← Back to responde.app

Privacy Policy

Last updated: October 2, 2026

1. Data controller

Responde.app is a service operated by Daniel Romero Herencia (D-U-N-S 373963083), a registered self-employed professional based in Spain (hereinafter, "the Provider"), with contact address at hola@responde.app.

2. Data we collect

Responde.app collects and processes the following data:

  • Conversation data: messages sent by users to the virtual assistant. They are stored linked to an anonymous session identifier.
  • Voluntary contact data: name, phone number and/or email if the user provides them in the chat to be assisted by a human agent.
  • Administrator data: email and password (encrypted) of administration panel users.
  • Panel usage: when you use the responde panel with your account, we record which screens you open and for how long, without storing anything you type in them.
  • Connected Shopify store data: Shopify API access token, store domain and product/order data queried in real time. Responde.app does not permanently store Shopify order or customer data.

3. Purpose of processing

  • Provide the virtual assistant service to end users of client organizations.
  • Allow administrators to manage the content and configuration of their assistant.
  • Integrate with Shopify to answer queries about products, stock and order status in real time.
  • Improve service quality through aggregated and anonymized conversation analysis.

4. Legal basis

Processing is based on the Provider's legitimate interest in delivering the contracted service, the user's consent when starting a conversation, and the execution of the contract with client organizations.

5. Shopify integration

When a store installs the Responde application on Shopify, read-only access to products, inventory and orders is requested (read_products, read_inventory, read_orders). This access is used exclusively to answer store customer queries in real time. Access tokens are stored securely and encrypted. The application does not sell, share or transfer Shopify data to third parties.

The store owner can revoke access at any time from their Shopify admin panel under Settings → Apps and sales channels.

5.a Meta integration (Facebook, Instagram, WhatsApp Business)

When a Responde.app customer connects their Facebook Page, Instagram Business account or WhatsApp Business number to the assistant, they authorize access through Meta's official OAuth flow. The permissions we request and why we use them:

  • pages_messaging — receive and reply to direct messages sent to the customer's Facebook Page through Messenger. Without this permission the assistant cannot read incoming messages or send replies on behalf of the page.
  • pages_show_list and pages_manage_metadata — list the Facebook Pages the admin manages and store the access token of the selected page to connect it to the assistant.
  • pages_manage_engagement — reply to comments on Page posts when the admin enables automatic comment replies.
  • instagram_basic — identify the Instagram Business account linked to the connected Facebook Page.
  • instagram_manage_messages — receive and reply to direct messages sent to the customer's Instagram account.
  • instagram_manage_comments — reply to comments on Instagram posts when the admin enables it.
  • business_management — list the admin's Business Accounts so they can pick which one to connect (needed when a user manages several businesses).
  • WhatsApp Business Platform — receive and reply to messages sent to the customer's connected WhatsApp Business number via the official WhatsApp API.

Data received (message contents, sender identifier, timestamp) is used solely so the connected customer's assistant can produce its reply. It is not shared with other Responde.app customers, not used to train general AI models, and not sold to third parties. Each customer has full isolation of their conversations.

Data is stored on servers located in the European Union (provider: Hetzner Online GmbH, Germany). The admin can disconnect their Facebook, Instagram or WhatsApp account at any time from Settings → Channels in their Responde.app panel, which revokes all tokens and stops message receipt.

End users (people who send messages to the connected accounts) can request deletion of their data at any time using Meta's official flow: Facebook/Instagram → Settings → Your data and permissions → Apps and websites → Responde.app → Delete. That request triggers our POST /api/data-deletion-callback endpoint, registers the request with a traceable confirmation code, and removes the associated data. The deletion status can be checked at the URL returned by that endpoint.

5.b Native mobile apps

Responde.app distributes native iOS and Android apps published on the App Store and Google Play under each client organization's name (town hall, school, business). The Provider signs the code and maintains the developer accounts.

Data the mobile app collects:

  • Device token (Firebase Cloud Messaging / APNs): unique identifier needed to send push notifications. Not linked to your name or email unless you sign in.
  • Session identifier: a random UUID generated on-device the first time you open the app. Used to link your chat conversations with reply notifications.
  • Contact details (name, email, phone): only if you voluntarily provide them to receive a response to a ticket, booking or incident report.
  • Approximate location (only if you open the "map" section and grant permission): used exclusively to center the tourism map near you. Not stored on our servers.

What we do NOT do: we do not track your activity across other apps or third-party websites, we do not share data with advertising networks, we do not sell information to third parties, and we do not access your contacts, photos or microphone.

You can disable notifications at any time from your operating system settings or from the app's own menu.

To request deletion of all your data, write to hola@responde.app with the organization's name and your session identifier (found in Settings → About). We will process the request within 30 days.

5.c Panel usage

  • Why: to know which screens are used and which are not, and improve the product.
  • Who sees it: the per-person detail is only seen by the responde team. Your company never sees it person by person: at most, by departments of at least three people.
  • Legal basis: our legitimate interest in improving the service your company subscribes to.
  • How long it is kept: 13 months.
  • How to opt out: at any time, from your panel preferences ("Don't measure my panel use"). From then on nothing more is recorded.

6. Data retention

  • Chat conversations: retained while the contract with the client organization is in force.
  • Voluntary contact data: until the user requests deletion or the contract expires.
  • Shopify data: the access token is deleted if the administrator disconnects the integration from the panel.
  • Visit statistics: 90 days for the detail and 25 months for the totals.
  • Panel usage: 13 months.

7. User rights

Users may exercise their rights of access, rectification, erasure, restriction, portability and objection by sending an email to hola@responde.app. Shopify store owners may contact the Provider directly to request deletion of their integration data.

8. Security

Responde.app applies technical and organizational measures to protect data: encryption in transit (HTTPS/TLS), storage on European servers, role-based access control and secure authentication.

9. Third-party providers

The service uses the following trusted providers that may process data on behalf of the Provider:

  • OpenAI — AI response generation (chat messages)
  • Google (Gemini) — semantic embeddings for content search
  • Supabase — database and authentication
  • Firebase Cloud Messaging (Google) — push notifications to Android and iOS mobile apps
  • Apple Push Notification Service (APNs) — push notifications on iOS devices (routed through Firebase)
  • Shopify — store integration (only for store-type organizations)
  • Stripe — subscription payment processing (affects only customer administrators, not end users)
  • DB-IP — the “IP to City Lite” database, used to estimate the approximate country, region and city from the IP address. No visitor data is sent to them: the database is downloaded and queried on our servers. IP Geolocation by DB-IP, CC BY 4.0 license.

10. Contact

For any questions about this policy, write to us at hola@responde.app.