Legal
Privacy Policy
Last updated: September 4, 2026
This Privacy Policy explains how Reapdat Staging("we," "us," or "our") collects, uses, stores, and protects your information when you use our platform and services.
1. Data Controller
The data controller responsible for your personal information is Reapdat Inc., a company incorporated in Canada with its registered office at 6 Willick Place, Brampton, Ontario, L6X 4Z5, Canada. For any questions relating to how we process your personal data, or to exercise the rights described in this policy, contact us at info@reapdat.in.
Reapdat Staging is operated by Reapdat Inc. In this policy, "we," "us," and "our" refer to Reapdat Inc. This policy covers the Reapdat web platform at reapdat.in and the Reapdat mobile app for Android and iOS. The web portal and the mobile app are the same account and the same data; the app is a companion to your existing Reapdat account, and accounts are created on the web.
2. Information We Collect
When you use Reapdat Staging, we collect information that you provide directly and information generated through your use of our services. This includes:
- Account information: name, email address, phone number, company name, and billing details provided during registration.
- Sign-in information: if you choose to sign in with Google, Google provides us with the email address, name and Google account identifier for the account you select. We do not receive your Google password, and we request no access to your Gmail, Drive or contacts. Signing in with Google on the mobile app does not create a Reapdat account — if the address you pick has no account, we tell you so and nothing is stored.
- Service data: AI call transcripts, chat logs, booking records, lead details, and knowledge base documents you upload.
- Usage analytics: pages visited, features used, session duration, and interaction patterns to improve our platform. This is measured on our own servers, not by third-party analytics cookies.
- Device and technical data: IP address, browser type, operating system, and device identifiers collected automatically.
- Advertising and measurement identifiers: if you consent to advertising cookies on our website, small identifiers set by Meta Platforms and by us (listed in the Cookies section) that record which campaign brought a browser to our site and whether it later took an action such as requesting a demo or creating an account. If you decline, these are not collected at all. This applies to our website only, never to the mobile app.
- Communication records: emails, support tickets, and other correspondence with our team.
- Mobile device session: when you sign in on the mobile app we issue a long-lived sign-in token so you are not asked to sign in every time you open it. It is stored in your device's own secure keystore, is tied to that device, expires after 60 days, and is revoked when you sign out. We record a device label so you can recognise the device in your account, along with the IP address and approximate location (country and city) of each sign-in, which we use to detect suspicious access.
- Files you choose to share from the app: photos and documents you pick from your device to upload as branding images or knowledge base content. The app reads only the files you select, and only when you select them.
The mobile app does not use push notification tokens. Its alerts are generated on the device itself, so no notification identifier is created, sent to us, or shared with Google or Apple. The app also keeps a short diagnostic log on the device, visible to you under Manage, which never leaves the device unless you choose to share it with our support team.
3. How We Use Your Information
We use the information we collect to provide, maintain, and improve our services. Specifically:
- Deliver and operate Reapdat services (chat widget, voice, email agent, bookings) on your behalf.
- Process bookings, manage leads, and sync data with your connected CRM systems.
- Train and improve your AI agent using the knowledge base documents you provide (your data is never used to train other tenants' agents).
- Send transactional notifications: booking confirmations, lead alerts, and system status updates.
- Analyze aggregate, anonymized usage patterns to improve platform performance and reliability.
- Detect and prevent fraud, abuse, and security incidents.
- Comply with legal obligations and respond to lawful requests from authorities.
- Measure how well our own advertising works, where you have consented — so we can tell which campaigns bring people who find Reapdat Staging useful, and stop paying for the ones that do not. Within Reapdat Staging, this information plays no part in your account, your pricing, or the service you receive. Meta's own use of the data it receives is governed by Meta's privacy policy rather than ours.
4. Data Storage and Security
Your data is stored on secure servers with industry-standard protections:
- Production databases are hosted on PostgreSQL 16 with pgvector, running in isolated Docker containers.
- All data in transit is encrypted with TLS 1.3.
- All data at rest is encrypted using AES-256 encryption.
- CRM credentials and OAuth tokens are encrypted with Fernet AES-128 before storage.
- Access to production systems is restricted by role-based access controls and audit logging.
- We conduct regular vulnerability assessments and penetration testing (VAPT).
5. Data Encryption
Reapdat Staging employs multiple layers of encryption to protect your information:
- Transport encryption: All API communication uses HTTPS with TLS 1.3. HTTP Strict Transport Security (HSTS) is enforced.
- Credential encryption: CRM API keys, OAuth tokens, and webhook secrets are encrypted using Fernet symmetric encryption before storage. Only encrypted values (prefixed with enc:) are persisted.
- Token security: JWT authentication tokens use HS256 signing. Token blacklisting is managed via Redis with SHA-256 hashed keys.
- Password hashing: User passwords are hashed using bcrypt with per-user salts. Plaintext passwords are never stored or logged.
6. Data Retention
We retain your data only as long as necessary to provide our services and comply with legal obligations:
- Active account data is retained for the duration of your subscription.
- Call transcripts and chat logs are retained for 12 months after creation, unless you request earlier deletion.
- Audit logs are retained for 24 months for compliance and security purposes.
- After account deletion, all associated data is permanently removed within 30 days, except where retention is required by law.
- You can export or delete your data at any time from the portal dashboard.
For step-by-step instructions on deleting your account — from the web portal, from the mobile app, or by email — including a full list of what is deleted and what we are obliged to keep, see our Account Deletion page.
7. Information About Outreach Recipients
In addition to processing data for our paying customers, Reapdat Inc. operates a limited business-to-business outreach program. If you are receiving a one-time email or WhatsApp message from us about a personalized AI front desk assistant demo built for your business, the following describes the personal data we processed in connection with that contact.
Sources of information: business name, public website URL, public phone, public email, public address, and publicly visible reviews — all sourced from your business's own website and public business directories (such as Google Maps). We do not purchase contact lists, and we do not extract data from any private database.
Purpose: to evaluate whether your business is a likely fit for Reapdat's AI front desk assistant product, to build a one-time personalized demo at a temporary URL (e.g., reapdat.com/c/your-business-name), and to send a single introductory message inviting you to try the demo.
Legal basis: implied consent under section 10(9)(b) of Canada's Anti-Spam Legislation (CASL) where your business has conspicuously published its contact details for business inquiries; legitimate interest under Article 6(1)(f) GDPR balanced against your rights; legitimate use under section 4 of India's DPDP Act 2023 for voluntarily published contact details; and the identification, opt-out, and physical-address requirements of the US CAN-SPAM Act for email messages.
Retention: if you do not engage with our message, your contact details and the personalized demo are automatically deleted within 90 days. If you engage (open, click, or reply), your record is retained as part of our sales engagement history until you ask us to delete it.
Your rights: you may unsubscribe from email by clicking the Unsubscribe link in any message, opt out of WhatsApp by replying STOP, ask us to delete the demo URL we built for your business by emailing outreach@reapdat.com, and request deletion of all personal data we hold by emailing privacy@reapdat.com.
For a complete explanation of our outreach practices, see our public Outreach Notice at https://reapdat.com/outreach-notice.
We are not affiliated with the businesses we contact for outreach. Any use of a business name in a demo URL or chat is nominative use to identify which business the demo is showcasing and does not imply any commercial relationship or endorsement.
8. Third-Party Services
We integrate with the following third-party services to deliver our platform. Each processes data in accordance with their own privacy policies:
- Twilio: Telephony infrastructure for voice calls and SMS delivery.
- OpenAI: Language model inference for chat, transcription, and embedding generation.
- Google: Calendar API for booking availability, Gemini for LLM fallback, and Google Sign-In (via Google Play Services on Android) when you choose to sign in with a Google account.
- Stripe: Payment processing for subscriptions and billing.
- CRM Providers (HubSpot, Salesforce, Pipedrive, Zoho, Odoo, HaloPSA, Freshsales, Close, Copper, Monday.com, Keap, Insightly): Data sync when you connect your CRM account.
- Google Play and the Apple App Store: distribute the mobile app. They receive install and crash information under their own policies. Reapdat does not sell subscriptions through either store, and the app contains no in-app purchase.
- Meta Platforms (Facebook, Instagram): advertising measurement, on our website only and only if you consent. When you do, we tell Meta that something happened on our own site — for example that a demo was requested, or an account was created — so we can see which of our advertising campaigns actually worked. Sent with it are the advertising identifiers described in the Cookies section, your IP address, and basic information about the browser you used. If you typed contact details into that form, such as an email address, they are turned into a fingerprint (a SHA-256 hash) before they leave our servers, so the details themselves are never transmitted.
The measurement described above covers our own public website only. It never includes anything from a Reapdat Stagingaccount: no call transcripts, no chat logs, no leads, no bookings, no knowledge base content, and no data belonging to our customers' own end-users. The mobile app is not part of it at all — the app contains no advertising or analytics software, makes no connection to Meta, and nothing you do inside the app is shared for advertising.
We do not sell or rent your personal information. We do not share it so that a third party can market to you on their own behalf. The advertising measurement described above is for our own campaigns, uses only activity on our own public website, and happens only with your consent — which you can withdraw at any time.
9. Cookies
We use cookies and similar technologies on our website in three categories. Only the first two are set without asking you.
- Strictly necessary — always on. Authentication cookies (HttpOnly, Secure, SameSite=Lax) holding your session token, and cookies used for security and rate limiting. The site cannot keep you signed in without them, and they are never used for advertising.
- Preferences — always on, and stored only in your browser. Your theme choice. This never leaves your device and is not shared with anyone.
- Advertising and measurement — off unless you turn it on. If you consent, Meta Platforms sets _fbp in your browser, and _fbc if you arrived from one of our ads. These let us tell whether an advertisement we paid for led to someone requesting a demo or creating an account. We also set one cookie of our own, rd_attr, which records only which campaign brought you to the site, so that we can credit it if you later sign up. It holds no contact details, is read only by us, and is kept for 90 days. If you decline, none of these are set at all.
Your choice, and how to change it: the first time you visit we ask which categories you allow. You may decline everything except the strictly necessary and preference cookies, and the site works normally. You can change or withdraw your choice at any time using the Cookie settings link in the footer of every page.
Withdrawing consent stops both the cookies in your browser and the corresponding server-side measurement described in the Third-Party Services section. We do not treat the two separately.
The mobile app sets no cookies of any kind and contains no advertising or analytics software.
10. Legal Bases for Processing
Where the UK or EU GDPR applies, we rely on the following legal bases:
- Performance of a contract: operating your account and delivering the services you subscribe to.
- Consent: advertising cookies and the related measurement described in the Third-Party Services and Cookies sections. You can withdraw at any time using the Cookie settings link in the footer, and withdrawal does not affect anything done before you withdrew.
- Legitimate interests: keeping the platform secure, preventing fraud and abuse, and improving reliability. We rely on this only where it does not override your rights.
- Legal obligation: tax and accounting records, and responding to lawful requests from authorities.
The legal bases for our business-to-business outreach program are set out separately in the Information About Outreach Recipients section above.
If you believe we have handled your personal data improperly, you may complain to your data protection authority: in Canada, the Office of the Privacy Commissioner of Canada; in the United Kingdom, the Information Commissioner's Office; in the EEA, the supervisory authority for your country. We would prefer you raise it with us first, at the contact address below.
11. Your Rights (GDPR)
If you are located in the European Economic Area, United Kingdom, or Canada, you have the following rights under applicable data protection laws:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure: Request deletion of your personal data (subject to legal retention requirements). See our Account Deletion page for how to do this yourself or ask us to.
- Right to data portability: Receive your data in a structured, machine-readable format.
- Right to restrict processing: Request that we limit how we use your data.
- Right to object: Object to processing based on legitimate interests.
- Right to withdraw consent: Where processing is based on consent, withdraw it at any time.
To exercise any of these rights, contact us at info@reapdat.in. We will respond within 30 days.
12. Children's Privacy
Reapdat Staging is not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that a child under 16 has provided us with personal information, we will take steps to delete such information promptly. If you believe a child has provided us with personal data, please contact us at info@reapdat.in.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, or legal requirements. When we make material changes:
- We will update the "Last Updated" date at the top of this page.
- For significant changes, we will notify you via email or a prominent notice in the portal dashboard.
- Continued use of our services after changes become effective constitutes acceptance of the updated policy.
14. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us:
- Email: info@reapdat.in
- Phone: +1-437-655-6573
- Registered office: Reapdat Inc., 6 Willick Place, Brampton, Ontario, L6X 4Z5, Canada