Privacy Policy
Last updated: April 20, 2026
CommentCart is a software platform that helps businesses respond to Instagram comments with product or storefront links. We provide automation and storefront technology for independent vendors. We are not the seller of record for products sold by vendors using the platform.
1. Information We Collect
Vendor Account Information
When vendors sign up for CommentCart, we may collect:
Name, email address, business/store information, subscription and billing details, storefront settings, product/media mappings, and related account configuration data.
Meta / Instagram Connection Data
When a vendor connects an Instagram professional account, we may collect and store:
Instagram business account ID, Instagram username, linked Facebook Page ID and Page name, access tokens, token expiration details, and connection status metadata required to operate the service.
Instagram Interaction Data
To provide comment-triggered automation, we may process:
Public comment text, Instagram comment ID, Instagram media ID, commenter username, commenter Instagram user ID when provided by Meta, timestamps, matched keyword information, and message delivery status.
Billing and Payment Data
Vendor subscription payments are processed by third-party payment providers such as Stripe. We do not store full payment card numbers on our servers.
2. How We Use Information
We use collected information to:
provide vendor login and account management, connect vendor Instagram professional accounts, detect keyword-triggered comments on vendor posts, send a single private reply when a configured trigger matches, generate analytics and usage records for vendors, prevent duplicate replies or abuse, provide customer support, maintain platform security, and manage subscriptions and billing.
3. How We Share Information
We do not sell personal data.
We may share information with service providers and platforms that are necessary to operate CommentCart, including:
Meta / Instagram APIs, Stripe for subscription billing, Supabase or other infrastructure/database providers, and hosting or logging providers used to run the application securely.
We may also disclose information when required by law, regulation, legal process, or to protect the rights, safety, and security of CommentCart, vendors, buyers, or third parties.
4. Data Retention
We retain information for as long as reasonably necessary to provide the service, maintain security and audit records, resolve disputes, comply with legal obligations, and enforce our agreements.
When a vendor disconnects a Meta account or requests deletion, we will remove or de-identify associated data within a reasonable period, subject to any legal, security, fraud-prevention, or backup retention needs.
5. Data Deletion
Vendors may request deletion of their CommentCart data by contacting us at [email protected].
Vendors may also disconnect their Instagram connection from the CommentCart dashboard, which stops future automation for that account.
For more information, please see our Data Deletion Instructions.
6. Security
We use reasonable administrative, technical, and organizational safeguards to protect information, including secure transport, access-controlled systems, and restricted backend access. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
7. Third-Party Services
CommentCart relies on third-party services and APIs, including Meta, Stripe, hosting providers, and database providers. Your use of related third-party services may also be subject to those third parties’ own terms and privacy policies.
8. Children’s Privacy
CommentCart is intended for businesses and adults and is not directed to children under 13. We do not knowingly collect personal information from children under 13.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Any updates will be posted on this page with a revised “Last updated” date.
10. Contact
If you have privacy questions or requests, contact us at [email protected].