Tahini
Back to home

Legal

Privacy Policy

How Tahini AI, Inc. handles personal information — both the information we collect about you directly, and the business data our customers entrust to us.

Effective August 13, 2026

1. Who we are

Tahini AI, Inc. (“Tahini,” “we,” “us,” or “our”) is a Delaware corporation based in San Francisco, California. We provide an AI-powered operating system for consumer brands, covering finance, inventory, and retail operations.

This policy applies to our website at usetahini.com, our product, and our sales and support communications.

2. Two different roles

We handle personal information in two distinct capacities, and your rights differ depending on which applies.

As a controller. When you visit our site, request a demo, or hold an account with us, we decide how your information is used. This policy governs that information, and you can exercise the rights in Section 9 directly with us.

As a processor or service provider.When a customer uploads documents or connects a system to Tahini, we process the resulting business data (“Customer Data”) on that customer’s instructions and on their behalf. Customer Data may include personal information about the customer’s own employees, suppliers, and end customers. We do not decide how that information is used, and we do not use it for our own purposes. That processing is governed by our Data Processing Addendum. If you believe your personal information appears in a Tahini customer’s account, contact that business directly; we will support them in responding, and we will refer your request to them if you contact us instead.

3. Information we collect

Information you give us

  • Demo and contact requests.First name, last name, email address, the operational areas you tell us you’re interested in, and any free-text message you write.
  • Account information. Your email address, organization name, your role within that organization, and the invitations you send or accept.
  • Support and sales correspondence. Anything you send us by email or discuss with us on a call.

Customer Data you or your systems send us

  • Documents you upload. Invoices, purchase orders, general-ledger exports, budget workbooks, remittance and deduction files, and similar financial records, including any personal information they happen to contain, such as vendor contact names or approver names.
  • Data from systems you connect. When you authorize a connection to a commerce or accounting system, we retrieve the data covered by the permissions you grant. For a connected Shopify store this includes product, inventory, and order records. Order records we retrieve include the original payload from the source system, which can contain your end customers’ names, email addresses, and shipping addresses.

Information we collect automatically

  • Log and device data. IP address, browser and device type, pages requested, referring page, and timestamps, recorded by our hosting and infrastructure providers as part of delivering and securing the service.
  • Cookies. We use strictly necessary cookies to keep you signed in and to maintain your session. We do not use advertising cookies or third-party tracking cookies on our marketing site.

Do Not Track.Some browsers can send a “Do Not Track” signal. There is no common industry standard for interpreting those signals, and we do not currently respond to them. As noted above, we do not track you across third-party sites or serve advertising, so there is no cross-site tracking to opt out of.

4. How we use information

  • To provide, operate, secure, and improve the service.
  • To extract, categorize, reconcile, and analyze the documents and data you send us, which is the core function of the product.
  • To respond to demo requests, answer questions, and communicate with you about your account or about changes to the service.
  • To detect, investigate, and prevent fraud, abuse, and security incidents.
  • To comply with legal obligations and enforce our agreements.

We do not sell personal information, and we do not share it for cross-context behavioral advertising.

5. Automated processing and AI

Tahini uses large language models to read documents, map spreadsheet columns, categorize spend, suggest matches between records, and answer questions about your data. To do this, the relevant contents of your documents and data are transmitted to our AI model provider for processing, under a commercial agreement that restricts what that provider may do with it.

  • We do not train models on Customer Data.We do not use your data to train, fine-tune, or improve any model, whether our own or a third party’s.
  • Our provider is contractually barred from training on it. Our agreement with our AI model provider prohibits the use of data submitted through its interface to train that provider’s models.
  • Automated suggestions are not automated decisions. Where the product proposes a match, a categorization, or an approval route, a person in your organization confirms it. Tahini does not make decisions producing legal or similarly significant effects about any individual without human involvement.
  • Outputs can be wrong. Model-generated extractions and analyses should be reviewed before you rely on them for accounting, payment, tax, or reporting purposes.

6. How we share information

We share information only as described here. We use the following categories of sub-processors to run the service:

  • Cloud hosting and application delivery — to run the web application and its servers.
  • Database, authentication, and file storage — to store your account, your records, and your uploaded documents.
  • AI model processing — to perform the extraction and analysis described in Section 5.
  • Transactional email — to send invitations, sign-in links, and service notices.

We also share information when required by law or valid legal process, to protect our rights or the safety of others, and with an acquirer in connection with a merger, financing, or sale of assets, subject to continued protection under this policy. A current list of named sub-processors is available on request at hello@usetahini.com.

7. Security

We use technical and organizational measures to protect information, including tenant isolation enforced at the database level, encryption in transit and at rest, additional application-level encryption of integration credentials, private document storage reachable only through short-lived signed links, and role-based access controls. See our Security page for detail. No system is perfectly secure, and we cannot guarantee absolute security.

8. Retention

We retain Customer Data for as long as the customer’s account is active, and delete or return it on request or within a reasonable period after the account closes, unless we are required to keep it longer. Demo and contact requests are retained while we have a legitimate business interest in following up. Logs are retained on our providers’ standard schedules. Some data may persist in backups for a limited period after deletion.

9. Your rights and choices

Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of your personal information; to opt out of the sale or sharing of personal information, which we do not do; to limit use of sensitive personal information; and to be free from discrimination for exercising these rights. If you are in the European Economic Area or the United Kingdom, you may also have the right to object to or restrict certain processing and to lodge a complaint with your supervisory authority.

To exercise any of these rights, email hello@usetahini.com. We will verify your request before acting on it, and we will not treat you differently for making one. An authorized agent may submit a request on your behalf with proof of authorization. As explained in Section 2, requests about information held inside a customer’s account are handled by that customer.

10. International transfers

We operate in the United States, and our providers process information in the United States and other countries. If you access the service from outside the United States, you understand that your information will be transferred to and processed in the United States, where data protection law may differ from that of your country. Where required, we rely on appropriate safeguards such as standard contractual clauses.

11. Children

Tahini is a business product and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us information, contact us and we will delete it.

12. Changes to this policy

We may update this policy from time to time. When we do, we will revise the effective date above, and for material changes we will provide additional notice, such as by email or an in-product notice.

13. Contact us

Questions, requests, or complaints about privacy can be sent to hello@usetahini.com, or by mail to Tahini AI, Inc., San Francisco, California.