TUNGA← Back to site

Privacy Policy

Last updated: September 15, 2026

This policy explains what data TUNGA ("we", "us") collects when you use our website and application, why we collect it, and the choices you have. TUNGA is a store-operations service for e-commerce merchants.

1. Data we collect

Account data. Your name, email address and a password. Passwords are stored only in a hashed form that cannot be read back.

Store data. When you connect a store, we read catalog and commerce data through the platform's official API: products, variants, prices, inventory levels, collections and metafields. Order data is requested on demand for sales reporting and reply assistance; it can include customer names, contact details and purchase history. We do not persist a separate copy of order or customer records in the TUNGA database.

Store profile. Settings you define in the product — pricing rules, rounding conventions, protected products, brand voice, trust mode and guardrail limits.

Usage data. Actions taken inside the application (instructions run, previews approved or rejected, undo operations), kept as an audit log so that your account has a complete, reversible history. Basic technical logs (IP address, browser type, timestamps) are kept for security and troubleshooting.

Cookies. We use a session cookie to keep you signed in and a preference cookie to remember your language. We do not use advertising or cross-site tracking cookies.

2. How we use data

  • To provide the service you asked for: analysis, previews, approved changes, reports and briefings.
  • To keep every change reversible: restore points and audit records are part of how the product works.
  • To secure accounts, prevent abuse and meet legal obligations.
  • To send service email such as verification, password reset and important account notices.

3. What we never do

  • Your store is never training data. The profile TUNGA builds from your catalog stays inside your account and is never pooled with other accounts or used to train shared models.
  • We do not sell personal data, and we do not share it with third parties for their own marketing.
  • We do not write to your store without an approval path you configured. The initial audit only reads.

4. Processors

We use a small number of service providers to run TUNGA: cloud hosting and database infrastructure, email delivery, language-model services used to interpret instructions and draft text, and — if you enable briefings — the messaging channel you choose. Each processor receives only the data needed for its task, under a data-processing agreement, and is prohibited from using it for any other purpose, including model training.

5. Where data lives

The application and database are hosted in the European Union (Frankfurt, Germany) and operated in accordance with the GDPR. Some processors may handle data outside the EU; where they do, transfers are covered by recognised safeguards such as standard contractual clauses.

6. Isolation and security

Every account's data is isolated: each database query is bound to one account identity, and that boundary is tested continuously. Sessions are signed, email addresses are verified, and changes to your store apply atomically with a restore point written before a job may report success.

7. Retention and deletion

We keep your data while your account is active. Disconnect your store and our API access ends immediately. You can export everything TUNGA holds about your store at any time, and you can ask us to delete your account and its data by writing to the address below; we complete deletion within 30 days, except where the law requires a longer retention (for example invoicing records).

8. Your rights

Depending on where you live, you have the right to access, correct, export, restrict or delete your personal data, and to object to certain processing. If you are in the EU/EEA or the UK, these are GDPR rights; if you are in Türkiye, equivalent rights apply under the KVKK. To exercise any of them, email us — no form, no waiting period beyond what verification requires. Your customers may also contact us directly; where we act as your processor we will refer the request to you and assist.

9. Changes

If this policy changes in a way that matters, we will update the date at the top and notify account holders by email before the change takes effect.

10. Contact

Privacy questions and requests: e.sonmez@dijipilot.com

© 2026 TUNGAPrivacy Policy · Terms of Service · Trust Center · Status · Contact