Security and Compliance

At Tailrec, we take your privacy and security seriously. We carefully select trusted services and apply top-tier security measures to protect your data. Our goal is to exceed your expectations when it comes to how we handle and secure your information. Rest assured, we have strict policies in place. Your privacy is our top priority, and we're committed to keeping your data safe and confidential at all times.

image

Cloud Hosting

Our infrastructure services and data are hosted exclusively on Amazon Web Services (AWS). All operations are conducted within US facilities.

image

Encryption and Secure Transmission

All data is securely transmitted over HTTPS/TLS, encrypted both in-transit and at-rest. We employ KMS to encrypt sensitive data, and the keys are automatically rotated to ensure the utmost safety of your information. With our premium plan, we take client-side encryption a step further by extending it to all of your text data, and the encryption keys are regularly rotated.

image

Service Monitoring

We are dedicated to delivering exceptional availability and performance for our services, catering to our valued customers worldwide.

image

Authorization and Permissions

Authorized access to customer data is meticulously restricted to personnel with job functions that necessitate it. Furthermore, our robust client-side encryption shields your data against queries within the database.

image

Secure Authentication

We seamlessly inherit your Slack workspace's authentication settings, including SSO (Single Sign-On) or 2FA (Two-Factor Authentication), providing a seamless and secure authentication experience. Our implementation of OpenID Connect (OIDC) adds an extra layer of security on top of OAuth v2, a widely adopted industry standard.

image

PCI Compliance

Payments are securely processed through Stripe, our trusted payment processor. We do not store or handle any of your payment information directly. For detailed information regarding Stripe's PCI compliance and security policies, we encourage you to review their official documentation and guidelines.

image

GDPR-Compliant Data Protection

Our service is designed with strong adherence to GDPR principles, placing a high emphasis on protecting your data privacy and security. With robust safeguards, strict access controls, and transparent practices, we strive to ensure your personal information is handled responsibly. You can trust that we prioritize your data protection and provide you with the necessary tools and controls to manage your privacy preferences.

image

Data Subject Rights Request

For any deletion requests or updates regarding your data, please reach out to our Data Protection Officer (Hussachai Puripunpinyo) at . He will assist you promptly and ensure that your requests are handled in accordance with applicable data protection regulations.

Sub-processors

Tailrec uses select third-party services (sub-processors) that have access to limited personal data to support the core functionality of its services. These sub-processors provide essential functions such as cloud infrastructure, email, service monitoring, file storage, analytics, and payment processing. Before engaging a sub-processor, Tailrec reviews their security and privacy practices and, when necessary, takes additional steps to ensure they meet our high privacy standards. Last updated: December 1, 2024

Sub-processor
Service Provided
Location
Amazon Web Services (AWS) Cloud Infrastructure: Database, Logs Processor, Monitoring System, Domain Name System (DNS), Message Queue System (MQS), Key Management System (KMS), Content Delivery Network (CDN) etc. United States
Stripe Payment Processing: Our apps securely transfer your payment information to Stripe for processing. We do not store your payment details but retain the payment status and references received from Stripe. United States
Lemon Squeezy Payment Processing: We use Lemon Squeezy as an alternative to Stripe to comply with local laws and tax regulations in countries outside the US. United States
BetterStack We use BetterStack telemetry and website monitoring to ensure our services run smoothly. Our logs do not contain Personally Identifiable Information (PII). United States
Open AI - ChatGPT We use ChatGPT LLM models from OpenAI. Rest assured, your data will not be used for training. United States
Anthropic - Claude We use Claude LLM models from Anthropic. Your data will not be used for training, ensuring your privacy. United States
Google - Gemini We use Gemini LLM models from Google. Your data will not be used for training, ensuring your privacy. United States
Google - Analytics Website Analytics: It's important to note that Google Analytics v4 is not inherently GDPR-compliant. However, we implement IP anonymization to ensure compliance with GDPR requirements. By anonymizing IP addresses, which are considered personal data, we safeguard your privacy. For more detailed information, please refer to our privacy policy. United States
Slack Collaboration platform. United States
Giphy Our apps integrate with a GIF service to provide users with animated GIFs.

It's important to note that we only pass the search keyword to the GIF service. If you don't use this feature, we do not make any calls to the GIF service. Your privacy is respected, and the GIF service is only invoked when explicitly requested by users.

United States
footer-seperator

@ Tailrec LLC. All Rights Reserved