Last updated: October 2, 2026
Responde.app is a service operated by Daniel Romero Herencia (D-U-N-S 373963083), a registered self-employed professional based in Spain (hereinafter, "the Provider"), with contact address at hola@responde.app.
Responde.app collects and processes the following data:
Processing is based on the Provider's legitimate interest in delivering the contracted service, the user's consent when starting a conversation, and the execution of the contract with client organizations.
When a store installs the Responde application on Shopify, read-only access to products, inventory and orders is requested (read_products, read_inventory, read_orders). This access is used exclusively to answer store customer queries in real time. Access tokens are stored securely and encrypted. The application does not sell, share or transfer Shopify data to third parties.
The store owner can revoke access at any time from their Shopify admin panel under Settings → Apps and sales channels.
When a Responde.app customer connects their Facebook Page, Instagram Business account or WhatsApp Business number to the assistant, they authorize access through Meta's official OAuth flow. The permissions we request and why we use them:
pages_messaging — receive and reply to direct messages sent to the customer's Facebook Page through Messenger. Without this permission the assistant cannot read incoming messages or send replies on behalf of the page.pages_show_list and pages_manage_metadata — list the Facebook Pages the admin manages and store the access token of the selected page to connect it to the assistant.pages_manage_engagement — reply to comments on Page posts when the admin enables automatic comment replies.instagram_basic — identify the Instagram Business account linked to the connected Facebook Page.instagram_manage_messages — receive and reply to direct messages sent to the customer's Instagram account.instagram_manage_comments — reply to comments on Instagram posts when the admin enables it.business_management — list the admin's Business Accounts so they can pick which one to connect (needed when a user manages several businesses).Data received (message contents, sender identifier, timestamp) is used solely so the connected customer's assistant can produce its reply. It is not shared with other Responde.app customers, not used to train general AI models, and not sold to third parties. Each customer has full isolation of their conversations.
Data is stored on servers located in the European Union (provider: Hetzner Online GmbH, Germany). The admin can disconnect their Facebook, Instagram or WhatsApp account at any time from Settings → Channels in their Responde.app panel, which revokes all tokens and stops message receipt.
End users (people who send messages to the connected accounts) can request deletion of their data at any time using Meta's official flow: Facebook/Instagram → Settings → Your data and permissions → Apps and websites → Responde.app → Delete. That request triggers our POST /api/data-deletion-callback endpoint, registers the request with a traceable confirmation code, and removes the associated data. The deletion status can be checked at the URL returned by that endpoint.
Responde.app distributes native iOS and Android apps published on the App Store and Google Play under each client organization's name (town hall, school, business). The Provider signs the code and maintains the developer accounts.
Data the mobile app collects:
What we do NOT do: we do not track your activity across other apps or third-party websites, we do not share data with advertising networks, we do not sell information to third parties, and we do not access your contacts, photos or microphone.
You can disable notifications at any time from your operating system settings or from the app's own menu.
To request deletion of all your data, write to hola@responde.app with the organization's name and your session identifier (found in Settings → About). We will process the request within 30 days.
Users may exercise their rights of access, rectification, erasure, restriction, portability and objection by sending an email to hola@responde.app. Shopify store owners may contact the Provider directly to request deletion of their integration data.
Responde.app applies technical and organizational measures to protect data: encryption in transit (HTTPS/TLS), storage on European servers, role-based access control and secure authentication.
The service uses the following trusted providers that may process data on behalf of the Provider:
For any questions about this policy, write to us at hola@responde.app.