Privacy Policy
Effective 16 August 2026
Who we are
WarmReply ("we", "us") is operated by Arsen Asatryan, an individual based in Yerevan, Armenia. WarmReply connects Yelp lead conversations with the HighLevel CRM on behalf of the businesses that install it. Contact: [email protected].
Two kinds of people, two roles
Customers are the businesses and agencies that install WarmReply. For their data we act as a data controller.
Consumers are the people who contact our customers through Yelp. We process their conversation data on the customer's behalf and under the customer's instructions, acting as a processor. The business you contacted, not WarmReply, decides how your inquiry is handled; direct requests about your data to that business first.
What we collect
- Account data (customers): CRM location identifiers, OAuth access tokens for the CRM connection, your Yelp business page identifiers and names, plan and setup state, and the email address of the CRM user who opens WarmReply, so we can send you setup help and the advance notice of material changes these terms promise.
- Lead conversation data (consumers, on customers' behalf): names as shown on Yelp, message text, project details (job type, location area, requested dates), Yelp's masked email addresses, and phone numbers when a consumer chooses to share one.
- Operational data: delivery logs, timestamps, error reports.
- Website analytics: the marketing site (warmreply.io) uses Google Analytics to measure visits, which sets Google's analytics cookies in your browser. The WarmReply app inside your CRM sets no cookies and carries no analytics, and we use no advertising cookies anywhere.
- Usage records (customers): how many Yelp leads your account received each month, derived from the conversation records above and used only for service health and fair-use review — there are no per-lead charges and no usage billing. No card or payment details; billing is handled by HighLevel and we never see them.
What we use it for
- Delivering the service: syncing conversations between Yelp and the CRM, sending the greetings customers configure, keeping contact records up to date.
- Reliability and support: delivery tracking, deduplication, diagnosing failures.
- Billing: handled entirely by the HighLevel marketplace. We never see or store card numbers.
We do not sell personal data, and we do not use conversation content for advertising or for training AI models.
Where it lives (subprocessors)
- Cloudflare: application hosting and networking (global edge).
- Supabase / AWS: database (United States region).
- Zapier: transport between Yelp and WarmReply.
- HighLevel: the CRM where conversations are delivered (your own account).
- Sentry: error monitoring (technical error context; no authentication tokens).
- Zoho Mail: support email.
- Resend: sending service notifications to customers (customer email addresses only; never a consumer's).
- Google Analytics: visit measurement on the marketing site only; never inside the app, and never any conversation data.
Retention
- Delivered reply texts are removed from our database as soon as we confirm delivery. If that removal does not go through, a clean-up job that runs every six hours removes it on its next pass. We keep the delivery status, not the message body.
- Reply texts we have not delivered (still queued, or failed to reach Yelp) are kept for up to 90 days so that the reply can be retried, and are then removed as well, leaving only the delivery status.
- Raw Yelp lead payloads are removed after 30 days, once they are past the window in which a failed delivery can be replayed. This covers both copies we hold: the one stored against the conversation and the one inside the delivery record, which is stripped of the consumer's name, message text, phone number and email at the same 30 days while the delivery record itself is kept.
- Delivery logs and deduplication records are purged after 90 days.
- Conversation mappings (which Yelp thread corresponds to which CRM contact and conversation) are kept while WarmReply is installed, so threads stay connected.
- Account and setup data (your CRM identifiers, Yelp page registry, greeting templates, connection settings and billing records) is kept for as long as the account exists, because the product cannot work without it. It is not on a timer; it goes when the account is deleted, on request or after uninstall as described below.
- After uninstall there is a 30-day reinstall grace period. After it, the CRM access tokens are erased and the conversation mappings for that account are deleted. A scheduled clean-up does this rather than a fixed deadline, so it takes effect shortly after the 30 days elapse and, if a pass fails, on a later one.
- On request, at any time, we delete everything we hold for an account. See "Your rights" below.
Security
All traffic is encrypted in transit (TLS). Access tokens are stored encrypted at the infrastructure level and are never exposed to browsers or third parties. Webhooks from the CRM are cryptographically signature-verified. Access to production systems is limited to the operator.
Your rights
You may request access to, correction of, or deletion of your personal data, or object to its processing, by emailing [email protected]. We answer within 30 days. Consumers should contact the business they messaged first, since that business controls the conversation; we support our customers in fulfilling such requests. Depending on where you live, these rights may be backed by laws such as the GDPR or the California Consumer Privacy Act.
Children
WarmReply is a business tool and is not directed at children under 16; we do not knowingly collect their data.
Changes
We will post any changes to this policy on this page with a new effective date, and notify customers by email for material changes.