Privacy Policy
Last Updated: December 14, 2025
1. Introduction
Welcome to Socialync. We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, and share information about you when you use our social media management platform and connect your social media accounts.
2. Information We Collect
2.1 Information You Provide Directly
- Account information (name, email address, password)
- Profile information and preferences
- Content you create, upload, or schedule (text, images, videos)
- Payment and billing information (processed securely through Stripe)
- Communications with our support team
2.2 Information from Connected Social Media Platforms
When you connect your social media accounts, we collect specific information as authorized by you and permitted by each platform's API:
Facebook Data Collection
- Page Information: Page names, IDs, and access tokens for pages you manage
- Basic Metrics: Public engagement data (likes, comments, shares) only for content you post through our platform
- Account Verification: Basic profile information to verify account ownership
- Publishing Data: Success/failure status of posts made through our platform
Instagram Data Collection
- Business Account Info: Instagram Business account username, ID, and basic profile data
- Content Publishing: Media upload capabilities and posting confirmations
- Basic Analytics: Public engagement metrics only for content posted through our platform
- Account Connection: Verification of Instagram Business account linkage to Facebook Pages
Twitter Data Collection
- Profile Information: Username, display name, profile picture, and public profile data
- Tweet Publishing: Ability to post tweets on your behalf when you use our platform
- Public Metrics: Follower count and public engagement data for analytics
- Account Verification: Basic account information to confirm identity and permissions
TikTok Data Collection
- User Profile: Basic user information including username and profile details
- Video Upload: Capability to upload and publish video content to your account
- Publishing Status: Confirmation of successful uploads and any error messages
- Content Settings: Privacy settings for uploaded videos (comments, duets, stitching)
YouTube Data Collection
- Channel Information: Channel name, ID, description, and basic statistics
- Video Upload: Capability to upload videos to your channel
- Video Metadata: Titles, descriptions, tags, and thumbnails for uploaded content
- Analytics Data: View counts, engagement metrics, and performance data for content posted through our platform
- Channel Settings: Video privacy settings and monetization status
LinkedIn Data Collection
- Profile Information: Name, headline, profile picture, and basic professional information
- Content Publishing: Ability to create posts and articles on your behalf
- Company Pages: Access to company pages you manage (with additional permissions)
- Network Information: Basic network size and professional connections count
2.3 Automatically Collected Information
- Usage analytics (pages visited, features used, time spent)
- Device information (browser type, operating system, IP address)
- Performance data (error logs, response times, system performance)
- Security information (login attempts, authentication events)
3. How We Use Your Information
We use your information to provide, maintain, and improve our services:
- Service Delivery: Enable posting, scheduling, and content management across platforms
- Account Management: Maintain your account, verify connections, and process payments
- Content Processing: AI-powered content generation and optimization (premium features)
- Analytics & Insights: Provide performance metrics and optimization recommendations
- Platform Compliance: Ensure all content meets platform guidelines and policies
- Technical Support: Troubleshoot issues and provide customer assistance
- Security: Detect fraud, prevent abuse, and protect account security
- Legal Compliance: Meet legal obligations and respond to lawful requests
4. Platform-Specific Data Handling
4.1 Facebook/Meta Data Compliance
- Data Minimization: We only access pages and data you explicitly connect
- User Control: You can disconnect pages and revoke access at any time
- Meta Platform Policy Compliance: All data usage complies with Meta's Platform Policy
- No Data Sharing: Facebook/Instagram data is never shared with third parties
- Retention Limits: Page access tokens are refreshed regularly; inactive connections are removed after 90 days
4.2 Google/YouTube API Compliance
- Limited Use Policy: YouTube data usage strictly adheres to Google's API Services User Data Policy
- No Data Transfer: YouTube data is never transferred to third parties
- Human Access Restrictions: YouTube data is only accessed by automated systems unless required for security
- No AI Training: YouTube data is never used for AI training or machine learning models
- User Consent: All YouTube actions require explicit user consent through our interface
- Data Deletion: YouTube access tokens and data are immediately deleted when you disconnect
4.3 Twitter API Compliance
- Developer Agreement: All usage complies with Twitter's Developer Agreement
- Content Policy: We enforce Twitter's content policies for all posted content
- Rate Limiting: API usage respects Twitter's rate limits and best practices
- Data Accuracy: Profile and metric data is refreshed regularly for accuracy
4.4 TikTok Developer Compliance
- Developer Policy: All integrations follow TikTok's Developer Policy
- Content Guidelines: Uploaded content must comply with TikTok's Community Guidelines
- Limited Data Access: Only basic profile and upload capabilities are accessed
- User Safety: Content moderation features are respected and maintained
4.5 LinkedIn API Compliance
- Professional Standards: All usage maintains LinkedIn's professional platform standards
- Content Quality: Published content adheres to LinkedIn's content policies
- Member Privacy: Personal connections and private member data are never accessed
- Company Pages: Company page management requires explicit authorization
5. Data Sharing and Disclosure
We do not sell, rent, or trade your personal information. We may share your information only in the following limited circumstances:
- With Connected Platforms: Content and data you explicitly choose to post to your connected social media accounts
- Service Providers: Trusted third-party providers who assist with hosting, payment processing, and analytics (under strict data agreements)
- Legal Requirements: When required by law, court order, or to protect rights and safety
- Business Transfers: In connection with mergers or acquisitions (with advance notice and data protection measures)
- With Your Consent: Any other sharing only with your explicit authorization
6. Data Security and Protection
6.1 Technical Safeguards
- Encryption in Transit: All data transmission uses TLS 1.3 encryption
- Encryption at Rest: All stored data, including OAuth tokens, is encrypted using AES-256
- Secure Authentication: Multi-factor authentication and secure session management
- API Security: Rate limiting, request validation, and secure token storage
- Database Security: Encrypted databases with access controls and regular security updates
6.2 Access Controls
- Principle of Least Privilege: System access limited to minimum necessary permissions
- Administrative Security: Multi-factor authentication required for admin access
- Regular Audits: Periodic review of access permissions and security practices
- Secure Development: Security-focused coding standards and regular code reviews
6.3 Monitoring and Response
- Security Monitoring: 24/7 monitoring for threats and unauthorized access
- Incident Response: Documented procedures for security incidents
- Vulnerability Management: Regular security assessments and penetration testing
- Compliance Monitoring: Continuous monitoring for platform policy compliance
7. Data Retention and Deletion
7.1 General Data Retention
- Account Data: Retained while your account is active and for 30 days after deletion
- Content Data: Drafts and scheduled posts retained until posted or manually deleted
- Analytics Data: Aggregated performance data retained for up to 2 years
- Support Data: Customer support communications retained for 1 year
7.2 Platform-Specific Retention
- OAuth Tokens: Automatically refreshed; immediately deleted when you disconnect platforms
- YouTube Data: Deleted within 30 days of disconnection for account recovery, then permanently removed
- Platform Analytics: Basic engagement metrics retained for 90 days to provide insights
- Error Logs: Technical logs retained for 30 days for debugging and improvement
8. Your Privacy Rights
You have comprehensive control over your data and privacy:
8.1 Access and Portability
- Data Access: Request a copy of all personal data we hold about you
- Data Export: Download your content, analytics, and account information
- Account Overview: View all connected platforms and permissions in your settings
8.2 Control and Modification
- Data Correction: Update or correct your personal information at any time
- Platform Management: Connect, disconnect, or modify platform connections individually
- Content Control: Edit, delete, or modify any content before or after posting
- Privacy Settings: Adjust data sharing and analytics preferences
8.3 Deletion and Withdrawal
- Platform Disconnection: Instantly revoke access to any connected platform
- Account Deletion: Permanently delete your account and all associated data
- Consent Withdrawal: Withdraw consent for specific data processing activities
- Data Deletion: Request deletion of specific data categories
9. International Data Transfers
Our services operate globally, and your data may be transferred to and processed in countries other than your own. We ensure adequate protection through:
- Adequacy Decisions: Transfers to countries with adequate data protection laws
- Standard Contractual Clauses: EU-approved contract terms for international transfers
- Platform Compliance: Following each social media platform's international data policies
- Security Measures: Additional safeguards for cross-border data protection
10. Children's Privacy
Our service is not intended for children under 16. We do not knowingly collect personal information from children under 16. If you believe we have collected information from a child under 16, please contact us immediately for deletion. Platform age requirements (13+ for most platforms, 18+ for some features) also apply to content posting.
11. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices, legal requirements, or platform policies. Material changes will be communicated through:
- Email notification to your registered email address
- Prominent notice in our application
- Updated "Last Updated" date at the top of this policy
- 30-day advance notice for significant changes affecting your rights
12. Contact Us
For any privacy-related questions, requests, or concerns, please contact us:
Email: privacy@socialync.com
Response Time: We respond to privacy requests within 30 days
12.1 Platform-Specific Privacy Contacts
For platform-specific privacy concerns, you can also contact the platforms directly:
- Facebook/Instagram: Meta Privacy Support
- YouTube/Google: Google Privacy Form
- Twitter: Twitter Privacy Support
- TikTok: TikTok Privacy Center
- LinkedIn: LinkedIn Privacy Support
