Overview
TellSpotAI provides an AI-powered platform that allows account owners to create public information Spots, chat experiences, knowledge bases, QR-linked pages, contact method displays, and related tools for their visitors and customers. This Privacy Policy explains how we collect, use, disclose, store, protect, and otherwise process personal information when you access or use TellSpotAI.
By using TellSpotAI, you acknowledge that personal information will be handled as described in this Privacy Policy. The Cookie Policy, applicable Data Processing Addendum, and Subprocessors page provide supplemental information about technologies, processing roles, and categories of independent providers and are incorporated by reference to the extent applicable.
This Policy does not govern independent websites, payment services, artificial-intelligence services, hosting services, customer websites, messaging platforms, social networks, or integrations that TellSpotAI does not control.
1. Scope
This Privacy Policy applies to visitors to our websites and public pages, individuals who create or manage TellSpotAI accounts, End Users who interact with public Spots or AI chats, individuals who contact us for support, billing, abuse, security, privacy, or legal matters, and business customers who use TellSpotAI to provide AI-powered information experiences to their own users.
2. Our Role
Depending on the context, TellSpotAI may act as a data controller or as a data processor or service provider.
For account registration, billing administration, platform security, fraud and abuse prevention, service analytics, internal account and service-health administration, support, legal compliance, Platform Analytics, and TellSpotAI's own business operations, TellSpotAI generally acts as a controller.
For visitor conversations, Customer-uploaded Knowledge Base content, Spot configuration, Customer Contact Methods, and other personal information processed on behalf of a Customer, TellSpotAI generally acts as a processor or service provider. In those cases, the Customer is responsible for the lawful basis, purpose, content, required notices, required consents, and processing instructions.
3. Personal Information We Collect
3.1 Account Information
Name, email address, username or account identifier.
Authentication data, verification events, login history, and account security signals.
Organization or business name, role, permissions, account status, language preferences, account settings, and service configuration.
3.2 Spot, Knowledge Base, and Contact Method Information
Spot name, description, public link, QR code, avatar or branding where available, and public-page settings.
Customer-uploaded text, files, business information, FAQs, policies, service descriptions, price lists, and other Knowledge Base content.
Instructions, prompts, guardrails, response preferences, usage limits, credit consumption, and feature settings.
Customer Contact Methods, such as phone numbers, email addresses, websites, messaging links, social media links, booking links, addresses, labels, and ordering preferences.
3.3 Visitor Chat Information
Messages submitted by visitors and AI-generated responses.
Chat session identifiers, Spot identifiers, public-page activity, approximate language preference, timestamps, usage events, and technical logs.
IP address, browser type, device information, approximate location derived from IP address, and similar technical data.
Abuse, safety, rate-limit, fraud, and security signals.
Answer status and outcome signals, including whether a response was answered, partially answered, unavailable from approved information, blocked, or classified as a contact request.
Limited samples, summaries, topic groups, counts, classifications, and related analytics metadata derived from visitor interactions.
3.4 Derived Analytics and Classification Information
Pseudonymous account or Spot identifiers, derived categories, sector or use-case classifications, topic clusters, Knowledge Base fingerprints or metadata, adoption and usage measures, service-health indicators, performance and reliability measures, billing and entitlement measures, aggregated contact or response indicators, benchmark inputs, trend data, and audit or snapshot metadata.
TellSpotAI designs these records to minimize direct identifiers and, where appropriate, applies pseudonymization, aggregation, suppression, or de-identification controls.
3.5 Payment and Billing Information
When paid services are enabled, payment processing may be handled by independent payment providers or merchant-of-record providers. We may receive limited billing-related information, such as customer name, billing email, Plan, payment status, invoice or receipt identifiers, billing country or tax information, transaction metadata, refund status, cancellation status, and renewal status. We do not intentionally store full payment card numbers on our own servers.
3.6 Support, Billing, Abuse, Security, and Communications
When you contact us, we may collect your name, contact details, account email, message content, request details, attachments, reports, feedback, complaints, and related communications.
3.7 Technical and Usage Information
We may automatically collect IP address, device type, browser type, operating system, referring URL, pages visited, feature usage, error logs, security logs, session events, approximate location derived from IP address, cookies, local storage, or similar identifiers where applicable.
Visitors should not submit sensitive personal information, payment card information, passwords, government identifiers, health information, children's information, or confidential information into a TellSpotAI chat unless the relevant Customer has lawfully authorized that processing and implemented appropriate safeguards.
4. Information We Do Not Intentionally Collect
TellSpotAI is not designed to intentionally collect full payment card numbers, government identification documents, biometric identifiers, precise geolocation, medical records, children's personal information, or special-category or sensitive personal information unless explicitly supported under a separate written agreement and appropriate legal safeguards.
5. How We Use Personal Information
- Provide, operate, maintain, secure, and improve TellSpotAI.
- Create, authenticate, administer, and protect accounts.
- Deliver AI chat responses based on approved Spot content and relevant context.
- Process Knowledge Base content for indexing, retrieval, classification, and response generation.
- Generate, maintain, and serve public Spot pages, QR-linked experiences, and Customer Contact Methods.
- Manage trials, subscriptions, Usage Credits, invoices, billing, account limits, entitlements, and payment status when billing is enabled.
- Provide support and respond to inquiries, requests, reports, complaints, and legal communications.
- Monitor service performance, reliability, adoption, usage, capacity, fraud, abuse, spam, security incidents, and unauthorized access.
- Administer account and service health, allocate support, manage service risk, enforce agreements, and maintain the customer relationship.
- Identify missing information, repeated questions, contact requests, response outcomes, topics, classifications, and usage trends.
- Create customer-facing analytics and reports.
- Create Platform Analytics for platform operation, security, quality measurement, capacity planning, product improvement, sector and market analysis, internal reporting, strategic and commercial planning, corporate development, financing, due diligence, valuation, or a merger, acquisition, reorganization, or sale of all or part of the business.
- Enforce our Terms, Acceptable Use Policy, and other policies.
- Send administrative messages, service notices, security alerts, account communications, billing communications, and permitted marketing communications.
- Comply with legal obligations and protect the rights, safety, property, and interests of TellSpotAI, Customers, End Users, and the public.
6. AI Processing and Service Infrastructure
TellSpotAI may process service requests through infrastructure operated or controlled by TellSpotAI and through independent providers of artificial intelligence, hosting, cloud infrastructure, databases, storage, email delivery, monitoring, security, fraud prevention, support, and related services.
To generate AI responses, TellSpotAI may process and transmit relevant prompts, limited Knowledge Base excerpts, conversation context, Customer Contact Methods, and technical metadata to the infrastructure or independent providers used for the applicable request. Data is limited to what is reasonably necessary for the assigned function.
Independent providers are required, as applicable, to process data under contractual, confidentiality, security, and data-protection obligations. Provider assignments may change as TellSpotAI operates, secures, scales, or improves the service.
TellSpotAI does not authorize independent AI providers to use Customer-uploaded Knowledge Base content or visitor chat content to train general-purpose or foundation models for their own purposes unless TellSpotAI separately discloses that use and obtains any authorization required by law.
7. Platform Analytics and Derived Information
TellSpotAI may derive Platform Analytics from account configuration, Spot profiles, published Knowledge Bases, Knowledge Base metadata or fingerprints, service usage, visitor interaction outcomes, billing and entitlement records, support activity, security signals, and other operational records.
Platform Analytics may include classifications, topics, trends, benchmarks, adoption measures, service-health indicators, response and contact indicators, usage and financial aggregates, pseudonymized facts, historical snapshots, audit information, and comparable statistical or analytical outputs.
TellSpotAI applies data minimization and may use pseudonymization, aggregation, de-identification, minimum-contributor thresholds, suppression, access restrictions, and other controls appropriate to the intended use. Cross-customer outputs are designed not to reveal raw Customer Content, raw Knowledge Base content, identifiable visitor chat content, or confidential information attributable to a specific Customer.
TellSpotAI may retain and use aggregated or de-identified information for lawful operational and business purposes where it does not reasonably identify an individual or Customer. Pseudonymized information remains protected as personal information where applicable.
Internal account-level operational indicators may be used to administer the service, allocate support, manage billing and entitlements, maintain security, assess service risk, enforce agreements, and plan the customer relationship. TellSpotAI does not use Platform Analytics to make legally or similarly significant decisions about individuals.
8. Legal Bases for Processing
Where a legal basis is required, TellSpotAI processes personal information on one or more of the following grounds:
- Performance of a contract or steps requested before entering a contract.
- TellSpotAI's legitimate interests in operating, securing, improving, measuring, supporting, and developing the service and business, where those interests are not overridden by the rights and interests of affected individuals.
- Consent where required.
- Compliance with legal obligations.
- Protection of rights, safety, property, and service integrity.
- Documented Customer instructions where TellSpotAI acts as a processor or service provider.
9. Cookies and Similar Technologies
We may use cookies, local storage, pixels, and similar technologies to keep users signed in, remember preferences, secure accounts and sessions, understand service usage, diagnose errors, measure performance, support analytics, and improve the product. Where required by law, we request consent before using non-essential technologies. For more details, see our Cookie Policy.
10. How We Disclose Personal Information
- Service providers and subprocessors: categories may include hosting and infrastructure, databases and storage, email delivery, artificial-intelligence services, payment and billing when enabled, analytics and monitoring, security and fraud prevention, customer support, and professional advisers.
- Customers: if you interact with a Customer-operated Spot, the Customer may access information associated with that Spot, including chat messages, AI responses, usage records, and related metadata, subject to the Customer's role and configuration.
- Legal and safety disclosures: we may disclose information to comply with law, enforce agreements and policies, investigate fraud, abuse, security incidents, or technical issues, and protect rights, safety, property, and service integrity.
- Business transfers and due diligence: information may be disclosed under appropriate confidentiality and data-protection safeguards in connection with financing, due diligence, a merger, acquisition, reorganization, sale of assets, bankruptcy, or similar transaction.
TellSpotAI does not disclose raw Customer Content, raw Knowledge Base content, or identifiable visitor chat content to another Customer for that Customer's independent use.
11. No Sale of Personal Information
TellSpotAI does not sell personal information for money. TellSpotAI does not knowingly share personal information for cross-context behavioral advertising unless it provides any notice and choice required by applicable law. TellSpotAI does not knowingly sell or share children's personal information.
The use of aggregated or de-identified information that does not reasonably identify an individual or Customer is not a sale of personal information, subject to applicable law.
12. International Data Transfers
TellSpotAI and its independent service providers may process and store personal information in countries other than the country where an individual is located. TellSpotAI limits transfers to data reasonably necessary for the applicable purpose and, where required, uses lawful transfer mechanisms and safeguards, which may include contractual protections, data processing agreements, standard contractual clauses, transfer assessments, adequacy mechanisms, certifications, or other permitted methods.
13. Data Retention
TellSpotAI retains personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law. Retention depends on the data category, Customer settings, account status, service requirements, security needs, legal obligations, disputes, audit requirements, and backup cycles.
Limited raw feedback and analytical signals, such as short question samples, response outcomes, contact-request classifications, and related metadata, are generally retained for up to ninety days unless longer retention is reasonably necessary or permitted for security, legal, billing, dispute, backup, audit, or operational purposes.
Customer-facing aggregated daily analytics may generally be retained for up to thirteen months. Aggregated or de-identified platform-level analytics may be retained for longer for historical trends, security, auditability, reproducibility, research, service planning, and lawful business purposes where they do not reasonably identify an individual or Customer.
Pseudonymized account-level or Spot-level analytical records are retained only as reasonably necessary and remain subject to applicable access, restriction, and account-deletion controls.
Data Category
Typical Retention Approach
Account information
Retained while the account is active and then deleted or anonymized from active systems within a reasonable period after account deletion, unless retention is required or permitted for legal, security, billing, audit, or dispute purposes.
Spot, Knowledge Base, and Customer Contact Methods
Hidden or unpublished when the account or Spot is deleted where applicable, and deleted from active systems within a reasonable period, unless retention is legally required or needed for security, abuse, audit, or dispute handling.
Visitor chat records
Retained according to Customer settings, platform defaults, legal requirements, security needs, abuse prevention, and service integrity.
Billing and transaction records
Retained as required for tax, accounting, audit, payment, dispute, and legal compliance.
Support, privacy, billing, abuse, legal, and security communications
Retained as needed for service quality, audit, investigation, dispute resolution, and legal compliance.
Security logs and abuse signals
Retained as needed to protect the platform, prevent abuse, investigate incidents, maintain auditability, and comply with legal obligations.
Backups
Deleted or overwritten according to backup cycles. Information may remain in backups for a limited period after deletion from active systems and is not restored except for disaster recovery, security, legal, or service-integrity purposes.
14. Account Deletion
If you delete your account or request account deletion, TellSpotAI may disable access, unpublish or restrict public Spots, disable QR-linked pages, remove Customer Contact Methods from public display, and delete or anonymize account data, Spot data, Knowledge Base content, embeddings, files, pseudonymized account or Spot analytical records, and related data from active systems within a reasonable period.
Some information may be retained where required or permitted for billing, tax, accounting, fraud prevention, security, legal compliance, auditability, dispute resolution, backup cycles, or legitimate operational needs. Aggregated or de-identified information that no longer reasonably identifies an individual or Customer may be retained and used as permitted by law.
To request help with account deletion or data requests, contact [email protected].
15. Data Security
TellSpotAI uses reasonable technical, administrative, and organizational measures designed to protect personal information against unauthorized access, loss, misuse, alteration, disclosure, and destruction. Measures may include encryption in transit, access controls, authentication safeguards, role-based permissions, audit logs, security monitoring, rate limiting, abuse prevention, secure secret management, backup and recovery controls, provider review, and vulnerability management. No system is completely secure.
16. Customer Responsibilities
- Provide notices, disclosures, consents, and legal bases required for the Customer's processing and use case.
- Ensure Customer Content and Customer Contact Methods are lawful, accurate, authorized, and appropriate.
- Avoid unnecessary personal information in uploaded files, prompts, instructions, and chats.
- Not use TellSpotAI for prohibited, regulated, or high-risk purposes unless expressly permitted by written agreement.
- Respond to privacy requests from individuals where the Customer acts as controller.
- Configure access, retention, contact methods, and Spot settings appropriately.
- Ensure the Customer's use of TellSpotAI complies with applicable laws.
17. Your Privacy Rights
Depending on location and applicable law, individuals may have rights to know about processing, access personal information, receive a copy, request correction, request deletion or destruction, request restriction, object to processing, withdraw consent, request portability, opt out of certain marketing, sale, sharing, targeted advertising, or profiling where applicable, limit certain sensitive-information uses, and lodge a complaint with a competent authority.
To exercise privacy rights, contact [email protected]. TellSpotAI may verify identity before responding. If a request relates to personal information controlled by a Customer, TellSpotAI may direct the requester to that Customer or process the request according to the Customer's lawful instructions.
18. Regional Privacy Notices
Saudi Arabia
Where the Personal Data Protection Law and its regulations apply, individuals may exercise the rights available under those laws, including rights to be informed, access personal data, obtain a copy, request correction, request destruction, withdraw consent where applicable, and complain to the competent authority. International transfers are subject to applicable transfer requirements and safeguards.
European Economic Area, United Kingdom, and Switzerland
Where applicable law provides, individuals may have rights to access, rectify, erase, restrict, object, receive portable data, withdraw consent, and lodge a complaint with a supervisory authority. Where TellSpotAI processes personal information as a processor for a Customer, the Customer generally acts as controller.
California and Other U.S. States
Where applicable state privacy laws apply, individuals may have rights to know, access, delete, correct, opt out of sale, sharing, targeted advertising, or certain profiling, limit certain sensitive-information uses, appeal certain decisions, and not be discriminated against for exercising privacy rights.
19. Marketing Communications
TellSpotAI may send service-related communications necessary for account administration, security, billing, or service operation. TellSpotAI may send marketing communications where permitted by law. Recipients may opt out of marketing emails through an unsubscribe mechanism or by contacting TellSpotAI. Non-marketing service communications may continue.
20. Children and Sensitive Information
TellSpotAI is not intended for children under thirteen years of age or the equivalent minimum age under applicable local law. TellSpotAI does not knowingly collect children's personal information. Customers must not create Spots directed to children or use TellSpotAI to collect children's personal information unless legally required authorizations and written agreements are in place.
TellSpotAI is not intended to process sensitive personal information unless expressly supported under a written agreement and appropriate safeguards. Do not submit sensitive information unless authorized and the specific processing is permitted.
21. Automated Decision-Making
TellSpotAI provides AI-generated informational responses and operational analytics. TellSpotAI is not intended to make legally or similarly significant decisions about individuals. Customers must not use TellSpotAI as the sole basis for employment, credit, insurance, housing, education, healthcare, legal rights, eligibility, public services, or similar decisions unless expressly permitted under a separate written agreement and applicable law.
22. Independent Links and External Services
TellSpotAI may display Customer Contact Methods or links to independent websites, customer websites, payment pages, messaging platforms, AI services, or external resources. TellSpotAI is not responsible for the privacy practices, security, availability, or content of independent services. Communications outside TellSpotAI are governed by the relevant Customer and independent service.
23. Abuse Reports and Safety
If you submit an abuse report, TellSpotAI may process the information provided, related account and Spot data, Customer Contact Methods, technical logs, and communications reasonably necessary to investigate and respond. Abuse reports may be sent to [email protected].
24. Changes to This Privacy Policy
TellSpotAI may update this Privacy Policy and its supplemental privacy documents from time to time. The Last Updated date and version identify the current policy. If a change is material, TellSpotAI may provide notice through the website, an authenticated in-service notice, email, or another reasonable method as required by applicable law.
Where a change requires express consent under applicable law, TellSpotAI will request that consent separately. Otherwise, the updated notice applies from its stated effective date.
25. Contact Us
- Privacy requests, account data requests, abuse reports, and support: [email protected]
- Billing and invoice matters: [email protected]
- General, legal, and business contact: [email protected]
- Website: https://tellspotai.com
