Privacy policy
This policy explains how Tilde AI (“Tilde”, “we”, “us”) collects and uses personal information when you visit trytilde.ai, book a demo, or hear from us about our products. It’s written to meet the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR), and it also covers the EU GDPR and US state privacy laws.
If your organisation uses the Tilde platform, the data you put into it is covered by your agreement with us. There, we act as your processor, and your organisation’s privacy notice applies.
Who we are
Tilde AI is a company registered in Delaware, United States. We’re the controller of the personal information described here. You can contact us about privacy at [email protected].
What we collect
| Category | Examples | Where it comes from |
|---|---|---|
| Contact and company details | Name, work email, job title, phone number, company, industry, company size, country | You, when you fill in a form or book a meeting |
| Meeting details | Meeting time, time zone, and anything you tell us when booking | You, through Calendly |
| Campaign and visit information | Pages viewed, the page or ad that brought you here (UTM tags and ad click IDs), referrer, browser and device type, approximate location from your IP address | Your browser, through cookies and similar technologies |
| Company identification | The company associated with your IP address, and, if you submit a form with analytics on, the link between your email and your visits | Snitcher |
| Advertising information | Whether you visited after seeing our ads, and conversions such as booking a demo | LinkedIn, Meta, Reddit and X pixels, with your consent or unless you opt out |
| Communications | Emails and messages with us, and notes from calls | You and our team |
We don’t ask for sensitive information, such as health or financial account details, and we ask you not to send it.
How we use it, and our lawful bases
| Purpose | Lawful basis (UK and EU) |
|---|---|
| Reply to your request and arrange your demo | Steps you ask us to take before a contract, and our legitimate interest in responding to business enquiries |
| Follow up about Tilde and send relevant business updates | Legitimate interests. You can opt out at any time. We only email individual (non-corporate) subscribers, such as sole traders, with consent or where the law allows |
| Understand how the site is used and which campaigns work | Consent, where cookies or device storage are involved. Legitimate interests for aggregate, cookieless statistics |
| Identify which companies visit | Consent |
| Measure our ads and show ads to past visitors | Consent |
| Keep the site secure and prevent spam | Legitimate interests |
| Meet legal obligations and defend legal claims | Legal obligation and legitimate interests |
Where we rely on legitimate interests, we’ve balanced them against your rights. You can object at any time (see your rights). We don’t make decisions about you with legal or similarly significant effects based solely on automated processing.
Who we share it with
We use these providers to run the site and our sales process. They process personal information on our instructions, unless noted.
| Provider | What they do for us |
|---|---|
| Attio | Customer relationship management: stores contact requests, bookings and our notes |
| Calendly | Meeting scheduling |
| PostHog (EU cloud) | Product and website analytics |
| Google Analytics | Website analytics |
| Snitcher | Identifying the companies that visit our site |
| LinkedIn, Meta (Facebook and Instagram), Reddit and X | Advertising measurement and audiences. These platforms also use the data for their own purposes as independent or joint controllers, under their own privacy policies |
| Vercel | Website hosting |
| Email, calendar and productivity providers | Running our communications |
We may also share information with professional advisers, with authorities where the law requires it, and with a buyer or successor if our business is reorganised or sold. We don’t sell personal information for money.
International transfers
We’re based in the United States, and several of our providers are too. When we transfer personal information from the UK or EU, we rely on adequacy regulations (including the UK Extension to the EU-US Data Privacy Framework, where the recipient is certified) or on standard contractual clauses with the UK Addendum or UK International Data Transfer Agreement. Contact us for a copy of the relevant safeguards.
How long we keep it
| Information | How long |
|---|---|
| Contact requests, bookings and sales records | Up to 3 years after our last contact with you, unless you become a customer, when our customer agreement applies |
| Records of email opt-outs | As long as needed to respect your choice |
| Analytics data | Up to 2 years |
| Your cookie choices | 6 months, then we ask again |
| Campaign attribution stored in your browser | Until you clear your browser storage or withdraw analytics consent |
Cookies and similar technologies
Cookies and similar technologies (such as local storage and pixels) store or read information on your device. We group them into three categories.
- Necessary: these make the site work and remember your privacy choices. They’re always on.
- Analytics: PostHog, Google Analytics, Snitcher, and our own record of the campaign that brought you here.
- Advertising: LinkedIn Insight Tag, Meta Pixel, Reddit Pixel and X Pixel.
In the UK, EU and everywhere outside the US, analytics and advertising only run if you accept them. Rejecting is as easy as accepting. Until you accept, PostHog may count visits without storing anything on your device.
In the US, analytics and advertising run unless you opt out. Your browser’s Global Privacy Control signal is treated as an opt-out of advertising.
You can change your choices at any time:
| Name | Provider | Purpose | Duration |
|---|---|---|---|
tilde_consent | Tilde | Remembers your cookie choices | 6 months |
tilde_region | Tilde | Decides which consent model applies, from your approximate country | 1 day |
tilde_attribution_first | Tilde (local storage) | The first page and campaign that brought you here (analytics) | Until cleared |
tilde_attribution_last | Tilde (local storage) | The most recent campaign that brought you here (analytics) | Until cleared |
ph_* | PostHog | Analytics visitor and session identifiers | Up to 1 year |
_ga, _ga_* | Analytics visitor and session identifiers | Up to 2 years | |
| Snitcher identifiers | Snitcher | Device and session identifiers for company identification | Up to 1 year |
li_fat_id, bcookie, lidc, UserMatchHistory | Ad measurement and audiences | Up to 1 year | |
_fbp, _fbc | Meta | Ad measurement and audiences | Up to 90 days |
_rdt_uuid | Ad measurement and audiences | Up to 90 days | |
muc_ads, personalization_id | X | Ad measurement and audiences | Up to 2 years |
| Calendly cookies | Calendly | Run the booking calendar after you ask to book. Set by Calendly under its own policy | Set by Calendly |
Your rights in the UK and EU
You have the right to access your personal information, correct it, have it erased, restrict or object to how we use it, and receive it in a portable format. You can object to direct marketing at any time, and we’ll stop. Where we rely on consent, you can withdraw it at any time without affecting earlier processing.
To use your rights, email [email protected]. We’ll reply within one month. If you’re unhappy with how we’ve handled your information, please tell us first. You can also complain to the UK Information Commissioner’s Office at ico.org.uk or on 0303 123 1113, or to your local data protection authority in the EU.
Your rights in the US
Depending on where you live, US state privacy laws, such as those in California, Colorado, Connecticut, Virginia and Texas, may give you the right to:
- know what personal information we collect, use and disclose, and get a copy
- correct or delete it
- opt out of the “sale” or “sharing” of personal information, and of targeted advertising
- not be treated differently for using these rights
Sale and sharing. We don’t sell personal information for money. When advertising pixels are on, LinkedIn, Meta, Reddit and X receive identifiers and browsing information for cross-context behavioural advertising, which some state laws call “sharing” or “targeted advertising”. In the last 12 months, the categories involved were identifiers and internet or other electronic network activity. To opt out, use the “Do Not Sell or Share My Personal Information” link in the footer or the button above. We honour Global Privacy Control signals as an opt-out. We don’t knowingly sell or share the personal information of anyone under 16.
Categories we collect. Identifiers (such as name, email and IP address), professional information (job title and company), internet activity (pages viewed and campaign information), and approximate location. We collect them from you, your device and the providers listed above, for the purposes described in this policy. We disclose them to the providers listed above. We don’t collect sensitive personal information for inferring characteristics about you.
Making a request. Email [email protected]. We’ll verify your request by matching the details you give us with our records. You can use an authorised agent, who will need your signed permission. If we decline your request, you can appeal by replying to our decision, and we’ll respond within the time the law requires.
Children
Our site and services are for businesses. They aren’t aimed at children, and we don’t knowingly collect information from anyone under 16.
Security
We use access controls, encryption in transit and reputable providers to protect personal information. No system is completely secure, so please contact us straight away if you think your information has been put at risk.
Changes to this policy
We’ll update this page when our practices change and show the date at the top. If a change is significant, we’ll tell you more prominently.
Contact us
Questions or requests? Email [email protected].