Deze pagina is op dit moment alleen in het Engels beschikbaar. De Nederlandse versie volgt. Vragen? info@shipitdigital.nl
Privacy Policy
Rvply Last updated: 3 August 2026
1. Who we are
Rvply is operated by ShipIt Digital, registered in the Netherlands.
| Company | ShipIt Digital |
| KvK number | 85945579 |
| Address | Torresstraat 50, 1056 RV Amsterdam, Nederland |
| info@shipitdigital.nl | |
| Website | https://rvply.nl |
In this policy, "we", "us" and "Rvply" refer to ShipIt Digital. "You" refers to the business that uses Rvply.
2. Our two roles under the GDPR
This distinction matters, because different rules apply to each.
We are a controller for the data of the person who signs up and uses Rvply: your name, email address, company details, billing information and how you use the application.
We are a processor for the data we access on your behalf through the Google Business Profile APIs: your locations and the reviews left on them. You remain the controller of that data. We process it only on your documented instructions, which are given through the settings you configure in the application and through the Data Processing Agreement you accept when you create an account.
3. What data we collect
3.1 Account data (we are controller)
- Name and email address
- Company name, address and VAT number
- The identifier of the identity provider you signed in with. There are no passwords in Rvply, so there is no password to store, leak or reset
- No payment details. Rvply does not take payment yet, so no card or bank data is collected or held anywhere. This line changes when it does, and the sub-processor list changes with it
- Application usage: pages viewed, actions taken, IP address, browser and device type
- Support correspondence
3.2 Google account data (we are processor)
When you connect your Google Business Profile account, we access:
- The list of Business Profile accounts you administer
- The list of locations within those accounts, and their name, address and category
- Reviews on the locations you select: the star rating, the review text, the reviewer's display name as shown publicly on Google, the date, and any existing reply
- An OAuth refresh token, so we can continue to work on your behalf without asking you to sign in repeatedly
We do not access your posts, messages, questions and answers, performance metrics, photos, or any other part of your Business Profile.
3.3 Data we generate
- Draft replies produced for your reviews
- Edits you make to those drafts, and your approval or rejection decisions
- Detected language, sentiment and topic classifications for each review
- An audit log recording which user approved and published which reply, and when
4. Google user data: access, use, storage and sharing
This section describes specifically how Rvply handles data obtained through Google APIs.
4.1 Which scope we request and why
Rvply requests a single scope: https://www.googleapis.com/auth/business.manage.
We use it for four operations, all performed only on locations you already administer:
- To list your Business Profile accounts and locations, so that you can choose which of your own locations to manage in Rvply.
- To read the reviews of the locations you select, so that we can display them to you and draft a reply.
- To publish a reply you have approved, using the review reply endpoint.
- To register a Google Cloud Pub/Sub notification, so that Google can tell us when a new review arrives instead of us polling continuously.
We do not create, edit or delete locations. We do not modify any business information such as opening hours, address, category, attributes or photos.
4.2 Limited Use
Rvply's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We use Google user data only to provide and improve the review management features you signed up for.
- We do not transfer Google user data to third parties except as necessary to provide the service (see section 6), to comply with applicable law, or as part of a merger or acquisition, and then only with notice to you.
- We do not use Google user data for advertising purposes of any kind.
- We do not sell Google user data.
- We do not allow humans to read Google user data, except: where you have given us specific permission, such as when you ask our support team to investigate a problem with a particular review; where it is necessary for security purposes, such as investigating abuse; or where required by law.
- We do not use Google user data to develop, improve or train generalised machine learning models.
4.3 Artificial intelligence and your review data
Rvply sends the text of a review, together with the tone of voice settings you have configured, to Anthropic's Claude API in order to generate a draft reply.
- This is a processing operation performed for you and on your instruction.
- We have contractually disabled the use of this data for model training.
- Anthropic does not retain this data for training purposes.
- We do not use your review data to train any model of our own.
If you do not wish your review text to be processed by an AI provider, Rvply cannot function, as this is the core of the service.
4.4 Storage and deletion of Google data
- OAuth refresh tokens are encrypted at rest using AES-256-GCM. The encryption key is held outside the database.
- Review data is stored for 24 months, after which it is deleted automatically.
- The audit log is retained for 12 months.
- When you disconnect a Google account, we delete the refresh token immediately and stop all access.
- When you delete your Rvply account, all data associated with it, including all Google data, is permanently deleted within 30 days.
5. Why we process your data, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Providing the service you subscribed to | Performance of a contract, Art. 6(1)(b) |
| Billing and accounting | Legal obligation, Art. 6(1)(c) |
| Security, abuse prevention and debugging | Legitimate interest, Art. 6(1)(f) |
| Product analytics to improve the application | Legitimate interest, Art. 6(1)(f) |
| Marketing emails to existing customers | Legitimate interest, with opt-out in every message |
For processing where we rely on legitimate interest, we have carried out a balancing test and concluded that our interest does not override your rights. You may object at any time, see section 8.
6. Who we share data with
We use the following sub-processors. Each is bound by a data processing agreement.
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Application server, database and backups | Nuremberg, Germany (EU) |
| HostArmada (Managed Hosting Ltd) | The public website at rvply.nl | Frankfurt, Germany (EU) |
| Anthropic PBC | Generating draft replies | United States, under EU Standard Contractual Clauses |
| Resend, Inc. | Transactional email delivery | United States, under EU Standard Contractual Clauses |
The current list is always available at https://rvply.nl/subprocessors. We will notify you at least 30 days before adding a new sub-processor, and you may object.
We do not sell your data to anyone, under any circumstances.
7. Where your data is stored
All primary storage is within the European Union. Where a sub-processor is established outside the EU, the transfer is covered by the European Commission's Standard Contractual Clauses together with supplementary technical measures, principally encryption in transit and at rest.
8. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you
- Have inaccurate data corrected
- Have your data erased
- Restrict or object to processing
- Receive your data in a portable, machine-readable format
- Withdraw consent at any time, where processing is based on consent
- Lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens
To exercise any of these, email info@shipitdigital.nl. We respond within 30 days.
Note on reviewers: if a person who left a review contacts us about their data, we will direct them to you, because you are the controller of that data. We will assist you in responding.
9. Security
- All traffic is encrypted with TLS
- Data is encrypted at rest
- OAuth tokens are encrypted separately, with the key held outside the database
- Access to production systems is restricted to named personnel and protected by multi-factor authentication
- We keep an audit log of every action taken on your data within the application
No system is perfectly secure. In the event of a personal data breach affecting you, we will notify you without undue delay and in any case within 72 hours of becoming aware of it, in line with Art. 33 GDPR.
10. Cookies
We place two cookies, both of them first-party: one that keeps you signed in, and one that remembers whether you read the interface in Dutch, English or Turkish. Neither requires consent, because a service you asked for cannot be delivered without them.
We place no analytics cookies, no advertising cookies and no third-party cookies, on the application or on the marketing site. That is why there is no cookie banner: there is nothing to consent to. If we ever add something that does require consent, we will ask before placing it.
The full list, with names and durations, is in our Cookie Statement.
11. Children
Rvply is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16.
12. Changes to this policy
We may update this policy. If a change materially affects how we handle your data, we will notify you by email at least 30 days before it takes effect. The date at the top of this page always shows the current version.
13. Contact
ShipIt Digital Torresstraat 50, 1056 RV Amsterdam, Nederland info@shipitdigital.nl KvK 85945579