Rekly ← Back to Rekly
Legal

Privacy Policy

Last updated: 7 September 2026
Draft for review. This policy is a thorough starting point written to reflect how Rekly actually works. Have it reviewed by a qualified data-protection lawyer, and replace the bracketed company details, before you publish or rely on it.

Rekly helps cafés, bars & restaurants manage their online reputation — answering Google reviews, collecting new ones, and running a digital menu. This policy explains what personal data we handle, why, and the choices you have. We keep it plain, and we don't sell your data.

01Who we are

Rekly is operated by [Rekly — legal entity to be registered] ([company registration no.]), [registered address — Barcelona, Spain]. When this policy says “we”, “us” or “Rekly”, it means that entity. For any privacy question, contact hello@rekly.co.

02Our two roles

Data-protection law (the EU/UK GDPR, and Albania's Law No. 9887 on Personal Data Protection) distinguishes the controller who decides why data is processed from the processor who acts on their instructions. Rekly is both, depending on the data:

03What we collect

CategoryExamplesWhere it comes from
AccountName, email, password (hashed), two-factor settingsYou, at sign-up
Venue & Google dataBusiness name, address, rating, review count and review text, photos, opening hoursYou, and Google's Places / Business Profile APIs
Content you createMenu items, brand-voice settings, owner notes, approved review repliesYou
Guest contactsEmail and/or phone a diner enters to unlock WiFi, on the venue's behalfThe venue's guests
BillingPlan, subscription status, billing email (card details are held by Stripe, never by us)You, via Stripe
Usage & technicalPages viewed, menu-QR opens, device/browser, IP address, log dataAutomatically, as you use the app

We do not intentionally collect special-category data (health, beliefs, and so on). Please don't put it in free-text fields such as owner notes or replies.

04How & why we use it — and our legal basis

Guest contacts captured through WiFi are used only to give the guest the WiFi password and, where the venue has enabled it, to send that guest a review invitation on the venue's behalf. We never reuse one venue's guest contacts for another venue or for our own marketing.

05AI-generated replies

🤝 Honest AI, by design

Rekly drafts review replies with an AI model. To do so, the review text and your venue's context are sent to our AI provider (currently Google's Gemini API; we may use Anthropic's Claude as an alternative). Providers process this to return a reply and, under our terms with them, do not use it to train their models. The AI is grounded — it is instructed never to invent facts, promotions or apologies — and you stay in control: sensitive or low-rated replies are held for your approval, and a run of bad reviews pauses auto-replies and emails you. We never fabricate reviews or gate/ incentivise them.

06Who we share data with

We share data only with service providers (“sub-processors”) that help us run Rekly, each under a contract that protects it. We don't sell personal data. Our providers include:

ProviderPurpose
GooglePlaces & Business Profile APIs — ratings, reviews, posting replies
AI providerGoogle Gemini (default) or Anthropic — drafting review replies
StripeSubscription payments and card processing
Email providerSending transactional email (digests, invites, alerts)
Hosting & infrastructureRunning the app and storing data in the EU

A current list of sub-processors is kept in our DPA. We may also disclose data where required by law, or to a buyer if Rekly is ever acquired (you'll be told first).

07International transfers

We aim to store personal data in the European Economic Area. Some providers (for example Google or our AI provider) may process data outside it; where they do, we rely on safeguards such as the European Commission's Standard Contractual Clauses. For Albania-based venues, transfers follow the requirements of Albanian data-protection law.

08How long we keep it

09Your rights

Subject to the law, you can access your data, correct it, delete it, restrict or object to processing, withdraw consent, and receive a portable copy. Much of this is self-service in the app (edit your profile, export a venue's WiFi contacts, delete your account). For anything else, email hello@rekly.co. If a request concerns data we handle for a venue, we'll pass it to that venue as the controller. You can also complain to a supervisory authority — in Spain, the Spanish Data Protection Agency (AEPD, www.aepd.es).

10Security

We protect data with encryption in transit, hashed passwords, optional two-factor authentication, access controls, and encrypted storage of sensitive tokens. No system is perfectly secure, but we work to keep yours safe and will notify you and the relevant authority of a qualifying breach as the law requires.

11Changes to this policy

We'll update this page when our practices change and revise the “last updated” date above. For material changes we'll give you reasonable notice by email or in the app.

Questions?

Email us at hello@rekly.co and we'll get back to you.

© 2026 Rekly Privacy Terms Cookies DPA Help Home