Documentation/Update your privacy policy
Update your privacy policy
Before your widget goes live, tell visitors how you use LeadReply. Start with the checklist, then copy and adapt the wording below.
What you need to add
Add a section about your website chat to your existing privacy policy, and update your cookie or browser-storage notice. Your business is the controller of visitor data; LeadReply processes it on your behalf. Linking to our policy is useful, but visitors also need to understand your business's use of their data.
- Who to contact: your business's legal name, address and privacy contact.
- What is collected and why: messages, volunteered contact details, visitor identifiers, page visits, chat activity and lead-source information; explain enquiry follow-up and analytics. Include order data if you enable order tracking.
- AI and providers: say the chat uses AI, that conversation content reaches AI providers, and that LeadReply processes data for you. Explain recipients and any international transfers using confirmed processing terms.
- Legal basis: state the basis for each purpose. Answering an enquiry, analytics and marketing are separate purposes; receiving a phone number or email is not a marketing opt-in.
- Retention: give your actual retention period or criteria and arrange deletion to match it.
- Storage and rights: explain cookies and similar storage, how consent is managed, and how visitors can exercise their rights or contact their supervisory authority.
Note
Copy and adapt: English
Add this section to your policy after completing the business details, legal bases, retention and provider information. Keep your cookie-policy link accessible to visitors.
Wording to adapt
Replace every bracketed field.
Texto para adaptar: español
Añade esta sección a tu política. Completa todos los campos entre corchetes, revisa las bases jurídicas y confirma los proveedores, las transferencias y la conservación antes de publicarla. Actualiza también tu política de cookies y el consentimiento cuando corresponda.
Texto para adaptar
Sustituye todos los campos entre corchetes.
Cookies, browser storage and consent
Describe storage by its purpose. The widget remembers chats and also measures visitor journeys and lead sources. First-party storage is not automatically exempt from consent. Where consent is required, your site must obtain it before the relevant storage or tracking starts and support withdrawal.
The current widget starts storing identifiers and tracking visits when it loads; it does not wait for your cookie banner. Have your website provider or developer connect script loading to your consent manager where required. Test both acceptance and rejection before publishing.
| Purpose | Storage and lifetime |
|---|---|
| Recognise returning browsers | Visitor ID in a first-party cookie (up to 400 days, refreshed on visits), local storage (no built-in expiry) and session storage. |
| Resume and protect conversations | A local conversation reference is usable for 30 days after saving; a local conversation security token has no built-in expiry. |
| Remember the first visit source | Local source data is reused for up to 90 days. That reuse limit does not automatically erase the stored value. |
| Group visits and remember widget behaviour | Session storage lasts for the tab session; visit sessions reset after 30 minutes of inactivity. Local page counters and trigger history have no built-in expiry. |
Browser-storage lifetimes are different from server retention. The LeadReply policy describes keeping conversations and leads while the account is active, archiving older conversations and deletion on verified requests or account closure. Archiving is not deletion. If you promise a shorter period, arrange deletion with your team and LeadReply support.
Before you publish
- Publish the completed chat section and cookie notice on your own website.
- Make your policy accessible where visitors start chatting or share details, and clearly tell them they are interacting with AI.
- Confirm the processing agreement, current sub-processors and transfer information with admin@leadreply.xyz before filling in those fields.
- Check your consent setup on a fresh visit, including rejecting consent and withdrawing it after acceptance.
- Confirm your privacy contact and deletion process work, then install and test your widget.
Further reading
The European Commission's transparency guidance covers explaining data use. For Spain, see the AEPD's privacy-notice guidance and cookie guidance.
Previous
Quickstart
From sign-up to a live widget in about ten minutes
Next
Widget overview
What the widget does on your site, end to end
Questions & answers
Ask about this page — the LeadReply team and other readers can answer and upvote.
Log in to ask a question, reply, or upvote. Reading is open to everyone.
Loading discussion…