Privacy Policy
Last updated: 7 September 2026Rekly helps cafés, bars & restaurants manage their online reputation — answering Google reviews, collecting new ones, and running a digital menu. This policy explains what personal data we handle, why, and the choices you have. We keep it plain, and we don't sell your data.
01Who we are
Rekly is operated by [Rekly — legal entity to be registered] ([company registration no.]), [registered address — Barcelona, Spain]. When this policy says “we”, “us” or “Rekly”, it means that entity. For any privacy question, contact hello@rekly.co.
02Our two roles
Data-protection law (the EU/UK GDPR, and Albania's Law No. 9887 on Personal Data Protection) distinguishes the controller who decides why data is processed from the processor who acts on their instructions. Rekly is both, depending on the data:
- We are the controller of the data about our own customers — the venue owners and staff who hold a Rekly account (your name, email, login, venue, billing).
- We are a processor for the personal data a venue's guests leave through Rekly — for example an email address entered to unlock the WiFi. There, the venue is the controller: it decides to collect that data and we only handle it to provide the service. Those arrangements are governed by our Data Processing Agreement.
03What we collect
| Category | Examples | Where it comes from |
|---|---|---|
| Account | Name, email, password (hashed), two-factor settings | You, at sign-up |
| Venue & Google data | Business name, address, rating, review count and review text, photos, opening hours | You, and Google's Places / Business Profile APIs |
| Content you create | Menu items, brand-voice settings, owner notes, approved review replies | You |
| Guest contacts | Email and/or phone a diner enters to unlock WiFi, on the venue's behalf | The venue's guests |
| Billing | Plan, subscription status, billing email (card details are held by Stripe, never by us) | You, via Stripe |
| Usage & technical | Pages viewed, menu-QR opens, device/browser, IP address, log data | Automatically, as you use the app |
We do not intentionally collect special-category data (health, beliefs, and so on). Please don't put it in free-text fields such as owner notes or replies.
04How & why we use it — and our legal basis
- To provide the service — sync your Google reviews, draft and (once you connect Google) post replies, run your menu and WiFi capture, show insights. Basis: performance of our contract with you.
- To send service email — the weekly digest, incident alerts, and important account notices. Basis: contract / legitimate interests; the digest is a preference you can switch off.
- To take payment and prevent fraud. Basis: contract and legal obligation.
- To improve and secure Rekly — troubleshooting, analytics, abuse prevention. Basis: legitimate interests, balanced against your rights.
- To comply with the law — tax, accounting, and lawful requests. Basis: legal obligation.
Guest contacts captured through WiFi are used only to give the guest the WiFi password and, where the venue has enabled it, to send that guest a review invitation on the venue's behalf. We never reuse one venue's guest contacts for another venue or for our own marketing.
05AI-generated replies
Rekly drafts review replies with an AI model. To do so, the review text and your venue's context are sent to our AI provider (currently Google's Gemini API; we may use Anthropic's Claude as an alternative). Providers process this to return a reply and, under our terms with them, do not use it to train their models. The AI is grounded — it is instructed never to invent facts, promotions or apologies — and you stay in control: sensitive or low-rated replies are held for your approval, and a run of bad reviews pauses auto-replies and emails you. We never fabricate reviews or gate/ incentivise them.
06Who we share data with
We share data only with service providers (“sub-processors”) that help us run Rekly, each under a contract that protects it. We don't sell personal data. Our providers include:
| Provider | Purpose |
|---|---|
| Places & Business Profile APIs — ratings, reviews, posting replies | |
| AI provider | Google Gemini (default) or Anthropic — drafting review replies |
| Stripe | Subscription payments and card processing |
| Email provider | Sending transactional email (digests, invites, alerts) |
| Hosting & infrastructure | Running the app and storing data in the EU |
A current list of sub-processors is kept in our DPA. We may also disclose data where required by law, or to a buyer if Rekly is ever acquired (you'll be told first).
07International transfers
We aim to store personal data in the European Economic Area. Some providers (for example Google or our AI provider) may process data outside it; where they do, we rely on safeguards such as the European Commission's Standard Contractual Clauses. For Albania-based venues, transfers follow the requirements of Albanian data-protection law.
08How long we keep it
- Account & venue data — while your account is active, then deleted or anonymised within a reasonable period after you close it.
- Guest contacts — kept for the venue as controller; deleted on the venue's instruction, when a contact opts out, or when the venue leaves Rekly.
- Billing records — retained as long as tax and accounting law requires (typically several years).
- Logs — kept for a short period for security and troubleshooting.
09Your rights
Subject to the law, you can access your data, correct it, delete it, restrict or object to processing, withdraw consent, and receive a portable copy. Much of this is self-service in the app (edit your profile, export a venue's WiFi contacts, delete your account). For anything else, email hello@rekly.co. If a request concerns data we handle for a venue, we'll pass it to that venue as the controller. You can also complain to a supervisory authority — in Spain, the Spanish Data Protection Agency (AEPD, www.aepd.es).
10Security
We protect data with encryption in transit, hashed passwords, optional two-factor authentication, access controls, and encrypted storage of sensitive tokens. No system is perfectly secure, but we work to keep yours safe and will notify you and the relevant authority of a qualifying breach as the law requires.
11Changes to this policy
We'll update this page when our practices change and revise the “last updated” date above. For material changes we'll give you reasonable notice by email or in the app.
Email us at hello@rekly.co and we'll get back to you.