Privacy Policy
Last updated August 2026
This policy explains what Tenpo collects, how we use and protect it, who else processes it, and the choices you have over your information and your connected commerce data.
1. Who We Are & Our Role
Tenpo is an AI operator for online stores. This policy covers app.tenpo.ai and the Tenpo service (the "Service").
We act in two different roles. For merchant account data — your name, email, billing details, and how you use the Service — Tenpo is the controller. For the store data we receive from the platforms you connect, including your customers' personal data, Tenpo acts as a processor on your behalf: you decide what is connected and what happens to it, and we process it on your instructions to deliver the Service. If you need a data processing agreement, email contact@tenpo.ai and we will put one in place. Tenpo is operated from Bengaluru, India. Under India's Digital Personal Data Protection Act, 2023, the same split applies: we are a Data Fiduciary for merchant account data and a Data Processor for the store data you connect.
The Service is a business tool and is not directed to individuals under 16.
2. Information We Collect
Information you give us. Account details such as your name, email address, and password when you sign up, along with billing information and anything you send us in support conversations or in chat with the operator.
Store data from platforms you connect. When you connect a platform such as Shopify, a marketplace, an ad account, an email tool, or an accounting system, we receive the records needed to run the Service — orders, products, inventory, suppliers, purchase orders, campaign and spend data, payouts and fees, support tickets, and customer records including names, email addresses, phone numbers, and shipping addresses.
Technical information. IP address, browser type, device information, and usage and error logs, which we use to keep the Service running, secure, and debuggable.
3. How We Use Your Information
We use what we collect to provide, maintain, secure, and improve the Service: to authenticate you, to generate analysis and recommendations specific to your store, to carry out the actions you enable, to bill you, to respond to support requests, and to send you service notices. We will never sell your personal data, and we do not use it for third-party advertising.
Legal bases. Where the GDPR or a similar law applies to our processing as a controller, we rely on performance of our contract with you (providing and billing for the Service), our legitimate interests (securing the Service, preventing abuse, and improving quality), your consent where we ask for it, and compliance with our legal obligations. Where we act as a processor on your behalf, establishing the legal basis for the data you connect is your responsibility.
4. Actions We Take on Your Behalf
The Service does not only analyze your data — when you enable a capability, it acts inside your connected systems. That can include issuing refunds, cancelling or editing orders, updating products and inventory, creating and sending purchase orders to suppliers, adjusting advertising campaigns, replying to support tickets, and sending email, messages, and campaigns to your customers through the sending accounts you connected.
Personal data needed for an action is passed to the platform performing it — a customer's email address for a win-back message, an order's details for a refund. When the Service messages your customers it sends from your accounts and under your brand: you are the sender, and we process those recipients' data on your instruction. Content generated for an action may be processed by the AI sub-processors described in section 8.
You choose which actions the Service may take and which require your approval first, in your account settings.
5. Network Learning & Your Opt-Out
We do not use your store's data to train AI models. To improve recommendation quality across the Service, we use aggregated statistical signals — for example, how often a given type of recommendation is accepted or declined across merchants. These aggregates never include your raw store data, product or supplier names, pricing, or customer information, and a signal is only used once it reflects a pattern shared by at least three distinct merchants.
You can turn network learning off at any time from your account settings.
6. How We Store & Protect Data
Each merchant's store data lives in its own separate database, isolated from every other merchant's. Credentials and API keys for your connected platforms are never stored alongside store data — they are held in a separate credential vault encrypted with AES-256-GCM. Customer email addresses and phone numbers in your customer records are encrypted at the field level with a per-merchant key and are searchable only through one-way lookup hashes. Traffic between you, us, and connected platforms is encrypted in transit with TLS, and backups are encrypted.
Access to production systems is limited to personnel who need it, and administrative actions are logged. No method of storage or transmission is completely secure and we cannot guarantee absolute security. If a breach affects your personal data, we will notify you — and, where required, the relevant supervisory authority — without undue delay.
7. Connected Platforms
Tenpo connects to a third-party platform only when you explicitly authorize it, and each integration accesses only the data needed to deliver the features you enabled. You can disconnect any integration at any time, and choose to purge the data synced from it when you do.
Shopify and other commerce platforms: connecting a store authorizes us to access orders, products, customers, and inventory to power analytics and automation, in accordance with that platform's API terms.
Google (Analytics, Gmail, Sheets, Ads): we access only the data required for the features you enable. Gmail access is used exclusively to read supplier email, draft replies, and manage labels on your behalf. Analytics data is used solely to display performance metrics in your dashboard. This access complies with the Google API Services User Data Policy, including its Limited Use requirements.
Other integrations — marketplaces, ad platforms, email tools, and accounting systems — are governed by their respective platform policies. We do not share your data beyond what is strictly necessary to deliver the integration you enabled.
8. Sub-processors
A small number of providers process data on our behalf to run the Service. They may use it only to deliver the Service to you, and are bound by data-processing terms.
- AI model providers — Google (Vertex AI and Gemini), Anthropic, OpenAI, and DeepSeek — to generate analysis, drafts, and responses.
- Supabase — account identity, authentication, and billing records.
- Cloudflare — file and media storage, and network protection.
- Our hosting provider — the servers that run the Service and hold your isolated store database.
On model training. We do not train models on your data. Our AI providers process it under their own API terms, and where a provider offers a no-training or zero-retention setting for API traffic we use it. Provider terms differ and change, and we cannot guarantee that every provider excludes all API data from service improvement. If your business requires processing limited to providers with contractual no-training commitments, contact us before connecting sensitive data.
We will give at least 30 days' notice by email before adding a new sub-processor that processes store data, so that you can object. You can request the current list at any time from contact@tenpo.ai.
9. International Transfers
Tenpo and its sub-processors operate across more than one country, and we will tell you where your data is hosted on request. If you or your customers are in the European Economic Area, the United Kingdom, or Switzerland, your data may be transferred to and processed in a country that does not offer the same level of protection as your own. Where that happens we rely on the European Commission's Standard Contractual Clauses, the UK Addendum, or another lawful transfer mechanism agreed with the receiving party, and we will provide details of the mechanism used on request.
10. Cookies
We use only the cookies the Service needs in order to work. The main one is the session cookie that keeps you signed in — without it you could not stay authenticated. We do not use advertising cookies, and we do not run third-party analytics or tracking scripts on the Service. Because we set no non-essential cookies, we do not ask you for cookie consent. You can block or delete cookies in your browser, but you will not be able to remain signed in.
11. Your Rights
Depending on where you are, you may have the right to access, correct, or delete the personal data we hold about you, to receive a portable copy, and to restrict or object to certain processing. Request an export or deletion at any time by contacting contact@tenpo.ai. We respond within 30 days, or sooner where the law requires it, and we do not charge for these requests unless they are manifestly unfounded or excessive.
You can also turn off network learning in your account settings and unsubscribe from marketing email using the link in every such message. If you are in the EEA, the UK, or Switzerland you have the right to lodge a complaint with your local supervisory authority.
If you are a customer of a store that uses Tenpo: your personal data reached us through that merchant, who is the controller of it. Please contact the merchant directly. If you contact us instead, we will forward your request to them.
12. Data Retention
Account data is kept while your account is active. Store data synced from a connected platform is kept while that platform is connected and your account is active — we do not silently expire it, because your history is what makes the analysis useful.
You can remove it at any time. Disconnecting an integration with the delete-data option purges the tables synced from that platform. Deleting your account starts a 7-day grace period during which you can cancel; once it elapses we irreversibly purge your store database, memories, and account records. Residual copies in encrypted backups are removed as those backups age out of our normal rotation. Afterwards we keep only what we are required to retain for legal, tax, accounting, or fraud-prevention purposes.
13. Changes to This Policy
We may update this policy as the Service changes. The current version is always posted here with the date it took effect, and for material changes to how we use your data we will give at least 30 days' notice by email to your account address before they take effect.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, contact us at contact@tenpo.ai. We are committed to resolving privacy concerns promptly and transparently.
The same address reaches our grievance officer for the purposes of India's Digital Personal Data Protection Act, 2023. If we cannot resolve your concern, you may escalate it to the Data Protection Board of India, or to your local supervisory authority if you are in the EEA, the UK, or Switzerland.