TML Quiz privacy notice

Last updated on October 3, 2026

This notice describes data handled by TML Quiz, operated by Taimanle. It covers the Shopify app and quizzes merchants publish on their storefronts. TML URL Redirect has a separate privacy policy.

Privacy and support contact: support@taimanle.com.

Data handled by the app

  • Shop and installation information: Shopify shop identifiers and domain, authenticated app sessions, granted access scopes, store name, and subscription or plan status needed to provide the app.
  • Quiz content and settings: questions, answer options, branching paths, results, design settings, product selections, lead-capture settings, saved drafts, and published versions.
  • Product information: selected catalog product and variant identifiers and titles used to configure or validate recommendations. Shopify product information is also used to display the products a merchant chooses on result screens.
  • Shopper activity and responses: quiz attempt and submission identifiers, the quiz version taken, answers, result, start and completion times, and aggregate starts and completions. Free-text answers can contain personal information if a shopper chooses to provide it.
  • Optional email capture: a shopper’s email address and consent status when the merchant enables email capture and the shopper selects the consent checkbox.
  • Operational information: AI action counts, plan, model, token counts, reported provider cost, timestamps, and error codes; request-rate counters derived from a hashed network-address fingerprint; and operational logs needed to run and troubleshoot the app.
  • Privacy requests: the authenticated shop, Shopify request identifier, customer identifiers supplied with the request, received time and due date, export time, and fulfillment status needed to track an access request.
  • Support correspondence: information you choose to send when contacting Taimanle.

Merchants control quiz content, product recommendations, and whether to request email addresses. Email capture is a separate feature from a store’s marketing subscription process. TML Quiz does not collect payment card details; Shopify handles subscription approval and payment.

How data is used

We use app data to authenticate merchants, save and publish quizzes, deliver the selected quiz on the storefront, validate submissions, show responses and completion information, provide requested AI assistance, verify plan access, manage AI allowances, prevent abuse, and respond to support or privacy requests.

Shopper responses are available to the merchant operating the quiz. Merchants can export responses as CSV and delete individual responses. Merchants are responsible for the purposes for which they collect or use shopper responses and email addresses, and for explaining those purposes in their own store privacy notice.

AI assistance and service providers

AI assistance is initiated by a merchant in the app editor. Requests are sent through OpenRouter to the model-serving providers it routes to. The configured models are Google’s Gemini Flash for quiz generation, revision, and basic styling, and OpenAI’s GPT for Pro brand styling.

An AI request can include your prompt, the existing quiz definition, relevant catalog product or variant identifiers and titles, and, for brand styling, your store name and chosen colors and typography. These services return quiz or design proposals for you to review. TML Quiz does not load stored shopper response or captured-email records into AI requests. Personal information that you include yourself in prompts or quiz content can nevertheless be transmitted as part of a request: do not include unnecessary personal information or secrets.

The app keeps AI accounting metadata rather than a separate saved prompt history. Quiz drafts and published versions remain saved as app content. AI routing is configured to deny providers that OpenRouter identifies as collecting request data. This setting is not a guarantee that every service has zero retention; provider handling is governed by the applicable service terms and privacy settings. See OpenRouter’s privacy policy and provider routing documentation.

Shopify provides the commerce platform, app authentication, API access, theme integration, and subscription services. Railway provides app hosting and persistent storage. These services may process data in the locations in which they operate. This notice does not promise that AI or other service processing stays within a single country.

Storage and deletion

Quiz definitions, versions, attempts, responses, plan-allowance records, and AI accounting metadata are stored in the app’s database. Data is retained while needed to provide the service, support merchant use, maintain security, or address applicable obligations.

Uninstalling the app removes app authentication sessions; it does not immediately erase every quiz or AI-allowance record. Shopify’s shop-deletion privacy webhook triggers deletion of shop-scoped app data. Shopify customer-deletion requests remove matching response records when customer identifiers or an email address are provided. Operational copies, logs, or backups can have separate retention from the active app database.

Shopify customer-data access requests are recorded in the app and made available to the authenticated merchant through Privacy Requests. Matching responses and their quiz-version context can be exported for the request. Fulfillment requires manual review and secure delivery to the verified store owner; recording or exporting a request does not automatically send the data to anyone. Request identifiers and status records remain until the applicable customer or shop deletion process; there is no automatic age-based purge of these records. Temporary downloaded exports must be handled and removed separately.

To request access, correction, export, or deletion, contact support@taimanle.com and identify the relevant store. We may need to verify your authority to access the data. Shoppers should contact the store that collected their responses first; Taimanle can help coordinate an app-data request with the merchant.

Safeguards and merchant responsibilities

The app uses Shopify authentication for admin access, signed Shopify app-proxy requests for storefront delivery, shop-scoped data access, and server-side validation of responses and email consent. Merchants should limit the personal information requested in quizzes and keep secrets and unnecessary shopper information out of AI prompts and support messages.

Updates and contact

This notice may be updated as the app or its service providers change. The date above identifies this version. Contact support@taimanle.com for privacy questions.