Privacy policy

What this website collects, and what the service does with data.

This website collects nothing. There is no analytics, no tag manager, no advertising pixel, no cookie and no form. The pages are static files and ship no JavaScript.

This website

Pages are served as static files from Firebase Hosting. Google records standard web server request logs — IP address, user agent, requested path, timestamp — as part of operating the hosting service. We do not set cookies, do not use analytics or advertising trackers, and do not build a profile of visitors. No fonts, scripts or images are loaded from third-party servers.

The service

Conversion API is a hosted service: an app owner signs up, configures their apps, and connects their own advertising accounts, and we operate the infrastructure that records ad clicks, matches them to app installs, and forwards conversions to the matched platform. That means the data described below passes through infrastructure we operate. Whether that makes us a data processor, a sub-processor, or something else for a given app owner's traffic depends on the relationship and the law that applies to it — this page states what the infrastructure actually does with the data, not a legal conclusion about who controls it; app owners should confirm the right characterization for their own compliance obligations.

What the service processes

  • Ad clicks — the platform click identifier, IP address, user agent, and any campaign parameters on the URL. These records carry a time-to-live and are deleted automatically once they are past the attribution window.
  • App events — an install identifier generated by the app, the event name and time, device operating system, version and model, and optionally a purchase value and currency.
  • Contact identifiers, optionally — an email address or phone number, if the operator's app chooses to send one. These are normalised and hashed with SHA-256 on the server and only the hash is transmitted onward, to the one matched ad platform. Raw values are never written to logs and never stored. Apps can send values already hashed, in which case raw contact data never leaves the device.

Who it is shared with

Only the advertising platform that the click came from — Meta, TikTok or Pinterest — and only for conversions matched back to a real ad click from that platform. Events are never sent to more than one platform. Installs that match no click are recorded as organic and are not forwarded anywhere.

Credentials

Advertising platform access tokens are held in Google Secret Manager. Configuration records store only the name of a secret, never a token. When a platform rejects an event and the payload is retained for replay, the access token is stripped from it first.

Retention

Click records expire automatically after the configured attribution window. The attribution outcome for an install is kept so that later conversions from the same install continue to report correctly. App owners control retention settings and configuration for their own apps within the service; they do not have direct access to another app owner's data.

Rights and requests

If you have questions about data collected through an app you installed, start with the app itself — the app owner has the direct relationship with you and decides what their app collects and where it goes. Depending on the request, they may need to involve us to fulfil it, since we operate the infrastructure their app's tracking runs on; we do not have an independent relationship with the end users of apps we host tracking for.

Changes

Material changes to this page will be reflected in the public repository history.