Legal

Privacy policy

Last updated: October 9, 2026

This policy explains what we collect when you use Tendlio and this website, why we need it, and what you can ask us to do with it.

What we collect

Your account. When you start a trial or buy a license we keep your name, email address, the address of your store, your license key, and your billing history (which plan, which dates, which amounts). Payments go through Paddle, our reseller and merchant of record. Paddle collects your payment details and your billing address; we never see your card number.

Your store data, inside your store. The Tendlio plugin runs inside your own WordPress installation. It reads your orders, customers and products there, and it stores its results (scores, to-do items, saved carts, email logs) in your own database, next to your WooCommerce data. Your customers’ names, email addresses, addresses and order details never leave your server as part of Tendlio. We cannot see them, and we do not want to.

What the plugin sends us. After each analysis the plugin sends us a summary so we can score your store, keep the product working, and compare your store with others of a similar size. It holds numbers, never your customers and never your product names: how many customers, products and orders you have; your retention, stock-health and margin figures and how they are spread (for example how many days pass between a customer’s orders); monthly order counts (which also set your price band); for each Tendlio feature, whether it is on, since when, what it did each day and each month, and what that produced; the figures each storefront widget recorded for every product it showed, with the product left out; how close past forecasts came to what sold; the values of your Tendlio settings; the shape of your catalog and your orders (how prices and basket sizes are spread, the hour and weekday orders arrive, and which of WooCommerce’s order sources they came from); how far you got through setup (the dates of steps such as the first widget switched on); how many errors the plugin logged and in which part of the plugin, never the error message; and technical facts about your setup (PHP, WordPress and WooCommerce versions, whether your theme is a block or a classic theme, which kind of page builder and page cache you use, how many plugins are active, your store’s currency, country, locale and time zone offset). There is no text in any of it: no names, email addresses, product names, widget titles, campaign names, custom order status names, or the names of your theme and plugins. The plugin also sends short usage events: that it was installed, that setup was completed, which days someone opened the admin and which of its pages, which guides and “Learn more” sections were opened, which to-do buttons were used and what happened to each to-do item (shown, done, archived, snoozed), and the reason you pick from a list if you deactivate it. You can switch usage events off in the plugin’s Settings; the summary of each analysis is part of the service and that switch does not cover it. There is no free-text field in any of this. Your store is identified by a pseudonymous id that the plugin derives from your site address with a secret key stored only on your server; we cannot turn it back into your address. You can read the exact payload at any time in the plugin under Help, System status.

Your activation code. When Tendlio checks your activation code (at least once a day, and when you click Activate), it sends our server the code, your store’s address, the address Tendlio was first set up on (or a fingerprint of it), and whether Tendlio treats the site as your live store. We use them to tell your store from its staging copies, and we keep a list of the addresses each code has run on.

This website. When you sign up for the trial or the launch email, or ask for early access, we store your email address and, if you give it, the address of your store. When you send us a message through the contact form we store your name, your email address, the store address if you give it, and what you write. Our web server keeps standard access logs (IP address, page, time, browser) for security and to keep the site running.

The chat on this website. When you write to Lio, the AI assistant in the chat window, we keep what you write and its replies, the title and address of the page you wrote from, the time, and your IP address. The IP address lets us apply daily message limits and block someone who abuses the chat; for that block list we also keep a scrambled (hashed) copy of it. Conversations are stored on our website’s server; our team reads them to improve the assistant’s answers and may join a conversation to reply in person. Please do not type passwords, card numbers or other sensitive details into the chat; for anything about your account, write to support@tendlio.com.

How we use it

  • To provide the service you asked for: creating your license, activating the plugin, scoring your store, delivering updates and answering support. Legal basis: the contract with you.
  • To send you the emails that belong to the trial and to your subscription: the trial key, setup tips during the trial, renewal reminders, receipts. Legal basis: the contract with you. Marketing emails beyond that go out only if you asked for them, and every one has an unsubscribe link.
  • To improve Tendlio and to build anonymous comparisons across stores (“stores your size keep 31% of customers”). Legal basis: our legitimate interest in understanding how the product performs, balanced by the fact that the summaries carry no personal data and no store name.
  • To answer the questions you ask in the chat and to keep the chat free of abuse. Legal basis: our legitimate interest in answering visitors’ questions, and the steps you ask for before buying.
  • To keep the site and our servers secure, and to keep our accounts. Legal basis: our legitimate interest, and the legal duties we have to keep billing records.

We do not sell personal data and we do not share it with anyone for their own marketing.

Cookies and analytics

This website sets one cookie for every visitor: __cf_bm, which Cloudflare (the network in front of our hosting) uses for about 30 minutes to tell people from automated traffic. If you log in to WordPress, WordPress sets its own login cookies; visitors never log in.

The website also uses Google Analytics and Microsoft Clarity to count visits and to see how people use its pages: which pages they read, where they click and scroll, and which sites send them. Visitors from the European Union, Norway, Iceland, Liechtenstein, the United Kingdom, Switzerland and Serbia see a cookie banner first. Until you accept, neither tool sets a cookie: Google Analytics sends Google a signal without an identifier when a page loads (which page, the time, your browser and the site that sent you), and Microsoft Clarity records the page as a separate visit that it cannot connect to your other visits. If you accept, Google Analytics sets the cookies _ga and _ga_5TXJM04X8F for up to 2 years, and Clarity sets _clck and _clsk, which connect your page views into one visit; Microsoft may also set its own cookies on its Clarity domain. Visitors from other countries get these cookies without a banner. The banner remembers your choice in cookies whose names start with cmplz_ and wp_consent_, and if you reject, the website removes the Google Analytics and Clarity cookies. You can change your choice at any time through Cookie settings at the bottom of every page. We do not use an advertising tracker on this website.

The chat sets no cookie. Until you use it, it keeps only a note in your browser’s session storage, for the current visit, that the small hint above the chat button was already shown (tdchat_teaser_seen), and, if you hide the chat button, that you did (tdchat_mini). When you open the chat it saves tdchat_opened in your browser’s local storage, so the hint is not shown to you again, and when you send your first message it saves a random conversation id there (tdchat_session), so the conversation continues on the next page and on your next visit. Only this website reads them. When you open the chat, Cloudflare Turnstile runs a short check in your browser to tell people from automated traffic before your first message is accepted. The chat window is masked in Clarity’s recordings, so what you write in it is not recorded.

The plugin on your shop can set five small cookies for your own shoppers, each for a feature you switched on. For measurement (the statistics category): tendlio_rec_src remembers which Tendlio recommendation a shopper clicked, for up to 7 days, so a later purchase can be credited to the right feature, and tendlio_seen remembers which products the shopper was shown, for the same 7 days, so a purchase can be linked to a showing; both hold product ids and times only. For the order source (the marketing category, the one WooCommerce’s own order attribution follows): tendlio_src keeps where the shopper came from (the site that sent them, the tags on the link, and which ad network’s click id the link carried, never the id itself) for up to 90 days, so the order they place can say which ad, search or site brought it. For the “Recommended for you” row (the preferences category): tendlio_viewed keeps the last products the shopper looked at and tendlio_bought what they bought, for 60 days, so the row can suggest what goes with them. None of these cookies is read by us; they are read by the plugin on your server. Cart recovery sets no cookie of its own: it links a checkout the shopper left unfinished to their cart through the session cookie WooCommerce already uses for the cart. If your shop uses a cookie consent tool that supports the WP Consent API, the plugin follows each shopper’s choice: without statistics consent it sets neither measuring cookie and counts none of their page views or clicks, without marketing consent it sets no tendlio_src and notes no source on their order, and without preferences consent the recommended row treats them as a new visitor. If you list cookies in your consent tool, list all five. Tendlio does not add any third-party analytics or advertising script to your shop, and none of these cookies is sent to an ad network.

Third parties and hosting

  • Kinsta hosts this website and our servers. The website runs in Kinsta’s data center in Chicago, in the United States. The server that receives the plugin’s summaries and checks activation codes runs in Frankfurt, Germany. Cloudflare runs the network in front of them that delivers the pages and filters automated traffic, and Turnstile, the check that keeps automated traffic out of the chat.
  • Anthropic provides the AI model behind the chat assistant. What you write in the chat, with the title and address of the page you wrote from, is sent to Anthropic to generate each reply. Anthropic processes it on its servers in the United States as our service provider, does not use it to train its models, and deletes it within 30 days, unless it has to keep it longer to enforce its usage policy or to comply with the law.
  • Paddle sells the license to you as our reseller and merchant of record: it runs the checkout, charges you, adds the taxes your country requires, issues the invoice and handles refunds. Paddle’s privacy policy covers the payment itself.
  • Brevo stores the email addresses from the forms on this website and sends the emails we send you.
  • Google runs Google Analytics for us (see Cookies and analytics). Google processes that data on its own servers, including in the United States, and Google Analytics does not log or store your IP address.
  • Microsoft runs Clarity for us (see Cookies and analytics) and processes that data on its own servers, including in the United States.
  • Your own email provider sends the emails the plugin sends to your customers. Tendlio connects to the account you choose (your Brevo, Amazon SES or your WordPress mail), so those emails go out under your name and your provider’s terms, not ours.

Each of these companies processes data only on our instructions and under a contract that requires them to protect it, except Paddle, which processes your payment data as a controller in its own right.

Retention

  • Account and license data: for as long as your license is active, and for 12 months after it ends, so you can come back without starting over. Invoices stay for as long as tax law requires.
  • Store summaries and usage events: for as long as we run the service, in pseudonymous form. If you ask, we delete every row tied to your store id (you find the id in the payload under Help, System status).
  • Website sign-ups and messages: until you unsubscribe or ask us to delete them, and at most 24 months after the last email you opened.
  • Chat conversations: 12 months after the last message, then deleted automatically, together with the IP address stored with them; the chat’s block list follows the same rule. To have yours deleted sooner, write to support@tendlio.com and tell us roughly when you wrote and from which page.
  • Server logs: 30 days.
  • Google Analytics data: 14 months, after which Google deletes it.
  • Microsoft Clarity data: session recordings for 30 days and heatmaps for 13 months, after which Microsoft deletes them.
  • Data inside your store: yours, on your server. Uninstalling the plugin with “delete all data” removes every table and setting it created; deactivating keeps them so you can come back.

Your rights (GDPR)

If you are in the European Union, the United Kingdom or another place with similar rules, you can ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, ask us to stop using it in a particular way, or ask for it in a file you can take elsewhere. We answer within 30 days. For data inside your store, you are the controller and the plugin gives you the tools: the customer list exports and erases a customer, and the WordPress privacy tools cover the rest.

Contact

Write to support@tendlio.com or use the contact form on this website. If you are not satisfied with our answer, you can complain to the data protection authority in your country.

Tendlio is made by Super Zivot d.o.o., the data controller for the information in this policy.