Skip to content

Trust

Your data, where the law says it should be.

The page to forward to your DPO. Where your data lives, who processes it, how long it stays and how to get it out again. Everything here mirrors the privacy policy, and where the two differ, the policy wins.

Shopify access

Read-only means read-only.

Repley asks for three scopes and no write scope at all. What it cannot do, it cannot do because it was never granted, not because it promises not to.

What it can read

  • read_ordersRead an order, its fulfilment and its tracking
  • read_customersRead the customer behind the order
  • read_fulfillmentsRead what shipped, and when

What it can never do

  • No order editsIt cannot change an order, ever
  • No refundsIt cannot move money
  • No writes at allNo write scope is requested, so none can be used

Subprocessors

Who touches your data.

Hosting and the database stay in the EU. Only the AI calls leave it, under Standard Contractual Clauses and a contractual ban on training.

Inside the EU

  • Hetzner Online GmbH

    EU

    Frankfurt, Germany

    Primary application hosting

    ReceivesAll data

  • Supabase Inc.

    EU

    Frankfurt, EU region

    Managed Postgres and authentication

    ReceivesMerchant account data, ticket data, operational data

Outside the EU · AI calls only

  • Anthropic PBC

    US · SCC

    United States

    Language-model API for classification, drafting and critique

    ReceivesInbound email content, knowledge-base excerpts, order context

    barred from training on it

  • Voyage AI Inc.

    US · SCC

    United States

    Embedding API for knowledge-base retrieval

    ReceivesKnowledge-base and inbound email excerpts

    barred from training on it

The complete list, including the platforms you connect (Shopify, Google, Microsoft), transactional email (Resend) and the self-hosted ingestion workflow (n8n, on the same German VPS), is in section 06 of the privacy policy. AI providers delete submitted data after a limited retention window, typically 30 days or less. Material changes to the list are announced with reasonable advance notice.

Controls

What a DPO asks first.

Encryption, retention, access and requests, in the words of the policy, minus the legalese.

Encryption

  • In transit TLS 1.2+ On every public endpoint.
  • At rest Authenticated symmetric Shopify tokens, SMTP credentials, webhook secrets and API keys. Database volumes encrypted at the provider level.
  • Key rotation Without user impact A single key gates decryption and rotates without downtime.

Retention

  • Tickets, AI traces, audit log 24 months From creation, or the shorter period you set in settings.
  • Application logs 90 days Rolling.
  • Backups 30 days Encrypted window.
  • After uninstall 48 hours Your tenant is purged when Shopify's shop/redact webhook arrives. Earlier deletion on request, any time.

Access

  • Shopify scopes Read-only Orders, customers and fulfilments. Nothing is ever written to your store.
  • Webhooks HMAC-SHA256 Every Shopify webhook is verified before it is read.
  • Tenant isolation Row-level security Enforced on every connection.
  • Production access Named staff Rotated SSH keys, and logged.

Your requests

  • Export or delete privacy@repley.io Exports within 30 days, usually much faster.
  • Customer requests Handled by webhook customers/data_request, customers/redact and shop/redact, HMAC-verified and logged.
  • Incidents Within 72 hours Affected merchants hear from us without undue delay, within 72 hours where the GDPR requires it.
  • GDPR-ready

    Processor under the GDPR, EU-hosted

  • DPA on request

    Signed, for your DPO

  • Transfers under SCCs

    The only data that leaves the EU

  • No training on your data

    Contractually barred, both vendors

  • Export or delete

    On request, any time

  • Incident notice

    Within 72 hours where the GDPR requires it

Paperwork

A DPA for your DPO, a door for researchers.

Both reach the same inbox, and a human reads it.

Data processing agreement

Need a DPA?

We sign one on request. Write with your company name and the store you run, and it comes back signed.

Responsible disclosure

Found something?

Write to security@repley.io. We investigate and respond within 72 hours. Please hold off on publishing until we have had the chance to fix it. If an incident ever touches personal data, affected merchants hear from us without undue delay, within 72 hours where the GDPR requires it.

Ready when you are

Recover revenue
while you sleep.

Connect your store and your inbox. Repley answers every customer in your voice, cited from your own docs, automatically. Live in 15 minutes.

Choose a plan

Live in 15 minutes·cancel anytime·or write to hello@repley.io