Privacy Policy
Effective date: August 26, 2026
This Privacy Policy describes how TallyLoops, operated by Digital Gravity, Inc. ("we", "us", or "TallyLoops"), collects, uses, and shares information when you use our service.
1. Information We Collect
Information handled through TallyLoops falls into two broad groups. First, there is data our customers collect and manage for their own business purposes using the service — visitors, leads, contacts, form submissions, page content, tracking events, and email activity. Our customers decide why they collect that data; TallyLoops provides the software and infrastructure that stores and processes it for them. Second, there are records TallyLoops itself maintains to run the platform — accounts, billing and subscription records, security and abuse-prevention records, and platform-operation records.
Account information. When you register, we collect your name, email address, and a password hash. When you subscribe, we receive a customer identifier and subscription status from Polar, our billing provider; we do not store full payment card details.
Customer content and operational data. When you use the service, you create, upload, or collect content and operational data including pages and sites, forms, contacts and leads, email recipients and email content, tracking and attribution events, and site and domain configuration. This data is stored and processed on your behalf to provide the service to you. Forms hosted or managed through TallyLoops collect the values visitors submit, and those submitted values are stored as part of your operational data.
Visitor tracking data. When you install the TallyLoops tracker on a website you operate, the tracker collects events that occur on that website. These events include:
- Page views (URL and page title)
- Scroll depth thresholds (25%, 50%, 75%, 100%)
- Clicks on phone-number, email, and outbound links
- Form-submit events — structural metadata only, including the form's destination URL, the count of fields, and whether the form contains an email or phone field. The installed tracker does not capture or transmit the values typed into form fields. (Forms hosted or managed through TallyLoops are different — they collect submitted values, as described above.)
Tracking-event records — from the installed tracker and from pages TallyLoops hosts — can also include the referring page, browser and device characteristics (such as browser and device type), and approximate location (country, region, and city) derived from network information. IP addresses are processed transiently for security and rate-limiting controls; they are not stored as part of tracking-event records.
The cookies and browser storage used to distinguish visitors are described in Section 4.
Email delivery and engagement data. Where you use email features, we record per-recipient delivery and engagement events — such as sent, opened, clicked, and bounced — together with the recipient address, so that you can see the delivery status and engagement history of the email you send.
Platform operation and security records. We keep operational records needed to run the platform securely, such as logs of rejected tracking submissions and other abuse-prevention records.
Payment information. Payment, billing address, and tax information collected during checkout is collected and handled directly by Polar as merchant of record, where applicable. We receive subscription and order status, not full payment details.
2. How We Use Information
We use the information we collect to:
- Provide and operate the service for you, including the AI-assisted generation and drafting features you request.
- Process subscription payments and prevent fraud and abuse.
- Send transactional email related to your account (billing notices, payment failures, renewal reminders, security alerts).
- Provide customer support.
- Improve the service.
For customer operational data — the visitors, contacts, submissions, and related records you collect through the service — you determine the business purposes, and we process that data to provide the service to you.
We do not sell personal information.
3. How We Share Information
We share information with the following service providers, only to the extent necessary to operate the service:
- Polar — subscription billing (merchant of record), checkout, subscriptions, and the customer billing portal. Polar collects payment, billing address, and tax details directly during checkout.
- Resend — outbound email delivery, and the setup and management of email sending domains (which involves the domain names you configure).
- Cloudflare — hosting, content delivery, DNS, media and file storage, and custom-domain and TLS certificate infrastructure (which involves the domain names you connect).
- Neon — database hosting.
- Google (Gemini) — AI generation and drafting features. When you use these features, the prompts and business and page context you supply — including relevant uploaded reference material such as a logo or reference screenshot — are sent to the AI provider to generate the requested content.
- Anthropic — the same AI generation and drafting features, as an alternative or fallback AI provider, receiving the same categories of prompt and context data (excluding uploaded images on the fallback path).
- Pexels — stock-image search and download during page and content generation, using content-derived stock-image search terms.
- Cookiebot — only where a site owner enables the supported Cookiebot consent integration for their site. In that case the Cookiebot service loads on that site's published pages to collect and manage visitor consent choices for that site.
Customer-directed transfers. If you configure an outbound integration such as a webhook, we send the data you direct (for example, a new lead's name, email, and phone number) to the destination you specify. Those transfers happen at your direction and under your responsibility.
We may disclose information if required by law, subpoena, or other valid legal process, or to protect our rights and the safety of others.
4. Cookies and Browser Storage
We use the following cookies and browser storage:
- A session cookie scoped to
.tallyloops.comfor authenticated access to the dashboard. This is set when you log in and cleared when you log out. - A first-party tracker cookie named
_vt_vid(one-year expiry) on websites operated by our customers. It is set on the customer's own domain by the TallyLoops tracking script the customer installs, and the tracker also uses session-scoped browser storage to track session continuity. The customer's use of the tracker on their website is governed by the customer's own privacy policy. - Pages that TallyLoops hosts for a customer use a first-party visitor cookie named
al_vid(one-year expiry) and session-scoped browser storage to distinguish visitors, track session continuity, and record how a visit arrived (such as the referring page).
We do not use third-party advertising cookies.
5. Data Retention
We retain account information while your account is active, and afterwards as described below.
We retain customer content and operational data for as long as you keep it in the service. You can delete content at any time. There is no separate per-account retention setting; operational data follows the account, site, and content lifecycle described here.
Visitor tracking events are retained for 90 days. Logs of rejected tracking submissions are retained for 30 days.
If your subscription is cancelled, your workspace data is retained for 30 calendar days after the cancellation takes effect, so that it remains available for recovery, export, or reactivation during that period. If you reactivate your subscription during that 30-day recovery period, the same workspace is restored automatically: its existing sites and customer operational data remain associated with that workspace, and reactivation does not create a replacement workspace. Cancellation itself does not immediately erase your workspace. After the 30-day recovery period ends, the workspace and the customer operational data in it are deleted through our workspace-deletion process. The recovery period defines how long your data remains available for recovery, not the exact moment deletion completes.
Separate from your operational data, we keep records needed to run the platform — such as billing and subscription records and security and abuse-prevention records — while they are needed for platform operation and legal and business obligations. Some limited records may be retained where applicable for platform security, business operations, or audit purposes, including minimal evidence that a deletion was carried out. Payment, billing, and tax records collected and retained independently by Polar as merchant of record are governed separately by Polar.
6. Your Rights
Depending on where you live, you may have rights to access, correct, delete, or export the personal information we hold about you, or to object to or restrict certain processing.
To exercise any of these rights, email support@tallyloops.com. We fulfil verified, actionable requests within 30 calendar days, subject to verification of your identity and authority. (This response window is separate from the 30-day post-cancellation retention period described in Section 5.)
When we erase an individual contact at a customer's direction, we may retain minimal suppression information needed to make sure that person is not emailed again. When a whole workspace is deleted, the customer operational data in it is removed, including the workspace's suppression state. Some limited records may be retained where applicable for platform security, business operations, or audit purposes, as described in Section 5, and records held by Polar as merchant of record are handled separately by Polar.
7. International Transfers
TallyLoops is operated from the United States. If you use the service from outside the United States, your information will be transferred to and processed in the United States. Where required, we rely on appropriate safeguards for such transfers.
8. Children
The service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided personal information to us, contact support@tallyloops.com and we will delete it.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the revised policy with a new effective date and notify active customers by email if the changes are material.
10. Contact
For questions about this Privacy Policy or our handling of personal information, email support@tallyloops.com.