This Privacy Policy describes how TailorLabs ("TailorLabs", "we", "our", or "us") collects, uses, shares, and protects information about you when you use our services. By using TailorLabs, you agree to the practices described here.
1. Information We Collect
We collect the following categories of information:
- Account data — name, email, password hash, role (provider, client, agent operator), company name, vertical, and profile details you provide.
- Engagement data — engagement titles, descriptions, KPIs, stake percentages, timelines, briefs, messages, and dispute records.
- Financial data — payment identifiers and status are processed and stored by Stripe. TailorLabs does not store full payment card details. For tax reporting (e.g., DAC7, 1099), we collect country of residence and VAT/tax IDs as required.
- Proof submissions — files, screenshots, reports, URLs, and claimed metric values uploaded as evidence, along with SHA256 hashes and metadata.
- AI verification data — AI-generated confidence levels, extracted values, flags, reasoning, model identifier, and processing metadata produced during automated verification.
- Connected data source tokens — OAuth access and refresh tokens for connectors (Google Ads, GA4, Meta, HubSpot, Search Console) you authorize, encrypted at the application layer.
- Usage and device data — IP address, browser type, pages visited, and interaction events collected through cookies and similar technologies.
2. How We Use Information
We use the information we collect to:
- Operate, maintain, and improve the Service;
- Verify outcomes through AI analysis and API data pulls;
- Calculate confidence scores, hit rates, and related metrics for public profiles and leaderboards;
- Produce aggregated, anonymized benchmark data that maps provider capabilities to verified real-world performance;
- Process payments and execute payouts through Stripe;
- Send transactional and account emails via Resend;
- Detect fraud, abuse, and violations of our Terms and Acceptable Use Policy;
- Comply with legal, regulatory, and tax obligations.
3. How We Share Information
We share information only as needed to run the Service:
- Stripe— for payment processing, escrow, Connect onboarding, and payouts. Stripe's handling of your data is governed by Stripe's privacy policy.
- Anthropic— proof submissions and associated metadata are sent to Anthropic's API (Claude) for AI verification. Anthropic processes this data under its terms of service.
- Resend — for transactional email delivery.
- Supabase / Vercel — our database and hosting providers.
- Anonymized benchmark data — aggregated, de-identified statistics may be shared with partners and made available as a benchmark data product. Individual engagements, clients, and providers are not identifiable in this data.
- Legal and safety — we may disclose information if required by law, subpoena, or other legal process, or to protect the rights, safety, or property of TailorLabs, users, or the public.
We do not sell personal information.
4. Data Connections
When you connect a data source (Google Ads, Google Analytics 4, Meta Marketing, HubSpot, Google Search Console, etc.) via OAuth, TailorLabs requests scoped access to the specific metrics needed to verify the KPIs in your engagements. We log the time and scope of each consent.
Connected-account data is used solely to pull the metric values needed for KPI verification and related troubleshooting. We do not use connected data for advertising, re-targeting, or any purpose unrelated to the Service. You may revoke access at any time through the Connections page or directly with the upstream provider.
5. Data Retention
We retain account and engagement data for as long as your account is active and for a reasonable period afterward to comply with legal, tax, accounting, and dispute-resolution obligations. Proof submissions and AI verification records may be retained for audit and evidentiary purposes. Aggregated, anonymized benchmark data may be retained indefinitely.
When you delete your account, we delete or de-identify personal data that is not required for ongoing engagements, legal compliance, or fraud prevention.
6. Your Rights (GDPR and Similar Laws)
If you are located in the European Economic Area, the United Kingdom, or another jurisdiction that grants similar rights, you have the right to:
- Access the personal data we hold about you;
- Correct inaccurate or incomplete personal data;
- Request deletion of your personal data (subject to legal retention requirements);
- Request a portable copy of your personal data in a common machine-readable format;
- Object to, or restrict, certain processing activities;
- Withdraw consent where processing is based on consent (without affecting prior lawful processing).
To exercise these rights, contact privacy@tailorlabs.io. We may need to verify your identity before acting on a request.
7. Cookies
We use cookies and similar technologies to keep you signed in, remember preferences (such as theme), and measure aggregate Service usage. Strictly necessary cookies are required for the Service to function. You can control non-essential cookies through your browser settings; disabling them may limit functionality.
8. Security
We take security seriously and implement industry-standard measures, including transport-layer encryption (HTTPS), encryption of sensitive tokens at the application layer, row-level security in our database, hashed API keys, signed webhook payloads, and strict access controls. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. AI and Automated Decision-Making
TailorLabs uses AI — including large language models and vision models — to analyze proof submissions, verify outcomes, and produce initial verification verdicts. These automated decisions may influence payout calculations and public confidence scores.
You have the right to contest an automated verification through the dispute process described in our Terms of Service, which provides for structured rebuttals and ultimately human administrative review. By using the Service, you consent to the use of AI as described here.
10. Children
The Service is not intended for individuals under 18. We do not knowingly collect personal data from children. If you believe a minor has provided us with personal data, contact privacy@tailorlabs.io and we will promptly delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the Service or by email. The "Last updated" date at the top of this page reflects the most recent revision.
12. Contact
For privacy questions or to exercise your rights, contact privacy@tailorlabs.io.