Privacy Policy

Last updated: July 23, 2026

This Privacy Policy describes how Converbase ("Converbase," "we," "us," or "our") handles information when you use our website, create an account, or operate a workspace on the platform. It also explains how we process certain data on behalf of customers who use Converbase to communicate with their subscribers and contacts.

Who this policy covers

Account users are individuals who register for Converbase, join a workspace, or otherwise use the service to manage customer communication and email marketing. Subscribers and contacts are individuals whose information is collected, uploaded, or processed by our customers through landing pages, signup forms, messaging channels, or email campaigns. In many cases, Converbase acts as a processor for subscriber and contact data on behalf of the customer workspace that controls that audience. Customers remain responsible for providing appropriate notices and obtaining lawful bases for processing subscriber data.

Information you provide

When you create or use a Converbase account, we may collect:

  • Name, email address, and authentication credentials
  • Workspace and team membership details
  • Profile, onboarding, and settings preferences
  • Support requests and communications you send to us
  • Billing-related identifiers if billing features are enabled for your workspace

Account and workspace data

We store workspace configuration, team roles, channel connections, domain verification records, campaign settings, landing page content, and operational metadata needed to provide the service. Workspace data is isolated using access controls designed to limit visibility to authorized workspace members.

Subscriber and campaign data processed on behalf of customers

When customers use Converbase for email marketing or audience management, we may process subscriber email addresses, list membership, consent and subscription status, campaign content, delivery events, unsubscribe requests, bounce and complaint signals, and related metadata. Customers determine what data they upload or collect and how they use it outside the platform.

Communication channel data

If you connect supported messaging channels such as WhatsApp, Instagram, or Telegram, we may process message content, participant identifiers, channel metadata, and delivery status needed to display conversations in your workspace. The data available depends on the channel integration you configure and the permissions granted to Converbase.

Technical and usage data

We automatically collect certain technical information, including:

  • IP address, browser type, device information, and operating system
  • Log data such as timestamps, pages viewed, and API or authentication events
  • Diagnostic, performance, and security information
  • Referrer URLs and approximate location derived from IP address

Cookies and similar technologies

We use cookies and similar technologies to maintain sessions, remember preferences, protect access to preview or gated environments where enabled, and understand how the service is used. You can control cookies through your browser settings, although disabling certain cookies may affect functionality such as sign-in.

How we use information

We use information to:

  • Provide, operate, maintain, and improve Converbase
  • Authenticate users and enforce workspace permissions
  • Send transactional messages such as account confirmations and security notices
  • Deliver email campaigns and process delivery events on behalf of customers
  • Verify domains, route custom landing pages, and support messaging integrations
  • Monitor abuse, protect the platform, and comply with legal obligations
  • Respond to support requests and communicate about the service

Service providers and infrastructure

We use third-party providers to host and operate Converbase. Depending on configuration, these may include:

  • Supabase for authentication and database storage
  • Railway or similar hosting providers for application infrastructure
  • Amazon SES for email sending and delivery event processing
  • Cloudflare for DNS, proxy, and custom domain services
  • Analytics, logging, and monitoring providers where enabled

These providers process data under contractual terms appropriate to their role. Customers should review their own obligations when selecting integrations and sending domains.

Data retention

We retain account and workspace data for as long as your account is active or as needed to provide the service, resolve disputes, enforce agreements, and comply with law. Subscriber and campaign data retained on behalf of customers is kept according to workspace settings, customer actions, and operational requirements such as suppression list maintenance. Customers may request deletion of workspace data subject to applicable law and technical constraints.

Security

We implement administrative, technical, and organizational measures designed to protect information, including access controls, encryption in transit where supported by providers, and workspace isolation. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

International processing

Converbase may process information in countries other than where you or your subscribers are located, including where our infrastructure providers operate data centers. Where required, we rely on appropriate safeguards for cross-border transfers.

Customer responsibilities for subscriber consent

If you use Converbase to collect or message subscribers, you are responsible for providing clear notice, obtaining valid consent where required, honoring unsubscribe and data subject requests for your audience, and ensuring your content and recipient lists comply with applicable law. Converbase provides tools to support permission-based email, but customers control list sources, message content, and audience practices.

Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, or object to certain processing of your personal information, or to receive a portable copy of your data. Account users may manage much of their information through workspace settings. Subscribers seeking to exercise rights regarding data controlled by a Converbase customer should contact that customer directly; we will assist customers where appropriate.

To make a privacy request related to your Converbase account, contact us at [email protected].

Children's privacy

Converbase is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will take appropriate steps to delete it.

Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will post the updated policy on this page and revise the "Last updated" date. Your continued use of Converbase after changes become effective constitutes acceptance of the updated policy.

Contact

Questions about this Privacy Policy or our data practices may be sent to [email protected].