Service operator
Avatar Genie LLC d/b/a Tessal
LLC formed in Delaware
Contact: Tessal contact page
Overview
This Privacy Policy explains how the service operator identified on this page (the “Company,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information across our marketing site, business accounts, dashboard, hosted customer websites, billing, support, and related services (the “Service”).
The key points:
- We are a business-to-business service. Accounts are for businesses and organizations.
- We do not sell personal information, and we do not share it for cross-context behavioral advertising.
- We do not run third-party advertising networks, advertising pixels, or cross-site tracking on our own pages.
- Our customers control the websites they build. For information collected through a customer’s website, that customer decides why and how it is used, and we act on their instructions.
- You can export your data and request deletion from the dashboard.
- Privacy questions and rights requests go to the privacy contact listed on this page.
Who we are and the roles we play
For our marketing site, signup, dashboard, billing, support, and security operations, we decide why and how personal information is used. Under United States state privacy laws we act as a business or controller for that information.
For information a customer collects from Visitors through their website, including form submissions, bookings, orders, reviews, uploads, and site analytics, the customer decides why and how it is used. We act as that customer’s service provider or processor, handling the information on their documented instructions and under our U.S. Data Processing Addendum.
Each customer website should publish its own privacy notice. This Policy does not cover the practices of our customers, or of third-party sites, embeds, or services a customer chooses to add.
Information we collect
Account and contact information. Name, business or organization name, email address, phone number, role, team membership, preferences, and the messages you send us.
Authentication and security information. Password hashes (we never store a password in readable form), session records, two-factor settings and encrypted secrets, hashed recovery codes, verification and reset tokens, sign-in history, and audit records of privileged actions.
Billing information. Plan and subscription status, billing period, invoices, tax details where applicable, and limited payment identifiers from our payment processor such as card brand, last four digits, and expiration. Full payment-card numbers are handled by Stripe and are never stored by us.
Customer business data and content. Sites, pages, media and files, forms and submissions, leads and customer records, bookings, orders, requests, quotes, reviews, loyalty records, settings, domains, and revision history that you create or collect through the Service.
Visitor information from customer websites. Information Visitors give our customers through forms, bookings, orders, uploads, and reviews, together with site analytics events. This information belongs to the customer’s relationship with the Visitor.
Technical and log information. IP address at the time of a request, used for security, rate limiting, and abuse prevention; browser and device details; operating system; referring page; pages and actions; timestamps; error and diagnostic records; and cookie or storage identifiers.
Site analytics information. Page views, engagement, clicks, form and booking funnel steps, downloads, and experiment exposure. Visitor and session identifiers, along with a coarse IP prefix, are hashed with a platform secret before storage, so no raw IP address is kept in site analytics. Query strings are stripped from paths and only the referring hostname is retained.
Product usage information. Bounded operational events such as signup, template selection, editor engagement, publication, module adoption, AI requests, and cancellation signals. These records do not contain page bodies, form answers, prompts, secrets, or raw visitor identifiers.
AI feature information. The prompts and business context you submit and the outputs returned, stored in your generation history so you can review, export, and delete them.
Support, abuse, and legal information. Support tickets and attachments, abuse reports submitted through our public form, notices we receive about content, and records of how we responded.
Marketing information. Contact-form submissions, update preferences, and how you found us if you tell us.
Where the information comes from
We receive information:
- directly from you and the people you invite to your account;
- from Visitors who interact with a customer website;
- automatically from browsers, devices, and our servers as the Service is used;
- from service providers such as our payment processor, email provider, and infrastructure provider; and
- from people who report abuse or a rights concern, and from public sources when we investigate one.
How we use information
We use personal information to:
- create and administer accounts, authenticate users, and operate the dashboard;
- build, host, publish, and deliver customer websites and the business tools you enable;
- process subscriptions, payments, renewals, invoices, and taxes;
- send service, security, billing, and legal messages, and the notifications you turn on;
- provide support and answer your questions;
- keep the Service secure, detect and prevent fraud and abuse, enforce plan limits, and investigate violations;
- measure and improve the Service, fix problems, and develop new features;
- keep records for accounting, dispute resolution, and legal compliance; and
- comply with law and enforce our agreements.
We may create aggregated or de-identified information that cannot reasonably be used to identify a person, and use it for product, security, and business analysis. We maintain de-identified information in de-identified form and do not attempt to re-identify it, except to test that our de-identification works.
How we disclose information
We disclose personal information only as needed, in these ways:
- Service providers. We use vendors for hosting, databases, storage, payments, email delivery, domains and certificates, bot protection, error monitoring, notifications, and optional AI features. Our Subprocessors page lists the current categories and providers. They may use the information only to perform services for us.
- Your team. Information in an account is available to that account’s members according to the roles you assign.
- Our customers. Visitor information collected through a customer website is made available to the customer who operates that site.
- Legal and safety. We may disclose information to comply with law, a subpoena, or other legal process; to respond to a government request; to enforce our agreements; to protect the rights, property, safety, or security of the Company, our customers, Visitors, or the public; and to investigate fraud or abuse. Where we may lawfully do so, we will try to notify the affected customer first.
- Business transactions. If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may transfer as part of that transaction, subject to this Policy or to notice of any material change.
- With your direction. We disclose information when you ask us to or otherwise consent.
We do not sell personal information for money or other valuable consideration, and we do not share it for cross-context behavioral advertising, as those terms are defined by United States state privacy laws. We have not done either in the twelve months before the effective date of this Policy.
Customer websites and Visitor information
When you use a website built with our Service, the business operating that site decides what information to collect and why. Direct your questions, including access and deletion requests, to that business. Their contact details and privacy notice should appear on the site.
We provide the tools that make those choices possible. Customers configure their consent settings, optional analytics, marketing technology, third-party embeds, and any age gate, and they are responsible for their own notices, permissions, retention choices, and responses to Visitor requests.
Our built-in site analytics is designed to be privacy-minimizing. It is first-party, builds no cross-site advertising profile, hashes visitor and session identifiers together with a coarse IP prefix, stores no raw IP address, strips query strings from paths, keeps only a referring hostname, and can run in a cookieless daily aggregation mode. Analytics history is retained according to the customer’s plan.
If a Visitor contacts us directly about information held by one of our customers, we will normally refer them to that customer and help the customer respond.
Cookies and similar technology
We use cookies and similar browser storage to keep you signed in, protect against cross-site request forgery, remember preferences, protect public forms from automated abuse, and support features you request. Our Cookie & Tracking Notice describes each category, what a customer can enable on their own site, and the choices available to you.
Because we do not sell personal information or share it for cross-context behavioral advertising, a Global Privacy Control or Do Not Track signal does not change how we process information on our own pages. Where a state law treats a Global Privacy Control signal as a valid opt-out request that applies to us, we honor it.
How long we keep information
We keep personal information only as long as we reasonably need it for the purposes described in this Policy. In practice:
- Account and site data is kept while the account is active.
- When you request account deletion, we schedule it with a 30-day recovery window during which you can cancel. After that window our lifecycle processes delete or de-identify the data.
- Data export files are stored privately and expire seven days after they are generated.
- Backups run on a limited rolling cycle for disaster recovery, so deleted data can persist briefly in backups before it ages out.
- Site analytics history is retained according to the account’s plan.
- Security, audit, and abuse records are kept for a period appropriate to investigation and legal defense.
- Billing, tax, and legal-acceptance records are kept as long as law or our recordkeeping obligations require.
- Anything subject to a legal hold, dispute, or investigation is kept until that matter is resolved.
How we protect information
We use administrative, technical, and organizational safeguards suited to the nature of the Service, including Argon2id password hashing, server-side revocable sessions that store only token hashes, cross-site request forgery protection, optional two-factor authentication with encrypted secrets, encryption in transit, private storage reached through short-lived authorized access, role-based access control and tenant isolation, rate limiting, restrictive browser security headers, audit logging of privileged actions, and monitoring.
No service can guarantee perfect security. You remain responsible for your account permissions, your team’s devices and credentials, the content you publish, and the security of data you export.
If we confirm a security incident affecting personal information, we will notify affected customers and, where required, individuals and regulators, in the manner and within the time the law and our Data Processing Addendum require.
Your choices
- Account information. Update your profile, business details, and team roles in the dashboard.
- Communications. While you have an account you will continue to receive essential service, security, billing, and legal messages. You can adjust notification, digest, quiet-hours, and browser-push settings, and you can unsubscribe from non-essential marketing email using the link in those messages.
- Browser controls. You can block or clear cookies and storage and revoke notification permissions in your browser. Blocking essential storage prevents sign-in and other features from working.
- Export. Request a portable export of your account or site data from the dashboard.
- Deletion. Schedule account deletion from the dashboard, and cancel it during the recovery window if you change your mind.
Your United States privacy rights
Depending on where you live, and on whether a law applies to us and to the information at issue, you may have the right to:
- know what personal information we collect, use, and disclose, and access or receive a copy of it in a portable form;
- correct inaccurate personal information;
- delete personal information we hold about you;
- opt out of the sale or sharing of personal information, of targeted advertising, and of certain profiling (we do not engage in these activities);
- limit the use and disclosure of sensitive personal information;
- appeal a decision we make about a request; and
- receive equal service and pricing when you exercise a right.
How to make a request. Send it to the privacy contact listed on this page, or use the export and deletion tools in the dashboard. Tell us which right you want to exercise and give us enough information to find your records.
Verification. We will take reasonable steps to verify your identity and authority before acting, which may mean confirming control of the account email address or asking for more information. Information you provide for verification is used only for that purpose. We may decline a request where law permits, and we will explain why.
Authorized agents. An authorized agent may submit a request on your behalf where the law allows. We may ask for proof of the agent’s authority and may ask you to confirm the request directly.
Timing and appeals. We respond within the period the applicable law requires, generally 45 days, with an extension where permitted. If we deny a request in whole or in part, our response explains how to appeal, and we will tell you the outcome of an appeal in writing within the period the law requires.
California. We collect the categories of personal information described under “Information we collect,” for the purposes described under “How we use information,” and disclose them to the categories of recipients described under “How we disclose information.” Retention is described under “How long we keep information.” We do not sell or share personal information as the California Consumer Privacy Act defines those terms, and we do not use or disclose sensitive personal information for purposes beyond those permitted without a right to limit. California residents may also ask about disclosures for third-party direct marketing under California’s “Shine the Light” law; we make no such disclosures.
Nevada. We do not sell personal information as Nevada law defines it. Nevada residents may still submit an opt-out request to the privacy contact on this page.
Other states. Residents of states with comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and Delaware, and others as their laws take effect, may exercise the rights listed above to the extent the law applies to us and to the information at issue, including the right to appeal a denial.
Children’s privacy
The Service is a business tool and is not directed to children. We do not knowingly collect personal information from children under 13, and account holders must be at least 18.
Customers may not use the Service to operate a website or experience directed to children under 13, or knowingly collect personal information from children under 13, unless we have agreed in writing that the required protections are supported. An age prompt or age gate by itself does not satisfy the Children’s Online Privacy Protection Act or similar laws.
We do not knowingly sell or share the personal information of anyone under 16. If you believe a child has provided personal information through the Service, contact the privacy contact listed on this page and we will take appropriate steps to delete it.
Where information is processed
We operate the Service in the United States, and our providers process information in the United States unless our Subprocessors page says otherwise. If you use the Service from outside the United States, your information will be transferred to, stored in, and processed in the United States, where privacy laws may differ from those where you live. We do not offer the Service as compliant with the European Union or United Kingdom data-protection regimes or with other non-United States privacy laws.
Third-party links, embeds, and payment pages
Our pages and customer websites may link to or embed third-party content. Payment steps are handled by Stripe on pages Stripe controls, under Stripe’s own privacy policy. Third parties collect information under their own policies, and we are not responsible for their practices. Review the privacy notice of any service before you use it.
Changes to this Policy
We may update this Policy as the Service, our providers, or the law changes. Each update is published on this page as a new version with a new effective date. If a change is material, we will give additional notice by email or in the dashboard before it takes effect where the law requires. Continuing to use the Service after the effective date means you accept the updated Policy.
How to contact us
Send privacy questions, rights requests, and appeals to the privacy contact listed on this page, or write to the mailing address shown there. If your question concerns information held by a business that uses our Service, contact that business first and we will help them respond.