Privacy policy
Last updated: July 21, 2026
1. Who we are, and the two roles we play
TEXOOM Ltd, a company registered in England and Wales, operates Pivolio — a server-side conversion tracking platform. In this policy “we”, “us” and “Pivolio” mean that company.
We handle personal data in two distinct capacities, and the distinction determines both your rights and who you should contact:
- As a controller for data about our own visitors, prospects and account holders — the people who visit this website, sign up, and pay us. Sections 2 to 4 cover that.
- As a processorfor the conversion event data our customers send through the platform. That data concerns our customers’ end users, not ours. The customer decides what is collected and why; we act on their instructions. Sections 5 to 7 cover that.
If you are an end user of a business that uses Pivolio and you want your data accessed or deleted, that business is the controller and your request should go to them. We will assist them, but we will not act on their data without instruction — see section 12.
2. Data we hold as a controller
When you interact with us directly, we process:
- Account data — name, work email, hashed password, workspace names, and the settings you configure.
- Billing data — plan, subscription status, and billing contact. Card details are handled entirely by Stripe; we never see or store a full card number.
- Support and contact data — anything you send us through the contact form or by email.
- Technical data — IP address, browser and device information, and log data generated when you use the dashboard or this website.
3. Why we process it, and on what basis
- To provide the service — creating your account, authenticating you, and delivering what you subscribed to. Basis: performance of a contract.
- To take payment — basis: performance of a contract, and legal obligation for tax records.
- To keep the platform secure and working — monitoring, error diagnostics, and abuse prevention. Basis: our legitimate interest in operating a secure service.
- To contact you about the service — operational notices, and marketing where you have opted in or where permitted for existing customers. Basis: consent or legitimate interests. You can opt out of marketing at any time.
We do not sell personal data, and we do not use it to train machine-learning models.
5. Data we process for our customers
When a customer installs Pivolio, their website and systems send us event data about their end users. We process it only to provide the service. Depending on what the customer chooses to send, it can include:
- Event data— event name, timestamp, page URL, referrer, order value, currency, and custom properties the customer defines. Page URLs and referrers are stored as sent, including their query strings. We do not strip or rewrite them, so whatever the customer’s own site places in a URL is retained with the event.
- Advertising identifiers — click IDs such as
gclidandfbclid, and their equivalents on other platforms. - Technical identifiers — IP address, user agent, device and browser characteristics, and any first-party identifier the customer sets.
- Contact identifiers — email address and phone number where the customer sends them for conversion matching, plus any customer traits they attach to a person.
IP addresses are personal data, and hashed identifiers remain personal data under the GDPR — hashing is pseudonymisation, not anonymisation, because the receiving advertising platform can match the hash back to a person. We treat all of the above accordingly.
6. How identifiers are stored and transmitted
We want to be precise here, because “everything is hashed” is a common claim that is rarely true end to end.
- In transit to advertising platforms, contact identifiers are normalised and hashed with SHA-256 before they leave our systems. Plain-text email addresses and phone numbers are never sent to a destination platform.
- At rest in the identity graph, normalised email addresses and phone numbers are stored in readable form, together with any traits the customer attaches to a person. This is what lets a customer find and manage their own customers in the dashboard, and act on a deletion request for a specific individual.
- Destination credentials — the platform access tokens a customer connects — are encrypted at rest and are never returned through the API or displayed again after entry.
Every workspace is isolated at the database level by row-level security, so one customer’s data cannot be reached through another customer’s session.
7. Where customer data is sent
We transmit conversion data to the advertising platforms a customer explicitly connects, and to no others. The customer chooses the destinations, supplies the credentials, and can disconnect at any time.
Those platforms act as independent or joint controllers for the data they receive, and their own terms govern what they do with it. The customer is responsible for having a lawful basis for that disclosure and for honouring the consent signals that accompany each event.
8. Subprocessors
We use a small number of third parties to run the platform. Each is bound by written terms, may process data only on our instructions, and is subject to confidentiality and security obligations.
- Amazon Web Services — Hosting, compute, and storage. United States.
- Stripe — Subscription billing and payment processing. United States.
- Resend — Transactional email (account and alert notifications). United States.
- Sentry — Error monitoring and diagnostics. United States.
- Cloudflare — DNS, CDN, and network protection. Global edge network.
- IPLocate — IP geolocation used in traffic-quality scoring. United States.
- Soketi — Realtime delivery of dashboard events. United States.
We give customers notice before adding or replacing a subprocessor, so they have a reasonable opportunity to object.
9. International transfers
The platform is hosted in the United States (AWS, us-east-1), and our team works from the United Arab Emirates and the United Kingdom. If you are in the UK or the EEA, your data — and the data you send us about your end users — is therefore transferred outside your jurisdiction.
Those transfers rely on the European Commission’s Standard Contractual Clauses, and on the UK International Data Transfer Addendum where UK data is involved, together with supplementary technical measures including encryption in transit and at rest. Copies are available on request.
10. How long we keep data
- Conversion events are retained for the life of the workspace. They are not deleted on a timer — a customer can export or delete them at any time. An individual erasure removes the person and their identifiers, but their past events are retained: the customer id on those events no longer resolves to anyone, while the hashed identifiers, IP address and full page URLs on them remain.
- Delivery logs — the record of what was sent to which platform and what came back — are retained on the same basis. Individual erasure does not remove delivery logs; they carry no direct identifiers.
- Identity records are retained for the life of the workspace, because they are what makes a returning customer recognisable. A customer can delete an individual person at any time.
- Account and billing records are kept for the life of the account, and afterwards for as long as tax and accounting law requires.
On termination we delete customer data within 30 days, except where law requires us to keep it. Backups are deleted on their normal rotation.
11. Security
- Encryption in transit (TLS) for every connection, and encryption at rest for stored data.
- Row-level security in the database, enforcing tenant isolation at the storage layer rather than relying on application code to remember it.
- Destination credentials encrypted with a separate key, never exposed through the API.
- Production access limited to staff who need it, with authentication and audit logging.
- Continuous error monitoring and a documented process for investigating incidents.
No system is perfectly secure. If a personal data breach affects customer data, we notify the affected customer without undue delay so they can meet their own notification obligations.
12. Your rights
Where we are the controller — you are a visitor, prospect, or account holder — you may ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or provide it in a portable form. Where we rely on consent, you can withdraw it at any time.
If you are an end user of a business that uses Pivolio, that business is the controller and your request should go to them. If you send it to us, we will pass it on promptly and help them respond, but we will not act on their data without their instruction.
California residents have the right to know, delete, correct, and opt out of the “sale” or “sharing” of personal information, and not to be discriminated against for exercising those rights. We do not sell personal information as that term is defined under the CCPA.
We respond within one month. If you are unhappy with our response you may complain to your local supervisory authority — in the UK, the Information Commissioner’s Office.
13. Children
14. Changes to this policy
15. Contact us
Privacy questions, rights requests, and subprocessor objections: privacy@pivolio.com. For anything else, use our contact page.
Customers who need processor terms should read our data processing agreement, which forms part of the contract.