Legal

Privacy Policy

Last updated: August 4, 2026

PingLynk (“we”, “our”, or “us”) is a hosted Instagram DM automation service: you sign in, connect your own Instagram Professional account, and we run the automation for you on infrastructure we operate. This Privacy Policy explains how we collect, use, disclose, and protect information when you use PingLynk, and how we process data obtained through Meta’s Instagram Platform in accordance with Meta’s Platform Terms and Developer Policies.

For the account, campaign, billing, and delivery data described below, Sidhira Tech and Consulting LLC is the data controller — we decide how that data is stored and processed in order to operate the service. Section 8 explains how that differs for data about the people who comment on your posts.

By using PingLynk, you agree to the collection and use of information described in this policy. If you do not agree, please discontinue use of the service.


1. Information We Collect

1.1 Instagram Platform Data

When you connect your Instagram Business or Creator account through Meta’s OAuth flow, we receive and process the following data solely to provide the automation service:

  • Instagram User ID of commenters (not their username or profile details)
  • Comment text content, to match against your configured trigger keyword
  • Media (post/reel) IDs on which comments appear
  • Your Instagram Business account access token (stored encrypted, used only to send DMs)

We do not collect, store, or process follower profile data, follower email addresses, phone numbers, or any other personal data beyond what is strictly necessary to match a keyword comment and send the configured DM reply.

1.2 Configuration Data You Provide

  • Trigger keyword(s) you set for your campaign
  • Your DM message template
  • Fulfilment link(s) embedded in DMs
  • Target media IDs (optional)

1.3 Technical / Operational Data

  • Webhook request logs (timestamp, action taken, result) — retained for operational debugging
  • Deduplification records: a hashed identifier per commenter, to prevent duplicate DMs
  • Server-side error logs (no personal data beyond Instagram User IDs)

1.4 Website & Product Usage Data

When you use our website or dashboard, we and our analytics/monitoring providers automatically collect:

  • IP address, browser type, device type, and operating system
  • Pages viewed, features used, buttons clicked, and time spent in the dashboard
  • Crash reports and error stack traces if something breaks, so we can fix it

We use PostHog for product analytics and Sentry for error tracking to collect this data. See Section 6 (Cookies & Similar Technologies) for how to control this, and Section 3 for how these providers are engaged as sub-processors.

1.5 Content You Choose to Publish

PingLynk also lets you publish photos and videos directly to your connected Instagram account, from the dashboard or through a connected AI tool (see 1.6 below). When you do this, we process:

  • The photo or video file itself, temporarily, to stage it for Instagram to fetch and publish
  • The caption text you write for that post
  • Post metadata Instagram returns after publishing — the media ID, media type, permalink, and a thumbnail image — so your dashboard can show you a history of what you’ve posted through PingLynk

You choose what to publish and when — we do not review, moderate, or alter the content before it goes live, and publishing is a real, public, irreversible action on your Instagram account. Thumbnail images shown in your post history are sourced from Instagram’s own CDN URLs, which Instagram’s API documents as time-limited; a thumbnail for an older post may eventually stop loading even though the post itself is unaffected.

1.6 API Keys & Third-Party AI Tools (MCP)

From Settings, you can generate a PingLynk API key (delivered as an MCP connection URL) that lets an external tool you choose to connect — such as Claude, ChatGPT, or another MCP-compatible AI assistant — check your Instagram connection status or publish to your account on your behalf, without signing in to PingLynk each time.

  • We store only a one-way hash of the key, never the raw value, the same way we’d store a password.
  • We record when the key was created and when it was last used, so you can spot unexpected activity.
  • Connecting a third-party AI tool this way is entirely your choice — PingLynk does not send your data to any AI provider on our own initiative. We only receive and act on requests the tool makes using your key, and those requests are limited to the same connection-status and publish actions available in your dashboard.
  • Whatever AI tool you connect processes your requests and any content you ask it to generate or publish under its own privacy policy — that’s between you and that provider, not something PingLynk controls.
  • You can revoke a key at any time from Settings, which immediately invalidates it — anyone or anything using it, including a connected AI tool, loses access that instant.

1.7 Affiliate Program Data

If you join our optional Affiliate Program, we additionally collect the display name and payout email you provide, and generate a unique referral code for you. We record clicks on your referral link, and when someone signs up for a new PingLynk account after clicking it within a 60-day window, we record that signup and the commission it generates against your affiliate account.

We set a first-party cookie (pinglynk_ref) on pinglynk.com when someone visits via a referral link, so we can credit the right affiliate if they sign up. This cookie stays on pinglynk.com — it is not used for cross-site tracking or advertising, and expires automatically after 60 days. See Section 6 for more on cookies, and Section 3.2 for what a referred customer’s affiliate can see about them.


2. How We Use Your Information

We use the data collected exclusively for the following purposes:

  • Keyword matching: To detect when a comment on your post contains your configured trigger keyword.
  • DM delivery: To send the configured message to the commenter via the Instagram Messaging API on your behalf.
  • Deduplication: To ensure each commenter receives the automated reply only once per campaign.
  • Activity logging: To provide you with a visible audit trail of webhook events and DM outcomes.
  • Security:To verify webhook authenticity via Meta’s HMAC-SHA256 signature mechanism.
  • Billing:To process your subscription payment through Stripe and track your plan’s monthly DM sending limit (see Section 3.1 and Section 5).
  • Content publishing:To publish a photo or video you upload to your connected Instagram account, and to show you a history of what you’ve posted through PingLynk (see Section 1.5).
  • API / MCP access:To authenticate a request from a third-party AI tool you’ve connected using your API key, and to carry out only the specific action it requested — checking your connection status or publishing to Instagram — on your behalf (see Section 1.6).
  • Affiliate commission tracking:If you join the Affiliate Program, to attribute new signups to your referral link, calculate the commission you’ve earned, and show your earnings in your affiliate dashboard (see Section 1.7).

We do not use any Instagram data for advertising, profiling, training machine learning models, or any purpose other than delivering the automation service described above.


3. Data Sharing and Disclosure

We do not sell, rent, or trade any personal data. We may share data only in these limited circumstances:

  • Meta (Instagram):Data is transmitted to and from Meta’s Graph API as part of the core service function. Meta’s own Privacy Policy governs data held on their platform.
  • Infrastructure providers: We use Railway (hosting), Firebase (authentication, database, and temporary storage for media you publish), and optionally Redis (deduplication cache). These providers process data only as directed by us and under appropriate data processing agreements.
  • AI tools you connect (MCP): If you generate an API key and connect it to a third-party AI tool, that tool can call a small set of PingLynkendpoints on your behalf (see Section 1.6). This isn’t us sharing your data with that provider — it’s a connection you set up and can revoke at any time from Settings.
  • Affiliates:If you signed up after clicking someone’s affiliate referral link, we share limited information about your account with that affiliate — see Section 3.2 below.
  • Analytics & monitoring: We use PostHog (product analytics) and Sentry (error tracking) to understand how the dashboard is used and to catch bugs. Neither is used for advertising, and neither receives your Instagram access token or DM content.
  • Transactional email: We use Resend to send account, billing, and onboarding emails on our behalf.
  • Stripe (payments): See Section 3.1 below.
  • Legal requirements: We may disclose data if required to do so by law or in response to valid requests by public authorities.

3.1 Payment Processing (Stripe)

Paid subscriptions are billed through Stripe, our payment processor and a sub-processor for this purpose. When you subscribe to a paid plan:

  • Stripe collects and stores your payment details (card number, billing address, etc.) directly — PingLynk never receives, transmits, or stores your raw card number, CVV, or full billing credentials on our own servers.
  • We store a Stripe customer ID, your subscription/plan name, and its status (e.g. active, past due, canceled) so the dashboard can enforce your plan’s monthly DM limit and show your billing status.
  • Stripe may process your payment data in accordance with its own Privacy Policy and applicable card network rules (Stripe is a PCI-DSS certified payment processor).

3.2 Affiliate Program — Referral Data Shared With Affiliates

If you sign up for a new PingLynkaccount after clicking someone’s affiliate referral link, we share limited information about your account with that affiliate through their affiliate dashboard: your email address, the plan you’re subscribed to, and the commission amount your subscription generates. This is the minimum needed to let the affiliate verify and track their own earnings — we do not share your Instagram data, campaign configuration, message content, or any other account details with an affiliate.

Payouts to affiliates are handled manually by us and are not processed through Stripe or any automated payment system.


4. Meta Platform Data Policy Compliance

PingLynk is built on Meta’s Instagram Platform and is subject to Meta’s Platform Terms and Developer Policies. In compliance with these policies:

  • We only request the Instagram permissions required to operate the features you use: instagram_business_basic, instagram_business_manage_messages, instagram_business_manage_comments (DM automation), and instagram_business_content_publish (publishing photos/videos to your account). We’re also granted instagram_business_manage_insights alongside content publishing, per Meta’s own requirements for that permission — PingLynk does not currently use it to display insights or analytics.
  • We do not use Instagram data to build user profiles or cross-reference with other data sources.
  • We do not transfer Instagram user data to any third-party data broker or analytics platform.
  • Instagram user data (commenter IDs) is used solely for the in-session purpose of sending a single DM and recording the deduplication hash.
  • We retain Instagram-derived data only for as long as necessary to operate the service (see Section 5 below).

5. Data Retention

  • Webhook event logs / activity log: Retained for up to 30 days for operational debugging and to power your dashboard’s activity log, then automatically purged.
  • Deduplication records:Retained for up to 30 days, then automatically expired by our cache’s TTL mechanism.
  • Access tokens: Stored encrypted in our database for as long as your Instagram account stays connected, and deleted immediately when you disconnect Instagram or delete your account.
  • Campaign configuration and delivery stats: Stored in our database for as long as your account is active. Deleted immediately when you remove an individual campaign from the dashboard, or entirely when you delete your account.
  • Billing records: Your Stripe customer ID and subscription/plan status are retained for as long as your account is active, plus a limited period afterward as needed for financial recordkeeping, then deleted or anonymized.
  • Media you publish: Photos/videos you upload to publish to Instagram are stored in our Storage bucket for as long as your account is active (so post-history thumbnails keep working), and deleted immediately when you delete your account.
  • Post history: The most recent 50 posts published through PingLynk (dashboard or a connected AI tool) are retained for as long as your account is active, then deleted entirely when you delete your account.
  • API keys: We store only a hash of your API key, retained until you revoke or regenerate it, or delete your account — any of which invalidates it immediately.
  • Affiliate program data:Your affiliate profile (display name, payout email, referral code) and commission records are retained for as long as your account is active, and deleted automatically and immediately when you delete your account (same as every other category above) — or sooner, if you ask us to remove you from the program without deleting your whole account. Referral attribution recorded on a referred customer’s account (which affiliate referred them) is retained for as long as that customer’s account exists, since it determines ongoing commission for the referring affiliate.

6. Cookies & Similar Technologies

We keep this deliberately simple — PingLynk does not use advertising or cross-site tracking cookies of any kind. What we do use:

  • Essential: Firebase Authentication session cookies/tokens, required to keep you signed in.
  • Preferences: a local-storage entry remembering your light/dark theme choice. This never leaves your browser.
  • Analytics: PostHog sets cookies to recognize repeat visits and measure feature usage in aggregate. This helps us see which parts of the dashboard get used, not to build advertising profiles.
  • Affiliate attribution:If you visit pinglynk.com via someone’s affiliate referral link, we set a first-party cookie (pinglynk_ref) remembering which affiliate referred you, for up to 60 days, so we can credit them correctly if you sign up. This cookie stays on pinglynk.com — it is not used for cross-site tracking or advertising, and has no effect if you never sign up.

Most browsers let you block or delete cookies in their settings. Blocking essential cookies will prevent you from staying signed in; blocking analytics or affiliate-attribution cookies has no effect on the Service’s core functionality.


7. Data Security

We implement appropriate technical measures to protect data in transit and at rest:

  • All webhook payloads are validated via HMAC-SHA256 signature verification before processing.
  • HTTPS/TLS is enforced for all API communications with Meta’s Graph API and our own servers.
  • Instagram access tokens are stored encrypted in our database — never in source code, and never visible to other users.
  • You sign in through Firebase Authentication (Google sign-in or email/password); dashboard requests are authorized using your signed Firebase identity token.
  • Payment details are handled entirely by Stripe’s PCI-DSS certified systems (see Section 3.1); we never see or store your raw card details.

No method of transmission over the Internet or electronic storage is 100% secure. If you ever suspect unauthorized access to your account, disconnect your Instagram account, change your PingLynk password (if applicable), and contact us using the details in Section 15.

If a breach occurs:in the event of a security incident that results in unauthorized access to your personal data and creates a real risk to your rights, we will notify affected users without undue delay after we become aware of it, describing what happened and what we’re doing about it, consistent with applicable breach notification laws.


8. Your Rights

As a PingLynk user, or as a third party whose data is processed (i.e., someone who comments on an Instagram post targeted by a PingLynk campaign), you may have the following rights depending on your jurisdiction:

  • Access & portability: Request a copy of data we hold about you.
  • Erasure: Delete your account and all associated data — your stored Instagram access token, campaigns, delivery stats, activity log, uploaded media, post history, and API key — immediately and permanently. For commenters, the only data held is a hashed user ID for deduplication, which expires automatically after the TTL period.
  • Correction: Request correction of inaccurate data.
  • Objection: Object to processing of your data.

If you have a PingLynk account, the fastest way to exercise your right to erasure is the Delete my account control in the Danger Zone under Settingsin the dashboard — type “DELETE” to confirm and it deletes everything immediately, with no waiting period. Full step-by-step instructions, including what to do if you can’t sign in, are on our Data Deletion Instructions page. For any other request, contact us at hello@pinglynk.com and we will respond within 30 days.

Note on who is responsible for what: Sidhira Tech and Consulting LLC is the data controller for your own account data — your email, Instagram access token, campaign configuration, billing information, and delivery stats — since we decide how that data is stored and processed to run the hosted service. For data about the people who comment on your Instagram posts, you (the PingLynk user who set up the keyword campaign) decide what campaigns run and what messages get sent, so you act as the data controller for that commenter data, and Sidhira Tech and Consulting LLC processes it on your behalf solely to deliver the automation you configured. Commenters can contact us at hello@pinglynk.comwith questions about a DM they received, and may also contact Instagram directly to manage their data via Instagram’s own privacy controls.


9. California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act and California Privacy Rights Act give you the following rights in addition to those in Section 8:

  • Right to know:what categories of personal data we’ve collected about you, the sources, the purpose, and the categories of third parties it was disclosed to.
  • Right to delete: request deletion of personal data we hold about you, subject to certain legal exceptions.
  • Right to non-discrimination: we will not deny you service, charge you a different price, or provide a different level of service for exercising any of these rights.
  • Authorized agents: you may designate an authorized agent to submit a request on your behalf; we may still ask you to verify your own identity directly with us first.

We do not sell personal data, and we do not share it for cross-context behavioral advertising, so there is no “opt out of sale/sharing” link on this site — there is nothing to opt out of. Submit any request under this section to hello@pinglynk.com; we will acknowledge it within 10 business days and respond within 45 days, consistent with CCPA/CPRA timelines.


10. Legal Basis for Processing (EEA, UK & Switzerland Residents)

If you are located in the European Economic Area, the UK, or Switzerland, our legal basis for processing your personal data depends on the purpose:

  • Performance of a contract — to create your account, operate your campaigns, and provide the Service you signed up for.
  • Legitimate interests — to secure the Service (webhook signature verification, fraud/abuse prevention), maintain activity logs, and improve the product through aggregated usage analytics.
  • Consent — where we rely on consent (for example, certain analytics cookies), you may withdraw it at any time without affecting processing that already took place.
  • Legal obligation — to comply with applicable law, such as financial recordkeeping for billing.

You have the right to lodge a complaint with your local data protection authority at any time. We’d appreciate the chance to address your concern directly first — contact us at hello@pinglynk.com.


11. Children's Privacy

PingLynk is not directed at individuals under the age of 13 (or 16 in certain jurisdictions). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately and we will delete it.


12. Third-Party Links

Fulfilment links sent in automated DMs are written and configured by the PingLynk user who set up that campaign, not by Sidhira Tech and Consulting LLC. We are not responsible for the privacy practices of third-party sites or services linked in those DMs. We encourage anyone who receives a link in a DM to review the privacy policy of any third-party site before visiting it.


13. International Data Transfers

Sidhira Tech and Consulting LLC is a U.S. company, and PingLynk is hosted on infrastructure that may be located outside your country of residence. If you are accessing the Service from the EEA, UK, or Switzerland, your data will be transferred to and processed in the United States and other countries that may not have data protection laws equivalent to your own.

Where required, we rely on Standard Contractual Clauses or equivalent safeguards with our service providers to protect data transferred internationally. By using PingLynk, you acknowledge and consent to this transfer, storage, and processing.


14. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page. If changes are material, we will provide additional notice. Your continued use of PingLynk after any changes constitutes your acceptance of the revised policy.


15. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or how we handle your data, please contact us:

Sidhira Tech and Consulting LLC

Email: hello@pinglynk.com

Website: pinglynk.com

Looking for billing, cancellation, or acceptable-use terms instead? See our Terms of Service. Looking for account/data deletion steps? See our Data Deletion Instructions.

← Back to Home