The fine print

Privacy Policy

Last updated January 2026

1. What we collect

Account data (name, email, password hash, workspace details), conversation content, and visitor metadata captured by the widget: page URL, referrer, browser, operating system, device type, approximate location derived from IP, and any details a visitor volunteers in the pre-chat form.

2. Why we collect it

To deliver live chat, route conversations, produce your reports, bill your subscription, and secure the platform. We do not sell personal data or use conversation content for advertising.

3. Roles

For your own customers, you are the data controller and ReplyOnSite is the processor. For your account data, we are the controller.

4. Sub-processors

We use infrastructure providers to run the service, and an AI model provider when a workspace enables the AI assistant. Conversation content is sent to the AI provider only for workspaces that turn that feature on.

5. Retention

Conversation history is retained for as long as your workspace is active. Deleted workspaces are purged within 30 days. Audit logs are retained for 12 months.

6. Your rights

You can access, correct, export or delete personal data from the workspace settings, or by contacting support. We respond to verified requests within 30 days.

7. Security

Passwords are hashed with bcrypt, sessions are signed and revocable, transport is encrypted, and sensitive administrative actions are recorded in an audit log.

8. Cookies

We set a session cookie for authenticated panels and a first-party identifier so the widget can recognise a returning visitor and restore their conversation. No third-party advertising cookies are used.

This document is a starting point for a real deployment. Have your own counsel review it before you launch commercially.

Privacy Policy | ReplyOnSite