Attune ("Attune", "we", "us") provides customer-support software for e-commerce merchants. This policy explains what data we collect when a merchant uses Attune — including data accessed through a connected Gmail or Outlook mailbox and a connected Shopify store — how we use it, how long we keep it, and how to reach us with questions or a deletion request.
This policy applies to merchants who use Attune ("you") and to the customers whose emails and order data pass through a merchant's connected mailbox and store. If you're a merchant's customer and have questions about your data, please contact the merchant directly — they control which mailbox and store are connected. If you can't reach them, contact us at the address below and we'll help.
Information we access and collect
From your connected Gmail or Outlook mailbox
When you connect a mailbox, Attune polls it for new mail and reads:
- The subject and body text of incoming emails.
- Sender and recipient email addresses and display names.
- Message and thread identifiers (e.g. the RFC822 Message-ID, In-Reply-To, and the mailbox provider's own thread ID), used to group a conversation correctly.
- Attachments included on an incoming email (files are copied into private storage; see "How we store your data" below).
We only read new mail arriving after you connect the mailbox — we do not do a one-time import of your entire mailbox history. We never read, access, or store emails unrelated to customer support that happen to sit in the same inbox, beyond what's necessary to identify which incoming messages are customer emails.
From your connected Shopify store
- Order details: order number, line items, total, fulfillment and shipment status, and tracking numbers.
- Customer records: name, email address, and order history.
Account and usage data
- Your name, work email, and password (if you sign in with email/password rather than Google) or Google account identifiers (if you sign in with Google).
- Your organization's name and team members' roles.
- Drafts, replies, and notes your team writes or approves inside Attune.
- If your team enables Slack notifications, a summary of a conversation and its related order may be posted to a Slack channel your organization controls.
Why we access this data
We use the information above only to operate the support workflow you've set up:
- To identify which incoming emails are from customers and which order they relate to.
- To draft a suggested reply, or — only when your organization has enabled it and confidence is high — send a reply automatically.
- To display your team's conversations, orders, and customers inside the Attune app.
- To generate the analytics your organization sees (response times, resolution rates, and similar aggregate figures).
- To detect and prevent abuse of the service, and to debug issues you report to us.
We do not use the content of your emails or your customers' data to train or fine-tune any AI or machine-learning model, ours or a third party's. We do not sell your data, and we do not share it with third parties for their own advertising or marketing purposes. We share data only with the service providers described below, to the extent needed to provide Attune to you.
Google user data & Limited Use disclosure
Attune's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We request only two Gmail scopes:
gmail.readonly(to read new customer emails) andgmail.send(to send the replies your team approves). We do not request or use any scope that would let Attune modify, label, archive, or delete anything already in your mailbox. - Gmail data is used solely to provide and improve the customer-support features described in this policy — never for advertising, and never to train AI/ML models.
- Gmail data is only transferred to the third parties listed below, and only as necessary to provide the service (for example, sending email body text to our AI provider to draft a reply, or to our email-delivery provider to send it).
- Human access to Gmail data is limited to what's necessary for support, security investigations, legal compliance, or with your consent.
How we store your data
Attune's database and file storage are hosted on Supabase, in the ap-northeast-1 region. Email attachments are stored in a private storage bucket that isn't publicly accessible; access requires a signed, time-limited link generated by our servers for an authenticated member of your organization. Supabase's underlying infrastructure encrypts data at rest.
How long we keep your data
While a mailbox or store remains connected, its conversations, messages, orders, and customer records stay available so your team has continuous support history — there is no automatic deletion timer on an active connection.
When you disconnect a mailbox or delete a store from Attune, an automated daily job removes the associated data on this schedule:
- Email attachments — deleted 30 days after disconnection.
- Messages (email content) — deleted 30 days after disconnection.
- Conversations — deleted 60 days after disconnection.
Order and customer records synced from Shopify, and account/organization records, are kept for as long as your Attune account is active, so that reporting and support history stay consistent. You can request deletion of your account and associated data at any time — see "Requesting deletion" below.
Who we share data with
We use a small number of service providers ("subprocessors") to run Attune. Each receives only the data it needs to perform its function, and none are permitted to use your data for their own purposes:
- Supabase — hosts our database and file storage (all data described above).
- Anthropic — receives email text, conversation history, and relevant order details to draft a suggested reply, classify an email, or summarize a conversation. Anthropic does not receive your Google account credentials.
- Resend — receives the recipient address, subject, and body of an outbound reply in order to deliver it, when your organization sends through Attune's shared sending domain instead of directly through your connected mailbox.
- Shopify — is the source of your order and customer data; we read from Shopify's API using credentials you provide when connecting a store.
- Slack — if your organization enables escalation or replacement-approval notifications, a summary of the relevant conversation and order is posted to a Slack channel your organization configures and controls.
- Shipment-tracking lookup services — a tracking number and destination country may be sent to a tracking-aggregation service to retrieve delivery status shown in the app.
- Vercel — hosts the Attune web application itself.
We may also disclose information if required by law, or to protect the rights, property, or safety of Attune, our merchants, or others.
Requesting deletion
You can disconnect a mailbox or delete a store yourself from Settings, which starts the deletion timers described above. To request deletion of your entire account and all associated data sooner, or to ask a question about data we hold about you, email Aamir@varivendio.com. We'll confirm what will be deleted before proceeding and complete verified requests within a reasonable time.
Children's privacy
Attune is a business tool intended for use by merchants and their staff. It is not directed at children, and we do not knowingly collect data from children.
Changes to this policy
If we make material changes to this policy, we'll update the "Last updated" date above and, where appropriate, notify account administrators directly.
Contact us
Questions about this policy or how your data is handled: Aamir@varivendio.com.