First 50 subscribes get 25% OFF!

Privacy Policy

Last updated: 18.02.2026

1. Introduction and Scope

This Privacy Policy (“Policy”) sets forth the comprehensive practices of Rappelo (“Company”, “we”, “us”, or “our”) regarding the collection, utilization, disclosure, and protection of personal information pertaining to individuals (“you”, “your”, or “User”) who interact with our platform, website, and lead management services (collectively, the “Services”).

As an entity established in Romania, we are committed to upholding rigorous data protection standards, including the General Data Protection Regulation (GDPR) for our European users and applicable United States federal and state privacy laws for our North American clientele, where relevant.

Please read this Privacy Policy carefully to understand our policies and practices for collecting, processing, and storing your information. By using our Services, you acknowledge that your personal data will be processed in accordance with this Privacy Policy and applicable data protection laws. If you do not agree with our policies and practices, your choice is not to use our Services.

If you have any concerns, questions, or feedback regarding privacy, please contact us at privacy@rappelo.com . We reserve the right to amend this Policy at our discretion. Where required by applicable law, we will provide notice of material changes. Your continued interaction with our Services following the posting of such changes constitutes your acceptance of the revised Policy.

2. Legal Capacity and Roles

Under applicable data protection laws, the roles are defined as follows:

  • Data Controller: You (the subscriber of Rappelo ) are the Data Controller for any personal information pertaining to your prospective customers (“Leads”) collected via our embeddable forms.
  • Data Processor: Rappelo acts as the Data Processor and processes Lead data strictly in accordance with your documented instructions for the purpose of providing notification and reminder services.
  • Data Controller (Independent): Rappelo acts as a Data Controller with respect to your account information (e.g., name, email address, billing details) necessary to administer your subscription, comply with legal obligations, and prevent fraudulent or unauthorized use.

Where required by applicable law, such processing activities are governed by a Data Processing Agreement (DPA) incorporated by reference into this Privacy Policy.

3. Categories of Information We Collect

A. Information Provided by You

Account identifiers (such as name and professional email address) and billing information (such as billing address, subscription plan, payment status, and transaction identifiers). Financial transactions are processed securely via Stripe, and we do not store sensitive cardholder data on our servers.

B. Automatically Collected Information

Technical metadata, including IP addresses, browser types, and unique device identifiers, collected for purposes of fraud prevention (e.g., monitoring trial abuse) and platform security. Platform usage and performance data may also be collected via Google Analytics, subject to IP anonymization and user consent, where required by applicable law.

C. Lead Information

Information submitted by your Leads (such as names, email addresses, and phone numbers), processed exclusively to trigger your “Instant Notifications” and “Follow-up Reminders” in accordance with your instructions.

4. Third-Party Sub-processors and Data Transfers

A. Third-Party Service Providers

We engage the following third-party service providers (sub-processors) to support the operation and delivery of our Services, where applicable and as necessary:

  • Vercel: Infrastructure hosting
  • Supabase: Database storage.
  • Resend: Communication and email delivery infrastructure.
  • Stripe: Secure payment processing and PCI-compliant transactions.
  • Google Analytics: Utilized for platform performance and usage insights. To ensure a high standard of privacy, IP anonymization is enabled, ensuring that full IP addresses are never stored on Google’s servers. Analytics tracking is initiated only after explicit user consent is obtained via our cookie management interface, in compliance with the GDPR and the ePrivacy Directive.

B. International Data Transfers

Where personal data is transferred outside of your jurisdiction, including to countries such as the United States, we ensure that such transfers are safeguarded through appropriate legal mechanisms, including the European Commission’s Standard Contractual Clauses (SCCs), together with any additional measures required to ensure an equivalent level of data protection.

5. Data Retention and Security

Data Retention Policy: We retain Account Data for the duration of your active subscription. Lead Data is stored for as long as your account remains active. Usage Logs and IP Data are retained for up to 90 days. Upon account termination, personal data is deleted or anonymized within a reasonable timeframe, unless retention is required by law.

Security Measures: We implement industry-standard protocols, including TLS encryption for data in transit and AES-256 encryption for data at rest.While no method of transmission over the internet or electronic storage is completely secure, we implement and continuously improve industry-standard technical and organizational measures to safeguard your personal information.

6. Your Rights and Data Control

Subject to applicable data protection laws, you have the following rights regarding your personal data:

Right to Erasure

Request deletion of your data. We apply a 30-day temporary restriction period (soft deletion) to prevent accidental loss before permanent removal.

Access & Data Portability

Request access to your personal data and obtain a copy in a commonly used, machine-readable format.

Right to Rectification

Request the correction of inaccurate or incomplete personal data associated with your account.

Restriction of Processing

Request that we limit the processing of your personal data under certain circumstances.

Right to Object

Object to processing based on our legitimate interests (e.g., fraud prevention metadata).

Withdraw Consent

Withdraw consent at any time where processing is based on your prior agreement.

We will respond to all verified requests within the timeframes required by applicable law, and in any event within 30 days. You also have the right to lodge a complaint with your local data protection authority (e.g., ANSPDCP in Romania).

7. Regional and Age Specifics

California (CCPA/CPRA)

We do not sell your personal information to third-party data brokers.

California residents may exercise their rights to access, delete, or opt out of the sale of their personal information by contacting us directly. We do not discriminate against residents for exercising these rights, ensuring equal service and pricing regardless of privacy choices.

Children's Privacy (COPPA/GDPR)

Our services are not directed at minors, and we do not knowingly collect personal information from children under the age of 13 (or under 16 in specific jurisdictions, such as the EU). If we learn that we have collected personal information from a child under the applicable age, we will promptly delete such information and close the account, unless verifiable parental consent is obtained.

8. User Responsibilities as a Data Controller

As a user of Rappelo , you are primarily responsible for maintaining your own Privacy Policy and ensuring that you have a valid legal basis for collecting information from your visitors through our lead capture forms.

While we provide tools to help facilitate compliance with applicable data protection laws, we do not verify or guarantee the legal basis for your processing activities. It is your obligation to ensure that your data collection practices meet the requirements of your local jurisdiction.

9. Updating this Privacy Policy

We reserve the right to change, modify, add, or remove portions of this Privacy Policy at any time. Material changes that may affect your rights or the way we process your personal data will be communicated to you via email at least 30 days prior to the update taking effect.

We encourage you to check this page periodically for any updates. Your continued use of this Site following the posting of changes to this Privacy Policy constitutes your acknowledgment and acceptance of the updated Policy.

Contact

Questions about our Privacy Policy?

privacy@rappelo.com