Privacy policy
Last updated 25 September 2026
TR Desk is an internal customer-service tool used by the TR e-commerce stores to answer customer emails. It is not offered to the public; only staff invited by an administrator can sign in.
What we access
When a store connects its support mailbox with Google, TR Desk requests permission to read, label and send email in that mailbox (Gmail scopes gmail.modify and gmail.send). We use this only to:
- import customer emails into the shared support inbox so staff can reply to them;
- send the replies that staff write or approve, from the store’s own address and in the same thread;
- keep read and label state in step between Gmail and TR Desk.
When a store connects Shopify, TR Desk reads order, customer and fulfilment details so staff can see the order a customer is writing about, and can issue refunds or submit dispute evidence when staff choose to.
How the data is used
- Email content is shown to authorised support staff of the store it belongs to.
- To help staff reply, message text may be sent to our processors for translation (DeepL) and for drafting suggested replies (Anthropic). They process it only to provide that service to us.
- We do not sell data, use it for advertising, or share it with anyone else, and no person reads mailbox data except the store’s own support staff.
Google API data
TR Desk’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Gmail data is used only to provide the support-inbox features described above.
Storage and security
Data is stored in a Supabase (PostgreSQL) database in the EU/UK region (London) and served from Vercel. Access tokens for Gmail and Shopify are stored server-side and are never exposed to the browser. Access inside TR Desk is limited per store and per role.
Retention and deletion
Conversations are kept as long as the store needs them for customer service. An administrator can disconnect a mailbox at any time in Settings, which stops all access; access can also be revoked from the Google account at myaccount.google.com/permissions. Customers can ask the store they contacted to have their data deleted.
Contact
Questions about this policy can be sent to the support address of the store you are in contact with.