StoriTail

Privacy Policy

Effective 26 July 2026. Last updated 26 July 2026.

Who we are

StoriTail provides catalog-governance software for retailers. StoriTail is the operator responsible for the personal information described in this notice. Questions or privacy requests can be sent to storitail.io@gmail.com. The business owner will confirm the final legal entity details before launch.

Information we collect and why

  • Early-access requests: organisation and contact details, website, retail vertical, approximate product count and the catalog challenge you describe. We use these to assess requests and contact applicants about access.
  • Account information: name, work email, organisation, role, password hash and account status. We use these to create, administer and secure approved workspaces.
  • Authentication and session data: signed session identifiers, password-reset or activation-token hashes and related timestamps. We use these to authenticate users and protect accounts.
  • Retailer catalog and supplier data: product, category, template and supplier-import information uploaded or created in a workspace. We process this to provide the service to the retailer; it may include personal information if a retailer chooses to upload it.
  • Support correspondence: messages and information you provide when asking for help. We use these to respond and improve support.
  • Technical and security information: request metadata, IP-derived abuse-prevention records, errors and security events where applicable. We use these to operate, diagnose and protect the service.

Lawful bases

Depending on the context, StoriTail expects to rely on steps taken at your request before entering a contract, performance of a contract, legitimate interests in operating and securing the service, and compliance with legal obligations. Where consent is the appropriate basis, it will be requested separately and may be withdrawn. The business owner must confirm these bases against the final launch operations.

Service providers and international transfers

StoriTail uses service providers for application hosting, managed database infrastructure and transactional email delivery. Current providers may include Vercel, MongoDB Atlas and Resend. They process information only to support the service under their applicable terms. Some providers or their infrastructure may process information outside the UK. Where required, StoriTail will use an appropriate transfer mechanism and review provider safeguards; we do not claim that all information remains in the UK.

Retention

We keep information only while it is reasonably needed for the purposes above, to provide an active workspace, handle a request, maintain security records or meet legal obligations. Retention depends on the record and the relationship. We do not state fixed periods that the service does not yet enforce. Information is deleted or anonymised when it is no longer reasonably required, subject to backups and legal requirements.

Security

StoriTail uses proportionate technical and organisational safeguards, including hashed passwords and activation tokens, HTTP-only signed session cookies, access controls and encrypted provider connections where supported. No online service can guarantee absolute security.

Essential cookies

StoriTail uses the st_session authentication cookie after login. It is an HTTP-only, same-site cookie used for authentication, session continuity, application security and protected dashboard access. It is persistent for an approximately 60-minute sliding idle period and cannot extend beyond an absolute seven-day lifetime. It is secure-only in production. Because this cookie is necessary for the service, StoriTail does not use a consent banner for it.

StoriTail does not add analytics, advertising or other non-essential tracking in this launch. If optional cookies are introduced later, they must be blocked until consent, offer equally clear accept and reject choices, allow preferences to be changed, and be documented here or in a separate cookie notice.

Your rights

UK data-protection law may give you rights to ask for access, correction, deletion, restriction or portability of your personal information, or to object to certain uses. Rights depend on the circumstances and may have lawful exceptions. Email storitail.io@gmail.com to make a request. We may need to verify your identity. You can also complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint.

Changes to this notice

We may update this notice as the service and its providers change. The effective and last-updated dates above identify the current version. Material changes will be communicated through an appropriate service channel where necessary.

Ready to apply? Request early access.