1. Introduction
Replyk is a service of VERSAAS LLC. It is a B2B platform that lets businesses sell to and support their customers over WhatsApp, Messenger and Instagram with an AI Sales Agent, and manage their orders, catalog, shipping and analytics.
This policy explains what personal data we collect, why we use it, who we share it with and the choices you have. It covers our website, the web dashboard, the mobile app and our APIs.
When a business (our "Client") uses Replyk to talk to its own customers, the Client is the data controller and we process that data on its behalf as a processor. For data about our own users, such as account, billing and website data, we are the controller.
2. Data We Collect
Information You Provide
- Account details: name, email, phone number and password (stored only as a hash)
- Business profile information (business name, industry, address)
- Billing details. Payments are handled by Stripe or, for apps installed from the Shopify App Store, by Shopify. We never see full card numbers.
- Products, offers, and catalog data you create
- Customer and recipient details entered by you or your connected stores, including names, phone numbers, addresses, cities, and order details
- Support tickets and communications with us
- What you type into the chat on our website, such as your name, contact details and questions
Information Collected Automatically
- Device information (browser type, OS, device identifiers)
- Log data (IP address, access times, pages viewed)
- Sign-in security data: IP address, the approximate location derived from it, and the devices you mark as trusted
- Usage analytics (features used, session duration)
- Recordings of how pages and app screens are used. Passwords and other credentials are masked, and on the web every form field is masked.
- Push notification tokens for the mobile app
- Cookies and similar tracking technologies
Meta Platform Data
- Meta Business, WhatsApp Business Account, phone number, and configuration identifiers such as Business ID, WABA ID, Phone Number ID, App ID, and webhook status
- Messenger and Instagram Page and account identifiers, when you connect those channels
- OAuth tokens, access tokens, app secrets, webhook verify tokens, and related credentials, stored with appropriate encryption and access controls where applicable
- WhatsApp message IDs, sender and recipient phone numbers, delivery/read/failure status, timestamps, conversation windows, and other messaging metadata
- Template message content, categories, language, approval status, and usage information
- Click-to-WhatsApp referral data, ad attribution, Meta Conversion API event data, and similar analytics data when you enable those features
Data From Services You Connect
- Store platforms (Shopify, YouCan, WooCommerce): the products, orders and customer details needed to sync your store
- Google Sheets: your Google account email and the spreadsheets you choose to import orders from
- Shipping carriers: tracking numbers, delivery statuses and delivery notes
- Sign in with Google or Facebook: your name, email address and account identifier
Your customers' conversations
When Clients use Replyk to talk to their customers, we store message content, media, voice notes, conversation history and order details so the dashboard can show conversations, the Agent can reply, orders can be created and support can be routed. We do not sell this data or use it to profile people for anyone else. Clients must give their customers any legally required notice, collect opt-in and honor opt-out and deletion requests.
3. How We Use Your Data
We use collected information for the following purposes:
- Service Delivery: To provide, maintain and improve Replyk
- To connect your WhatsApp, Messenger and Instagram accounts and to send and receive messages
- AI Agent Automation: To power Sales Agent responses, order processing, follow-ups, and customer engagement features
- To provide dashboards, reports, and insights about your messaging performance
- Compliance Controls: To support message template rules, 24-hour conversation windows, opt-out handling, abuse prevention, and Meta/WhatsApp policy compliance
- Account Management: To process payments, manage subscriptions, and handle billing
- Customer Support: To respond to inquiries, troubleshoot issues, and provide assistance
- To send service updates, security alerts, and marketing (with consent)
- Legal Compliance: To comply with laws, regulations, and enforce our terms
- To detect, prevent, and address fraud, abuse, and security threats
4. Legal Bases for Processing
Where the GDPR or UK GDPR applies, we rely on these legal bases:
- To provide the service you signed up for, including your account, billing and support.
- Legitimate interests: To secure the service, prevent fraud and abuse, and improve our product. You can object at any time.
- For analytics and marketing cookies and marketing emails. You can withdraw it at any time.
- Legal obligation: To keep tax and accounting records and to answer lawful requests.
For data we process on behalf of a Client, the Client decides the legal basis.
5. How the AI Agent Uses Data
The AI Sales Agent reads the conversation, the Client's catalog and settings, and relevant order history to write replies, create or update orders, open support tickets, transcribe voice notes, describe images and, when enabled, reply with voice notes.
These tasks run on Google's Gemini models through Google Cloud Vertex AI and the Gemini API. Google processes the data to return a result and, under its terms for these paid services, does not use it to train its models. We also use TypeSafe to check some Agent replies and decisions, such as whether an address is complete, before they take effect.
If a Client turns on self-learning, the Agent keeps short notes from that Client's past conversations to improve its future replies for that Client. These notes are never shared with other Clients.
The Agent acts on the Client's instructions, and the Client can review and override what it does. If you are a customer of a Client, you can ask that business to have a person look at your case.
6. Data Sharing & Disclosure
We do not sell personal data. We share it only as described below.
Service Providers
| Provider | Purpose |
|---|---|
| Google Cloud | AI replies, voice and image processing, address lookup |
| DigitalOcean | Application hosting and database |
| Cloudflare | Network security, content delivery and file storage |
| Stripe | Subscription and wallet payments |
| Shopify | Billing for apps installed from the Shopify App Store |
| Brevo | Account and service emails |
| PostHog | Product analytics and session recordings |
| Expo | Mobile push notifications |
| TypeSafe | Checks on Agent replies and decisions |
| Meta | WhatsApp, Messenger and Instagram messaging, and measuring our own ads |
Integrations You Turn On
When you connect a store, a shipping carrier, a Google Sheet or conversion tracking for Meta, TikTok or Google, we send it the data that integration needs, such as order and delivery details or conversion events. You control these connections and can disconnect them at any time.
Meta Platforms
To run WhatsApp, Messenger and Instagram features we share business identifiers, phone numbers, templates, messages, message metadata and, when enabled, conversion events with Meta Platforms, Inc. and WhatsApp. This is governed by Meta's Platform Terms, the WhatsApp Business Terms and related policies. We process Meta Platform Data only for the purposes in this policy and, where we act for a Client, on that Client's instructions.
Legal Requirements
We may disclose information when required by law, subpoena, court order, or to protect our rights, property, safety, or that of others.
Business Transfers
In connection with a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
7. Google User Data
If you connect Google Sheets, we ask for access to the spreadsheets you choose, and your email address. We read orders from those sheets, and write to one only when you export orders to it. We cannot see any other file in your Google Drive. Signing in with Google gives us your name and email address.
We use this data only to import orders from the sheets you select and to show which Google account is connected. We do not use it for advertising, do not sell it, do not use it to train AI models, and do not let people read it except with your permission, for security, or where the law requires.
Replyk's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can remove access at any time by disconnecting Google Sheets in Replyk or from your Google Account settings.
9. Data Security
We protect your data with technical and organizational measures, including:
- HTTPS/TLS encryption for data in transit
- Encryption and strict access controls for sensitive credentials, provider tokens, and high-risk integration secrets
- Business/tenant isolation and role-based access controls
- Two-factor authentication, sign-in lockout and new-device alerts
- Automated security tests for authentication, tenant isolation and webhooks
- Access controls based on role and necessity
- Incident response procedures
Breach Notification
If a breach affects your personal data, we will notify you and the relevant authorities without undue delay, as the law requires.
Security Reports
To report a vulnerability or suspected misuse of Meta or WhatsApp data, email contact@replyk.io with enough detail for us to investigate.
10. International Data Transfers
Replyk is operated from the United States, and our providers may process data in other countries. For personal data from the EEA, the UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses, with the UK Addendum where needed, or another lawful transfer mechanism.
Any Client can request our Data Processing Agreement, which includes these clauses, at legal@replyk.io.
11. Data Retention
We retain data for the following periods:
| Data Type | Retention Period |
|---|---|
| Account information | Duration of account + 30 days |
| Meta/WhatsApp credentials | Duration of active integration + 30 days after disconnect |
| Billing/payment records | 7 years (legal requirement) |
| WhatsApp conversations and messages | Duration of Client account unless deleted earlier by the Client, recipient request, or applicable law |
| Orders and customer records | Duration of Client account + lawful tax, accounting, fraud, and dispute periods |
| Analytics data | 24 months |
| Support tickets | 3 years |
| Server logs | 90 days |
| Webhook event logs | 30 days |
Deletion Procedures
Upon account deletion or data erasure request, we will delete or anonymize your data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., fraud prevention, security, tax, accounting, chargeback defense, or dispute resolution). Backup copies may persist for a limited period until overwritten in the normal backup lifecycle.
12. Data Deletion Requests
This section is our public data deletion page, and the User Data Deletion URL we give Meta: https://replyk.io/privacy/#data-deletion
How to request deletion
- Email privacy@replyk.io with the subject "Data Deletion Request" and include the email address, phone number, business name or Meta/WhatsApp account ID linked to the data.
- Business customers can delete much of their data from the dashboard, or email contact@replyk.io to close the account and delete its data.
- If you messaged a business that uses Replyk, contact that business first. We will help it handle your request as its processor.
Meta/Facebook app removal requests
If you remove our Meta-connected app from your Facebook Apps and Websites settings and request deletion, Meta may send us a deletion request or make user identifiers available in the App Dashboard. We will promptly initiate deletion or anonymization of Platform Data associated with the request, unless we must retain limited data for legal, security, fraud-prevention, or dispute-resolution reasons.
When Meta sends us a deletion request, we reply with a confirmation code and a link back to this page, where the code is shown.
Expected response:
We confirm verified requests and complete them within 30 days. Complex requests can take longer where the law allows.
13. Your Rights in the EU, EEA and UK
If you are in the EU, the EEA or the UK, you have these rights:
- Right of Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your data (the "right to be forgotten")
- Right to Restrict Processing: Limit how we use your data
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing based on legitimate interests or for direct marketing
- Right to Withdraw Consent: Withdraw consent at any time for consent-based processing
- Right to Lodge a Complaint: File a complaint with your local data protection authority
Response Time:
We answer within one month, which the law lets us extend by two more months for complex requests. Email privacy@replyk.io to exercise any of these rights.
If your data reached us through a business you dealt with, send your request to that business. We will pass on any request we receive for it.
14. California Privacy Rights
California residents have the following rights under the CCPA/CPRA:
- Right to Know: What personal information we collect, use, disclose, and sell
- Right to Delete: Request deletion of your personal information
- Right to Correct: Correct inaccurate personal information
- Right to Opt-Out: Opt out of the sale/sharing of personal information
- Right to Non-Discrimination: Not be discriminated against for exercising your rights
- Right to Limit Use: Limit use of sensitive personal information
We do not sell personal information. The Meta Pixel on our own website may count as "sharing" for cross-context behavioral advertising. You can opt out by turning off marketing cookies in the Cookies section above.
Authorized Agents
You may use an authorized agent to make a request for you. We may ask for proof of the agent's authority and verify your identity.
Shine the Light
California Civil Code Section 1798.83 permits California residents to request information about disclosure of personal information to third parties for direct marketing. We do not share personal information with third parties for their direct marketing purposes.
15. Children's Privacy
Replyk is for businesses and is not directed to children. You must be at least 18 to create an account. We do not knowingly collect data from children under 13, or under 16 in the EEA. If you believe we have, email privacy@replyk.io and we will delete it.
16. Third-Party Links & Services
Third-party services we link to or integrate with have their own privacy policies, which we do not control. Your use of WhatsApp, Messenger and Instagram features is also subject to Meta's terms and policies:
17. Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors.
- Material changes will be notified via email and/or prominent notice on our platform
- We update the effective date at the top of this page
- Continued use after changes constitutes acceptance
18. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Privacy Team
- privacy@replyk.io
- General Support
- contact@replyk.io
- Legal Inquiries
- legal@replyk.io
- Security Reports
- contact@replyk.io
- Mailing Address
- VERSAAS LLC8206 Louisiana Blvd Ne, Ste A #7849, Albuquerque, New Mexico 87113, United States