Privacy Policy
This policy explains what personal information Conversion collects across our website, agency services, and Shopify apps — and how we use, share, and protect it.
Effective date: · Last updated:

1. Who we are
Conversion (“Conversion,” “we,” “us,” or “our”) is a growth agency and software developer operated by DGY LLC, a company registered in the United States with its principal place of business at 15 Westgate Drive, San Francisco, CA 94127, USA. We operate the website conversion.is, provide marketing, development, and growth services to clients, and publish applications on the Shopify App Store.
For the purposes of the EU and UK General Data Protection Regulation (“GDPR”), DGY LLC is the data controller for personal information collected through our website and marketing activities. Where we process data on behalf of our agency clients or on behalf of merchants who install our Shopify apps, we generally act as a data processor and process that data only on their documented instructions.
2. Scope of this policy
This policy covers personal information we handle in three contexts:
- Website visitors — anyone browsing conversion.is, submitting a form, booking a call, or contacting us.
- Clients and prospects — businesses and their representatives who engage (or consider engaging) our agency services.
- Shopify app users— merchants who install our Shopify apps, and the customer data those apps process on the merchant's behalf. Section 6 covers this context in detail.
This policy does not cover third-party websites we link to, or the independent privacy practices of platforms such as Shopify, Meta, Google, or Klaviyo. We encourage you to review their policies directly.
3. Information we collect
Information you provide to us
- Contact details — name, email address, phone number, company name, and role, when you fill out a form, book a call, or email us.
- Business information — details about your store, traffic, revenue, ad accounts, and growth goals that you share during discovery or an engagement.
- Billing information — billing contact and address details needed for invoicing. Card payments are processed by our payment providers; we never store full card numbers.
- Communications — the content of emails, call notes, and messages you exchange with us.
Information collected automatically
- Usage data — pages visited, referring URLs, time on page, and interactions with our website.
- Device data — IP address, browser type, operating system, screen size, and language settings.
- Cookies and similar technologies — see Section 8 for details.
Information from other sources
- Platform data — when you connect an ad, analytics, or commerce account (e.g., Google Ads, Meta, GA4, Shopify) as part of an engagement, we access the data those platforms make available under the permissions you grant.
- Publicly available business information used to prepare for a call or proposal.
4. How we use your information
- To provide, operate, and improve our services and Shopify apps.
- To respond to inquiries, schedule calls, and prepare proposals.
- To perform contracted work — running campaigns, building storefronts, analyzing performance data, and reporting results.
- To send service updates, and — where permitted — marketing communications you can opt out of at any time.
- To monitor, secure, and debug our website and apps.
- To comply with legal obligations and enforce our agreements.
We do not sell your personal information, and we do not use client data or Shopify app data to train machine-learning models unrelated to the service you engaged us for.
5. Legal bases (GDPR)
Where GDPR applies, we rely on the following legal bases:
- Contract — processing needed to deliver services you or your company have engaged us for.
- Legitimate interests — operating and securing our website, responding to inquiries, and business development, balanced against your rights.
- Consent — marketing emails and non-essential cookies, which you can withdraw at any time.
- Legal obligation — record-keeping, tax, and responding to lawful requests.
6. Shopify apps privacy
Conversion develops and publishes apps on the Shopify App Store. This section explains how those apps handle data and applies in addition to the rest of this policy. If anything in this section conflicts with another section, this section controls for app-related data.
What our apps collect
When a merchant installs one of our apps, the app may access:
- Store information — shop name, domain, email, plan, timezone, and currency, provided by Shopify on installation.
- Store content and commerce data — products, collections, orders, themes, or other resources, strictly limited to the API access scopes the merchant approves at install time. Each app requests only the minimum scopes it needs to function.
- Customer data— where an app's function requires it (for example, order or conversion analysis), the app may process customer names, email addresses, order details, and similar records. We process this data solely as a processor on the merchant's behalf and never use it for our own marketing.
Protected customer data
Where our apps access data Shopify designates as protected customer data, we comply with Shopify's Protected Customer Data requirements: we process it only for the app's stated purpose, apply the data-minimization, encryption, and retention controls Shopify mandates, maintain records of processing, and make our practices transparent to merchants through this policy.
Mandatory privacy webhooks
All of our apps implement Shopify's mandatory GDPR webhooks and respond to them within the required timeframes:
customers/data_request— when a customer requests their data through a merchant, we compile and return the personal data our app holds for that customer.customers/redact— when a merchant requests deletion of a customer's data, we delete or anonymize that customer's personal data from our systems.shop/redact— 48 hours after a merchant uninstalls an app, Shopify sends this webhook and we delete the shop's stored data in line with the retention schedule below.
App data retention and deletion
- Active installs — data is retained only as long as needed for the app to function.
- After uninstall — shop and customer data is deleted within 30 days of receiving the shop/redact webhook, except where a longer period is required by law (e.g., billing records).
- Merchants can also email us at any time to request early deletion of their app data.
App subprocessors
Our apps run on vetted cloud infrastructure and may use subprocessors for hosting, databases, error monitoring, and email delivery. All subprocessors are bound by data processing agreements consistent with this policy, and app data is never shared with advertising networks.
7. How we share information
We share personal information only with:
- Service providers — hosting (e.g., Vercel), analytics, scheduling (e.g., Cal.com), email, CRM, and payment processors, each bound to process data only on our instructions.
- Platforms you connect — when an engagement requires us to work inside your Shopify, Google, Meta, Klaviyo, or similar accounts, data flows through those platforms under their terms and the permissions you control.
- Legal and safety — where required by law, court order, or to protect the rights, safety, or property of Conversion, our clients, or others.
- Business transfers — if we undergo a merger, acquisition, or asset sale, personal information may transfer as part of that transaction subject to this policy.
We never sell personal information to data brokers or advertisers.
8. Cookies & analytics
We use a small number of cookies and similar technologies: strictly necessary cookies that make the site work, and analytics cookies that help us understand how visitors use our pages so we can improve them. Analytics data is aggregated and not used to identify you personally. You can control cookies through your browser settings; blocking non-essential cookies will not break the site.
9. Data retention
- Inquiry and prospect data — up to 24 months after last contact, then deleted or anonymized.
- Client engagement records — for the duration of the engagement plus the period required for legal, tax, and accounting obligations (typically 7 years for financial records).
- Website analytics — retained in aggregate form; raw event data is retained for no longer than 14 months.
- Shopify app data — see Section 6 for app-specific retention and deletion timelines.
10. Data security
We apply administrative, technical, and physical safeguards appropriate to the sensitivity of the data we handle: encryption in transit (TLS) and at rest for stored app data, least-privilege access controls, multi-factor authentication on internal systems, and vendor due diligence. No method of transmission or storage is 100% secure, but if we become aware of a breach affecting your personal data we will notify you and the relevant authorities as required by law.
11. International transfers
We are based in the United States and serve clients in the US, Canada, UK, and Australia. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision.
12. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or object to our processing of your personal data, the right to data portability, and the right to withdraw consent at any time. To exercise any of these rights, email us at tarun@conversion.is. We respond to verified requests within 30 days. If you are in the EEA or UK, you also have the right to lodge a complaint with your local supervisory authority.
If your data reached us through a merchant's Shopify store, please direct your request to that merchant first — they control the data, and we will assist them in fulfilling it.
13. California privacy rights
If you are a California resident, the CCPA/CPRA gives you the right to know what personal information we collect, request its deletion or correction, opt out of “sale” or “sharing” of personal information, and not be discriminated against for exercising these rights. We do not sell or share personal information as defined by the CPRA. To exercise your California rights, contact us using the details in Section 16.
14. Children's privacy
Our website, services, and apps are directed at businesses and are not intended for anyone under 16. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
15. Changes to this policy
We may update this policy from time to time. When we do, we will revise the “Last updated” date at the top of this page, and for material changes we will provide additional notice (such as an email to active clients or an in-app notice for merchants). Continued use of our website, services, or apps after an update means you accept the revised policy.
16. Contact us
Questions, requests, or complaints about this policy or your data:
- Email: tarun@conversion.is
- Mail: DGY LLC (Conversion), 15 Westgate Drive, San Francisco, CA 94127, USA
- Phone: +1 909-353-1789
You can also visit our About page to learn more about who we are.