Privacy policy

Updated September 6, 2026

This policy explains what personal data ECOM FR LLC processes when you visit convrail.com or use Convrail, why, with whom it is shared, and your rights. We wrote it to be read, not skimmed: the short version is that customer emails and phone numbers are hashed before we store or send anything, this website sets no cookies of its own, and you can reach us at [email protected].

1. Who is responsible

For data about you as a merchant or visitor of this website, ECOM FR LLC is the controller. For data about your store's customers that we process to provide the Service, you (the merchant) are the controller and we act as your processor, on your instructions and under the terms of service. A data processing agreement is available on request.

2. Data about you (merchant, website visitor)

DataWhyRetention
Store domain, platform, currency, account emailOperate the Service, reach you about alerts and changesWhile the store is connected; deleted on uninstall or request
Platform access token, OpenAI pixel ID and API tokens, SFTP credentialsAct on your behalf toward Shopify, WooCommerce and OpenAIEncrypted with AES-256-GCM; deleted on uninstall or request
Contact form: name, email, store URL, platform, messageAnswer your requestDeleted on request once the exchange is closed
Early-access form: email, language, page of originSend you the install linkDeleted on request or once early access ends
Hashed IP address on form submissionsAbuse preventionSame as the form entry

This website uses no analytics, no advertising tags and sets no cookies of its own. Fonts are loaded from Google Fonts, which receives your IP address to serve the files; see Google’s privacy policy for that processing.

3. Data about your customers (processed for you)

DataOriginNotes
Conversion events: type, timestamp, page URL, oppref click identifier, IP address, user agentBrowser pixel and order webhooksIP and user agent are sent to OpenAI for matching, as their API expects
SHA-256 hashes of customer email and customer IDOrder webhooksThe clear values are hashed on receipt and never stored
Orders: ID, amount, currency, line items, landing URL, referrerOrder webhooksUsed for attribution and the dashboard
Consent statePixelDeclined visitors are recorded as skipped and never sent

An automated guard inspects every payload before it leaves our infrastructure and refuses to send anything containing an email address, a phone number or a forbidden personal-data key. Platform deletion webhooks (customer redaction, store redaction) are honored: we purge the matching events by hashed identifier, or the whole store.

4. Product data

Your catalog (titles, descriptions, prices, images, availability, identifiers) is synced to build the product feed and, if you use the optimization features, to compute scores and drafts. Product data is not personal data in itself; it is deleted with the store.

5. Recipients and sub-processors

RecipientRoleLocation
Infomaniak Network SAHosting of the platform and databaseSwitzerland
OpenAIReceives conversion events (hashed identifiers, IP, user agent) and the product feed, on your instruction and under your OpenAI accountUnited States
AnthropicOnly if AI rewriting is enabled: receives product title, description, brand and category to draft copy. No customer dataUnited States
Email delivery provider (SMTP)Sends alerts, reports and contact notificationsDepends on the configured provider

We do not sell personal data and do not share it with advertisers. Transfers outside the European Economic Area rely on the recipient’s data processing terms and standard contractual clauses where required; hosting in Switzerland benefits from an EU adequacy decision.

6. Cookies set on your store

The pixel installed on a merchant store sets a first-party cookie named __oppref on the store’s domain for 7 days when a visitor arrives from a ChatGPT Ads click, so the resulting order can be attributed. The WooCommerce plugin also stores the landing URL and referrer in first-party cookies for the same purpose. These cookies are set by the merchant’s store, under the merchant’s consent management; they are not readable by this website.

7. Security

  • Secrets (access tokens, API tokens, SFTP credentials) are encrypted at rest with AES-256-GCM.
  • All traffic uses TLS. Webhooks are verified by HMAC signature before processing.
  • Personal identifiers are hashed on receipt; an automated guard blocks clear personal data before any network call.
  • Access to production systems is limited to the people who operate the Service.

8. Your rights

Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal data, to object to or restrict its processing, and to lodge a complaint with a supervisory authority. Write to [email protected]; we answer within 30 days. If you are a customer of a store that uses Convrail, please contact the store first: it is the controller of your data and we act on its instructions.

9. Children

The Service and this website are intended for businesses and are not directed to children under 16.

10. Changes and contact

We update this policy when our processing changes; the date at the top is the current version. Contact: [email protected]. Postal address: ECOM FR LLC, 28 Geary St Ste 650, San Francisco, CA 94108-5700, United States.