Privacy policy
Last Updated: December 22, 2024
Effective Date: December 22, 2024
Introduction
MYLINKPAL ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Instagram automation platform and related services (collectively, the "Service").
Business Information:
MYLINKPAL Proprietor: Sudharsan Kumar
Email: sudharsankumar@mylinkpal.co Website: https://mylinkpal.co
Please read this Privacy Policy carefully. By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with this Privacy Policy, please do not use the Service.
1. Information We Collect
We collect several types of information from and about users of our Service.
1.1 Information You Provide Directly
Account Information:
- Email address (for account creation and authentication via Clerk)
- Name (full name or business name)
- Payment information (processed by Lemon Squeezy or Razorpay - we do not store complete payment card details)
- Billing address and contact details
Service Configuration:
- Message templates and automation rules you create
- Keyword triggers and automation settings
- Custom configurations and preferences
1.2 Instagram Data Collected via Meta API
When you connect your Instagram Business or Creator account, we collect:
Instagram Account Information:
- Instagram User ID (IGSID)
- Instagram username and handle
- Profile picture URL
- Account type (Business or Creator)
- Follower count
- Account verification status
Instagram User Interactions:
- Direct Messages: Message content, sender IGSID, timestamps, read receipts, reaction emojis
- Comments: Comment text, commenter IGSID, post ID, timestamps
- Story Mentions: Mention content, story ID, sender IGSID, timestamps
- Story Replies: Reply content, story ID, sender IGSID, timestamps
Instagram Subscriber Data:
- IGSID of users who interact with your account
- Username and profile information of subscribers
- Conversation history and message threads
- Opt-out status and preferences
- Engagement metrics and interaction history
Purpose of Instagram Data Collection: We collect this data to provide our core automation service - processing triggers (keywords, comments, mentions) and sending automated responses to your Instagram followers. This data is essential for the Service to function.
1.3 Automatically Collected Information
Usage Data:
- Pages visited and features used within the Service
- Time and date of visits
- Time spent on pages
- Click-through rates and interaction patterns
- Automation performance metrics (messages sent, delivery rates, engagement)
Device and Technical Information:
- IP address
- Browser type and version
- Device type (mobile, desktop, tablet)
- Operating system
- Unique device identifiers
- Referring/exit pages
- Crash reports and error logs
1.4 Cookies and Tracking Technologies
We use cookies and similar tracking technologies:
Essential Cookies (Required for Service Operation):
- Authentication and session management
- Security and fraud prevention
- Load balancing and performance optimization
Analytics Cookies (With Your Consent):
- Usage analytics via PostHog Cloud
- Feature usage tracking
- Conversion and funnel analysis
- A/B testing and product optimization
Marketing Cookies (With Your Consent):
- Retargeting and advertising campaigns
- Email campaign tracking
- Referral source attribution
You can control cookie preferences through your browser settings or our cookie consent banner. However, disabling essential cookies may limit Service functionality.
2. How We Use Your Information
We use the collected information for the following purposes:
2.1 Service Delivery
- Account Management: Create and manage your account, authenticate users, provide customer support
- Instagram Automation: Process automation triggers, send automated messages, manage subscriber lists, track conversation history
- Payment Processing: Process subscription payments, manage billing, send invoices
- Service Communications: Send service notifications, account alerts, security warnings, and technical updates
2.2 Service Improvement
- Analytics and Research: Analyze usage patterns, improve features, identify bugs and performance issues
- Product Development: Develop new features, test improvements, optimize user experience
- Aggregated Insights: Create anonymized, aggregated reports on service usage and trends
2.3 Legal and Security
- Compliance: Comply with legal obligations, respond to lawful requests from authorities
- Security: Detect and prevent fraud, abuse, security incidents, and technical issues
- Enforcement: Enforce our Terms of Service, investigate violations, protect our rights and property
2.4 Marketing (With Your Consent)
- Promotional Communications: Send marketing emails, product updates, special offers (you can opt out anytime)
- Personalization: Customize your experience based on preferences and usage patterns
3. Legal Basis for Processing (GDPR)
For users in the European Union, we process your personal data under the following legal bases:
3.1 Contract (Article 6(1)(b) GDPR)
Processing is necessary to deliver the service you signed up for:
- Instagram account data (IGSID, username, messages, comments)
- Account information (email, subscription details)
- Usage data required to provide automation services
3.2 Legitimate Interest (Article 6(1)(f) GDPR)
We have legitimate business interests that do not override your privacy rights:
- Security and fraud prevention
- Service improvement and analytics
- Customer support and troubleshooting
- Network and information security
3.3 Consent (Article 6(1)(a) GDPR)
We obtain your explicit consent for:
- Marketing communications
- Non-essential analytics cookies
- Optional data processing beyond core service delivery
You may withdraw consent at any time without affecting the lawfulness of processing based on consent before withdrawal.
3.4 Legal Obligation (Article 6(1)(c) GDPR)
We process data to comply with legal requirements:
- Tax and accounting obligations
- Responses to lawful government requests
- Compliance with court orders
4. How We Share Your Information
We do not sell, rent, or trade your personal information. We share information only in the following limited circumstances:
4.1 Service Providers (Data Processors)
We share information with third-party service providers who process data on our behalf:
Infrastructure and Hosting:
- Supabase (database storage) - Privacy Policy: https://supabase.com/privacy
- Data Location: United States (Virginia)
- Planning EU region (Frankfurt) for EU users
- Standard Contractual Clauses in place for GDPR compliance
- Vercel (web application hosting) - Privacy Policy: https://vercel.com/legal/privacy-policy
- Data Location: Global CDN
- Railway (worker and webhook hosting) - Privacy Policy: https://railway.app/legal/privacy
- Data Location: United States
Authentication:
- Clerk (user authentication and identity management) - Privacy Policy: https://clerk.com/legal/privacy
- Processes: Email addresses, names, authentication credentials
Data Storage and Caching:
- Railway Redis (rate limiting, caching, session management)
- Data Location: United States
Payment Processing:
- Lemon Squeezy (international payments) - Privacy Policy: https://www.lemonsqueezy.com/privacy
- Processes: Payment information, billing addresses, email addresses
- Razorpay (India payments) - Privacy Policy: https://razorpay.com/privacy/
- Processes: Payment information, billing addresses, phone numbers
Analytics:
- PostHog Cloud (product analytics) - Privacy Policy: https://posthog.com/privacy
- Processes: Usage data, anonymized user behavior, feature interactions
- Data Location: United States
Instagram/Meta Platform:
- Meta Platforms, Inc. (Instagram API) - Privacy Policy: https://www.facebook.com/privacy/policy
- We access Instagram data through Meta's official APIs
- Subject to Meta's Platform Terms and Data Policy
All service providers are contractually obligated to:
- Use data only for providing services to us
- Implement appropriate security measures
- Comply with applicable data protection laws
- Delete or return data upon termination
4.2 Legal Requirements
We may disclose information if required by law or in good faith belief that such action is necessary to:
- Comply with legal obligations, court orders, or government requests
- Enforce our Terms of Service and investigate violations
- Protect the rights, property, or safety of MYLINKPAL, our users, or the public
- Detect, prevent, or address fraud, security, or technical issues
4.3 Business Transfers
If MYLINKPAL is involved in a merger, acquisition, asset sale, or bankruptcy:
- Your information may be transferred to the successor entity
- We will notify you via email and/or prominent notice on our Service
- You will have the opportunity to opt out before the transfer
4.4 With Your Consent
We may share information for any other purpose with your explicit consent.
5. Data Retention
We retain your information for as long as necessary to provide the Service and fulfill the purposes outlined in this Privacy Policy.
5.1 Account Data
Retention Period: Until you delete your account or request deletion
Includes:
- Email address and account credentials
- Subscription and billing history
- Account settings and preferences
After Deletion: Deleted within 7 days of account closure request
5.2 Instagram Data
Message History: Retention Period: 120 days from message date OR until you request deletion, whichever comes first
Includes:
- Direct message conversations
- Comment threads
- Story mention and reply history
Immediate Deletion Triggers:
- When an Instagram user deletes their account (Meta sends deletion webhook)
- When you manually delete message history
- When a subscriber opts out (deleted after 7 days)
After Deletion Request: Deleted within 7 days
Instagram Subscriber Records: Retention Period: Until you delete the subscriber or they opt out
After Opt-Out: Subscriber data deleted after 7 days; anonymized analytics retained
5.3 Analytics Data
Retention Period: Indefinitely (anonymized and aggregated)
Purpose: Service improvement, trend analysis, feature development
Important: Analytics data is stripped of personally identifiable information (PII) and cannot be linked back to individual users.
5.4 Backup Data
Retention Period: Up to 30 days in encrypted backups
Purpose: Disaster recovery and business continuity
After Deletion Request: Purged from backups within 30 days
5.5 Legal Hold
We may retain data longer if required by law, regulation, legal process, or to establish, exercise, or defend legal claims.
6. Data Security
We implement industry-standard security measures to protect your information:
6.1 Technical Safeguards
Encryption:
- Data in Transit: All data transmitted between your browser and our servers is encrypted using TLS 1.3 (HTTPS)
- Data at Rest: Sensitive data (passwords, Instagram access tokens) encrypted using AES-256-GCM
- Token Storage: Instagram access tokens encrypted before storage and decrypted only when needed
Access Controls:
- Role-Based Access Control (RBAC) - users can only access data they own
- Workspace isolation - data segregated by workspace
- Multi-factor authentication (2FA) available via Clerk
- API authentication using secure bearer tokens
Infrastructure Security:
- Firewalled databases and services
- Regular security monitoring and logging
- Automated vulnerability scanning
- DDoS protection via hosting providers
6.2 Organizational Safeguards
- Limited access to personal data (only necessary personnel)
- Secure development practices
- Regular security reviews
- Incident response procedures
6.3 Limitations
No system is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. You acknowledge that:
- Internet transmission is never completely secure
- Unauthorized third parties may unlawfully intercept data
- Security systems may be compromised
Your Responsibility:
- Keep your account credentials confidential
- Use strong, unique passwords
- Enable two-factor authentication
- Report suspicious activity immediately
7. Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal data:
7.1 Rights for All Users
Access: Request a copy of the personal data we hold about you
Correction: Request correction of inaccurate or incomplete data
Deletion: Request deletion of your personal data (subject to legal retention requirements)
Objection: Object to processing of your data for certain purposes
Portability: Request your data in a structured, machine-readable format
Withdrawal of Consent: Withdraw consent for marketing communications or optional processing
7.2 European Union Users (GDPR Rights)
In addition to the rights above, EU users have:
Right to Restriction: Request restriction of processing in certain circumstances
Right to Object to Automated Decision-Making: We do not use automated decision-making or profiling that produces legal effects
Right to Lodge a Complaint: File a complaint with your local data protection authority
Data Protection Officer: As a small business (sole proprietor), we are not required to appoint a DPO. Privacy inquiries should be directed to sudharsankumar@mylinkpal.co
7.3 California Users (CCPA Rights)
California residents have the right to:
Know: What personal information we collect, use, and disclose
Delete: Request deletion of your personal information
Opt-Out: We do not sell personal information, so no "Do Not Sell" option is required
Non-Discrimination: Exercise your rights without discriminatory treatment
7.4 India Users (IT Rules & SPDI)
Indian users have rights under the Information Technology Act, 2000 and Sensitive Personal Data or Information (SPDI) Rules:
Access and Correction: Review and correct your personal data
Withdrawal of Consent: Withdraw consent at any time
Grievance Redressal: Contact our Grievance Officer at sudharsankumar@mylinkpal.co
7.5 How to Exercise Your Rights
To exercise any of these rights:
Email: sudharsankumar@mylinkpal.co
Subject Line: "Privacy Rights Request - [Your Request Type]"
Include:
- Your full name and registered email address
- Specific right you wish to exercise
- Details of your request
- Proof of identity (if required)
Response Time: We will respond within 30 days (or as required by applicable law). For complex requests, we may extend this by an additional 30 days with notice.
8. Data Deletion and Meta Compliance
8.1 User-Initiated Deletion
You can request deletion of your data at any time:
How to Request:
- Email sudharsankumar@mylinkpal.co with subject "Data Deletion Request"
- Provide your account email address
- Specify what data you want deleted (account, messages, specific conversations)
Deletion Timeline:
- Account Data: Deleted within 7 days
- Message History: Deleted within 7 days
- Backups: Purged within 30 days
- Confirmation: You will receive email confirmation when deletion is complete
8.2 Instagram User Data Deletion (Meta Requirement)
When an Instagram user deletes their Instagram account:
- Meta sends us a deletion webhook with the user's IGSID
- We automatically delete all data associated with that IGSID within 30 days:
- All message conversations
- Subscriber records
- Profile information
- Interaction history
- Anonymized analytics may be retained (cannot be linked back to the user)
When an Instagram user opts out of your automation:
- We immediately stop sending messages to that user
- Message history is deleted after 7 days
- User can re-opt-in by messaging you again after 7 days
8.3 Data We Retain After Deletion
Even after deletion, we may retain:
- Anonymized analytics (no personal identifiers)
- Aggregated usage statistics
- Data required by law (e.g., tax records, legal proceedings)
- Data in encrypted backups for up to 30 days
9. International Data Transfers
MYLINKPAL operates globally, and your data may be transferred to and processed in countries other than your own.
9.1 Data Transfer Locations
Primary Data Storage:
- United States (Supabase US region - Virginia)
- Future: European Union (Supabase EU region - Frankfurt) for EU users
Other Locations:
- Service providers may process data in various global locations
- All transfers comply with applicable data protection laws
9.2 GDPR Compliance for EU Data Transfers
For transfers of EU personal data to the United States or other non-EU countries:
Standard Contractual Clauses (SCCs):
- We use European Commission-approved SCCs with our US service providers
- Supabase has implemented SCCs for GDPR compliance
- SCCs ensure adequate data protection safeguards
Additional Safeguards:
- Encryption in transit and at rest
- Access controls and monitoring
- Regular security assessments
- Contractual obligations with service providers
Planned EU Data Residency:
- We are planning to migrate EU user data to Supabase EU region (Frankfurt)
- EU user data will remain within the European Union
- No SCCs required for intra-EU transfers
10. Children's Privacy
Our Service is designed for Instagram Business and Creator accounts, which are subject to Meta's platform eligibility requirements.
We do not knowingly collect data from individuals who do not meet Meta's Instagram platform eligibility requirements.
Instagram Business and Creator accounts are intended for businesses, brands, organizations, and content creators. Users must comply with Meta's Terms of Service, which include age and eligibility restrictions.
If we become aware that we have inadvertently collected personal information from someone who does not meet these requirements:
- We will delete the information as soon as possible
- We will terminate the associated account
- Parents or guardians can contact us at sudharsankumar@mylinkpal.co
11. Third-Party Links and Services
Our Service may contain links to third-party websites, apps, or services not operated by us:
We are not responsible for:
- Privacy practices of third-party websites
- Content or accuracy of external sites
- Data collection by third-party services
Examples of third-party services:
- Meta/Facebook/Instagram
- Payment processors
- Analytics providers
- Hosting providers
We strongly advise you to:
- Review the privacy policies of any third-party sites you visit
- Understand how they collect, use, and protect your data
- Make informed decisions about sharing information
Our integration with third parties:
- Uses official APIs and authorized methods
- Complies with third-party terms and policies
- Limits data sharing to what's necessary for Service operation
12. Marketing Communications and Opt-Out
12.1 Types of Communications
Service Communications (Cannot Opt Out):
- Account notifications and security alerts
- Billing and payment confirmations
- Service updates affecting your account
- Legal notices and policy changes
Marketing Communications (Can Opt Out):
- Product updates and new features
- Tips and best practices
- Special offers and promotions
- Company news and blog posts
12.2 How to Opt Out of Marketing
You can opt out of marketing emails at any time:
Option 1: Unsubscribe Link
- Click "Unsubscribe" at the bottom of any marketing email
- Takes effect immediately
Option 2: Email Request
- Send email to sudharsankumar@mylinkpal.co
- Subject: "Unsubscribe from Marketing"
- Processed within 2 business days
Option 3: Account Settings
- Update email preferences in your account dashboard
After Opt-Out:
- You will stop receiving marketing emails within 48 hours
- You will still receive essential service communications
- You can re-subscribe at any time
13. Data Breach Notification
In the event of a data breach that affects your personal information:
13.1 Our Obligations
Notification Timeline:
- We will notify affected users within 72 hours of discovering the breach
- We will notify relevant authorities as required by law (e.g., GDPR supervisory authorities)
Notification Method:
- Email to your registered email address
- In-app notification or dashboard alert
- Public notice on our website (for large-scale breaches)
Information Provided:
- Nature of the breach and data affected
- Likely consequences of the breach
- Measures taken to address the breach
- Recommended actions for affected users
- Contact information for inquiries
13.2 Our Response
Immediate Actions:
- Contain and investigate the breach
- Assess the scope and impact
- Implement remediation measures
- Notify law enforcement if criminal activity suspected
Long-Term Measures:
- Review and strengthen security controls
- Update security policies and procedures
- Provide support to affected users
- Cooperate with regulatory investigations
14. Cookie Policy
14.1 What Are Cookies
Cookies are small text files stored on your device when you visit our website. They help us:
- Remember your preferences and settings
- Understand how you use our Service
- Improve your experience
- Deliver relevant content
14.2 Types of Cookies We Use
Essential Cookies (Always Active):
- Session management and authentication
- Security and fraud prevention
- Load balancing
- CSRF protection
These cookies are necessary for the Service to function and cannot be disabled.
Analytics Cookies (Requires Consent):
- PostHog analytics
- Usage tracking and heatmaps
- Feature adoption metrics
- Performance monitoring
Marketing Cookies (Requires Consent):
- Email campaign tracking
- Retargeting campaigns
- Conversion tracking
- Referral attribution
14.3 Managing Cookies
Browser Settings:
- Most browsers allow you to block or delete cookies
- Instructions: Check your browser's help section
- Warning: Blocking essential cookies will prevent the Service from working properly
Cookie Consent Banner:
- On first visit, you'll see our cookie consent banner
- Choose which non-essential cookies to accept
- Update preferences at any time in Account Settings
Opt-Out of Analytics:
- Disable analytics cookies in your preferences
- Use browser "Do Not Track" settings (we honor DNT signals)
14.4 Third-Party Cookies
Our Service may use third-party cookies from:
- PostHog (analytics)
- Lemon Squeezy / Razorpay (payment processing)
- Clerk (authentication)
These are governed by the respective third-party privacy policies.
15. Changes to This Privacy Policy
15.1 How We Update This Policy
We may update this Privacy Policy from time to time to reflect:
- Changes in our data practices
- New features or services
- Legal or regulatory requirements
- Feedback from users
Last Updated Date: We will update the "Last Updated" date at the top of this policy
15.2 Notification of Material Changes
For material changes, we will:
- Send you an email notification at least 3 days before the changes take effect
- Post a prominent notice on our website
- Provide a summary of key changes
Material changes include:
- New types of data collection
- Changes to how we share data
- Reduction in your privacy rights
- Changes to data retention periods
15.3 Notification of Minor Changes
For minor changes (e.g., clarifications, typo fixes, formatting):
- We will update the "Last Updated" date only
- No email notification required
- Changes take effect immediately upon posting
15.4 Your Acceptance
Continued use of the Service after changes constitutes acceptance of the updated Privacy Policy.
If you do not agree to the changes:
- Stop using the Service
- Contact us to delete your account
- Request deletion of your data
16. Contact Us and Grievance Redressal
16.1 Privacy Inquiries
For questions, concerns, or requests regarding this Privacy Policy or your personal data:
Email: sudharsankumar@mylinkpal.co Subject Line: "Privacy Inquiry - [Your Topic]"
Website: https://mylinkpal.co
Response Time: We aim to respond within 2 business days
16.2 Grievance Officer (India IT Rules)
In accordance with India's Information Technology Act, 2000 and SPDI Rules:
Grievance Officer: Sudharsan Kumar (Proprietor) Email: sudharsankumar@mylinkpal.co Response Time: Within 30 days of receiving the complaint
16.3 Data Protection Authorities
European Union Users: You have the right to lodge a complaint with your local supervisory authority if you believe we have violated GDPR.
Find your authority: https://edpb.europa.eu/about-edpb/board/members_en
California Users: For CCPA complaints, contact the California Attorney General: https://oag.ca.gov/contact/consumer-complaint-against-business-or-company
17. Additional Disclosures for Specific Jurisdictions
17.1 India-Specific Disclosures
Reasonable Security Practices: We comply with Rule 8 of the SPDI Rules by implementing:
- Comprehensive security policies
- Encryption of sensitive data
- Access controls and monitoring
- Regular security audits
Consent for SPDI Processing: By using the Service, you consent to our collection and processing of Sensitive Personal Data or Information (as defined under Indian law), including:
- Financial information (for payments)
- Passwords (encrypted)
Data Retention Compliance: We retain data only as long as necessary for the purposes stated in this policy or as required by Indian law.
17.2 California-Specific Disclosures (CCPA)
Categories of Personal Information Collected:
- Identifiers (name, email, IP address)
- Commercial information (subscription history)
- Internet activity (usage data)
- Financial information (payment details via processors)
Categories of Sources:
- Directly from you
- Automatically through your use of the Service
- From Instagram via Meta API
Business Purposes for Collection:
- Providing and improving the Service
- Security and fraud prevention
- Legal compliance
Categories of Third Parties with Whom We Share:
- Service providers (hosting, analytics, payments)
- Professional advisors (legal, accounting)
- Law enforcement (when required)
Sale of Personal Information: We do NOT sell personal information. We have not sold personal information in the past 12 months.
Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
17.3 European Union-Specific Disclosures (GDPR)
Data Controller: MYLINKPAL (Sudharsan Kumar, Proprietor) Contact: sudharsankumar@mylinkpal.co
Data Protection Officer: Not required (business with fewer than 250 employees)
Legal Bases for Processing: See Section 3 (Legal Basis for Processing)
International Transfers: See Section 9 (International Data Transfers)
Automated Decision-Making: We do not engage in automated decision-making or profiling that produces legal effects.
Data Retention Periods: See Section 5 (Data Retention)
Your Rights: See Section 7 (Your Privacy Rights)
Right to Lodge a Complaint: You may file a complaint with your local supervisory authority.
18. Meta Platform Data Use Disclosure
18.1 Instagram API Usage
Our Service uses Meta's Instagram Messaging API to:
- Receive messages, comments, and story mentions from your Instagram followers
- Send automated responses on your behalf
- Manage subscriber lists and conversation history
- Track message delivery and engagement
18.2 Data Received from Instagram
We receive the following data from Instagram (via Meta API):
- Instagram User IDs (IGSID) of users who interact with your account
- Usernames and profile information
- Message content, timestamps, and metadata
- Comment content and metadata
- Story mention and reply content
- Read receipts and reaction data
18.3 How Instagram Data is Used
We use Instagram data ONLY to:
- Deliver the automation service you configured
- Display conversation history in your dashboard
- Provide analytics on automation performance
- Manage opt-outs and deletion requests
We do NOT:
- Sell Instagram user data to third parties
- Use Instagram data for purposes unrelated to our Service
- Share Instagram data with advertisers
- Use Instagram data to build user profiles for other purposes
18.4 Instagram User Rights
Instagram users who interact with your account can:
- Opt out of automation by sending "STOP" or similar keywords
- Request deletion of their message history
- Delete their Instagram account (which triggers automatic data deletion on our end)
You (as the MYLINKPAL user) are responsible for:
- Providing privacy notices to your Instagram followers
- Honoring opt-out requests
- Complying with Meta's data policies
- Obtaining necessary consents for data processing
18.5 Meta's Data Policies
By using our Service, you agree to comply with:
- Meta's Platform Terms: https://developers.facebook.com/terms
- Meta's Data Policy: https://www.facebook.com/privacy/policy
- Instagram's Terms of Use: https://help.instagram.com/581066165581870
Meta may independently collect data about your use of Instagram. Refer to Meta's Privacy Policy for details.
By using MYLINKPAL, you acknowledge that you have read, understood, and agree to this Privacy Policy.
Last Updated: December 22, 2024