How TailorLoom handles your data
What happens to the files you upload
Where your files are stored
Your uploaded CSV is never stored as a file on our servers. While you map columns it stays in your own browser, which clears it after four hours. During import our server reads it in memory and discards it when the import finishes. Our logs contain no rows or cell values from your files.
Processed records and analyses are stored in a Postgres database hosted by Supabase in US East (Northern Virginia). The application runs on Railway in US East (Virginia). Your data stays in the United States.
Who at TailorLoom can access your data
Access is limited to authorized users in your own workspace and a small number of TailorLoom personnel who need it for support, security, maintenance, or legal compliance. Everyone with access is under confidentiality obligations.
Your workspace is separated from every other workspace by row-level security on every database table, and by application checks that take your organization from your signed-in session rather than from anything the browser sends. An automated test attempts cross-workspace reads and writes on every code change. TailorLoom records who imported a file, who deleted a workspace and who erased a member.
How long your data is kept
Uploaded files are never kept on our servers, and the copy in your browser clears after four hours. Processed records and analyses stay until you delete them — there is no time limit and nothing is removed automatically. Canceling a paid subscription moves your workspace to the free plan and deletes nothing.
We do not keep backups. Deleted data cannot be restored, so keep your own copies of the exports you upload.
Deleting your data
Three controls, all self-service from inside TailorLoom.
Delete an import. Removes the stored copies of its rows and the records it created: payments, bookings, visits, memberships, guest records and client-list entries. Customers created only by that import go too, along with contact details no other import supplied. Dashboards and draft Snapshots recalculate immediately. Sealed Snapshots keep their totals, and a deleted person appears as "Removed member".
Erase an individual. Removes that person's name, email address and phone number everywhere in your workspace, including sealed Snapshots, and prevents a later upload from recreating them.
Delete the workspace. Available to an admin once any paid subscription is canceled. Removes every record in the workspace — customers, payments, bookings, visits, memberships, imports, row copies, analyses, Snapshots and settings — along with the workspace's sign-in organization.
Deletions run immediately and apply only to your own workspace. Because there are no backups, they cannot be undone. You can also email support@tailorloom.com; a verified workspace deletion is completed within 30 days.
Some records remain afterwards. Stripe keeps billing records, invoices and subscription history for tax and accounting. Product-analytics events tied to account IDs remain, and contain no names, member information or imported rows. Individual sign-in accounts remain until each person deletes their own.
AI providers and your data
There is no AI provider. No customer or member information is sent to one, and there is no AI service key in production. Insights come from fixed calculations that run inside your own workspace.
Your data is never used to train shared or generalized AI models, and one customer's identifiable data is never used to produce results for another. If we add AI-assisted features, we will update the Privacy Policy before those features process customer data.
This page summarizes how the product works today. The Privacy Policy and the Terms of Service are the full and governing statements.
Have a question about how your data is handled?
Contact us
