Privacy Policy
Effective date: Version 1.0, effective on the date this version is first posted on tailorloom.com
This Privacy Policy explains how TailorLoom Intelligence LLC, a Texas limited liability company ("TailorLoom," "we," "us," or "our"), collects, uses, discloses, retains, and protects personal information through tailorloom.com, app.tailorloom.com, related communications, and the TailorLoom software service (collectively, the "Services").
1. Scope and our roles
This Policy applies to personal information we handle about website visitors; prospective and current customers; customer account users; and individuals whose information a customer uploads or connects to the Services, such as the customer's members, guests, leads, and contacts.
TailorLoom acts in different roles depending on the context:
- TailorLoom determines how and why it uses account, business-contact, billing, support, product-usage, website, and security information for its own business purposes. In that context, TailorLoom acts as a controller or business under applicable privacy law.
- When a customer uploads or connects information about its members, guests, leads, or other individuals, the customer generally determines why that information is processed. TailorLoom processes it on the customer's instructions to provide the Services and generally acts as a processor or service provider.
- If you are an individual whose information was supplied by a TailorLoom customer, the customer's privacy notice and instructions generally govern the relationship. We may route your request to that customer unless applicable law requires us to respond directly.
2. Personal information we collect
2.1 Information from customers and account users
- Account and contact information, such as name, work email address, business name, role, and login information.
- Business profile information, such as number of locations, business type, and the booking or membership platform used.
- Billing and subscription information. Payment-card details are handled by our payment processor; TailorLoom does not receive or store complete card numbers or security codes.
- Support and communications content, including messages, requested assistance, feedback, and records of our responses.
- Product-use, device, log, and security information, such as login events, IP address, browser or device information, feature activity, errors, and suspected misuse.
2.2 Customer-uploaded or connected information
Customers may provide CSV files and other supported records (together with information received through a Connected Service described in Section 2.3, "Customer Data") containing information about their members, guests, leads, transactions, visits, attendance, bookings, and memberships. Depending on the customer's source data, this may include:
- names and contact details, including email addresses or telephone numbers;
- membership status, plan, start date, cancellation, or related account information;
- visits, attendance, bookings, class or service participation, and engagement history;
- guest, lead, trial, referral, or conversion activity;
- transaction dates, amounts, product or membership references, and basic revenue context; and
- identifiers used to match records within the customer's own data.
Customers should not submit unsupported highly sensitive data. The Services are not intended to receive protected health information, medical records, or other health information such as injuries, medical conditions, body measurements, or wearable-device readings, complete payment-card data, government identifiers, biometric templates, information about individuals under 18, or other highly sensitive information unless TailorLoom expressly approves a supported use in writing.
2.3 Information from future Connected Services
If TailorLoom offers an optional integration, API, OAuth connection, or other account connection in the future, we may receive the data and permissions that the customer authorizes from the third-party provider. The fields available and frequency of access depend on the provider, the customer's settings, and the connection offered. TailorLoom does not represent that any particular native integration is available at launch. Any access token or credential used for a connection would be used only to import and refresh the data the customer authorizes. Disconnecting stops future imports, and data already imported stays in the customer's workspace until it is deleted as described in Section 8.
2.4 Website and analytics information
We use cookies and similar browser storage to sign users in, keep sessions secure, and operate the Services. We also use these third-party tools in the Services:
- PostHog, for product analytics. PostHog receives usage events tied to an account ID. It does not receive names, email addresses, or customer-uploaded records.
- Cloudflare Turnstile, to protect sign-in from automated abuse. Turnstile evaluates signals from the browser and does not receive customer-uploaded records.
- Clerk, to manage sign-in and workspace membership, including optional sign-in with Google. If you choose Google sign-in, Google shares the account information you authorize, such as your name and email address.
You can block or delete cookies through your browser settings, but sign-in may not work without them. Before we add any advertising tool, advertising pixel, or session-recording tool, we will update this Policy to describe it. Our website and application do not currently respond to browser Do Not Track signals. We do not allow third parties to collect personal information about your online activities over time and across other websites when you use the Services, and the service providers named above collect information only to perform services for us.
3. How we use personal information
We use personal information to:
- provide, operate, personalize, maintain, and secure the Services;
- create and administer accounts, authenticate users, and manage subscriptions and billing;
- ingest, validate, organize, match, and analyze customer-provided records for the customer's own account;
- produce health checks, customer timelines, cohort comparisons, summaries, insights, exports, alerts, and other features that are actually available in the customer's plan;
- provide support, diagnose errors, communicate about the Services, and respond to requests;
- prevent fraud, abuse, unauthorized access, and security threats;
- monitor performance and improve reliability and usability without using Customer Data to train shared or generalized AI models;
- create aggregated or de-identified information from Customer Data and use it to improve the Services and to provide benchmarks, as described in Section 4;
- comply with law, enforce agreements, and protect our rights and those of others; and
- carry out other purposes disclosed at collection or with appropriate authorization.
4. Automated insights and artificial intelligence
TailorLoom currently generates insights through fixed calculations applied to the information in a customer's own account. TailorLoom does not use an artificial intelligence provider, and no customer or member information is sent to one. TailorLoom follows these commitments for Customer Data:
- Customer Data is not used to train shared or generalized AI models.
- One customer's identifiable data is not used or disclosed to generate results, benchmarking, enrichment, or insights for another customer.
- TailorLoom may combine Customer Data from many customers into aggregated or de-identified information that cannot reasonably identify any customer, member, organization, or other individual, and may use that information to improve the Services and to provide benchmarks. TailorLoom takes reasonable measures to keep that information from being linked to any customer, member, organization, or individual, does not attempt to re-identify it, and does not publish or share a benchmark drawn from fewer than five organizations. Any party that receives it must agree to the same restrictions. TailorLoom does not use aggregated or de-identified information to train shared or generalized AI models or for advertising, and that information may remain after the underlying Customer Data is deleted.
- If TailorLoom adds AI-assisted features, their outputs will be generated only for the customer that supplied the data and may require human review.
Before TailorLoom uses a third-party AI provider to process Customer Data, we will update this Policy to describe the provider's role and the categories of information it receives, and the commitments above will continue to apply.
5. How we disclose personal information
We may disclose personal information to:
- service providers and subprocessors that support hosting, storage, authentication, payments, support, communications, security, and analytics, subject to appropriate contractual restrictions;
- professional advisers such as attorneys, accountants, insurers, and auditors where reasonably necessary;
- government authorities, regulators, courts, or other parties when we reasonably believe disclosure is required by law or necessary to protect rights, safety, security, or the integrity of the Services;
- an acquirer, investor, lender, or successor in connection with a financing, merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to customary protections; and
- other parties at the customer's direction or with appropriate authorization.
TailorLoom does not sell customer-uploaded personal information. TailorLoom also does not disclose one customer's identifiable uploaded information for another customer's advertising, benchmarking, enrichment, or model training. Aggregated or de-identified information described in Section 4 may appear in benchmarks, but it cannot reasonably identify any customer, member, organization, or other individual.
6. Data location
TailorLoom and its service providers may process personal information in the locations where they operate. TailorLoom stores processed customer records and analyses with Supabase in the United States (US East, Northern Virginia) and runs its application with Railway in the United States (US East, Virginia). Clerk (sign-in), Stripe (billing), and PostHog (product analytics) process account, billing, and usage information in the United States. Cloudflare Turnstile and Google sign-in operate on global networks. Google Workspace hosts our email, including support communications, and may process it in the United States and other countries where Google operates. If you use the Services from outside the United States, your information will be processed in the United States.
7. Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including providing the Services, maintaining security, resolving disputes, enforcing agreements, and meeting legal, tax, accounting, or regulatory obligations. Different categories may have different retention periods.
A CSV file stays in the uploading user's browser while columns are mapped and is cleared after four hours. During import, our application host processes the file in memory and discards it when the import ends. TailorLoom does not keep uploaded CSV files on its servers, and our logs do not contain uploaded rows or file contents.
Processed records, row-level copies of each import, and analyses stay in the customer's workspace until the customer deletes them or deletes the workspace. TailorLoom does not currently delete this information automatically after a set period, and canceling a paid subscription does not delete it.
We keep account, billing, and support records while the account exists and afterward for as long as needed for accounting, tax, legal, security, and dispute-resolution purposes. TailorLoom does not currently maintain database backups, so deleted information cannot be restored.
8. Deletion
Customers control deletion of Customer Data inside the Services. Deleting an import immediately removes the row copies and the records created by that import, such as payments, bookings, visits, memberships, guest records, and client-list entries, along with individuals created only by that import and contact details that no other import or manual edit supplied. Dashboards and draft Snapshots are recalculated right away. Sealed Snapshots keep their historical totals, but a deleted individual appears as "Removed member." A temporary copy of the file may remain in the uploading user's browser for up to four hours.
Erasing an individual member removes that person's name, email address, and telephone number throughout the workspace, including sealed Snapshots, and prevents a later upload from recreating that individual.
Canceling a paid subscription moves the workspace to the free Membership Health Check plan at the end of the current billing period and does not delete its data. After any paid subscription is canceled, a workspace administrator can delete the entire workspace. Workspace deletion immediately removes the workspace's customers, imported records, row copies, payments, bookings, visits, memberships, analyses, Snapshots, and settings, along with the related organization in our sign-in system.
Customers may request deletion of an account or other personal information through support@tailorloom.com, and TailorLoom will complete a verified workspace deletion request within 30 days. We may need to verify the requester's authority and may retain limited information when required or permitted for security, legal compliance, billing, or dispute resolution.
Some records remain after a workspace is deleted. Stripe keeps billing records, invoices, and subscription history for accounting and tax purposes. PostHog keeps product-analytics events tied to account IDs, which contain no names, member information, or imported rows. The individual sign-in accounts of people who used the workspace remain until each person deletes the account or asks us to delete it.
9. Security and internal access
We use administrative, technical, and organizational measures intended to protect personal information in light of its nature and the risks involved. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Access to customer-uploaded information is limited to authorized customer users and a small number of TailorLoom personnel who need access for support, security, maintenance, legal compliance, or other authorized operational purposes. Personnel with access must be subject to confidentiality requirements.
Each customer's information is kept separate from other customers' information through database access rules and application checks tied to the signed-in user's organization, and we test for cross-customer access whenever we change our code. The Services record who imports data, deletes a workspace, or erases a member.
10. Privacy rights and requests
Some state privacy laws give residents rights to request access to, correction of, deletion of, or a copy of certain personal information; to opt out of certain processing; or to appeal a decision about a request. Those laws apply to TailorLoom only when their coverage tests are met, and many of them do not cover information about people acting in a business or employment role. Where a privacy law applies, TailorLoom will honor the rights it provides. We will not unlawfully discriminate against you for exercising a privacy right.
Account users and website visitors may submit a request to support@tailorloom.com with the subject line "Privacy Request." We may verify identity and authority before completing a request. An authorized agent may submit a request where applicable law permits, subject to verification requirements. If we deny your request, you may appeal by replying to our decision with the subject line "Privacy Appeal," and we will respond in writing within 45 days.
If your information was provided to TailorLoom by one of our business customers, please contact that business first. Because that business controls the purpose and means of processing, we generally forward or refer the request to it and assist it as required by law and our agreement.
11. Children
The Services are designed for businesses and account users who are at least 18 years old. The Services are not directed to children, and TailorLoom does not knowingly collect personal information directly from children under 13. Customers must not upload information about individuals under 18 unless TailorLoom has expressly approved a supported use and all applicable legal requirements are satisfied. If you believe information about a minor has been submitted contrary to this Policy, contact us at support@tailorloom.com, and we will work with the customer to delete it.
12. Third-party links and services
The Services may link to or interoperate with third-party websites, platforms, payment processors, or Connected Services. Their privacy practices are governed by their own policies. Customers should review those policies and configure third-party permissions carefully. TailorLoom is not responsible for a third party's independent privacy or security practices.
13. Changes to this Policy
We may update this Policy to reflect changes in our Services, practices, or legal obligations. We will post the updated Policy and revise the effective date. If a change materially affects how we use Customer Data or other personal information, we will notify account administrators by email or in the Services before the change takes effect and will obtain consent when required by law.
14. Contact us
Privacy questions, requests, and support: support@tailorloom.com
Legal notices to TailorLoom Intelligence LLC: email support@tailorloom.com with the subject line "Legal Notice," or mail our registered agent at the address listed with the Texas Secretary of State

