Privacy Policy
At HeyThallo, we understand the importance of privacy and the protection of Personal Information. We are committed to providing a safe, transparent, and secure environment for our users.
1. What “Personal Information” Means
In this Policy, “Personal Information” means information that identifies you as an individual, such as your name, email address, telephone number, or billing information. Personal Information does not include “Usage Data,” which we define as encoded or anonymized information or aggregated data we collect about a group or category of services, features, or users which does not contain personally identifying information.
2. How We Collect, Use, and Share Data
Information You Provide to Us
When you use our service, we may collect Personal Information such as your name, email address, or billing information. As you use our Instagram automation service, the software continuously documents telemetry items such as when automations are configured, last open dates, and execution triggers.
Note that we will never email you to ask for your account password. If you ever receive such an email, please forward it immediately to security@heythallo.com.
Information From Third-Party Platforms (Meta / Instagram)
If you access our Service through Instagram or connect Meta OAuth credentials to HeyThallo, Meta passes authorization tokens, Instagram User IDs, and authorized page scopes necessary to deliver DM triggers and comment auto-replies. Always review your Meta privacy permissions when connecting accounts.
Log Files, Cookies & Analytics
We collect technical web server logs (IP address, access timestamps, user agent string, language, and screen resolution) to monitor API bandwidth usage, billing tier execution, anti-fraud enforcement, and infrastructure health.
- To remember authentication tokens across sessions
- To measure aggregate traffic and conversion analytics
- To diagnose worker execution performance and error states
- To deliver automated application updates
3. International Data Transfers (GDPR / CCPA)
HeyThallo is headquartered in the United States, operating global Cloudflare edge worker infrastructure. Data transferred from the European Economic Area (EEA), UK, or Switzerland is handled under standard contractual clauses and strict GDPR compliance.
If you are located in the EEA or UK, you have the right to access, rectify, port, or erase your Personal Information by contacting privacy@heythallo.com.
4. Data Retention
We retain your Personal Information as long as your account remains active or as required to fulfill legal obligations. Upon account termination, personal data is permanently scrubbed or anonymized within 30 days.
5. Data Security
All API traffic and web socket streams are encrypted via TLS 1.3/SSL. Payment data is processed directly via PCI-DSS Level 1 compliant Stripe infrastructure; HeyThallo never stores raw credit card numbers.
6. Children's Privacy
HeyThallo does not knowingly collect or solicit data from children under the age of 13. If you believe a minor has registered an account, please notify support@heythallo.com for immediate account purge.
7. Policy Changes & Contact Information
We may update this Privacy Policy periodically. Material updates will be notified via email or dashboard alert prior to taking effect.