Privacy Policy
This Privacy Policy explains how Tailwind Reviews ("Tailwind", "we", "us") collects, uses, stores, shares and deletes information when you ("Customer", "you") use the Tailwind Reviews application, website (tailwind.reviews) and related services (the "Service").
If you have questions, write to support@tailwind.reviews.
1. Who we are
Tailwind Reviews is a reputation-management product operated by [Legal entity name], [address], [country] ("we"). We act as a data processor for content the Customer connects from third-party platforms (Google, Meta) and as a data controller for account registration data.
2. Information we collect
2.1 Account information
When you create a Tailwind account we collect: name, work e-mail, hashed password (or OAuth identifier), company name, time zone, and locale.
2.2 Connected-platform data
When you connect a third-party business asset (Google Business Profile, Facebook Page, Instagram Business account, Threads profile) we receive only the data the platform's API returns under the OAuth scopes you approve. The scopes are listed below in §3 and §4.
2.3 Usage data
We collect standard product analytics: log-in events, feature usage counters, IP address, user-agent, error traces. We use this to operate, secure and improve the Service.
2.4 Cookies
We use a minimum set of first-party cookies required for authentication and session security. We do not place advertising cookies.
3. Google User Data
Tailwind integrates with Google Business Profile API. With the Customer's consent we read business profile metadata, location reviews and review replies for locations the Customer owns. Tailwind's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We do not use Google user data for advertising, do not sell it, and do not transfer it to third parties except sub-processors strictly necessary to provide the Service (see §6).
4. Meta Platform User Data
Tailwind integrates with Meta platforms (Facebook, Instagram and Threads) through the Meta Graph API and Threads API to provide reputation-management features for Customers who connect their own Meta-owned business assets (Facebook Pages, Instagram Business accounts, Threads profiles). Our use of data received from Meta APIs adheres to the Meta Platform Terms and Developer Policies.
4.1 Data accessed
When the Customer connects a Meta business asset to Tailwind, we may access:
- Authentication data: Meta user id, name, profile picture (from Facebook Login for Business).
- Page data: Page id, name, category, contact info, posts published by the Page, comments and reactions on those posts, Page-level insights (followers, reach, engagement).
- Instagram Business data: account id, username, business posts, comments on those posts, mentions, basic insights.
- Threads data: profile id, username, posts published by the connected Threads profile, replies to those posts, mentions of the profile, post-level and account-level insights, and (when explicitly enabled by the Customer) public Threads posts matching brand keywords the Customer monitors.
4.2 What we do with this data
- Display reviews, comments, replies and mentions in the Customer's Tailwind dashboard.
- Allow the Customer to reply to comments and replies from inside Tailwind (writes back through the Meta APIs only with the Customer's explicit click).
- Show aggregated and per-post insights (reach, engagement) to the Customer.
- Trigger Customer-configured notifications (e-mail, in-app) when new reviews, comments or mentions appear.
- Generate AI-assisted reply suggestions which the Customer reviews and approves before publishing.
4.3 What we do not do with Meta data
- We do not sell, license or rent Meta data.
- We do not use Meta data to build advertising audiences or for targeted advertising.
- We do not enrich profiles by combining Meta data with data from other sources for marketing.
- We do not use Meta data to train general-purpose AI/ML models. AI reply suggestions are produced by per-request prompts to a third-party LLM provider (see §6); the prompt content is not retained by the LLM provider for training.
- We do not transfer Meta data outside our processor list in §6.
4.4 Storage and retention
Meta data is stored encrypted at rest in our EU-region cloud database. Default retention is 24 months from the date of ingestion, after which records are automatically deleted. The Customer can shorten the retention window in account settings.
When a Customer disconnects a Meta asset or deletes their Tailwind account, all Meta data tied to that asset is purged within 30 days (see §8 and the Data Deletion page).
5. How we use information
We use the information described in §2–§4 to:
- Provide, maintain and secure the Service.
- Display the Customer's connected-platform content inside Tailwind.
- Enable the Customer to reply to comments, reviews and mentions.
- Send Customer-configured notifications.
- Bill the Customer and prevent fraud.
- Comply with legal obligations.
We do not use the data for advertising, profiling unrelated to the Service, or sale.
6. Sub-processors
We rely on a limited set of sub-processors to deliver the Service. The current list is published at tailwind.reviews/subprocessors. Today it includes:
- Cloud hosting: [AWS / GCP / Hetzner — replace with your actual provider], EU region.
- Database: managed PostgreSQL on the same provider, EU region.
- Transactional e-mail: [Postmark / SendGrid — replace].
- Error monitoring: [Sentry — replace].
- AI reply suggestions: [OpenAI / Anthropic — replace], no-training data-processing terms in place.
- Customer support tooling: [Intercom / Help Scout — replace].
Each sub-processor is bound by a Data Processing Agreement and is restricted to the data needed to perform its function.
7. Sharing
We share information only:
- with sub-processors listed in §6;
- with the Customer's authorized users;
- when legally required (subpoena, court order) — we will notify the Customer unless legally prohibited;
- in connection with a corporate transaction (merger, acquisition) — successor will be bound by this Policy.
We do not sell personal information.
8. Data deletion and retention
The Customer can:
- Disconnect any Meta or Google asset from inside Tailwind at any time. We delete data tied to that asset within 30 days.
- Delete the Tailwind account from Settings → Account → Delete account. All account and connected-platform data is purged within 30 days.
- Use the data-deletion request form at
tailwind.reviews/data-deletion. - Use the Meta-initiated data deletion callback (Tailwind responds to Meta's deletion-request callback automatically — see Data Deletion page).
Backups are rotated on a 30-day cycle; deletion is fully effective once the next backup cycle completes.
9. Security
Encryption in transit (TLS 1.2+), encryption at rest (AES-256), least-privilege access, audit logs, mandatory MFA on production, code review and dependency scanning. Incident-response runbook with breach-notification commitments to Customers within 72 hours of confirmation.
10. International transfers
Our infrastructure is hosted in the EU. Where sub-processors are located outside the EU/EEA, transfers are covered by EU Standard Contractual Clauses or equivalent safeguards.
11. Your rights
Depending on your jurisdiction (GDPR, UK GDPR, CCPA/CPRA and similar) you may have the right to access, correct, delete, port your data, restrict processing, and object to processing. Send requests to support@tailwind.reviews — we respond within 30 days.
You can also object to processing at any time by disconnecting integrations or deleting your account.
12. Children
Tailwind is a B2B product not directed to children under 16. We do not knowingly collect data from children.
13. Changes
We will post material changes to this Policy on tailwind.reviews/privacy and notify Customers by e-mail at least 14 days before the change takes effect.
14. Contact
Tailwind Reviews — Privacy [Legal entity name] [Postal address] support@tailwind.reviews
For Meta-related privacy questions reference Meta App ID [your app id] in the subject line.