Privacy Policy
Effective date: August 22, 2026
Tapestry is a managed AI operations platform operated by Schubring Global Solutions, LLC, doing business as Tapestry ("Tapestry," "we," "our," or "us").
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you:
- Visit our website at tapestryops.com or another website that links to this policy;
- Request a working session, security review, integration, or other information;
- Communicate with us;
- Create or use a Tapestry account; or
- Use a Tapestry service when this policy applies.
A customer agreement, order form, data processing agreement, or other written contract may govern how we process information for a Tapestry customer. If that agreement conflicts with this Privacy Policy, the customer agreement controls for the covered service.
1. Our role
When we collect information through our website, manage accounts, operate our business, or communicate directly with you, Tapestry generally determines why and how that information is processed.
When Tapestry processes information on behalf of a customer through a configured AI operation, the customer generally determines the purpose of that processing. In that context, Tapestry acts as a service provider or processor under the applicable customer agreement.
If your information was provided to Tapestry by your employer, customer, or another organization, direct questions or rights requests to that organization first. We will assist the organization as required by contract and applicable law.
2. Information we collect
The information we collect depends on how you interact with Tapestry.
Information you provide
We may collect:
- Your name;
- Company or organization;
- Job title and business role;
- Work email address and telephone number;
- Account and profile information;
- Communications with us;
- Support requests;
- Feedback;
- Information submitted when requesting a working session, integration, or security review;
- Descriptions of workflows, systems, operational requirements, or business problems; and
- Other information you choose to provide.
Please do not submit passwords, authentication credentials, payment-card information, government identifiers, health information, or other sensitive personal information through a marketing-site form.
Customer and service information
When an organization uses Tapestry, we may process information such as:
- Company documents, policies, contracts, spreadsheets, and other customer-provided content;
- Information received from systems connected at the customer's direction;
- Workflow configurations;
- AI specialist roles and permissions;
- Work products;
- Evidence and citations;
- Approval decisions;
- Operating-history records;
- Support information; and
- Account, membership, and access-control records.
We refer to information submitted to or processed through a customer's configured Tapestry environment as "Customer Content."
Technical and usage information
We may automatically collect:
- IP address;
- Browser type;
- Device and operating-system information;
- Referring page;
- Pages viewed;
- Date and time of access;
- Approximate location derived from IP address;
- Session, diagnostic, and performance data;
- Security events;
- Login and authentication activity; and
- Interactions with website or service features.
Cookies and similar technologies
We may use cookies and similar technologies that are necessary to operate and secure the website and service.
We may also use limited analytics technologies to understand aggregate website usage and improve the visitor experience.
Where required, we will request consent before using nonessential cookies. You may also be able to control cookies through your browser settings.
3. How we use information
We may use personal information to:
- Provide, operate, secure, and maintain Tapestry;
- Respond to inquiries and working-session requests;
- Communicate about an evaluation, engagement, or customer relationship;
- Configure and support customer operations;
- Authenticate users and enforce permissions;
- Process workflows and create requested work products;
- Provide evidence, review, approval, and operating-history capabilities;
- Diagnose errors and improve reliability;
- Detect, investigate, and prevent fraud, abuse, unauthorized access, and security incidents;
- Analyze aggregate website and service usage;
- Improve our products, services, documentation, and customer experience;
- Comply with legal and contractual obligations;
- Establish, exercise, or defend legal claims; and
- Send business communications where permitted.
We may use de-identified or aggregated information for legitimate business purposes when that information cannot reasonably identify an individual.
4. AI and automated processing
Tapestry uses artificial intelligence models to support configured business operations. Depending on the operation, AI may help analyze information, prepare work products, identify exceptions, retrieve relevant knowledge, or recommend actions.
Customer Content may be transmitted to an approved model provider when necessary to perform an operation requested or configured by the customer. Model-provider access is controlled through Tapestry's managed service gateway and is subject to applicable provider terms, security controls, and customer agreements.
Tapestry does not use Customer Content to train a general-purpose AI model for Tapestry's independent benefit.
AI-generated work can contain errors. Tapestry is designed to support evidence, acceptance checks, defined responsibilities, and human approval. Customers remain responsible for reviewing consequential decisions as described in their agreement and configured approval rules.
The public marketing website does not use submitted inquiry information to make decisions that produce legal or similarly significant effects about an individual.
5. How we disclose information
We may disclose information to:
Service providers
We use providers that help us operate infrastructure, authentication, communications, analytics, support, security, document processing, integrations, and AI model access.
These providers may process information only for the services they provide to us and subject to applicable contractual restrictions.
Customer-authorized integrations
When a customer connects a third-party system, Tapestry may exchange information with that system as directed by the customer and within the configured permissions.
The third party's own terms and privacy policy govern its independent handling of information.
Your organization
If you use Tapestry through an employer or another organization, authorized administrators and users of that organization may access account information, Customer Content, work products, approvals, and operating records according to their roles.
Professional advisers
We may disclose information to attorneys, auditors, insurers, accountants, and other professional advisers when reasonably necessary.
Legal and safety purposes
We may disclose information when we reasonably believe disclosure is necessary to:
- Comply with law, regulation, legal process, or governmental request;
- Protect the rights, safety, or property of Tapestry, our customers, users, or others;
- Investigate fraud, abuse, security events, or violations of an agreement; or
- Establish, exercise, or defend legal claims.
Business transactions
Information may be disclosed as part of a merger, acquisition, financing, reorganization, sale of assets, or similar transaction. We will require the recipient to handle personal information consistently with applicable law.
6. Sale, targeted advertising, and profiling
Tapestry does not sell personal information for money.
Tapestry does not share personal information for cross-context behavioral advertising or use personal information for targeted advertising based on activity across unrelated businesses.
Tapestry does not profile marketing-site visitors to make decisions that produce legal or similarly significant effects.
If our practices change, we will update this policy and provide any legally required choices before applying the change.
7. Data retention
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including to provide services, maintain security, meet legal obligations, resolve disputes, and enforce agreements.
Unless a different period is required by contract or law:
- Marketing inquiries and working-session requests may be retained for up to 24 months after the last substantive interaction;
- Account information is retained while the account remains active and for a reasonable period afterward;
- Customer Content is retained according to the applicable customer agreement and configured retention settings;
- Security, diagnostic, and operating-history records are retained according to documented security and operational requirements; and
- Information subject to a legal hold may be retained until the hold is released.
Deletion from active systems may not immediately remove information from encrypted backups. Backup copies are isolated, protected, and removed according to established backup-retention schedules.
8. Data security
Tapestry uses administrative, technical, and physical safeguards designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure.
These safeguards may include:
- Tenant-scoped access controls;
- Role-based permissions;
- Encryption in transit and at rest;
- Protected credential storage;
- Authentication controls;
- Activity and security logging;
- Approval requirements;
- Infrastructure monitoring;
- Vulnerability management; and
- Incident-response procedures.
No method of transmission or storage is completely secure. We cannot guarantee absolute security.
If you believe information has been accessed or used improperly, contact us promptly at hello@tapestryops.com with the subject line "Security."
9. Your choices and privacy rights
Depending on where you live and whether the relevant law applies, you may have the right to:
- Know whether we process your personal information;
- Access personal information we maintain about you;
- Correct inaccurate personal information;
- Delete personal information;
- Obtain a portable copy of certain information;
- Restrict or object to certain processing;
- Withdraw consent where processing relies on consent;
- Opt out of sale, targeted advertising, or qualifying profiling;
- Appeal a decision concerning a privacy request; and
- Lodge a complaint with an applicable regulator.
Tapestry does not discriminate against individuals for exercising applicable privacy rights.
To submit a request, email hello@tapestryops.com with the subject line "Privacy Request."
Describe your request and the relationship through which Tapestry may have received your information. We may need to verify your identity and authority before completing the request.
If we deny a request, you may appeal by replying to our response with the subject line "Privacy Appeal."
An authorized agent may submit a request where permitted by law. We may require evidence of the agent's authority and may verify the request directly with the individual.
If Tapestry processes your information solely on behalf of a customer, we may direct the request to that customer.
10. European Economic Area, United Kingdom, and Switzerland
Where applicable, our legal basis for processing personal information may include:
- Performance of a contract;
- Steps requested before entering a contract;
- Our legitimate interests in operating, securing, and improving Tapestry;
- Compliance with legal obligations; and
- Consent, where required.
Our legitimate interests include responding to business inquiries, maintaining service security, improving reliability, preventing misuse, and administering customer relationships.
Information may be processed in the United States and other countries where Tapestry or its service providers operate. Where required, we use legally recognized transfer safeguards, such as approved standard contractual clauses.
You may contact the relevant data-protection authority in your country if you believe your rights have been violated.
11. Children
Tapestry is a business service and is not directed to children under 18.
We do not knowingly collect personal information from children through the marketing website. If you believe a child has submitted personal information, contact us so we can review and delete it where appropriate.
12. Third-party websites and services
Our website and service may contain links to or integrations with third-party services.
Tapestry does not control those services and is not responsible for their independent privacy practices. Review the third party's privacy policy before providing information or authorizing a connection.
13. Changes to this policy
We may update this Privacy Policy to reflect changes in our services, practices, or legal obligations.
We will post the updated policy and revise the effective date. If a change materially affects how we use previously collected personal information, we will provide additional notice where required.
14. Contact us
For privacy questions or requests, contact:
Schubring Global Solutions, LLC, doing business as Tapestry
Email: hello@tapestryops.com
For requests involving a customer-managed Tapestry account, include the name of the relevant organization.