Privacy policy
This policy explains what data the Social Gateway platform, operated by [operator name not set yet], processes, why, how long it is kept, and how to have it deleted.
What the platform is
The platform sits between companies' customer-relationship (CRM) systems and the Facebook Pages and Instagram professional accounts those companies manage. It publishes on the company's behalf, reads comments on its posts, sends its replies, and forwards these events to the company's own system. It is not a CRM and does not build profiles of people.
Data we process
- Workspace user accounts: name, email, a one-way hash of the password (never the password itself), and sign-in records.
- Meta connection data: the ID and name of the Facebook user who connected the Pages, access tokens (encrypted), IDs, names and pictures of the Pages and Instagram accounts, and the permissions granted.
- Page content: posts published through the platform or read from the connected Pages, and the comments on them, including the commenter's public name, ID and text as Meta provides them.
- Technical data: IP addresses in the audit log, request identifiers, and records of background jobs and event deliveries.
How we use it
We use the data only to provide the service to the company that connected the Page: publishing, reading comments, replying, forwarding them to the company's system, and protecting the service from abuse. We do not sell data, use it for advertising, or build profiles from it.
Who we share it with
With the company that connected the Page and the systems it configures itself (webhooks); with Meta through its API, to do what the company asks; with the hosting provider the platform runs on; and with authorities where the law requires it.
How long we keep it
- Access tokens are deleted as soon as a connection is removed or the app is removed from Facebook.
- Comments: 180 days.
- Raw Meta events: their text is masked after 72 hours and they are deleted after 30 days.
- Event delivery logs: 30 days. Operations: 90 days. Audit log: 365 days.
- Uploaded files: 30 days.
- When a company's workspace is cancelled, all its data is permanently deleted after 30 days.
Security
Access tokens and all secrets are encrypted with AES-256-GCM under a key that is never stored in the database; API keys are kept only as one-way hashes; each company's data is isolated from every other; and connections are encrypted with TLS.
Your rights and deleting your data
- From inside the workspace: Connections, then Disconnect, deletes the access tokens immediately.
- From Facebook: Settings & privacy → Settings → Business integrations, then remove the app. Meta notifies us and we delete the connection data automatically.
- A deletion request through Facebook gives you a confirmation code; you can check its status on the deletion status page. Data deletion request status
- Or write to [contact email not set yet] and we will answer within 30 days.
If you commented on a Page of a company that uses the platform: the comment belongs to that Page and Meta shows it publicly. Delete it on Facebook or Instagram; it is removed from the platform when Meta notifies us, or when the retention period ends.
Meta Platform
Our use of Meta data follows the Meta Platform Terms and Developer Policies. We ask only for the permissions the service needs.
Contact
For any privacy question: [contact email not set yet]