Legal

Privacy Policy

Effective date: 21 May 2026Last updated: 25 May 2026
Plain-English summary: Resparo connects to the review platforms you use to read your reviews and publish replies on your behalf. We use your business information to personalise your AI responses. We store only what we need, never sell your data, and you can delete everything at any time.

1Who we are

Resparo (“Resparo”, “we”, “us”, or “our”) is a software service that provides an AI-powered review response platform for local businesses.

This Privacy Policy explains how we collect, use, store, and protect personal data when you use our website at resparo.io and our services.

By using Resparo, you agree to the collection and use of information in accordance with this policy.

2Data we collect

Account and business information

  • Your name and email address (used to create your account and send notifications)
  • Business name, type, and location
  • Your business’s voice profile (tone preferences, personality settings, context notes)
  • Industry category and any custom instructions you provide

Connected review platform data

When you connect a review platform, we collect and store:

  • Access and refresh tokens (used to read reviews and publish replies on your behalf)
  • The account email address associated with the connection
  • Review content, reviewer names, ratings, and review dates
  • Your reply history
  • The account and location identifiers needed to route replies

Payment information

All payment processing is handled by our payment provider, which acts as Merchant of Record. Resparo does not collect, store, or process your payment card details. We receive only confirmation of your subscription status and plan tier.

Usage data

  • Number of AI replies generated and published
  • Features used and settings configured
  • Email open and click events (for notification emails)
  • Browser type, operating system, and IP address
  • Pages visited on resparo.io and time spent

Communications

If you contact us by email, we store your messages and email address to respond to you and improve our support.

3How we use your data

We use the data we collect for the following purposes:

To provide the service

  • Monitor your connected review platforms for new reviews
  • Generate AI-powered responses personalised to your business voice
  • Publish approved replies on your behalf
  • Send you email notifications when new reviews arrive
  • Enforce your free tier limits and paid subscription entitlements

To improve the service

  • Analyse aggregated, anonymised usage patterns to improve response quality
  • Identify and fix bugs and performance issues
  • Develop new features based on how the product is used

To communicate with you

  • Send transactional emails (new review alerts, approval confirmations, billing notifications)
  • Send product updates and important announcements
  • Respond to support requests

Legal basis (GDPR)

For users in the European Economic Area and United Kingdom, our legal bases for processing are:

  • Contract performance: processing necessary to deliver the service you signed up for
  • Legitimate interests: improving the service, preventing fraud, and security monitoring
  • Consent: connecting your review platforms via authorisation (OAuth)
  • Legal obligation: complying with applicable laws
We never sell your personal data to third parties. We never use your review content or business information to train AI models without your explicit consent.

4Service providers

Resparo relies on a small set of third-party service providers to operate. Each processes data only as needed to deliver the service, under its own privacy policy and data processing terms:

  • The review platforms you connect: accessed through their official APIs and your explicit authorisation, used only for the scopes you grant
  • An AI provider: review content and your business context are sent to generate response suggestions; this provider does not use the data to train its models by default
  • A payment provider (Merchant of Record): handles billing, tax, and subscriptions
  • A cloud infrastructure provider: hosts the application and database
  • An email provider: sends transactional and notification emails

5Data storage and security

Your data is stored on our cloud infrastructure provider’s global network, with processing occurring in the region closest to the request origin.

Security measures

  • All data transmitted between your browser and Resparo is encrypted via HTTPS/TLS
  • Access tokens are encrypted at rest
  • Access to production systems is restricted to authorised personnel only
  • Our payment provider handles all payment card data. We never store card numbers

Data retention

  • Account data is retained while your account is active
  • Review response history is retained for 12 months after generation
  • Access tokens are deleted immediately when you disconnect a platform or delete your account
  • Upon account deletion, all personal data is removed within 30 days
  • Anonymised, aggregated usage statistics may be retained indefinitely

6Your rights

Depending on your location, you may have the following rights regarding your personal data:

Rights for all users

  • Access: request a copy of the personal data we hold about you
  • Deletion: request deletion of your account and all associated data
  • Correction: update inaccurate personal information in your account settings
  • Disconnect: revoke a connected platform’s access at any time from your dashboard
  • Export: request a portable copy of your data

Additional rights for EEA/UK users (GDPR)

  • Restriction: request that we restrict processing in certain circumstances
  • Object: object to processing based on legitimate interests
  • Withdraw consent: withdraw previously given consent at any time
  • Lodge a complaint: file a complaint with your local data protection authority

Rights for California users (CCPA)

California residents have the right to know what personal information we collect, the right to delete personal information, and the right to opt out of the sale of personal information. We do not sell personal information.

Rights in other regions

If you reside in another region with its own data protection law, you may have additional rights to access, correct, or request deletion of your personal data. Contact us to exercise them.

To exercise any right, email us at privacy@resparo.io. We will respond within 30 days.

7Cookies

Resparo uses minimal cookies necessary to operate the service:

  • Session cookies: keep you logged in during your browser session
  • Authentication cookies: store your login state securely
  • Preference cookies: remember your settings

We do not use advertising cookies or tracking cookies from third-party ad networks, and we do not run third-party analytics or advertising pixels on our platform.

8Children's privacy

Resparo is a business tool intended for adults operating local businesses. We do not knowingly collect personal data from individuals under the age of 16. If you believe a minor has provided us with personal data, please contact us and we will delete it promptly.

9International data transfers

Resparo operates globally. When you use our service, your data may be processed in countries outside your own through our service providers. These transfers are made subject to appropriate safeguards, including standard data processing agreements with those providers.

By using Resparo, you consent to the transfer of your data to these countries for the purposes described in this policy.

10Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and update the “Last updated” date at the top of this page. Your continued use of Resparo after changes are posted constitutes acceptance of the updated policy.

11Contact us

If you have any questions about this Privacy Policy, want to exercise your data rights, or need to report a privacy concern, please contact us:

  • Email: privacy@resparo.io
  • Response time: we aim to respond to all privacy requests within 30 days