Sub-processors
Telltale engages the following sub-processors to provide the service. Each is bound by contract to confidentiality and data-protection obligations consistent with our DPA. We will give merchants advance notice of new sub-processors where required.
Infrastructure & platform
| Sub-processor | Purpose | Data | Region |
|---|---|---|---|
| Amazon Web Services (AWS) | Application hosting, database (Postgres, encrypted at rest), object storage (S3), compute (ECS), in-memory cache/queue (Redis — incl. the transient on-site-pixel event buffer) | All processed data (encrypted) | US (us-east-1) |
| Vercel | Frontend dashboard hosting | Merchant account/session data | US/global edge |
| Clerk | Merchant user authentication | Merchant user identity (name, email, auth IDs) | US |
AI processing
| Sub-processor | Purpose | Data | Region |
|---|---|---|---|
| Anthropic | AI generation and analysis across the product: retention campaign copy (Voice AI), plain-language report summaries (churn and recovered-revenue), brand-voice and brand-reference analysis, product copy, sentiment analysis of customer-authored review and support text, image analysis of merchant-uploaded brand media, the in-app AI assistant (chat over the merchant's own retention data), and cross-account insight generation for analytics. | No customer identity fields — name, email, phone, postal address, or platform IDs — are sent in prompts: per-customer analytical rows are anonymized before processing (identity removed; rows labeled “customer 1/2/3”), so only analytical values (risk scores, drivers, dollar figures, product names, timing) are sent. Where the product analyzes a customer's own review, support ticket, or cancellation message, that text is sent and may contain whatever information the customer chose to include. No customer lists or bulk exports are sent. Anthropic does not train on Telltale's API traffic. | US |
Operations
| Sub-processor | Purpose | Data | Region |
|---|---|---|---|
| Stripe | Subscription billing (non-Shopify merchants) | Merchant billing contact + subscription metadata (no card data stored by us) | US |
| Shopify (App Pricing / App Events) | Subscription and performance-fee billing for Shopify-installed merchants | Merchant billing/subscription metadata | US/global |
| Resend | Transactional email to merchant users (invites, notices) | Merchant user email | US |
| Sentry (optional) | Error monitoring (configured with PII scrubbing) | Diagnostic data, PII excluded | US |
Public-data services
These are read-only queries to public data APIs. No customer personal data is sent to them; they are listed here for transparency.
| Service | Purpose | What is sent | Region |
|---|---|---|---|
| US Census Bureau API | Area-level demographic enrichment (age/income distributions by ZIP) | A ZIP code only (an area, not a person) | US |
| GDELT | Brand news and press signals | The merchant's brand name as a news search query; no customer data | Global |
Merchant-directed providers
When a merchant connects an email/SMS provider, Telltale shares campaign audience data with that provider at the merchant's direction so the provider can deliver the merchant's campaigns. These include, depending on what the merchant connects: Klaviyo, Omnisend, Mailchimp, Postscript (and other commerce/CRM integrations the merchant enables). The merchant's agreement with each provider governs that provider's processing.
Note: Telltale does not send marketing messages to customers itself; it pushes audiences to the merchant's chosen provider, which delivers them.