CSignal Convert Privacy & Data Policy
Applies to: the Convert capability of CSignal (the on-site CSignal pixel) Roles: you (the store) are the data controller; Charle London Limited is your processor, see section 2 Version: 1.0 Last updated: 1 July 2026
1. About this policy
This policy explains how CSignal Convert handles data. Convert is the part of CSignal that measures how visitors interact with your store, so it can recommend improvements to your on-site experience. It works through the CSignal pixel, a small piece of analytics technology you install on your storefront.
Read this together with the CSignal Platform Privacy & Data Policy (the umbrella policy). This policy also includes, at section 12, what you need to add to your own store's privacy policy: please act on that section.
The methods and models CSignal uses to score behaviour and produce recommendations are proprietary to Charle. This policy describes what the pixel collects and why: not how the analysis works.
2. Who is responsible for what (controller and processor)
This is the most important part to understand.
- You are the data controller. It is your store, your visitors, and your decision to install CSignal. Under UK GDPR you decide the purpose, and you are responsible to your visitors, including telling them about CSignal in your own privacy policy and having a lawful basis (see sections 11 and 12).
- Charle is your processor. We collect and analyse the pixel data on your behalf and on your instructions, to provide the CSignal service to you. We do not sell this data to third parties, and we do not use it to build profiles of individuals.
There is one exception, which we are transparent about:
- For anonymised network insights, Charle acts as a controller. After data has been anonymised and aggregated, we use it to understand trends across our whole network of stores and to improve CSignal. This is how we understand what works and what doesn't, so we can improve your performance. At that point it is no longer personal data and no longer relates to your store specifically (see section 8).
3. What the CSignal pixel collects
The pixel is designed to capture how people interact with your pages, not who they are. It collects:
- A pseudonymous visitor identifier and session identifier: random IDs stored in the browser (via local/session storage) so we can tell repeat visits and sessions apart. These are not linked to a name, email or account.
- On-page behaviour: how visitors navigate and interact with your pages.
- Form interactions: that a form field was focused, and that a form was submitted or abandoned. We capture the interaction, not the information a visitor types. The pixel is designed not to capture the contents of form fields.
- Conversions: that a conversion (such as a completed checkout or enquiry) took place, and information about it such as the order value.
- Technical and performance data: device type, browser, operating system, page-performance measures, and JavaScript errors, used to spot technical problems that hurt the experience.
- Traffic source: the referring site and campaign parameters (for example UTM tags) that brought the visit.
- A hashed IP address: see section 4.
What the pixel does not collect: we do not collect visitors' names, email addresses, postal addresses, phone numbers, payment details, or the content they type into forms. We do not build profiles of individual people, the data is used in aggregate to understand behaviour and improve the experience generally, not to identify, track or target any individual. You should not configure the pixel to send us any such personal data.
How the pixel gets installed. You can install CSignal either through our app on the Shopify App Store, or by pasting a script into your theme (manual install). If you install through the Shopify App, CSignal receives checkout events (such as completed orders and their value) automatically through Shopify's own Web Pixel API, in addition to the on-page behavioural data described above. This does not change who is responsible for what: you remain the controller and we remain your processor (section 2), and Shopify does not pass card, contact or delivery details through the Web Pixel API to us either way.
Customer lifetime-value data (Shopify App only). To measure whether features like loyalty programmes and subscriptions help you keep customers longer, CSignal also stores, for your identified (logged-in) customers only, a small set of lifetime order statistics read from Shopify: total amount spent, number of orders, first and most recent order dates, and Shopify's own value-based segments (such as its predicted-spend tier and RFM group). This is linked to the Shopify customer identifier, so unlike the pseudonymous on-page data above it is customer-level information about a known person, and is more personal than the rest of Convert. We use it only to measure, in aggregate and across the network, how on-site features relate to customer value; we do not use it to profile, target or contact individual customers, and it never includes card, contact or delivery details. Guest checkouts and anonymous browsing carry no customer identifier and are not included. This data is held under the same per-store isolation (section 6), 12-month retention (section 7) and erasure route (section 10) as the rest of Convert, and it is only collected when you install through the Shopify App.
4. IP addresses
An IP address is treated as personal data, so we handle it carefully. The pixel uses a visitor's IP address only momentarily, at the point of collection, for a single purpose: to recognise and exclude traffic you have asked us to ignore, for example your own team, developers or agency staff who visit or edit the site, so their activity doesn't blur or distort your analytics. The IP is then stored only as an irreversible, salted hash; we do not retain a readable IP address. The stored hash cannot be used to identify, locate or contact anyone, it can only be matched against a known IP to keep honouring an exclusion (such as continuing to filter out your team, or erasing a visitor's data on request).
5. Cookies and local storage
The CSignal pixel does not set third-party advertising cookies. It stores its pseudonymous visitor and session identifiers in the browser's local and session storage. Because this is analytics technology that is not strictly necessary to run your site, storing it on a visitor's device generally requires consent under the UK's PECR rules, which is why your cookie/consent banner needs to cover CSignal (see section 12).
6. How we keep it secure
Convert data is protected using the measures in the Platform Policy's Security section, including encryption in transit and at rest, least-privilege access controls, and per-store isolation enforced by row-level security so no store can see another's data. Combined with IP hashing (section 4), this keeps the data tightly protected.
7. How long we keep it
We retain raw pixel data for no longer than 12 months, after which it is deleted. Aggregated and anonymised data (including the rollups that power your dashboards and the network insights in section 8) is not personal data and may be kept for longer.
8. Network insights (anonymised)
Pooling data across stores is core to how CSignal works, it is what lets us tell you whether a pattern on your store is unusual or normal, and it is a benefit of being on the network. This is always done using anonymised and aggregated data:
- Network insights describe patterns, never people: no individual visitor can be identified.
- We never expose one store's data to another. Cross-store analysis produces aggregate statistics only.
- Because this pooling is intrinsic to the service, it is not something you switch off, it is part of how CSignal delivers value, but it never involves sharing identifiable data.
9. Sub-processors specific to Convert
In addition to the platform-wide sub-processors in the Platform Policy, Convert data is stored and processed using:
| Category | Purpose | Location |
|---|---|---|
| Primary database hosting | Pixel events, rollups and configuration | EU (London) |
| High-volume analytics event storage | Stores pixel event data at scale | EU (London) |
Each is bound by contract to protect the data and process it only on our instructions.
10. International transfers
Where Convert data is transferred outside the UK/EU, the safeguards described in the Platform Policy's International Transfers section apply.
11. Visitors' rights
Because you are the controller, your visitors' data-protection requests come to you first, and we will help you respond as your processor. In practice:
- A visitor can be excluded and their data erased using the pixel's exclusion mechanism, which removes their events from your store's data.
- We will assist with access, correction, erasure and objection requests that you receive, to the extent the data is within CSignal.
Because the on-page pixel data is pseudonymous and contains no direct identifiers, we may be unable to single out one person from it without additional information you or the visitor provide. The customer lifetime-value data (section 3, Shopify App only) is the exception: it is keyed to a Shopify customer identifier, so a specific customer's records can be located and erased on request, and are removed when that customer is erased from your store.
12. What you must add to your own privacy policy
As the controller, you must tell your visitors that you use CSignal. Please make sure your store's privacy policy (and cookie/consent banner) covers the following:
- That you use CSignal, an analytics tool provided by Charle London Limited, to understand on-site behaviour and improve your store.
- What it collects: pseudonymous behavioural and technical data as described in section 3, and a hashed IP address; it does not collect the content visitors type into forms. If you installed CSignal through the Shopify App, this also includes checkout events (such as completed orders and their value), and, for logged-in customers only, lifetime order statistics (total spent, order count and value-based segments) linked to their Shopify customer identifier, used to measure customer lifetime value.
- Your lawful basis: typically consent (for the storage of identifiers on the device, under PECR) and/or your legitimate interests in improving your store. You are responsible for choosing and, where needed, capturing this.
- Consent: ensure the CSignal pixel is covered by your cookie/consent banner, so that non-essential storage happens with appropriate consent.
- How visitors can opt out, and that they can contact you to exercise their rights.
- That data is processed by Charle as your processor, including anonymised, aggregated network analysis, and may be stored in the EU and transferred under appropriate safeguards.
Sample wording you can adapt:
We use CSignal, a website-analytics tool provided by Charle London Limited, to understand how visitors use our site, such as which pages and sections people look at and where they click, so we can keep improving it. CSignal looks at how the site is used, not who you are. It does not collect your name, contact details, payment information, or anything you type into forms, and it cannot be used to identify you personally. It uses some technical information, such as your device and browser and a securely scrambled (one-way hashed) version of your IP address that cannot be traced back to you, only to keep the analytics accurate. Charle processes this on our behalf, and you can manage your preferences any time in our cookie settings.
This sample is a starting point, not legal advice, please tailor it to your business and take your own advice where needed.
13. Contact
For any question about how Convert handles data, contact us at hello@charle.co.uk. Your visitors should contact you as the controller in the first instance.