Tendlio works from the orders, products and customers already in your store, and keeps what it works out in your own WordPress database. The emails it sends go through the sending method you chose. We, the team behind Tendlio, receive your activation code and your site’s address when Tendlio checks the code, a summary of each analysis, and short usage events. Under Help → System status, the Store data section shows that summary exactly as Tendlio stores it.
What Tendlio keeps on your site #
Tendlio keeps these in your WordPress database:
- About each customer: their customer group, how many orders they’ve placed, how much they’ve spent, and the dates of their first and last order. Tendlio works these out again at each analysis.
- Abandoned carts and checkouts: the shopper’s email address and first name, the products and the cart total, once you switch on capture on the Recover sales page.
- Review requests: which order each request was about, and the rating and any message the customer sent back.
- Emails: a record of each email Tendlio sent (the kind of email, when it went out, whether it was delivered, and when it was opened or clicked, if your sending method reports that), and where each customer is in the welcome and second-order emails.
- The emails themselves: each email’s recipient address and name, subject and whole message, while it waits to go out and for up to 30 days after.
- The do-not-email list: customers who unsubscribed, and addresses that bounced or complained.
- On customer accounts, while Customer recognition is on: the day each logged-in customer last visited your store, and when they last got a Customer recognition coupon.
- On each order: where the shopper came from (the site that sent them, the tags on the link and which ad network, never who they are), and which products in the order the shopper had been shown, clicked or added to the cart.
- Storefront counts: views, clicks, add-to-carts and purchases, per product and per day, with no record of who the shopper was.
- Messages you send from Help: until Tendlio can deliver them, they stay on your site, listed under Help → System status.
- Summaries and usage events: the summary of each analysis and the usage events described below, until Tendlio sends them to us.
- Your activation code: the code, and what our server last answered about it.
Tendlio’s records hold email addresses of up to 170 characters. Tendlio doesn’t shorten a longer address to fit, because a shortened address can belong to someone else. It leaves that address out and never emails it.
How long Tendlio keeps it #
Unless you choose otherwise, Tendlio keeps most records without a time limit. Under Help → System status, Data retention sets how long Tendlio keeps older records: Forever (keep everything), 6 months, 12 months or 24 months. With a shorter period, Tendlio removes older records once a day: the record of sent emails, saved carts and checkouts, review requests, price history, and to-do cards that are done, archived or have gone away. Only an administrator can change this setting.
Some records stay whatever you choose:
- your scores, the score trend, and the product and customer results of past analyses, because your reports are built from them;
- the do-not-email list, so a customer who unsubscribed stays unsubscribed;
- where each customer is in the welcome emails, so nobody gets a welcome twice;
- which Customer recognition coupons each customer already got, so nobody gets the same one twice;
- your sales-lift history, so the Sales lift total keeps the sales it has already counted;
- to-do cards you marked Not relevant, so they don’t come back.
Two kinds of records follow their own schedule, whatever you choose:
- Storefront counts: Tendlio keeps them day by day for about 13 months, and as monthly totals for three years.
- The emails themselves: Tendlio deletes each one 30 days after it goes out. The record of sent emails follows your Data retention choice.
What leaves your site #
The emails Tendlio sends #
When Tendlio sends an email, the recipient’s address and name, the subject and the whole message go to the sending method you set up: your WordPress host’s mail, your Brevo account or your Amazon SES account. Any email tool works this way. It’s your account, under your provider’s terms.
The activation code check #
When Tendlio checks your activation code, it sends our server the code, this site’s address, the address Tendlio was first set up on (or a fingerprint of it), and whether Tendlio treats this site as your live store. Our server uses those four to tell your store from its copies, and keeps a list of the addresses each code has run on. A copy of your store sends this check too, and nothing else. The check runs once a day, when you click Activate or change the code in Settings, on the day the code ends, and when someone opens your WordPress admin and the last answer is more than 12 hours old.
What reaches us #
Tendlio sends us a summary of each analysis. Under Help → System status, the Store data section says whether your store sends it, and Preview the store data shows the summary exactly as it’s stored. The summary holds:
- your store’s totals and rates;
- how each Tendlio feature was used day by day, and what it produced;
- each storefront widget’s figures product by product, without saying which product;
- the values of your Tendlio settings, and the WooCommerce settings that change the figures, such as whether your prices include tax;
- a description of your setup: your WordPress, WooCommerce and PHP versions, your site’s language and time zone, whether your theme is built from blocks, and whether your site is a multisite;
- what else runs on your site: how many plugins are active, whether it uses an object cache, whether WordPress’s scheduled tasks are switched off, and which page builder and caching plugin you use, when Tendlio recognizes them;
- the parts of Tendlio where errors happened, without the error messages.
The summary never holds names, email or postal addresses, phone numbers, individual orders or carts, product names, or anything someone typed, such as widget titles, tag names or campaign names.
Usage events #
Besides the summary, Tendlio records short usage events:
- that it was installed and set up;
- which days someone opened it, and which of its pages;
- which help articles and Learn more sections were opened;
- which to-do buttons were used, and what happened to each to-do item;
- the reason you pick from the list if you deactivate it (never free text).
They show us which parts of Tendlio help and where people give up. Like the summary, they go to our server only from your live store, never from a copy of it.
Share usage events, under Settings → General → License & data sharing, is on from the start. If you switch it off, Tendlio stops recording usage events and deletes the ones it recorded before. The switch doesn’t cover the summary of each analysis, because your scores come from it.
Support requests #
When you send a message from Contact support, Tendlio attaches the System status summary to it: versions, settings, rough counts and recent errors. Before Tendlio stores an error, it masks any email address in it, so a customer’s address can’t travel inside an error message.
Your shoppers on the storefront #
What Tendlio measures #
Tendlio counts products, not people: each product’s views, clicks, add-to-carts and purchases per day, and on each order, where the shopper came from and which of its products they had been shown, clicked or added. It never records names, email addresses or IP addresses. The switch for this is Track widget and product performance, under Settings → General → Storefront, and it’s on from the start.
If you turn it off, your shop works as before, but the Storefront widgets and Views to sales reports get no new numbers from that day on, and Marketing & profit reads only WooCommerce’s own record of where orders came from.
Cookies #
Tendlio can set five cookies in a shopper’s browser. Settings lists all five under Storefront, with their categories, for your cookie banner:
tendlio_rec_srcandtendlio_seen(statistics): which widget led to a sale, and which products a shopper was shown. They hold product ids and times, andtendlio_rec_srcalso which widget each product was clicked in. Tendlio sets them while Track widget and product performance is on.tendlio_src(marketing): where the shopper came from, kept for up to 90 days, so their order can say which ad, search or site brought it. It holds the site that sent them, the tags on the link and which ad network’s click id the link carried, never the id itself. Tendlio also sets it only while Track widget and product performance is on.tendlio_viewedandtendlio_bought(preferences): what a guest looked at and bought, set by the Recommended for you row.
For the same measuring, Tendlio also keeps a short list of product ids in the shopper’s browser storage, so a product seen twice is counted once. For your cookie banner, that list counts as statistics, like tendlio_rec_src and tendlio_seen.
Recover sales doesn’t set a cookie. It remembers a guest’s checkout through the cart session WooCommerce already keeps.
Following each shopper’s cookie choice #
If your cookie banner supports the WP Consent API, Tendlio follows each shopper’s choice, with nothing for you to set up:
- A shopper who declines statistics gets neither measuring cookie nor the list in browser storage, and isn’t counted in views or clicks.
- A shopper who declines marketing gets no
tendlio_src, and their order carries no source from Tendlio. WooCommerce’s own order source tracking waits for the same marketing answer. - A shopper who declines preferences sees the Recommended for you row as a new visitor would.
Tendlio asks for the shopper’s choice in their browser, so this works on a shop with page caching too. If many of your shoppers decline, your reports count fewer visits than your shop gets, and your widgets get credit for fewer of their sales.
If your consent tool doesn’t support the WP Consent API, a developer can still connect it through the tendlio_visitor_tracking_allowed filter. The filter answers while the page is built, so on a shop with page caching it can’t follow each shopper.
Cart recovery doesn’t follow these choices on its own: the email address is one the shopper typed into your checkout, and Recover sales has its own switch. If your cookie banner supports the WP Consent API, you can make the reminder follow the marketing choice: under Marketing consent in the Recover sales settings, turn on Don’t send the reminder to shoppers who declined marketing in your cookie banner. Those shoppers then get neither the reminder nor the offer that follows it. Tendlio still saves their cart.
A customer asks for their data, or wants it erased #
WordPress has a tool for each request, Tools → Export Personal Data and Tools → Erase Personal Data, and Tendlio answers both. You enter the customer’s email address there, and WordPress can email the customer to confirm the request. Once the customer confirms, WordPress emails you, and you finish the request on the same page: click Send export link next to an export request, or Erase personal data next to an erasure request. WordPress then collects or erases the customer’s data, Tendlio’s included.
Export returns, for one address, seven groups: Tendlio’s customer analysis, abandoned carts and checkouts, review requests, emails sent, emails waiting to be sent, welcome and follow-up emails, and the do-not-email list.
Erase removes, for that address: the customer analysis, saved carts and checkouts, review requests, the emails themselves (waiting or already sent), their place in the welcome and follow-up emails, the last-visit and Customer recognition marks on their account, and their place in a campaign that hasn’t reached them yet. Unused coupons Tendlio made for them go to the trash.
Tendlio keeps these on purpose:
- the address on the do-not-email list, so nothing Tendlio sends can reach it again;
- the record of emails already sent to that address;
- coupons the customer already used, because the discount is part of an order’s price;
- sales-lift figures already worked out, which no longer carry the address;
- which Customer recognition coupons the customer already got, kept with their account and a coded form of their email address, so they don’t get the same one twice.
The erase tool’s results list the first four, each with its reason.
An erased address never gets another email from this plugin. Removing the address from the do-not-email list is the one thing that could undo that, and only the customer can do it, from the email preferences link in an earlier email from Tendlio.
Tendlio works out its customer analysis from your orders again at each analysis, so as long as the customer’s orders are in your store, the next analysis adds the customer back. To remove the personal data in their orders, run WooCommerce’s own erasure as well. It runs in the same request when Remove personal data from orders on request is ticked under WooCommerce → Settings → Accounts & Privacy. The next analysis then no longer finds their email address in those orders.
Additional resources #
- Who you can email (consent, in plain words)
- How to recover abandoned checkouts and carts: the Marketing consent switch.
- Measuring what the widgets earn: what the storefront counts are used for.
- Starting over, or what happens if I uninstall: removing all of Tendlio’s data.
- How to use the System status page
Frequently asked questions #
Does Tendlio send my customers' data to its servers? #
No. Once a server connection is set up, Tendlio sends a summary of each analysis with your store's totals and rates. It never holds names, email or postal addresses, individual orders or product names.
Which cookies does Tendlio set? #
Up to five: tendlio_rec_src and tendlio_seen (statistics), tendlio_src (marketing), and tendlio_viewed and tendlio_bought (preferences). Settings lists them with their categories.
What happens when a customer asks to be erased? #
Run WordPress's Erase Personal Data tool, and once the customer confirms, click Erase personal data next to the request. Tendlio removes most of what it keeps about that address and puts it on the do-not-email list, so nothing Tendlio sends can reach it again.