Privacy Policy
This policy explains what data ReplyIQcollects, how we use it, who we share it with, how long we keep it, and the rights you have over it — including the inbox-email messages and conversation records generated through your use of the service. AI customer service for multi-channel e-commerce brands.
1. Data we collect
To operate the service, ReplyIQcollects the data needed to authenticate you, connect the storefronts and channels you choose, process your customers' requests, and bill you. This includes the email address and identity record used for sign-in, the authentication session that links a browser to your account, the tokens you grant when you connect a merchant storefront or an inbox channel, the message bodies and metadata of every inbox email and live-chat conversation that flows through the service, the prompt-and-response traffic exchanged with the AI model that drafts and scores replies, and the billing identifiers returned by our payment processor for each charge and refund. We never store full payment-card numbers; only tokenised references returned by the processor.
We also collect aggregated, de-identified usage telemetry (counts of tickets handled, escalation rates, response-latency distributions) so we can spot regressions and size capacity, and we record any content you paste into the dashboard or import through the merchant-policy flow, because that content is exactly what the service operates on. You remain the controller of all customer data you bring into the service through your connected stores and channels.
2. How we use it
The data described above is used to operate the service: to draft, score, and route replies; to escalate conversations to a human reviewer when configured rules fire; to render your dashboard; to authenticate your sessions; to prevent abuse and to keep the service secure; to charge and refund you per the billing terms; and to communicate with you about billing, security incidents, material changes to the service, and the policies on this page. Aggregated telemetry is used to improve the product; we do not attribute aggregated analytics to a single merchant's identifiable customer correspondence for AI-improvement purposes without a separate legal basis.
AI-in / AI-out traffic flows through the Polsia-managed AI proxy. The proxy forwards requests to model providers and returns their responses to the running service; we never see a provider API key, and we do see the request and response bodies that the service exchanges on your behalf. Provider-side logging is governed by the proxy's terms and by whatever caching and retention policies are documented in section 4 below.
3. Third-party processors
To deliver the service ReplyIQ relies on a small set of named processors, each of which receives only the data it needs to perform its function and is bound by its own privacy commitments: better-auth for sign-in and session authentication; Stripe (via the installed billing module) for payment processing, receipts, and tax handling; the Polsia-managed AI proxy for LLM traffic; IMAP / Gmailfor the inbox-email channel you connect; and the application's own Postgres-backed store for contact-form submissions (no third-party CRM is involved).
We do not sell your data, we do not share it with advertising networks, and we do not allow third-party processors to use it for their own purposes. A current list of processors, with the data each one handles and the region in which it processes that data, is available on request.
4. Retention
We retain the data we collect for as long as you maintain an account, and for thirty days after account deletion to allow recovery. Within that window: conversation bodies and message records are kept for the life of the account; tokenised store and inbox-channel credentials are deleted from our stores within twenty-four hours of you disconnecting the integration; access and security audit logs are kept for twelve months; AI prompt-and-response logs are kept for ninety days; and aggregated, de-identified usage telemetry is kept indefinitely so we can model long-running performance trends.
Where a processor holds data on our behalf — for example, AI model providers that cache prompts to enforce abuse-detection rules — their own retention windows apply and we surface them on request. If a legal hold or regulatory obligation requires longer retention of a specific record, we will retain that record for the required window and notify you where permitted.
5. Your rights
You have the right to accessthe personal data we hold about you and to export a copy — including the inbox-email messages and live-chat transcripts linked to your account, available from the dashboard; to correct the merchant policies and configuration that drive the AI replies you send; to delete specific inbox messages and conversations, to disconnect a channel (which triggers cascade deletion of its cached credentials within the window in section 4), and to close your account outright, with erasure cascading to AI caches within the same windows; and to object to processing carried out for AI-improvement analytics.
You also have the right to lodge a complaint with the data-protection authority in your jurisdiction if you believe we have not handled your data lawfully. If you are unsure which authority applies, contact us and we will help you identify the right one.
6. Contact
Privacy questions, requests to exercise the rights in section 5, data-protection complaints, and notices of intended processing change should be sent to replyiq-lxwy1t@polsia.app. We will acknowledge within two business days and resolve account, access, and data-handling matters within ten business days.
Material changes to this policy will be announced by email to the address on your account at least thirty days before they take effect. Continued use of the service after that date constitutes acceptance of the updated policy. The current version of this policy is always available at this page.
Last updated: 2026-07-24. Reference URL: https://replyiq-lxwy1t.polsia.app/legal/privacy