Reportly AI Ltd — Privacy Policy
Effective date: 5 September 2026
Last updated: 5 September 2026
This policy explains what personal data Reportly AI Ltd collects, why we collect it, what we do with it, and the rights you have over it. We have written it to be read rather than skimmed, and we have tried to avoid saying anything we could not stand behind.
Reportly AI Ltd is a company registered in Northern Ireland. Our registered office is at 3rd Floor, 29 Market Street, Portadown, County Armagh, BT62 3LD, Northern Ireland.
For questions about this policy, to exercise your rights, or to raise a concern, email us at welcome@askreportly.com. A person reads that inbox, and we aim to reply within one business day.
We are not currently required to appoint a Data Protection Officer. Privacy questions are handled directly by our leadership team at the address above.
Reportly handles personal data in two distinct ways, and your rights differ depending on which applies.
We are the controller for the data of our own customers and website visitors — the people who sign up for Reportly, log in, contact us and read our site. We decide why and how that data is used, and this policy governs it.
We are a processor for the data inside a customer's connected store — their orders, their returns, their shoppers. We only ever handle that data on the instruction of the merchant, who is the controller of it. If you are a shopper who bought something from a brand that uses Reportly, and you want your data corrected or erased, please contact that brand directly. They will instruct us, and we will act on it. Our Data Protection statement sets out exactly how we handle that data on their behalf.
When you create an account we collect your name, work email address, password (stored only as a one-way bcrypt hash, never in readable form), company name and, where relevant, your role. When you subscribe, our payment provider Stripe collects and processes your billing details. We receive from Stripe a customer reference, the plan, the billing status and the last four digits and card brand for display. We never receive or store your full card number.
If you contact us — by email, through the contact form, or through the support area of the product — we keep the message, your contact details and our reply, so that we have a record of the conversation and can help you properly next time.
We record how the product is used: pages and features opened, questions typed into the search bar, sync events, plan limits consumed, and errors. Search queries are recorded so we can improve what the product can answer. Where an email address ever appears inside a recorded query it is stripped before storage. We also collect standard technical data such as IP address, browser and device type, and timestamps, largely through error monitoring and server logs.
If you sign up for a trial or subscribe to updates, we hold your email address and name in our email platform so we can send you product news and onboarding help. You can unsubscribe from any message.
When a merchant connects a platform such as Shopify, a Mirakl marketplace, Loop Returns or Criteo, we import commercial data so we can analyse it. That data is mostly not personal — products, quantities, prices, sizes, return reasons. But some of it is, and we would rather be explicit than vague:
We do not import payment details, full postal addresses, or shopper passwords. We do not use this data to contact shoppers, to profile individuals, or to build any product other than the analytics we deliver to the merchant whose store it came from.
| What we do | Why | Lawful basis |
| Create and run your account, provide the product | To deliver what you signed up for | Performance of a contract |
| Take payment, manage subscriptions, send invoices | To be paid, and to keep proper records | Contract, and legal obligation |
| Provide support and respond to you | To help you use the product | Contract, and legitimate interests |
| Monitor errors, security and abuse | To keep the service working and safe | Legitimate interests |
| Improve the product from usage and unanswered questions | To build what customers actually need | Legitimate interests |
| Send product and marketing email | To keep you informed | Consent, or soft opt-in for existing customers |
| Keep financial and tax records | Because we must | Legal obligation |
| Process store data inside a customer's account | To produce their analytics | On the merchant's documented instructions |
Where we rely on legitimate interests, we have considered whether our interest is outweighed by your rights, and we have concluded it is not — but you can object at any time, and we will look at it again properly.
We use a small number of carefully chosen suppliers to run the service. Each is bound by contract to process data only on our instructions and to keep it secure.
| Supplier | What they do for us |
| Neon | Hosts our database |
| Railway | Hosts our application servers and background workers |
| Vercel | Hosts and delivers our web front end |
| Upstash | Caching and queueing |
| Stripe | Payment processing and subscription billing |
| Resend | Transactional email such as sign-in and password reset |
| Klaviyo | Product and marketing email |
| Sentry | Error monitoring, hosted in the EU |
| Anthropic | AI features inside the product |
| Webflow | Hosts this website |
Data is also exchanged with the platforms you choose to connect — Shopify, Mirakl marketplaces, Loop Returns, Criteo — because that is the point of connecting them. Those platforms are separate controllers of the data they hold, and their own privacy policies apply.
Beyond that, we disclose personal data only where we are legally required to, where it is necessary to establish or defend a legal claim, or in connection with a merger or sale of the business — in which case you will be told, and this policy will continue to apply to data transferred until it is replaced by one at least as protective.
Our infrastructure is hosted in the United Kingdom, the European Economic Area and the United States, depending on the supplier. Where personal data leaves the UK or the EEA, we rely on the UK International Data Transfer Addendum, the European Commission's Standard Contractual Clauses, or an adequacy decision, and we carry out the transfer risk assessment those mechanisms require.
You can ask us for details of the safeguards that apply to any particular transfer by emailing welcome@askreportly.com.
Data is encrypted in transit using TLS. Credentials for connected platforms are encrypted at rest. Passwords are stored only as bcrypt hashes and are never recoverable, by us or by anyone else. Every query in the application is scoped to a single customer's organisation, and that scoping has been audited route by route; database-level row security is deployed in enforcing-capable form and can be armed by configuration. Access to production systems is limited to the people who need it. The database is backed up continuously with point-in-time recovery.
Our Data Protection statement describes our security measures in more detail.
We use a small number of cookies and similar technologies. Strictly necessary cookies keep you signed in, keep your session secure and remember your preferences — the product cannot work without them. We also use limited analytics to understand how the site and product are used.
Where consent is required, we ask for it before setting non-essential cookies, and you can change your mind at any time. Most browsers also let you block or delete cookies, though blocking essential ones will stop you being able to sign in.
Under UK and EU data protection law you have the right to:
To exercise any of these, email welcome@askreportly.com. We will respond within one month, and we will not charge you. We may need to verify your identity first. Exercising your rights will never trigger any detriment from us.
If you are a shopper asking about data held inside a merchant's Reportly account, please contact the merchant. We will support them in answering you promptly.
If you are unhappy with how we have handled your data, tell us first at welcome@askreportly.com and we will try to put it right.
You also have the right to complain to a supervisory authority. In the UK that is the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF — telephone 0303 123 1113, or ico.org.uk. If you are in the EEA you may complain to the supervisory authority in the country where you live or work.
Reportly is a business tool. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us and we will delete it.
We will update this policy when the way we handle data changes. The date at the top always shows the current version. If a change materially affects you, we will email you before it takes effect.
Reportly AI Ltd
3rd Floor, 29 Market Street
Portadown, County Armagh
BT62 3LD
Northern Ireland
Email: welcome@askreportly.com
© All rights reserved. Reportly AI LTD.