Privacy Policy
Effective 13 August 2026
Who we are
WarmReply ("we", "us") is operated by Arsen Asatryan, an individual based in Yerevan, Armenia. WarmReply connects Yelp lead conversations with the HighLevel CRM on behalf of the businesses that install it. Contact: hello@warmreply.io.
Two kinds of people, two roles
Customers — businesses and agencies that install WarmReply. For their data we act as a data controller.
Consumers — people who contact our customers through Yelp. We process their conversation data on the customer's behalf and under the customer's instructions, acting as a processor. The business you contacted — not WarmReply — decides how your inquiry is handled; direct requests about your data to that business first.
What we collect
- Account data (customers): CRM location identifiers, OAuth access tokens for the CRM connection, your Yelp business page identifiers and names, plan and setup state.
- Lead conversation data (consumers, on customers' behalf): names as shown on Yelp, message text, project details (job type, location area, requested dates), Yelp's masked email addresses, and phone numbers when a consumer chooses to share one.
- Operational data: delivery logs, timestamps, error reports. We do not use analytics trackers or advertising cookies; the marketing site sets no cookies at all.
What we use it for
- Delivering the service: syncing conversations between Yelp and the CRM, sending the greetings customers configure, keeping contact records up to date.
- Reliability and support: delivery tracking, deduplication, diagnosing failures.
- Billing: handled entirely by the HighLevel marketplace — we never see or store card numbers.
We do not sell personal data, and we do not use conversation content for advertising or for training AI models.
Where it lives (subprocessors)
- Cloudflare — application hosting and networking (global edge).
- Supabase / AWS — database (United States region).
- Zapier — transport between Yelp and WarmReply.
- HighLevel — the CRM where conversations are delivered (your own account).
- Sentry — error monitoring (technical error context; no authentication tokens).
- Zoho Mail — support email.
Retention
- Delivered reply texts are removed from our database shortly after delivery; we keep delivery status, not message bodies.
- Deduplication records are purged on a rolling basis.
- Conversation mappings are kept while the account is active so threads stay connected.
- After uninstall, access tokens are purged after a 30-day reinstall grace period; account data is deleted on request at any time.
Security
All traffic is encrypted in transit (TLS). Access tokens are stored encrypted at the infrastructure level and are never exposed to browsers or third parties. Webhooks from the CRM are cryptographically signature-verified. Access to production systems is limited to the operator.
Your rights
You may request access to, correction of, or deletion of your personal data, or object to its processing, by emailing hello@warmreply.io. We answer within 30 days. Consumers should contact the business they messaged first, since that business controls the conversation; we support our customers in fulfilling such requests. Depending on where you live, these rights may be backed by laws such as the GDPR or the California Consumer Privacy Act.
Children
WarmReply is a business tool and is not directed at children under 16; we do not knowingly collect their data.
Changes
We will post any changes to this policy on this page with a new effective date, and notify customers by email for material changes.