RemarketlyEvery scan saves a tree🌱
Product ▾
QR Commerce
Turn every surface into a storefront
AI Conversation
GPT-4o agents, multi-language
WhatsApp Commerce
Catalog · cart · checkout in chat
Remarketing
Segments, broadcasts, A/B tests
WhatsApp CRM
Unified contact database
Analytics & BI
AI insights, attribution
Digital Receipts
POS-linked WhatsApp receipts
Digital Stamp CardNEW
Stamps + scratch & win loyalty
Green BookNEW
Paperless visitor logbook
RequestNEW
Scan → chat → accept → delivered
Events & TicketsNEW
Invites · RSVP · QR tickets · check-in
See all eleven pillars
Industries ▾
Restaurants
Bookings, orders, receipts
Retail
Loyalty, restock alerts, POS
Salons & Spa
AI booking, deposits, rebook
Hotels
Concierge, F&B, in-stay
Clinics
Triage, intake, recall
Real Estate
Viewings, lead capture, listing alerts
Browse every industry
🌱SustainabilityFree QRBlog
Join Waitlistالعربية
← Home
Legal · Remarketly

Privacy Policy

What we collect, why we collect it, how long we keep it, and what you can do about it.

Effective 26 May 2026·Last updated 26 May 2026

We collect the minimum we need to run the product. We don’t sell your data, we don’t share it with advertisers, and you can ask us to delete it any time.

On this page
  1. 01What we collect
  2. 02Why we use it
  3. 03Our role
  4. 04WhatsApp and Meta
  5. 05Cookies
  6. 06Who else touches your data
  7. 07How long we keep it
  8. 08Your rights
  9. 09Security
  10. 10Children
  11. 11Changes to this policy
  12. 12Contact us
Questions about this document?
[email protected]

01What we collect

From everyone who visits remarketly.io

  • The page you visited, when, your approximate location (derived from your IP), and the device and browser you used.
  • A small set of cookies and similar storage — see Cookies.
  • What you typed if you submitted a contact, demo, or waitlist form, plus your IP at submission time.

From people who join our waitlist or book a demo

  • Name, email, phone (with country code), WhatsApp number, organisation, country, and the module you said you were interested in.
  • Any free-text notes you added and the journey events we recorded after you signed up.

From paying customers and people in their workspace

  • Account data: business name, billing address, payment method tokens (held by our payment processor — we never see full card numbers), the people on your team and their roles.
  • Operational data: templates you create, conversations your team holds with end customers through our inbox, files you upload, receipts you issue, appointments you schedule, loyalty stamps you award.
  • End-customer contacts: people your business has chosen to add to Remarketly. We act as a processor for this data on your behalf — see Our role.
  • Audit logs: who did what in your workspace, when, from which IP. Kept for security.
What we DON’T collect. We don’t fingerprint your device for ad-tech, we don’t buy enriched data about you from data brokers, and we don’t install third-party advertising pixels on our site.

02Why we use it

The short list:

  • To run the product you signed up for.
  • To bill you and keep tax records.
  • To send you the product emails you can’t opt out of (security alerts, billing receipts, terms changes).
  • To send you marketing emails — only when you’ve opted in. You can opt out at any time.
  • To keep the platform secure — debugging, fraud detection, abuse prevention.
  • To show you who’s online in your workspace and when they last signed in.
  • To aggregate anonymised statistics, like “customers saved X tonnes of paper this month”.

Where we rely on your consent, you can withdraw it at any time without affecting anything we did before the withdrawal.

03Our role

When you sign up directly with Remarketly — fill in our waitlist form, book a demo, become a paying customer — we are the controller for the data we hold about you.

For the data your business puts into Remarketly about your end customers — names, phone numbers, conversation history, receipts, loyalty stamps — your business is the controller and Remarketly is the processor. We process that data only on your documented instructions.

If one of your end customers asks us to delete the records they have with your business, we’ll route that request to you so you can decide.

04WhatsApp and Meta

When your business sends or receives a message through Remarketly via the WhatsApp Business Platform, the message itself transits Meta’s infrastructure under Meta’s own privacy policy.

  • We don’t use the content of your customer conversations to train AI models, target ads, or build profiles of your customers.
  • We do use aggregated message metadata (template performance, response times) to power your dashboards.
  • If you connect a Meta Business Account to Remarketly, you grant us narrow permissions to manage templates and send messages on your behalf. You can revoke them in Meta Business Manager at any time.

05Cookies

The cookies and local-storage entries we set:

NamePurposeRetention
rm_sessionKeeps you signed in to your Remarketly workspace.30 days
rm_csrfCross-site request forgery protection on form submissions.Session
mk-themeYour dark/light mode choice.Until cleared
rm_refReferral attribution — which channel introduced you. No cross-site tracking.30 days
__cf_bm (Cloudflare)Bot management — distinguishes humans from automated traffic.30 minutes

We don’t use third-party advertising cookies. Anything we add to that list in future will appear in this table before it ships.

06Who else touches your data

We use a small set of trusted vendors to run the platform. Each is bound by a data-processing agreement. Current list:

VendorWhat they do
Meta (WhatsApp Business API)Delivers your messages.
Amazon Web Services / HetznerApplication hosting, database, file storage.
CloudflareCDN, DDoS protection, bot management.
Stripe / Telr / HyperpayPayment processing.
Resend / Postmark / Amazon SESTransactional email delivery.
OpenAI / AnthropicAI features. Content sent under no-training agreements.
SentryError monitoring — stack traces from server crashes.

Material changes to this list are announced at least 30 days before they take effect.

07How long we keep it

We keep data only as long as we need it for the purpose it was collected for.

CategoryRetention
Waitlist submissions (un-converted)24 months from your last interaction, then deleted.
Customer-account data (active)For the duration of your subscription.
Customer-account data (after cancellation)90 days for soft restore, then deleted. Tax records kept as required by law.
Conversation / message archiveDefault 24 months from message date. Configurable per workspace.
Receipts and invoicesAs required by local tax law.
Audit logs12 months minimum.
Aggregated anonymised statsIndefinitely — these no longer identify any individual.

08Your rights

You can ask us to:

  • Send you a copy of the personal data we hold about you.
  • Fix anything that’s wrong or out of date.
  • Delete your data (subject to any retention required by law, like tax records).
  • Pause processing while we sort something out.
  • Export your data in a structured, machine-readable format (CSV / JSON).
  • Stop processing based on legitimate interests, including direct marketing.

For data we hold as a processor on behalf of a customer business (most end-customer data), make your request to that business directly. We’ll help them respond.

We aim to respond to requests within 30 days. We may ask for proof of identity before acting on a request involving sensitive data.

09Security

  • Encryption in transit (TLS 1.2+) for every connection.
  • Encryption at rest (AES-256) on every database and file-storage bucket.
  • Per-tenant data isolation in the database — your workspace can’t query another customer’s rows.
  • Role-based access for our staff with least-privilege defaults. Production access is logged.
  • Multi-factor authentication required for admin accounts.
  • Regular dependency scanning and penetration testing.

If you spot something that looks like a vulnerability, write to [email protected]. We don’t prosecute good-faith security research.

10Children

Remarketly is a tool for businesses. It’s not aimed at, and not knowingly used by, children under 18. If you believe a child’s data has reached our systems, write to [email protected] and we’ll delete it.

11Changes to this policy

We update this page when our processing changes or when we add a new vendor. Material changes are announced in-product and by email at least 14 days before they take effect. Non-material clarifications (typos, broken links, formatting) are made silently — the “Last updated” date at the top will always be current.

12Contact us

For privacy questions, data-rights requests, or anything else:

  • Email — [email protected]

We’d rather hear from you than have you guess at a clause.

Plain talk. Real humans.

We’d rather answer a question than have you guess at a clause. Email [email protected] — we typically reply the same business day.

Talk to us
Remarketly

The complete WhatsApp business operating system. Built for the Gulf, the wider MENA region, and Southeast Asia.

Product
All 11 pillarsQR CommerceAI ConversationWhatsApp CommerceRemarketingCRMAnalyticsDigital ReceiptsDigital Stamp Card NEWGreen Book NEWRequest NEWEvents & Tickets NEWFranchise Management NEW
Industries
All industriesRestaurantsRetailSalons & SpaHotelsClinicsReal EstateTravel & Tours NEWEducation NEWGyms & Fitness NEW
Resources
Free QR code generatorGreenFlip · Living CatalogWhatsApp API pricing guideWhatsApp Business glossary NEWMessage template library NEWPricing calculator NEWSaudi Arabia (KSA) NEWPhilippines NEWSustainability · save treesRemarketly Forever NEWForest partnersForest methodologyJoin the waitlistBlogGoing paperless guideQR code playbook
Company
Join the waitlist 🌱About RemarketlyBook a demoSign inContact usPrivacyTermsData deletion
© 2026 Remarketly · Every scan saves a tree 🌱
v1.0 · Paperless, by design · Personalized AI trained on your business
العربية