Legal
Privacy Policy
This policy explains how instasupport collects, uses, and protects your data.
Information we collect
- Account information: When you create an account, we collect your email address, workspace name, and password (stored as a secure hash).
- Store data: When you run audits, we crawl publicly accessible pages on your storefront. We store audit results, findings, scores, and screenshots.
- Support data: Messages, tickets, and conversations created through the help desk, live chat, or contact forms are stored in your workspace.
- Analytics data: If you connect Google Search Console, GA4, or Merchant Center, we sync aggregated metrics. We do not access individual user data from your Google accounts.
- Usage data: We collect anonymized usage patterns to improve the platform — page views, feature usage, and performance metrics.
How we use your data
- To provide the instasupport platform services — audits, support, knowledge base, CX intelligence, growth recommendations, and analytics.
- To generate AI-powered insights, suggested replies, and recommendations using third-party AI providers (Anthropic Claude).
- To send transactional emails: password resets, ticket reply notifications, audit completion alerts, and scheduled reports.
- To improve the platform based on aggregated, anonymized usage patterns.
- We never sell your data. We never use your store data to train AI models.
Data storage and security
- All data is stored in PostgreSQL databases with encryption at rest.
- Data in transit is encrypted via HTTPS (TLS 1.2+).
- OAuth tokens for Google integrations are encrypted using ASP.NET Core Data Protection before storage.
- Passwords are hashed using ASP.NET Core Identity with industry-standard algorithms.
- Workspace data is isolated — each merchant account can only access its own data.
Third-party services
- Anthropic Claude: Used for AI ticket classification, suggested replies, audit summaries, and CX intelligence. Ticket content is sent to Claude for processing but is not used for model training.
- Google APIs: Search Console, Analytics 4, and Merchant Center data is accessed via OAuth with read-only scopes. We store aggregated metrics, not raw Google data.
- Postmark: Used for transactional email delivery. Email content passes through Postmark servers for delivery.
- Cloudflare R2: Used for storing audit screenshots and file attachments.
Your rights
- Access: You can export your audit data, support tickets, and analytics via CSV and HTML export.
- Deletion: You can request deletion of your account and all associated data by contacting support@instasupport.com.
- Portability: Audit findings, support tickets, and analytics metrics are exportable in structured formats.
- Correction: You can update your account information through the account settings page.
Data retention
- Active account data is retained as long as your account exists.
- Deleted accounts: All workspace data is permanently deleted within 30 days of account deletion.
- Audit screenshots: Stored for the lifetime of the audit report.
- Support ticket data: Retained with the workspace. Closed tickets are not automatically deleted.
Contact
- For privacy-related questions or data requests, contact us at: privacy@instasupport.com
- This privacy policy was last updated on March 19, 2026.