Skip to content

Privacy

A plain-language map of the data Tactrail handles.

This page describes the current release candidate. It separates observed product behavior from legal commitments that still require an identified operator, contracts, and deployment decisions.

Pre-release legal notice. The legal operator name and registered contact address have not been configured, so this is not yet a complete statutory privacy notice. Tactrail must not onboard external production data until those details, the lawful basis, retention schedule, transfer mechanism, and final subprocessor register have been reviewed and published.

Roles and scope

Who decides how data is used

The merchant or workspace customer normally decides why shopper, order, and support data is handled. Tactrail is designed to process that data on the customer's instructions. The exact legal roles can vary by jurisdiction and use case and must be stated in the signed customer agreement and data-processing terms.

For account administration, security, billing, and operation of the public website, the product operator may make separate decisions about processing. This page does not assign a lawful basis on behalf of a merchant or claim that every configured use is lawful.

Current product data map

Account and workspace data

Examples
Email address, authentication identifier, organization, membership role, invitations, plan, and workspace configuration.
Product purpose
Create accounts, authorize access, operate workspaces, and administer subscriptions.

Store and integration data

Examples
Shopify shop domain, store settings, locale, currency, store guidance, email-domain configuration, connector scopes, and encrypted access credentials.
Product purpose
Connect an authorized store, synchronize operational context, and send or receive support email.

Shopper and commerce data

Examples
Customer name, email, phone, locale, order number and status, totals, fulfillment, carrier, and tracking events received from the connected store.
Product purpose
Identify the relevant order, answer support questions, route requests, and display context to authorized workspace members.

Support communications

Examples
Sender and recipient details, subject, email bodies, message headers, conversation references, attachment metadata, drafts, replies, and delivery identifiers.
Product purpose
Build and display a conversation, classify intent, draft or deliver replies, and reconcile provider outcomes.

Requests and service operations

Examples
Exchange, refund, cancellation, or withdrawal request details; reason if voluntarily supplied; opaque receipt token; webhook IDs; usage counts; and operational error state.
Product purpose
Process a requested workflow, avoid duplicates, enforce limits, investigate failures, and maintain service continuity.

Where data comes from

Data can be supplied by workspace users, connected Shopify stores, inbound email, customer-facing request and tracking forms, and service providers returning delivery, billing, or authentication events. Customers should only connect stores and mailboxes they are authorized to administer.

AI processing

When an AI workflow runs, relevant support text, store guidance, conversation history, and available order context can be sent to the configured model provider to classify or draft a response. Human-only mode skips generation. Automatic delivery is disabled by default.

No statement is made here that a third-party model provider will never retain or train on submitted data; that depends on the commercial terms and configuration selected for production and must be verified before launch.

Current service integrations

The application contains integrations with Supabase for database and authentication, Shopify for store data, Postmark for email, Anthropic for AI generation, and Stripe for subscription billing. A deployment host and its infrastructure providers may also process connection and operational data.

This is a technical inventory, not a finalized subprocessor register. Contracting entity, location, processing region, transfer safeguards, and retention terms must be confirmed for the production accounts.

Cookies and public-site tracking

Authenticated pages use essential session cookies and a workspace preference cookie. The current public-site code does not include an advertising tracker. Hosting, CDN, and security services may still create request logs; their production configuration must be reflected in the final notice.

Retention and deletion

The current release candidate does not implement a complete automated retention schedule or self-service workspace export and deletion workflow. Database relationships support removal of many workspace records with the organization, but backups, provider copies, billing evidence, security logs, and legally required records need explicit policies.

A production agreement must define retention windows, deletion and export procedures, backup expiry, and what happens when a subscription ends.

Requests and choices

Shoppers should first contact the merchant responsible for the store. Workspace users can ask their workspace owner to correct membership or account information. Identity and authority must be verified before a request is fulfilled.

A monitored operator privacy contact has not yet been configured. Publishing one, together with a verified request procedure, is a release requirement.

International use and children

Tactrail is intended for business support operations, not for use by children. Global storefronts may create cross-border processing. This page does not claim that a particular data location or transfer mechanism applies until the production accounts and contracts have been selected and documented.

Merchants remain responsible for giving their shoppers an accurate notice and for configuring the service consistently with applicable law and their own promises.

Last updated: . Material changes should be dated here and communicated through an appropriate customer channel.