Privacy
Privacy Policy
This Privacy Policy explains how Send Link To Me collects, uses, stores and protects information, including Instagram Platform Data and Shopify shop data, when you use Send Link To Me on the website or in the Shopify App.
Last updated September 8, 2026
Who we are
This Privacy Policy explains how Send Link To Me ("we", "us", or "our") collects, uses, stores and protects information when you use Send Link To Me at https://sendlinkto.me, including the website dashboard and the Shopify App.
Send Link To Me is a self-serve SaaS for Instagram comment-to-DM automation at sendlinkto.me.
Location: Chennai, India. Email: support@sendlinkto.me.
This page is written in plain language for customers, Meta App Review, and Shopify App Store review. It is a product policy summary, not legal advice.
Information we collect
Account information: email, optional name and phone, OTP verification codes (short-lived), and session cookies used to keep you signed in.
Instagram account information: the Instagram Professional account you connect, including Instagram user id, username, display name, profile picture URL, OAuth scopes, and webhook subscription status.
Instagram Platform Data from Meta: encrypted long-lived access tokens, media ids and captions needed to attach automations, and other fields Meta returns for the permissions you approve. See the Meta usage policy at https://sendlinkto.me/meta-policy.
Comments and messages required for automation: comment id, media id, comment text, commenter Instagram-scoped id (IGSID), commenter username, and delivery outcomes (private-reply or DM message ids, errors, skip reasons). Optional lead fields you collect in chat (name, email, phone) are stored with that contact.
Automation configuration: automations, keyword rules, DM templates (text, links, captions), and uploaded media files (images, video, PDF) stored for templates you configure.
Usage and analytics information: dashboard delivery logs and counts of successful final DMs used to show performance and enforce plan limits.
Website traffic information: page path, referrer, campaign tags (UTM), browser user agent, IP address, and approximate location (country, region, city, network) collected when you visit marketing pages, docs, or login. A first-party visitor cookie (sltm_vid) helps us recognize returning browsers. Staff use this log to understand new traffic. It is not shown in the customer dashboard.
Advertising pixels: the marketing site loads Google Ads and the Meta Pixel so we can measure ads. Those companies receive data according to their own policies.
Technical and log information: request metadata needed to run and secure the service, including rate limiting keys and session IP on login.
Shopify shop information, if you install the Admin app: shop domain, shop id, shop name, and an encrypted Shopify offline access token.
Shopify catalog data used to build DMs: products, collections, images, prices, and handles you select.
Unique offer codes we create on your shop when you turn offers on.
Attributed order identifiers, totals, and discount codes when a shop link or offer code from Send Link To Me matches an order.
Lead email, name, and phone when you turn those asks on. We also write those fields to a tagged Shopify customer and a Send Link To Me segment on that shop.
Billing information, if you subscribe on the website: plan selection, billing currency, subscription status, Razorpay customer and subscription identifiers, and payment event metadata needed to enforce entitlements. We do not store full card or UPI credentials.
Billing information, if you subscribe through the Shopify App: Shopify plan handle, subscription status, and period dates from Shopify App Pricing. Shopify collects payment. We do not store card numbers.
How Instagram data is used
Customers connect their own Instagram Professional accounts and configure automations. We process Instagram Platform Data only as necessary to provide the requested automation functionality.
Examples include: detecting eligible top-level comments via Meta webhooks, matching configured keywords, sending configured private replies and allowed DMs through Meta Graph APIs, optionally posting a short public comment reply, recording delivery and automation status, providing analytics in the customer dashboard, publishing or scheduling content when you use that feature, and enforcing plan limits.
Access tokens are encrypted at rest and used only to call Meta on your behalf.
We do not sell Instagram Platform Data. We do not use Platform Data to build unrelated advertising profiles. We do not scrape Instagram or use unofficial clients.
How data is stored
We store data on infrastructure we operate or instruct, including application hosting, a managed database, and object storage for media you upload.
Instagram access tokens are encrypted at rest. Website sessions use cookies. OTP codes are short-lived. The Shopify App uses App Bridge session tokens instead of a website login cookie. The visitor cookie used for traffic logs is httpOnly and lasts up to one year or until pruned from our logs.
We apply access controls, HTTPS in transit, and least-privilege use of tokens so they are used only to call Meta for the automations you configured.
How long data is retained
We keep account and product data while your account is active and as needed to provide the service.
Comment and DM delivery logs used for debugging, analytics, and plan metering are retained up to 90 days, then pruned.
Website page-view logs and unlinked visitor records are retained up to 90 days, then pruned.
If billing pauses after failed payment, product data is retained for 60 days from the pause, then deleted if you do not resume a plan or continue on Free within Free limits.
Encrypted Instagram tokens are removed when you disconnect an account or when a Meta deletion request completes.
Sharing of data
We do not sell Instagram Platform Data.
We share data with Meta and Instagram only as needed to operate APIs you authorized (OAuth, webhooks, Graph calls).
We use processors under our instructions: hosting for the application, email delivery for OTP and support, object storage for media you upload, Razorpay for website payments, Shopify for Admin API access, App Pricing, and App Bridge, and Slack for internal operational alerts (for example new signups). Google and Meta receive advertising pixel data on the marketing site as described above.
When you collect lead fields in a Shopify automation, we may create or update a customer on that shop and add them to a Send Link To Me segment.
We may disclose information if required by law or to protect the service and users from abuse.
Meta Platform Data
A dedicated Meta usage policy describes login, the four OAuth scopes, webhooks, private replies, publish, and what we do not do with Platform Data.
Read it at https://sendlinkto.me/meta-policy.
Disconnecting Instagram
Disconnect an Instagram account in the Send Link To Me dashboard. That deletes tokens and cascaded product data for that connection and stops API calls for that account.
You can also revoke app access in Instagram or Meta Apps and Websites settings at any time. Meta may then call our data deletion callback.
Disconnecting Instagram does not cancel your Send Link To Me subscription. On the website, cancel billing from Settings. On the Shopify App, cancel in Shopify Admin or uninstall the app.
Data deletion
Email us from your registered address to request full account deletion.
We honor Meta Data Deletion Request Callbacks. Check status on the data deletion page at https://sendlinkto.me/deletion with your confirmation code.
Uninstalling the Shopify app or a Shopify shop-redact request removes that shop's connection. A Shopify-origin login can be deleted when Shopify sends a shop-redact request.
User rights
You may request access to the account data we hold, correction of inaccurate account details, or deletion of your account and related product data by emailing us.
You can disconnect Instagram yourself in the dashboard, which deletes that connection's tokens and cascaded data.
Do not submit sensitive personal data in DM templates unless you have a lawful reason to share it.
Contact
Privacy questions: support@sendlinkto.me.
Location: Chennai, India.
Questions
We can clarify the fine print
For account, billing, deletion, or Meta permission questions, use live chat or email. For product limits, the FAQ and pricing pages have the short version.