Repley Legal
Home  /  Legal  /  Privacy Policy

Privacy Policy

v1.1 Effective 20 April 2026 · Last updated 17 May 2026

How TimeFuser LTD, the operator of the Repley AI customer-support application, collects, uses, shares and protects personal data for Shopify merchants and their customers.

On this page
  1. 1. Who we are and how to reach us
  2. 2. What this policy covers
  3. 3. Data we collect and process
  4. 4. Why we process data (purposes and legal bases)
  5. 5. AI-assisted processing
  6. 6. Sub-processors and third parties
  7. 7. International data transfers
  8. 8. Data retention
  9. 9. Security
  10. 10. Your rights
  11. 11. Shopify data-subject requests
  12. 12. Cookies and tracking
  13. 13. Children's privacy
  14. 14. Security incidents
  15. 15. Changes to this policy
  16. 16. Google API Services User Data Policy
  17. 17. Contact

Effective date: 20 April 2026 Last updated: 17 May 2026

This Privacy Policy explains how TimeFuser LTD ("TimeFuser", "we", "us", "our"), the operator of the Repley AI customer-support application (the "App"), collects, uses, shares and protects information when Shopify merchants install and use the App, and when we process data about their customers as a data processor on their behalf.

If you are a Shopify merchant, we act as the data controller for the limited account information you provide to us directly (e.g. your login email) and as a data processor for the customer, order and fulfillment data we access from your store on your instructions.

If you are a customer of a Shopify merchant using Repley, the merchant is the data controller for your personal data and we act as their data processor; please read the merchant's own privacy notice alongside this policy.



1. Who we are and how to reach us#

The App is provided by TimeFuser LTD, a company registered in the Republic of Cyprus, company number HE480325, with its registered office at Voukourestiou 25, NEPTUNE HOUSE, 1st floor, Flat/Office 183, 3045 Limassol, Cyprus.

Privacy questions, data-subject requests or security reports: privacy@repley.io. General support: support@repley.io. Website: https://repley.io.


2. What this policy covers#

This policy applies to data processed in connection with the App, including:

It does not apply to the websites, apps or practices of other companies we integrate with (such as Shopify, Anthropic, Supabase or others listed in §6), which are governed by their own privacy notices.


3. Data we collect and process#

3.1 Merchant account data#

When a merchant signs up for Repley or installs it on a Shopify store, we collect and process:

3.2 Shopify store data ("Protected Customer Data")#

With the merchant's authorisation, the App requests limited scopes from Shopify and accesses:

We request only the minimum scopes needed for the feature the merchant has enabled and do not use Protected Customer Data for any purpose beyond providing the agreed service to the merchant.

3.3 Email and support-ticket data#

When a merchant connects their support inbox to Repley, the App ingests inbound email that reaches that inbox. Repley supports two connection methods:

In either case, the data ingested per message can include:

Outbound replies generated or assisted by the App are sent back to the customer via the merchant's own email infrastructure (the merchant's SMTP credentials), not from TimeFuser-owned addresses.

A merchant may revoke Repley's access to their Gmail account at any time by visiting their Google Account permissions page at https://myaccount.google.com/permissions and removing Repley. Revocation immediately stops further data ingestion; previously-ingested data remains subject to the retention schedule in §8.

3.4 Operational data#

We log information required to operate the service securely:

3.5 Marketing website (repley.io)#

On our marketing website we may process basic analytics data (pages visited, approximate location, device and browser) and any information you submit through contact or demo forms. We do not use cookies for cross-site advertising on repley.io.


PurposeData categoriesLegal basis (GDPR)
Provide and operate the App (authentication, Shopify OAuth, ticket ingestion, AI-assisted drafting and sending, escalation routing)Merchant account data, Shopify store data, email and ticket data, operational dataPerformance of the merchant's subscription contract (Art. 6(1)(b)); our legitimate interest in operating a secure, reliable service (Art. 6(1)(f)) for data from merchants' customers, under instruction of the merchant as controller
Billing, invoicing and managing the commercial relationshipMerchant account data, metering dataContract (Art. 6(1)(b)); compliance with tax & accounting obligations (Art. 6(1)(c))
Security, fraud prevention, incident responseOperational data, IP addresses, audit logLegitimate interest (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c))
Service improvement, debugging and model-free product analyticsAggregated / pseudonymised operational dataLegitimate interest (Art. 6(1)(f))
Marketing communications to merchants who have opted inMerchant email, preferencesConsent (Art. 6(1)(a)) or legitimate interest (Art. 6(1)(f)) with right to opt out
Complying with law, Shopify platform rules and enforcing our termsAny of the aboveLegal obligation (Art. 6(1)(c)); legitimate interest (Art. 6(1)(f))

5. AI-assisted processing#

The App uses large language models and embedding models to classify inbound emails, draft replies, and match customer questions to merchant-uploaded knowledge-base content. Specifically:

Merchants may disable AI autonomy features at any time from the App settings; when disabled, drafts are only surfaced for human review and are not sent automatically.


6. Sub-processors and third parties#

We use the following sub-processors to operate the App. Each has its own security and privacy program and is bound by a data-processing agreement with us:

Sub-processorPurposeData categoriesLocation
Shopify Inc.Source of merchant store data; platform on which the App runsAll store-derived dataCanada / global
Google LLC (Gmail API)Source of inbound email when a merchant connects Gmail via OAuth; provides authentication tokens and message retrieval APISender / recipient addresses, message headers, subject, body of inbound email; OAuth tokensUnited States
Hetzner Online GmbHPrimary application hostingAll dataGermany (EU)
Supabase Inc.Managed Postgres database, authenticationMerchant account data, ticket data, operational dataEU (Frankfurt)
Anthropic PBCLarge-language-model API (classification, drafting, critique)Inbound email content, knowledge-base excerpts, order contextUnited States
Voyage AI Inc.Embedding model API (knowledge-base retrieval)Knowledge-base excerpts, inbound email excerptsUnited States
Resend (Resend Inc.)Transactional email delivery (account notifications, digests)Merchant email address, email content sent by us to merchantsUnited States / EU
n8n GmbH (self-hosted)Email ingestion workflow automationInbound email content, headersGermany (our VPS)

An up-to-date list of sub-processors is available on request at privacy@repley.io. We will notify merchants of material changes to our sub-processor list with reasonable advance notice.


7. International data transfers#

Our primary infrastructure is hosted in the European Union. Some sub-processors (notably AI providers) are located outside the EEA/UK. When personal data is transferred outside the EEA/UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum where applicable, and supplementary technical measures including encryption in transit and contractual prohibitions on training on submitted data. A copy of the transfer mechanism applicable to a specific sub-processor is available on request.


8. Data retention#

DataRetention
Active merchant account dataFor the duration of the account plus 90 days after termination, then deleted or anonymised unless a longer legal retention applies
Tickets, AI traces, audit log24 months from creation, or the period the merchant configures in settings, whichever is shorter
Shopify access tokensUntil the merchant uninstalls; marked as revoked immediately on the app/uninstalled webhook; encrypted record retained for 48 hours after uninstall for GDPR reconciliation, then purged
Application logs90 days rolling
BackupsEncrypted; 30-day rolling window
Marketing website analytics12 months rolling

Merchants can request early deletion of any tenant data at any time via privacy@repley.io. When Shopify sends the mandatory shop/redact webhook (48 hours after uninstall), we purge the associated tenant data on our side without further request.


9. Security#

We follow a defence-in-depth approach:

No system is impenetrable. We commit to timely breach notification as described in §14.


10. Your rights#

Depending on where you live, you may have rights in relation to your personal data, including the right to:

If you are a customer of a Shopify merchant using Repley, please contact that merchant directly to exercise your rights. The merchant is the controller of your data; we will assist them in fulfilling your request. If the merchant is unresponsive, you may also contact privacy@repley.io and we will support the request to the extent permitted by law.

Residents of California, Colorado, Connecticut, Virginia and similar US states: you have equivalent rights under applicable state privacy law (e.g. the CCPA/CPRA, CPA, CTDPA, VCDPA). We do not "sell" personal information as defined in those laws.


11. Shopify data-subject requests#

The App implements the three mandatory Shopify data-protection webhooks:

All three webhooks are HMAC-verified with the app's signing secret and logged for auditability.


12. Cookies and tracking#

The App itself uses only strictly-necessary session tokens — there is no advertising, analytics or cross-site tracking inside the App. On our marketing website at repley.io, we may use first-party analytics cookies to understand aggregate traffic. We do not use advertising cookies or similar trackers on that website. Where required by law we will show a cookie banner and honour your choices.


13. Children's privacy#

Repley is a business-to-business service intended for use by Shopify merchants operating in a commercial capacity. The App is not directed at children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.


14. Security incidents#

If we become aware of a security incident that has led, or is reasonably likely to lead, to unauthorised access to personal data, we will notify affected merchants without undue delay and, where required by law, within the timeframes specified (typically 72 hours for controllers under the GDPR). Merchants remain responsible for notifying their own customers where the affected data relates to those customers.


15. Changes to this policy#

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, sub-processor list, or for other operational reasons. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify merchants by email or in-App. Continued use of the App after a change constitutes acceptance of the updated policy.


16. Google API Services User Data Policy#

Repley uses Google APIs to access Gmail data on behalf of merchants who have explicitly granted access through Google's OAuth 2.0 consent flow.

Repley's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, Repley:

A merchant may revoke Repley's access to their Gmail account at any time via https://myaccount.google.com/permissions. Revocation immediately stops new data ingestion; previously-ingested data remains subject to the retention schedule in §8.


17. Contact#

TimeFuser LTD Voukourestiou 25, NEPTUNE HOUSE, 1st floor, Flat/Office 183 3045 Limassol, Cyprus Company number HE480325 Email: privacy@repley.io Website: https://repley.io


TimeFuser LTD · Limassol, Republic of Cyprus · privacy@repley.io

Version 1.1 · Effective 20 April 2026 · Last updated 17 May 2026 (added Google Gmail OAuth + Google API Services User Data Policy disclosure).