Conversion UploaderSign in
New North Digital · Legal

Privacy Policy

Last updated: 26 June 2026

Conversion Uploader is operated by New North Digital("NND", "we"), an analytics agency based in the Netherlands. This policy explains what personal data the tool processes, why, and how. Questions: hello@newnorth.nl.

Our two roles

We act in two different roles, and which one applies depends on whose data it is:

  • Processor.When we upload conversions for one of our clients, the client is the controller of that data and decides why it is processed. We process it on the client's documented instructions under a data processing agreement (DPA). Most of this policy describes that processing.
  • Controller. For this public website and for people who contact us by email, NND is the controller of the limited data involved.

What the tool processes (on behalf of clients)

For each conversion the tool handles a small, fixed set of fields, read from a source the client controls (a Google Sheet, a BigQuery query, a CRM or website webhook, a CSV upload, or a connected business system such as Exact Online):

  • Contact identifiers — email address and/or phone number, hashed with SHA-256 before transmission. They are not retained in readable form after a row is processed. One exception, stated plainly because it matters: where a source delivers data by webhook or CSV upload, the payload we receive is stored encrypted at rest until it is consumed and its retention period expires, and that payload contains the address as the client sent it.
  • Name and address components — first name, last name, postal code and country, but only where a client has explicitly mapped those columns. Names are hashed; postal code and country are sent to Google unhashed, because Google's matching requires them in plain form.
  • Online identifiers — Google click ids (gclid, gbraid, wbraid) and the GA4 client id, where present. Also a session-attributes blob collected on the client's website, which describes the visit that produced the click (landing page, referrer, campaign parameters).
  • Conversion details — a transaction id, the conversion value and currency, and the conversion time.
  • Consent signals — the data subject's consent for ad user data and ad personalization, as provided by the source.

We do not collect special-category data, and we read only the fields above from the source. Where the source is an accounting or CRM system, we deliberately read the minimum needed and do not replicate the client's wider records.

What we do with it

  • Normalize and de-duplicate rows by transaction id so nothing double-counts.
  • Hash email, phone and name components before transmission. Postal code and country are the exception and travel unhashed, because Google's matching requires it.
  • Enforce consent. For data subjects in the EEA, any row that does not carry consent for ad user data is dropped and never sent. A client may instead configure a source to run on a documented legal basis, which treats every row from that source as consented; that is a deliberate setting, it is recorded on the source and logged on every run that relies on it, and the client is responsible for the basis.
  • Build audience lists. Where a client enables it, the same hashed identifiers are also added to Google Customer Match lists. That is advertising targeting rather than measurement, and it happens only for clients who switch it on.
  • Send the resulting conversions to Google (Google Ads and/or Google Analytics 4) through Google's Data Manager API, so the client can measure advertising results.
  • Reconcile each batch: we record how many conversions Google accepted, rejected (with the reason) or is still processing, so the client can see and fix problems.

Legal basis and consent

For conversion data processed through the tool, the client is the controller and NND acts solely as processor, on the client's documented instructions and on the basis of our contract and data processing agreement. Collecting, recording, maintaining and evidencing a valid legal basis, including any consent from data subjects, for using contact data for advertising measurement and personalisation is and remains the client's sole responsibility.

We rely on the consent signal or documented legal basis the client supplies per source and do not independently verify it. As a safeguard the tool transmits ad-related identifiers only where consent is indicated and drops rows that do not carry the required consent for data subjects in the EEA, in line with Google's EU user consent policy; this technical control does not transfer or reduce the client's responsibility.

Retention

  • Hashed and pseudonymous references (such as the transaction id) and aggregate reconciliation counts are retained to run the service and report results.
  • Raw payloads received via webhook or CSV are encrypted at rest and deleted on a configurable schedule, 30 days by default. An absolute ceiling also applies: no such payload is kept beyond the greater of three times the configured period or 90 days, whichever is longer, so an unconsumed event from a paused source cannot be retained indefinitely.
  • Order ids paired with click ids, and email digests paired with click ids, are kept 120 days: long enough to cover Google's 90-day click window plus the lag before an invoice appears.
  • Transaction references used for de-duplication are kept 180 days.
  • Outside those payloads, no readable email address or phone number is retained after hashing.

Recipients and sub-processors

To deliver the service we use:

PartyPurpose
GoogleRecipient of the conversions (Google Ads / GA4) for advertising measurement
VercelApplication hosting
NeonDatabase
ResendOperational email alerts, to the operator and, where a client provides an address, to the client

Some of these providers may process data outside the EEA (for example in the United States). Where that happens, transfers are covered by appropriate safeguards such as the EU Standard Contractual Clauses. The full, current list with locations and safeguards is at /subprocessors; EU-region hosting is available for clients that require EU data residency.

Security

Data is encrypted in transit and at rest, contact identifiers are hashed, the operator console is access-controlled, and secrets are held in environment configuration rather than in code. Uploads can be paused with a global kill-switch and are subject to per-run volume and value caps.

Your rights

If your data was processed because you are a customer or lead of one of our clients, the client is the controller and your rights (access, rectification, erasure, objection, restriction) are exercised with them. We assist our clients in responding to such requests. You can also reach us at hello@newnorth.nl and we will route the request appropriately. You may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

This website

The public Conversion Uploader website does not set marketing or advertising cookies. If you email us, we use your message and contact details only to respond.

Changes

We may update this policy. The current version is always shown here with its "last updated" date. For questions, contact hello@newnorth.nl.