01What we collect
From everyone who visits remarketly.io
- The page you visited, when, your approximate location (derived from your IP), and the device and browser you used.
- A small set of cookies and similar storage — see Cookies.
- What you typed if you submitted a contact, demo, or waitlist form, plus your IP at submission time.
From people who join our waitlist or book a demo
- Name, email, phone (with country code), WhatsApp number, organisation, country, and the module you said you were interested in.
- Any free-text notes you added and the journey events we recorded after you signed up.
From paying customers and people in their workspace
- Account data: business name, billing address, payment method tokens (held by our payment processor — we never see full card numbers), the people on your team and their roles.
- Operational data: templates you create, conversations your team holds with end customers through our inbox, files you upload, receipts you issue, appointments you schedule, loyalty stamps you award.
- End-customer contacts: people your business has chosen to add to Remarketly. We act as a processor for this data on your behalf — see Our role.
- Audit logs: who did what in your workspace, when, from which IP. Kept for security.
02Why we use it
The short list:
- To run the product you signed up for.
- To bill you and keep tax records.
- To send you the product emails you can’t opt out of (security alerts, billing receipts, terms changes).
- To send you marketing emails — only when you’ve opted in. You can opt out at any time.
- To keep the platform secure — debugging, fraud detection, abuse prevention.
- To show you who’s online in your workspace and when they last signed in.
- To aggregate anonymised statistics, like “customers saved X tonnes of paper this month”.
Where we rely on your consent, you can withdraw it at any time without affecting anything we did before the withdrawal.
03Our role
When you sign up directly with Remarketly — fill in our waitlist form, book a demo, become a paying customer — we are the controller for the data we hold about you.
For the data your business puts into Remarketly about your end customers — names, phone numbers, conversation history, receipts, loyalty stamps — your business is the controller and Remarketly is the processor. We process that data only on your documented instructions.
If one of your end customers asks us to delete the records they have with your business, we’ll route that request to you so you can decide.
04WhatsApp and Meta
When your business sends or receives a message through Remarketly via the WhatsApp Business Platform, the message itself transits Meta’s infrastructure under Meta’s own privacy policy.
- We don’t use the content of your customer conversations to train AI models, target ads, or build profiles of your customers.
- We do use aggregated message metadata (template performance, response times) to power your dashboards.
- If you connect a Meta Business Account to Remarketly, you grant us narrow permissions to manage templates and send messages on your behalf. You can revoke them in Meta Business Manager at any time.
06Who else touches your data
We use a small set of trusted vendors to run the platform. Each is bound by a data-processing agreement. Current list:
| Vendor | What they do |
|---|---|
| Meta (WhatsApp Business API) | Delivers your messages. |
| Amazon Web Services / Hetzner | Application hosting, database, file storage. |
| Cloudflare | CDN, DDoS protection, bot management. |
| Stripe / Telr / Hyperpay | Payment processing. |
| Resend / Postmark / Amazon SES | Transactional email delivery. |
| OpenAI / Anthropic | AI features. Content sent under no-training agreements. |
| Sentry | Error monitoring — stack traces from server crashes. |
Material changes to this list are announced at least 30 days before they take effect.
07How long we keep it
We keep data only as long as we need it for the purpose it was collected for.
| Category | Retention |
|---|---|
| Waitlist submissions (un-converted) | 24 months from your last interaction, then deleted. |
| Customer-account data (active) | For the duration of your subscription. |
| Customer-account data (after cancellation) | 90 days for soft restore, then deleted. Tax records kept as required by law. |
| Conversation / message archive | Default 24 months from message date. Configurable per workspace. |
| Receipts and invoices | As required by local tax law. |
| Audit logs | 12 months minimum. |
| Aggregated anonymised stats | Indefinitely — these no longer identify any individual. |
08Your rights
You can ask us to:
- Send you a copy of the personal data we hold about you.
- Fix anything that’s wrong or out of date.
- Delete your data (subject to any retention required by law, like tax records).
- Pause processing while we sort something out.
- Export your data in a structured, machine-readable format (CSV / JSON).
- Stop processing based on legitimate interests, including direct marketing.
For data we hold as a processor on behalf of a customer business (most end-customer data), make your request to that business directly. We’ll help them respond.
We aim to respond to requests within 30 days. We may ask for proof of identity before acting on a request involving sensitive data.
09Security
- Encryption in transit (TLS 1.2+) for every connection.
- Encryption at rest (AES-256) on every database and file-storage bucket.
- Per-tenant data isolation in the database — your workspace can’t query another customer’s rows.
- Role-based access for our staff with least-privilege defaults. Production access is logged.
- Multi-factor authentication required for admin accounts.
- Regular dependency scanning and penetration testing.
If you spot something that looks like a vulnerability, write to [email protected]. We don’t prosecute good-faith security research.
10Children
Remarketly is a tool for businesses. It’s not aimed at, and not knowingly used by, children under 18. If you believe a child’s data has reached our systems, write to [email protected] and we’ll delete it.
11Changes to this policy
We update this page when our processing changes or when we add a new vendor. Material changes are announced in-product and by email at least 14 days before they take effect. Non-material clarifications (typos, broken links, formatting) are made silently — the “Last updated” date at the top will always be current.
12Contact us
For privacy questions, data-rights requests, or anything else:
- Email — [email protected]
We’d rather hear from you than have you guess at a clause.
