1. Introduction
RepEaters is a customer relationship and marketing platform operated by The 1 Studios LLC (“RepEaters,” “we,” “us,” or “our”). RepEaters is provided to restaurants and other local businesses (“Business Clients”) to help them build and communicate with their own guest contact lists.
This Privacy Policy explains what information we collect, how we use it, how we protect it, and the choices available to you.
This policy covers two distinct groups of people:
- Business Clients — restaurants and businesses who use the RepEaters platform.
- Guests — individuals who provide their contact information to a Business Client through RepEaters (for example, by scanning a QR code, filling out a sign-up form, or submitting a Meta lead form).
By using RepEaters, or by providing your information through a RepEaters-powered form, you agree to the practices described in this policy.
2. Information We Collect
2.1 Guest Information
When a Guest signs up through a RepEaters-powered capture form, QR code, or Meta Instant Form, we may collect:
- Full name
- Email address
- Phone number
- Date of birth (birthday)
- Consent records, including the date, time, and method of opt-in for SMS and email communications
- Source attribution data (for example, which QR code, form, or ad campaign the Guest came from)
- Message engagement data, such as delivery status, opens, clicks, and replies
- Opt-out requests and their timestamps
We do not collect payment card numbers, government identification numbers, precise geolocation, or biometric data from Guests.
2.2 Business Client Information
From our Business Clients, we collect:
- Account credentials (email address and securely hashed password, or authentication via Google Sign-In)
- Business name, business address, time zone, and contact details
- Sending identity configuration (such as the business’s SMS sending number and email sending domain)
- Team member names, email addresses, and assigned roles
2.3 Advertising Data
Where a Business Client authorizes it, we retrieve read-only advertising performance data from Meta (Facebook and Instagram) advertising accounts, including campaign names, ad spend, reach, impressions, clicks, and results.
We access this data solely to display reporting to the Business Client who owns the advertising account. We do not create, modify, publish, pause, or spend on advertising campaigns through this access.
2.4 Meta Lead Ads Data
Where a Business Client has authorized it, RepEaters may receive contact information submitted by Guests through Meta Instant Forms (Facebook and Instagram lead forms). This information is limited to the fields the Guest completed on that form and is delivered to us by Meta.
Guests who submit a Meta lead form are not automatically enrolled in SMS or email marketing. Marketing consent is recorded separately and conservatively — see Section 5.
2.5 Public Review Data
Where a Business Client authorizes it, we may retrieve publicly available Google review content associated with that Business Client’s own business listing, including review text, star ratings, and reviewer display names as publicly shown. We collect this only to help the Business Client monitor and respond to reviews of their own business.
2.6 Business Reports Uploaded by Business Clients
Business Clients may voluntarily upload business reports — such as aggregate transaction summaries, daily sales totals, or guest count reports — for the purpose of analyzing marketing performance against business outcomes.
Important limitations regarding uploaded reports:
- Uploading these reports is entirely optional. RepEaters functions without them.
- We ask Business Clients to upload aggregate business data only, and not to upload individual customer payment details, full payment card numbers, or other sensitive financial identifiers.
- Uploaded reports are treated as strictly confidential business information of the Business Client.
- Uploaded reports are used solely to generate analysis and recommendations for that specific Business Client.
- We do notsell, share, publish, or disclose an individual Business Client’s uploaded reports to any other Business Client or to any third party, except as required by law.
2.7 Technical Information
We automatically collect limited technical information necessary to operate and secure the service, including IP address, browser type, device type, and timestamps of access.
3. How We Use Information
We use the information we collect to:
- Provide the RepEaters platform to Business Clients
- Enable Business Clients to send SMS and email communications to Guests who have consented to receive them
- Record, maintain, and honor consent and opt-out preferences
- Attribute Guest sign-ups to the source that generated them
- Display advertising performance reporting to the Business Client who owns the ad account
- Generate analysis and recommendations from data a Business Client has provided
- Maintain the security, integrity, and reliability of the platform
- Comply with our legal obligations
We do not sell personal information.We do not share Guest contact information with other Business Clients, and we do not use one Business Client’s data to benefit another.
4. Legal Basis for Processing
Where required by applicable law (including the GDPR), we process personal information on the following legal bases:
- Consent — you have given clear, affirmative consent for a specific purpose, such as receiving SMS or email marketing. You may withdraw consent at any time.
- Performance of a contract — processing is necessary to provide the RepEaters platform to a Business Client under our agreement with them.
- Legal obligation — processing is necessary to comply with a legal requirement, such as retaining consent records for messaging compliance.
- Legitimate interests — processing is necessary for legitimate business purposes, such as securing the platform, preventing abuse, and improving our services, provided those interests are not overridden by your rights.
If you would like clarification on the specific legal basis applying to a particular processing activity, contact us using the details in Section 19.
5. SMS and Email Communications: Consent and Compliance
We take messaging compliance seriously. This section describes our practices in detail.
5.1 Express Written Consent
Guests are only enrolled in SMS marketing after providing express written consent in compliance with the Telephone Consumer Protection Act (TCPA). Consent is obtained through a clear, affirmative action — such as checking an unchecked opt-in box on a sign-up form — accompanied by disclosure that:
- The Guest will receive marketing messages from the specific business
- Message and data rates may apply
- Message frequency varies
- Consent is not a condition of any purchase
- The Guest may opt out at any time by replying STOP
Consent for SMS and consent for email are collected separately. Consenting to one does not enroll a Guest in the other.
5.2 Consent Records
For every Guest, we retain a record of consent including the timestamp, the method of collection, and the source. These records are retained to demonstrate compliance and are not deleted when a Guest opts out — the opt-out itself is recorded as an additional compliance event.
5.3 Meta Lead Form Consent
Guests whose information arrives through a Meta Instant Form are recorded with SMS and email marketing consent set to off by default. We do not infer or assume marketing consent from a lead form submission. Any consent language captured on such a form is flagged for human review before marketing consent is granted.
5.4 Opting Out
Guests may opt out of SMS messages at any time by replying STOP to any message. Opt-outs are processed automatically and immediately. Guests may resume messages by replying START.
Guests may opt out of email at any time using the unsubscribe link included in every marketing email.
Opt-out requests are honored across the platform and cannot be overridden by a Business Client.
5.5 Service Providers for Messaging
SMS messages are delivered through Twilio Inc.RepEaters maintains registered A2P 10DLC campaigns as required by U.S. mobile carriers, which includes brand registration, campaign registration, and carrier review of message content and opt-in practices. Twilio processes message content and phone numbers as a service provider on our behalf. Twilio’s privacy practices are available at https://www.twilio.com/legal/privacy
Email messages are delivered through Resend, Inc.Resend processes email addresses and message content as a service provider on our behalf. Sending domains are authenticated using SPF, DKIM, and DMARC records. Resend’s privacy practices are available at https://resend.com/legal/privacy-policy
We do not authorize Twilio or Resend to use Guest information for their own marketing purposes.
6. How Information Is Shared
We share information only in the following circumstances:
With the Business Client who collected it. Guest information belongs to the Business Client whose form, QR code, or ad the Guest responded to. That Business Client can view and manage those contacts.
With service providers who operate the platform on our behalf, each bound by contractual obligations to protect the data:
| Provider | Purpose |
|---|---|
| Supabase | Database hosting and authentication |
| Vercel | Application hosting |
| Twilio | SMS delivery |
| Resend | Email delivery |
| Meta Platforms | Advertising reporting and lead form delivery |
| Anthropic | AI-assisted content and analysis features |
When required by law, including in response to valid legal process, or to protect the rights, safety, or property of RepEaters, our Business Clients, or the public.
In connection with a business transfer, such as a merger or acquisition, in which case we will provide notice before information becomes subject to a different privacy policy.
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.
7. Data Isolation Between Business Clients
RepEaters is a multi-tenant platform. Each Business Client’s data is logically isolated from every other Business Client’s data through database-level access controls (row-level security). A Business Client cannot access, view, or export another Business Client’s guest contacts, campaigns, reports, or advertising data.
8. Data Security
We maintain administrative, technical, and physical safeguards designed to protect personal information, including:
- Encryption of data in transit using TLS
- Encryption of data at rest by our hosting providers
- Role-based access controls limiting employee and Business Client access to what their role requires
- Row-level security enforcing tenant isolation at the database layer
- Cryptographic signature verification on all inbound webhooks
- Credentials and API keys stored in server-side environment variables, never exposed to browsers
- Passwords stored using industry-standard one-way hashing
No method of transmission or storage is completely secure. While we work to protect your information, we cannot guarantee absolute security.
9. Data Retention
We retain Guest contact information for as long as the Business Client maintains an active account with RepEaters, or until the Guest requests deletion.
Consent and opt-out records are retained for a minimum of four (4) years after the last message sent, as recommended for demonstrating TCPA compliance, even if the underlying contact is otherwise removed.
Business reports uploaded by a Business Client are retained for as long as that Business Client maintains an active account, and are deleted upon account termination or written request.
10. Your Rights and Choices
Depending on where you live, you may have the right to:
- Access the personal information we hold about you
- Correct inaccurate personal information
- Delete your personal information
- Opt out of marketing communications at any time
- Opt out of sale or sharing of personal information (we do not sell or share personal information for behavioral advertising)
- Non-discrimination for exercising any of these rights
- Data portability — receive a copy of the information you provided in a portable format
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal
Guests: To exercise these rights, contact the business you provided your information to, or contact us using the details in Section 19 and we will route your request to the appropriate Business Client.
How to Exercise Your Rights
Send your request using the contact information in Section 19. To protect your information, we must verify your identity before acting on a request. Please include:
- Enough information to identify you (full name, and the email address or phone number you provided)
- The name of the business whose form or ad you responded to, if known
- A description of the right you wish to exercise
We may request additional information to verify identity. We are not obligated to fulfill an access or portability request if we cannot verify that the requester is the individual whose information we hold, or someone authorized to act on their behalf.
Response Timelines
We will confirm receipt of your request within 10 business days. We will fulfill verified requests within 45 days, and may extend by an additional 45 days where permitted, in which case we will notify you of the extension and the reason.
We will not discriminate against you for exercising any privacy right. Exercising these rights will not affect the price or quality of any goods or services.
11. Cookies and Similar Technologies
Our website and application use cookies and similar technologies. A cookie is a small text file stored on your device.
We use the following categories:
- Essential cookies — required for the platform to function, including authentication and session management. These cannot be disabled without breaking core functionality.
- Functional cookies — remember your preferences and settings.
- Analytical cookies — help us understand aggregate usage patterns so we can improve the service.
We also use pixels and web beacons in marketing emails to record whether a message was opened or a link clicked. This engagement data is used for campaign reporting.
You can configure your browser to refuse cookies or to alert you when cookies are being sent. If you disable essential cookies, portions of the platform may not function correctly.
Do Not Track: Our systems do not currently respond to Do Not Track browser signals, as no common industry standard for these signals has been adopted.
12. Analytics
We use analytics tools to understand how visitors use our website, including metrics such as pages viewed, time on page, and referral source.
Where Google Analytics is used, information collected is governed by Google’s privacy practices, available at https://www.google.com/policies/privacy/ You may opt out of Google Analytics using Google’s browser add-on at https://tools.google.com/dlpage/gaoptout
We also use aggregated, non-identifying information for statistical analysis and service improvement.
13. U.S. State Privacy Rights
Several U.S. states provide their residents with specific privacy rights. To exercise any of the rights below, contact us using the information in Section 19 and indicate the applicable state request in your message.
California (CCPA/CPRA)
California residents have the right to know what personal information we collect, use, and disclose; to request deletion; to request correction; to data portability; and not to be subject to automated decision-making that produces legal or similarly significant effects.
Do Not Sell or Share: RepEaters does not sell personal information, and does not share personal information for cross-context behavioral advertising. Because we do not engage in these activities, there is nothing to opt out of. If this ever changes, we will update this policy and provide a clear opt-out mechanism before doing so.
California “Shine the Light”: California residents may request information about disclosures of personal information to third parties for those third parties’ direct marketing purposes. As stated above, we do not make such disclosures.
Utah (UCPA)
Utah residents may request access to and deletion of personal data, obtain a copy of their data, and opt out of the processing of personal data for targeted advertising or the sale of personal data. Indicate “Utah Privacy Request” in your message.
Virginia (VCDPA)
Virginia residents may confirm whether we process their personal data, correct inaccuracies, request deletion, obtain a copy, and opt out of processing for targeted advertising, sale, or profiling. Indicate “Virginia Privacy Request” in your message.
Colorado, Connecticut, Texas, Oregon, and Other States
Residents of Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), Oregon (OCPA), and other states with comparable consumer privacy laws have rights to access, correct, delete, and obtain a copy of their personal data, and to opt out of targeted advertising, sale, and certain profiling. Indicate your state in your message.
Nevada
Nevada residents may request to be placed on our opt-out list for future sales of covered information. As noted, we do not sell personal information.
Appeals
If we decline a privacy request, you may appeal that decision by replying to our response or contacting us again with “Privacy Appeal” in your message. We will respond to appeals within the timeframe required by your state’s law.
14. Right to Lodge a Complaint
We welcome questions and concerns about how we handle personal information, and we encourage you to contact us first so we can resolve the issue directly.
You also have the right to complain to a regulator:
- United States: the Federal Trade Commission at https://www.ftc.gov/ or your state Attorney General’s office
- European Economic Area / United Kingdom: your local data protection supervisory authority
15.Children’s Privacy
RepEaters is not directed to children. We do not knowingly collect personal information from anyone under the age of 16. If we learn that we have collected such information, we will delete it promptly. If you believe a child has provided us information, please contact us.
16. International Data Transfers
RepEaters is operated in the United States, and information is processed and stored in the United States. If you access RepEaters from outside the United States, you understand that your information will be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction.
17. Third-Party Websites
Our website and the messages sent through RepEaters may contain links to third-party websites, including our Business Clients’ own websites and social media profiles. We are not responsible for the privacy practices of those sites. We encourage you to review the privacy policy of any site before providing personal information to it.
18. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page. If we make material changes, we will provide additional notice to Business Clients. We encourage you to review this policy periodically.
19. Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, contact us at:
The 1 Studios LLC
ATTN: Privacy Officer
3698 W Suri Rise Ln
Herriman, UT 84096
Email: hello@getrepeaters.com
Website: https://getrepeaters.com
We will confirm receipt of privacy requests within 10 business days.
This policy describes the practices of RepEaters, a product of The 1 Studios LLC. Business Clients using RepEaters are independently responsible for their own compliance obligations regarding the guests whose information they collect.