Legal

Privacy Policy

Effective 1 August 2026 Last updated 8 August 2026 Version 1.0

MaCommerce (“we”, “us”) provides software that helps Instagram Business accounts respond to customer comments and messages and complete sales. This policy explains what data we handle, why, how long we keep it, and how you can have it deleted. It covers our website and our web application.

01Who we are

MaCommerce is the data controller for the information described here. You can reach us at privacy@macommerce.shop for any privacy request.

02Data we collect

CategoryExamplesSource
AccountName, email address, business name, password hashYou, at sign-up
Instagram profileInstagram Business account ID, username, profile picture URL, connected Facebook Page IDMeta, on authorisation
CommentsComment ID, comment text, media (post) ID, commenter's Instagram-scoped user ID and usernameMeta webhooks
MessagesMessage ID, conversation ID, message text and attachment references sent or received through your accountMeta webhooks / API
CommerceProduct names, prices, stock levels, order and invoice records, delivery address supplied by the buyerYou and your customers
TechnicalIP address, browser and device type, timestamps, application error logsAutomatically

We do not collect payment card details. Payments, where offered, are processed by a third-party payment provider that receives the transaction data directly.

03Data received from Meta platforms

When you connect your Instagram Business account, you grant MaCommerce a scoped access token via Facebook Login. We never receive or store your Instagram or Facebook password. We request only the permissions our features require:

  • instagram_business_basic — to identify the connected account and its posts.
  • instagram_business_manage_comments — to receive comment webhooks and send private replies to people who comment on your posts.
  • instagram_business_manage_messages — to read and send direct messages so purchase inquiries, addresses and order confirmations can be handled in one place.
  • pages_show_list — to list the Facebook Pages linked to your Instagram account during setup.

You can revoke these permissions at any time in your Facebook settings under Settings & Privacy → Settings → Business integrations. Revoking immediately stops all data flow to MaCommerce.

Platform data use. Data obtained from Meta is used solely to deliver the features you enabled. We do not sell it, do not use it for advertising or ad targeting, do not build user profiles for resale, and do not transfer it to data brokers or analytics networks.

04How we use your data

  • To detect comments containing your configured trigger words and send the corresponding private reply.
  • To present your conversations, orders and invoices in your dashboard.
  • To create and track invoices and order status.
  • To provide support, investigate faults, and prevent abuse and fraud.
  • To send essential service notices (for example, a disconnected Instagram account).

We do not use automated decision-making that produces legal effects for individuals.

05Legal basis

Where the GDPR or similar laws apply, we rely on: performance of a contract (operating the service you signed up for), legitimate interests (security, abuse prevention, product reliability), consent (where you explicitly enable an optional feature), and legal obligation (retaining transaction records where required).

06Sharing and disclosure

We do not sell or rent personal data. We share data only with processors that are necessary to run the service, and only to the extent required:

  • Cloud hosting and database providers — to store and serve your data.
  • Transactional email provider — to deliver account and order emails.
  • Payment provider — to process payments you initiate.
  • Error monitoring — to capture application errors, with message contents excluded where technically possible.

All processors are bound by data-processing agreements. We may also disclose data where required by law or to protect our rights or the safety of users.

07Retention

DataKept for
Comment & message records12 months from receipt, then deleted
Order & invoice recordsUp to 7 years where tax law requires; otherwise 24 months
Access tokensUntil you disconnect or revoke, then deleted immediately
Technical logs90 days
Account dataDeleted within 30 days of account closure

08Security

Data is transmitted over HTTPS/TLS and stored on access-controlled infrastructure. Access tokens and passwords are stored encrypted or hashed. Access to production data is limited to personnel who need it and is logged. All webhook payloads from Meta are signature-verified before processing. No system is perfectly secure, but we will notify you and, where required, the relevant supervisory authority without undue delay if a breach affects your data.

09Your rights

Subject to applicable law, you may request access to your data, correction of inaccurate data, deletion, restriction of processing, a portable copy, or object to processing based on legitimate interests. Write to privacy@macommerce.shop; we respond within 30 days. If you are in the EEA or UK you may also complain to your local data protection authority.

10Deleting your data

Step-by-step instructions — including the self-service option and the email route for Instagram users who are not MaCommerce customers — are on our Data Deletion Instructions page.

11Children

MaCommerce is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children. If you believe a child's data has reached us, contact us and we will remove it.

12Changes to this policy

If we make material changes we will update the “last updated” date above and notify account holders by email at least 14 days before the change takes effect. Continued use after that date constitutes acceptance.

13Contact

MaCommerce · Privacy
Email: privacy@macommerce.shop
General: hello@macommerce.shop

MaCommerce is an independent product and is not affiliated with, endorsed by, or sponsored by Meta Platforms, Inc.