Replyva · Version 2026-10-02 · Effective October 2, 2026
Privacy Policy
How Replyva collects, uses, and protects information across the Replyva Platform.
1. Introduction
Replyva ("we," "us") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use the Replyva Platform ("Service").
"Service" has the same meaning as in our Vendor Terms of Service, including all current and future Replyva websites, apps, APIs, portals, and related products.
This Policy applies to vendor account holders and their authorized users. Your clients interact with client portals and forms you control; you are responsible for providing them appropriate privacy notices for their relationship with you.
Effective date: October 2, 2026.
2. Information We Collect
Account & profile: name, business name, email, phone, website, timezone, billing details, plan selections, and authentication identifiers from our identity provider.
Vendor Content: client records, contracts, proposals, galleries, messages, files, and other data you upload or generate in the Service.
Usage & device: log data, IP address, browser type, pages viewed, feature usage, crash reports, and security signals.
Payment: subscription billing is processed by third parties (e.g., Stripe, Square). We receive transaction metadata, not full card numbers stored by us.
Communications: support tickets, feedback, and email correspondence.
3. How We Use Information
We use information to provide, maintain, and improve the Service; authenticate users; process subscriptions; send transactional messages; detect fraud and abuse; comply with law; and analyze aggregated usage.
We may use de-identified or aggregated data for analytics, benchmarking, and product development.
We do not sell your personal information for money. Under some US state laws, certain advertising or analytics cookie sharing may be treated as a "sale" or "sharing." You can opt out at /privacy/do-not-sell and we honor Global Privacy Control (GPC) signals where required.
We do not use Vendor Content to train public third-party AI models except as disclosed in-product when you enable AI features. AI-assisted features may produce incomplete or incorrect outputs — review before relying on them. You may request human review via /privacy/request or privacy@replyva.com.
4. New Products & Features
When we launch new Replyva apps, modules, or integrations, we may collect additional categories of information disclosed in-product. This Policy applies to those products unless a separate privacy notice expressly supersedes it.
Beta and experimental features may log additional diagnostic data. Beta, preview, experimental, and early-access features are provided AS IS, may change or be withdrawn without notice, and are excluded from any SLA or uptime commitment.
6. Client Data & Your Responsibilities
When you store client personal information in the Service, you determine the purposes and means of processing. Replyva processes that data on your behalf to provide the Service.
You must obtain lawful bases and consents, honor data-subject requests for client data you control, and maintain your own privacy policy for your business.
Portal links, public forms, and share URLs you generate may expose data to anyone with the link if you configure them that way. You are responsible for link distribution and access controls.
7. Data Retention & Deletion
We retain information while your account is active and as needed to provide the Service, comply with law, resolve disputes, and enforce agreements.
Upon account closure, we may delete or anonymize data within a reasonable period. Residual copies may persist in backups for a limited time before rotation.
YOU ARE RESPONSIBLE FOR EXPORTING DATA YOU WISH TO KEEP BEFORE CLOSING YOUR ACCOUNT. WE ARE NOT LIABLE FOR DATA LOST AFTER TERMINATION OR DUE TO BACKUP EXPIRATION.
8. Security
We implement administrative, technical, and organizational measures designed to protect information, including encryption in transit, access controls, and optional field-level encryption for certain sensitive data.
NO METHOD OF TRANSMISSION OR STORAGE IS 100% SECURE. WE CANNOT GUARANTEE ABSOLUTE SECURITY OR PREVENT UNAUTHORIZED ACCESS, LOSS, OR ALTERATION.
9. Your Rights & Choices
Depending on your location (including EU/UK GDPR, California CCPA/CPRA and other US state privacy laws, Canada PIPEDA, Australia Privacy Act, India DPDP, Brazil LGPD, Japan APPI, South Africa POPIA, and China PIPL where applicable), you may have rights to access, correct, delete, or port personal information, opt out of sale/sharing, or object to or restrict certain processing.
Submit a request at /privacy/request or email privacy@replyva.com. We may verify your identity before responding. SLA timing depends on your jurisdiction (commonly 15–45 days). If we process client data on your behalf as a vendor customer, direct client requests to you as the controller; we will assist with reasonable vendor tooling.
You may update account information in dashboard settings. Marketing emails include unsubscribe options where applicable. Cookie and sale/share preferences: /privacy/preferences and /privacy/do-not-sell.
9A. Biometric & Location Data
Some features (guest face matching, crew clock selfie / GPS geofence) collect biometric identifiers or precise location. Those features require affirmative consent where required by law, and data is limited to the stated purpose (gallery matching or timekeeping verification).
Vendors configuring face recognition must enable consent collection for end users. Defaults require consent before biometric processing.
9B. Automated Decision-Making & AI
Replyva may use automated or AI-assisted tools for drafting, matching, recommendations, and similar assistance. These tools do not make solely automated decisions with legal or similarly significant effects without human involvement available on request.
Australia Privacy Act ADM transparency obligations (from December 2026 where applicable) and EU AI Act transparency expectations are addressed through in-product notices and this Policy. Contact privacy@replyva.com for human review.
10. International Transfers
We primarily operate infrastructure in the United States. If you access the Service from other regions, your information may be transferred to and processed in the U.S. and other countries with different data-protection laws.
Where required (including GDPR, UK GDPR, LGPD, DPDP, and PIPL), we use appropriate safeguards for cross-border transfers and provide transfer notices. China PIPL may impose localization or security-assessment requirements; Replyva does not currently offer a dedicated mainland China data residency region — processing for CN users includes an explicit transfer caution, and high-risk localization claims are not made until infra exists.
11. Children
The Service is not directed to children. Age floors vary by jurisdiction (commonly 13–18). Public forms may ask you to attest you meet the applicable age floor. We do not knowingly collect personal information from children below the applicable age. Contact us if you believe we have collected such information.
12. Changes
We may update this Policy. We will post the revised version with a new effective date and provide additional notice for material changes when appropriate.
13. Contact
Privacy inquiries: privacy@replyva.com
Legal inquiries: legal@replyva.com
This document is provided for operational clarity and does not constitute legal advice. Consult qualified counsel for your jurisdiction and business model.