Privacy Policy

[Effective date to be set at launch]

This policy explains what Tilly collects when you use it, why, and what you can do about it. Tilly is a product of Mybranz, Inc. ("Mybranz", "we", "us").

The short version: running the free audit on a store URL reads only what is already public. Connecting your Shopify, Klaviyo, Meta or Google account lets Tilly read the data those platforms hold about your store so it can build accurate emails, ads, posts and page fixes, and nothing built from that data is sent anywhere without your approval.

What we collect

The free audit reads your storefront the way a visitor does: product pages, collection pages, published reviews and public policies. It needs no login and no account.

If you create an account, we collect your name, email address and the store URL you sign up with. Sign-in works by emailing you a one-time link rather than storing a password.

  • Shopify: products, collections, orders, customers and their reviews, and your theme, when you connect a store.
  • Klaviyo, Omnisend or Shopify Email: your lists, flows, campaigns and their results, when you connect an email tool.
  • Meta and Google: ad accounts, campaigns and their results, when you connect them.
  • What you type: edits you make to a draft, approvals and dismissals, and support messages you send us.
  • Usage data: which pages you visit and which features you use, so we can tell what is confusing and fix it.

Why we collect it

To run the product: building an email, an ad or a page fix means reading your products, your past orders and your reviews so the draft is about your store and not a generic one.

To build customer personas from what your own reviews and orders actually show, never from a purchased list or a third-party audience.

To bill for what you use: credits are metered against the actions in this policy's companion, the Terms of Service, and payment is processed by Stripe, who receive your payment details directly — Tilly never stores your card number.

To improve the product, using aggregated and de-identified usage patterns, not the content of your store or your customers' data.

What we never do

Nothing you connect is published, sent or made public until you approve it. An email flow, an ad, a blog post or a theme change all sit as a draft you can read, edit or dismiss first.

We do not sell your data or your customers' data, and we do not use your store's data to build or train a product for anyone other than you.

We do not read quotes, evidence or anything from a connected account into the one page that is shareable without a login (an audit result page); that page shows the summary score and personas only.

Who we share it with

The platforms you connect: Shopify, Klaviyo, Omnisend, Shopify Email, Meta and Google each receive what is needed to publish the draft you approved, through their own APIs, under their own terms.

Service providers who process data on our behalf under contract: hosting and database infrastructure, Resend for account emails, Stripe for payment, and the AI providers whose models draft the copy and creative you review — Anthropic and OpenAI, at the time this was written. None of these providers may use your data for anything but running Tilly.

We disclose data if the law requires it, or to protect the rights, property or safety of Mybranz, our users, or the public.

How long we keep it

Account and store data for as long as your account is open, plus a reasonable period afterward for backups, fraud prevention and legal obligations.

A shared audit result page persists until you delete your account, since the link to it may already be shared.

You can ask us to delete your account and the data attached to it at any time; see "Your choices" below.

Your choices

Disconnect any connected platform at any time from your account settings; Tilly stops reading new data from it immediately.

Export or delete your account and the data attached to it by writing to the address below.

If you are in the UK, EU, or a US state with its own privacy law, you may have additional rights to access, correct, port or restrict the use of your data — the same request address handles all of these.

Security

Data in transit is encrypted, and connected-account tokens are stored encrypted rather than in plain text. No system is perfectly secure, and we will tell you if a breach affects your data as the law requires.

Children

Tilly is a business tool for people running a Shopify store. It is not directed at, and we do not knowingly collect data from, anyone under 16.

Changes to this policy

If this policy changes in a way that matters, we will tell you by email or by a notice in the product before the change takes effect.

Contact

Questions, requests or complaints about this policy: [privacy contact email to be set at launch]. Mybranz, Inc., [registered business address to be set at launch].