Last update: August 17, 2026
This Privacy Policy applies to the website tevello.com (hereinafter the “website”) operated by Tevello LLC, a limited liability company organized under the laws of the State of Wyoming, United States (hereinafter “Tevello” or “we”), and its other services and products for which personal data is being communicated to Tevello.
Please read this Privacy Policy carefully as it explains how Tevello uses your personal data and how to exercise your rights. This Privacy Policy supplements the Terms & Conditions or any documents or notices that may refer to this Privacy Policy.
Should you have any questions, you may directly contact Tevello by sending an email to support@tevello.com.
DATA means data about a living individual who can be identified from those data (or from those and other information either in our possession or likely to come into our possession).
USAGE DATA is data collected automatically either generated by the use of Service or from Service infrastructure itself (for example, the duration of a page visit).
COOKIES are small files stored on your device (computer or mobile device).
DATA CONTROLLER means a natural or legal person who (either alone or jointly or in common with other persons) determines the purposes for which and the manner in which any personal data are, or are to be, processed. For the purpose of this Privacy Policy, we are a Data Controller of your data.
DATA PROCESSORS (OR SERVICE PROVIDERS) means any natural or legal person who processes the data on behalf of the Data Controller. We may use the services of various Service Providers in order to process your data more effectively.
DATA SUBJECT is any living individual who is the subject of Personal Data.
THE USER is the individual using our Service. The User corresponds to the Data Subject, who is the subject of Personal Data.
We abide by the recommendations of the relevant authorities and have put in place an organization to ensure our compliance with the regulatory framework established by the General Data Protection Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), the United Kingdom General Data Protection Regulation and the Data Protection Act 2018 (together, the “UK GDPR”), and any other laws or regulations relating to personal information that apply to us.
Under the GDPR, we are considered as a data controller. It means that we set the whys and hows we process your personal information. For example, when you are visiting our website, we are in charge of determining the purposes and the means that are necessary to administer, operate and manage our users’ personal information that we collect from it.
Depending on the activity we perform on your data, we may also be considered as a data processor. This means that you are our customer’s end user and that we are processing your data under the instructions of our customer considered as a data controller. In this case, the data controller sets the purposes and means of the processing activity, and we abide and deliver our service in regards to these.
We only collect and process personal information that is relevant and adequate. We give special attention to its accuracy and updates when needed. Personal information includes in particular:
| Type of data | Examples of data |
|---|---|
| Identification data | e.g. first name, last name, picture, birth date, etc. |
| Connection data | e.g. IP address, logs, terminal and connection identifiers, timestamp, etc. |
| Contact data | e.g. email address, phone number, postal address, etc. |
| Internet data | e.g. cookies, tracers, navigation data, audience metrics, etc. |
The collection of this information may at times be mandatory in order to provide our service, other times optional to enhance your experience and left to your good will. Mandatory information will be identified as such when we collect your data. Know that if you refuse to provide it, Tevello won’t be able to provide you with its utmost service and you will unfortunately experience inconveniences.
We collect your personal information on various occasions.
| Sources | Description |
|---|---|
| Sign up form | Individual signed up online |
| Import via API | Import of personal data via API |
| Website or software visit | Individual browsed our website or our solution |
| Partner relationships | Individual gave their data to one of our partners |
| Chat & Email conversation | Individual contacted us directly by mail |
| Online or paper form | Individual filled in a form |
Your personal information will never be processed for incompatible purposes regarding why it was first collected. We only collect and process personal information for specified, explicit and legitimate purposes, like:
| Processing Activities | Purposes | Legal basis |
|---|---|---|
| Creation and management of Merchants' accounts | To grant individuals access to the service, administer and manage accounts | Contractual duties, Legitimate interest |
| Creation and management of Merchants' end-customers accounts | To grant individuals access to the service, administer and manage accounts | Contractual duties, Legitimate interest |
In order to comply with the principle of lawfulness, the legal bases for each data processing is determined carefully and on a case-by-case basis in accordance with the list provided by Article 6 of the GDPR.
We do not process your data or use automated decision making without your knowledge, nor do we sell or rent your personal information without your explicit consent.
Recipients to whom we disclose your personal information are carefully chosen by us. They receive data for legitimate purposes, especially when it comes to pursuing our business activity and providing a qualitative service:
| Subprocessor | Service provided |
|---|---|
| CloudFlare | Infrastructure |
| Amazon AWS | Cloud Infrastructure for apps and services |
| Shopify | Ecommerce platform |
| Google Cloud | Cloud computing services |
| Crisp | Customer support chat and dashboard |
| Bunny.net | Cloud infrastructure and content delivery |
Certain data recipients are considered our data processors in accordance with Article 28 of the GDPR, which means we review how they handle personal information and make sure they put in place appropriate guarantees to protect it.
Other recipients are considered authorized third parties in accordance with Article 4 of the GDPR, which means we have to communicate your personal information to them to comply with applicable legal obligations, lawful requests and processes (subpoenas, requests from government or tax authorities, etc.).
We may also disclose or transfer your personal information as part of a corporate transaction, such as a merger, acquisition, corporate reorganization, or sale of some or all of our assets. In that case, the recipient of the personal information is required to handle it in a manner consistent with this Privacy Policy, and you will be informed of any change of data controller.
Tevello is based in the United States, and your personal information is processed in the United States and in the European Union, where our main infrastructure providers operate. Some of our service providers may also process data in other countries.
When personal information protected by the GDPR or the UK GDPR is transferred to a country that has not been recognized as ensuring an adequate level of protection, we put in place appropriate safeguards in accordance with Articles 44 to 50 of the GDPR and the equivalent UK GDPR provisions — in particular the European Commission’s Standard Contractual Clauses, supplemented by the UK International Data Transfer Addendum, which are incorporated into our Data Protection Agreement — or we rely on other appropriate guarantees such as adequacy decisions.
| Subprocessor | Location | Adopted safeguard |
|---|---|---|
| Shopify | USA | Data Processing Agreement |
| CloudFlare | USA, European Union | Data Processing Addendum |
| Amazon AWS | USA, European Union | GDPR Center & Data Processing Addendum |
| Google Cloud | USA, European Union | Data Processing Addendum |
| Crisp | European Union (France) | Privacy commitments |
| Bunny.net | European Union (Slovenia), global CDN | Privacy commitments |
As a general rule when we are considered a data controller by the GDPR, retention periods of your personal information are determined according to the purposes for which we collected it and our legal obligations.
Regarding our activities as a data processor, we retain our customers’ end users personal information as long as required by our terms and conditions and the pursuing of the service our customers’ subscribed to.
When these purposes are fulfilled or when you ask us, your personal information is archived, erased or anonymized.
We care deeply about the safety of your personal information and that is why we put in place adequate technical and organizational security measures to preserve its confidentiality, integrity and availability.
We take into account the risks for your rights and freedoms and therefore follow with great care the recommendations of the competent authorities regarding security.
In accordance with Articles 12 to 23 of GDPR, you have rights over your personal information that we are committed to respect:
These rights can be exercised directly and at any time by sending an email to support@tevello.com. In the case you are our customer’s end user, please take into consideration that this request will be forwarded and must be answered directly by them.
Our Services are not intended for use by children under the age of 13 (" Children").
We do not knowingly collect personally identifiable information from Children under 13. If you become aware that a Child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from Children without verification of parental consent, we take steps to remove that information from our servers.
This Privacy Policy may be modified in the future to keep it updated with legal jurisprudence and evolution. You'll be informed either by a special mention on this page or by a personalized warning, by email for instance.
If you have any questions about this Privacy Policy, please contact us via email at support@tevello.com.
Tell us where to set things up and we'll take you to the Shopify App Store to install Tevello — free for 14 days.