PRIVACY & DATA PRACTICES

Controls for responsible
behavior analytics.

This page describes current product behavior and implementation guidance. Final contractual Privacy Policy, Terms and DPA require the service operator's verified legal identity and legal review.

What the collector records

  • Anonymous session identifiers and a site-scoped hash used to connect consented return visits.
  • Page paths, timestamps, clicks, normalized pointer positions and scroll-depth milestones.
  • Commerce or lead milestones, form-error signals and performance measurements.
  • Masked DOM changes needed for session replay.

What customers must not send

  • Payment-card or authentication credentials.
  • Email, phone, postal address or government identifiers.
  • Health, financial or other sensitive-category data.
  • Unmasked free-form field contents.

Built-in controls

Mask and exclude

Inputs are masked by default. Mark sensitive regions with data-private and sensitive text with data-mask.

Consent first

Configure the plugin to wait for analytics consent and connect the site's consent platform before collecting.

Retention and deletion

Workspace owners can configure site retention, pause collection, export data, delete sites and schedule organization deletion.

Current infrastructure providers

Cloudflare provides edge delivery, Workers and D1 storage. Stripe processes subscription billing. No transactional-email provider is active yet. A formal subprocessor schedule and DPA will be published only after the operating legal entity and contractual terms are finalized.

Cookie and consent guidance

ConvertClarity uses an anonymous first-party session identifier in session storage and, after analytics consent, a random first-party visitor identifier in local storage. The server stores only a site-scoped hash of that visitor identifier. Customers remain responsible for their consent banner, regional consent rules, privacy notices and lawful-basis analysis. Do not start analytics collection before required consent, and dispatch conversion-lens:consent-denied when consent is withdrawn so collection stops and the identifier is removed.