Tillie Privacy Policy
Operator: Clarity Insights Imaging Pty Ltd (ABN 92 696 493 740), [Company number], 8/10 Lower River Terrace, South Brisbane QLD 4101 ("Tillie", "we", "us")
Contact: support@hellotillie.com
Effective date: [Effective date]
Tillie is a Shopify app. It answers a store's phone calls with an AI assistant, and it drafts and sends replies to the store's customer emails and help-desk tickets. This policy explains what information we handle, why, who receives it, how long we keep it, and your rights.
1. Who this policy covers
- Merchants. Shopify store owners and their staff who install and use Tillie.
- Callers. People who phone a store that uses Tillie.
- Emailers. People who email a store, or open a help-desk ticket, where the store has connected Tillie.
- Website visitors to https://hellotillie.com.
2. Our role
For merchant account data (section 3.1), we decide how the information is used. We are the "controller" (or "agency" in New Zealand, "APP entity" in Australia).
For caller and emailer data (sections 3.2 and 3.3), the merchant decides why and how it is used. We handle it only on the merchant's behalf, under our Data Processing Agreement. The merchant is the controller and we are the processor (or "service provider" under California law). If you are a caller or emailer, the store you contacted is your main contact for privacy questions. We will help the store answer you. You can also contact us directly (section 16).
3. What we collect
3.1 From merchants
- Store details from Shopify: store name, domain, country, time zone, currency, store policies, locations and the product catalogue.
- Staff details: name and email of the person who installs the app or sets up alerts, and the Shopify staff account ID of people who open call records.
- Settings: greeting, agent name, voice, business hours, FAQ answers, spend budget, alert email, help-desk connection details.
- Help-desk credentials (API keys or tokens). We store them encrypted.
- Phone number registration details. Australian and New Zealand phone numbers need a regulatory registration. The merchant gives business name, business number (ABN, ACN or NZBN), address and the details of an authorised person, and uploads supporting documents (for example a company register extract, proof of address and the authorised person's ID), in the registration form inside the app. We pass the details and documents straight to Twilio for its review. We do not keep a copy of the documents: they are held only in memory while the upload is sent, and are never saved to our database, file storage or logs. Twilio holds the details and documents. We keep Twilio's references for them, the registration status and Twilio's reasons if it rejects the registration.
- Billing records: plan, trial dates, minutes used and charges. Shopify handles payment. We never see card details.
- An access log of who viewed call transcripts, played recordings, looked up orders, or exported or deleted data.
3.2 From callers
- The caller's phone number (caller ID), and the number they dialled.
- Call audio. When the store has turned recording on, we record the call. The caller hears "This call is recorded" at the start.
- Transcript. A written record of what the caller and the assistant said.
- Details the caller gives: name, order number, postcode, surname, the products they ask about, a message, or a request for a callback.
- Order information from the store's Shopify account, only when the caller asks about an order and passes an identity check (section 6). This can include order number, items, status, shipping and tracking details, delivery city, and the name, phone, email and address on the order. The assistant speaks only the delivery city, not the full address. It never asks for or reads out an email address.
- A short summary of the call and its outcome.
- If the caller asks for a text message: their mobile number and the link we sent.
3.3 From emailers
- The email or ticket text, subject, sender name and email address, and the thread history, read from the store's help desk (Gorgias, Zendesk or Re:amaze) or mailbox.
- Order information for orders whose email or phone matches the sender.
- The draft reply, review results, whether it was sent automatically or by a staff member, and an audit record.
We remove links, hidden text and attachments before any AI model sees an email. We do not open links or attachments.
3.4 From website visitors
Standard server logs: IP address, browser type and pages requested. [List any analytics tool, or state "We do not use analytics or advertising cookies."]
4. Why we use it
| Purpose | Data used | Legal basis (EU/UK GDPR) |
|---|---|---|
| Answer calls for the store: product questions, order status, store policies, hours, callbacks, messages, transfers | Caller data, order data, store data | Processed for the merchant. The merchant's basis, usually contract or legitimate interests |
| Draft and send replies to store emails and tickets | Emailer data, order data, store data | As above |
| Send a checkout link by text when the caller asks for one | Mobile number, link | As above, with the caller's request |
| Give the merchant call summaries, transcripts and recordings | Caller data | As above |
| Set up and run the merchant's account, phone number and settings | Merchant data | Contract with the merchant |
| Bill usage through Shopify | Minutes, plan, store ID | Contract; legal obligation (tax records) |
| Keep the service secure, stop abuse, fix faults | Access logs, technical logs without personal content | Legitimate interests |
| Meet legal duties and answer lawful requests | As needed | Legal obligation |
We do not:
- sell personal information or share it for advertising;
- use caller or emailer data, or store data, to train or improve AI models;
- use caller or emailer data for our own marketing;
- use one store's data to serve another store.
Shopify's API terms and Partner Program Agreement also forbid these uses.
5. How we use AI
- Phone. An AI voice model from OpenAI listens to the caller and speaks the replies. It uses tools that read the store's Shopify data. It cannot change orders, issue refunds or take payments.
- Email and help desk. AI models draft replies. A separate check reviews every draft against the store's order records and policies before it can be sent. [Confirm: OpenAI only, or OpenAI and Anthropic.]
- Summaries. An AI model writes a short summary after each call.
We tell our AI providers not to keep data for training. OpenAI and Anthropic do not train on business API data by default. They may keep inputs and outputs for up to 30 days to detect abuse, unless we have a zero-retention agreement. [Confirm whether zero-data-retention has been approved.]
Does the assistant say it is an AI? Each store chooses. Under the default setting the assistant does not open by saying it is an AI, but it always answers truthfully if asked. A store can choose to have it say so at the start of every call. Emails sent by Tillie go out in the store's name.
6. Automated decisions
Some steps are decided by software without a person. We list them here, as the Australian Privacy Principles require from 10 December 2026 (APP 1.7) and as GDPR Article 22 and Shopify's data rules expect.
| Decision | Information used | Effect | Human option |
|---|---|---|---|
| Identity check before order details are shared. The caller must give the order number and one detail that matches the order (caller ID, delivery postcode or surname). | Order number, caller ID, postcode, surname, order records | If the check fails, the assistant does not share order details. | The assistant offers a callback or message to store staff. |
| Auto-send of email replies (only if the merchant turns it on for a type of question) | Email text, order records, store policies | A reply is sent without a person reading it first. Complaints, order changes and money matters never auto-send. | Any reply can be answered by staff; the customer can reply to ask for a person. |
| Spam closing (only if the merchant turns it on) | Email text | A message the software is very sure is spam is closed without a reply. | Staff can see and reopen closed items. |
| Routing to a message or callback when the assistant is paused, busy or unavailable | Call time, store settings | The caller leaves a message instead of speaking to the assistant. | Store staff follow up. |
None of these decisions has a legal effect. None decides price, credit, refunds, eligibility or access to goods. Refunds, cancellations and order changes are always left to store staff.
7. Call recording notice
When a store has recording on, every caller hears "This call is recorded" near the start of the call. Recording cannot be on without this notice. If recording is off, we still keep a written transcript so the store can see what was said. Callers who do not want to be recorded can end the call and contact the store another way.
Stores are responsible for any further notice their local law needs. See our Terms of Service.
8. Who receives the information (subprocessors)
We use these companies to run the service. Each has a written data processing agreement with us.
| Company | What they do | Data they handle | Where |
|---|---|---|---|
| Cloudflare, Inc. | Hosting, database, file storage, job queues, network security | All service data (encrypted at rest) | Global network; storage location [confirm region hint] |
| OpenAI, L.L.C. / OpenAI Ireland Ltd | AI voice, summaries, email drafting and checks | Call audio in real time, transcripts, email text, order facts needed to answer | United States |
| Twilio Inc. | Phone numbers, call routing, call audio stream, recording (deleted from Twilio after we copy it), text messages, number registration | Caller number, call audio, text messages, registration documents | United States; numbers in Australia and New Zealand |
| Shopify Inc. / Shopify Commerce Singapore | Store platform, app install, billing | Store data, order data, billing | Canada, United States and other Shopify locations |
| Anthropic, PBC [only if used] | Email drafting or checking | Email text, order facts | United States |
| [Email provider — TBD] | Sending call summaries and alerts to merchants | Merchant email, call summaries | [Location] |
Help desks the merchant chooses (Gorgias, Zendesk, Re:amaze, or a mailbox) are the merchant's own providers, not ours. When a merchant connects one, we read and write tickets there on the merchant's instruction.
We may also disclose information when the law requires it, to protect people from serious harm, or as part of a sale of our business (the buyer must keep this policy's promises).
We give merchants at least 30 days' notice before adding or replacing a subprocessor. The current list is at https://hellotillie.com/privacy#8-who-receives-the-information-subprocessors.
9. International transfers
Our providers process data outside the caller's country, mainly in the United States. We take these steps:
- New Zealand (IPP 12) and Australia (APP 8). We choose providers bound by contract to protect information to a standard like our own law. We stay responsible for how they handle it.
- EU, UK and Swiss data. We rely on the EU Standard Contractual Clauses (Commission Decision 2021/914), the UK Addendum, and, where a provider is certified, the EU-US Data Privacy Framework. [SCC module references to be added by lawyer.]
10. How long we keep it
These are the default periods. A merchant can set shorter periods (and some longer ones, within the limits shown) in the app's Settings.
| Data | Default | Merchant can set |
|---|---|---|
| Call recordings | 30 days after the call | 0 to 365 days (never longer than transcripts) |
| Call transcripts | 90 days | 1 to 730 days |
| Call records (time, length, outcome, masked number) | 400 days | 30 to 1,095 days |
| Messages and callback requests | 90 days | 1 to 365 days |
| Email drafts, review results and thread copies | [90 days — confirm] | [confirm] |
| Access log | 2 years | No |
| Data exports for a customer request | 30 days | No |
| Billing records (minutes, charges; no caller data) | 7 years (tax law) | No |
| Live call working memory | 2 hours after the call | No |
A daily job deletes expired data. A storage rule deletes any call files older than 800 days as a backstop. Twilio's copy of a recording is deleted once our encrypted copy is saved.
When a merchant uninstalls: the assistant stops answering at once. For 14 days the store's number plays a short message telling callers how to reach the store (not recorded). Shopify then sends us a deletion request 48 hours after uninstall. We delete the store's call, email and settings data, and destroy the store's encryption key so any remaining copies cannot be read. We complete this within 30 days of uninstall. We keep only billing records.
11. Security
- All connections use encryption (TLS).
- Call recordings, transcripts, caller numbers, help-desk keys and Shopify access tokens are encrypted with a separate key for each store.
- Phone numbers used for lookups are stored as one-way codes (hashes).
- Our system logs do not record call content, phone numbers or emails.
- Our staff have no standing access to call content. Emergency access needs a written reason, approval and expires after 24 hours. Every access is logged.
- Staff accounts use multi-factor sign-in or passkeys.
- Test systems use made-up data only.
- We have a written incident response plan. If a breach affects a store's data, we tell the store within 48 hours and Shopify within 24 hours.
No system is perfectly secure. Tell us at support@hellotillie.com if you find a security problem.
12. Your rights
You can ask to see, correct or delete personal information about you. Where GDPR or UK GDPR applies you can also object, ask us to restrict use, and ask for a copy in a portable form. California residents have rights to know, delete and correct, and not to be discriminated against for using them. We do not sell or "share" personal information as California law defines it.
Callers and emailers. Please contact the store first. The store can send your request through Shopify. Shopify then sends us a formal request:
- Copy of your data (Shopify's
customers/data_request): we find calls, messages and emails linked to you, and give the store an export within 30 days. The store sends it to you. - Deletion (Shopify's
customers/redact): we delete recordings, transcripts, messages and email copies linked to you within 30 days. We keep only non-personal billing facts (call length and minutes).
You can also contact us directly. We will pass your request to the store and help it answer you. We may need to check your identity first.
Merchants. Contact support@hellotillie.com, or use the export and delete tools in the app.
Complaints. Contact us first. If you are not satisfied, you can complain to:
- New Zealand: Office of the Privacy Commissioner, privacy.org.nz
- Australia: Office of the Australian Information Commissioner, oaic.gov.au
- EU/UK: your local data protection authority
- California: California Privacy Protection Agency, cppa.ca.gov
We answer requests within 20 working days (New Zealand), 30 days (Australia), one month (GDPR) or 45 days (California), or sooner.
13. Notice to people whose information we receive from others
Under New Zealand's IPP 3A (from 1 May 2026) and Australia's APP 5, we must tell people when we collect information about them from someone else. We receive order details from the store's Shopify account, and email text from the store's help desk. This policy is that notice. It tells you what we collect (section 3), why (section 4), who receives it (section 8), and how to see or correct it (section 12). The store you contacted is also responsible for telling you about its own use of your information.
14. Children
Tillie is for businesses. It is not aimed at children. We do not knowingly collect information from children under 16, other than what a child may say on a call to a store. If you believe a child's information is held, contact us and we will delete it.
15. Changes to this policy
We will post changes here with a new date. For material changes we will tell merchants in the app or by email at least 30 days before the change takes effect.
16. Contact
Clarity Insights Imaging Pty Ltd, 8/10 Lower River Terrace, South Brisbane QLD 4101 Privacy contact: support@hellotillie.com