Legal
How Tailro collects, uses, and protects your personal data.
Effective date: July 21, 2026
Tailro is a B2B SaaS appointment scheduling and business management platform designed for appointment-based businesses including boutiques, tailoring studios, salons, spas, clinics, and consultants.
Contact: [email protected]
Data Controller Roles: Tailro acts as the data controller for merchant account data (store owners and staff). Merchants act as data controllers for their customers' booking data. In that relationship, Tailro is the data processor acting on the merchant's instructions.
The AI booking assistant does not read Google Calendar contents, Google Calendar OAuth tokens, or Google Workspace API responses. It only uses Tailro platform data needed to help customers book.
| Data | Purpose | Legal Basis |
|---|---|---|
| Merchant email & name | Account creation, login OTP, transactional email | Contract performance |
| Google OAuth token | Sync appointments to merchant's Google Calendar | Explicit consent |
| Shopify access token | Manage booking link in merchant's Shopify store navigation | Contract performance |
| End customer email | Appointment confirmation and reminder emails | Legitimate interest / consent |
| End customer booking history | Display to merchant and customer, power analytics dashboard | Contract performance |
| Payment IDs (Razorpay) | Reconciliation, dispute resolution | Legal obligation |
| Subscription data | Plan enforcement, feature gating | Contract performance |
| Feature usage logs | Enforce plan limits (appointment quotas, staff limits) | Contract performance |
| File uploads | Display in booking pages and merchant dashboards | Contract performance |
| Request logs | Debugging, security monitoring (no long-term profiling) | Legitimate interest |
| AI booking chat messages | Power the in-product booking assistant so customers can ask questions and book appointments | Contract performance / consent |
The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
When a merchant connects Google Calendar, Tailro uses Calendar access only to support scheduling features for that merchant. This includes creating, updating, and deleting appointment events, attaching Google Meet links for online or hybrid appointments, and managing attendees for group sessions.
Tailro does not use Google Calendar or other Google Workspace user data to create, train, fine-tune, or improve foundational or generalized machine learning or artificial intelligence models. We also do not transfer Google Workspace or Calendar user data (raw, aggregated, anonymized, or derived) to third-party AI providers for those purposes.
Merchants can disconnect Google Calendar at any time from the Tailro dashboard. When disconnected, related Google Calendar tokens are deleted.
We share data with the following third parties only as necessary to operate the platform:
| Service | What We Send | Why | Their Privacy Policy |
|---|---|---|---|
| Razorpay | Merchant subscription billing amounts; customer appointment payments | Payment processing | razorpay.com/privacy |
| Google (Calendar API) | Appointment details (title, time, staff, meeting URL) | Sync to merchant's Google Calendar | policies.google.com/privacy |
| Google (OAuth) | Email address, name | Merchant & customer login | policies.google.com/privacy |
| Anthropic (Claude API) | Customer chat messages and Tailro booking-help context (services and availability from Tailro APIs). We do not send Google Calendar data, Google OAuth tokens, or Workspace API responses to Anthropic. | Power Tailro's AI booking assistant | anthropic.com/privacy |
| Shopify | Customer name, email, phone (sync on new booking) | Merchant requested customer sync | shopify.com/legal/privacy |
| Cloudflare (R2 Storage) | Uploaded files (logos, images, invoices) | Object storage & CDN | cloudflare.com/privacypolicy |
| Cloudflare (Custom Domains) | Merchant's custom domain hostname | SSL/DNS management for branded booking pages | cloudflare.com/privacypolicy |
| SMTP Email Provider | Recipient email, appointment details | Transactional emails | Provider's own policy |
Tailro's AI booking assistant uses Anthropic's Claude models through Anthropic's commercial API. In production we currently use Claude Haiku 4.5 (claude-haiku-4-5-20251001).
The assistant helps customers on a merchant's booking page by answering service questions and guiding them through booking. To do that, it may receive chat messages and Tailro platform data such as services and available slots returned by Tailro's own APIs.
The assistant does not call Google Calendar APIs and does not receive Google Calendar event contents, calendar lists, free/busy data, or Google OAuth tokens. Google Calendar sync is handled separately by Tailro's backend scheduling system after a booking is created or updated in Tailro.
Under Anthropic's commercial API terms, API customer content is not used to train Anthropic's foundation models. Tailro does not use Google Workspace or Calendar user data to train or improve any AI models.
| Data | Retention Period |
|---|---|
| Merchant account data | Duration of account + 90 days after deletion request |
| Staff records | Duration of account |
| End customer data | As long as their merchant relationship exists; customers can request deletion via merchant or [email protected] |
| Appointment records | Duration of merchant account (needed for merchant's business records) |
| Payment records | 7 years (financial/tax legal requirement) |
| Shopify integration tokens | Deleted immediately on disconnect or app uninstall (hard delete) |
| PendingShopifyInstall records | Deleted on completion or shop/redact webhook |
| OTP codes | 2 minutes TTL + swept by automated cron job |
| Google Calendar tokens | Deleted on calendar disconnection |
| Request logs | 30 days rolling |
| Uploaded files (R2) | Deleted when merchant deletes them or account is closed |
If you are located in the European Economic Area (EEA), you have the following rights:
Tailro is not directed at children under the age of 13 (or 16 in certain EU jurisdictions). We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a minor, please contact us at [email protected] and we will delete it promptly.
We will notify merchants by email of any material changes to this Privacy Policy. The effective date at the top of this page will always reflect the most recent version. We encourage you to review this policy periodically.
If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us at:
Tailro
Email: [email protected]
© 2026 Tailro. All rights reserved.