Privacy Policy

How Replymerce handles personal data.

ReplyMerce Privacy Policy

Last updated: September 15, 2026

English

1. Who We Are

ReplyMerce is an AI-assisted sales and customer communication platform for businesses. It provides tools for managing conversations, generating AI-assisted replies, recommending products, capturing leads, coordinating human support, and connecting channels such as Instagram, Facebook Messenger, WhatsApp Business, website chat, and optional voice services.

ReplyMerce is a trading name operated by Artashes Baghdasaryan, Individual Entrepreneur, registered in the Republic of Armenia (referred to in this Privacy Policy as “ReplyMerce,” “we,” “us,” or “our”).

Website: https://replymerce.com
Privacy contact: [email protected]
Location: Yerevan, Republic of Armenia

This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data when you visit our website, create or use a ReplyMerce account, contact us, or communicate with a business that uses ReplyMerce.

2. Scope and Our Data-Protection Roles

This Policy applies to the ReplyMerce website, application, dashboard, chat widget, integrations, AI features, voice features, support, and related services (collectively, the “Service”).

Our role depends on the context:

  • For website visitors, account holders, prospective customers, and our direct business contacts, ReplyMerce generally acts as the controller of personal data.

  • For messages, customer profiles, leads, recordings, transcripts, and other data that a business customer processes through ReplyMerce, the business customer generally acts as the controller and ReplyMerce acts as its processor or service provider. We process that data according to the customer’s instructions, the applicable agreement, and law.

If you are an individual communicating with a store or other business that uses ReplyMerce, that business’s privacy notice also applies. Questions about its purposes, legal basis, or business decisions should normally be directed to that business first.

3. Personal Data We Collect

Depending on how the Service is used, we may process the following categories of data.

3.1 Website and device data

  • IP address and approximate location or country;

  • browser type, operating system, device information, language, and time zone;

  • pages viewed, referring pages, clicks, timestamps, and similar activity data;

  • cookie identifiers, analytics identifiers, error logs, and security logs.

3.2 Account and organization data

  • name, business email address, password hash, and authentication information;

  • organization name, role, permissions, team membership, and workspace settings;

  • subscription plan, account status, communication preferences, and support history.

3.3 Business content and knowledge data

  • product catalogs, prices, product URLs, inventory or availability data provided by the customer;

  • FAQs, policies, instructions, uploaded documents, website text, and other knowledge-base content;

  • AI instructions, prompts, configurations, reply rules, and brand settings.

3.4 Integration and channel data

  • connected-page, account, phone-number, store, or channel identifiers;

  • access tokens, API keys, webhooks, and configuration data needed to operate integrations;

  • data received from connected services such as Meta platforms, WhatsApp Business, ecommerce systems, AI providers, telephony providers, and other services selected by the customer.

Integration credentials are encrypted at rest. Customers may be able to use their own third-party API keys, in which case the relevant provider’s terms and privacy practices also apply.

3.5 Conversation, end-user, and lead data

  • direct messages, website-chat messages, public comments, agent replies, AI-generated replies, attachments, and conversation history;

  • social profile name, username, platform identifier, profile image, phone number, email address, or other information supplied by an end user or made available through a connected channel;

  • timestamps, delivery or read-status information when available, assignments, internal notes, tags, lead status, lead scoring, and human-takeover events;

  • product interests, questions, preferences, and other information contained in a conversation.

3.6 Voice data

If a customer enables Voice AI or telephony features, we may process caller and recipient phone numbers, call time and duration, call routing data, audio recordings, transcripts, summaries, and AI-generated or agent responses. Recording and consent requirements vary by country. The customer using the voice feature is responsible for giving legally required notices and obtaining any legally required consent before recording or analyzing a call.

3.7 Billing and transaction data

  • billing contact, company name, billing address, country, and tax or invoice details;

  • plan, billing interval, transaction status, payment identifier, and limited payment-method metadata made available by the payment provider.

Payment-card details are processed by the applicable payment provider. ReplyMerce does not need to store full card numbers or card security codes.

3.8 Contact and support data

When you contact us, request a demo, or submit a support request, we may process your name, email address, company, message, attachments, and related correspondence.

3.9 Sensitive data

ReplyMerce is not designed to collect full payment-card numbers, account passwords, government identification numbers, health data, biometric identifiers, or other highly sensitive or regulated data through ordinary customer conversations. Customers should not intentionally upload or request such data through ReplyMerce unless the use has been separately agreed, is lawful, and appropriate safeguards are in place. If an end user voluntarily includes sensitive information in a message, the relevant customer is responsible for determining how that information should be handled.

4. How We Obtain Data

We obtain personal data:

  • directly from you or your organization;

  • from end users who communicate through connected channels or a ReplyMerce website widget;

  • from a customer’s administrators, agents, catalogs, files, websites, or systems;

  • from third-party platforms and integrations authorized by the customer;

  • automatically through cookies, local storage, server logs, analytics, and security technologies.

5. How We Use Personal Data and Our Legal Bases

Where ReplyMerce acts as a controller, we use personal data for the following purposes and legal bases, as applicable:

Purpose

Typical legal basis

Create accounts, authenticate users, operate workspaces, provide support, and deliver paid or free services

Performance of a contract or steps requested before entering a contract

Process connected-channel messages, generate AI-assisted replies, provide a unified inbox, capture leads, and enable human takeover

Performance of our customer contract; for end-user data, processing on the customer’s documented instructions

Maintain security, prevent abuse and fraud, debug errors, enforce limits, and protect the Service

Legitimate interests in protecting users and operating a secure and reliable service; legal obligations where applicable

Analyze use of the website and Service and improve usability, reliability, and features

Legitimate interests; consent where required for non-essential analytics technologies

Manage subscriptions, billing, invoices, and accounting

Performance of a contract and compliance with legal obligations

Answer sales, support, privacy, and legal requests

Performance of a contract, steps requested by you, legitimate interests, and legal obligations

Send product updates or marketing communications

Consent where required, or legitimate interests where permitted; you may opt out at any time

Establish, exercise, or defend legal claims and respond to lawful requests

Legitimate interests and compliance with legal obligations

Where ReplyMerce acts as a processor, the customer determines the purposes and legal basis for processing end-user data. ReplyMerce processes that data only to provide the Service, comply with documented customer instructions, protect the Service, or meet legal obligations.

6. AI-Assisted Processing

ReplyMerce may submit relevant conversation content, business knowledge, catalog information, and instructions to an AI model to generate suggested or automated responses, summaries, classifications, recommendations, or lead-related insights. Depending on the customer’s configuration, processing may use a ReplyMerce-managed AI service or the customer’s own API key and provider account.

AI-generated outputs may be incomplete or incorrect. ReplyMerce provides human-takeover and review features, and customers remain responsible for configuring the Service, reviewing important outputs, and deciding how to use them.

ReplyMerce does not use its Service to make decisions about individuals that produce legal or similarly significant effects on behalf of ReplyMerce. Customers must not use AI output as the sole basis for regulated, high-risk, or legally significant decisions unless they have an independent lawful basis, appropriate safeguards, and human review.

We do not use a customer’s end-user messages or confidential business content to train a general-purpose public AI model unless the customer has expressly agreed to that use. Third-party AI providers process data under their own contractual terms and the customer’s configuration.

7. Cookies and Similar Technologies

ReplyMerce uses cookies, browser local storage, and similar technologies for language and country preferences, authentication, workspace selection, analytics, security, and service operation.

Current examples include:

Technology

Purpose

Typical duration

rm_country cookie

Remembers or derives the visitor’s country so the site can provide localized content

Up to 30 days

rm_locale cookie

Remembers the selected Armenian or English language

Up to 30 days

replymerce_token local-storage item

Keeps an authenticated user signed in and authorizes account requests

Until logout, expiry, or browser storage is cleared

replymerce_org_id local-storage item

Remembers the selected ReplyMerce organization or workspace

Until changed, logout, or browser storage is cleared

Google Analytics technologies

Measures visits, page use, device/browser information, and website performance

According to our analytics configuration and Google’s applicable retention settings; analytics cookies may persist for up to two years

Security and infrastructure technologies

Protects the website, detects abusive traffic, and delivers content reliably

Session-based or for the period reasonably required for security

You can manage cookies through your browser and, where available, through the site’s consent controls. Blocking strictly necessary storage may prevent login or other core features from working. Google also provides a browser add-on for opting out of Google Analytics.

8. How We Disclose Personal Data

We may disclose personal data to the following categories of recipients, only as reasonably necessary:

  • Connected platforms: Meta services, including Facebook and Instagram, WhatsApp Business providers, and any other messaging channel selected by the customer;

  • AI and voice providers: AI-model, speech-to-text, text-to-speech, and telephony providers, including OpenAI or Twilio when enabled or configured;

  • Infrastructure and security providers: cloud hosting, databases, content delivery, monitoring, email delivery, backup, and cybersecurity services;

  • Analytics providers: including Google Analytics for website measurement;

  • Payment and billing providers: to process subscription payments, payment methods, invoices, and fraud checks;

  • Commerce and business integrations: such as Magento, Shopify, WooCommerce, CRM tools, or other systems authorized by the customer;

  • Professional advisers: accountants, lawyers, auditors, insurers, and consultants subject to confidentiality obligations;

  • Authorities and other parties: when disclosure is required by law, lawful process, or reasonably necessary to protect rights, safety, security, and the integrity of the Service;

  • Business transaction participants: in connection with a financing, merger, acquisition, restructuring, or sale of assets, subject to appropriate confidentiality and data-protection measures.

We do not sell personal data. We do not share personal data for cross-context behavioral advertising. We do not allow service providers to use customer data for their own unrelated purposes merely because they process it for ReplyMerce.

Third-party platforms remain responsible for the processing they perform under their own terms and privacy notices. A current list of relevant subprocessors may be requested at [email protected].

9. International Data Transfers

ReplyMerce is operated from Armenia. Our customers, end users, connected platforms, and service providers may be located in Armenia, the European Economic Area, the United Kingdom, the United States, or other countries. Personal data may therefore be processed outside the country where it was collected.

Where applicable law requires a transfer mechanism, we use or require appropriate contractual, organizational, or technical safeguards, such as approved standard contractual clauses or equivalent protections. Customers should contact us if they need transfer-related documentation for their use of ReplyMerce.

10. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including providing the Service, following customer instructions, maintaining security, complying with legal and accounting obligations, and resolving disputes.

Retention is generally determined as follows:

  • account and organization data is retained while the account is active and afterward for the period needed for account closure, legal compliance, dispute resolution, and enforcement;

  • customer content, knowledge-base data, conversations, and end-user data are retained according to the customer’s settings, instructions, contract, and account status;

  • integration credentials are retained while the integration remains connected and are deleted or made unusable when the integration or account is removed, subject to security and backup procedures;

  • billing records are retained for the periods required by tax, accounting, payment, and anti-fraud rules;

  • support and sales correspondence is retained for as long as needed to manage the relationship and follow up on the request;

  • security, audit, and technical logs are retained for the period reasonably required to protect, diagnose, and operate the Service;

  • deleted data may remain temporarily in restricted backups until those backups are overwritten through the ordinary backup cycle.

We may retain limited information longer when required by law, to prevent fraud or abuse, or to establish, exercise, or defend legal claims.

11. Security

We use reasonable technical and organizational measures designed to protect personal data. These measures may include encryption in transit, encryption at rest for integration credentials, logical separation of customer organizations, access controls, authentication, monitoring, backups, and least-privilege practices.

No online service can guarantee absolute security. Customers are responsible for protecting passwords and API keys, managing team access, using secure devices, and promptly disconnecting credentials or users who should no longer have access.

12. Your Privacy Rights

Depending on your location and the applicable law, you may have the right to:

  • request access to personal data about you;

  • request correction of inaccurate or incomplete data;

  • request deletion of personal data;

  • object to or request restriction of certain processing;

  • withdraw consent where processing is based on consent, without affecting earlier lawful processing;

  • request a portable copy of certain data;

  • opt out of marketing communications;

  • lodge a complaint with the Personal Data Protection Agency of the Republic of Armenia or another competent supervisory authority;

  • exercise other rights available under applicable law.

To exercise a right concerning ReplyMerce account or website data, email [email protected]. We may need to verify your identity and clarify the scope of the request. We will respond within the period required by applicable law.

If your request concerns a conversation with a business that uses ReplyMerce, contact that business first. As its processor, we will assist the business in responding where required.

13. Data Deletion Instructions

ReplyMerce customers and account users

To request deletion of your ReplyMerce account or associated personal data:

  1. Email [email protected] from the email address connected to your account.

  2. Use the subject line “Data Deletion Request.”

  3. Include your full name, account email, organization or workspace name, and the specific data or integration you want deleted.

  4. We may ask for additional information to verify that you are authorized to make the request.

Where the request is valid, we will delete or de-identify the relevant data, subject to contractual restrictions, technical backup cycles, fraud-prevention needs, and legal retention obligations.

Instagram, Facebook, WhatsApp, website-chat, or voice end users

If you communicated with a business through one of these channels, contact that business and ask it to delete the conversation or related personal data. You may also email [email protected] with the business or page name, channel, your username or phone number, and enough information to locate the conversation. We may forward the request to the relevant business or ask it to confirm deletion instructions.

Disconnecting a platform integration stops new data from being imported through that integration but does not necessarily delete data already stored in ReplyMerce. Submit a deletion request if previously stored data must also be removed.

14. Marketing Communications

You can unsubscribe from marketing emails by using the unsubscribe link in the message or contacting [email protected]. We may still send non-marketing communications required to operate your account, provide support, deliver security notices, or manage billing.

15. Children

ReplyMerce is a business service and is not directed to children under 18. We do not knowingly collect personal data directly from children for their own use of the Service. If you believe a child has provided personal data to ReplyMerce without appropriate authorization, contact [email protected].

Customers must configure and use ReplyMerce in accordance with laws applicable to children and minors in their markets.

16. Third-Party Links and Services

The Service may link to or integrate with third-party websites and services. Their privacy practices are governed by their own notices and agreements. ReplyMerce is not responsible for a third party’s independent processing.

17. Changes to This Policy

We may update this Privacy Policy to reflect changes in the Service, law, or our data practices. We will post the updated version at https://replymerce.com/privacy and revise the “Last updated” date. If a change materially affects how we use personal data, we will provide additional notice where required.

18. Contact Us

For privacy questions, rights requests, or complaints, contact:

Artashes Baghdasaryan, Individual Entrepreneur
Operator of ReplyMerce
Yerevan, Republic of Armenia
Email: [email protected]
Website: https://replymerce.com

Ready to turn DMs into revenue?

Set up in minutes. Connect Meta, add your catalog, and let AI handle the first reply while your team closes the sale.