Convertras
Convertras

Privacy policy

What Convertras collects, why, and the difference between the data we hold about you and the data you hold about your own customers.

Last updated 18 August 2026 · Stratos Tech LLC

Convertras is operated by Stratos Tech LLC ("we", "us"). This page describes how we handle personal data in the Convertras application at convertras.com.

The distinction that matters most

Convertras is a CRM. That means there are two very different kinds of personal data involved, and we treat them differently because our responsibilities for them are not the same.

Data we hold about you, our customer

Your name, email address, password hash, workspace name and billing records. For this data we are the data controller: we decide why it is held and how it is used, and this policy governs it.

Data you hold about your contacts

Everything you enter into your workspace — contacts, companies, deals, conversations, notes, uploaded documents — is your data about your customers. For that data we are a data processor acting on your instructions. You are the controller. We do not decide what you collect, we do not use it for our own purposes, we do not sell it, and we do not use it to train models.

Concretely, as a processor we will: process that data only to provide the service; keep it isolated to your workspace; not disclose it except where you instruct us or the law compels us; and delete or return it when you close your account.

A Data Processing Agreement covering this relationship, including sub-processors and international transfers, is available on request from hello@convertras.com. If you are subject to the GDPR or a comparable regime and need one signed before you can use Convertras, ask — it is a normal request and we expect it.

What we collect

  • Account. Name, email address, a hashed password (never the password itself), and if you enable two-factor authentication, an encrypted secret. Used to authenticate you and to contact you about your account.
  • Workspace. Workspace name, members, roles and invitations. Used to decide who may see what.
  • CRM content you enter. Contacts, companies, deals, conversations, messages, notes, documents, products and orders. Held on your behalf, as described above.
  • Payment data. Handled entirely by Stripe. Card numbers never reach our servers and are never stored by us. We keep only what Stripe returns for billing purposes: a customer reference, a subscription status, and invoice records.
  • Operational records. Audit logs of significant actions in your workspace, API request logs, and error reports. Used to keep the service secure and to diagnose faults.
  • Cookies. A session cookie and a CSRF token, both strictly necessary. See the cookie policy.

What we do not do

  • We do not sell personal data, yours or your contacts'.
  • We do not use your CRM content to train AI models.
  • We do not run third-party advertising or analytics trackers on the application.
  • We do not store card numbers.

Who else processes data

We use a small number of sub-processors to run the service. Each receives only what it needs:

  • Stripe — payments and subscription billing.
  • Hostinger — server hosting.
  • Resend — transactional email (password resets, invitations, quotes).
  • Sentry — error reporting. Configured not to send request bodies or user identifiers.

If you have enabled an optional integration — WhatsApp, Shopify, WooCommerce, an AI provider — data flows to that service because you asked it to, and that service's own terms apply to what it receives.

How long we keep it

  • Account and workspace data — for as long as your account is open.
  • CRM content — until you delete it, or until you close your account.
  • Audit logs — 13 months.
  • API request logs — 90 days.
  • Deleted records — recoverable for 90 days, then permanently purged.
  • Billing records — as long as tax and accounting law requires.

Your rights

Depending on where you live, you may have the right to access, correct, export or erase your personal data, to object to processing, or to complain to a supervisory authority. Write to hello@convertras.com and we will respond within 30 days.

If your request concerns data held in someone else's workspace — for example, you are a contact of a business that uses Convertras — we have to refer you to that business. They are the controller of that data; we hold it for them and cannot amend or release it on our own initiative. Tell us who they are and we will pass the request on.

Security

Traffic is encrypted in transit with TLS. Passwords are hashed. Integration credentials, two-factor secrets and webhook signing secrets are encrypted at rest. Each workspace is isolated at the database query level, and that isolation fails closed — a query without a workspace context returns nothing rather than everything. Backups of the database and of stored documents are taken nightly and verified after writing.

No system is perfectly secure. If you believe you have found a vulnerability, please write to hello@convertras.com before disclosing it publicly.

Changes

We will update this page when our practices change, and the date at the top will tell you when. If a change materially affects how we handle your data, we will tell you by email rather than relying on you to notice.