Information We Collect
Account & profile data
When you sign up, we collect your name, email address, and organization details. If you connect a messaging channel, we store the credentials and webhook tokens necessary to receive and send messages on your behalf.
Customer conversation data
Repnow.io processes the messages sent to and from your customers across connected channels (WhatsApp, Telegram, Messenger, Instagram, email). This data is stored in your workspace and scoped exclusively to your organization.
Usage and analytics data
We collect product usage data (feature interactions, page views, error logs) to improve the service. This data is aggregated and does not include the content of customer conversations.
AI processing data
When AI auto-reply is enabled, conversation messages are sent to our AI provider (Google AI) to generate responses. No data is used to train third-party models. Refer to Google's data processing terms for details on their handling.
Minimum Age
Repnow.io is not directed at children. You must be at least 18 years old to use this Service. By registering, you represent that you meet this requirement. If we become aware that a user is under 18, we will delete their account and associated data promptly.
How We Use Your Data
Service delivery
We use your data solely to provide, maintain, and improve Repnow.io. This includes routing messages, running AI automation, generating reports, and managing team access.
Communications
We may send you transactional emails (password resets, invitation links) and, with your consent, product updates. You can opt out of marketing emails at any time.
Security and fraud prevention
We analyze access patterns to detect unauthorized access, abuse, or violations of our Terms of Service.
Legal Basis for Processing
Contract performance
We process account and service data as necessary to perform the contract between you and Repnow.io — including routing messages, running AI automation, and managing team access.
Consent
We process data for marketing communications and optional analytics only with your explicit consent. You may withdraw consent at any time without affecting the lawfulness of prior processing.
Legitimate interests
We process usage and security data based on our legitimate interest in operating, securing, and improving the Service, where these interests are not overridden by your rights.
Legal compliance
We may process or disclose data where required to comply with applicable laws, court orders, or regulatory obligations.
Data Storage & Security
Infrastructure
All data is stored on Supabase (PostgreSQL) with row-level security (RLS) enforced at the database layer. Each organization's data is fully isolated — no cross-tenant access is possible by design.
Encryption
Data is encrypted at rest (AES-256) and in transit (TLS 1.2+). API keys and channel credentials are stored encrypted.
Access controls
Internal access to customer data is limited to authorized personnel for support and maintenance purposes only, and is logged.
Data Sharing
Third-party sub-processors
We share data with a limited set of sub-processors required to operate the service: Supabase (database), Google AI (AI inference), and messaging platform APIs (Meta, Telegram). We do not sell your data to any third party.
Legal requirements
We may disclose data if required by law, subpoena, or court order, or to protect the rights, property, or safety of Repnow.io, our users, or the public.
Your Rights
Access and portability
You can export your conversation data and contact records from your workspace settings at any time.
Deletion
You may delete your account and all associated data at any time. Deletion is permanent and irreversible. Some data may be retained for up to 30 days in backups before being purged.
Correction
You can update your account information directly from your profile settings. Contact us at privacy@repnow.io for corrections we need to make on your behalf.
Restriction and objection
You have the right to restrict or object to certain processing of your personal data, including processing based on legitimate interests or for direct marketing purposes.
Withdraw consent
Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Lodge a complaint
If you believe we have not handled your personal data in accordance with applicable law, you have the right to lodge a complaint with your local data protection supervisory authority.
Cookies
Session cookies
We use cookies to maintain your authenticated session. No third-party advertising cookies are used.
Analytics
We may use privacy-respecting analytics tools to understand aggregate usage patterns. These do not track individuals across sites.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you by email and/or by posting a notice in the product at least 14 days before significant changes take effect. Continued use of the service after the effective date constitutes acceptance.
Contact Us
Questions about this policy? Reach us at privacy@repnow.io.
Have privacy questions?
Our data protection team responds within 48 hours.