Customer Privacy Policy

Last updated: March 2025

This Customer Privacy Policy explains how your personal information is collected, used, and protected when you use a business's public storefront hosted on the Replypop platform. This policy applies to end-customers who create accounts, book services, or make payments through a Replypop-powered storefront. For information about how Replypop handles data for business users, please see our main Privacy Policy.

1. Information We Collect

1.1 Account Information

When you create a storefront account, we collect:

  • Name and email address
  • Phone number (if provided)
  • Profile picture (if signing in with a social provider)
  • Date of birth (if provided by the business's form)

1.2 Authentication

You may create an account or sign in using:

  • Email with one-time password (OTP) verification
  • Google Sign-In
  • Apple Sign-In
  • Facebook Sign-In

We only access basic profile information (name, email, profile picture) from social sign-in providers.

1.3 Booking and Transaction Data

When you book services or make payments, we collect:

  • Booking details (service, date, time, location)
  • Payment transaction records
  • Payment proof images (if you upload them for manual payment verification)
  • Service package purchases and usage history

1.4 Communication Data

When you communicate with a business through our platform, we process:

  • Message content and conversation history
  • Images you send (which may be analyzed by AI — see Section 3)
  • Your preferred language

1.5 Location Data

If you provide your address or the business collects it:

  • Postal address
  • Location coordinates (for location-based services)

2. How Your Data Is Used

Your personal information is used to:

  • Create and manage your storefront account
  • Process your bookings and payments
  • Enable businesses to communicate with you via messaging platforms
  • Send booking confirmations, reminders, and notifications
  • Improve the storefront experience
  • Detect and prevent fraud

3. AI Processing of Your Data

When you communicate with a business through our platform, your messages may be processed by AI to provide automated responses. This includes:

  • Text messages are analyzed to understand your intent and provide relevant responses
  • Images you send (up to 5 per 24-hour session) may be analyzed for visual context. Images are resized and metadata (such as EXIF data) is stripped before AI processing
  • The AI may perform actions such as creating bookings, checking available schedules, or looking up service information on behalf of the business

AI processing is performed using third-party AI language model providers. Your conversation context is cached for 24 hours for operational purposes and then automatically cleared.

4. How Your Data Is Shared

Your data is shared with:

  • The business you interact with — The business operating the storefront has access to your booking history, payment records, communications, and profile information
  • Messaging platform providers — If you communicate via WhatsApp, Instagram, or Facebook Messenger, your messages are processed through those platforms
  • Payment processing providers — If you make online payments, your payment information is processed by third-party payment processors
  • AI language model providers — Your messages and images may be sent to AI providers for automated response generation
  • Cloud hosting providers — Your data is stored on secure cloud infrastructure

We do not sell your personal information to third parties.

5. Data Retention

Your storefront account data is retained for as long as your account is active. Booking and payment records are retained as required for business and legal purposes. AI conversation context is cached for 24 hours and then automatically cleared. You may request deletion of your account and associated data at any time.

6. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and data
  • Object to certain processing of your data

To exercise these rights, contact the business you interacted with or email us at [email protected].

7. Data Security

We implement industry-standard security measures to protect your data, including encryption of data in transit and at rest, secure authentication, and regular security assessments.

8. Children's Privacy

Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.

9. Changes to This Policy

We may update this Customer Privacy Policy from time to time. We will post the updated policy on this page and update the "Last updated" date.

10. Contact Us

If you have questions about this Customer Privacy Policy, please contact us at:

Email: [email protected]

You may also contact the business whose storefront you used, as they are responsible for their own use of your data.