Tempo Growth Tools
Privacy Policy
Effective and last updated: 6 August 2026
1. Who we are
Tempo Growth Tools (the Service) is operated by GetRobo ("we", "us", or "our"). Contact us at contact@getrobo.xyz.
2. Scope and roles
This policy applies when a business installs or uses the Service through BigCommerce, enables storefront tools, uses an authorized connected workspace, or contacts support. The Service is intended for business users. We act as controller for merchant account administration, security, service usage records and support communications. We act as processor for storefront configuration and shopper submissions processed on behalf of a merchant. The merchant remains the controller of shopper data and decides which campaigns to enable and which lawful basis and notices apply.
3. Information we process
- BigCommerce installation data: store hash, connected channel and site identifiers, storefront domains, granted OAuth scopes, application client identifier, an administrator email address and an encrypted access token.
- Tool configuration: content, schedules, styles, visibility and targeting rules, product, category, brand and customer-group identifiers, promotion and coupon references, URLs and merchant-supplied images.
- Shopper submissions: email addresses submitted through Promotional Popups or Spin-to-Win, source product or storefront URL, campaign identifier, submission time and limited coupon or campaign metadata.
- Billable interaction records: random event and 30-minute session identifiers, widget and channel identifiers, action type and time. These records deduplicate valuable interactions and enforce the merchant plan; the defined event record does not contain a customer identifier, name, email, order value or IP address.
- Catalog and platform data: product, category, brand, promotion and customer-group names and identifiers, prices, stock context, store currency and timezone, and storefront URLs requested from BigCommerce. Tempo does not request the customer list for group targeting.
- Campaign analytics when enabled: random per-tab session identifier, campaign and channel identifiers, event type and time, page type and path without query string or fragment, device class, locale, currency and controlled error reason. The defined analytics event does not contain a customer identifier, name, email, cart contents, coupon code, order ID, revenue or IP address.
- Connected-workspace data: when an authorized SpectoAI-connected workflow is used, the connected service may provide the BigCommerce store hash, OAuth credential and scopes, application client identifier, Tempo plan and interaction entitlement period so Tempo can establish the store workspace. Tempo encrypts the stored BigCommerce access token.
- Technical and browser data: essential application and security logs, a short-lived admin session token, and browser storage used for campaign dismissals, countdown deadlines, a pseudonymous interaction session, recently viewed products, selected currency and an optional analytics session.
- Support data: contact details, store and campaign references, message content and redacted screenshots voluntarily provided to support.
Intercom support context: when a workspace token is configured, Tempo identifies the merchant account in Intercom with the BigCommerce administrator email address, the store name, the storefront domain, the store's secure URL and the current Tempo plan. It also keeps the names and number of currently enabled storefront tools, the number of connected storefronts and the current interaction usage as contact and company attributes, so support can see the store's setup during a conversation. Administrators of the same store are grouped under one company keyed by the storefront domain. Feature events additionally include the stable feature identifier, feature kind and its new state; admin usage events include a predefined section name and bounded visit duration. Tempo does not send store hashes, OAuth or Intercom access tokens, passwords, private keys, campaign configuration, shopper submissions, product data, scopes, browser-session identifiers or arbitrary event context to Intercom.
The Service does not request payment-card or financial-account data and does not include advertising tracking, cross-store customer profiles or revenue attribution.
4. Purposes and legal bases
- Contract and steps requested before a contract: authenticate the merchant, provide the application, maintain entitlements, publish configured campaigns and answer service requests.
- Legitimate interests: secure the Service, prevent abuse, deduplicate billable interactions, diagnose failures and improve reliable operation, balanced against the limited and pseudonymous data used for those purposes.
- Legal obligations: retain and disclose information when applicable law requires it.
- Processing on merchant instructions: publish the merchant's configuration and store shopper submissions. The merchant determines the lawful basis for shopper-facing campaigns, including any consent required for marketing or analytics.
When Analytics is enabled, BigCommerce controls whether the separate Analytics-category script is loaded under the storefront consent configuration. Merchants are responsible for configuring that mechanism and presenting required notices.
5. Service providers and disclosure
- BigCommerce: application installation, OAuth, catalog and storefront APIs, Script Manager, promotions and platform billing when used.
- Railway and its infrastructure providers: application hosting, network delivery, operational logs and PostgreSQL storage.
- SpectoAI: authorized connected-workspace bootstrap, session handoff and entitlement synchronization when that integration is used.
- Intercom: support messaging, installation tracking and onboarding communication when a workspace token is configured. The admin support widget loads in the Tempo application only, not on the storefront.
- ipapi.co: approximate country lookup when a merchant enables country-dependent targeting or location detection. The shopper's browser contacts this provider directly, so the provider receives ordinary request data such as the IP address and browser headers.
- Google Fonts: font delivery when a merchant-selected storefront style requests a Google-hosted font. The shopper's browser contacts Google directly.
- Frankfurter: exchange-rate data for live currency conversion. Tempo requests rates from the server and does not intentionally include shopper identifiers in that request.
- Email and GitHub: support communication and issue handling where used.
We disclose information when required by law, to protect rights and security, or in connection with a business transfer. We do not sell personal information.
6. International transfers
Some providers and hosting regions may process data outside Poland or the EEA, including in the United States. Where Chapter V of the GDPR requires a transfer safeguard, we rely on an applicable adequacy mechanism or contractual safeguards made available by the provider, including Standard Contractual Clauses where applicable. Contact us to request information about the safeguard relevant to a particular transfer.
7. Retention and deletion
Campaign analytics events older than 30 days and billable interaction records older than 62 days are removed during subsequent event processing or maintenance. If a store has no subsequent event processing, an older record may remain until maintenance or uninstall. Store configuration and shopper-submission events are retained while the app is installed, subject to storage caps. When BigCommerce sends a valid uninstall callback, the Service deletes the store record, encrypted access token, configurations, billable records and stored events from the active database. Restricted infrastructure backups may persist for the hosting provider's normal backup lifecycle. Support records are retained for the time needed to resolve the request and meet legal or security obligations.
8. Security
We use HTTPS, encrypted access-token storage, access controls, input validation, parameterized database queries, and store-level data separation. No security measure can guarantee absolute protection.
9. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, objection or portability, withdraw consent where processing relies on consent, and complain to a supervisory authority. Contact contact@getrobo.xyz. For shopper data processed on behalf of a merchant, contact the merchant first; we assist the merchant with verified requests. Providing BigCommerce installation information is necessary to operate the Service. Support information is voluntary, but missing diagnostic details may limit our ability to investigate.
10. Automated decisions, children and changes
Tempo does not use the information described here to make decisions that produce legal or similarly significant effects about individuals. The Service is not directed to children. We may update this policy and will revise the date above when changes are made.