PrivacyPolicy
What we collect, why we collect it, who we share it with, and how you stay in control — written to be read, not skimmed past.
The short version. Mtschat is a Singapore company that helps creators and businesses automate Instagram direct messages through Meta’s official Instagram API. We never ask for or store your Instagram password. We only access Instagram data you authorise, we use it to run the automations you build, and we never sell personal data. For the people who message our customers, we act as a processor on our customers’ behalf. You can ask us to delete your data at any time by writing to privacy@mtschat.com.
1. Who we are
Mtschat (“Mtschat”, “we”, “us”, “our”) is a company registered and based in Singapore. We operate the website at mtschat.com and the Mtschat software-as-a-service platform (the “Service”), a no-code tool for automating Instagram direct messages, comment replies and story-reply conversations.
Where this policy refers to “you”, it means the person reading it — whether you are a Mtschat customer, a member of a customer’s team, a visitor to our website, or someone who has interacted with a customer’s Instagram account.
2. Scope of this policy
This policy explains how we handle personal data when you:
- visit mtschat.com or read our blog;
- create a Mtschat account, connect an Instagram professional account, or use the Service;
- are invited to a customer’s workspace as a teammate;
- comment on, reply to a story of, or send a direct message to an Instagram account that uses Mtschat; or
- contact us for support, sales or any other reason.
It should be read together with our Terms of Use and our Cookie Policy. More detail on our technical safeguards is on our Security page.
3. Controller and processor roles
Data protection laws distinguish between the party that decides why and how personal data is processed (a “controller”, or an “organisation” under Singapore’s Personal Data Protection Act 2012, the “PDPA”) and a party that processes data on someone else’s instructions (a “processor”, or a “data intermediary” under the PDPA).
When we are the controller
We are the controller of account data, billing data, website and usage data, and correspondence with us. This policy describes in full how we handle that data.
When we are a processor
When a customer connects their Instagram account to Mtschat, the people who interact with that account — the ones who comment, reply to a story or send a DM — are the customer’s contacts, not ours. The same applies to any contact data a customer imports. For this data, the customer is the controller and Mtschat is the processor (or data intermediary). We process it only to provide the Service, on the customer’s documented instructions, and under our Terms of Use.
If you messaged a business that uses Mtschat and want to exercise your privacy rights, the quickest route is to contact that business directly. If you contact us instead, we will pass your request to the relevant customer and help them respond, where the law allows.
4. Data we process
4.1 Account and customer data
- Identity and contact details — name, email address, company name, and the password you set for Mtschat (stored only as a salted hash).
- Workspace data — teammates you invite, their roles and permissions, and settings you choose.
- Billing data — plan, billing address, tax identifiers and payment history. Card details are collected and stored by our payment processor; we see only limited information such as card brand, last four digits and expiry date.
- Communications — messages you send to our support, sales or privacy teams, and any feedback you give us.
4.2 Instagram data accessed through the API
When you connect an Instagram professional account, you sign in with Meta and grant specific permissions. We never receive your Instagram password and we never log in as you. Depending on the permissions you grant and the features you use, we access:
- Account basics — your Instagram account ID, username, profile name, profile picture and account type, plus the access token Meta issues to us.
- Content metadata — the posts, Reels and stories on your account, so you can attach automations to them.
- Comments — comments left on your content, including the commenter’s Instagram-scoped ID, username and comment text, so that keyword triggers can fire and public replies can be posted.
- Messages — direct messages and story replies sent to your account, and the messages your automations or teammates send back, including text, button taps, links and attachments.
- Profile basics of people who interact with you — the Instagram-scoped ID, username, name and profile picture that Meta makes available for people who have contacted your account.
We only receive data that Meta’s API makes available for the permissions granted. Mtschat only sends messages to people who have first contacted the connected account, within the windows Instagram allows.
4.3 Contact data
- Contact records — data built up from Instagram interactions, such as conversation history, tags, segments, custom fields and the automations a contact has entered.
- Imported data — contact data a customer uploads, for example through CSV import, or syncs from a connected integration. Customers are responsible for having the right to share that data with us.
- Captured data — information a contact chooses to share in a conversation, such as an email address entered into a lead-capture flow.
4.4 Usage, device and cookie data
- Service usage — the features you use, automations you build and publish, actions you take in the app, and performance data such as runs, link clicks and conversions shown in Insights.
- Technical data — IP address, browser type and version, device type, operating system, language, time zone, referring pages and timestamps.
- Logs — server, security and error logs used to keep the Service reliable and secure.
- Cookies and similar technologies — described in our Cookie Policy.
We do not intentionally collect special categories of personal data (such as health or biometric data). Customers should not use the Service to request such data from their contacts unless they have a lawful basis to do so and have told us in advance.
5. Purposes and legal bases
Where the EU or UK General Data Protection Regulation (“GDPR”) applies, we must have a legal basis for each purpose. Under the PDPA, we rely on consent, deemed consent, or an applicable exception. The list below summarises our purposes as a controller.
- Providing the Service — creating your account, connecting Instagram, running your automations, syncing integrations and delivering support. Basis: performance of our contract with you.
- Billing and account administration — processing payments, issuing invoices, managing plan changes and collecting taxes. Basis: contract; legal obligation.
- Security and abuse prevention — detecting fraud, spam, unauthorised access and breaches of our acceptable use rules. Basis: legitimate interests in protecting our customers, their contacts and the platform; legal obligation.
- Improving the Service — understanding how features are used, fixing bugs and planning new features, using aggregated or de-identified data wherever possible. Basis: legitimate interests.
- Communications — sending service notices (such as billing, security and policy updates) and, where permitted, product news. You can unsubscribe from marketing emails at any time. Basis: contract for service notices; consent or legitimate interests for marketing, as required by local law.
- Website analytics and preferences — measuring site traffic and remembering your choices. Basis: consent where required; otherwise legitimate interests.
- Legal compliance — keeping records, responding to lawful requests and enforcing our agreements. Basis: legal obligation; legitimate interests.
When we process contact data as a processor, the customer is responsible for establishing the legal basis for that processing.
We do not sell personal data, and we do not share it for cross-context behavioural advertising. We do not use Instagram data or contact data to train general-purpose machine-learning models, and we do not use one customer’s contact data to benefit another customer.
6. Instagram and Meta Platform Terms
Mtschat is built on Meta’s official Instagram API. We comply with the Meta Platform Terms and Meta’s Developer Policies when accessing and using Instagram data. In particular, we:
- request only the permissions needed for the features you use;
- use Platform Data only to provide the Service to the customer who authorised access, and not for unrelated purposes;
- do not sell, licence or purchase Platform Data, and do not use it to build profiles for advertising or data brokerage;
- do not attempt to re-identify, track or surveil individuals;
- delete Platform Data when it is no longer needed for the Service, when access is revoked, or when Meta or the user asks us to; and
- provide a clear data deletion path, described in section 12.
Your use of Instagram is also governed by Meta’s own terms and privacy policy, which we do not control. Mtschat is not affiliated with, endorsed by or sponsored by Meta Platforms, Inc. or Instagram. Instagram is a trademark of Meta Platforms, Inc.
7. Sharing and sub-processors
We share personal data only as described here. We do not name vendors in this policy because our providers may change over time; customers can request our current sub-processor list at privacy@mtschat.com.
- Infrastructure providers — cloud hosting, databases, storage and content delivery that run the Service.
- Payment processors — to take payments and manage subscriptions.
- Email and communication providers — to send transactional emails and, where permitted, product updates.
- Customer support tools — to receive and answer support requests.
- Monitoring and analytics tools — to measure performance, diagnose errors and understand website usage.
- Meta — messages, replies and API requests are sent through Meta’s platform as required to deliver the Service.
- Integrations you enable — when you connect a service such as a CRM, email marketing tool, store or spreadsheet, or configure webhooks or the REST API, we send data to that destination on your instruction. The receiving service’s own terms and privacy policy apply.
- Professional advisers — lawyers, accountants and auditors, under duties of confidentiality.
- Authorities — where required by law, regulation or valid legal process, or to protect the rights, safety and property of Mtschat, our customers or others.
- Corporate transactions — a buyer or successor in a merger, acquisition, financing or sale of assets, subject to this policy’s protections.
Our sub-processors are bound by written contracts that require them to protect personal data, process it only on our instructions and meet security and confidentiality standards at least as protective as ours.
8. International transfers
We are based in Singapore, and our providers may process data in Singapore and other countries. Wherever personal data is transferred outside the country where it was collected, we take steps to ensure it receives a comparable standard of protection. These include:
- for transfers out of Singapore, ensuring recipients are bound by legally enforceable obligations as required by the PDPA’s Transfer Limitation Obligation;
- for transfers out of the European Economic Area, the UK or Switzerland, relying on adequacy decisions where available, or the European Commission’s Standard Contractual Clauses (with the UK Addendum or Swiss amendments where relevant); and
- supplementary technical and organisational measures, such as encryption in transit and at rest.
You can request more information about the safeguards we use by contacting privacy@mtschat.com.
9. Retention
We keep personal data only for as long as we need it for the purposes in this policy, or as the law requires.
- Account data — for as long as your account is open. If you close your account, we delete or anonymise account data within 30 days, except for records we must keep for legal, tax or accounting reasons (usually up to seven years for financial records).
- Instagram data and contact data — for as long as the customer’s account is active and the Instagram account remains connected. Customers can delete individual contacts and conversations at any time. When a customer disconnects an Instagram account, its access token is revoked immediately; the related data is deleted within 30 days unless the customer reconnects in that time. When a customer closes their account, all associated contact and Instagram data is deleted within 30 days.
- Cancelled subscriptions — cancelling a paid plan does not delete your data. Your workspace moves to the Free plan and your data stays in place until you close the account or ask us to delete it.
- Deletion requests — we act on verified deletion requests within 30 days, as described in section 12.
- Backups — deleted data may persist in encrypted backups for up to a further 35 days, after which it is overwritten. Backups are not used to restore deleted data except for disaster recovery.
- Logs — security and system logs are generally kept for up to 12 months.
10. Security
We use administrative, technical and physical safeguards designed to protect personal data, including encryption in transit (TLS) and at rest, encrypted storage of Instagram access tokens, role-based access controls, least-privilege access for staff, logging and monitoring, and regular review of our providers. Inside the product, customers can assign role-based permissions so teammates see only what they need.
No system is perfectly secure. If we become aware of a data breach that affects your personal data, we will notify you and the relevant authorities as required by law — including within the timelines set by the PDPA and the GDPR. To report a vulnerability, email security@mtschat.com. More detail is on our Security page.
11. Your rights
Your rights depend on where you live. We honour the requests below wherever the law gives you the right, and we will not discriminate against you for exercising them.
Singapore (PDPA)
- Request access to your personal data and information about how it has been used or disclosed in the past year.
- Request correction of errors or omissions.
- Withdraw consent to collection, use or disclosure, on reasonable notice. We will tell you the likely consequences, which may include being unable to continue providing the Service.
- Where applicable, request that your data be ported to another organisation.
European Economic Area, UK and Switzerland (GDPR)
- Access, rectification and erasure of your personal data.
- Restriction of processing and objection to processing based on legitimate interests, including an absolute right to object to direct marketing.
- Data portability for data you provided to us.
- Withdrawal of consent at any time, without affecting earlier processing.
- The right to lodge a complaint with your local supervisory authority.
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. Automations in Mtschat are configured by our customers to reply to messages; they do not make such decisions on our behalf.
California (CCPA, as amended by the CPRA)
- Know the categories and specific pieces of personal information we collect, the sources, the purposes and the categories of third parties we disclose it to.
- Delete personal information, subject to legal exceptions.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information. We do not sell or share personal information as those terms are defined.
- Limit the use of sensitive personal information. We do not use sensitive personal information for purposes that would trigger this right.
- Not be discriminated against for exercising these rights.
In the past 12 months we have collected the categories described in section 4 — identifiers, commercial information, internet or network activity, and the content of communications processed for our customers — for the business purposes in section 5, and disclosed them only to the categories of recipients in section 7.
How to make a request
Email privacy@mtschat.com. We may need to verify your identity before acting, for example by asking you to confirm from the email address linked to your account. You may use an authorised agent; we will ask for proof of their authority. We respond within the time required by law — generally within 30 days. If you are a contact of one of our customers, see section 3.
12. Data deletion instructions
You can have your data deleted at any time. Choose the route that fits you.
If you are a Mtschat customer
- Disconnect in the app. Open your workspace settings, go to Channels, and disconnect your Instagram account. We stop accessing your account immediately and delete the associated Instagram data within 30 days.
- Revoke access in Instagram. In the Instagram app, go to Settings, then Website permissions (or Apps and websites), find Mtschat and remove it. When Meta notifies us, we delete the associated data.
- Close your account or email us. Close your account from account settings, or email privacy@mtschat.com from the address on your account with the subject “Data deletion request”. We confirm receipt, verify the request and complete deletion within 30 days.
If you interacted with an account that uses Mtschat
Contact the business you messaged and ask it to delete your data — it can remove your contact record and conversation history in Mtschat directly. You can also email privacy@mtschat.com with your Instagram username and the account you interacted with. We will forward your request to that customer and, where appropriate, delete the data ourselves. Deleting data from Mtschat does not delete messages held by Instagram; you can manage those in Instagram itself.
If a deletion request reaches us through Meta’s data deletion callback, we process it automatically and provide a confirmation code you can use to check its status with us.
13. Children
The Service is a business tool intended for people aged 18 or over, and you must meet Instagram’s minimum age requirements to use Instagram. We do not knowingly collect personal data from children under 13 (or the higher age of digital consent in your country) as a controller. If you believe a child has given us personal data, email privacy@mtschat.com and we will delete it.
Customers must not use Mtschat to knowingly target children, and must comply with any laws that apply to communicating with minors.
14. Changes to this policy
We may update this policy as the Service, the law or our providers change. The “Last updated” date at the top shows when it last changed. If we make a material change, we will notify customers by email or in the app at least 14 days before it takes effect, unless the change is required sooner by law. Earlier versions are available on request.
15. Contact us
Questions, requests or complaints about privacy can be sent to:
- Privacy and data protection: privacy@mtschat.com — our Data Protection Officer can be reached at this address.
- Security issues: security@mtschat.com
- Legal notices: legal@mtschat.com
- Everything else: our contact page
If you are not satisfied with our response, you may complain to Singapore’s Personal Data Protection Commission, or to the data protection authority where you live or work.
Related: Terms of Use · Cookie Policy · Security