Back to home
Privacy Policy

Notice on the processing of personal data

This notice explains in a transparent way how Repliva collects, uses, stores and protects personal data when you visit the website, request access to the waitlist, create an account, or use the platform to connect Gmail, Shopify and other operational tools.

Last updated: September 14, 2026

Data processed

Merchant account data, support emails, tickets, Shopify order data, technical data, operational logs and integration settings.

Assisted AI

AI prepares analysis and drafts; the merchant’s operator always reviews and approves the final reply, including through MCP.

Integrations

Email, Shopify, AI providers and MCP clients can receive data needed for authorized functions. We do not promise zero retention.

Security measures

We implement authentication, authorization, logical segregation, secret protection, logging, backup and recovery controls.

1. Controller and contact details

The controller for website data, business inquiries, professional accounts and management of the contractual relationship is Antonino Lombardo, owner of Repliva. Privacy contact: replivacustomer@gmail.com.

For emails, tickets, orders and other customer data processed on the merchant’s behalf, Repliva acts as processor on merchant instructions under the agreement required by GDPR Article 28. Processing conditions appear in section 18 of the Terms of Service, subject to any specifically and validly concluded DPA.

2. Scope of this notice

This notice covers processing carried out when you browse the website, fill in a form, create or use an account, connect integrations, import emails or tickets, use AI features, or communicate with the Repliva team.

  • the public Repliva website;
  • the waitlist page;
  • demo or commercial requests;
  • the Repliva SaaS application;
  • integrations authorized by the merchant, such as Gmail, Shopify, SMTP/IMAP or other operational tools;
  • AI features used for ticket classification, summarization, suggestions and draft generation;
  • communications with Repliva for technical, commercial or administrative support.

3. Privacy roles between Repliva and merchants

Repliva may process personal data in different roles depending on the context.

Repliva acts as controller when processing data relating to website visitors, waitlist users, commercial leads, merchant accounts, authorized merchant users, commercial or administrative communications, security, abuse prevention and technical platform management.

When a merchant connects Gmail, Shopify or other operational systems and Repliva processes end-customer data contained in emails, tickets, orders or support conversations, the merchant normally remains the controller of its own customer data and Repliva acts as a processor, handling the data exclusively on the merchant’s behalf and according to documented instructions.

  • having a valid legal basis to use Repliva;
  • informing its end customers about the use of customer support, automation and AI tools;
  • configuring integrations, retention settings and permissions correctly;
  • handling privacy requests from its end customers;
  • ensuring that use of the platform complies with applicable laws.

4. Categories of personal data processed

Repliva may process different categories of personal data depending on the integrations, tenant and features actually used.

  • Merchant account data: name and surname, email address, business role, store name, store domain, onboarding information, account settings, subscription plan or status, operational preferences.
  • Evidence of contractual choices: account identifier, terms version, language, time the choice was received and server-recorded, entry method and wording of the acceptance; specific clause approvals are documented only when actually collected. Used to document the contract and protect rights, without inferring acceptance merely from saving onboarding.
  • Public website and waitlist data: email address, name if provided, data entered in forms, commercial or demo requests, technical data strictly necessary to use the site, consent-related information where applicable.
  • Email integration data: connected email address, email provider, technical configuration, OAuth tokens including Google refresh tokens, SMTP/IMAP credentials where applicable, integration status, sync timestamps, technical errors and connection logs.
  • Support ticket and email data: sender, recipient, subject, snippet, message content, email thread, timestamps, labels, ticket status, attachments, operational notes, reply drafts and action history.
  • Ecommerce data from Shopify or connected systems: customer name, customer email, order number, purchased products, order amount, currency, payment status, fulfillment status, tracking, shipping address when necessary for the request, operational history, order notes, return, refund or replacement details.
  • Data derived from AI processing: ticket classification, request intent, conversation summary, sentiment, suggested priority, missing fields, suggested actions, reply drafts, tone suggestions, operational logs and outputs generated on the basis of merchant policies.
  • Technical and security data: IP address, user agent, access logs, authentication events, application errors, diagnostic data, operational audit trail, timestamps, device and browser information, security events.

5. Sources of personal data

  • Data provided directly when you fill in a form, request access to the waitlist, book a demo, create an account, complete onboarding, contact Repliva for support, or configure the platform.
  • Data obtained from integrations authorized by the merchant, such as Google/Gmail, Shopify, SMTP/IMAP providers, email providers or other operational tools connected to the platform.
  • Data generated by use of the service, such as synchronization states, created drafts, AI classifications, technical logs, operational history, user actions, errors or security events.
  • Data contained in the merchant’s emails, tickets, orders or systems and processed by Repliva on the merchant’s instructions.

6. Purposes and lawful bases

The following lawful bases concern processing by Repliva as controller. For end-customer data, the merchant determines purposes and lawful basis: its contract with Repliva does not itself authorize processing of any customer data.

Account data and data necessary for requested integrations are needed to provide those functions; optional data and marketing consent are not necessary to use the service. Consent can be withdrawn without affecting earlier lawful processing.

  • Accounts, authentication, support and contractual relationship: performance of a contract with the individual or requested pre-contractual steps; for organization contacts, legitimate interest in managing the business relationship.
  • Requested demos, information and waitlist access updates: pre-contractual steps; additional newsletters and promotions: consent, where offered.
  • Security and abuse prevention: legitimate interest in protecting the service and users, subject to necessity and proportionality; tax and administrative compliance: legal obligation; legal claims: legitimate interest.
  • Email import, order consultation, classification, drafts and transmission to MCP clients: for end-customer data, processing on documented merchant instructions under the lawful basis the merchant must determine.

7. Google/Gmail integration and Limited Use

With merchant authorization, Repliva accesses Google/Gmail data needed for requested functions: message import and display, classification, summaries, drafts, synchronization and sending operator-approved replies.

Data may include addresses, senders, recipients, subjects, content, metadata, threads, necessary attachments, labels and technical integration credentials.

Repliva’s use of information received from Google APIs and its transfer to other applications are subject to the Google API Services User Data Policy, including Limited Use requirements, and applicable Google Workspace policies.

Google data is not sold, used for advertising or advertising profiles, or used to train, improve or fine-tune general-purpose AI models. A simple agreement with the merchant does not create an exception. Transfers to providers and authorized clients are limited to requested functions and uses permitted by Google; MCP connections do not authorize further reuse.

Human access to Google data is limited to cases permitted by those policies, such as explicit consent for specific messages, security needs or legal requirements. Communications are not freely read for independent purposes.

8. Shopify integration

When a merchant connects Shopify, Repliva may access the data necessary to provide operational context for support requests.

Repliva uses Shopify data to display order information within tickets, help operators respond more quickly, generate more contextual drafts, suggest actions consistent with order status and reduce the merchant’s manual workload.

Repliva does not use Shopify data for its own advertising purposes and does not sell such data to third parties.

  • store data;
  • customer data;
  • customer email;
  • order number;
  • purchased products;
  • order total;
  • payment status;
  • fulfillment status;
  • tracking;
  • shipping data;
  • order history;
  • order notes;
  • return, refund or replacement information.

9. AI, human oversight and providers

Repliva is a semi-automatic service: AI classifies, summarizes and prepares suggestions. The merchant’s operator must always review and approve the final reply before sending. This is a workflow obligation, including through MCP, rather than a guarantee that Repliva can verify every approval inside external clients.

Processing may transmit necessary email and conversation content, order data, policies, FAQs and merchant instructions to AI providers. The setup chat can also transmit messages, proposed settings and imported page text to AI providers.

Requests can pass through intermediaries such as OpenRouter to the configured model provider, for example Google/Gemini or OpenAI. Intermediary retention and model-provider retention are separate. Diagnostics services such as Langfuse, if enabled, may receive metadata and processing content to investigate errors and performance.

We do not guarantee that providers collect or retain no data. They may process inputs, outputs and metadata to deliver services, manage security and abuse, retain logs or meet legal obligations under applicable terms, settings and agreements. No training does not mean zero retention; we do not promise anonymity, a complete absence of authorized human access or exclusively EU residency.

Repliva does not use merchant data, emails or tickets to train its own general-purpose AI models. Adapting replies to an individual merchant’s policies and corrections can involve storing rules and history in that merchant’s account; this is distinct from general model training.

This notice does not authorize providers to use data freely or release Repliva from its duties when selecting, instructing and overseeing subprocessors. DPAs, minimization and provider restrictions, particularly for Google data, remain binding. Incompatible uses require excluding the provider or stopping the transfer, rather than an exemption in this notice.

The service is intended to assist an operator, not to make solely automated decisions with legal or similarly significant effects on individuals. If the merchant changes workflows through external tools, it must assess lawfulness and safeguards without bypassing required human review.

10. Special or sensitive data

Repliva does not intentionally request the input of special categories of personal data, such as data relating to health, political opinions, religious beliefs, trade union membership, sexual orientation or biometric data.

However, such data may accidentally appear in messages sent by end customers to merchants or in attachments imported into the platform.

In those cases, Repliva processes such data only on the merchant’s instructions, within the limits necessary to provide the service, subject to the applicable security measures and the agreement required under GDPR Article 28. The merchant must also assess the conditions of GDPR Articles 9 and 10 where applicable.

The merchant is responsible for avoiding the import or upload of data that is not necessary for customer support purposes.

11. Recipients and services involved

Data is not publicly disclosed. It is accessible to authorized persons for the stated purposes, advisers bound by confidentiality and authorities where required by law.

Technical services involved depend on enabled features. The contractual subprocessor list, with legal entities, locations, services and safeguards, must be established and authorized under the DPA; request it at replivacustomer@gmail.com. The following description does not certify unverified locations or settings.

  • Vercel and Supabase: application hosting, database, authentication and infrastructure services according to service configuration.
  • OpenRouter and configured model providers, including Google/Gemini and OpenAI where used: transmission and processing of AI requests. Routing may involve multiple providers.
  • Langfuse, if enabled: AI diagnostics, potentially including input and output content as well as technical metadata.
  • PostHog: optional analytics and session recordings on public pages and in the dashboard, only after consent, with masked data as described in the cookie section.
  • Google/Gmail, Microsoft/Outlook, Shopify and connected SMTP/IMAP providers: data needed for integrations and authorized operations. Kaching or Checkout Champ, if connected, receive data needed for merchant-requested subscription management.
  • MCP clients, AI assistants and external tools selected by the merchant: requested data and results within granted permissions. They are not automatically subprocessors selected by Repliva; their role depends on their actual relationship with the merchant.

12. Transfers outside the EEA

Infrastructure providers, AI intermediaries and models, or external clients may process data outside the European Economic Area. We do not promise that all data remains in the EU; routing depends on the service, provider and configuration.

For transfers under its responsibility, Repliva must establish a valid mechanism under GDPR Chapter V, such as an adequacy decision applicable to the recipient or standard contractual clauses with necessary assessments and supplementary safeguards. Merely accepting this page or enabling MCP does not replace these safeguards.

You can request information about recipients, processing countries and applicable safeguards, and a copy of safeguards as provided by law, from the privacy contact. The merchant separately assesses transfers by external clients it selects.

13. Retention and residual copies

Account data is retained to manage the relationship; tax data, contractual evidence and records needed to protect rights follow relevant legal duties and limitation periods. Business inquiry and waitlist data remains only while needed for the request, or until consent withdrawal for consent-based communications.

Emails, tickets, analysis, drafts and history are retained to provide the merchant’s service and under deletion instructions and applicable agreements. Moving a ticket to trash or archiving it is not deletion: there is no general automatic expiry of all content after a fixed number of days.

Sending records, action evidence and accounting data may outlast content deletion to prevent duplicates, resolve pending operations, meet legal obligations or protect rights. Retention must be limited to data needed for these purposes; it does not authorize indefinite retention of all message copies.

Diagnostic logs, revoked credentials and backups can have different periods from tickets. Deletion does not mean immediate removal from every backup or provider; residual copies must be protected, excluded from ordinary use and removed under the documented schedule for the system. To learn or agree on applicable account periods and request deletion, contact replivacustomer@gmail.com.

The onboarding draft and conversation may remain in browser local storage for the account after refresh; closing the tab does not delete them. The conversation is not included in the final settings save, but messages submitted to the chat are processed by AI providers as described above.

14. Integration revocation and data deletion

A merchant may disconnect Gmail, Shopify or other integrated providers at any time from the Repliva dashboard, from the external provider settings or by contacting Repliva support.

After disconnection, Repliva stops synchronization with the disconnected integration, no longer accesses new data through that integration, and related tokens or technical credentials are revoked, disabled or removed according to applicable technical timing.

Data already imported may still be retained according to retention settings, legal obligations, technical backup needs or deletion requests.

The merchant may request deletion of tenant data according to the procedures available in the service or under applicable contractual arrangements. When Repliva acts as a processor, requests concerning end-customer data are handled according to the merchant’s instructions.

15. Cookies, analytics and preferences

This section provides the notice for cookies and similar technologies. Strictly necessary tools support authentication, security, saved choices and features requested by the user. They do not depend on consent to analytics.

On your first visit, you can accept or reject optional analytics without losing access to browsing or registration. Without a choice, analytics stays disabled. You can use the Change cookie preferences link in this section at any time and withdraw as easily as you accepted. Cookie consent is separate from acceptance of the terms.

Only after consent to analytics and recordings, on permitted public pages and in the dashboard, PostHog can receive page-view events, predefined button clicks and recordings of interactions (navigation, pointer movement and scrolling), with random identifiers kept in memory. Text and input values are masked; images, videos, embedded attachments, console output and network request contents are excluded. We do not create personal profiles. Account registration, authentication and onboarding are excluded. Address parameters and fragments are not included in transmitted recordings; article addresses are generalized. Rejection, withdrawal or expiry of consent stops collection. This new version requires a new choice from visitors who previously accepted analytics alone.

The technical connection exposes the connection IP address to the provider; geographical enrichment is disabled. The PostHog service and its location depend on configuration, without a guarantee of exclusively EU processing. We do not use this consent for advertising or marketing.

Withdrawal stops new collection; it does not undo transmitted events or instantly delete them at the provider. Already in-flight events may complete. For requests concerning data already collected, contact replivacustomer@gmail.com.

You can clear cookies and site data in your browser; this may end your session or remove unsaved drafts. If saving your choice fails, we display an error and analytics remains disabled. Identifiers from older versions may remain until removed or expired and are not reused by this configuration.

  • Cookie preferences: version, choice, date and expiry are saved in the database and in repliva_cookie_consent local storage with a validity of 180 days. The technical HttpOnly cookie repliva_privacy_receipt, valid for 180 days, retrieves your choice even when local storage is unavailable. The database stores only a hash of the cookie code and the choice, without linking it to your account or using it for analytics. At expiry, analytics stops and the banner reappears for a new choice. Before expiry it stays hidden after acceptance or rejection, unless site data is cleared or material changes require new consent. repliva_posthog_consent stores the SDK’s technical consent flag; it is subordinate to the main choice and is updated on withdrawal.
  • Analytics: in-memory identifiers during page use, without persistent analytics cookies or identifiers in this configuration. Provider-side retention is separate from browser-choice duration and follows applicable configuration and agreements; request details from the privacy contact.
  • Authentication: Supabase session identifiers and tokens for access and renewal; duration depends on the session and browser settings. If you choose Remember me, the preference and email address may remain locally until you remove that choice or site data.
  • OAuth security: temporary Google, Microsoft and Shopify cookies, valid for ten minutes, to verify requested connections.
  • Terms acceptance: the signed HttpOnly technical cookie repliva_legal_intent, valid for at most 24 hours, holds temporary evidence of the choice and, for email registration, a hash of the address. It is removed when account acceptance is recorded or on expiry. It is not analytics consent.
  • Preferences and drafts: local storage for theme and interface state; repliva_onboarding_draft_v2 stores the setup draft and conversation per account until removed by the application or user, without automatic browser expiry.

16. Security measures

Repliva adopts technical and organizational measures that are reasonable and proportionate to the nature of the data processed.

No measure can guarantee absolute security, but Repliva implements controls aimed at reducing the risks of unauthorized access, loss, alteration, disclosure or misuse of data.

In the event of a security incident involving personal data, Repliva will take the measures required by applicable law and, where necessary, will inform merchants, users or competent authorities within the timeframes and using the methods required by law.

  • user authentication;
  • authorization controls;
  • logical tenant segregation;
  • application access policies;
  • principle of least privilege;
  • encryption or equivalent protection for tokens, credentials and secrets;
  • technical logging;
  • operational audit trails;
  • anomaly and abuse monitoring;
  • backup and recovery procedures;
  • infrastructure hardening;
  • separation of operational access;
  • limitation of access to data to authorized personnel or systems;
  • incident management procedures.

17. Rights and requests

Where provided by law, you can request access, rectification, deletion, restriction and portability, object to legitimate-interest processing and withdraw consent. Withdrawal does not affect earlier lawful processing. You can complain to the Italian Garante per la protezione dei dati personali or the competent authority where you habitually live or work or where the alleged infringement occurred.

Send requests to replivacustomer@gmail.com. We respond within GDPR deadlines, normally one month; any extension for complexity or number of requests is explained within the first month. We request only necessary and proportionate identity-verification information.

If you are a merchant’s customer, contact that merchant as controller. If we receive a request concerning data processed on its behalf, we forward it and assist under applicable obligations.

18. Children

The Repliva service is not directed to children under 16 and is not designed to knowingly collect personal data from children.

If you believe that a child has provided personal data to Repliva, you may contact us to request removal.

Data relating to minors may accidentally appear in support messages or data imported by merchants. In those cases, Repliva processes such data only on the merchant’s instructions and only to the extent necessary to provide the service.

19. Changes to this notice

Repliva may update this Privacy Policy to reflect legal, technical, organizational or functional changes to the service.

If relevant changes occur, Repliva will publish the updated version on this page together with the revised last-updated date.

Where necessary, Repliva may also provide an additional notice through the service, by email or through other appropriate channels.

20. Contacts

For questions about this notice or the processing of personal data, you may contact Antonino Lombardo at replivacustomer@gmail.com.

If your organization has entered into a DPA, specific contractual terms or other additional agreements with Repliva, those documents also govern the allocation of privacy roles and responsibilities where applicable.

21. Data transmitted through MCP

Connecting an MCP client authorizes access within granted scopes. The client can receive ticket content, customer and order data, drafts, results and operational data necessary for invoked tools. Keys, OAuth authorizations and call records are processed to manage access, security and operations.

An external client may forward results to its AI provider, retain them in logs or use them in merchant-configured workflows under its own terms. The merchant must assess this processing, inform individuals and limit data and permissions. Revocation prevents future access through the revoked credential but does not remove copies already held by the client.

Repliva provides the technical interface and can execute real sends on authorized calls; connecting alone does not start an autonomous sending workflow. Final replies remain subject to human review and approval under Terms section 17. The merchant is responsible for external workflows it configures, without releasing Repliva from its own privacy responsibilities.