Reportly AI Ltd — Data Protection and Security
Effective date: 5 September 2026
Last updated: 5 September 2026
This document sets out how Reportly protects the data you connect to us. It is written for the people who have to sign off on a supplier — a founder, an operations lead, a legal or IT reviewer — and it is meant to answer their questions without a call.
It sits alongside our Privacy Policy and our Terms and Conditions, and it forms part of our agreement with you. Where you need a signed Data Processing Agreement for your own records, email welcome@askreportly.com and we will provide one.
When you connect a store to Reportly, you remain the controller of that data. We are your processor. That is not a formality — it is the whole basis on which we handle it.
It means we process your store's data only on your documented instructions, which are given by the act of connecting a platform and using the product. We do not decide what to do with it. We do not repurpose it. If you tell us to stop, we stop; if you tell us to delete, we delete.
We are the controller only for our own customer relationship with you — your account, your billing, your support history. That is covered in our Privacy Policy.
We import commercial data: products, variants, sizes, prices, costs, orders, order lines, returns and return reasons, inventory levels and marketing spend. Almost none of it identifies a person.
Some of it does, and we would rather name it than let you find it later:
We do not import payment card data, full postal addresses, phone numbers, or shopper account credentials. We do not contact your shoppers. We do not profile individuals. Every figure the product produces is an aggregate about products, sizes, channels and time — never about a named person.
Every customer's data lives under its own organisation identifier, and every query the application issues is scoped to a single organisation. That scoping has been audited route by route rather than assumed, and it is covered by automated tests that fail the build if a query loses its scope.
Database-level row security is deployed in enforcing-capable form and can be armed by configuration. We describe it that way deliberately, because we would rather tell you precisely where we are than claim a control we have not yet switched on and verified in production.
Caches, queues and background jobs are namespaced by organisation on the same basis.
Our database is backed up continuously with point-in-time recovery, so we can restore to a moment rather than to yesterday. Backups inherit the same encryption and access controls as the live database and are held with the same provider region.
If a connected platform is unavailable, Reportly keeps serving the data it already holds and resumes importing when the platform returns. Imports are resumable, so an interrupted sync continues from where it stopped rather than starting again.
We use the following sub-processors. Each is engaged under a written contract containing data protection terms at least as protective as ours, and each is used for one clearly defined purpose.
| Sub-processor | Purpose | Region |
| Neon | Primary database | EU / US |
| Railway | Application and worker hosting | EU / US |
| Vercel | Web front-end hosting and delivery | Global edge |
| Upstash | Cache and job queue | EU / US |
| Stripe | Payments and subscription billing | EU / US |
| Resend | Transactional email | EU / US |
| Klaviyo | Product and marketing email | US |
| Sentry | Error monitoring | EU |
| Anthropic | AI features within the product | US |
| Webflow | Marketing website hosting | Global edge |
We will give you at least 30 days' notice by email before adding or replacing a sub-processor that handles your store data, so you have time to object. To be added to that notification list, email welcome@askreportly.com.
Where personal data leaves the UK or the EEA, we rely on the UK International Data Transfer Addendum, the European Commission's Standard Contractual Clauses, or an adequacy decision, and we complete the transfer risk assessment those mechanisms require. We can share the safeguards that apply to any specific transfer on request.
We keep your store data for as long as your account is open, because that history is what the analytics are built on.
When you close your account we retain it for 30 days so you can reactivate or export, and then delete it. You can ask us to delete sooner at any time and we will do so within 30 days. Backups containing deleted data are overwritten on their normal cycle within 90 days.
Deletion is a real deletion across every table that holds your data, not a flag on a row. Where a record must survive for legal or financial reasons — a billing record, for example — it is detached from your account rather than kept whole.
We also honour the platform-level erasure requests that connected platforms send us on your behalf, including Shopify's data request, customer redaction and shop redaction webhooks.
If one of your shoppers asks you for a copy of their data, or asks you to erase it, you are the controller and the request is yours to answer. Tell us at welcome@askreportly.com and we will locate, export or delete the relevant records and confirm back to you, at no charge, within 10 business days — and faster if you are on a deadline.
If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any event within 72 hours of becoming aware of it. We will tell you what happened, what data was affected, what we have done, and what we recommend you do — and we will keep telling you as we learn more, rather than waiting until we have a complete picture.
We will not quietly absorb an incident. If something goes wrong that affects you, you will hear it from us first.
Everyone with access to customer data is bound by confidentiality obligations that survive the end of their engagement, has access limited to what their role requires, and is briefed on how to handle customer data before they are given any.
We are not currently certified to ISO 27001 or SOC 2. We say so plainly rather than implying otherwise. Our controls are the ones described in this document, and we are happy to answer a security questionnaire, walk a reviewer through our architecture, or complete your own vendor assessment. Email welcome@askreportly.com and we will make time.
You may audit our compliance with these commitments once in any 12-month period, on reasonable notice, in a way that does not disrupt the service or compromise another customer's confidentiality.
Data protection questions, DPA requests, security questionnaires and breach queries all go to the same place, and a person reads it.
Reportly AI Ltd
3rd Floor, 29 Market Street
Portadown, County Armagh
BT62 3LD
Northern Ireland
Email: welcome@askreportly.com
You may also complain to the Information Commissioner's Office at ico.org.uk, or to your local supervisory authority in the EEA.
© All rights reserved. Reportly AI LTD.