Privacy Policy
Last updated: 28 July 2026
DMBud ("we", "us") provides a service that lets a business connect its own Instagram
Business or Creator account and automatically reply to comments — sending a matched
customer a public reply and a private DM with product details pulled from the business's
own Shopify or WooCommerce store. This policy explains what data we collect to run that
service, why, how long we keep it, and how to have it deleted.
Who this applies to
Two kinds of people interact with DMBud:
- Workspace owners — the business that signs up for DMBud, connects an
Instagram account and a store, and configures the automation.
- Commenters — people who comment on that business's Instagram posts.
We only ever see a commenter's data if they comment on a post belonging to a business
that has connected DMBud, and only to the extent needed to reply to that comment.
What we collect
- Account data — email, name, password (stored as a salted hash, never
in plain text), and role, for the workspace owner and any teammates they invite.
- Instagram connection data — the connected account's Instagram user ID
and username, the access token Meta issues (encrypted at rest), and the permissions
granted. Obtained via Instagram's own OAuth login — we never see the account's
Instagram password.
- Comment data — when someone comments on a connected account's post
with a keyword the business configured, we process that comment's ID, the post's media
ID, the commenter's Instagram ID and username, and the comment text, in order to match
it against the business's rules and identify which product to reply about.
- Message content — the text of the automated public reply and private
DM we send on the business's behalf, and whether delivery succeeded.
- Store data — the business's Shopify or WooCommerce store URL and API
credentials (encrypted at rest), used only to look up a product by SKU.
- Security logs — IP address and timestamp for login attempts, used to
detect abuse and rate-limit requests.
What we don't do
We don't sell any of this data, use it for advertising, or share it with anyone except
the platforms strictly necessary to deliver the service: Meta's Instagram Graph API (to
send the reply/DM) and the business's own connected store (to look up a product). We never
message a commenter unless they first commented a matching keyword — DMBud never sends
unsolicited or bulk messages.
How long we keep it
- Comment and message history (used to power the Activity Log) is kept for
90 days, then automatically and permanently deleted.
- Raw Instagram webhook payloads are kept for 30 days for debugging,
then automatically deleted.
- Connection data (the linked Instagram account, store credentials, automation rules)
is kept until the business disconnects it or requests deletion.
Deleting your data
A business can disconnect its Instagram account at any time from within DMBud, which
immediately stops the automation. To delete all associated data, disconnect the
app from your Instagram or Facebook Accounts Center — this triggers an automatic deletion
callback that permanently removes the connection, its automation rules, and its comment/
message history from our systems. You can check the status of any deletion request at
our deletion status page. You can also email us
directly (see Contact below) to request deletion.
Security
Access tokens and store API credentials are encrypted at rest. Passwords are hashed,
never stored in plain text. Incoming Instagram webhook requests are verified against a
signature before we act on them. Login attempts are rate-limited.
Children
DMBud is a business tool and is not directed at, or knowingly used to collect data
from, children.
Changes to this policy
If this policy changes, we'll update the date at the top of this page.
Contact
Questions about this policy or a data request: privacy@dmbud.com