DRAFT - pending legal review. This is a working draft, not yet in effect. Reply Desk makes no warranty as to its completeness or fitness; have qualified counsel review it before you rely on or publish it.
// legal

Privacy Policy

Last updated: June 22, 2026

This Privacy Policy explains how WickScout Finance LLC (“Reply Desk,” “we,” “us,” or “our”) collects, uses, shares, and protects personal information in connection with the Reply Desk service at desk.replyline.io (the “Service”). Reply Desk is a business-to-business platform that turns service requests into tickets, schedules and dispatches technicians, documents jobs, and supports optional invoicing and payments. We are based in Philadelphia, Pennsylvania, USA.

1. Scope & Our Two Roles

It is important to understand the difference between the two kinds of data we handle, because we play a different legal role for each.

Data we control (the focus of this Policy)

This Privacy Policy describes the personal information for which we act as a controller— that is, information about our own customers and the people who use the Service. This includes account and contact details of the businesses and individual users who sign up for Reply Desk, billing metadata, and usage and log data generated as you use the Service.

Data our customers control (covered by the DPA, not this Policy)

Reply Desk is a tool that our customers (each a “Customer” or “Controller”) use to run their own operations. When a Customer creates tickets, schedules jobs, or sends notifications, they may load personal data about their own end-customers, employees, students, or other individuals into the Service. With respect to that data, Reply Desk acts only as a processor: we process it on the Customer's behalf, on their documented instructions, and for the purpose of providing the Service to them. The Customer — not Reply Desk — decides what data to collect and why, and is responsible for providing notice to and obtaining any required consent from those individuals. Our handling of that data is governed by our Data Processing Addendum (DPA), not by this Policy. If you are an end-customer of a business that uses Reply Desk and you have questions about your data, please contact that business directly; they are the controller.

2. Information We Collect

2.1 Account & contact information

When you create or are invited to an account, we collect identifiers such as your name, business name, email address, phone number, job role, and authentication credentials managed through our authentication provider. We may also collect information you provide when you contact us for support or sales.

2.2 Billing metadata

For paid plans, we collect billing-related information such as your plan, subscription status, and billing contact. Payment card processing is handled by Stripe; Reply Desk does not collect or store full payment card numbers on our systems. We receive only limited billing metadata from Stripe (for example, the last four digits of a card, card brand, expiration, and transaction status) needed to manage your subscription.

2.3 Usage, log & device data

As you use the Service, we automatically collect technical information such as IP address, browser and device type, operating system, pages and features accessed, timestamps, referring URLs, and diagnostic and performance logs. We use this to operate, secure, and improve the Service.

2.4 Cookies & similar technologies

We and our providers use cookies and similar technologies to keep you signed in, remember preferences, secure sessions, and understand how the Service is used. See Section 11 (Cookies) for details.

2.5 Content you submit

We collect the content you and your team submit into the Service — tickets, notes, photos, signatures, checklists, attachments, and messages. Where this content includes personal data about a Customer's end-customers, we process it as a processor under the DPA as described in Section 1.

3. How We Use Information

We use the information we control for the following purposes:

  • Provide the Service — create and manage accounts, deliver ticketing, scheduling, dispatch, job documentation, the self-service intake portal, email-to-ticket, and reporting features.
  • Secure the Service — authenticate users, prevent fraud and abuse, monitor for security incidents, and maintain availability.
  • Support — respond to your questions, troubleshoot, and provide customer service.
  • Billing — manage subscriptions, invoices, and payments through Stripe.
  • Improve the Service — understand usage trends, fix bugs, and develop new features.
  • Communicate — send service, security, and administrative messages, and (where permitted) relevant product updates.
  • Legal — comply with legal obligations, enforce our terms, and protect our rights and the rights of others.

4. Legal Bases for Processing (GDPR / UK GDPR)

If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases to process personal data for which we are the controller:

  • Performance of a contract — to provide the Service to you and your organization and to administer your account and billing.
  • Legitimate interests — to secure and improve the Service, prevent abuse, understand usage, and run our business, balanced against your rights and interests.
  • Consent — where required, for example for certain cookies or optional marketing communications. You may withdraw consent at any time.
  • Legal obligation — to comply with applicable laws and respond to lawful requests.

5. How We Share Information

We do not sell personal data, and we do not share it for cross-context behavioral advertising. We share information only as described below:

  • Sub-processors — service providers that perform functions on our behalf (see Section 6). They may access personal data only to provide their service to us and are bound by confidentiality and data-protection obligations.
  • Stripe (payments) — when payments are enabled, they are processed by Stripe via Stripe Connect. The Customer is the merchant of record; Reply Desk is not a party to the payment and is not a money transmitter. Stripe's Connected Account Agreement and privacy policy govern its handling of payment data.
  • Legal & compliance — we may disclose information if required by law, court order, or governmental request, or to protect the safety, rights, or property of Reply Desk, our customers, or the public.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, information may be transferred, subject to this Policy or a successor policy.
  • With your direction — where you or your organization instructs us to share information, for example when you connect a third-party integration.

6. Sub-processors

We use the following sub-processors to provide the Service. The first three support our core platform; the others support specific features (and Google/Microsoft only apply when a Customer connects calendar sync).

Sub-processorPurpose
RailwayCloud hosting, application infrastructure, and database storage.
ClerkUser authentication, session management, and account security.
StripePayment processing and subscription billing via Stripe Connect.
TwilioSMS notifications (status updates, “on my way,” appointment reminders).
ResendSending outbound transactional and notification emails on the Customer's behalf.
PostmarkProcessing inbound email for the email-to-ticket feature.
Google / MicrosoftCalendar sync, when the Customer chooses to connect Google Workspace or Microsoft.

SMS and email notifications are sent on the Customer's behalf. The Customer is responsible for having any consent required from recipients under applicable laws (including the TCPA and CAN-SPAM) and for honoring opt-out requests.

7. Data Retention

We retain personal data for as long as your account is active and as needed to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. When you close your account, we delete or de-identify data we control within a commercially reasonable period, except where retention is required by law or for legitimate business purposes such as backups, fraud prevention, and recordkeeping. Customer content processed under the DPA is retained and deleted in accordance with that addendum and the Customer's instructions.

8. Security

We use administrative, technical, and organizational measures designed to protect personal data, including:

  • Encryption of data in transit using industry-standard protocols (TLS).
  • Access controls and authentication, with access limited to personnel who need it.
  • Tenant isolation — data is scoped per organization so that one Customer's data is not accessible to another.
  • Logging, monitoring, and regular review of our systems and providers.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we become aware of a breach affecting personal data, we will notify affected parties as required by law and, for Customer content, in accordance with the DPA.

9. Your Privacy Rights

Depending on where you live, you may have the rights described below with respect to personal data we control. For data we process on a Customer's behalf, please direct your request to the relevant Customer (the controller); we will assist them as required by the DPA.

9.1 All users

  • Access — request a copy of the personal data we hold about you.
  • Correction — request that we correct inaccurate or incomplete data.
  • Deletion — request that we delete your personal data, subject to legal exceptions.
  • Portability — request a copy of certain data in a portable, machine-readable format.

9.2 California residents (CCPA/CPRA)

California residents have the right to know what personal information we collect, use, and disclose; the right to request deletion; the right to correct inaccurate information; and the right to non-discrimination for exercising these rights. We do not sell personal information and do not share it for cross-context behavioral advertising.

9.3 EEA / UK / Switzerland (GDPR / UK GDPR)

You may have the right to access, rectify, erase, restrict, or object to processing, the right to data portability, and the right to withdraw consent. You also have the right to lodge a complaint with your local supervisory authority.

9.4 How to exercise your rights

To exercise any of these rights, email us at wickscoutio@gmail.com. We may need to verify your identity before responding, and we will honor your request as required by applicable law. You may use an authorized agent where the law permits.

10. Cookies

We use cookies and similar technologies that are strictly necessary to operate the Service (for example, to keep you signed in and to secure sessions), as well as functional cookies to remember preferences and analytics cookies to understand usage. You can control cookies through your browser settings; disabling some cookies may affect how the Service works. Where required by law, we will request your consent for non-essential cookies.

11. Children's Privacy

The Service is a business tool and is not directed to children. We do not knowingly collect personal information directly from children under 13 (or under 16 where a higher age applies) for our own purposes. Where a Customer (for example, an education customer) loads data about students into the Service, that data is processed under the DPA and the Customer's instructions. For education customers in the United States, Reply Desk acts as a “school official” with a legitimate educational interest under FERPA: we use student data solely to provide the Service to the institution and do not re-disclose it except as permitted by the institution or required by law.

12. International Data Transfers

We are based in the United States, and our sub-processors may process data in the United States and other countries. Where we transfer personal data from the EEA, the United Kingdom, or Switzerland to countries that have not been deemed to provide an adequate level of protection, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, together with supplementary measures where needed.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Service after an update means you accept the revised Policy.

14. Contact Us

If you have questions about this Privacy Policy or our privacy practices, contact us at:

This Policy is governed by the laws of the Commonwealth of Pennsylvania, USA, without regard to its conflict-of-laws rules.