1. Who we are
CodeChest Ltd is the operator and data controller for the CodeChest-operated Cavabla service. We are registered in England and Wales under company number 16912070. Our registered office is 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.
2. What Cavabla does and what this Policy covers
Cavabla enables authorised businesses and teams to connect Instagram professional accounts, configure keyword campaigns, receive Meta webhooks, send replies through official Meta APIs, track campaign links, and review delivery and performance records. This Policy covers the website, accounts, workspaces, billing, support, and those automation activities.
3. Information we collect
Account and profile information
We collect your name, email address, phone number, date of birth, chosen gender setting, password hash, email-verification status, consent record, workspace membership, and account preferences. If you use Google sign-in, we receive your Google account identifier, name, email address, and profile image. We do not receive your Google password.
Security and device information
We process session identifiers, IP address, browser or device information, sign-in activity, session access times, two-factor authentication status, and rate-limit or security events. Consent audit records may include the date, IP address, and general device type used when accepting legal terms.
Workspace, campaign, and Instagram information
We process workspace names and roles; connected Instagram professional account identifiers, usernames, names, encrypted access tokens, token status, and follower snapshots; campaign names, keywords, message text, public replies, links, templates, and settings; webhook payloads, comment or message text and identifiers, sender identifiers, delivery results, error logs, and operational diagnostics.
Billing and link analytics
We store plan, subscription, promotion, invoice-status, and Stripe customer or subscription references. Stripe processes payment-card and payment-method details; Cavabla does not store full card numbers. For tracked campaign links, we may process a pseudonymous delivery token associated with the Instagram sender identifier and available username, together with a hashed IP value, browser information, referrer, link, campaign, and click time. This lets workspace users see total clicks, unique attributed recipients, and recipient-level click counts without placing the Instagram identifier in the URL.
What we do not collect
- Instagram or Google passwords;
- full payment-card numbers;
- phone address books or contact lists;
- precise GPS location;
- data for sale to data brokers; or
- content for training artificial-intelligence models.
4. How and why we use information
| Purpose | Examples | Typical legal basis |
|---|---|---|
| Provide the service | Accounts, workspaces, campaigns, Meta connections, replies, reports | Contract |
| Authenticate and secure | Verification, sessions, 2FA, abuse prevention, audit records | Contract and legitimate interests |
| Support and communicate | Service email and timely contact about important account or operational issues | Contract and legitimate interests |
| Administer billing | Plans, payments, subscription changes, fraud and accounting | Contract and legal obligation |
| Comply and improve | Diagnostics, platform compliance, reliability, legal requests | Legitimate interests and legal obligation |
We do not use account, campaign, comment, message, or Instagram data to train AI models or to make decisions that produce legal or similarly significant effects about users.
5. Why we require a phone number
We require a phone number so authorised CodeChest support staff can reach you quickly when an important account, security, billing, Instagram integration, or service problem needs timely resolution. Depending on the issue and the number supplied, contact may be by phone call or service message. This is intended to reduce delays when email alone is not fast enough.
We do not use your phone number for advertising or promotional campaigns without separate consent, and we do not sell it. Access is limited to authorised personnel and providers that need it to deliver support or protect the service. You can ask us to correct or delete it, subject to account requirements and legal retention duties.
7. Service providers and disclosures
We do not sell personal information. We disclose only what is reasonably needed to operate Cavabla, process payments, deliver communications, connect Instagram, secure the service, or comply with law.
| Provider | Purpose | Privacy information |
|---|---|---|
| Meta | Instagram OAuth, account data, webhooks, comments, messages, and replies | Meta Privacy Policy |
| Stripe | Subscription checkout, payment processing, invoices, fraud prevention | Stripe Privacy Policy |
| Resend or configured mail provider | Verification, security, billing, and service emails | Resend Privacy Policy |
| Optional Google sign-in | Google Privacy Policy | |
| Hosting, database, Redis, and network providers | Application hosting, storage, queues, backups, security, and delivery | The providers configured for the CodeChest-operated deployment |
We may also disclose information to professional advisers, regulators, courts, law enforcement, or a buyer in a genuine corporate transaction where lawful and appropriately protected.
8. Data retention and deletion
| Information | Retention approach |
|---|---|
| Account, profile, phone, and workspace data | For the life of the account. A signed-in user may hard-delete the account after every subscription on an owned workspace has reached CANCELED status |
| Authentication sessions | Up to 30 days unless you sign out, revoke the session, or it is removed for security |
| Instagram tokens | Until disconnection, account or workspace deletion, expiry, or when no longer needed |
| Campaigns, webhooks, messages, delivery logs, and link analytics | While needed to operate the workspace; hard-deleted from the live application when the owner deletes the workspace through account deletion |
| Billing, tax, fraud, and accounting records | Normally up to 6 years, or longer where law or an active dispute requires it |
| Consent and legal records | As needed to demonstrate the agreement and compliance with law |
Disconnecting Instagram removes the stored connection and stops related campaigns. For broader deletion instructions, see our Data Deletion page.
Self-service account deletion is permanent. It removes the user's authentication and profile data, memberships, and every owned workspace with its live application records. It does not delete another owner's workspace. Active, paused, trial and other non-canceled subscriptions block deletion; a scheduled cancellation must first reach CANCELED. Stripe and other processors may retain transaction or compliance records independently where required by law.
9. Your privacy rights
Depending on applicable law, you may have rights to access, correct, delete, restrict, or receive your information; object to processing; withdraw consent; and complain to a regulator. UK and EEA users may exercise rights under the UK GDPR or GDPR. California residents may request access, correction, or deletion and may ask about categories collected or disclosed. We do not sell or share personal information for cross-context behavioural advertising.
Send requests to [email protected]. We may verify your identity and authority before acting. We normally respond within one month or the period required by applicable law. UK users may also complain to the Information Commissioner's Office.
10. International transfers
Cavabla and its providers may process information in the United Kingdom, European Economic Area, United States, and other locations in which providers operate. Where required, we rely on adequacy regulations, the UK International Data Transfer Agreement or Addendum, standard contractual clauses, and appropriate technical and contractual safeguards.
11. Age restriction
Cavabla is intended only for people aged 18 or older. We do not knowingly permit people under 18 to create accounts or use the service. Date of birth is used to confirm this requirement. If you believe a person under 18 has supplied information, contact us so we can investigate and delete or restrict it as appropriate.
12. Security
We use measures designed to protect information, including HTTPS/TLS, password hashing, secure session cookies in production, role-based workspace access, encrypted Instagram tokens, optional two-factor authentication, rate limiting, webhook verification, and operational logging. No online system is completely secure. Contact us immediately if you suspect unauthorised access.
13. Changes to this Policy
We may update this Policy when the service, providers, law, or data practices change. We will publish the revised date and provide an additional email or in-app notice where a change materially affects users. New processing that requires consent will not begin until the required consent is available.
14. Contact
Privacy requests, deletion requests, and data-protection complaints can be sent to [email protected]. You may also write to CodeChest Ltd at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.