Legal
Privacy Policy
Last updated: August 26, 2026 · v2026-08-26
Engineer draft for transparency — not legal advice. A qualified lawyer should review before you treat this as final compliance guidance.
Engineer draft for transparency — not legal advice. A qualified lawyer should review before you treat this as final compliance guidance. This is not a “GDPR certified” claim.
Policy version: 2026-08-26 · Last updated: August 26, 2026
1. Who we are (controller / contact)
Insta24 operates insta24.net, app.insta24.net, m.insta24.net, and related applications for Instagram management and automation.
- Privacy contact: privacy@insta24.net — we aim to respond to access, export, deletion, and other rights requests within 30 days.
- General / support: hello@insta24.net, support@insta24.net
Controller identity (placeholder until counsel confirms): Insta24 is the brand behind these services. A registered legal entity name, company number, and registered office have not been published in this draft. Contact privacy@insta24.net. We have not appointed an EU or UK representative (GDPR Art. 27 / UK GDPR) in this draft — counsel should confirm whether one is required.
If you are in the EEA, UK, or Switzerland, Insta24 is the controller for personal data processed for our websites and your Insta24 account (login, billing for our SaaS, cookies, marketing preference), except where Meta or other providers act as independent controllers for their own services.
2. Two roles: your account vs your audience
| Role | Whose data | Who decides |
|---|---|---|
| Insta24 = controller | Your name, email, phone, Keycloak login, workspace membership, SaaS invoices, cookie consent, marketing opt-in | Insta24 |
| You (workspace) = controller; Insta24 = processor | Instagram followers’ DMs, comments, CRM contacts, appointments, shop orders, lottery entries, media you upload | You. See our Data Processing Addendum |
You must have a lawful basis (and Meta permission) for automations and messaging you configure. We process audience data only to provide the features you turn on.
3. Data we collect
| Category | Examples |
|---|---|
| Account | Name, email, phone, credentials via Keycloak (including Google login), locale, workspace membership, role |
| Billing | Plan, invoice number, amounts, period, payment status; Stripe and/or ZarinPal identifiers (we do not store full card numbers) |
| Instagram / Meta | Account IDs, usernames, pages you connect, encrypted access tokens, messaging and comment metadata needed to run features you configure |
| Product usage | Automation rules, inbox activity, feature settings, approximate usage metrics |
| Technical | IP address, device/browser info, logs, security events, error reports (Sentry — PII minimized) |
| Cookies / similar | Locale, consent choice, session/auth, analytics when allowed — Cookie Policy |
| Communications | Messages you send to support or sales |
| MCP / agents | OAuth grants if you connect an AI agent to Insta24 (revoked on account deletion) |
4. How we use data (lawful bases)
- Contract: provide the SaaS, authenticate, run automations you configure, process payments you start
- Legal obligation: keep anonymized invoice amounts/periods as required by tax and accounting law (duration to be confirmed by counsel, commonly 7–10 years; until then we retain those billing records after account closure rather than deleting them)
- Legitimate interests: security, fraud prevention, product reliability (you may object)
- Consent: marketing emails; non-essential analytics cookies in the EEA/UK/CH
We do not sell personal data for money. Under some US state laws, analytics may be treated as “sale” or “sharing” — opt out via Cookie settings.
Marketing emails are sent only if you opted in. Transactional mail (security, billing, product notices needed to run the account) is separate.
5. Meta / Instagram
Insta24 connects to Instagram Business or Creator accounts through Meta’s official authorization. Meta’s terms and privacy policy apply to data Meta processes. We only request permissions needed for features you use.
Disconnect vs delete: Disconnecting an Instagram account in the app stops new sync and clears our access token. Conversations, contacts, and orders we already stored remain until you use Disconnect and delete Meta-sourced data, Delete my data, or Meta’s deletion callback.
6. Subprocessors and sharing
See the public Subprocessors list. In summary: Cloudflare (CDN/Pages), our VPS (API, PostgreSQL, Redis, MinIO, self-hosted Keycloak), Stripe (global cards), ZarinPal (Iran-market billing only — EEA/UK/CH workspaces do not use this gateway), Sentry (EU ingest), Google (GTM/GA4 when consented; Google login), Meta (Instagram Graph). Transfers outside the EEA use appropriate safeguards such as standard contractual clauses where required.
7. Cookies
See the Cookie Policy. Necessary cookies support security, auth, and locale. Analytics cookies load only when allowed by your consent regime.
8. Retention
| Data | Period |
|---|---|
| Account and workspace product data | While the account is active; deleted or anonymized when you delete the account (subject to holds below) |
| SaaS billing invoices (number, amounts, period, status) | Held after account deletion for tax/fraud — counsel to confirm years; not full payer identity |
| Raw Meta webhook payloads | 90 days, then emptied (idempotency id may remain) |
| Automation execution logs and dead-letter jobs | 90 days, then deleted |
| Sentry error reports | Short operational window per Sentry project settings |
| Backups | We do not offer a consumer backup product. Operational database backups, if taken, age out on a limited window (typically up to 30 days), after which deleted live data is gone from backups too |
| Cookie consent | About 1 year, then we ask again |
9. International transfers
We may process data in countries other than where you live (infrastructure may be in the EU, US, or other regions). Where required, we use safeguards such as standard contractual clauses for transfers from the EEA/UK/CH.
Iran: GDPR does not automatically apply to purely Iran-resident processing. It does apply to EEA/UK/CH account holders on the same product, and to EEA Instagram users whose messages an Iran business stores in Insta24.
10. Your rights (EEA, UK, Switzerland)
You may have rights to access, rectify, erase, restrict, object, portability, and to withdraw consent where processing is consent-based. You may lodge a complaint with your local supervisory authority.
How to exercise them:
- Access / portability: Settings → Privacy → Download my data, or email privacy@insta24.net (30-day aim)
- Rectify: Settings → Profile (name, phone, locale)
- Erase: Settings → Privacy → Delete my data, or email us. Deletion is not total: tax-held billing records, Meta’s own copies, and backup lag remain as described above
- Marketing: Settings toggle, or the unsubscribe path when we send campaigns
- Cookies: Cookie settings in the footer / app
- Workspace audience data: export Contacts CSV / Booking CSV in the product; you are the controller for followers
US state privacy rights (know/delete/opt out of sale/sharing) can use Cookie settings or email.
11. Children’s data
Insta24 accounts are not directed to children under 16 (or a higher age required in your country). We do not run an identity age-check; a register checkbox is a statement, not verification. Instagram’s platform minimum (often 13+) is not the same as GDPR consent age.
Customers are responsible for their audience: do not use Insta24 to target or harvest data from children. See the DPA.
Contact us if you believe a child provided account data so we can delete it.
12. Teams
Deleting your account removes workspaces you own (and that tenant’s product data). Other members lose access to those workspaces. Removing a teammate only removes their membership — it does not delete their Insta24 login. You cannot delete another user’s Keycloak identity. Owners cannot “leave” a workspace; they must delete the account or keep it.
13. Security
We use administrative, technical, and organizational measures appropriate to the risk (HTTPS, access controls, encrypted Instagram tokens, monitoring). No method of transmission or storage is 100% secure. Significant breaches involving EEA personal data are handled under our internal 72-hour playbook.
14. Changes
We may update this policy and bump the policy version. Material changes that require re-acceptance for accounts are surfaced in the product.
15. Contact
Privacy requests: privacy@insta24.net