Skip to content

Security

How we handle the data you trust us with. The same posture everywhere: the minimum access required, protected while we hold it, deleted when we no longer need it.

Access model

Tacet connects to client systems with the minimum access required to deliver the Service, and every scope we request is explicitly justified.

  • Access to commerce platforms is read-only for analytical purposes
  • We never write to your store and never modify your systems
  • We never contact your customers
  • Scores are delivered through platform integrations you authorize, such as Klaviyo

Data protection

We implement commercially reasonable technical and organizational safeguards designed to protect client data from unauthorized access, disclosure, alteration, or destruction. These include:

  • Encryption of sensitive information
  • Access controls restricting data to authorized personnel
  • Logical separation of each client's data
  • Secure infrastructure practices, continuously evaluated and improved

Data lifecycle

We retain client data only as long as necessary to provide contracted services and meet legal obligations.

  • If an engagement ends after the free diagnostic, the data used to produce it is deleted
  • When a subscription ends, personal data is deleted in accordance with our contractual agreements

What we never do with client data

We do not sell client data.

We do not use identifiable client data for advertising or marketing.

We do not contact our clients’ customers.

Anonymized, aggregated data that cannot identify any individual or business may be used to improve our models, as described in our Privacy Policy.

Data Processing Agreement

A Data Processing Agreement covering our obligations as a data processor, including confidentiality, security measures, and deletion, is available as part of contracting. Request a copy at legal@tacet.ai.

Reporting a security concern

If you believe you have found a vulnerability in our website or services, we want to hear about it. Contact security@tacet.ai, or see security.txt. We review every report.