● Trust
Privacy Policy
Last updated 26 September 2026
Who we are
Guildia is a product of SPIN LLC (შპს სპინ), a company registered in Georgia (reg. № 405173191), Ana Politkovskaia St. 22a, Floor 10, Apt 140, Vake, Tbilisi 0186, Georgia. Contact: hello@spin.ge.
The agreement with businesses that use Guildia, including how we process their customers' data, is in our Terms of Service and Data Processing Addendum. Guildia is an AI employee that answers a business's customers — by chat, text, email and phone — from the knowledge that business has approved. We have two roles. For businesses that use Guildia (our customers), we act on their behalf and only on their instructions when we handle their customers' information. For the people who sign up and run a Guildia account, we decide how that account information is used, as described here.
What we collect
Account information — name, email, sign-in details, the business's name, location, settings and billing status. Card details are handled by our payment provider; we never see or store full card numbers.
What a business teaches its agent — interview answers, documents, web pages and knowledge cards.
Conversations with a business's customers — the messages the agent receives and sends, and the contact details the business imports or that a customer gives (for example a name, phone number or email). Phone calls are not recorded; what is said is turned into text so the agent can answer. Website chats that are not handed to a person are deleted after 24 hours of inactivity.
Connected systems — when a business connects its own calendar, phone number, customer system or online store, we read what the agent needs from it. For an online store such as Shopify that means orders (to answer “where's my order?” after checking who is asking), customers, products and stock. We only ever read it; we never place, change, cancel or refund an order.
Usage and cost records — counts of conversations, voice minutes and messages, used for billing and to keep the service healthy. We keep names and phone numbers out of our logs and analytics and use internal IDs instead.
How we use it
Only to provide Guildia to the business: answer its customers from its approved knowledge, draft the messages it approves, keep its records, bill it, and keep the service secure and working. We do not sell personal information, we do not use a business's customer data for advertising, and we do not use it to train AI models.
Text messages are only sent to people with consent on file; “STOP” is honored immediately and permanently.
Who processes it for us
We use a small set of service providers (hosting, database, AI models, messaging, payments). The full, current list — with what each is used for — is on our subprocessors page. AI providers receive only what is needed to produce an answer.
How long we keep it
For as long as the business keeps its Guildia account, unless the business deletes it sooner. Operational records age out automatically: usage analytics after 1 year, AI cost records and the data-access log after 2 years, and deleted sales leads 90 days after deletion. When a business deletes its account we delete its data; we keep only a redacted record that the deletion happened and the financial records we are legally required to keep.
When a store uninstalls the Guildia Shopify app, access to the store stops immediately, and the store's data (products, customers imported from the store, and the connection) is erased when Shopify sends its store-deletion request.
Your rights
You can ask for a copy of your information, or ask for it to be corrected or deleted. If you are a customer of a business that uses Guildia, contact that business first — it controls your data and can export or erase your record in Guildia directly. You can also write to us at hello@spin.ge and we will pass your request on or act on it. Requests from a Shopify store about its customers are handled through Shopify's privacy requests.
Security
Credentials for connected systems are encrypted; access to data is limited by business and by role; every approval, send and settings change is written to an audit log, and every time someone opens a customer's record or conversation, or exports data, it is logged (who and when — never the data itself). More detail is on our security page.
Changes
If we change this policy we will update the date above, and tell account holders about material changes before they take effect.