Privacy Policy
Last updated: July 2, 2026
1. Introduction
Redressly is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services. Please read this policy carefully to understand our practices regarding your personal data.
2. Information We Collect
We collect information that you provide directly to us, including:
- Personal Identification: Full name, email address, country of residence
- Platform Information: Usernames, account identifiers, platform names
- Case Details: Description of issues, type of dispute, supporting documentation
- Communication Records: Correspondence with our team and platforms
- Payment Information: Transaction details (processed securely by third-party providers)
- Identity Verification Data (KYC): When identity verification is required for a case, our processor Didit collects a government-issued ID document, a live selfie / liveness capture, biometric facial-comparison data, document metadata (country, type, issue/expiry), and technical/device signals used for fraud detection. Redressly itself receives only the verification outcome, document country/type, and a one-way SHA-256 hash of the document number — never the raw document or selfie. See section 5b for full detail.
3. How We Use Your Information
We use the collected information for the following purposes:
- To assess and process your case submissions
- To communicate with you regarding your case status
- To facilitate connection with appropriate EU dispute resolution bodies
- To improve our services and user experience
- To comply with legal obligations and protect our rights
- To send service-related notifications and updates
4. Information Sharing
We may share your information with:
- Dispute Resolution Bodies: We facilitate connection with certified out-of-court dispute settlement bodies operating under the Digital Services Act (DSA) within the European Union. Your case information may be shared with these bodies as part of the dispute resolution process. Note that Redressly is not affiliated with or endorsed by these bodies.
- Third-Party Platforms: Information necessary to file and pursue disputes with relevant platforms on your behalf.
- Service Providers / Sub-processors: Third-party vendors who assist us in operating our website, conducting business, or servicing you. Our current sub-processors include: Supabase (EU-hosted database, storage and authentication), Stripe (payment processing), Resend (transactional email delivery), Didit (EU-based identity verification / KYC), Google (Analytics & Tag Manager) and Microsoft Clarity (behavioural analytics, consent-based).
- Legal Requirements: When required by law, court order, or governmental authority.
5. Data Security
Our team consists of cybersecurity professionals who implement appropriate technical and organizational measures to protect your personal data. These measures include:
- Encryption of data in transit and at rest
- Secure access controls and authentication
- Regular security assessments and updates
- Limited access to personal data on a need-to-know basis
However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
5b. Identity Verification (KYC)
For selected cases — typically those we escalate to an official EU Online Dispute Resolution (ODR) body, or where fraud-risk signals are detected — we require you to complete a one-time identity verification. This check is powered by Didit (Didit ID, S.L.), an EU-based, GDPR-compliant identity verification provider acting as our data processor under a Data Processing Agreement (Art. 28 GDPR).
When we request KYC
- The case is escalated to an official EU ODR / dispute-resolution body that requires proof of identity.
- Our fraud/risk engine flags the submission (e.g. non-EU IP without a plausible EU explanation, suspicious payment signals, or high-value claim).
- The submitting email matches a prior case that was declined for identity or fraud reasons.
- An admin manually requests verification for legitimate case-handling reasons.
Data categories processed
- Identity document: passport, national ID card or residence permit — image and extracted MRZ/OCR fields.
- Biometric data: a live selfie and liveness capture, compared against the document photo. This is a special category of data under GDPR Art. 9 and is processed by Didit on our behalf.
- Technical & fraud signals: IP address, device/browser fingerprint, geolocation, and anti-spoofing metrics.
- Verification outcome: approved / declined / in-review, plus the reason code.
What Redressly stores
Redressly receives from Didit and stores only: the verification outcome, the document country and type, the session identifier, timestamps, and a one-way SHA-256 hash of the document number (and, separately, a SHA-256 hash of the submitting email). We do not store or have access to images of your ID, your selfie, your raw biometric template, or your raw document number.
Purpose & legal basis
- Fraud prevention and duplicate-identity blocking — legal basis: legitimate interest (GDPR Art. 6(1)(f)). We use the hashed document number solely to prevent the same identity from being used to open multiple fraudulent or previously declined cases.
- Case escalation to an EU ODR / dispute body — legal basis: performance of a contract(Art. 6(1)(b)) and, where applicable, legal obligation(Art. 6(1)(c)).
- Processing of biometric data by Didit is carried out on the basis of your explicit consent (Art. 9(2)(a)), which you provide inside the Didit verification flow before capturing your selfie.
Retention
- Redressly: the verification outcome and hashed identifiers are retained for the lifetime of the case and for a reasonable period thereafter for fraud-prevention and legal-defence purposes.
- Didit: retains raw verification data (ID images, selfie, biometric template) according to its own retention policy — see didit.me/privacy-policy.
International transfers
Didit processes personal data primarily within the European Economic Area. Where any transfer outside the EEA occurs, it is covered by the European Commission's Standard Contractual Clauses (SCCs) and appropriate supplementary measures.
Your rights
Providing KYC data is not mandatory in general — but if you decline when we request it for a specific case, we may be unable to escalate that case to an ODR body and may close it. You can:
- Request access to, correction of, or deletion of the KYC-related records we hold about you.
- Request removal of your hashed identifier from our internal duplicate-prevention blocklist.
- Withdraw the consent you gave Didit for biometric processing at any time via Didit's privacy channels.
- Lodge a complaint with your national Data Protection Authority.
To exercise any of the above with Redressly, contact support@redressly.com.
6. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. Case-related data may be retained for a reasonable period after case closure for record-keeping and legal compliance purposes.
7. Your Rights Under GDPR
If you are located in the European Economic Area (EEA), you have certain data protection rights:
- Right of Access: Request copies of your personal data
- Right to Rectification: Request correction of inaccurate data
- Right to Erasure: Request deletion of your personal data
- Right to Restrict Processing: Request limitation of data processing
- Right to Data Portability: Request transfer of your data
- Right to Object: Object to processing of your personal data
- Right to Withdraw Consent: Withdraw consent at any time
To exercise these rights, please contact us at support@redressly.com.
8. Cookies and Tracking
We use cookies and similar tracking technologies to enhance your experience on our website and to understand how visitors interact with our services. We distinguish between analytics that are always active and those that require your explicit consent.
Types of Cookies We Use
- Essential Cookies: Required for basic website functionality, such as remembering your cookie consent preference. These cannot be disabled.
- Basic Analytics Cookies (Always Active): We use Google Analytics and Google Tag Manager for basic traffic measurement such as page views, traffic sources, and general usage patterns. These tools may set cookies including
_gaand_gid. These are loaded on every visit under the legal basis of legitimate interest (see below). - Enhanced Analytics Cookies (Consent Required): We use Microsoft Clarity for detailed behavioral analytics such as session recordings and heatmaps. These are only activated after you provide explicit consent via our cookie banner.
Legal Basis for Analytics
We process basic analytics data (Google Analytics and Google Tag Manager) under the legal basis of legitimate interest (GDPR Article 6(1)(f)). Our legitimate interest is to understand aggregate website traffic, measure service performance, and improve the user experience. This data is anonymized and aggregated and does not involve profiling or targeted advertising.
Enhanced behavioral analytics (Microsoft Clarity) are processed under explicit consent (GDPR Article 6(1)(a)), which you provide via the cookie consent banner.
You have the right to object to processing based on legitimate interest. To exercise this right, you can:
- Install the Google Analytics Opt-out Browser Add-on
- Use your browser's built-in tracking protection or cookie blocking settings
- Contact us at support@redressly.com to object to processing
Google Analytics & Google Tag Manager
Google Analytics and Google Tag Manager are loaded on every page visit to measure basic traffic metrics. Google may process this data on servers outside the EU. For more information about how Google handles your data, please review the Google Privacy Policy and Google Analytics Data Practices.
Microsoft Clarity Analytics (Consent Required)
With your consent, we use Microsoft Clarity to analyze how you use our website. Clarity is a behavioral analytics tool that helps us improve our service. Here's what Clarity collects:
- Session Recordings: Anonymous recordings of mouse movements, clicks, and scrolling behavior to understand user experience
- Heatmaps: Aggregated data showing which areas of pages receive the most attention
- Device Information: Browser type, screen resolution, operating system, and device type
- Page Views: Which pages you visit and how long you spend on each page
- Geographic Region: General location (country/region level)
- Referral Sources: How you arrived at our website
What Clarity Does NOT Collect: Clarity masks sensitive information including passwords, form inputs, and personal data you enter on our site. It does not track keystrokes or capture any personal information you submit through forms.
For more information about how Microsoft handles this data, please review the Microsoft Privacy Statement.
Managing Your Cookie Preferences
When you first visit our website, you'll see a cookie consent banner. This banner controls whether Microsoft Clarity (enhanced analytics) is activated. Google Analytics runs independently under legitimate interest and is not controlled by the cookie banner.
To opt out of Google Analytics, you can install the Google Analytics Opt-out Browser Add-on or use your browser's built-in tracking protection settings. You can also manage all cookies through your browser settings. To change your Clarity consent preference, clear your browser's local storage for our site and refresh the page.
9. International Data Transfers
Your information may be transferred to and processed in countries within the European Union where our partner entities operate. We ensure that any such transfers comply with applicable data protection laws and that appropriate safeguards are in place.
10. Children's Privacy
Our services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. You are advised to review this Privacy Policy periodically for any changes.
12. Contact Us
If you have questions about this Privacy Policy or our data practices:
- General Inquiries: support@redressly.com
- Ongoing Cases: appeals@redressly.com