Privacy Policy

Effective date: June 28, 2026

This Privacy Policy explains how FRelay (“FRelay,” “we,” “us,” or “our”) collects, uses, discloses, and safeguards your personal information when you use our business messaging platform and related websites and services (collectively, the “Services”). It applies to information we process as a service provider on behalf of the businesses that use our platform, and to information we process about our own account holders.

We are committed to handling personal information in accordance with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and Canada’s Anti-Spam Legislation (CASL), applicable U.S. federal and state privacy laws, the EU/UK General Data Protection Regulation (GDPR) where it applies, and, where a business customer is a HIPAA-covered entity, the privacy and security obligations set out in the applicable Business Associate Agreement.

1. Who is responsible for your information

FRelay operates a multi-tenant messaging platform. When you exchange messages with a business that uses our Services, that business is the controller of your conversation data and decides why your information is collected. FRelay acts as that business’s service provider (processor) and handles your information only to deliver the Services and as instructed by that business. If you have questions about how a particular business uses your data, contact that business directly. For questions about our platform-level practices, contact us using the details in Section 12.

2. Information we collect

We collect the following categories of information:

  • Account information. Name, business name, email address, phone number, billing details, and login credentials for users who create an account.
  • Messaging content and metadata. The content of SMS, MMS, and other channel messages sent or received through the platform, along with phone numbers, timestamps, delivery receipts, and message status.
  • Consent and opt-in records. Records of how and when consent to receive messages was obtained, the consent basis, and any opt-out (STOP) or help (HELP) requests. These records are retained to demonstrate compliance with CASL and the U.S. Telephone Consumer Protection Act (TCPA).
  • AI processing data. Where a business enables AI-assisted replies, message content may be processed by AI models to classify messages, draft suggested responses, or send automated replies within the limits the business configures.
  • Usage and device data. Log data, IP address, browser type, device identifiers, and interactions with our web application, collected for security, debugging, and analytics.

3. How we use information

  • To deliver, maintain, and secure the Services.
  • To send and receive messages on behalf of the businesses that use the platform, including AI-assisted and automated replies they configure.
  • To process and honor consent, opt-in, and opt-out requests, and to maintain auditable compliance records.
  • To provide billing, support, and account administration.
  • To detect, prevent, and investigate fraud, abuse, and security incidents.
  • To comply with legal obligations and enforce our agreements.

4. SMS, MMS, and mobile data

Mobile opt-in information and consent are used only to provide the messaging program you joined. We do not sell, rent, or share mobile opt-in data, phone numbers, or SMS consent with third parties for their own marketing purposes. Message and data rates may apply to messages you send or receive. You can opt out of any messaging program at any time by replying STOP, and you can request help by replying HELP. See our Messaging Policy for full program details.

5. How we share information

We share personal information only as needed to operate the Services and as described here:

  • With the business you are communicating with, which controls your conversation data.
  • With subprocessors and infrastructure providers that support the platform — including our cloud database and hosting provider, our telecommunications carriers and aggregators (for message delivery), and our AI model providers — each bound by contractual confidentiality and data-protection obligations.
  • With white-label partners who resell the platform, limited to account metadata, usage, and billing. Partners do not receive message content unless the business has granted explicit, time-bound, auditable access.
  • When required by law, such as in response to a valid legal request, or to protect the rights, safety, and security of users and the public.
  • In a business transfer, such as a merger or acquisition, subject to this Policy.

We do not sell personal information as “sale” is defined under applicable U.S. state privacy laws.

6. Data retention

We retain personal information for as long as needed to provide the Services to the relevant business, and thereafter as required to meet legal, accounting, and compliance obligations. Consent and opt-out records are retained as an immutable ledger to demonstrate ongoing compliance with CASL and the TCPA. When information is no longer required, it is deleted or de-identified.

7. Security

We use administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit, tenant-level access isolation enforced at the database layer, role-based access controls, and audit logging. No method of transmission or storage is perfectly secure, but we work to protect your information and to notify affected parties and regulators of breaches as required by law.

8. International transfers

We operate in Canada and the United States, and your information may be stored or processed in either country and by our service providers elsewhere. Where personal information is transferred across borders, we rely on appropriate safeguards, such as standard contractual clauses, as required by PIPEDA, GDPR, and other applicable law.

9. Your privacy rights

Depending on where you live, you may have the right to access, correct, update, port, or delete your personal information, to withdraw consent, and to object to or restrict certain processing. Because we typically process conversation data on behalf of a business, we will refer many requests to that business, the controller of your data. To exercise a right or raise a concern, contact us using the details in Section 12; we will respond within the timeframes required by applicable law. Canadian residents may also contact the Office of the Privacy Commissioner of Canada, and EU/UK residents may contact their local supervisory authority.

10. Children’s privacy

The Services are intended for businesses and their customers and are not directed to children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us so we can delete it.

11. Changes to this Policy

We may update this Privacy Policy from time to time. When we make material changes, we will revise the effective date above and, where appropriate, provide additional notice. Your continued use of the Services after an update constitutes acceptance of the revised Policy.

12. Contact us

If you have questions about this Privacy Policy or our handling of your personal information, contact FRelay at [email protected].

Privacy Policy — FRelay