1. Who operates SocialIO
SocialIO is the product available at socialio.org. The legal operator entity will be listed here when configured.
2. Scope
This Policy applies to SocialIO accounts, the marketing site, the customer app, and platform-operated features. Visitors to a customer-generated website may also interact with that customer’s content and forms; that customer may have separate privacy obligations as a business. This Policy does not automatically replace a customer website’s own notices.
3. Information we process
Depending on how you use SocialIO, we may process:
- Account data: name, email, password (stored hashed), country, workspace/brand name.
- Organization/team data: company/workspace records, invited users, roles/access.
- Subscription/billing metadata: plan, terms acceptance version/timestamp, invoices/payment transaction references via Odoo payment providers. Card numbers are handled by the payment provider when used; SocialIO does not claim to store full card PANs in ordinary assisted checkout.
- Content you create: posts, captions, media assets, schedules, delivery records, comments synced into SocialIO, brand profiles, ideas, and similar workspace content.
- Technical/log data: IP address, browser/user-agent, timestamps, security and error logs reasonably needed to operate the service.
- Session cookies: authentication/session and security cookies required to run the logged-in app. We do not describe advertising cookies here because SocialIO does not currently operate a marketing-ad cookie program on the platform Legal Center.
We do not knowingly collect government ID numbers, precise GPS tracks, biometrics, or device address books as a SocialIO product feature unless you voluntarily upload such content into your own materials.
4. Social network and Meta connection data
When you connect Facebook/Instagram (Meta) or other networks, SocialIO receives data authorized by you through OAuth. For Meta, SocialIO currently requests scopes such as:
public_profilepages_show_list,pages_manage_posts,pages_manage_metadatapages_read_engagement,pages_manage_engagementinstagram_basic,instagram_content_publish
Practical categories include account/Page identity, Page names and identifiers, access tokens, granted permissions, publishing metadata, and engagement/insight data where enabled and permitted. Tokens are used to perform customer-authorized actions (connect, display connection state, publish/schedule, retrieve allowed status/insights). Technical token storage details are not published here.
TikTok and other providers use their own OAuth scopes (for example content posting
scopes such as video.publish where configured). Only permissions you
grant are used.
5. AI prompts and outputs
If you use AI features, prompts, selected context, and generated outputs may be processed by SocialIO and by configured third-party AI providers (for example an OpenAI-compatible provider when enabled by the operator). Provider-specific retention is governed by that provider’s terms and the operator’s configuration. We do not claim that any AI vendor “never stores” data.
6. Website builder and visitor data
Customer websites may collect visitor-submitted contact-form fields (such as name, email, message, and other configured fields). That data is associated with the relevant customer/tenant workspace. High-volume analytics events (views/clicks) are privacy-conscious and are subject to retention purge (raw view/click events are purged on a rolling approximately 90-day schedule in current implementation; aggregates may be retained longer).
Depending on applicable law, the customer may act as an independent controller/business for its website visitor data. Customers should publish appropriate notices for their own sites.
7. How we use information
- provide, secure, and improve SocialIO;
- authenticate users and manage workspaces;
- connect social accounts and publish/schedule on your instruction;
- show delivery status and enabled analytics;
- operate AI features you request;
- host websites and process form submissions for your workspace;
- bill and activate plans;
- comply with law, prevent abuse, and resolve disputes.
Where privacy laws require a “legal basis,” we rely on bases such as contract performance, legitimate interests in operating a secure SaaS platform, consent where obtained, and legal obligation — as applicable to your jurisdiction.
9. Retention
We retain information as long as needed to provide the service, meet legal, security, accounting, and dispute-resolution needs, and honor deletion requests subject to those needs. Exact multi-year retention schedules for all record types are operator policy and may be refined; website analytics raw events currently purge on an approximately 90-day rolling basis as noted above.
10. Security
We use reasonable technical and organizational safeguards appropriate to a multi-tenant SaaS product. No method of transmission or storage is 100% secure. If a breach notification is required by law, we will provide notice as required by applicable law.
11. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to certain processing, or to lodge a complaint with a regulator. To exercise rights, use in-product controls where available, submit an authenticated request via Data Deletion, or contact the privacy email when configured.
Disconnecting a social account in SocialIO removes SocialIO’s connection and related tokens under our control, but does not delete data held independently by Meta or other platforms.
12. Children
SocialIO is directed to adults and organizations with legal capacity. We do not knowingly collect personal information from children in violation of applicable law. If you believe a child has provided personal information inappropriately, contact us to request deletion.
13. Changes
We may update this Privacy Policy. The effective date and version above identify the current published version. Material changes will be communicated reasonably.
Contact
A monitored legal/privacy email is not yet configured by the operator. Authenticated customers may submit a data deletion request at /data-deletion while signed in. Other legal requests should use the support channel published by the SocialIO operator once available.