Privacy Policy
Last updated: 25 July 2026
This Privacy Policy explains how Meritly handles personal information. Meritly is an AI lead-capture and outreach platform used by businesses (“Customers”) to talk to, qualify, and follow up with their own leads and contacts. Where required by law, the bracketed details below (legal entity name, address, and governing jurisdiction) must be completed before publication.
Contents
- Who we are & the scope of this policy
- Our roles: controller and processor
- Information we collect
- How and why we use information
- Artificial intelligence & automated processing
- Legal bases (EEA/UK)
- How we share information & sub-processors
- International data transfers
- Data retention
- Security
- Your privacy rights
- Cookies & similar technologies
- Children's privacy
- Changes to this policy
- Contact us
1. Who we are & the scope of this policy
Meritly (“Meritly”, “we”, “us”, or “our”) is operated by [Legal Entity Name], a company registered in [Country/State of incorporation] with its registered address at [Registered business address]. This policy applies to:
- our marketing website at meritly.dev (the “Site”);
- the Meritly dashboard, receptionist, and embeddable chat widget (the “Service”); and
- personal information we process about visitors, prospective and current Customers, and the leads and contacts our Customers interact with through the Service (“End Users”).
If you are an End User (for example, someone chatting with a business that uses Meritly), the business you contacted — not Meritly — decides why and how your information is used. Please see that business's own privacy notice and direct access or deletion requests to them first; we will assist them as described in Section 11.
2. Our roles: controller and processor
Depending on the data, Meritly acts in one of two roles:
- Controller.For information about our Site visitors and Customer account holders (for example, the email address used to sign in, billing and support communications, and Site analytics), Meritly is the “controller” and this policy governs that use.
- Processor.For the lead, conversation, and contact data that a Customer captures and manages through the Service (“Customer Data”), the Customer is the controller and Meritly is a “processor” acting on the Customer's documented instructions under our Terms of Service and any Data Processing Agreement. We do not use Customer Data for our own purposes, and we do not sell it.
3. Information we collect
a. Information from Customers (account holders)
- Account & authentication data: your email address and the sign-in (magic-link) tokens and session records used to log you in.
- Configuration & content: business name and details, widget settings, greetings and system prompts, and any knowledge-base documents or text you upload to train your assistant.
- Communications: messages you send us for support or sales, and email we send you.
- Usage & logs: product events, diagnostic logs, and technical metadata (such as timestamps and request information).
b. Information about End Users (processed on a Customer's behalf)
- Contact identifiers: name, email address, phone number, and WhatsApp number, where provided.
- Conversation content: chat messages, and — where voice is enabled — voice input and its transcript, across website chat, WhatsApp, SMS, and email.
- AI-derived information: inferences generated by the Service such as intent, urgency, budget signals, decision stage, objections, preferences, a lead score, and a priority or summary.
- Delivery & consent metadata: channel used, message direction and delivery status, follow-up history, preferred channel, and opt-out/unsubscribe status.
The specific fields depend on how each Customer configures the Service and what an End User chooses to share. Customers are responsible for the information they collect and for having a lawful basis to do so (see our Terms of Service).
c. Information collected automatically on the Site
- Basic technical data (such as IP address, browser type, and pages viewed) and strictly necessary cookies used to operate the Site and keep you signed in. See Section 12.
4. How and why we use information
As a controller (Customer & Site data), we use information to:
- provide, secure, and operate the Site and the Service, and authenticate accounts;
- respond to enquiries and provide customer support;
- send service and administrative messages (for example, sign-in links and important notices);
- with your consent where required, send product updates and marketing you can opt out of at any time;
- monitor, debug, and improve the Service and prevent fraud and abuse; and
- comply with legal obligations and enforce our Terms.
As a processor (Customer Data), we use information only to provide the Service to the relevant Customer — for example, to capture and store a conversation, qualify and score a lead, route and send follow-up messages across channels, and present results in the Customer's dashboard — and otherwise on that Customer's documented instructions.
5. Artificial intelligence & automated processing
The Service uses third-party AI models to power conversations and to analyze and score leads. Conversation content and related data may be sent to our AI sub-processors (currently OpenAI and Anthropic; see Section 7) solely to generate a response or an assessment for the Customer. Meritly's configured providers do not use Customer Data submitted through their APIs to train their foundation models under their standard API terms; however, Customers and End Users should not submit information they do not wish to be processed by these providers.
Lead scoring and prioritization are forms of automated processing and may involve profiling. These outputs are intended as decision support and can be inaccurate or incomplete. Customers are responsible for any decision they make about an End User and for providing any notice or human review required by law (for example, under Article 22 GDPR). If you are an End User and wish to contest an automated assessment, contact the business you interacted with, or contact us and we will refer your request to them.
6. Legal bases (EEA/UK)
Where the GDPR or UK GDPR applies and Meritly is the controller, we rely on:
- Contract — to provide the Service and account you request;
- Legitimate interests — to secure, operate, and improve the Service and communicate with Customers, balanced against your rights;
- Consent — for optional marketing and any non-essential cookies, which you may withdraw at any time; and
- Legal obligation — to meet our legal and regulatory duties.
Where Meritly is a processor, the Customer is responsible for establishing the legal basis for its processing of End User data.
7. How we share information & sub-processors
We do not sell personal information. We share it only as follows:
Sub-processors that help us run the Service, under contracts requiring appropriate protection. Current sub-processors include:
- OpenAI — conversational AI and lead analysis/scoring.
- Anthropic — processing of uploaded knowledge-base content.
- ElevenLabs — voice synthesis for voice interactions.
- Twilio — SMS and WhatsApp message delivery.
- Resend (and, where configured, an SMTP email provider) — email delivery.
- Supabase — database hosting and storage.
- Railway and Vercel — application and website hosting.
We may also share information with professional advisers, in connection with a merger, acquisition, or sale of assets (with notice where required), and where necessary to comply with law, respond to lawful requests, or protect rights, safety, and the integrity of the Service.
8. International data transfers
Our sub-processors may process information in countries other than yours, including the United States. Where we transfer personal information out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum) or another lawful transfer mechanism. You may request more information using the contact details in Section 15.
9. Data retention
We retain Customer account information for as long as the account is active and as needed to provide the Service, then for a limited period to meet legal, accounting, or dispute-resolution needs. We retain Customer Data (including End User conversations and lead records) for as long as the Customer keeps it in the Service; the Customer controls deletion of its own records, and End User opt-out/unsubscribe status is retained so we can honor those preferences. On termination, we delete or return Customer Data as described in our Terms, subject to legal retention requirements and routine backup cycles.
10. Security
We use technical and organizational measures designed to protect personal information, including encryption in transit, access controls and database row-level security, scoped API access, and server-side handling of sensitive keys. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a personal data breach affecting your information, we will notify affected parties and regulators as required by applicable law.
11. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to the processing of your personal information, and to withdraw consent. Because automated decision-making may be involved, you may also have the right not to be subject to certain decisions based solely on automated processing.
California (CCPA/CPRA):California residents may request access to, deletion of, and correction of personal information, and may opt out of the “sale” or “sharing” of personal information. We do not sell or share personal information as those terms are defined by the CPRA. We will not discriminate against you for exercising your rights.
To exercise rights over data for which Meritly is the controller, contact us using Section 15. Where Meritly is a processor, we will refer your request to the relevant Customer (the controller) and assist them in responding. We may need to verify your identity before acting. You also have the right to lodge a complaint with your local data protection authority.
12. Cookies & similar technologies
We use strictly necessary cookies to operate the Site and keep Customers signed in. Where we use any non-essential analytics or preference cookies, we will request consent where required and provide controls. You can also manage cookies through your browser settings; blocking strictly necessary cookies may prevent parts of the Service from working.
13. Children's privacy
The Service is intended for businesses and is not directed to children. We do not knowingly collect personal information from children under 16 (or the age defined by local law). If you believe a child has provided us personal information, contact us and we will delete it.
14. Changes to this policy
We may update this policy from time to time. If we make material changes, we will update the “Last updated” date and, where appropriate, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
15. Contact us
For privacy questions or to exercise your rights, contact us at hello@meritly.dev, or by mail at [Legal Entity Name, Registered business address]. If you are in the EEA or UK and we are required to designate a representative or data protection officer, their details will be provided here: [EU/UK Representative or DPO details, if applicable].