Legal

Privacy Policy

This Policy explains how CodeChest Ltd handles personal information when you visit, create an account, connect Instagram, run campaigns, purchase a plan, or contact us through the CodeChest-operated Cavabla service.

Last updated: September 8, 2026

1. Who we are

CodeChest Ltd is the operator and data controller for the CodeChest-operated Cavabla service. We are registered in England and Wales under company number 16912070. Our registered office is 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.

2. What Cavabla does and what this Policy covers

Cavabla enables authorised businesses and teams to connect Instagram professional accounts, configure keyword campaigns, receive Meta webhooks, send replies through official Meta APIs, track campaign links, and review delivery and performance records. This Policy covers the website, accounts, workspaces, billing, support, and those automation activities.

3. Information we collect

Account and profile information

We collect your name, email address, phone number, date of birth, chosen gender setting, password hash, email-verification status, consent record, workspace membership, and account preferences. If you use Google sign-in, we receive your Google account identifier, name, email address, and profile image. We do not receive your Google password.

Security and device information

We process session identifiers, IP address, browser or device information, sign-in activity, session access times, two-factor authentication status, and rate-limit or security events. Consent audit records may include the date, IP address, and general device type used when accepting legal terms.

Workspace, campaign, and Instagram information

We process workspace names and roles; connected Instagram professional account identifiers, usernames, names, encrypted access tokens, token status, and follower snapshots; campaign names, keywords, message text, public replies, links, templates, and settings; webhook payloads, comment or message text and identifiers, sender identifiers, delivery results, error logs, and operational diagnostics.

Billing and link analytics

We store plan, subscription, promotion, invoice-status, and Stripe customer or subscription references. Stripe processes payment-card and payment-method details; Cavabla does not store full card numbers. For tracked campaign links, we may process a pseudonymous delivery token associated with the Instagram sender identifier and available username, together with a hashed IP value, browser information, referrer, link, campaign, and click time. This lets workspace users see total clicks, unique attributed recipients, and recipient-level click counts without placing the Instagram identifier in the URL.

What we do not collect

  • Instagram or Google passwords;
  • full payment-card numbers;
  • phone address books or contact lists;
  • precise GPS location;
  • data for sale to data brokers; or
  • content for training artificial-intelligence models.

4. How and why we use information

PurposeExamplesTypical legal basis
Provide the serviceAccounts, workspaces, campaigns, Meta connections, replies, reportsContract
Authenticate and secureVerification, sessions, 2FA, abuse prevention, audit recordsContract and legitimate interests
Support and communicateService email and timely contact about important account or operational issuesContract and legitimate interests
Administer billingPlans, payments, subscription changes, fraud and accountingContract and legal obligation
Comply and improveDiagnostics, platform compliance, reliability, legal requestsLegitimate interests and legal obligation

We do not use account, campaign, comment, message, or Instagram data to train AI models or to make decisions that produce legal or similarly significant effects about users.

5. Why we require a phone number

We require a phone number so authorised CodeChest support staff can reach you quickly when an important account, security, billing, Instagram integration, or service problem needs timely resolution. Depending on the issue and the number supplied, contact may be by phone call or service message. This is intended to reduce delays when email alone is not fast enough.

We do not use your phone number for advertising or promotional campaigns without separate consent, and we do not sell it. Access is limited to authorised personnel and providers that need it to deliver support or protect the service. You can ask us to correct or delete it, subject to account requirements and legal retention duties.

6. Cookies and tracking technologies

Cavabla currently uses a necessary authentication cookie and related security storage. We do not currently use advertising cookies or third-party behavioural analytics on the Cavabla frontend. If that changes, we will update this Policy and provide consent controls where required.

TechnologyPurposeDuration / control
auth.session-tokenKeeps you signed in and links the browser to a server-side sessionUp to 30 days; removed on sign-out or through browser controls
Necessary local or session storageShort-lived interface, verification, and security contextUntil replaced, cleared, or the browser session ends

Blocking necessary storage may prevent sign-in or other core functions. Browser-level Do Not Track signals do not change necessary processing.

Each tracked campaign link delivered by direct message passes through a first-party Cavabla redirect before the visitor reaches the destination. A click is recorded only when the link contains a valid personalised delivery token, and it is attributed to the intended Instagram recipient. This does not rely on an advertising cookie. A forwarded link may still be attributed to its original recipient, and automated link previews may register as clicks.

7. Service providers and disclosures

We do not sell personal information. We disclose only what is reasonably needed to operate Cavabla, process payments, deliver communications, connect Instagram, secure the service, or comply with law.

ProviderPurposePrivacy information
MetaInstagram OAuth, account data, webhooks, comments, messages, and repliesMeta Privacy Policy
StripeSubscription checkout, payment processing, invoices, fraud preventionStripe Privacy Policy
Resend or configured mail providerVerification, security, billing, and service emailsResend Privacy Policy
GoogleOptional Google sign-inGoogle Privacy Policy
Hosting, database, Redis, and network providersApplication hosting, storage, queues, backups, security, and deliveryThe providers configured for the CodeChest-operated deployment

We may also disclose information to professional advisers, regulators, courts, law enforcement, or a buyer in a genuine corporate transaction where lawful and appropriately protected.

8. Data retention and deletion

InformationRetention approach
Account, profile, phone, and workspace dataFor the life of the account. A signed-in user may hard-delete the account after every subscription on an owned workspace has reached CANCELED status
Authentication sessionsUp to 30 days unless you sign out, revoke the session, or it is removed for security
Instagram tokensUntil disconnection, account or workspace deletion, expiry, or when no longer needed
Campaigns, webhooks, messages, delivery logs, and link analyticsWhile needed to operate the workspace; hard-deleted from the live application when the owner deletes the workspace through account deletion
Billing, tax, fraud, and accounting recordsNormally up to 6 years, or longer where law or an active dispute requires it
Consent and legal recordsAs needed to demonstrate the agreement and compliance with law

Disconnecting Instagram removes the stored connection and stops related campaigns. For broader deletion instructions, see our Data Deletion page.

Self-service account deletion is permanent. It removes the user's authentication and profile data, memberships, and every owned workspace with its live application records. It does not delete another owner's workspace. Active, paused, trial and other non-canceled subscriptions block deletion; a scheduled cancellation must first reach CANCELED. Stripe and other processors may retain transaction or compliance records independently where required by law.

9. Your privacy rights

Depending on applicable law, you may have rights to access, correct, delete, restrict, or receive your information; object to processing; withdraw consent; and complain to a regulator. UK and EEA users may exercise rights under the UK GDPR or GDPR. California residents may request access, correction, or deletion and may ask about categories collected or disclosed. We do not sell or share personal information for cross-context behavioural advertising.

Send requests to [email protected]. We may verify your identity and authority before acting. We normally respond within one month or the period required by applicable law. UK users may also complain to the Information Commissioner's Office.

10. International transfers

Cavabla and its providers may process information in the United Kingdom, European Economic Area, United States, and other locations in which providers operate. Where required, we rely on adequacy regulations, the UK International Data Transfer Agreement or Addendum, standard contractual clauses, and appropriate technical and contractual safeguards.

11. Age restriction

Cavabla is intended only for people aged 18 or older. We do not knowingly permit people under 18 to create accounts or use the service. Date of birth is used to confirm this requirement. If you believe a person under 18 has supplied information, contact us so we can investigate and delete or restrict it as appropriate.

12. Security

We use measures designed to protect information, including HTTPS/TLS, password hashing, secure session cookies in production, role-based workspace access, encrypted Instagram tokens, optional two-factor authentication, rate limiting, webhook verification, and operational logging. No online system is completely secure. Contact us immediately if you suspect unauthorised access.

13. Changes to this Policy

We may update this Policy when the service, providers, law, or data practices change. We will publish the revised date and provide an additional email or in-app notice where a change materially affects users. New processing that requires consent will not begin until the required consent is available.

14. Contact

Privacy requests, deletion requests, and data-protection complaints can be sent to [email protected]. You may also write to CodeChest Ltd at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.