Legal

Privacy Policy

Last updated: June 16, 2026

1. Introduction & Scope

This policy explains how Raddly (available at raddly.net, referred to as “we,” “us,” or “the Service”) collects, uses, and protects your data when you use our website, dashboard, or any related service. By using the Service, you agree to the practices described here. If you do not agree with any part of it, please stop using the Service and contact us.

2. Data We Collect

  • Account data: your name, email, password (encrypted), or your Google sign-in identifier, and your phone number if you add one.
  • Business data: your business name, branches, category, and brand voice (the tone you choose for replies) as entered in your settings.
  • Google Business Profile data: your business profile information, the reviews posted on it, and their replies — detailed in Section 4.
  • Billing data: processed by our external payment provider; we never store your card numbers on our servers.
  • Usage data: technical logs (number of replies generated, sync times, system errors) used to operate and improve the Service and to calculate your plan quota.
  • Contact messages: the name, email, and message you submit through our “Contact us” form.

3. How We Use Your Data

We use the data above exclusively to:

  • Sync your business reviews and display them in your dashboard.
  • Generate AI-suggested replies and publish the ones you approve to Google.
  • Manage your subscription and track your monthly reply quota.
  • Notify you of new reviews and important service alerts.
  • Improve service quality and fix issues.
  • Respond to your inquiries and comply with legal requirements.

We do not sell or rent your personal data to any third party, and we do not use it for advertising.

4. Google Data & Limited Use

Raddly accesses your Google Business Profile data exclusively through Google’s secure OAuth 2.0 protocol, requesting only the single minimum scope required to operate, namely https://www.googleapis.com/auth/business.manage. You sign in on Google’s own page during connection, so we never receive or store your Google account username or password; we receive only a short-lived, revocable access token that you can revoke at any time. This access is limited to your business profile information (name and branches), the reviews posted on it, and their replies — the minimum necessary for the Service to function. We do not access your email, contacts, files, or any other service in your Google account.

  • We use this data only to provide the features visible to you inside Raddly: we fetch your locations’ reviews and display them on your private dashboard, and we send the replies you approve (whether you wrote them yourself or they were generated by AI and approved by you) to the Google API to publish on your Google Maps profile — and for no other purpose.
  • We do not transfer it to any third party except to provide the Service itself (Section 6), to comply with applicable law, or as part of a merger or acquisition under the same safeguards.
  • We never use or transfer it for advertising purposes.
  • We never use or transfer it to train generalized AI models or to develop machine-learning models beyond providing the feature to you.
  • No employee accesses it except with your consent (such as a support request), for security purposes, or to comply with law.
  • You can revoke our access at any time from your Raddly settings or your Google account permissions page, after which we delete the Google data associated with your account.

Raddly's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. AI & Your Data

To generate a suggested reply, the review text and your business context (name and chosen tone) are sent to our AI model provider (Anthropic) under contractual agreements that prohibit using your data to train its models. Generated replies are stored in your account for you to review and approve, and none are published to Google without your explicit approval (or in line with the Auto-Pilot settings that you enable yourself).

6. Sharing With Third-Party Processors

We rely on service providers that process data on our behalf and only on our instructions, each contractually bound to protect it: application hosting (Vercel), database and authentication (Supabase), reply generation (Anthropic), payment processing (our billing provider), and Google’s APIs to sync reviews and publish replies. There is no other sharing except under a court order or a binding legal requirement.

7. Storage, Security & Retention

Your data is encrypted in transit (TLS) and at rest, and each customer’s data is isolated from others through Row-Level Security (RLS) access policies, with internal privileges restricted to the minimum necessary. We retain your data for as long as your account is active; when you delete your account, your personal data and the associated Google data are deleted within 30 days, except where the law requires us to retain it (such as billing records).

8. Your Rights (PDPL, GDPR & CCPA)

Saudi Personal Data Protection Law (PDPL): you have the right to be informed how your data is processed, to request a copy of it, to correct inaccurate data, to request its deletion or destruction once the purpose no longer applies, and to withdraw your consent to processing.

General Data Protection Regulation (GDPR) — for users in the EU/EEA: in addition to the above, you have the right to restrict processing, to data portability (receiving your data in a structured format), to object to processing, not to be subject to purely automated decisions, and to lodge a complaint with your competent supervisory authority. Our processing relies on one or more legal bases: your consent, performance of the contract with you, or our legitimate interest in operating and securing the Service.

California Consumer Privacy Act (CCPA/CPRA) — for California residents: you have the right to know the categories of data we collect and the purpose, to request its deletion or correction, to opt out of any “sale” or “sharing” of it, and not to receive discriminatory treatment for exercising your rights. We confirm that we do not sell your personal data and do not share it for cross-site behavioral advertising within the meaning of this law.

To exercise any of these rights, email us at the address in Section 10, and we will respond within the periods set by applicable law and free of charge.

9. Cookies & measurement

We use strictly necessary cookies only: your login session and your language preference. We do not use advertising trackers, we do not sell your data, and we do not track you across other sites. Disabling these cookies in your browser will prevent sign-in.

We use visitor measurement from Vercel (our hosting provider) to see how many people reach each page and where they came from. It sets no cookies, creates no persistent identifier for you, does not follow you to other sites, and collects nothing that identifies you personally. Measurement is at the page level, not the person level.

10. Changes & Contact

We may update this policy from time to time; for any material change we will notify you by email or an in-dashboard notice before it takes effect, and the “last updated” date always appears at the top of the page. For any privacy question, email us at info@raddly.net or via our Contact page.

See also our Terms of Service — together they form your agreement with Raddly.