This policy explains how SocialMaker, operated by IPRINTYFUN SERVICES LLC (the “Controller”), collects, uses and protects your information when you use socialmaker.ai (the “Service”), including publishing to your connected networks (Facebook, Instagram and LinkedIn).
Data controller
IPRINTYFUN SERVICES LLC, a limited liability company (LLC) formed in the United States, is the controller of your data. For any privacy matter, email us at [email protected]. If you contact us from the European Union, you may also exercise your rights through that channel.
Data we collect
- Account data: name, email, language and time zone, plus your profile picture if you sign in with Google.
- Content you create: carousels, text, brands and images.
- Connected accounts: identifiers (Facebook Page, Instagram Business account, LinkedIn URN, and Facebook user id), public handle, profile picture and the access tokens needed to publish; tokens are stored encrypted (AES-256-GCM) and never shown in full.
- Scheduled posts and, after publishing, the post id/permalink to show you analytics.
- Usage data (technical logs of errors and Service operation) and billing data (processed by our payment provider; we don't store full card data).
How we use it and legal basis
We use your data to run the Service, publish on your behalf only when you schedule or request it, show you analytics, manage your subscription and provide support. We don't sell your data and never publish without your explicit action. The legal bases (Art. 6 GDPR) are: performance of the contract (running the Service you sign up for), your consent (connecting your networks and publishing on your behalf, which you can withdraw anytime), and our legitimate interest (security, abuse prevention and support).
Facebook, Instagram and LinkedIn data
We access only the permissions you authorize to manage and publish content (and metrics if you allow it): listing your Pages, reading their basic information, and publishing to them and to the linked Instagram Business account. Use of data from the Meta and LinkedIn APIs complies with their developer policies and is never less protective than them. We don't use this data for purposes other than providing the Service, and we don't sell it. You can disconnect an account anytime in Settings → Connections; doing so deletes its tokens and revokes the app's access on the platform.
Google Sign-In
If you choose to sign in with Google, SocialMaker receives your name, email address and profile picture from your Google account. We only request this basic profile information: we don't access your Gmail, contacts, files or any other Google data. We use it only to create your account, sign you in, show your name and picture in the app, and contact you about your account. We don't sell it or use it for advertising, and we don't share it with third parties, except with the providers listed in this policy when needed to run the Service. You can ask us to delete your account and this data at any time by emailing [email protected] (see our Data deletion page), and you can revoke SocialMaker's access from your Google Account settings. SocialMaker's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements (https://developers.google.com/terms/api-services-user-data-policy).
Providers (subprocessors)
- Meta Platforms (Facebook/Instagram): publishing and metrics.
- LinkedIn: publishing on your behalf.
- Google: sign-in with your Google account, only if you choose to use it.
- Hosting and infrastructure provider: application and database hosting (data center in the United States).
- Media storage provider: storage of the media (photos and videos) you upload.
- Stripe: payment and subscription processing.
- AI provider: generating text drafts from your prompts.
- Email provider (SMTP): transactional emails (verification, recovery, notices).
International transfers
Your data is processed in the United States, where our infrastructure and providers (including Meta and Stripe) are located. For users in the European Economic Area, transfers from the EU to the US rely on recognized safeguards, such as the European Commission's Standard Contractual Clauses and/or the EU–US Data Privacy Framework.
Cookies
We use only strictly necessary cookies: a session cookie to keep you signed in and remember your language. We don't use advertising or third-party tracking cookies.
Visit measurement
We measure site usage with our own first-party system: we record the page visited, the source of the visit (for example the link or campaign that brought you), approximate location (city and country), language, and device and browser type. Your IP address is not stored. We use this information to understand how SocialMaker is used and to improve the product and our outreach. We don't share or sell this data and we don't use third-party analytics tools.
Analytics for our users' pages
When you visit the public page of someone who uses SocialMaker (socialmaker.ai/name), we measure that visit with the same first-party system to show that person their analytics: which network or site you came from, your approximate location (city and country), your device type, which links on the page you saw or tapped, how far you scrolled and how long you stayed. Your IP address is not stored and we don't use cookies for this. The page owner sees this data without anything that identifies you.
Retention and deletion
We keep your account data and content while your account is active. Your network tokens are deleted without undue delay when you disconnect an account or delete your account. If you cancel your plan, we keep your media for a 60-day grace period in case you reactivate; after that we may permanently delete it. Upon a deletion request, we complete the erasure within 30 days. You can manage all of this on our Data deletion page.
Security
Tokens are encrypted at rest (AES-256-GCM), access to credentials is restricted, and all traffic travels over TLS. No system is 100% secure; keep your credentials safe.
Your rights
You can access, rectify, delete and port your data, and object to or request restriction of its processing and withdraw consent (by disconnecting your accounts). To exercise them, email [email protected] from your account's address; we respond within 30 days. If you are in the EU/EEA, you also have the right to lodge a complaint with your local supervisory authority.
Law enforcement and government requests
We may receive requests from public authorities, such as law enforcement agencies and courts, asking us to disclose user data. When we receive such a request, we (a) review it for legal validity and proper process; (b) challenge or push back on requests we believe are unlawful, overbroad, or improper; (c) disclose only the minimum information strictly necessary to comply with a valid request; and (d) keep a record of the request and our response. We notify the affected user about the request unless we are legally prohibited from doing so or doing so would be futile or present a risk to safety.
California privacy rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you the right to know about and access the personal information we collect, to delete it, to correct inaccurate personal information, and to opt out of any sale or sharing of your personal information, and you will not be discriminated against for exercising these rights. The categories of personal information we collect are described earlier in this policy and include your account and identity data, connected-account identifiers and access tokens, content you create, and usage and billing data. We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We disclose personal information only to the service providers listed in this policy so that they can help us operate the Service. To exercise your rights, email us at [email protected] from the email address associated with your account; you may also use an authorized agent to make a request on your behalf.
Minors
The Service is intended for people 18 or older. We don't knowingly collect minors' data; if we detect a minor's account, we delete it. If you believe a minor provided us data, contact us and we'll erase it.
Changes
We may update this policy; we'll notify material changes in the Service or by email. Contact: [email protected].