ConversionOS and privacy
Conversion tracking handles customer and event data. Review the current data-processing terms and configure consent and identifiers appropriately for your installation.
On this page
Identifiers and matching
Supported ingestion paths use normalized or hashed identifiers for matching. Hashing is not the same as anonymization: stable identifiers can still link a customer’s activity.
Use the format required by the integration. Do not send plaintext personal data to a field that requires a hash, and verify the behavior of your selected capture path.
Credentials
Destination access is managed server-side. A website tracking key is distinct from ad-platform credentials: rotating the key does not revoke a Google or Meta connection. Use the relevant integration controls for that connection.
Data retention and deletion
ConversionOS order line items and delivery records use a configurable 730-day default cleanup period. The cleanup also clears matching identifiers from eligible historical conversion events, but does not delete the base event rows used for revenue history. Those records remain subject to the purposes and deletion obligations in the Privacy Policy and Data Processing Agreement.
Administrators can change the cleanup period or disable automatic cleanup. When cleanup is disabled, records can remain beyond the default period until cleanup resumes or deletion is processed. This does not extend a contractual deletion obligation. Contact support to confirm the applicable settings or request deletion; cancelling a subscription alone is not the same as deleting an account.
Consent and disclosure
Configure consent handling and explain the tracking you use in your privacy notice. Server-side delivery does not remove those responsibilities. Consult the current privacy policy and data-processing agreement for the contractual terms.
Frequently asked questions
Does using ConversionOS make a website compliant?
No tool alone establishes compliance. It depends on your purposes, consent, notices, contracts and implementation. Review the current terms and obtain advice appropriate to your circumstances.
Does rotating the site key revoke Google or Meta access?
No. The website key and destination credentials are separate. Use integration controls to manage a platform connection.