Privacy policy

Last updated: July 19, 2026

Tend (“we”, “us”), operated by Convect Technologies Ltd, helps small shops run their Instagram DM and comment conversations with customers, take orders and payments out of those conversations, and reach nearby shoppers through its public marketplace at tendto.you. Tend runs on the web and in a mobile app. This policy explains what personal data we collect from shop owners, from the customers who message and buy from their shops, and from shoppers browsing the marketplace — why we collect it, and how we protect it.

Roles

Three kinds of people's personal data flow through Tend:

  • Shop-owner data: your sign-in identity and the configuration you enter (products, prices, policies, notes). For this we are the data controller.
  • Customer content: the DMs and comments your shop receives from third-party Instagram users, and the order details that come out of them — including any delivery or shipping address, and the answers to any questions you ask at checkout. For this content your shop is the data controller and Tend acts as a processor on your behalf, under instructions set by your use of the product. A data processing addendum (DPA) is available on request at hello@tendto.you.
  • Marketplace shoppers: people who sign in to search the marketplace and buy from the shops on it. For a shopper's own account, their searches, and the view of their orders and tickets collected across shops, Tend is the data controller. (The order details a shopper gives a particular shop at checkout are that shop's customer content, controlled by the shop as above.)

What we collect

You can sign in four ways, and what we receive depends on which you use:

  • Instagram: your Instagram user id, username, and an access token scoped to read your Instagram DMs and comments and to reply on your behalf (scopes: instagram_business_basic, instagram_business_manage_messages, instagram_business_manage_comments). We do not receive your email or phone number from Meta.
  • Google: your name, email address, and Google account id. The same consent screen also includes the scope that lets Tend create and manage its single “Tend” calendar (see Google Calendar below).
  • Apple (in the mobile app): Sign in with Apple returns a stable identifier for you and the name and email you agree to share. Apple lets you hide your real email behind a private relay address.
  • Email & password: the email address you register. Passwords are kept only as a hash, never in plain text. We send verification and password-reset emails to that address through our email provider, Resend.

We store the customer-facing DM threads your shop receives: message text, attachments, the sender's Instagram handle, profile name and profile photo, and timestamps. We also store any shop policies, products, or notes you enter into the app yourself.

If you turn on comment replies, we also store the public comments left on your Instagram posts that the feature reads and responds to (comment text, commenter handle, timestamps). A related feature scans your recent public post comments to suggest answers to common questions for your shop; before that comment text is sent to an AI model, the commenter's identity is removed.

If you join the waitlist before signing up, we collect the email address you submit. We use it only to contact you about access and you can ask for it to be removed at any time.

For paying accounts, we store billing-related identifiers from Stripe for your own Tend subscription (your Stripe customer id, subscription id, plan, status, trial end, and current-period end date). We do not see or store your card number, CVC, or bank details. Those live with Stripe.

To take payment from your own customers you connect a payout rail, and we store what we need to create checkouts on your behalf and to record the result. With Stripe Connect we store your connected-account id and its charge status, and per order the Stripe Checkout Session / payment-intent id and whether it was paid. With Paystack we store your subaccount details (the account name, bank, and last four digits of the account number) and per-order transaction status. In both cases we never see or store your customers' card numbers; the payment provider handles those on its own page. This is separate from the Stripe subscription that bills you for Tend: there, Stripe is our payment processor; here, your own connected account collects money from your customers.

We track per-day usage counters (number of drafts produced, owner calls placed, call minutes used, inbound and outbound messages) for billing, capacity planning, and the in-app usage dashboard. These counters are aggregate per shop and don't contain message content.

If you connect your Google Calendar, we ask Google for permission to create and manage one calendar in your Google account (named “Tend”). We do not request, and Google does not grant us, access to your primary calendar or any other calendar you own or share — only the single calendar Tend creates. When a booking is created, changed, or cancelled in Tend, we write it into that calendar: the booking time and duration, the product name, the customer's name or Instagram handle, and any notes you saved. We do not read your other calendars. We store an OAuth refresh token, an OAuth access token, and your Google account email (so we can show “Connected as <email>” in Settings). Tokens are encrypted at rest.

We log standard request metadata (timestamps, IP addresses, user agents) for security and debugging, retained for up to 90 days. Each active session record also stores the IP address and browser information it was created from. When you first sign up, we do a one-time, country-level lookup of your IP address to set your shop's default currency.

AI processing and retention

Instagram DM and comment content, and the order details drawn from it, is processed by AI models (Anthropic's Claude) to classify customer messages, draft your shop's replies, build up orders and carts, and surface order details. Whether a draft is sent automatically or waits for you to handle depends on your shop's settings.

The model providers are reached through AWS Bedrock in the EU and are configured for zero data retention on our traffic. We do not share conversation content with advertisers and we do not sell it.

Tend itself keeps a copy of each AI request and response for up to 180 days. Because a request carries the material the model needs to do its job, a copy can include message text, order details, and the names inside them. We keep these copies to debug problems, evaluate the quality of Tend's AI, and improve Tend's AI features. Access is restricted to a small number of named Convect staff. The copies expire automatically within 180 days, including after an account is deleted.

We do not use this content to train the model providers' models. If we ever use stored content to improve our own models beyond debugging and evaluation, we will update this policy before we do.

Owner calls

Tend can call you when the bot needs a decision on a customer message. Here is how that works and what it involves:

  • We collect a phone number from you and verify it with a one-time code sent to you over WhatsApp.
  • Calls are placed to you over WhatsApp calling.
  • During a call, the audio is streamed in real time to Google's Gemini Live API through infrastructure Convect runs. The AI on the call is briefed with your shop context (products, prices, delivery area) and the details of the order in question, including the customer's name, so it can ask you the right question.
  • We store the transcript and a written summary of the call, not the audio.
  • After the call, an Anthropic model turns your answer into the customer-facing reply.

Your number is never shared with customers and never used for marketing. You can pause owner calls at any time, set quiet hours, or remove your number to opt out entirely.

Marketplace (tendto.you)

Tend runs a public marketplace at tendto.you where shoppers can find local shops. Your shop is listed there automatically once it meets the listing requirements: a claimed public shop handle, a shop name, a location, and a connected Instagram account. The listing is drawn from information you have already published or entered: your shop name and handle, your tagline and trade, your logo, your location at the precision you choose in Settings (a neighbourhood or area such as “Rathmines, Dublin 6”, or a full street address if you opt into that), your products and prices, your opening hours, your published answers to common questions, and your public Instagram posts (their captions and images). It does not include your DMs, your customers' messages, or your contact details.

To power search, this published shop content is turned into numerical embeddings by an embedding model running on AWS Bedrock (Cohere's model), including the images on your Instagram posts. When a shopper searches, their typed query is embedded the same way and matched against shops.

Searching or chatting on the marketplace requires signing in. We store your search conversation and your recent searches on your account and show them back to you as “recents”. By default we work out an approximate, city-level location from your IP address so we can show nearby results — on the website from the connection details our hosting provider passes us, and where that isn't available (and in the mobile app) by looking your IP address up through ipwho.is, a third-party service. We never ask your browser or phone for precise location on its own; you can grant it yourself, from the location picker, for more accurate nearby results. When you type a place into a location search, that text goes to Photon, a geocoding service run by Komoot (komoot.io), directly from your browser or the app.

Checkout, tickets, and shipping

When you buy from a shop through Tend, at checkout we collect your name, email, and phone number, and — for delivery — a delivery address. As you type an address, the text is sent to Google Places (through our server) to offer autocomplete suggestions; once an order has a delivery address, we send it to Google's Maps Geocoding API to turn it into coordinates and check it against the shop's delivery area. A shop can add its own questions at checkout; the shop sees and can export your answers together with the order, so answer them as you would answer the shop directly — Tend does not control what a shop asks. An order page is reachable by an unguessable link, so you can pay without an account; anyone who has that link can view that order, so don't forward it. Buyers receive order-confirmation and refund emails through our email provider, Resend. If you are signed in as a shopper, your orders and tickets are collected under your account so you can find them again.

A ticket's QR code is an unguessable token. If you add a ticket to Apple Wallet or Google Wallet, the pass contains the ticket barcode, the event, the tier, the venue (including its location), and the attendee name; Google Wallet passes are issued through Google. At the door, the shop scans the QR code and sees the attendee name; scanning decodes the code on the device and captures no photos.

When a shop buys a shipping label for your order, your name, address, and contact details are sent to the shop's connected shipping provider (Packlink, Parcel2Go, or An Post's Intersoft SAPIENT gateway, depending on the shop) and printed on the label. The label itself is stored privately and reachable only through short-lived links.

The mobile app

Our mobile app for iOS and Android can, with your permission, use some of your device's features:

  • Location: optional, and used only while the app is open, to show shops and availability near you. If you don't grant it, we fall back to the approximate IP-based location described above.
  • Camera: used only to scan ticket QR codes at event check-in. Nothing is recorded; the code is read on the device.
  • Photo library: used only when a shop owner adds product or shop images.

On your device, the app keeps your session token, your cart, your last known location, and cached images in the app's own sandboxed storage. If the app crashes, a report is sent to Convect's self-hosted error tracker; it includes a trail of the recent screens and taps, scrubbed of account identifiers (such as your email and IP address) before it leaves your device. The app records the same first-party product-analytics events as the web (see Product analytics below), tagged with a random session id generated each time the app launches. The app can also receive over-the-air updates to its code from us.

The app sends no push notifications, contains no advertising or tracking SDKs, and does not track you across other apps or websites.

Google API user data

Tend's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use Google Calendar data only to provide the calendar sync feature you opted into, reflecting your Tend bookings on your phone & desktop alongside the rest of your life.
  • We do not transfer Google user data to any third party except as necessary to provide that feature, comply with applicable law, or as part of a merger or acquisition with equivalent privacy protections.
  • We do not use Google user data to serve advertisements.
  • We do not allow humans to read Google user data unless we have your explicit consent for a specific message, it is necessary for security investigations or to comply with law, or it is aggregated and de-identified for internal operations.

You can disconnect Google Calendar at any time from Settings → Calendar in Tend, or by revoking access at myaccount.google.com/permissions. On disconnect we revoke our token at Google and delete the encrypted token + email from our database. The Tend calendar in your Google account remains under your control; you can delete or keep it as you wish.

Subprocessors

We rely on a small set of providers to run the service:

  • Meta Platforms: the source and delivery channel for Instagram DMs and comments, and for WhatsApp messages and calls. The one-time codes that verify your phone number, the flag notifications sent to you, and the owner calls themselves are all carried over WhatsApp.
  • Amazon Web Services (EU, Ireland): serverless compute, queueing, storage, and AI inference. Media (product and shop images, event covers, and the Instagram attachments mirrored from your conversations) is stored in S3 and served over unguessable public links. A separate, private store holds the AI request / response diagnostics copies described above, and another private store holds our first-party analytics events. AI inference runs on AWS Bedrock, in-region.
  • Anthropic: the AI model provider (Claude), used through AWS Bedrock for classification, drafting, cart-building, and turning owner-call answers into replies.
  • Cohere: the embedding model (through AWS Bedrock, in-region) that turns marketplace shop content and shopper searches into vectors for semantic search.
  • Google: several services — sign-in (name, email, account id); Google Calendar sync (the single “Tend” calendar only); Maps Places autocomplete (the address text a customer types at checkout is sent to Google under a per-session token) and Geocoding (turning a delivery address into coordinates); Gemini Live (the audio model used during owner calls); and Google Wallet (event passes are issued through Google).
  • Apple: Sign in with Apple (in the mobile app) and Apple Wallet passes.
  • Stripe: processes your Tend subscription payments, and, via Stripe Connect, the card and bank-debit payments your shop takes from its own customers. Stripe handles the card details on its own page; we never see card numbers, only Stripe identifiers, subscription state, and per-order payment status.
  • Paystack: a live payment rail for shops in supported regions. Each shop gets its own Paystack subaccount. The payer enters their card details on Paystack's own hosted page; Tend never sees card numbers.
  • Photon by Komoot (komoot.io): turns location-search text into places. The text is sent straight from your browser or the app.
  • ipwho.is: works out an approximate location from your IP address — in the mobile app, and on the website when our hosting provider doesn't already tell us the city.
  • Resend: sends our transactional emails — verification and password-reset emails, order-confirmation and refund emails to buyers, and sale notifications plus a trial-ending reminder to owners. Transactional only, never marketing.
  • Shopify: for shops that connect Shopify, syncs the product catalogue only (read-only product access). No customer data is exchanged.
  • Eventbrite: for shops that connect Eventbrite, imports event listings using the connecting owner's own Eventbrite identity. Imported events link out to Eventbrite; Tend does not take those ticket payments.
  • Acuity Scheduling: for shops that connect Acuity, we receive the connecting owner's Acuity identity (name, email) and mirror the shop's own appointment-type catalogue as link-out listings. No customer data is exchanged.
  • Packlink / Parcel2Go / An Post's Intersoft SAPIENT gateway: shipping. When a shop buys a label, the recipient's name, address, and contact details are sent to the shop's connected shipping provider and printed on the label.
  • Vercel: hosts the web app and, for shops on a custom domain, serves that domain.

We previously offered SumUp as a payment rail. We no longer process new SumUp payments. We keep historical SumUp payment records, and the stored SumUp credentials are retained only to complete the wind-down.

Cookies & local storage

We use a session cookie (set by our authentication library) to keep you signed in. We do not use third-party advertising or analytics cookies, and no tracking pixels or cross-site trackers, so there is no consent banner to click through. The app also keeps non-tracking UI preferences in browser storage, and a rotating, anonymous analytics session id in the browser's session storage that groups your own product-usage events within a session (see Product analytics below). Fonts are served by us, not fetched from a third party as you browse.

Product analytics

To understand what's useful and improve the product — above all which results and features people actually engage with — we collect a small set of first-party interaction events as you use Tend on the web and in the mobile app: that a card or element was shown (an impression) or tapped (a click), which kind of element it was, and which screen you were on. This covers both the marketplace and the shop dashboard.

These events are first-party and self-hosted: they are sent only to our own infrastructure on AWS (eu-west-1), never to any third-party analytics or advertising service, and they are used only to measure and improve Tend. Each event carries an anonymous, rotating session id (not your name), the identifiers of the shop, product, or element involved, the screen, and a timestamp. Where you run a search or tap a suggested prompt, the text you entered is included too. Events never contain message content or your customers' data. We keep them for about 13 months, after which they are deleted automatically.

These events are never linked to your name or account id: each one carries only the anonymous per-session id, whether you are a signed-in owner, a signed-in shopper, or using the app. We use them only for aggregate analysis, not to profile individuals.

Your rights

You can:

  • Disconnect a linked account at any time: Instagram via its Settings → Apps and Websites, or Google via your Google account permissions. We'll receive the deauthorization signal (or revoke our own token) and immediately drop the linked credentials.
  • Revoke Sign in with Apple from your Apple account settings. Apple notifies us, and we delete the link and sign your Tend sessions out.
  • Request access, correction, export, or deletion of all data associated with your account by emailing hello@tendto.you. We carry that out within 30 days. See our data-deletion page for how to make the request.
  • Use Meta's data deletion request flow; we honour those via the data-deletion callback registered with our Meta app.
  • If you're in the EU/UK, you can lodge a complaint with your local data protection supervisory authority. The Irish Data Protection Commission is our lead authority.

Customers of your shop

If you messaged or bought from a shop that uses Tend: your messages and order details reach Tend only because you chose to contact or buy from that shop. Your shop is the controller of that content and is the right party to handle deletion or access requests in the first instance. You can also contact us directly at hello@tendto.you and we'll route or action the request as appropriate.

Children's privacy

Tend is a tool for shop owners and their customers and is not directed at children. We don't knowingly collect personal data from anyone under 16. If a customer message arrives that you believe came from a child, treat it according to your local rules and contact us if you need the data removed.

Data location and retention

All data is processed and stored in the European Union (AWS eu-west-1, Vercel EU regions where applicable). Your DM and comment messages are kept for as long as your account is active. When you ask us to delete your account, we carry that out within 30 days; backups roll off within 90 days.

Two things keep their own clocks. The AI request / response copies described above expire automatically within 180 days — they outlive account deletion only until that expiry. Product-analytics events are kept for about 13 months. See our data-deletion page for how to request deletion of your account and data.

Security

Access tokens are stored encrypted at rest, under a key managed with AWS KMS. Webhook payloads are verified against the sending platform's signature. Connections to our database are TLS-encrypted, and infrastructure access uses IAM-scoped credentials. When our AI features query your data, they do so through restricted, shop-scoped database views rather than direct table access. Error and crash reporting runs on Convect's own infrastructure, and reports are scrubbed of account identifiers — emails, IP addresses, and cookies — before they are stored (on mobile, before they leave your device). No system is perfectly secure; we'll notify affected accounts without undue delay if we become aware of a breach.

Changes to this policy

We'll update this page when our practices change and bump the “Last updated” date above. Material changes will be communicated to active accounts via email.

Contact

Questions? Reach us at hello@tendto.you.