Privacy Policy
This Privacy Policy explains how AFS Digital LLC (2335 E Atlantic Blvd, Ste 200, Pompano Beach, FL 33062, USA) handles personal data when you visit replyon.app, create a Replyon account or use the Service, and how we process the data of your store's customers on your behalf.
We follow the EU and UK General Data Protection Regulation (GDPR), Brazil's LGPD, and applicable US state privacy laws such as the CCPA/CPRA.
1. Who is responsible for your data
- Account and website data (you, your team, billing, website visitors): AFS Digital LLC is the controller.
- Customer Data (your store's customers, their emails, orders and requests): your business is the controller and AFS Digital LLC is the processor, acting only on your instructions. Section 9 contains our data processing terms.
2. Data we collect
- Account: name, email, password (stored as a secure hash), language, team role, store names and settings.
- Integrations: Shopify domain and access credentials, mailbox address and access credentials (encrypted at rest with AES-256).
- Billing: plan, subscription status and invoices. Card details are collected directly by Stripe; we never see or store full card numbers.
- Customer Data processed for you: support emails (sender, subject, body), order and tracking data, request form answers, IP address of form submissions and generated PDF receipts.
- Usage and technical data: log records, IP address, browser type, error reports and AI usage counters, used for security and to operate the Service.
- Contact and feedback: what you send us through the contact form, email or the bug/suggestion tab.
3. How we use data and legal bases
- To provide the Service you signed up for — performance of a contract.
- To bill your subscription and meet tax and accounting duties — contract and legal obligation.
- To keep the Service secure, prevent fraud and abuse, and fix errors — legitimate interest.
- To send service messages (security, billing, changes to terms) — contract and legitimate interest.
- To answer your contact requests — legitimate interest or pre-contractual steps.
We do not sell personal data, we do not share it for cross-context behavioral advertising, and we do not use Customer Data to train AI models.
4. Artificial intelligence
To answer emails, the content of the relevant message and the necessary order data are sent to our AI providers. They process it only to return the result, under agreements that forbid using it to train their models, and keep it only for the short period needed for abuse monitoring.
High-risk cases (for example, chargeback threats) are routed to a human on your team. You can keep every reply in draft mode so a person approves it before sending.
6. International transfers
Some providers are located outside your country, including in the United States. When data from the EU, UK or Brazil is transferred, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK Addendum, the EU-US Data Privacy Framework where applicable, and the contractual clauses accepted under the LGPD.
7. How long we keep data
- Account and Customer Data: while your account is active. After cancellation, deleted or anonymized within 30 days.
- Backups: overwritten within 30 days.
- Billing records: kept for as long as tax law requires (usually 5 to 7 years).
- Security logs: up to 12 months.
When a store uninstalls the Replyon app, our access is removed immediately and, when Shopify requests it (48 hours later), we erase the order data imported from that store. We also honor Shopify's customer redaction requests.
8. Security
- Encryption in transit (HTTPS/TLS) and encryption at rest for passwords and access credentials.
- Each account only sees its own data; access checks are enforced on every request.
- Restricted internal access, signed sessions and rate limits against abuse.
If a personal data breach affects you, we will notify you without undue delay and, where required, within 72 hours.
9. Data processing terms (for store owners)
When we process Customer Data for you, we commit to:
- Process it only to provide the Service and on your documented instructions.
- Keep it confidential and limit access to authorized personnel.
- Use only the subprocessors listed above and notify you of changes, giving you the chance to object.
- Help you answer your customers' requests to access, correct, delete or export their data.
- Notify you of breaches and help you meet your legal duties.
- Delete or return Customer Data when the contract ends.
If your customer contacts us directly, we will forward the request to you.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to the processing of your data, to data portability, to withdraw consent and to not be discriminated against for exercising these rights.
To exercise them, write to support@replyon.app with the subject "Privacy". We answer within 30 days (15 days under the LGPD). You also have the right to complain to your data protection authority.
12. Children
The Service is for businesses and is not directed to anyone under 18. We do not knowingly collect data from children.
13. Changes and contact
We may update this policy. Material changes will be notified by email or in the dashboard. If translated versions differ, the English version prevails.
Questions: support@replyon.app · Contact form · AFS Digital LLC, 2335 E Atlantic Blvd, Ste 200, Pompano Beach, FL 33062, USA.