1. Introduction
Welcome to Conect ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our agency management platform.
By using Conect, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our service.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address (required for authentication)
- Display name
- Account type (agency or solopreneur)
- Organization name and details
Note: We do not collect mobile phone numbers anywhere in our platform.
2.2 Customer Information
When you add customers to your organization, we store:
- Customer name and business information
- Contact email and phone (if provided)
- Business address (if provided)
- Professional information
2.3 Social Account Information
When you connect social media accounts (such as Instagram) to manage on behalf of your customers, we collect and store:
- Access Tokens: Encrypted authentication tokens required to access social media APIs on your behalf
- Profile Data: Username, profile picture, follower count, bio, and other public profile information
- Media Data: Recent posts, captions, and media metadata (for display and management purposes)
- Account Type: Whether the account is personal, business, or creator account
Important: All access tokens and credentials are encrypted using industry-standard encryption (AES-256-GCM) before storage. We never store passwords or unencrypted credentials.
2.4 Usage and Technical Information
We automatically collect:
- IP addresses and browser information
- Device information and operating system
- Usage patterns and feature interactions
- Audit logs of system events (for security and compliance)
3. How We Use Your Information
We use the collected information to:
- Provide, maintain, and improve our services
- Authenticate users and manage accounts
- Enable organization and team management features
- Connect and manage social media accounts on your behalf
- Sync and display social media profile data and content
- Send important service-related communications
- Monitor and analyze usage patterns to improve our platform
- Ensure security and prevent fraud
- Comply with legal obligations
4. Meta Platform Integration and Platform Data Usage
Our Service integrates with Meta platforms (Facebook, Instagram, and Threads) through official Meta APIs to provide social media management and content embedding capabilities. This section explains how we collect, use, and protect Platform Data (any information or data obtained from Meta platforms) in compliance with Meta's Platform Data Use Policy.
4.1 Authentication and Account Connection
When you connect Meta platform accounts (Facebook Pages, Instagram Business/Creator accounts) through our platform:
- We use OAuth 2.0 authentication, which allows you to grant us limited access to your Meta platform accounts without sharing your password
- We store encrypted access tokens that enable us to access Meta APIs on your behalf
- We automatically refresh these tokens to maintain access without requiring re-authentication
- You can disconnect your Meta platform accounts at any time, which will revoke our access
- We only request and access permissions necessary for the features you use
4.2 Instagram Graph API Integration
We use Meta's Instagram Graph API to enable you to manage your Instagram Business and Creator accounts. Through this integration, we may collect and process the following Platform Data:
- Profile Information: Username, profile picture, biography, follower count, and other public profile data
- Content Data: Posts, stories, reels, carousels, captions, hashtags, and media metadata for content management and publishing
- Engagement Data: Comments, likes, shares, and other engagement metrics (when permissions are granted)
- Account Information: Account type, linked Facebook Page information, and account settings
Purpose of Use: We use this Platform Data solely to:
- Enable you to publish and schedule content to your Instagram accounts
- Display your Instagram profile and content within our platform
- Provide content management and scheduling features
- Enable engagement management features (comments, messages) when authorized
Permissions Used: We request the following permissions through Instagram Graph API:pages_show_list, pages_read_engagement, and instagram_content_publish. These permissions are requested only when you explicitly connect your Instagram account and authorize the integration.
4.3 Facebook Pages API Integration
We use Meta's Facebook Pages API to enable you to manage your Facebook Pages. Through this integration, we may collect and process the following Platform Data:
- Page Information: Page name, profile picture, cover photo, description, and other page metadata
- Content Data: Posts, photos, videos, albums, events, and associated metadata for content management and publishing
- Engagement Data: Comments, reactions, shares, and other engagement metrics for posts (when permissions are granted)
- Page Insights: Basic engagement metrics and page performance data (when permissions are granted)
Purpose of Use: We use this Platform Data solely to:
- Enable you to publish and schedule content to your Facebook Pages
- Display your Facebook Page information and content within our platform
- Provide content management and scheduling features
- Enable engagement management features (comments, reactions) when authorized
Permissions Used: We request the following permissions through Facebook Pages API:pages_show_list, pages_read_engagement, pages_manage_posts, pages_manage_metadata, pages_read_user_content, and pages_manage_engagement. These permissions are requested only when you explicitly connect your Facebook Page and authorize the integration.
4.4 oEmbed API Integration
We use Meta's oEmbed API to enable embedding of publicly available content from Facebook, Instagram, and Threads on websites and applications. Through this integration, we may collect and process the following Platform Data:
- Public Content: Publicly available posts, images, videos, and associated metadata (captions, timestamps, engagement metrics)
- Embedding Information: URLs, embed codes, and formatting data necessary to display content on external websites
- Content Creator Information: Public profile information (username, profile picture) for attribution purposes
Purpose of Use: We use this Platform Data solely to:
- Enable users to embed and display Meta platform content on their websites and applications
- Provide proper attribution to content creators and original sources
- Maintain compliance with Meta's Terms of Service and Community Standards
Important: We only embed content that is publicly available. We do not access, collect, or embed private or restricted content. All embedded content is sourced directly from Meta's official oEmbed API endpoints.
4.5 Compliance with Meta's Platform Data Use Policy
Our use of all Meta APIs and Platform Data complies with Meta's Platform Data Use Policy:
- Authorized Use Only: We use Platform Data only as authorized by you through OAuth permissions and solely to provide the services you request
- No Unauthorized Sharing: We do not share Platform Data with unauthorized third parties. Platform Data is only shared with Meta's APIs as necessary to provide our services
- No Advertising Use: We do not use Platform Data for advertising, marketing, or any purpose other than providing the specific service features you authorize
- No Data Scraping: We do not engage in data scraping or automated data collection from Meta platforms outside of official APIs
- Data Minimization: We only collect and store Platform Data that is necessary for the features you use
- Secure Storage: All Platform Data, including access tokens, is encrypted and stored securely
4.6 Prohibited Activities
We do not engage in any of the following prohibited activities with Platform Data:
- Data scraping or automated data collection from Meta platforms outside of official APIs
- Using Platform Data for advertising, marketing, or monetization purposes
- Sharing Platform Data with unauthorized third parties
- Modifying, misrepresenting, or altering content in ways that violate Meta's policies
- Storing Platform Data beyond what is necessary for the authorized service features
- Using Platform Data to build competing services or products
- Combining Platform Data with data from other sources to identify users without authorization
4.7 Third-Party Services and Policies
Our Meta platform integrations are powered by official APIs provided by Meta. Your use of these integrations is also subject to:
- Meta Terms of Service: Facebook Terms of Service, Instagram Terms of Use
- Meta Privacy Policy: Meta Privacy Policy
- Meta Platform Data Use Policy: We comply with Meta's Platform Data Use Policy, which governs how developers can use data obtained from Meta platforms
- Meta Community Standards: We respect and comply with Meta's Community Standards when accessing and displaying content
5. User Rights and Data Control
You have the right to:
- Access: Request access to your personal data and Platform Data we hold
- Correction: Update or correct inaccurate information through your account settings
- Deletion: Request deletion of your account and associated data, including Platform Data
- Disconnect Meta Accounts: Disconnect any connected Meta platform accounts at any time, which will revoke our access and stop Platform Data collection
- Export: Request a copy of your data, including Platform Data, in a portable format
- Opt-Out: Unsubscribe from non-essential communications
- Content Removal: If you are a content creator, you can request removal of your content from our embedding service by contacting us or making your content private on the original Meta platform
To exercise these rights, please contact us at the email address provided below. When you disconnect a Meta platform account, we will immediately stop collecting new Platform Data from that account and will delete stored Platform Data in accordance with our data retention policies and Meta's requirements.
6. Data Storage and Security
We take data security seriously and implement industry-standard measures to protect your information:
- Encryption: All sensitive data, including social media access tokens, are encrypted at rest using AES-256-GCM encryption
- Secure Transmission: All data is transmitted over HTTPS/TLS encrypted connections
- Database Security: We use Supabase with Row Level Security (RLS) to ensure data isolation between organizations
- Access Controls: Only authorized personnel with necessary permissions can access your data
- Regular Audits: We maintain audit logs of all system events for security monitoring
However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.
7. Data Sharing and Disclosure
We do not sell your personal information. We may share your information:
- With Service Providers: We use Supabase for authentication and database services. They process data on our behalf under strict confidentiality agreements
- With Social Media Platforms: When you connect social accounts, we interact with their APIs (Instagram Graph API, etc.) as authorized by you
- With Meta Platforms: When you connect Meta platform accounts or use embedding features, we interact with Meta's APIs (Instagram Graph API, Facebook Pages API, oEmbed API) as authorized by you. This interaction is necessary for the service functionality and is performed in compliance with Meta's Platform Data Use Policy
- For Legal Compliance: If required by law, court order, or government regulation
- To Protect Rights: To protect our rights, privacy, safety, or property, or that of our users
- With Your Consent: In any other situation with your explicit consent
Platform Data: We do not share Platform Data obtained through Meta's APIs (Instagram Graph API, Facebook Pages API, oEmbed API) with any third parties except as necessary to provide the authorized service features or as required by law. We do not sell, rent, or monetize Platform Data. Platform Data is only shared with Meta's APIs as necessary to provide the services you authorize.
8. Your Rights and Choices
You have the right to:
- Access: Request access to your personal data we hold
- Correction: Update or correct inaccurate information through your account settings
- Deletion: Request deletion of your account and associated data
- Disconnect Social Accounts: Disconnect any connected social media accounts at any time
- Export: Request a copy of your data in a portable format
- Opt-Out: Unsubscribe from non-essential communications
To exercise these rights, please contact us at the email address provided below.
9. Data Retention
We retain your personal information for as long as your account is active or as needed to provide services. When you delete your account, we will delete or anonymize your personal information, except where we are required to retain it for legal, regulatory, or audit purposes.
Social media access tokens are automatically revoked when you disconnect accounts or delete your organization.
Platform Data Retention: We retain Platform Data obtained through Meta's APIs only as long as necessary to provide the authorized service features:
- Instagram Graph API & Facebook Pages API: Platform Data is retained while your account is connected and for a reasonable period after disconnection to ensure service continuity. When you disconnect an account, we delete Platform Data in accordance with Meta's Platform Data Use Policy
- oEmbed API: Platform Data is retained only as long as necessary for the immediate embedding request. We do not store Platform Data beyond what is required for the embedding functionality, in compliance with Meta's Platform Data Use Policy
All Platform Data is deleted when you disconnect Meta platform accounts or delete your organization, in compliance with Meta's Platform Data Use Policy requirements.
10. Children's Privacy
Our service is not intended for users under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.
11. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country. By using our service, you consent to the transfer of your information to these countries.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. You are advised to review this Privacy Policy periodically for any changes.
13. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at:
Email: parthc2002@gmail.com
Platform: Conect — Agency Management Platform