Privacy Policy

Last updated: June 9, 2026

This Privacy Policy explains how CodeLab Software LLP ("ReplyZap", "we", "us") collects, uses, shares, and protects information when you use ReplyZap at replyzap.com and our connected services. We process data in accordance with applicable law (including the GDPR and the CCPA/CPRA where they apply) and with Meta's Platform Terms and Developer Policies.

1. Information We Collect

Account data: your name, email address, and a hashed password when you sign up.

Meta Platform Data: when you connect your Instagram Professional account and Facebook Page through Meta's official OAuth login, we receive only the data the permissions you grant allow - typically your basic profile, account/Page IDs, and the messaging and comment events you authorize us to handle on your behalf (for example, comments containing a keyword you choose and the direct messages our automations send or receive). We request only the Meta permissions needed to run the features you enable.

Usage data: standard analytics such as page views and click events collected through Google Analytics, Google Tag Manager, and PostHog to improve the product.

2. How We Use Information

We use the information to operate the service (run triggers, send and receive DMs, reply to comments, store your templates and settings); to authenticate you and secure your account; to communicate with you about your account and support; to process payments; and to improve the product. We have a clear, limited purpose for each use, and we use Meta Platform Data only to provide the ReplyZap features you have enabled.

3. Meta Platform Data - Our Commitments

In line with Meta's Platform Terms and Developer Policies:

  • We do not sell, license, or rent Meta Platform Data.
  • We do not use Meta Platform Data to build user profiles, for advertising, or for any purpose other than providing ReplyZap to you.
  • We do not transfer Meta Platform Data to data brokers or any party other than the service providers needed to operate the platform.
  • We use Meta data only within the scope of the permissions you granted, and only while your account remains connected.

4. Legal Bases (where GDPR applies)

We process data to perform our contract with you (providing the service), based on your consent (for the Meta connection and analytics cookies), and for our legitimate interests in securing and improving the service.

5. Sharing

We share data only with service providers that help us operate the platform - cloud hosting, email delivery, analytics, and payment processing - and only as needed to provide the service. We may disclose data where required by law or to comply with a Meta enforcement action. We never sell personal data.

6. Data Retention

We keep account data while your account is active. Meta access tokens are deleted when you disconnect your account. Message, comment, and trigger history is retained for up to 30 days for delivery and support purposes, then deleted, unless we are required to keep it longer by law.

7. Data Deletion and Your Rights

You can ask us to access, correct, export, or delete your personal data at any time. You have several ways to delete your data:

  • Disconnect: removing your Instagram/Facebook connection inside ReplyZap immediately revokes our access and deletes the stored Meta access tokens.
  • Delete your account: deleting your ReplyZap account removes your account data and associated Meta Platform Data from our active systems.
  • Email request: email hello@replyzap.in with the subject "Data Deletion" and we will delete your data and confirm within 30 days.
  • Data Deletion page: see our dedicated Data Deletion Instructions for step-by-step guidance.

When you delete your account or remove the ReplyZap app from your Meta settings, we delete the associated Meta Platform Data without undue delay, except where it has been de-identified or we are legally required to retain it. Residents of the EEA, UK, and California also have rights to object to or restrict processing and to lodge a complaint with their data protection authority.

8. Data Storage & Security

Data is stored on encrypted infrastructure with reputable cloud providers. We use industry-standard safeguards including TLS in transit and encrypted backups. No method of transmission or storage is completely secure, but we work to protect your data.

9. International Transfers

We may process and store data in countries other than your own. Where required, we apply appropriate safeguards for international data transfers.

10. Cookies & Analytics

This site uses cookies for essential functionality and for analytics (Google Analytics, Google Tag Manager, PostHog). You can disable analytics cookies via your browser settings.

11. Children

ReplyZap is not directed to children under 16, and we do not knowingly collect their personal data.

12. Changes

We may update this policy. Material changes will be announced in-product or by email, and the "Last updated" date above will change.

13. Contact

Questions or requests? Email hello@replyzap.in. Data controller: CodeLab Software LLP.