Privacy Policy
For the Ballast agent · Last updated 30 July 2026
This policy explains how the Ballast agent (“Ballast”, “we”, “us”) handles data. Ballast is a Microsoft 365 Copilot agent published by TALONOID Technologies Private Limited that reports a connected Shopify store's revenue and settlement. This policy is separate from our Terms of Use.
1. Who we are
TALONOID Technologies Private Limited is the data controller for the processing described here. Contact: support@talonoid.com.
2. Data Ballast accesses
Ballast works from a Shopify order export that you upload (the native Orders CSV export from your Shopify admin). It reads the order, payment-method, refund, and tax figures in that file to produce your reports. Ballast has no connection to your Shopify store — it cannot read, write to, change, or access it, and it holds no store credentials.
3. Customer personal data
Ballast is designed to report financial aggregates — amounts by gateway, currency, tax, and refunds. Ballast does not store customer personal data such as customer names, email addresses, shipping addresses, or payment card details. If your uploaded file contains customer-identifying columns, Ballast ignores them and does not persist them.
4. What we do store
| Data | Purpose | Retention |
|---|---|---|
| Your uploaded order export, reduced to financial figures (order ids, gateways, currencies, amounts, dates, line titles/SKUs, destination country — no customer PII) | To produce the reports you ask for | Until you replace it with a new upload, remove it, or cancel your subscription |
| Computed financial summaries and cached report figures (no customer PII) | To answer your questions within the response-time limits Microsoft requires | Refreshed on each upload; deleted when you remove the data |
| Subscription and entitlement records (subscription ID, plan, tenant ID, status) received from the Microsoft commercial marketplace | To confirm you have an active subscription | For the life of the subscription plus as required for billing records |
5. Billing data
Your subscription to Ballast is sold and billed by Microsoft through the commercial marketplace. We receive subscription lifecycle information (such as subscription identifier, plan, and status) from Microsoft. We never receive or store your payment card or bank details — those are handled entirely by Microsoft under Microsoft's terms.
6. How we use data
We use the data solely to operate Ballast: to read your store's records, compute the figures you ask for, generate Excel exports you request, and manage your subscription. We do not sell your data, use it for advertising, or use it to train machine-learning models.
7. Processing within Microsoft 365
Ballast runs as a Copilot agent. Your prompts and Ballast's responses are processed within your Microsoft 365 environment under Microsoft's terms. Ballast's own service receives only the requests needed to return the figures you ask for.
8. Sub-processors and hosting
Ballast's service is operated by TALONOID Technologies on infrastructure it controls, accessed only over encrypted (TLS) connections. We use the Microsoft commercial marketplace (for billing and identity). Ballast has no connection to Shopify — it only processes the export file you upload. We do not share your data with other third parties except as required by law.
9. Your choices and rights
You can remove your uploaded data at any time, or replace it with a new upload. Cancelling your subscription through Microsoft ends processing. To request deletion of remaining records, contact support@talonoid.com.
10. Security
Connection credentials are encrypted at rest, all traffic is served over TLS, and access to production systems is restricted. Because Ballast stores no customer personal data, the impact of any incident is limited to non-personal financial aggregates and store connection metadata.
11. Changes to this policy
We will update this page when our practices change and revise the “last updated” date above.
12. Contact
Questions about privacy: support@talonoid.com.