Privacy Statement
Last updated: December 17, 2025
This Privacy Statement explains how http://smartbranch.io/ (“we”, “us”) collects, uses, discloses, and protects personal data when you use our product (the “Service”).
If you are using the Service on behalf of a business (e.g., a brand owner, franchise, or branch), that business may control certain data processing decisions.
1) Who we are
Data Controller: [Company Legal Name], [Company Address], [Country]
Contact: [privacy@yourdomain.com]
If applicable (EU/UK): [DPO / EU Representative details]
2) What data we collect
We collect data in three main categories:
A. Account and onboarding data
-
Name, email, phone number (optional), organization/brand/branch details
-
Roles and permissions (e.g., brand owner, branch manager)
B. Social and publishing-related data (when you connect accounts)
-
Facebook Page IDs, Instagram Business Account IDs, and related metadata
-
Access tokens / permissions required to act on your behalf (e.g., publish content, read/manage comments), when granted by you through the relevant platform
-
Publishing history, post IDs, media references (images/videos), scheduling information
-
Comments and messages only if you explicitly enable features that retrieve or manage them
C. Technical and usage data
-
Log data (timestamps, requests, error logs), device/browser info, IP address
-
Cookies or similar technologies (see Section 8)
Sensitive data: The Service is not intended to collect sensitive personal data (e.g., health, political opinions). Do not upload such data.
3) How we use data
We use personal data to:
-
Provide the Service (account creation, authentication, role management, publishing workflows)
-
Connect and operate integrations (e.g., Facebook/Instagram APIs for posting and account linking)
-
Secure and maintain the Service (fraud prevention, abuse detection, auditing, troubleshooting)
-
Improve product performance (analytics, feature usage insights, reliability monitoring)
-
Communicate with you (support responses, service notices, operational updates)
4) Legal bases (where applicable)
Depending on your jurisdiction, we process data based on:
-
Contract necessity (to deliver the Service you requested)
-
Legitimate interests (security, improvement, fraud prevention)
-
Consent (certain cookies, optional marketing communications, and certain integrations)
-
Legal obligation (compliance requests, recordkeeping)
5) How we share data
We may share data only as needed:
-
Service providers / subprocessors (hosting, databases, monitoring, support tooling) acting under contractual obligations
-
Integration partners you choose (e.g., Meta platforms) to perform the actions you request (publishing, fetching content)
-
Legal and compliance if required by law, regulation, or valid legal process
-
Business transfers in case of merger, acquisition, or asset sale (with appropriate safeguards)
We do not sell personal data.
6) Tokens, platform permissions, and revocation
If you connect a Facebook Page / Instagram account, we store the permissions and tokens needed to operate the Service on your behalf. We apply security controls intended to protect these credentials (see Section 9).
You can revoke access at any time via:
-
Your settings within the Service (where available), and/or
-
The relevant platform’s business/integration settings (e.g., Facebook/Meta settings)
Revocation may limit or disable Service features.
7) Data retention
We retain personal data only as long as necessary for the purposes described above, including:
-
While your account is active
-
For a reasonable period after termination to support reactivation, audits, dispute resolution, and compliance
-
Longer where required by law
You may request deletion (see Section 10). Some data may be retained in backups for limited periods and deleted on a rolling schedule.
8) Cookies and similar technologies
We use cookies/local storage (or similar) for:
-
Essential functions (login sessions, security, preferences)
-
Performance/analytics (understanding usage and improving reliability), where enabled
Where required, we provide a cookie banner/consent mechanism. You can also control cookies via browser settings, but disabling them may impair functionality.
9) Security
We implement administrative, technical, and organizational measures designed to protect data, such as:
-
Access controls and least-privilege permissions
-
Encryption in transit (TLS) and, where applicable, encryption at rest
-
Monitoring and logging for security events
No system is 100% secure; we cannot guarantee absolute security.
10) Your rights
Depending on your jurisdiction, you may have rights to:
-
Access, correct, or delete your personal data
-
Object to or restrict processing
-
Data portability
-
Withdraw consent (where processing is based on consent)
To exercise rights, contact: [privacy@yourdomain.com]. We may need to verify identity before fulfilling requests.
11) Customer data and roles (Controller / Processor)
If you are a business customer using the Service to manage content and interactions for your own end users (e.g., leads, commenters), you may be the data controller for that data and we may act as a data processor on your behalf.
Where applicable, a Data Processing Addendum (DPA) can govern these responsibilities.
12) International transfers
Your data may be processed in countries other than your own. Where required, we use appropriate safeguards (e.g., contractual protections) for cross-border transfers.
13) Children’s privacy
The Service is intended for business use and is not directed to children. We do not knowingly collect personal data from children.
14) Changes to this statement
We may update this Privacy Statement from time to time. We will post the updated version and revise the “Last updated” date. Material changes may be communicated via the Service or email.