Privacy Policy
How Replymerce handles personal data.
ReplyMerce Privacy Policy
Last updated: September 15, 2026
English
1. Who We Are
ReplyMerce is an AI-assisted sales and customer communication platform for businesses. It provides tools for managing conversations, generating AI-assisted replies, recommending products, capturing leads, coordinating human support, and connecting channels such as Instagram, Facebook Messenger, WhatsApp Business, website chat, and optional voice services.
ReplyMerce is a trading name operated by Artashes Baghdasaryan, Individual Entrepreneur, registered in the Republic of Armenia (referred to in this Privacy Policy as “ReplyMerce,” “we,” “us,” or “our”).
Website: https://replymerce.com
Privacy contact: [email protected]
Location: Yerevan, Republic of Armenia
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data when you visit our website, create or use a ReplyMerce account, contact us, or communicate with a business that uses ReplyMerce.
2. Scope and Our Data-Protection Roles
This Policy applies to the ReplyMerce website, application, dashboard, chat widget, integrations, AI features, voice features, support, and related services (collectively, the “Service”).
Our role depends on the context:
For website visitors, account holders, prospective customers, and our direct business contacts, ReplyMerce generally acts as the controller of personal data.
For messages, customer profiles, leads, recordings, transcripts, and other data that a business customer processes through ReplyMerce, the business customer generally acts as the controller and ReplyMerce acts as its processor or service provider. We process that data according to the customer’s instructions, the applicable agreement, and law.
If you are an individual communicating with a store or other business that uses ReplyMerce, that business’s privacy notice also applies. Questions about its purposes, legal basis, or business decisions should normally be directed to that business first.
3. Personal Data We Collect
Depending on how the Service is used, we may process the following categories of data.
3.1 Website and device data
IP address and approximate location or country;
browser type, operating system, device information, language, and time zone;
pages viewed, referring pages, clicks, timestamps, and similar activity data;
cookie identifiers, analytics identifiers, error logs, and security logs.
3.2 Account and organization data
name, business email address, password hash, and authentication information;
organization name, role, permissions, team membership, and workspace settings;
subscription plan, account status, communication preferences, and support history.
3.3 Business content and knowledge data
product catalogs, prices, product URLs, inventory or availability data provided by the customer;
FAQs, policies, instructions, uploaded documents, website text, and other knowledge-base content;
AI instructions, prompts, configurations, reply rules, and brand settings.
3.4 Integration and channel data
connected-page, account, phone-number, store, or channel identifiers;
access tokens, API keys, webhooks, and configuration data needed to operate integrations;
data received from connected services such as Meta platforms, WhatsApp Business, ecommerce systems, AI providers, telephony providers, and other services selected by the customer.
Integration credentials are encrypted at rest. Customers may be able to use their own third-party API keys, in which case the relevant provider’s terms and privacy practices also apply.
3.5 Conversation, end-user, and lead data
direct messages, website-chat messages, public comments, agent replies, AI-generated replies, attachments, and conversation history;
social profile name, username, platform identifier, profile image, phone number, email address, or other information supplied by an end user or made available through a connected channel;
timestamps, delivery or read-status information when available, assignments, internal notes, tags, lead status, lead scoring, and human-takeover events;
product interests, questions, preferences, and other information contained in a conversation.
3.6 Voice data
If a customer enables Voice AI or telephony features, we may process caller and recipient phone numbers, call time and duration, call routing data, audio recordings, transcripts, summaries, and AI-generated or agent responses. Recording and consent requirements vary by country. The customer using the voice feature is responsible for giving legally required notices and obtaining any legally required consent before recording or analyzing a call.
3.7 Billing and transaction data
billing contact, company name, billing address, country, and tax or invoice details;
plan, billing interval, transaction status, payment identifier, and limited payment-method metadata made available by the payment provider.
Payment-card details are processed by the applicable payment provider. ReplyMerce does not need to store full card numbers or card security codes.
3.8 Contact and support data
When you contact us, request a demo, or submit a support request, we may process your name, email address, company, message, attachments, and related correspondence.
3.9 Sensitive data
ReplyMerce is not designed to collect full payment-card numbers, account passwords, government identification numbers, health data, biometric identifiers, or other highly sensitive or regulated data through ordinary customer conversations. Customers should not intentionally upload or request such data through ReplyMerce unless the use has been separately agreed, is lawful, and appropriate safeguards are in place. If an end user voluntarily includes sensitive information in a message, the relevant customer is responsible for determining how that information should be handled.
4. How We Obtain Data
We obtain personal data:
directly from you or your organization;
from end users who communicate through connected channels or a ReplyMerce website widget;
from a customer’s administrators, agents, catalogs, files, websites, or systems;
from third-party platforms and integrations authorized by the customer;
automatically through cookies, local storage, server logs, analytics, and security technologies.
5. How We Use Personal Data and Our Legal Bases
Where ReplyMerce acts as a controller, we use personal data for the following purposes and legal bases, as applicable:
Purpose | Typical legal basis |
|---|---|
Create accounts, authenticate users, operate workspaces, provide support, and deliver paid or free services | Performance of a contract or steps requested before entering a contract |
Process connected-channel messages, generate AI-assisted replies, provide a unified inbox, capture leads, and enable human takeover | Performance of our customer contract; for end-user data, processing on the customer’s documented instructions |
Maintain security, prevent abuse and fraud, debug errors, enforce limits, and protect the Service | Legitimate interests in protecting users and operating a secure and reliable service; legal obligations where applicable |
Analyze use of the website and Service and improve usability, reliability, and features | Legitimate interests; consent where required for non-essential analytics technologies |
Manage subscriptions, billing, invoices, and accounting | Performance of a contract and compliance with legal obligations |
Answer sales, support, privacy, and legal requests | Performance of a contract, steps requested by you, legitimate interests, and legal obligations |
Send product updates or marketing communications | Consent where required, or legitimate interests where permitted; you may opt out at any time |
Establish, exercise, or defend legal claims and respond to lawful requests | Legitimate interests and compliance with legal obligations |
Where ReplyMerce acts as a processor, the customer determines the purposes and legal basis for processing end-user data. ReplyMerce processes that data only to provide the Service, comply with documented customer instructions, protect the Service, or meet legal obligations.
6. AI-Assisted Processing
ReplyMerce may submit relevant conversation content, business knowledge, catalog information, and instructions to an AI model to generate suggested or automated responses, summaries, classifications, recommendations, or lead-related insights. Depending on the customer’s configuration, processing may use a ReplyMerce-managed AI service or the customer’s own API key and provider account.
AI-generated outputs may be incomplete or incorrect. ReplyMerce provides human-takeover and review features, and customers remain responsible for configuring the Service, reviewing important outputs, and deciding how to use them.
ReplyMerce does not use its Service to make decisions about individuals that produce legal or similarly significant effects on behalf of ReplyMerce. Customers must not use AI output as the sole basis for regulated, high-risk, or legally significant decisions unless they have an independent lawful basis, appropriate safeguards, and human review.
We do not use a customer’s end-user messages or confidential business content to train a general-purpose public AI model unless the customer has expressly agreed to that use. Third-party AI providers process data under their own contractual terms and the customer’s configuration.
7. Cookies and Similar Technologies
ReplyMerce uses cookies, browser local storage, and similar technologies for language and country preferences, authentication, workspace selection, analytics, security, and service operation.
Current examples include:
Technology | Purpose | Typical duration |
|---|---|---|
| Remembers or derives the visitor’s country so the site can provide localized content | Up to 30 days |
| Remembers the selected Armenian or English language | Up to 30 days |
| Keeps an authenticated user signed in and authorizes account requests | Until logout, expiry, or browser storage is cleared |
| Remembers the selected ReplyMerce organization or workspace | Until changed, logout, or browser storage is cleared |
Google Analytics technologies | Measures visits, page use, device/browser information, and website performance | According to our analytics configuration and Google’s applicable retention settings; analytics cookies may persist for up to two years |
Security and infrastructure technologies | Protects the website, detects abusive traffic, and delivers content reliably | Session-based or for the period reasonably required for security |
You can manage cookies through your browser and, where available, through the site’s consent controls. Blocking strictly necessary storage may prevent login or other core features from working. Google also provides a browser add-on for opting out of Google Analytics.
8. How We Disclose Personal Data
We may disclose personal data to the following categories of recipients, only as reasonably necessary:
Connected platforms: Meta services, including Facebook and Instagram, WhatsApp Business providers, and any other messaging channel selected by the customer;
AI and voice providers: AI-model, speech-to-text, text-to-speech, and telephony providers, including OpenAI or Twilio when enabled or configured;
Infrastructure and security providers: cloud hosting, databases, content delivery, monitoring, email delivery, backup, and cybersecurity services;
Analytics providers: including Google Analytics for website measurement;
Payment and billing providers: to process subscription payments, payment methods, invoices, and fraud checks;
Commerce and business integrations: such as Magento, Shopify, WooCommerce, CRM tools, or other systems authorized by the customer;
Professional advisers: accountants, lawyers, auditors, insurers, and consultants subject to confidentiality obligations;
Authorities and other parties: when disclosure is required by law, lawful process, or reasonably necessary to protect rights, safety, security, and the integrity of the Service;
Business transaction participants: in connection with a financing, merger, acquisition, restructuring, or sale of assets, subject to appropriate confidentiality and data-protection measures.
We do not sell personal data. We do not share personal data for cross-context behavioral advertising. We do not allow service providers to use customer data for their own unrelated purposes merely because they process it for ReplyMerce.
Third-party platforms remain responsible for the processing they perform under their own terms and privacy notices. A current list of relevant subprocessors may be requested at [email protected].
9. International Data Transfers
ReplyMerce is operated from Armenia. Our customers, end users, connected platforms, and service providers may be located in Armenia, the European Economic Area, the United Kingdom, the United States, or other countries. Personal data may therefore be processed outside the country where it was collected.
Where applicable law requires a transfer mechanism, we use or require appropriate contractual, organizational, or technical safeguards, such as approved standard contractual clauses or equivalent protections. Customers should contact us if they need transfer-related documentation for their use of ReplyMerce.
10. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including providing the Service, following customer instructions, maintaining security, complying with legal and accounting obligations, and resolving disputes.
Retention is generally determined as follows:
account and organization data is retained while the account is active and afterward for the period needed for account closure, legal compliance, dispute resolution, and enforcement;
customer content, knowledge-base data, conversations, and end-user data are retained according to the customer’s settings, instructions, contract, and account status;
integration credentials are retained while the integration remains connected and are deleted or made unusable when the integration or account is removed, subject to security and backup procedures;
billing records are retained for the periods required by tax, accounting, payment, and anti-fraud rules;
support and sales correspondence is retained for as long as needed to manage the relationship and follow up on the request;
security, audit, and technical logs are retained for the period reasonably required to protect, diagnose, and operate the Service;
deleted data may remain temporarily in restricted backups until those backups are overwritten through the ordinary backup cycle.
We may retain limited information longer when required by law, to prevent fraud or abuse, or to establish, exercise, or defend legal claims.
11. Security
We use reasonable technical and organizational measures designed to protect personal data. These measures may include encryption in transit, encryption at rest for integration credentials, logical separation of customer organizations, access controls, authentication, monitoring, backups, and least-privilege practices.
No online service can guarantee absolute security. Customers are responsible for protecting passwords and API keys, managing team access, using secure devices, and promptly disconnecting credentials or users who should no longer have access.
12. Your Privacy Rights
Depending on your location and the applicable law, you may have the right to:
request access to personal data about you;
request correction of inaccurate or incomplete data;
request deletion of personal data;
object to or request restriction of certain processing;
withdraw consent where processing is based on consent, without affecting earlier lawful processing;
request a portable copy of certain data;
opt out of marketing communications;
lodge a complaint with the Personal Data Protection Agency of the Republic of Armenia or another competent supervisory authority;
exercise other rights available under applicable law.
To exercise a right concerning ReplyMerce account or website data, email [email protected]. We may need to verify your identity and clarify the scope of the request. We will respond within the period required by applicable law.
If your request concerns a conversation with a business that uses ReplyMerce, contact that business first. As its processor, we will assist the business in responding where required.
13. Data Deletion Instructions
ReplyMerce customers and account users
To request deletion of your ReplyMerce account or associated personal data:
Email [email protected] from the email address connected to your account.
Use the subject line “Data Deletion Request.”
Include your full name, account email, organization or workspace name, and the specific data or integration you want deleted.
We may ask for additional information to verify that you are authorized to make the request.
Where the request is valid, we will delete or de-identify the relevant data, subject to contractual restrictions, technical backup cycles, fraud-prevention needs, and legal retention obligations.
Instagram, Facebook, WhatsApp, website-chat, or voice end users
If you communicated with a business through one of these channels, contact that business and ask it to delete the conversation or related personal data. You may also email [email protected] with the business or page name, channel, your username or phone number, and enough information to locate the conversation. We may forward the request to the relevant business or ask it to confirm deletion instructions.
Disconnecting a platform integration stops new data from being imported through that integration but does not necessarily delete data already stored in ReplyMerce. Submit a deletion request if previously stored data must also be removed.
14. Marketing Communications
You can unsubscribe from marketing emails by using the unsubscribe link in the message or contacting [email protected]. We may still send non-marketing communications required to operate your account, provide support, deliver security notices, or manage billing.
15. Children
ReplyMerce is a business service and is not directed to children under 18. We do not knowingly collect personal data directly from children for their own use of the Service. If you believe a child has provided personal data to ReplyMerce without appropriate authorization, contact [email protected].
Customers must configure and use ReplyMerce in accordance with laws applicable to children and minors in their markets.
16. Third-Party Links and Services
The Service may link to or integrate with third-party websites and services. Their privacy practices are governed by their own notices and agreements. ReplyMerce is not responsible for a third party’s independent processing.
17. Changes to This Policy
We may update this Privacy Policy to reflect changes in the Service, law, or our data practices. We will post the updated version at https://replymerce.com/privacy and revise the “Last updated” date. If a change materially affects how we use personal data, we will provide additional notice where required.
18. Contact Us
For privacy questions, rights requests, or complaints, contact:
Artashes Baghdasaryan, Individual Entrepreneur
Operator of ReplyMerce
Yerevan, Republic of Armenia
Email: [email protected]
Website: https://replymerce.com
Ready to turn DMs into revenue?
Set up in minutes. Connect Meta, add your catalog, and let AI handle the first reply while your team closes the sale.