Privacy.
Eric watches how people move through your website so he can tell you where they get stuck. That is the whole job. He does not build profiles of your visitors, he has nothing to sell to advertisers, and the access you give him is the least he can do the work with.
Last updated 12 September 2026.
The short version
- A visitor is a random number kept in their own browser, not a name. We never store their IP address.
- Anything that looks personal is redacted before it reaches our database. An email address becomes a one-way fingerprint so a sale can be matched to a visit, and can never be read back.
- We never record screens, keystrokes, or what anyone types into a form.
- When you connect Google Tag Manager, we use that access once to add one tag, then throw the access away. No refresh token is ever issued, so nothing stays open behind you.
- No data is sold, and none of it goes to an advertising network or a data broker.
Two different people are in this policy
You — the person or business with an EverConvert account. We decide what we collect about you, so for your own data we are the controller.
Your website visitors — the people whose journeys Eric reads. That is your data about your customers. You decide what happens to it and you are the controller; we only hold and process it for you. If one of your visitors asks you to delete what you hold on them, write to us and we will find and delete their rows.
What the tracking code collects
One small script, served from our domain, on the pages you choose. Here is everything it sends, and it is a complete list rather than a summary.
| What | Why Eric needs it |
|---|---|
| The page address and title | To know which page a visit happened on. Before storing, we drop everything after the # and replace any query value that looks personal — an email, a phone number, a token — with [redacted]. |
Where they came from: the referring address and any utm_ tags on the link | To tell you which channel brought the people who convert, and which brought the people who leave. |
A random visitor number and a session number, kept in the visitor’s own browser as ec_vid and ec_sid | To join three page views into one journey. The session number expires after 30 minutes of quiet. Neither number means anything outside your site, and neither is shared with anybody. |
| Phone, tablet or desktop | To catch the pages that only break on a phone. We read the browser’s user-agent to work this out and store only the answer, never the user-agent itself. |
| Country | Handed to us by Cloudflare as a two-letter code. The IP address it came from is never stored, and we never ask for a city. |
| Presses: the label on the link or button, up to 80 characters, and its address | To see the path through a page. A press on a phone or email link is marked as a contact, because that is usually the thing you wanted them to do. |
| That a form was submitted, and the form’s name | To measure the step that matters most. Never the values typed into it. The script does not read form fields at all. |
| How far down the page they got: a quarter, half, three quarters, all of it | To tell you whether anyone reaches the part of the page you care about. |
Anything you send yourself with ec("track", …) | Your own milestones — a signup, a booking, an order value. The redaction below applies to these too. |
| When it happened | The visitor’s clock, believed only if it is within a day of ours. Otherwise we use the time it reached us. |
How personal data is kept out
The properties you can attach to an event are the one place an email address could reach us, so they are filtered on arrival, not later:
- An email address becomes a one-way fingerprint, salted per workspace. Two visits by the same person match; nobody, including us, can turn the fingerprint back into the address.
- A card number, password, national identifier, token or anything under a name that suggests one is replaced with
[redacted]before the row is written. - A string that reads like a phone number or a postal address is replaced the same way.
What the tracking code never does
- No session recording, no screen recording, no heatmap, no keystroke capture.
- No reading of form fields, and no password field is ever touched.
- No IP address stored.
- No following anyone across other websites. The visitor number lives in your site’s own browser storage and cannot be read by any other site, ours included.
- No sharing with advertising networks, data brokers or anyone buying audiences.
- No fingerprinting of devices, and no third-party tracker loaded alongside ours.
Cookies and consent
The tracking code sets no cookies. It keeps the two numbers above in the browser’s own local storage, which is readable only by your site. On our own app, the cookies we set are the ones that keep you signed in and the short-lived ones that tie an install to the browser that started it.
We measure our own app with our own tool, which is the only honest way to sell it. When you set EverConvert up, the steps you reach are recorded the same way a page view is, so we can see where people get stuck and fix it. It is the same redaction and the same storage described above, and it never runs on a developer’s machine or a preview copy.
If you need consent before any measurement starts — and in the UK and EU you often do — hold the tag back until you have it. The script queues anything sent before it loads, so firing it from your consent tool, or on a consent trigger in Tag Manager, loses nothing. That call is yours to make: you know which of your visitors the law covers.
Google Tag Manager: exactly what the access is used for
The quickest way to get Eric onto a site is through the Tag Manager the site already runs. If you choose it, you sign in with Google and we ask for three permissions and no others.
| Permission | What we do with it |
|---|---|
tagmanager.edit.containers | To create one workspace of our own inside your container and add a single tag to it. It is the only way to add a tag without editing the workspace you may be halfway through. |
tagmanager.edit.containerversions | To turn that workspace into a version. Tag Manager will not publish anything that has not been versioned first. |
tagmanager.publish | To publish that version, so the tag is actually live on your site. Without it you would have to finish the job by hand in Tag Manager. |
The whole install, step by step
- We list the Tag Manager accounts and containers your Google account can reach, so we can find yours.
- We read your website’s own pages to see which container it actually loads, and we only touch that one. A container id typed into a browser is never trusted.
- We create a workspace of our own called
EverConvert. Whatever you have half-finished in your own workspace is left exactly as it was. - Inside it we add one Custom HTML tag — the EverConvert script, with your site key already in it — on the All Pages trigger. Nothing else is added, edited or deleted.
- We create a version from that workspace and publish it, because a tag that is not published is not live.
- We then fetch your published container the way a browser would, and check our tag is really being served. That is how the screen can tell you it worked instead of hoping.
What we keep afterwards, and for how long
- Not the access. We ask Google for online access only, so no refresh token is ever issued. The access token lasts about an hour at most, and we delete our copy the moment the install finishes, fails, or the attempt expires.
- We keep the container id we published to, the permissions you granted, and the time — so the screen can tell you what happened and so you can see it later.
- We never read your other tags, your other containers, your Analytics, or anything else the permissions would technically allow. The install writes one tag and reads back the same container.
- Data from these permissions is never sent to a language model, never used to train any model, never used for advertising, and never shared with anyone.
Google API Services User Data Policy
EverConvert’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Taking it back
You can remove our access at any time at myaccount.google.com/permissions. Because we hold no standing access, there is usually nothing there to remove after an install has finished. Removing access does not remove a tag that is already published — to stop the measurement, delete the EverConvert tag in Tag Manager and publish, or ask us and we will tell you exactly which tag it is.
Slack
Eric lives in Slack, so connecting it is how you talk to him. When you add him we ask for the permissions that let him do exactly that: read the messages that mention him, post and reply, create and join the channel he works in, invite you to it, message you directly, and read your workspace’s name and the name and email address on your own Slack profile.
Your email address is used to make your EverConvert account and to sign you in, which is why connecting Slack is enough to get started and no confirmation email is needed. We store your Slack workspace and channel ids, the messages Eric posts, and what you ask him.
What you ask Eric is read by a language model to write his reply. That happens through the Lovable AI Gateway on Google Gemini models. Those providers do not use it to train their models. Nothing from your Google Tag Manager permissions is ever included.
The other tools you connect
You can connect Google Analytics, Search Console, Stripe, HubSpot, Shopify and others so Eric can line up what happened on your site with what happened in your business. Those connections are made through Composio, which holds the tokens; we ask each one for the least it can answer with, and for the analytics and revenue tools that means read access only. You choose each one, and you can disconnect any of them from Connections whenever you like, which revokes the token.
The Shopify app and its checkout pixel
Shopify’s checkout runs on Shopify’s own pages, where the tracking code cannot go, so the EverConvert app adds a checkout pixel instead. It reports three things: a checkout was started, payment details were submitted, and an order was completed, each with the order total, the currency and the order number. It reads the same visitor and session numbers the rest of your site uses, so a sale joins the journey that produced it. It never sends us a shopper’s name, email address, postal address or payment details.
Uninstalling the app in Shopify stops all of it and removes what we hold about that store. The order number is kept so the same order is never counted twice.
Who else touches the data
| Who | What for |
|---|---|
| Supabase | The database and file storage everything is kept in. |
| Cloudflare | Serving the app and the tracking script, and the country code described above. |
| Lovable AI Gateway, on Google Gemini models | Writing Eric’s answers and his suggestions. |
| Composio | Holding the connections you choose to the tools you already use. |
| Slack | Where the conversation happens. |
| Paddle | Taking payment. Your card details go to them and never reach us. |
We add a processor only when it is needed to run the product, and we do not sell, rent or trade data with anybody.
How long things are kept
- Raw website events — the visitor-level rows — are kept for up to 12 months, then deleted or irreversibly anonymised. Ask us to delete them sooner and we will.
- Messages sent and received through Eric on WhatsApp, Slack and SMS are kept for up to 12 months. The delivery record behind them — sent, delivered, failed, with no content — is kept for 24 months for billing and disputes.
- An install nobody finished is cleared automatically: the token is dropped and the attempt is marked as never completed.
- Tokens for a one-off install — Google Tag Manager, ClickFunnels — are deleted as soon as the install ends, either way.
- Your account and what Eric has learned about your business stay until you close it. Closing it deletes the workspace: personal data goes within 30 days and backups age out within 90.
What Eric learns, and what survives deletion
Eric gets better by spotting patterns, so it matters exactly what is kept once the raw data is gone. There are two separate layers and they never mix.
- What Eric knows about your business stays inside your workspace, is used only for you, and is deleted with your account. We do not train shared models on your raw events, your messages or your customers’ words.
- What Eric knows in general — statistical patterns across many businesses, such as “removing this kind of form field tends to lift mobile sign-ups” — may be kept indefinitely, because it is aggregated and irreversibly anonymised. No person, no message and no individual customer can be identified or reconstructed from it, which is why it is no longer personal data.
The purpose is stated plainly so there are no surprises: we use your data to run the product for you, and we use anonymised patterns derived from it to improve Eric’s analysis and recommendations for everyone. If you would rather your workspace was excluded from that general layer, tell us and we will exclude it. Business customers can read the detail in the data processing terms.
What you can ask for
- A copy of everything we hold on you, or on one of your visitors.
- Deletion of any of it, including a single visitor’s rows.
- Correction of anything wrong.
- Disconnection of any tool, which revokes the token behind it.
Write to support@everconvert.ai and we will do it within 30 days, usually the same week. If you are in the UK or EU these are your rights under the GDPR; we answer everyone the same way regardless.
Children
EverConvert is a business tool and is not directed at children. We do not knowingly collect anything about anyone under 16. If you believe we have, tell us and we will delete it.
If this page changes
The date at the top changes with it. If a change matters — a new permission, a new processor, a new kind of data — Eric will tell you in Slack rather than leaving you to notice.
Asking us something
support@everconvert.ai reaches a person. Privacy questions, deletion requests and anything about the Google permissions above go to the same address.
The controller of your account data is EVERCONVERT.AI LTD, a company registered in England and Wales, company number 17009673, incorporated 3 February 2025. For the personal data we hold on your behalf, see the data processing terms. Cookies and browser storage are listed on the cookie notice.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner’s Office at ico.org.uk, though we would rather you gave us the chance to put it right first.