Privacy Policy
Last updated: March 2026
GetSetReply ("we," "us," or "our") respects your privacy and is committed to protecting the personal information you share with us. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data.
1. Data Collected
We collect the following types of information when you use our Service:
- Account information: Your name, email address, and password when you create an account.
- Business information: Business name, address, industry, and connected platform accounts (Google, Yelp).
- Review data: Reviews and ratings imported from your connected platforms, along with any responses you generate or customize through the Service.
- Payment information: Billing details are collected and processed securely by Stripe. We do not store your full credit card number on our servers.
- Customer data you provide: Any data you choose to share with us, including customer contact lists uploaded via CSV, data imported from POS integrations (such as Square, Clover, Toast, or Lightspeed), and any other information you provide through the Service. This data remains in your control — you can delete it at any time by removing contacts or revoking integrations.
- Usage data: Information about how you interact with the Service, including pages visited, features used, and timestamps.
2. How Data Is Used
We use the information we collect for the following purposes:
- Service delivery: To provide, maintain, and improve the GetSetReply platform, including managing your account and connected business profiles.
- AI processing: Review text is sent to our AI providers (including OpenAI and Anthropic) via their APIs to generate response suggestions. This data is processed in real time, is not stored by these providers, and is not used to train third-party models.
- Analytics: To generate insights about your review performance, sentiment trends, and response metrics.
- Communication: To send transactional emails such as account confirmations, billing receipts, and service updates.
- Security: To detect and prevent fraud, abuse, and unauthorized access.
3. Third-Party Services
We rely on trusted third-party providers to operate the Service. Each provider has its own privacy policy governing how they handle data:
- Supabase: Database hosting and user authentication.
- OpenAI: AI-powered response generation. Review text is sent to OpenAI's API for processing. Data sent to OpenAI is not stored and is not used to train their models.
- Anthropic: AI-powered response generation. Review text may be sent to Anthropic's API for processing. Data sent to Anthropic is not stored and is not used to train their models.
- Stripe: Payment processing and subscription management. All payment data is handled in accordance with PCI DSS standards.
- Resend: Transactional email delivery.
- Axiom: Application logging and observability. Logs may contain request metadata but do not include personally identifiable information.
4. Data Retention and Deletion
We retain your data for as long as your account is active or as needed to provide the Service. When you delete your account, we will remove your personal data within 30 days, except where retention is required by law or for legitimate business purposes such as fraud prevention or financial record-keeping.
When you disconnect a platform integration (such as Google, Yelp, or a POS system), we delete all synced data associated with that integration, including imported reviews, responses, and contact records. This deletion happens immediately upon disconnection.
Backups containing your data may persist for up to 90 days after deletion before being permanently removed.
5. User Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request that we correct any inaccurate or incomplete personal data.
- Deletion: Request that we delete your personal data, subject to legal and contractual obligations.
- Portability: Request an export of your data in a machine-readable format.
- Objection: Object to certain processing of your data, such as direct marketing.
To exercise any of these rights, contact us at support@getsetreply.com. We will respond within 30 days.
6. Cookie Usage
GetSetReply uses cookies and similar technologies for the following purposes:
- Authentication: Session cookies to keep you signed in.
- Preferences: To remember your settings and display preferences.
- Analytics: To understand how the Service is used and identify areas for improvement.
You can manage cookie preferences through your browser settings. Disabling cookies may affect the functionality of the Service.
7. Contact for Privacy Inquiries
If you have any questions, concerns, or requests related to this Privacy Policy or our data practices, please contact us:
Email: support@getsetreply.com
We aim to respond to all privacy-related inquiries within 30 calendar days.