Privacy Policy
1. Who we are
This policy describes how ATT ECOMMERCE GLOBAL LLC ("we", "us") handles information when you use our application GraceYears Insights 2 (the "App").
Contact: caugheycassi@gmail.com
Registered address: 3308 48th St, Des Moines, Iowa 50310, United States
2. What the App does
The App is a publishing tool for business owners who manage their own Facebook Pages and Instagram professional accounts. It allows an authorised user to:
- Publish photo, video and Reels content to Facebook Pages and Instagram accounts they manage
- Search their own Meta product catalog and attach product tags to the content they publish
- Read back published content to confirm that publishing succeeded
The App acts only on accounts and assets that the user already administers, and only at the user's explicit direction.
3. Information we access
| Data | Why | Permission |
|---|---|---|
| Facebook Page ID and name | To identify which Page to publish to |
pages_show_list, pages_read_engagement
|
| Page access token | To publish on the Page owner's behalf | pages_manage_posts |
| Business and asset listing (businesses, Pages, Instagram accounts the user administers) | To let the user choose which asset to publish to | business_management |
| Instagram professional account ID and username | To identify which account to publish to | instagram_basic |
| Content the user chooses to publish (image, video, caption) | To create and publish the post | instagram_content_publish |
| Product catalog entries (product ID, name, review status) | To let the user pick which products to tag | catalog_management |
| Product tags attached to media | To attach and verify product tags | instagram_shopping_tag_products |
4. What we do NOT do
- We do not sell, rent, or license any data obtained from Meta Platforms.
- We do not share Platform Data with advertising networks, data brokers, or any third party for their own purposes.
- We do not use Platform Data to build profiles of individuals.
- We do not access private messages, follower lists, or the personal profiles of people who interact with the user's content.
- We do not use Platform Data to train machine learning models.
5. How we store and protect data
- Access tokens are stored encrypted at rest and are never written to logs, error messages, or analytics.
- All traffic to Meta APIs uses HTTPS/TLS.
- Access to production systems requires multi-factor authentication.
- Where the App serves more than one customer, each customer's data is stored logically separated from every other customer's data, in line with Meta Platform Terms section 5.b.
- We run a vulnerability scan or penetration test of the App at least once per year and retain the report.
6. Data retention and deletion
We keep only what is needed to operate the App:
- Access tokens — kept until the user disconnects the App or revokes access.
- Publishing history (post IDs, timestamps, success/failure) — kept for up to 90 days, then deleted.
- Catalog data — not stored; it is read from Meta at the moment it is needed.
When a user disconnects the App in their Facebook settings, the access tokens we hold for that user stop working immediately. When a user asks us to delete their data, we delete all Platform Data associated with that user as soon as reasonably possible and in any case within 120 days.
To request deletion, see our Data Deletion Instructions.
7. Your rights
You may at any time:
- Revoke the App's access from your Facebook settings (Settings & Privacy → Settings → Apps and Websites)
- Ask us what data we hold about you
- Ask us to delete it
Write to caugheycassi@gmail.com. We respond within 30 days.
8. Children
The App is a business tool and is not directed at anyone under 18. We do not knowingly collect information from children.
9. Changes to this policy
If we change this policy we will update the "Last updated" date above. Material changes will be notified to active users by email before they take effect.
10. Compliance
Our handling of data received from Meta Platforms is governed by the Meta Platform Terms and Developer Policies. Where this policy conflicts with those terms, those terms prevail.