Granite – Privacy Policy

Effective 10 June 2026 · Version 1.0


Granite is a customer-communications and CRM platform operated by ConvertedClick (“we”, “us”, “our”). This policy explains what personal information we collect when you use Granite, why we collect it, who we share it with, and the choices and rights you have. We follow South Africa’s Protection of Personal Information Act, 2013 (POPIA).

Two roles to keep in mind:

  • For your own Granite account — your login, your billing, how you use the product — we are the responsible party: we decide how that information is handled.
  • For the contacts, conversations, and other data your business manages inside Granite, you (the Granite customer) are the responsible party and we act as your operator — we process that data on your instructions, to run the service for you.

1. Who we are

Granite is operated by ConvertedClick. If you have any question about this policy or your personal information, email [email protected] and we’ll help.

2. What we collect

Your account. When you sign up we collect your name, email address, password, and the name of your organization or workspace. If you connect a channel such as WhatsApp Business or Google Ads, we store the access tokens and account identifiers those services give us so the integration can work.

Your conversations and content. Granite stores the messages, contacts, deals, forms, automations, and campaigns you and your team create. This is the operational data you hire Granite to manage.

Identifiers and attribution. When you, or a visitor to a Granite-hosted page, arrive, we may record:

  • a durable visitor ID stored in a first-party cookie, used to recognise a returning browser;
  • advertising click identifiers in the page address (such as Google’s gclid or Meta’s fbclid) and campaign tags (UTM parameters), used to understand which campaign brought a visitor;
  • the page address and referrer at the moment of arrival, for diagnostics;
  • any email address or phone number you choose to give us through a form or a WhatsApp conversation. We turn these into a one-way fingerprint (a SHA-256 hash) the moment they reach our database, and the original value is erased before it is stored. We cannot read the original email or phone number afterwards.

Cookies are covered in section 4.

3. How we use your information

  • To run your account and provide the service — the core of our agreement with you.
  • To contact you about your account — service updates, security notices, and billing.
  • To understand and improve how Granite is used — analytics, which you can switch off (see cookies).
  • For advertising and personalisation — only if you switch it on. This lets us share campaign-attribution data with Google and Meta so paid campaigns can be measured. It is off by default and needs your explicit consent under POPIA.
  • To meet our legal obligations — for example keeping financial records.

4. Cookies and your choices

We use three categories of cookies and similar technologies:

  • Necessary — required to log you in, keep your session, and remember basic settings. Always on.
  • Analytics — helps us see how Granite is used so we can improve it. On by default; you can switch it off.
  • Advertising and personalisation — lets us share campaign-attribution data with Google and Meta. Off by default; only on with your explicit consent.

You can review or change these choices at any time using the button below, or by clearing the granite_consent entry in your browser storage.

5. When information is shared or leaves Granite

We do not sell your personal information. We share it only with the service providers that help us run Granite (section 6), when you switch on an integration, or when the law requires it.

Granite has an optional advertising-enrichment feature with two levels:

  • Default (free). We only ever send a non-identifying advertising click identifier (such as gclid) back to the ad platform to measure a conversion. No email or phone number leaves Granite.
  • Enhanced (opt-in). If your business turns this on and the visitor has consented, we send the hashed (one-way fingerprinted) email or phone number to Google Ads and Meta so conversions can be matched. The raw values never leave Granite, because we never store them.

6. Service providers and cross-border transfers

We use a small number of trusted providers, some outside South Africa. POPIA allows this where the provider offers an adequate level of protection through law, contract, or both.

  • Supabase (Singapore) — our main database and backend.
  • Vercel (United States and edge regions) — hosts the Granite web app; no personal information is stored there.
  • Google (Ireland) — only when Enhanced advertising-enrichment is enabled, to measure and match conversions.
  • Meta (Ireland) — only when Enhanced advertising-enrichment is enabled, for the same purpose.

7. Your rights

Under POPIA you have the right to:

  • access the personal information we hold about you and a description of it;
  • correct or delete information that is inaccurate, out of date, or excessive;
  • object to processing we carry out on the basis of legitimate interest;
  • withdraw consent at any time — for example by switching advertising and personalisation off. Withdrawing consent doesn’t undo processing that already happened lawfully;
  • complain to the Information Regulator (South Africa) at inforegulator.org.za.

To exercise any of these, email [email protected]. We respond within the timeframes POPIA requires. Note that hashed identifiers cannot be reversed: for an access request we can confirm whether a value you supply matches a fingerprint we hold and describe how it is used, but we cannot reconstruct the original from our records.

8. How long we keep it

  • Account data — while your account is open, and for a short period afterwards to allow reactivation.
  • Identifiers and attribution data — up to 24 months from your last activity, then deleted.
  • Hashed identifiers — up to 24 months from last activity, then deleted, or sooner if you ask us to erase them.
  • Financial and billing records — up to 7 years, as required by South African company and tax law.

9. If you’re a Granite customer

When you use Granite to manage your own contacts and customers, you are the responsible party for that data and we act as your operator. You are responsible for having a lawful basis to process it and for honouring your customers’ rights. If you turn on Enhanced advertising-enrichment, you become a responsible party for the data shared with Google and Meta and must register your own Information Officer with the Information Regulator under POPIA. We provide onboarding material to help.

10. Contact us

ConvertedClick operates Granite. For any privacy question or request, email [email protected].

11. Changes to this policy

If we make a material change we’ll let account holders know by email and update the date at the top of this page. Where POPIA requires fresh consent for a new purpose, we’ll ask for it. Continuing to use Granite after a change means you accept the updated policy, except where the law requires your renewed consent.