The fine print
Privacy Policy
Last updated January 2026
1. What we collect
Account data (name, email, password hash, workspace details), conversation content, and visitor metadata captured by the widget: page URL, referrer, browser, operating system, device type, approximate location derived from IP, and any details a visitor volunteers in the pre-chat form.
2. Why we collect it
To deliver live chat, route conversations, produce your reports, bill your subscription, and secure the platform. We do not sell personal data or use conversation content for advertising.
3. Roles
For your own customers, you are the data controller and ReplyOnSite is the processor. For your account data, we are the controller.
4. Sub-processors
We use infrastructure providers to run the service, and an AI model provider when a workspace enables the AI assistant. Conversation content is sent to the AI provider only for workspaces that turn that feature on.
5. Retention
Conversation history is retained for as long as your workspace is active. Deleted workspaces are purged within 30 days. Audit logs are retained for 12 months.
6. Your rights
You can access, correct, export or delete personal data from the workspace settings, or by contacting support. We respond to verified requests within 30 days.
7. Security
Passwords are hashed with bcrypt, sessions are signed and revocable, transport is encrypted, and sensitive administrative actions are recorded in an audit log.
8. Cookies
We set a session cookie for authenticated panels and a first-party identifier so the widget can recognise a returning visitor and restore their conversation. No third-party advertising cookies are used.
This document is a starting point for a real deployment. Have your own counsel review it before you launch commercially.