Privacy policy
Effective October 11, 2026. This policy covers TendMyStore for WooCommerce ("TendMyStore"), a YLabs product, its website tendmystore.com and its service at api.tendmystore.com.
What changed on October 11, 2026. TendMyStore can now manage your store, not only read it. To do that, it now:
- asks WooCommerce for a Read/Write key instead of a view-only key;
- keeps your store connection and your sign-in in an encrypted file on our server, so a restart no longer signs you out;
- keeps a 30-day history of the changes it makes, so you can see and undo them.
Each item is described below.
What TendMyStore does
TendMyStore lets an AI assistant (ChatGPT or Claude) manage a WooCommerce store that its owner has approved. It uses a Read/Write REST API key that WooCommerce creates when the store owner approves access. With it, TendMyStore reads and changes products, orders, customers, coupons, shipping, taxes and store settings when you ask your assistant to. It sends requests only to a fixed list of WooCommerce endpoints.
TendMyStore never moves money. It records refunds in WooCommerce without asking your payment provider to pay them, and it never reads or changes payment-gateway credentials.
What we receive and keep
| Data | Why | Where and how long |
|---|---|---|
| Your store's address | To send requests to your store | In the encrypted state file on our server, until you disconnect or the key stops working |
| The Read/Write API key and secret that WooCommerce creates | To read and change your store when you ask | In the encrypted state file on our server, until you disconnect or the key stops working. Never logged and never shown to the assistant |
| Sign-in sessions and tokens for your assistant | To keep you signed in | Stored only as hashes, in the encrypted state file. Access tokens last 1 hour, refresh tokens 7 days, a session at most 30 days |
| Change history: for each change made through TendMyStore, the tool, the item, and the old and new values of the fields it changed | So you can list and undo changes | In the encrypted state file, for 30 days. Deleted when you disconnect. It can contain customer details when you change a customer or an order |
| Files you ask for: CSV exports of products or orders, invoices and packing slips | So you can download them | In server memory for one hour behind a long random link (at most five downloads), then deleted. Never written to disk. Order exports hold no customer names, emails, phones or addresses; an invoice or packing slip shows that one customer's name and address. Anyone you give a link to can open it during that hour |
| A CSV file you ask us to import from a link | To import the products in it | Read once into memory for that request, then discarded |
| Other store data your assistant asks for | To answer the question | Held in memory for the length of one request, then discarded |
| Security events (a fixed event code, a time and a random store id) | To detect and investigate abuse | A file on our server of at most 10 MiB. It contains no names, emails, keys, IP addresses or store data |
| Rate-limit counters | To protect stores and the service | Counts only, kept for one minute or one hour |
| Error records of our web server (for example, a failed request during a restart) | To fix faults | The requested address and time, without your IP address. A rotating log of at most 30 MB. There is no access log |
The state file is encrypted with AES-256-GCM. The key that decrypts it is kept only in the server's configuration, not in the file.
What reaches your AI assistant
The answers to your requests go to the assistant you use. They are governed by OpenAI's or Anthropic's own privacy terms. TendMyStore returns what the request needs:
- Orders: number, status, dates, totals, items, shipping, refunds and notes. When you open one order, also the customer's name, email, phone and billing and shipping address, because fulfilling and answering an order needs them. Order lists show the customer's name and email only.
- Customers: name, email, addresses and recent orders, when you ask about a customer.
- Products, coupons, reviews, shipping, taxes, store settings and reports. Settings that hold passwords or keys are hidden.
Text that you, your staff or your customers typed into your store, such as product descriptions, order notes or reviews, may itself contain personal data.
Cookies
The sign-in pages set one short-lived cookie to bind the sign-in to your browser. It is removed when the sign-in ends. We use no advertising or analytics cookies. Cloudflare, which protects our site, may set its own security cookies.
Who processes data for us
- Cloudflare, Inc. carries all traffic to our website and service.
- DigitalOcean, LLC hosts our server in Frankfurt, Germany.
We do not sell or rent any data, and we do not use it for advertising.
Your choices
- Disconnect at any time. Ask your assistant to disconnect your store, or revoke the "TendMyStore" key in WooCommerce under Settings > Advanced > REST API. Either one ends our access. When you disconnect, we delete the key, your sessions and the change history for your store.
- Ask us what we hold about your store, or ask us to delete it, at support@tendmystore.com.
Children
TendMyStore is a tool for store owners. It is not meant for children under 16.
Changes
If we change this policy, we will update this page and its date. A change that lets us keep more data will be announced on this site before it takes effect.
Contact
YLabs, support@tendmystore.com