Privacy
A plain-language map of the data Tactrail handles.
This page describes the current release candidate. It separates observed product behavior from legal commitments that still require an identified operator, contracts, and deployment decisions.
Pre-release legal notice. The legal operator name and registered contact address have not been configured, so this is not yet a complete statutory privacy notice. Tactrail must not onboard external production data until those details, the lawful basis, retention schedule, transfer mechanism, and final subprocessor register have been reviewed and published.
Roles and scope
Who decides how data is used
The merchant or workspace customer normally decides why shopper, order, and support data is handled. Tactrail is designed to process that data on the customer's instructions. The exact legal roles can vary by jurisdiction and use case and must be stated in the signed customer agreement and data-processing terms.
For account administration, security, billing, and operation of the public website, the product operator may make separate decisions about processing. This page does not assign a lawful basis on behalf of a merchant or claim that every configured use is lawful.
Current product data map
Account and workspace data
- Examples
- Email address, authentication identifier, organization, membership role, invitations, plan, and workspace configuration.
- Product purpose
- Create accounts, authorize access, operate workspaces, and administer subscriptions.
Store and integration data
- Examples
- Shopify shop domain, store settings, locale, currency, store guidance, email-domain configuration, connector scopes, and encrypted access credentials.
- Product purpose
- Connect an authorized store, synchronize operational context, and send or receive support email.
Shopper and commerce data
- Examples
- Customer name, email, phone, locale, order number and status, totals, fulfillment, carrier, and tracking events received from the connected store.
- Product purpose
- Identify the relevant order, answer support questions, route requests, and display context to authorized workspace members.
Support communications
- Examples
- Sender and recipient details, subject, email bodies, message headers, conversation references, attachment metadata, drafts, replies, and delivery identifiers.
- Product purpose
- Build and display a conversation, classify intent, draft or deliver replies, and reconcile provider outcomes.
Requests and service operations
- Examples
- Exchange, refund, cancellation, or withdrawal request details; reason if voluntarily supplied; opaque receipt token; webhook IDs; usage counts; and operational error state.
- Product purpose
- Process a requested workflow, avoid duplicates, enforce limits, investigate failures, and maintain service continuity.
Where data comes from
Data can be supplied by workspace users, connected Shopify stores, inbound email, customer-facing request and tracking forms, and service providers returning delivery, billing, or authentication events. Customers should only connect stores and mailboxes they are authorized to administer.
AI processing
When an AI workflow runs, relevant support text, store guidance, conversation history, and available order context can be sent to the configured model provider to classify or draft a response. Human-only mode skips generation. Automatic delivery is disabled by default.
No statement is made here that a third-party model provider will never retain or train on submitted data; that depends on the commercial terms and configuration selected for production and must be verified before launch.
Current service integrations
The application contains integrations with Supabase for database and authentication, Shopify for store data, Postmark for email, Anthropic for AI generation, and Stripe for subscription billing. A deployment host and its infrastructure providers may also process connection and operational data.
This is a technical inventory, not a finalized subprocessor register. Contracting entity, location, processing region, transfer safeguards, and retention terms must be confirmed for the production accounts.
Cookies and public-site tracking
Authenticated pages use essential session cookies and a workspace preference cookie. The current public-site code does not include an advertising tracker. Hosting, CDN, and security services may still create request logs; their production configuration must be reflected in the final notice.
Retention and deletion
The current release candidate does not implement a complete automated retention schedule or self-service workspace export and deletion workflow. Database relationships support removal of many workspace records with the organization, but backups, provider copies, billing evidence, security logs, and legally required records need explicit policies.
A production agreement must define retention windows, deletion and export procedures, backup expiry, and what happens when a subscription ends.
Requests and choices
Shoppers should first contact the merchant responsible for the store. Workspace users can ask their workspace owner to correct membership or account information. Identity and authority must be verified before a request is fulfilled.
A monitored operator privacy contact has not yet been configured. Publishing one, together with a verified request procedure, is a release requirement.
International use and children
Tactrail is intended for business support operations, not for use by children. Global storefronts may create cross-border processing. This page does not claim that a particular data location or transfer mechanism applies until the production accounts and contracts have been selected and documented.
Merchants remain responsible for giving their shoppers an accurate notice and for configuring the service consistently with applicable law and their own promises.
Last updated: . Material changes should be dated here and communicated through an appropriate customer channel.