Legal

Privacy Policy

This policy explains how instasupport collects, uses, and protects your data.

Information we collect

  • Account information: When you create an account, we collect your email address, workspace name, and password (stored as a secure hash).
  • Store data: When you run audits, we crawl publicly accessible pages on your storefront. We store audit results, findings, scores, and screenshots.
  • Support data: Messages, tickets, and conversations created through the help desk, live chat, or contact forms are stored in your workspace.
  • Analytics data: If you connect Google Search Console, GA4, or Merchant Center, we sync aggregated metrics. We do not access individual user data from your Google accounts.
  • Usage data: We collect anonymized usage patterns to improve the platform — page views, feature usage, and performance metrics.

How we use your data

  • To provide the instasupport platform services — audits, support, knowledge base, CX intelligence, growth recommendations, and analytics.
  • To generate AI-powered insights, suggested replies, and recommendations using third-party AI providers (Anthropic Claude).
  • To send transactional emails: password resets, ticket reply notifications, audit completion alerts, and scheduled reports.
  • To improve the platform based on aggregated, anonymized usage patterns.
  • We never sell your data. We never use your store data to train AI models.

Data storage and security

  • All data is stored in PostgreSQL databases with encryption at rest.
  • Data in transit is encrypted via HTTPS (TLS 1.2+).
  • OAuth tokens for Google integrations are encrypted using ASP.NET Core Data Protection before storage.
  • Passwords are hashed using ASP.NET Core Identity with industry-standard algorithms.
  • Workspace data is isolated — each merchant account can only access its own data.

Third-party services

  • Anthropic Claude: Used for AI ticket classification, suggested replies, audit summaries, and CX intelligence. Ticket content is sent to Claude for processing but is not used for model training.
  • Google APIs: Search Console, Analytics 4, and Merchant Center data is accessed via OAuth with read-only scopes. We store aggregated metrics, not raw Google data.
  • Postmark: Used for transactional email delivery. Email content passes through Postmark servers for delivery.
  • Cloudflare R2: Used for storing audit screenshots and file attachments.

Your rights

  • Access: You can export your audit data, support tickets, and analytics via CSV and HTML export.
  • Deletion: You can request deletion of your account and all associated data by contacting support@instasupport.com.
  • Portability: Audit findings, support tickets, and analytics metrics are exportable in structured formats.
  • Correction: You can update your account information through the account settings page.

Data retention

  • Active account data is retained as long as your account exists.
  • Deleted accounts: All workspace data is permanently deleted within 30 days of account deletion.
  • Audit screenshots: Stored for the lifetime of the audit report.
  • Support ticket data: Retained with the workspace. Closed tickets are not automatically deleted.

Contact

  • For privacy-related questions or data requests, contact us at: privacy@instasupport.com
  • This privacy policy was last updated on March 19, 2026.