Privacy policy

Last updated: August 7, 2026

1. Who we are

Telltale ("Telltale", "we", "us") is a retention-intelligence application for direct-to-consumer merchants, operated by Telltale AI Ltd. Co. (a Utah, USA limited company), c/o Registered Agents Inc, 7533 S Center View Ct Ste R, West Jordan, UT 84084, USA. Telltale analyzes a merchant's commerce data to surface retention insights and generate retention campaigns that the merchant sends through their own email/SMS service provider. Telltale does not send marketing messages to your customers itself — it pushes campaign audiences to the merchant's connected provider, which delivers them.

This policy explains what personal data we process, why, and the rights available to merchants and their customers. For questions or to exercise a right, contact owl@telltale.pro.

2. Our role (controller vs. processor)

  • For merchant account data (the store owner / staff who sign in to Telltale), we are a data controller.
  • For a merchant's customer data that we ingest from the merchant's Shopify store (and other connected platforms), we act as a data processor / service provider on the merchant's behalf and instructions. The merchant is the controller of that data. Our processing of customer data is governed by our Data Processing Agreement (DPA).

3. What data we process

From the connected Shopify store (and equivalent commerce platforms):

  • Customer records — name, email address, phone number, and shipping address (city, state/region, ZIP/postal code).
  • Orders — order totals, line items, currency, dates, fulfillment and shipping/delivery events, refunds and cancellations.
  • Abandoned checkouts — the cart and the associated email.
  • Products — product names and attributes (for recommendations).
  • Returns, discounts, inventory, and store media — return reasons (product- quality signals), the store's discount codes (offer recommendations), stock status (so we never recommend out-of-stock products), and store images (for campaign content the merchant approves).
  • On-site behavioral events (optional Web Pixel) — when the merchant enables Telltale's Shopify Web Pixel, we collect consent-gated on-site browsing on the merchant's storefront: pages and products viewed, on-site searches, cart events, and dwell time, tied to a first-party visitor identifier (and, where the visitor is a known customer, to that customer). These are collected only when the storefront's consent mechanism signals analytics consent; non-consented events are dropped server-side (fail-closed). We do not store raw IP addresses, and we do not track visitors across other websites.

We request only the minimum Shopify scopes required for this functionality: read_customers, read_orders, read_products, read_fulfillments, read_checkouts, read_returns, read_inventory, read_discounts, read_files, write_pixels, read_customer_events.

Account data (merchant users): name, email, authentication identifiers, and basic usage/audit information.

From other providers the merchant connects (at the merchant's direction): email/SMS engagement events (opens, clicks, sends, unsubscribes) from providers such as Klaviyo, Omnisend, Mailchimp, and Postscript; support-ticket events and satisfaction scores from helpdesk providers (e.g. Gorgias, Zendesk, Intercom); product reviews (e.g. Judge.me); and subscription lifecycle events (e.g. Recharge) — used to measure and improve retention performance.

We do not collect payment card numbers, government IDs, or special-category data.

4. Why we process it (purposes)

Solely to provide the service to the merchant:

  • compute retention analytics (cohorts, lifetime value, churn risk, reorder timing);
  • build and recommend retention campaign audiences;
  • push those audiences to the merchant's connected email/SMS provider for delivery;
  • where the merchant connects an advertising account, build and maintain advertising audiences (e.g. Google Ads Customer Match, Meta and TikTok Custom Audiences) in the merchant's own ad account using hashed customer identifiers, for retention and suppression campaigns;
  • measure campaign performance and attribute recovered revenue (a 7-day post-send attribution window);
  • operate, secure, and support the service.

We limit processing to these stated purposes (purpose limitation) and do not sell personal data or use it for our own marketing.

5. Automated decision-making

Telltale uses machine-learning models to estimate churn risk and reorder timing in order to suggest which customers a retention campaign should target. These are marketing-optimization decisions; they do not produce legal or similarly significant effects on customers. A customer who opts out of marketing (via the merchant's ESP unsubscribe / suppression) is excluded from Telltale-generated campaigns, and merchants can exclude customers from automated targeting.

6. How we share data (sub-processors)

We share data only with vetted sub-processors that help us run the service, under contract and confidentiality, and with the merchant's connected email/SMS providers at the merchant's direction. Our current sub-processors are listed at telltale.pro/pages/subprocessors. We do not otherwise disclose personal data except to comply with law or protect rights, with notice where permitted.

Advertising audiences. Where a merchant connects an advertising account (for example Google Ads, Meta, or TikTok), Telltale may — on that merchant's behalf and using the merchant's own first-party customer data — create and maintain "Customer Match" or "Custom Audience" lists in that merchant's ad account so the merchant can run retention, win-back, and suppression campaigns. For matching, email addresses are normalized and irreversibly SHA-256 hashed before they leave our systems — we do not share plaintext email addresses. We share only that merchant's own customers' hashed identifiers, only for that merchant's audiences, and only with the platforms the merchant has connected. We do not sell personal data or combine data across merchants for advertising. A customer who opts out of marketing (via the merchant's unsubscribe/suppression), or whom the merchant excludes from targeting, is excluded from these audiences; customers may request removal as described in §10 (Rights).

7. International transfers

Data is hosted in the United States (AWS, us-east-1). Where we transfer personal data internationally, we rely on appropriate safeguards (e.g. Standard Contractual Clauses) as described in our DPA.

8. Security

We apply technical and organizational measures appropriate to the risk, including: encryption in transit (TLS) and at rest; field-level encryption of stored customer email and phone (AES); salted SHA-256 hashing of emails used for matching; least-privilege staff access with audit logging; separation of test and production data; encrypted backups; and a documented security incident-response process. See §11 for breach notification.

9. Data retention and deletion

We retain a merchant's customer data only while needed to provide the service:

  • Per-customer deletion: on a Shopify customers/redact request we erase that customer's data, including any orphaned records (e.g. guest abandoned checkouts matched by hashed email).
  • Full deletion: when a merchant uninstalls, Shopify sends shop/redact ~48 hours later and we erase the merchant's data across our systems. (The 48h window is a grace period so an accidental uninstall/reinstall doesn't lose analytics.)
  • Raw webhook payloads are pruned on a rolling 90-day schedule.
  • On-site behavioral events (Web Pixel) are retained in raw form for up to 90 days; only derived, aggregated browsing signals persist on the customer's profile thereafter. They are erased with the customer on customers/redact.
  • Merchant account data is retained for the life of the account and a limited period afterward as required for legal/operational purposes.

10. Rights

Customers of a merchant may exercise their privacy rights (access, deletion, opt-out of sale/sharing, etc.) through the merchant, who is the controller; we support these requests via Shopify's customers/data_request and customers/redact flows and our DPA. Merchant users may access, correct, or delete their account data by contacting owl@telltale.pro. We honor customer consent and opt-out decisions communicated to us.

11. Breach notification

If we become aware of a personal-data breach affecting a merchant's data, we will notify the affected merchant(s) without undue delay and provide the information needed to meet their notification obligations, consistent with our DPA and applicable law.

12. Children

Telltale is a B2B service and is not directed to children. We do not knowingly process children's personal data.

13. Changes

We may update this policy; material changes will be posted here with a new "last updated" date and, where appropriate, communicated to merchants.

14. Contact

Telltale AI Ltd. Co. · 7533 S Center View Ct Ste R, West Jordan, UT 84084, USA · owl@telltale.pro Governing law: State of Utah, United States.

15. SMS / text messaging

Telltale’s own text messages to you

If you give us your mobile number and opt in — by ticking the SMS box in a Telltale sign-up, onboarding or account form, or by texting one of our published keywords — you agree to receive recurring automated text messages from Telltale about your account: onboarding and setup help, service and incident notices, product updates, and occasional offers. Message frequency varies, typically 1–4 messages per month. Message and data rates may apply. Consent to receive marketing text messages is never a condition of purchasing or using Telltale. You can opt out at any time by replying STOP, and get help by replying HELP.

How we collect your number and your consent

We collect a mobile number only when you provide it to us directly. The opt-in box is never pre-checked, and you must be at least 18 years old and the account holder of, or authorized by the account holder for, the number you give us. Your number and SMS consent are used solely to send you the messages you signed up for, to honor your opt-out and help requests, and to keep the records we are required to keep in order to evidence your consent.

Who we share it with

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties. Text messaging originator opt-in data and consent are never sold, rented, or shared with any third party, including affiliates, for any purpose. We use messaging providers only to transmit these messages on our behalf; a provider acts solely on our instructions as a service provider under contract, may not use your information for its own purposes, and receives no text messaging opt-in data or consent for any purpose other than delivering the messages you requested.

Cart and browsing activity, and cart reminder messages

Telltale’s app and web pixel record shopping activity on a merchant’s own store — products viewed, items added to a cart, and carts left without completing checkout — using cookies and a first-party script that the merchant installs on their store, together with abandoned-checkout records supplied by the merchant’s commerce platform. That information (the products in the cart, their value, and when the shopper last interacted with it) is what determines that a cart has been abandoned and builds the audience for a cart reminder message, which the merchant’s own email or SMS provider then delivers. For these signals Telltale acts as a processor on the merchant’s instructions; the merchant is the controller and is responsible for obtaining the shopper’s consent. As stated in section 1, Telltale does not send marketing messages to a merchant’s shoppers from its own text messaging program.

Location tracking and location-based services

We do not collect GPS or precise device location, and we do not operate location tracking or location-based services of any kind. The only location information we process is the billing and shipping address, and the derived region (state, postal code, country), that a merchant’s commerce platform supplies with an order — used for regional retention analytics and shipping/tax context — plus coarse country-level information derived from an IP address for security and fraud prevention. Location is never used to track an individual’s movements and is never used to target text messages by real-time location.