Maps Fixer
For Businesses
Free Fix

Privacy Policy.

How Conversionate LLC collects, uses, shares, retains, and protects personal information across every product we offer.

Last updated: May 28, 2026

TL;DR — The Quick Version

30-day default retention

Maps Fixer optimization data auto-deletes 30 days after the engagement ends.

We never sell your data

Not to advertisers, not to brokers, not to anyone. Period.

GDPR + CCPA aligned

EU and California rights honored for every user, including access, correction, and deletion.

Delete on request

Email us and we wipe what we hold, subject only to legal retention duties.

The TL;DR above is a plain-English summary for your convenience. It is not a legal substitute for the full document below. If the TL;DR and the full document conflict, the full document controls.

1. Who we are and how to reach us

This Privacy Policy (“Policy”) explains how Conversionate LLC, a Wyoming limited liability company (“Conversionate,” “we,” “our,” or “us”), collects, uses, discloses, retains, transfers, and protects personal information about you when you visit conversionate.com, gmaps.conversionate.com, any successor or related domain, or when you otherwise interact with any of the products, services, websites, mobile applications, APIs, content, features, or communications we make available (collectively, the “Services”).

This Policy is part of, and incorporated by reference into, our Terms & Conditions, Acceptable Use Policy, and Subscription Agreement. Capitalized terms used but not defined here have the meanings given in the Terms & Conditions.

For privacy questions, requests, or notices, contact us at hello@conversionate.com (subject line “Privacy Request”). Our registered mailing address is Conversionate LLC, 312 W 2nd St Unit A3707, Casper, WY 82601, United States.

For users in the European Economic Area, the United Kingdom, or Switzerland, Conversionate is the data controller of your personal information in respect of the Services. Where we process personal information on behalf of one of our customers, that customer is the controller and we are the processor.

2. Information we collect

We collect personal information in the following categories.

(a) Information you provide directly. When you create an account, place an order, complete a form, contact support, or otherwise communicate with us, you may provide: your name, email address, phone number, business name, billing address, payment information (which is collected and processed by our payment processor, not by us), and any other information you choose to provide. For users of Google Maps Fixer, you also provide the Google Maps URL of the business profile you want analyzed.

(b) Information we collect automatically. When you access or use the Services, we automatically collect log data (browser type and version, operating system, IP address, access times, pages viewed, referring URLs, exit pages, and the route you took through the Services), device identifiers, and information stored in cookies and similar technologies (see Section 7).

(c) Information obtained from Google APIs. When you connect a Google account to apply Maps Fixer changes, we obtain (i) basic profile information (name, email address, profile picture) for authentication; and (ii) read/write access to the Google Business Profile(s) you own or manage for the limited purpose of applying the changes you have explicitly approved. Our handling of this data is subject to the Google API Services User Data Policy and the Limited Use restrictions described in Section 6.

(d) Information from public sources. For Maps Fixer, we retrieve publicly available business profile data (categories, description, services, ratings, review text, photos, opening hours) from Google Maps and from data providers that index those public listings.

(e) Information from our customers about their end users. When you use our subscription products to manage your own customer relationships, you may submit personal information about your customers, employees, or contacts (collectively, “Customer Personal Information”). Conversionate processes Customer Personal Information on behalf of you, the customer, as a processor.

(f) Information from advertising partners. We may receive information from advertising platforms about how users arrived at the Services (e.g. campaign identifiers, referring ad creative) and combine it with information we already hold about you for the purposes described in Section 3.

3. How we use information

We use the information we collect to:

  • provide, operate, maintain, secure, and improve the Services;
  • create, manage, and authenticate your account, including authenticating sign-ins through third-party identity providers (such as Google) you choose to use;
  • process payments, deliver invoices, handle refunds, and comply with related accounting and tax obligations;
  • apply the specific changes you have approved to Google Business Profiles you own or manage (Maps Fixer only);
  • send transactional, security, and administrative communications (e.g. receipts, account notices, security alerts);
  • with your separate consent or where permitted by law, send marketing communications and product updates;
  • monitor and analyze trends, usage, and activity to improve the Services and develop new features;
  • detect, investigate, prevent, and respond to fraud, abuse, and security incidents and to enforce our Terms & Conditions and Acceptable Use Policy;
  • comply with applicable law, lawful government requests, court orders, subpoenas, and the policies of third-party platforms we rely on;
  • personalize content and recommendations within the Services (but not for cross-site behavioral advertising);
  • train and improve our own non-AI features through aggregated, de-identified analysis;
  • carry out any other purpose described to you at the time the information was collected or for which you give consent.

We do not train third-party generative-AI models on your personal information. When we send data to third-party AI providers (such as OpenAI or Anthropic) to power features inside the Services, we instruct those providers under their enterprise terms to not use the data for training their generally-available models.

4. How we comply with applicable privacy laws

Conversionate is a United States company, and the majority of our users are in the United States. We design our privacy practices around the framework of federal U.S. law, state U.S. privacy laws (including, without limitation, the California Consumer Privacy Act as amended by the California Privacy Rights Act (collectively, “CCPA/CPRA”), the Virginia Consumer Data Protection Act (“VCDPA”), the Colorado Privacy Act (“CPA”), the Connecticut Data Privacy Act (“CTDPA”), the Utah Consumer Privacy Act (“UCPA”), and the Texas Data Privacy and Security Act (“TDPSA”)), and other applicable state privacy laws. Where U.S. federal law applies to specific activities (for example, the CAN-SPAM Act and Telephone Consumer Protection Act for marketing communications, the Children’s Online Privacy Protection Act for users under 13, and the Federal Trade Commission Act for unfair or deceptive practices), we comply with those laws as well.

For users located in the European Economic Area, the United Kingdom, or Switzerland, we additionally rely on the following lawful bases under GDPR Article 6 and the equivalent provisions of UK GDPR and the Swiss FADP: performance of a contract; legitimate interests (securing the Services, preventing fraud, performing pseudonymous analytics to improve the product, and pursuing our ordinary business interests in a manner not overridden by your fundamental rights); consent (for marketing communications, optional analytics cookies, and other processing where required by law); and compliance with legal obligations (retention, accounting, tax, and lawful requests). Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

5. How we share information

We share personal information only as follows:

  • Service providers and sub-processors we engage to operate the Services (see Section 6) under written agreements that require them to protect the information and use it only for the purposes we specify.
  • Payment processors, currently Stripe, to process your transactions and detect payment fraud. We do not store full payment-card numbers ourselves.
  • Professional advisors (lawyers, accountants, insurers, auditors) under duties of confidentiality.
  • Authorities and other parties where we believe in good faith that disclosure is required by law, legal process, court order, subpoena, or governmental request, or is reasonably necessary to investigate, prevent, or respond to fraud, security incidents, or other harm.
  • Successors in connection with, or during negotiations of, any merger, acquisition, financing, reorganization, bankruptcy, receivership, sale of company assets, or transition of service to another provider.
  • Affiliates and group companies for the purposes described in this Policy, under confidentiality and data-processing obligations no less protective than those of this Policy.
  • Aggregated or de-identified information that cannot reasonably be used to identify any individual, for any purpose, including marketing, research, and benchmarking.
  • With your consent or at your direction.

We do not sell or rent your personal information. We do not share your personal information with third parties for their independent direct-marketing or advertising purposes.

6. Categories of third parties and Google API data

To operate the Services, we engage third-party service providers that act on our documented instructions under a written data-processing or similar agreement. We disclose these third parties by category, consistent with the requirements of the CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, TDPSA, other applicable U.S. state privacy laws, and GDPR Article 13. The categories include:

  • Payment processing. A PCI-compliant payment processor handles your transactions and detects payment fraud. Our current payment processor is Stripe; you can review Stripe’s privacy practices at the preceding link.
  • Google APIs. When you use Maps Fixer, we interact with Google APIs (including the Business Profile API and Google identity services). Google’s privacy practices are described in the Google Privacy Policy. See also the Limited Use disclosure below.
  • Cloud infrastructure and hosting. Compute, database, edge networking, caching, message-queue, and content-delivery providers that host the Services.
  • Data sources. Providers that supply publicly available business-profile and search-result data for the Services.
  • AI providers. Large-language-model providers that power AI features. Where we send data to these providers, we do so under enterprise terms that prohibit training on submitted data.
  • Email and messaging delivery. Providers that send transactional, notification, and (with your consent or as otherwise permitted by law) marketing communications.
  • Product analytics and session monitoring. Providers that help us understand how the Services are used and detect bugs. Session recordings are pseudonymous, mask form inputs and sensitive details, and auto-delete on short retention periods.
  • Security, fraud prevention, and CAPTCHA. Providers that protect against DDoS attacks, abuse, credential-stuffing, and bot activity.
  • Professional advisors. Lawyers, accountants, insurers, and auditors under duties of confidentiality.

We may add, change, or replace providers in any category at any time without updating this Policy, so long as the new provider is bound by substantially equivalent confidentiality and data-protection obligations. The specific providers we use at any given time may be listed on a sub-processor page or supplied on written request.

Google API Services User Data — Limited Use disclosure. Conversionate’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: (i) we use Google user data only to provide or improve the user-facing features that are prominent in the application’s user interface; (ii) we do not transfer Google user data to third parties except as necessary to provide or improve the user-facing features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users; (iii) we do not use Google user data for serving advertisements, including retargeting or interest-based advertising; and (iv) we do not allow humans to read Google user data except (a) with the user’s express consent for specific data, (b) where necessary for security purposes (including investigating abuse), (c) where required to comply with applicable law, or (d) where the data has been aggregated and anonymized so it cannot be used to identify any individual.

7. Cookies and similar technologies

We use cookies, local storage, pixels, web beacons, and similar technologies (collectively, “Cookies”) for: (a) strictly necessary functions (authentication, security, load balancing, fraud prevention); (b) preferences (remembering your settings); and (c) analytics (understanding how the Services are used in aggregate). We do not use Cookies for third-party advertising or cross-site behavioral tracking.

You can control non-essential Cookies through your browser settings, by enabling “Do Not Track,” or, where a cookie banner is presented, by adjusting your preferences there. Disabling Cookies may degrade or prevent use of parts of the Services. Where required by law, we obtain consent before placing non-essential Cookies.

8. Data retention

We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, tax, dispute-resolution, or reporting requirements. Specifically:

  • Maps Fixer optimization data (business profile snapshot, generated fixes, ranking snapshots): auto-deleted 30 days after the engagement ends.
  • OAuth tokens for Google Business Profile: stored until you revoke access or terminate your account with us, whichever is earlier; rotated and re-encrypted as needed for security.
  • Payment and billing records: retained for up to seven (7) years to comply with tax and accounting laws.
  • Subscription product customer records: retained for the duration of the subscription and for a reasonable period after termination as needed for legitimate business purposes (e.g. dispute defense, recovery of fees).
  • Email logs and communications: up to twelve (12) months, or shorter if you request deletion.
  • Security and audit logs: up to two (2) years, longer if needed for an active investigation.

After the applicable retention period, we delete or irreversibly anonymize the information.

9. International data transfers

Conversionate is based in the United States. Many of our third-party processors store and process data in the United States or in other countries. By using the Services, you understand that your personal information will be transferred to, stored in, and processed in countries (including the United States) where data-protection laws may differ from those of your jurisdiction.

Where we transfer personal information of users in the European Economic Area, the United Kingdom, or Switzerland to a country that is not the subject of a European Commission adequacy decision, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses and any applicable U.K. or Swiss addendum, or on a derogation under GDPR Article 49 where applicable.

10. Your privacy rights (U.S. and international)

Subject to applicable law and to verification of your identity, you have the right to:

  • Know / Access the personal information we hold about you and obtain a copy. (Available under CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, TDPSA, GDPR, and equivalent laws.)
  • Correct / Rectify inaccurate or incomplete personal information. (CCPA/CPRA, VCDPA, CPA, CTDPA, TDPSA, GDPR.)
  • Delete / Erase personal information in certain circumstances (the “right to be forgotten” under GDPR; the right to delete under CCPA/CPRA and other state laws).
  • Opt out of sale, sharing, or targeted advertising. We do not sell or share personal information for cross-context behavioral advertising as those terms are defined under CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, TDPSA, and other applicable state laws, and therefore no separate opt-out is currently required.
  • Restrict our processing of personal information in certain circumstances (GDPR; analogous rights under certain state laws).
  • Portability — receive personal information in a structured, commonly used, machine-readable format.
  • Object to processing based on legitimate interests, including profiling, and to direct marketing.
  • Limit use of sensitive personal information. We do not use sensitive personal information for purposes that would trigger this right under CCPA/CPRA.
  • Non-discrimination. We will not deny, charge different prices for, or provide a different level or quality of Services because you exercised any of these rights.
  • Appeal our decision on a privacy request (where required by VCDPA, CPA, CTDPA, TDPSA, or other state laws). You may submit an appeal by replying to our response with the word “Appeal” in the subject line; we will respond within 60 days. If the appeal is denied, you may contact your state attorney general.
  • Withdraw consent at any time, where processing is based on consent.
  • Lodge a complaint with the U.S. Federal Trade Commission, your state attorney general, or, for EU/UK/Swiss users, your local data-protection supervisory authority. We would, of course, appreciate the chance to address your concerns directly first.

How to exercise these rights. Email hello@conversionate.com with subject line “Privacy Request” (or “California Privacy Request” if you are a California resident). We may require verification of your identity before fulfilling a request. You may use an authorized agent; we may require written permission and verification of the agent’s authority. We aim to respond within 45 days; complex requests may take up to an additional 45 days, in which case we will notify you. There is no charge for the first request in any 12-month period.

11. State-specific U.S. privacy disclosures

California (CCPA/CPRA). We collect the categories of personal information described in Section 2 for the business and commercial purposes described in Section 3, and we disclose them to the categories of third parties described in Section 6. We do not sell personal information or share it for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA, and we have not done so in the prior 12 months. Personal information is retained for the periods described in Section 8. California residents have the rights described in Section 10, including the rights to know, delete, correct, limit use of sensitive personal information, and non-discrimination.

Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), and other state privacy laws. If you are a resident of a U.S. state that has enacted a comprehensive consumer privacy law, you may have rights similar to those described in Section 10, subject to the eligibility thresholds and definitions of the applicable law. We honor these rights as set out in each applicable law, including the right to appeal a denied request to us before contacting your state attorney general.

“Shine the Light” (California Civil Code § 1798.83). California residents may request, once per year, a list of categories of personal information we disclosed to third parties for their direct-marketing purposes during the prior calendar year. We do not disclose personal information to third parties for their independent direct-marketing purposes.

“Do Not Track.” Our Services do not respond to Do-Not-Track signals other than as described in Section 7, because there is no industry-standard interpretation of those signals. We do honor opt-out signals recognized under applicable state laws (such as the Global Privacy Control) for opt-outs of sale or sharing, to the extent applicable to our processing.

To exercise any of the rights described in this Section, email hello@conversionate.com.

12. Customer Personal Information (processor role)

When Conversionate processes personal information on behalf of a customer in connection with that customer’s use of the Services (“Customer Personal Information”), we act as a processor under instructions of the customer. Individuals seeking to access, correct, delete, or restrict processing of Customer Personal Information should direct their request to the applicable customer. We will assist the customer in responding within a reasonable time and as required by applicable law. We do not use Customer Personal Information for any purpose other than providing and supporting the Services for that customer.

13. Security

We implement reasonable and appropriate physical, technical, and organizational measures to protect personal information against unauthorized access, alteration, disclosure, loss, and destruction, including (without limitation) encryption in transit (TLS), encryption at rest, role-based access controls, audit logging, network segmentation, secure credential storage, and regular security review.

No transmission over the internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security. You are responsible for keeping your account credentials confidential.

14. Children's privacy (COPPA)

The Services are intended for adult business users and are not directed to children. Consistent with the U.S. Children’s Online Privacy Protection Act (“COPPA”), we do not knowingly collect personal information from children under 13 years of age. Consistent with the higher protections of GDPR and certain state laws, we also do not knowingly collect personal information from individuals under 16 years of age. If you believe we have inadvertently collected personal information from a child under the applicable age, please contact us at hello@conversionate.com and we will take prompt steps to delete it.

15. Marketing communications (CAN-SPAM and TCPA)

With your consent or where otherwise permitted by law, we may send you marketing emails about Conversionate products and offers. All of our commercial email communications comply with the U.S. CAN-SPAM Act (15 U.S.C. § 7701 et seq.): they include accurate sender identification, a truthful subject line, our valid postal address, and a functional unsubscribe mechanism. You can opt out at any time by clicking the unsubscribe link in any marketing email or by emailing hello@conversionate.com; we will honor opt-out requests within 10 business days as required by CAN-SPAM.

If you receive SMS or other telephone-based marketing from us, you may opt out at any time by replying STOP to any marketing message or by contacting us. We do not place marketing calls or send marketing text messages without prior express written consent where the U.S. Telephone Consumer Protection Act (“TCPA”), 47 U.S.C. § 227, or any analogous state law requires it.

Opting out of marketing does not stop transactional or service messages such as receipts, security alerts, account notices, and similar communications that we are required or authorized to send to operate the Services.

16. Automated decision-making

We do not make decisions about you that produce legal effects or similarly significant effects based solely on automated processing or profiling. AI Output (including Maps Fixer recommendations and CRM-style suggestions) is generated for your review and is applied only after you have approved it.

17. External links

The Services may contain links to or integrations with third-party websites and services not operated by us. We are not responsible for the privacy practices of those third parties. Please review their privacy notices before submitting any personal information.

18. Changes to this Policy

We may revise this Policy from time to time. If we make material changes, we will update the “Last updated” date at the top and, where required by law, provide additional notice (such as by email or by an in-app notice). Your continued use of the Services after the effective date constitutes acceptance of the revised Policy.

19. Disclosures required by law and business transfers

We may disclose personal information when reasonably necessary to comply with applicable law, lawful government requests, court orders, subpoenas, or legal process; to enforce or apply the Terms & Conditions; or to protect the rights, property, or safety of Conversionate, our users, or others. In the event of a merger, acquisition, financing, reorganization, bankruptcy, receivership, sale of company assets, or transition of service to another provider, personal information may be transferred to a successor or acquirer.

20. Contact

For privacy questions, requests, or notices, contact:

Conversionate LLC
State of Wyoming, USA
Email: hello@conversionate.com (subject line “Privacy Request”)

Questions about this document?

Reach out and we’ll explain anything in plain English. For urgent legal notices, use the formal address listed inside the document.

Contact Us

Other legal documents

  • Terms & Conditions
  • Acceptable Use Policy
  • Subscription Agreement
  • ·
  • Back to Home
Conversionate

Get Found.
Get Booked.
Get Regulars.
Get Your Time Back.

Legal

  • Privacy Policy
  • Terms & Conditions
  • Acceptable Use

Contact

  • hello@conversionate.com
  • +1 (833) 381-1160
  • Conversionate LLC · Wyoming, USA

© 2026 Conversionate LLC. All rights reserved.