Information Clarvivo collects
Account data may include your email address, name, company, team size, timezone, authentication method, subscription status, usage totals, and account activity. Passwordless sign-in also creates a short-lived token and expiry record. Google sign-in provides your email address and profile name.
When the Clarvivo script runs on a customer site, it can send the page URL, page title, referrer, page path, query string, URL fragment, random visitor and session identifiers, user agent, screen resolution, browser language, campaign parameters, and custom event properties. Clarvivo derives device, browser, operating system, approximate location, traffic source, session, and new or returning visitor information from those events.
For commerce and revenue attribution, Clarvivo can receive product, cart, order, currency, revenue, refund, subscription, campaign, and payment-provider reference data. Connected payment providers may also send a customer email address. Clarvivo does not need or intend to collect payment card numbers or security codes.
Connected services can add data and credentials needed for that connection. For example, Google Search Console provides query and page performance data, Shopify provides store and order data within the approved scopes, and customer-configured webhooks provide payment events. Customers choose which integrations to enable.
Cookies and first-party browser storage
The Clarvivo tracking script does not set cookies. It stores a random visitor identifier and first-touch and last-touch attribution values in the measured site's localStorage. It stores the current session identifier, current campaign values, and cart identifier in sessionStorage. localStorage remains until it is cleared by the visitor or the site. sessionStorage normally ends when the browser tab or session ends.
The Clarvivo dashboard uses a first-party session cookie to keep account holders signed in. The cookie is HttpOnly, SameSite=Lax, Secure in production, and configured with a 30-day maximum age. It is used for authentication, not advertising.
Clarvivo's own marketing site and dashboard load the Crisp support chat, which is a third-party script that sets its own cookies and browser storage to keep a conversation attached to the same person across visits. This applies to clarvivo.com and app.clarvivo.com. It is not part of the Clarvivo tracking script and is never loaded onto a customer's measured site.
Browser storage can still be regulated even when it is not a cookie. Each Clarvivo customer is responsible for deciding whether its use requires consent, notice, or an opt-out under the laws that apply to that site.
How information is used
Clarvivo uses information to operate accounts, authenticate users, measure site activity, connect visits with payments, create dashboards and exports, provide integrations, answer support requests, secure the service, prevent abuse, bill subscriptions, and send service messages.
Where applicable, Clarvivo relies on the performance of a contract, legitimate interests in operating and securing the service, compliance with legal obligations, or consent. When Clarvivo processes site-visitor data for a customer, the customer is responsible for selecting and documenting the appropriate legal basis.
Clarvivo does not sell personal information, share it with advertising networks, build cross-site profiles, or use customer analytics data for behavioural advertising.
AI insights and chat
When an account holder requests an AI insight, chat answer, or weekly summary, Clarvivo sends Groq the project name and the selected analytics context needed to answer the request. Depending on the feature, that context can include aggregated traffic, conversion, revenue, campaign, page, and daily performance data. Chat questions and responses are stored with the Clarvivo project.
Traffic forecasts are computed locally from the project's analytics history and are not sent to Groq. Do not include sensitive personal information in an AI question or custom tracking property.
Service providers and data transfers
Clarvivo uses Supabase for PostgreSQL database and session storage, Vercel for application hosting and network delivery, Dodo Payments for subscription billing, Resend for transactional email, Google for optional sign-in and Search Console connections, Groq for requested AI features, Crisp for support chat on Clarvivo's own site and dashboard, and ipwho.is to turn a network address into an approximate location. Customer-selected services such as Stripe, Razorpay, Paddle, Polar, LemonSqueezy, and Shopify process data under their own terms when connected.
These providers may process information in countries other than the country where it was collected. Clarvivo does not currently publish a fixed data-region commitment or a public standard DPA. If your organisation requires a particular storage region, transfer mechanism, or DPA, contact Clarvivo before connecting production data.
IP addresses and location
Network addresses may be received briefly at the application edge. Clarvivo uses them for abuse protection and, where available, approximate location. Rate-limiting identifiers are hashed before storage, and Clarvivo's analytics schema does not include a raw IP-address field.
To derive approximate country, region, city, latitude, and longitude for analytics and the real-time activity view, Clarvivo sends the visitor's network address to ipwho.is, a third-party lookup service, and falls back to the location supplied by hosting-network headers when that lookup is unavailable. Results are cached briefly so a repeat visit does not repeat the lookup. Clarvivo does not use precise GPS location.
Retention and deletion
Core analytics, commerce, revenue, chat, and account records are currently kept while the relevant project or account remains active. Clarvivo does not currently apply a general age-based deletion schedule to those records. Durable analytics session records are cleaned after 45 days. Real-time session and event records are cleaned after approximately 5 and 10 minutes respectively.
A project owner can delete a project from the service. Clarvivo deletes the project's associated analytics, commerce, revenue, goal, alert, insight, chat, membership, and related project records through the project-deletion process. Clarvivo does not currently offer self-service account deletion. Contact Clarvivo to request account deletion or assistance with a project deletion.
Clarvivo does not currently publish a separate backup-retention schedule. Billing providers may retain transaction records when required for tax, accounting, fraud prevention, or other legal obligations.
Security
Clarvivo uses access controls, signed sessions, restricted project access, webhook verification, rate limiting, and encrypted network transport to protect the service. Integration credentials are not returned in normal project-settings responses. No system is completely secure, so Clarvivo cannot guarantee that unauthorised access will never occur.
Customers are responsible for protecting their account, limiting team access, securing integration secrets, and avoiding sensitive personal information in page URLs, query strings, custom properties, or AI questions.
Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal data. You may also have the right to complain to a data-protection authority. Contact Clarvivo to make a request concerning account data.
If you are a visitor to a site using Clarvivo, contact that site's owner first. The site owner controls the analytics and payment data and can identify the project involved. Clarvivo will assist its customer with valid requests as required by applicable law.
You can clear the measured site's localStorage and sessionStorage through your browser controls. Blocking the Clarvivo script prevents new browser events from being sent, but does not delete data already collected.
Children and sensitive information
Clarvivo is a business analytics service and is not directed to children. Customers must not configure Clarvivo to collect children's data or sensitive personal information unless they have a lawful basis and have completed any required safeguards.
Changes to this policy
Clarvivo may update this policy when the product, providers, or legal requirements change. The date at the top shows the latest revision. Material changes will be communicated through the service or by email when appropriate.
Questions or requests
Contact Clarvivo at support@clarvivo.com. If your request concerns data collected by a customer using Clarvivo, contact that website or business first.