Apps Privacy Policy
Last updated: October 2026
This policy explains how the apps of i3 Software Solutions (the "apps") process personal data, in particular when a business uses them to create posts and publish them to Facebook and Instagram. Our website has its own privacy policy.
1. Controller
i3 Software Solutions UG (haftungsbeschränkt)
Stolberger Straße 146
52068 Aachen, Germany
Represented by: Umme Salma Sadia (Managing Director)
Email: contact@i3softwaresolutions.de
Phone: +49 177 6664715
2. Which apps this policy covers
- Shop app — for retail shops: product photos, names and prices turned into product videos and image posts.
- Restaurant app — for restaurants and cafés: menus and dishes, and promotions such as offers and the daily menu.
When we add further apps, we will list them here. All apps connect to Facebook and Instagram in the same way, through one Meta app named "i3 Software Solutions".
In each app, a business can publish videos (on Instagram as Reels), single images and multi-image posts (carousels on Instagram) to a Facebook Page and/or an Instagram professional account it has connected — immediately, or at a time or on a repeating schedule it has set.
3. Data we process
3.1 Your account
- Email address and password (the password is stored only as a secure hash by our authentication provider), and an optional display name.
- Which business your account belongs to and your role in it.
3.2 Your business and your content
- Business details such as name, an optional address line shown on your posts, time zone and an optional logo.
- Content you enter in the app, for example products, dishes, menus, prices, offers and opening days.
- Photos you upload, and the videos and images the app creates from them.
- Your posts: captions, the channels you chose, and for scheduled posts the date, time or repeating pattern.
- For each published post and channel: its status, the ID and link of the published post, and error messages if publishing failed, including the platform's technical response (kept for support).
3.3 Data from Facebook and Instagram
When you connect a channel, you log in on Facebook's or Instagram's own page. We never receive your Facebook or Instagram password. We receive and store only:
- Facebook: the ID and name of each Facebook Page you choose to connect, and a Page access token that allows the app to publish to that Page.
- Instagram: the ID, username and account type of your Instagram professional account, and an access token that allows the app to publish to it. Instagram tokens expire after 60 days; the app renews them automatically while the connection is active.
- The permissions you granted.
Access tokens are encrypted (AES-256-GCM) before they are stored. The encryption key is kept separately from the database, so access to the database alone is not enough to use them. To publish scheduled posts, the app uses your stored token at the scheduled time, without you being signed in.
We use these permissions only to publish the posts you created and sent or scheduled, and to show you their links. We do not read your feed, posts by others, comments, messages, followers or insights; we do not publish anything you did not create and send or schedule; we do not use Facebook or Instagram data for advertising or profiling; and we do not sell or share it with anyone except the service providers listed below.
3.4 Technical data
When you use an app, our servers process technical data such as your IP address, the time of the request and error logs. We use it to run the apps, keep them secure and fix problems.
4. Purposes and legal bases
- Providing the apps — your account, business data, content, posts, schedules and channel connections — to perform our contract with you (Art. 6(1)(b) GDPR).
- Security, stability and troubleshooting using technical data, based on our legitimate interest in a secure and working service (Art. 6(1)(f) GDPR).
- Keeping records where the law requires it (Art. 6(1)(c) GDPR).
5. Service providers and recipients
We use the following providers, each bound by a data processing agreement under Art. 28 GDPR:
| Provider | What for | Where |
|---|---|---|
| Supabase, Inc., 970 Toa Payoh North #07-04, Singapore 318992 | Databases and user login | Servers in the EU (Frankfurt, Germany) |
| Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland | Running the apps' servers, scheduled publishing and video creation | Servers in the EU (Frankfurt, Germany) |
| Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA | Delivering the apps and storing photos and videos | Global network; see section 6 |
Meta. When a post is published, the content you chose is sent to Meta Platforms Ireland Limited (Facebook and Instagram) and becomes visible on your Page or account. From then on, Meta's own privacy policy applies to it.
6. Transfers outside the EU
Some providers are based outside the EU or may access data from there. Where data is transferred to the USA, we rely on the provider's certification under the EU-US Data Privacy Framework (Art. 45 GDPR) and, in addition, on the EU Standard Contractual Clauses (Art. 46 GDPR). For other countries we rely on the Standard Contractual Clauses.
7. How long we keep data
- Photos, videos and images made for a post: deleted from storage automatically once the post has been published to every channel you chose. If publishing failed, they are kept so you can try again. Preview images are deleted shortly after the preview. Photos you keep in the app on purpose (for example a dish photo in your menu) stay until you delete them.
- Scheduled posts: kept until they are published or you cancel them; afterwards they are part of your post history.
- Channel connections and access tokens: when you disconnect a channel in the app, the app stops using it immediately, including for scheduled posts. Connection data and tokens are deleted when your account is deleted or when you ask us to delete your data.
- Account, business data, content and post history (captions, status, links): kept while your account exists and deleted when it is deleted, unless the law requires us to keep them longer.
- Technical logs: kept for a short period, normally no longer than 30 days.
8. Deleting your data and revoking access
You can disconnect a Facebook Page or Instagram account at any time under Channels in the app. You can also remove access directly on Facebook (Settings → Business integrations) or Instagram (Settings → Website permissions → Apps and websites). Our apps appear there as i3 Software Solutions; removing it there disconnects all of our apps from that Page or account.
To have all your data deleted, follow our data deletion instructions.
9. Your rights
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). To exercise them, contact us at contact@i3softwaresolutions.de.
You also have the right to complain to a supervisory authority (Art. 77 GDPR). Ours is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, www.ldi.nrw.de.
10. Security
All connections to the apps are encrypted (HTTPS). Access tokens are encrypted at rest, each business can only access its own data, and stored photos are private and only shared with Facebook and Instagram through short-lived links when publishing.
11. Children
The apps are business tools and are not intended for people under 16.
12. Changes
We update this policy when our apps or the law change, including when we add a new app. The current version is always available on this page, with its date at the top.