LEGAL
Privacy Policy
Last updated: August 1, 2026
Havinta ("we", "us", "our") provides a unified inbox and engagement tools for businesses that connect their Instagram professional accounts to our service. This policy explains what information we collect through Meta's Instagram Platform APIs, why we collect it, and how it is stored, used, and deleted.
Information we collect
When you connect an Instagram professional account to Havinta, we collect:
- Account information: your Instagram-scoped business account ID, username, and account type, obtained during the OAuth connection flow.
- Access tokens: a long-lived access token issued by Instagram that authorizes Havinta to act on your behalf via the Instagram API. We never see or store your Instagram password.
- Content you have authorized us to access: direct messages sent to your connected account and comments left on your posts, delivered to us in real time through Meta's webhooks, so they can be shown together in Havinta's unified inbox.
- Basic account and usage data: your Havinta sign-in email and workspace membership information.
How we use your information
We use the information above solely to operate the features you and your business have authorized: displaying your Instagram comments and direct messages in one place, letting your team reply, and (where you enable it) powering automation and AI-assisted replies. We do not sell your data, and we do not use it for advertising purposes, including our own.
How we store and protect your information
Data is stored in Google Cloud (Firebase Authentication and Cloud Firestore) with access restricted to authenticated members of your workspace and to the backend services that operate Havinta. Access tokens are stored server-side and are never exposed to the browser or to other workspaces.
Data sharing
We share data only with the infrastructure providers necessary to run Havinta (Google Cloud/Firebase) and with Meta, as required to call the Instagram APIs on your behalf. We do not sell or rent your data to third parties, and we do not share it for third-party advertising.
Data retention and deletion
We retain connected-account and conversation data for as long as your Instagram account remains connected to Havinta. You can request deletion of your data at any time — see our Data Deletion Instructions page for how.
Your rights
You can revoke Havinta's access to your Instagram account at any time from Instagram's own Settings → Apps and Websites page, which immediately stops any further data collection. You may also contact us to request a copy of, or the deletion of, the data we hold about you.
Changes to this policy
We may update this policy as Havinta's features change. Material changes will be reflected by updating the Last updated date above.
Contact us
Questions about this policy or your data can be sent to stevelayton@outlook.com.