hashed identifier, or the whole store.
4. Product data
Your catalog (titles, descriptions, prices, images, availability, identifiers) is synced to build the product feed and, if you use the optimization features, to compute scores and drafts. Product data is not personal data in itself; it is deleted with the store.
5. Recipients and sub-processors
| Recipient | Role | Location |
|---|---|---|
| Infomaniak Network SA | Hosting of the platform and database | Switzerland |
| OpenAI | Receives conversion events (hashed identifiers, IP, user agent) and the product feed, on your instruction and under your OpenAI account | United States |
| Anthropic | Only if AI rewriting is enabled: receives product title, description, brand and category to draft copy. No customer data | United States |
| Email delivery provider (SMTP) | Sends alerts, reports and contact notifications | Depends on the configured provider |
We do not sell personal data and do not share it with advertisers. Transfers outside the European Economic Area rely on the recipient’s data processing terms and standard contractual clauses where required; hosting in Switzerland benefits from an EU adequacy decision.
7. Security
- Secrets (access tokens, API tokens, SFTP credentials) are encrypted at rest with AES-256-GCM.
- All traffic uses TLS. Webhooks are verified by HMAC signature before processing.
- Personal identifiers are hashed on receipt; an automated guard blocks clear personal data before any network call.
- Access to production systems is limited to the people who operate the Service.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal data, to object to or restrict its processing, and to lodge a complaint with a supervisory authority. Write to privacy@convrail.com; we answer within 30 days. If you are a customer of a store that uses Convrail, please contact the store first: it is the controller of your data and we act on its instructions.
9. Children
The Service and this website are intended for businesses and are not directed to children under 16.
10. Changes and contact
We update this policy when our processing changes; the date at the top is the current version. Contact: privacy@convrail.com. Postal address: ECOM FR LLC, 28 Geary St Ste 650, San Francisco, CA 94108-5700, United States.