Privacy Policy

Version 1.1 — last updated 2026-08-27. This document describes actual practice and should be reviewed by your own counsel before launch.

Files selected for HEIC conversion are processed locally in your browser. Image contents are not transmitted to our servers, not stored, and not inspected by anyone.

1. Who operates this service

HEIC Convert Free ("we", "us", "the service") is operated by Merkel Digital Ltd., 1771 Robson Street – 1139, Vancouver, BC V6G 3B7, Canada, at heicconvertfree.com. For personal data we determine the purposes and means of processing, we act as controller. Privacy enquiries: info@heicconvertfree.com.

2. Summary

  • Your photos never leave your device and are never received by us.
  • We collect an email address only if you create an account.
  • We never sell or share personal data for cross-context behavioural advertising.
  • We use no advertising or profiling trackers.
  • You can delete your account and associated data at any time.

3. Data we collect

  • Account data: email address, authentication identifiers, hashed credentials held by our authentication provider, sign-in timestamps, account creation date, marketing preference.
  • Subscription and billing data: payment processor customer and subscription identifiers, plan, status, trial end and renewal dates, invoice records, partial card metadata (brand and last four digits) as supplied by the processor.
  • Support data: the email address, category and message you submit through the support form and any subsequent correspondence.
  • Privacy request data: the request type, the details you provide and our record of how the request was handled.
  • Aggregate usage data: date, number of files converted, success and failure counts, chosen output format, and coarse device class. These are counters, not content.
  • Security and operational logs: IP address, user agent, request path, timestamp and error diagnostics, retained for a limited period.

4. Data we do not collect

  • Your photos or any part of their image data.
  • Thumbnails, previews, derivatives or perceptual hashes of your photos.
  • Filenames, folder names or folder paths.
  • EXIF, GPS or other metadata embedded in your images.
  • Payment card numbers, CVC codes or bank credentials.
  • Biometric identifiers, facial recognition data or precise geolocation.
  • Data brokered or purchased from third parties.

5. How local image processing works

Conversion is performed by JavaScript and WebAssembly running inside your browser tab. The file is read from your device with the browser File API, decoded in memory, re-encoded as JPG or PNG, and handed back to the browser as a download or an in-memory ZIP. No network request carries the image, and there is no server-side conversion fallback: if a file cannot be converted on your device, it fails on your device.

Decoded image data lives only in the tab's memory and is released when the page is closed or refreshed. Nothing is written to cookies, localStorage, sessionStorage, IndexedDB or a service worker cache.

6. Purposes and legal bases (UK/EU GDPR)

  • Providing the service and your account — Article 6(1)(b), performance of a contract.
  • Processing payments, invoicing and preventing fraud — Article 6(1)(b) and 6(1)(c).
  • Responding to support and privacy requests — Article 6(1)(b) and 6(1)(c).
  • Securing the service, preventing abuse and understanding aggregate usage — Article 6(1)(f), legitimate interests, balanced against your rights.
  • Marketing email, where you have opted in — Article 6(1)(a), consent, withdrawable at any time.
  • Retaining accounting and tax records — Article 6(1)(c), legal obligation.

7. Payments

Payments are processed by Stripe. Card details are entered on Stripe-hosted pages and are never received, seen or stored by us. We store only processor identifiers and subscription state. Stripe processes your payment information as an independent controller for its own legal, fraud-prevention and compliance purposes and may retain transaction records as required by law. See Stripe's own privacy notice for that processing.

8. Cookies and browser storage

We use essential cookies and browser storage for authentication, security and remembering your converter preferences. No advertising or marketing trackers are installed by default. Full detail, including each key and its lifetime, is on the Cookie Policy page.

9. Service providers and disclosures

We share limited account data with the providers listed on our Subprocessors page, under contracts that restrict them to processing on our instructions. We may also disclose personal data where required by law, valid legal process or a lawful government request; to establish, exercise or defend legal claims; to protect the rights, safety or property of users or the public; or in connection with a merger, acquisition or asset sale, in which case we will notify you before your data becomes subject to a different policy.

We do not sell personal data and we do not share it for targeted advertising.

10. International transfers

Our providers may process data outside your country, including in the United States. Where personal data is transferred out of the UK, EEA or Switzerland we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses together with the UK Addendum, or an applicable adequacy decision. You may request a copy of the relevant safeguards at info@heicconvertfree.com.

11. Retention

  • Account data: retained while your account exists, then deleted or anonymised within 30 days of deletion.
  • Support and privacy request records: up to 24 months, for accountability and dispute handling.
  • Security and operational logs: typically up to 90 days, longer only where an active incident requires it.
  • Aggregate usage counters: retained indefinitely in aggregate form; they contain no personal data.
  • Billing, invoice, tax and accounting records: retained for the period required by applicable law, commonly 6–10 years, even after account deletion.

12. Security

We apply the technical and organisational measures described on the Security page, including HTTPS everywhere, row-level authorisation scoped to the signed-in user, server-side-only secrets, restricted administrative access and audit logging of administrative actions. No system is perfectly secure, but the highest-risk data in a converter — your photographs — is architecturally out of reach because it is never transmitted to us.

13. Personal data breaches

Where a breach affecting personal data is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where required, within 72 hours of becoming aware, and we will notify affected users without undue delay where the risk is high. Because image data is never received by us, a breach of our systems cannot expose your photographs.

14. Your rights (UK/EU and similar regimes)

Subject to local law you may have rights to access your personal data, correct it, delete it, restrict or object to processing, receive it in a portable format, withdraw consent without affecting prior processing, and not be subject to solely automated decisions with legal or similarly significant effects. We do not carry out such automated decision-making or profiling.

Use the Privacy Request page or contact info@heicconvertfree.com. We respond within one month and may extend by two further months for complex requests, telling you why. We verify identity proportionately to the sensitivity of the request and do not charge a fee unless a request is manifestly unfounded or excessive. You also have the right to complain to your local supervisory authority — in the UK, the Information Commissioner's Office.

15. United States state privacy rights

If you are a resident of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana or another state with comparable law, you may have the right to know or access the personal information we collect, to request deletion or correction, to obtain a portable copy, to opt out of sale, sharing or targeted advertising, and not to be discriminated against for exercising these rights.

In the preceding twelve months we have not sold personal information, have not shared it for cross-context behavioural advertising, and have not knowingly collected or sold the personal information of minors under 16. We do not process sensitive personal information for purposes requiring a limitation right. Categories collected map to identifiers, commercial information and internet activity as described in section 3. Submit a request through the Privacy Request page; authorised agents may submit on your behalf with proof of authorisation.

16. Canadian privacy rights

We are established in British Columbia and comply with PIPEDA and BC's Personal Information Protection Act. You may request access to the personal information we hold about you, request correction of inaccuracies, and withdraw consent subject to legal or contractual restrictions — we will tell you the consequences of withdrawal. We collect only what is reasonable for the purposes identified in this policy. Complaints can be made to us at info@heicconvertfree.com, to the Office of the Privacy Commissioner of Canada, or to the Office of the Information and Privacy Commissioner for British Columbia. Some of our providers store data outside Canada, principally in the United States, where it may be accessible to foreign courts and law enforcement under local law.

17. Do Not Track and global privacy signals

We do not run cross-site tracking, so there is nothing for a Do Not Track header to disable. Where we are required to honour an opt-out preference signal such as Global Privacy Control, we treat it as a valid opt-out of sale and sharing — which we do not engage in regardless.

18. Children

The service is not directed to children under 16 (or the minimum age required for an account where you live, if higher) and we do not knowingly collect their personal data. If you believe a child has provided us with personal data, contact info@heicconvertfree.com and we will delete it.

19. Changes

We will update this policy when our practices change and will revise the version and date at the top. Material changes will be notified in-app or by email at least 14 days before they take effect where practicable. Previous versions are available on request.

20. Contact

info@heicconvertfree.comMerkel Digital Ltd., 1771 Robson Street – 1139, Vancouver, BC V6G 3B7, Canada.