Legal

Privacy policy

What we collect when shops use Tily and when their customers plan or visualise a room — and, as importantly, what we don't.

Last updated 8 October 2026

1. Who we are

Tily makes a tile planner and a room visualiser that tile shops embed on their websites, and free versions of both on trytily.com. This policy is published by Tily, called “Tily” or “we” below.

We act in two roles. For shop accounts and for our own website and free tools, we decide how the data is used and are the controller under UK GDPR. When a shopper uses the planner or the visualiser on a shop’s website, we process what the widget sends on that shop’s behalf; the shop’s own privacy policy covers its site.

Contact us about anything in this policy at hello@trytily.com.

2. Shop accounts

Accounts are opened by invitation. For each person with access to a shop’s dashboard we keep:

  • first name, surname and email address, and the shop’s name;
  • a password, stored only as a salted hash we cannot read back;
  • sign-in sessions: when they started and were last used, and the browser they came from (its user agent);
  • security records: failed sign-in attempts, temporary lockouts, password and email changes;
  • a record of changes made in the account, so a shop and our support can see who changed what.

We also keep what a shop puts into Tily to run it: its products, prices, images and catalogue feeds, and the widget settings. Credentials a shop saves for a catalogue feed are stored encrypted.

We use this to provide the service, keep accounts secure and support the shop. The legal basis is the contract with the shop and, for security records, our legitimate interest in keeping accounts safe.

3. Shoppers using the planner and visualiser

The widgets do not ask shoppers who they are, set no cookies and do not record IP addresses. To show the shop how its widgets are used, they send events such as “a room was drawn”, “a photo was uploaded” or “added to basket”, each with:

  • which widget and which shop it ran for, and the website it ran on;
  • the product (SKU), area and tile count where relevant;
  • a random visit ID, made fresh each time the widget opens and never stored on the device.

A visit ID cannot be linked to a person across visits. Basket clicks go to the shop’s own basket; we do not see what is ordered or who orders it.

4. Room photos

When you upload a photo to the room visualiser:

  • your browser redraws it before sending it, which removes the photo’s metadata, including any location it was taken at;
  • our servers find the floor and walls in it, send back the result, and discard the photo;
  • the photo is not saved, not used to train models and not shared with anyone;
  • we log that a photo was processed (time, outcome, which shop), never the photo itself.

Please avoid photos that show people or private documents; we do not need them to find a floor.

5. Our website and free tools

trytily.com uses no analytics or advertising trackers and sets no cookies. The free planner and visualiser work like the shop widgets above. A plan you draw on /plan is kept in your own browser so it is there when you return; we do not receive it unless you share a link, and a shared plan travels in the link itself.

When you send us a message through a contact or feedback form, we keep your email address and message so we can reply. Our web server keeps standard access logs (IP address, page, time, browser) to keep the site secure and fix faults; they are rotated regularly.

The legal basis for these is our legitimate interest in running a secure website and answering the people who write to us.

6. Who else sees the data

We do not sell personal data or share it for advertising. It is handled only by:

  • the shop whose widget you used, which sees its own usage figures;
  • our hosting provider, which runs the servers and stores the database and backups;
  • Mailgun, on its EU infrastructure, which delivers our account emails (invitations, password resets, email changes);
  • authorities, where the law requires us to disclose it.

Where a provider processes data outside the UK, we rely on the safeguards UK law provides for that, such as adequacy regulations or the UK International Data Transfer Agreement.

7. How long we keep it

  • Shop accounts: while the account is open. When it is closed we delete its users, products, settings and usage events.
  • Widget events: 180 days in detail; after that only daily totals remain, with no visit IDs.
  • Sign-in sessions: deleted a week after they expire or are signed out.
  • Room photos: not kept at all.
  • Contact messages: as long as we need them to deal with what you asked; tell us and we will delete them.
  • Backups: 30 days, then overwritten.

8. Your rights

Under UK GDPR you can ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a portable form. Email hello@trytily.com; we reply within one month. If your request is about a shop’s website, we will pass it to the shop and help them answer it.

You can also complain to the Information Commissioner’s Office at ico.org.uk. We would appreciate the chance to put things right first.

9. Security

Everything travels over HTTPS. Passwords are hashed, feed credentials encrypted, sign-in sessions can be revoked, and repeated failed sign-ins lock an account for a while. Only the people who run Tily can reach the servers.

10. Changes to this policy

When we change how we handle data we update this page and the date at the top. If a change affects shop accounts materially, we tell account holders by email first.

Questions about this page: hello@trytily.com. See also our Privacy policy, Terms of service and Cookie policy.