Privacy Policy
Privacy Policy
This policy explains how Reachly handles account data, workspace data, connected account data, prospect data, messages, AI outputs, billing records, and operational logs for an AI-assisted outbound prospecting platform.
Effective date: May 22, 2026
1. Who we are
Reachly is an AI-assisted outbound prospecting platform operated by Smartside AI ("Reachly", "we", "us", or "our"). You can contact us about this policy or privacy requests at tecnologia@smartside.ai.
For personal data about Reachly users, billing contacts, and visitors, Reachly acts as the controller or business responsible for that processing. For prospect records, outreach content, connected accounts, and messages that a customer uploads, imports, connects, sends, or receives through the Service, the customer is generally the controller or business and Reachly acts as a processor or service provider.
2. Personal data we collect
We collect and process the following categories of personal data:
- Account data, such as name, email address, password authentication records handled through Supabase Auth, locale, timezone, and workspace membership.
- Workspace and business profile data, such as company name, website, customers, offer, positioning, ICPs, audience filters, campaign settings, cadence steps, message templates, and setup chat content.
- Connected account data, such as LinkedIn account identifiers, email account address, display name, sending limits, connection status, Google OAuth connection data, calendar links, CRM connection configuration, encrypted CRM credentials, and webhook secrets.
- Prospect and lead data, such as work email address, first and last name, LinkedIn URL, company name, job title, company profile, enrichment data, timezone, campaign status, CRM identifiers, and related public business information.
- Messaging and inbox data, such as outbound and inbound messages, subjects, bodies, timestamps, delivery and reply events, bounce or send errors, conversation status, AI classifications, suggested replies, and final replies sent by the user.
- Billing and usage data, such as plan, subscription status, Stripe customer and subscription identifiers, credit balances, credit ledger entries, invoices, and checkout or customer portal events. Full payment card details are processed by Stripe, not stored by Reachly.
- Operational data, such as IP address and request metadata in hosting logs, device/browser information, authentication cookies, theme/sidebar preferences, webhook payloads, audit/debug records, error telemetry, and security events.
3. Sources of personal data
- You provide data directly when you create an account, configure a workspace, upload spreadsheets or CSV files, connect accounts, write prompts, create campaigns, edit messages, or contact us.
- Connected services provide data at your direction, including Supabase, Unipile, Google, email providers, calendar providers such as Calendly or Cal.com, CRMs, Stripe, Clay, LeadMagic, Inngest, Sentry, and Vercel.
- Prospect data may come from customer uploads, connected LinkedIn search workflows, enrichment providers, public business sources, inbound replies, and calendar or CRM events.
- We automatically collect security, diagnostic, cookie, and log data when you use the Service.
4. How we use personal data
- Provide, secure, maintain, troubleshoot, and improve the Service.
- Create accounts, authenticate users, manage workspaces, and enforce access controls.
- Connect LinkedIn, email, calendar, enrichment, billing, CRM, and webhook providers at the customer's direction.
- Build ICPs, import or enrich audiences, generate and run cadences, send messages, receive replies, classify inbox responses, suggest reply drafts, update lead status, and sync status changes to CRMs.
- Use AI providers to generate campaign drafts, classify replies, suggest responses, retrieve public website context, and produce operational insights. AI outputs are drafts or classifications and should be reviewed by a human before business decisions or outreach are sent.
- Process subscriptions, credits, invoices, trials, payment events, and customer portal actions.
- Detect, prevent, investigate, and respond to fraud, abuse, deliverability issues, security incidents, policy violations, and legal requests.
- Comply with legal obligations and enforce our Terms of Service.
5. Legal bases
Where GDPR, UK GDPR, LGPD, or similar laws apply, our legal bases may include performance of a contract, legitimate interests, consent, compliance with legal obligations, and the establishment, exercise, or defense of legal claims.
For B2B prospecting records processed for customers, the customer is responsible for determining and documenting the lawful basis for its outreach, enrichment, messaging, and retention practices. Reachly processes that data according to the customer's instructions and this policy.
6. Cookies and similar technologies
We use cookies and local storage for authentication, session continuity, security, theme preference, sidebar preference, and basic app functionality. We may use diagnostic or product analytics tools when enabled to understand performance and improve the Service.
We do not use advertising cookies in the current product. If we add non-essential cookies for users in regions that require consent, we will provide the required controls.
7. How we share personal data
We share personal data only as needed for the Service and related business purposes:
- With infrastructure, database, hosting, authentication, observability, and security providers, including Vercel, Supabase, and Sentry.
- With workflow, AI, enrichment, email, LinkedIn, calendar, CRM, billing, and webhook providers used to deliver the product, including Inngest, Anthropic, Unipile, Google, Clay, LeadMagic, Stripe, Calendly or Cal.com, and customer-selected CRMs or webhook endpoints.
- With the customer's connected services and recipients when the customer sends outreach, replies to messages, syncs CRM status, or triggers webhook payloads.
- With professional advisors, auditors, insurers, and service providers under confidentiality obligations.
- When required by law, legal process, government request, or to protect rights, safety, security, and service integrity.
- In connection with a merger, acquisition, financing, restructuring, or sale of assets, subject to appropriate protections.
8. AI processing
Reachly uses AI providers to power setup agents, campaign drafting, message classification, response suggestions, and related workflow assistance. Prompts and outputs may include account, workspace, campaign, lead, and message context needed to complete the requested task.
Reachly does not intend AI suggestions to be legal, financial, or professional advice. Customers remain responsible for reviewing AI output before using it, sending it, or relying on it in business decisions.
9. International transfers
Reachly is designed for global use. Personal data may be processed in countries other than where you or prospects are located, including the United States and other regions where our providers operate. Where required, we use appropriate transfer mechanisms such as standard contractual clauses, data processing terms, and other safeguards.
10. Retention
We retain personal data for as long as needed to provide the Service, maintain security and audit records, comply with legal obligations, resolve disputes, enforce agreements, and support billing, tax, and operational records.
Workspace, campaign, lead, message, and AI session data is generally retained while the workspace remains active. After account closure or deletion, we will delete or de-identify customer workspace data within a reasonable period, normally within 90 days, unless retention is required for security, backups, legal compliance, dispute handling, or legitimate business records. Backup copies may persist for a limited period before cycling out.
11. Your privacy rights
Depending on your location, you may have rights to access, correct, delete, export, restrict, object to, or withdraw consent for certain processing of personal data. You may also have the right to complain to a data protection authority.
Customers can access and manage much of their workspace data directly in the app. For additional requests, contact tecnologia@smartside.ai. If you are a prospect contacted by a Reachly customer, we may need to forward your request to that customer because they control the outreach record.
12. California notices
We do not sell personal information or share it for cross-context behavioral advertising as those terms are used under California privacy law. We do not use or disclose sensitive personal information to infer characteristics. Integration credentials, tokens, and similar sensitive operational data are used to provide and secure the requested integrations.
California residents may request access, correction, deletion, portability, and information about categories of personal information collected, disclosed, sold, or shared. You may also opt out of sale or sharing if our practices change in the future by contacting us at tecnologia@smartside.ai.
13. Prospect opt-out requests
If you receive outreach sent through Reachly and want to stop receiving it, use the unsubscribe, opt-out, or reply instructions in the message. You may also contact the sender directly. If you contact Reachly, we will help route the request to the relevant customer where we can identify the workspace responsible for the outreach.
14. Security
We use administrative, technical, and organizational safeguards designed to protect personal data, including access controls, provider security controls, encryption in transit, encrypted storage for certain integration credentials, webhook validation, and monitoring for errors and abuse. No system is perfectly secure, and customers are responsible for protecting their credentials and connected accounts.
15. Children
The Service is intended for business users and is not directed to children. Do not use Reachly to collect, import, enrich, or message data about children.
16. Changes to this policy
We may update this policy from time to time. If changes are material, we will take reasonable steps to notify users, such as posting the updated policy in the app or by email. The effective date above shows when this version applies.