Privacy Policy
Effective Date: March 28, 2026
1. Introduction
ReplyWise AI ("we," "us," or "our") operates the website www.replywiseai.com and related services (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. By accessing or using the Service, you agree to the terms of this Privacy Policy.
2. Information We Collect
2.1 Information You Provide
- Account information: name, email address, and password (via Supabase authentication with Google OAuth or magic link).
- Business information: business name, Google Business Profile data, store locations, and branding preferences.
- Payment information: billing details processed securely through Stripe. We do not store your full credit card number on our servers.
- Support communications: any messages or files you send to our support team.
2.2 Information Collected Automatically
- Usage data: pages visited, features used, timestamps, and interaction patterns.
- Device and browser information: IP address, browser type, operating system, and device identifiers.
- Cookies and similar technologies: see Section 6 below.
2.3 Information from Third Parties
- Google Business Profile: review data, ratings, and business details accessed through your authorized Google account.
- Authentication providers: profile information from Google OAuth when you sign in.
3. How We Use Your Information
We use your information to:
- Provide, maintain, and improve the Service, including AI-powered review generation using OpenAI GPT-4o-mini.
- Process transactions and manage your subscription through Stripe.
- Send transactional emails (account verification, billing receipts, review notifications).
- Analyze usage trends to improve our product and user experience.
- Detect and prevent fraud, abuse, or security incidents.
- Comply with legal obligations.
4. AI-Powered Data Processing
Our Service uses OpenAI's GPT-4o-mini model to generate review drafts and reply suggestions. When you use these features, relevant context (such as business name, selected tags, and review content) is sent to OpenAI's API for processing. We do not send your personal account credentials to OpenAI. OpenAI's data processing is subject to their own privacy policy and data usage terms.
5. How We Share Your Information
We do not sell your personal information. We may share data with:
- Service providers: Supabase (database and authentication), Stripe (payments), OpenAI (AI processing), Vercel (hosting), and Google Analytics (if enabled) -- each under agreements to protect your data.
- Legal requirements: when required by law, court order, or governmental authority.
- Business transfers: in the event of a merger, acquisition, or sale of assets, your data may be transferred as part of the transaction.
- With your consent: in any other circumstance where you have given explicit permission.
7. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. If you delete your account, we will remove your personal data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., fraud prevention, legal compliance). Aggregated, anonymized data may be retained indefinitely for analytics purposes.
8. Data Security
We implement industry-standard security measures including encryption in transit (TLS), encryption at rest, row-level security (RLS) in our database, and role-based access controls. However, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your data.
9. Your Rights
9.1 General Rights
Depending on your jurisdiction, you may have the right to:
- Access, correct, or delete your personal information.
- Object to or restrict the processing of your data.
- Data portability -- receive your data in a structured, machine-readable format.
- Withdraw consent at any time where processing is based on consent.
9.2 GDPR (European Economic Area)
If you are located in the EEA, you have additional rights under the General Data Protection Regulation (GDPR), including the right to lodge a complaint with your local data protection authority. Our legal basis for processing personal data includes contract performance, legitimate interests, and consent.
9.3 CCPA (California)
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with specific rights regarding your personal information, including the right to know what data we collect, the right to delete your data, and the right to opt out of the sale of personal information. We do not sell personal information.
9.4 PIPEDA (Canada)
If you are a Canadian resident, you have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA), including the right to access and correct your personal information.
10. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States and Canada, where our service providers operate. We ensure appropriate safeguards are in place for such transfers in compliance with applicable data protection laws.
11. Children's Privacy
Our Service is not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 16, we will delete it promptly.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the revised policy on our website and updating the "Effective Date" above. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.
13. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:
ReplyWise AI
Email: hello@replywiseai.com
Website: www.replywiseai.com