Privacy Policy
Effective date: August 13, 2026
This policy describes how MYSTOREFRONT INC (“MyStorefront,” “we,” “us”) collects, uses, and shares information in MyStorefrontChat, including the website chat widget and Facebook Messenger and Instagram messaging. It is written to meet Meta’s Platform Terms and Developer Policies for apps that use Facebook Login, Messenger, and Instagram messaging.
1. Who this policy covers
This service has two kinds of people:
- Store operators — businesses that sign in, connect a Facebook Page or Instagram professional account, and use the inbox and AI replies.
- Customers — people who message a store through the website widget, Facebook Messenger, or Instagram Direct.
The store is responsible for its own customer relationship. We process conversation data so the store can operate its chatbot. If you messaged a store, you can also contact that store directly.
2. Information we collect
From store operators
- Account information: name, email, and login session.
- Widget settings, knowledge-base content the store uploads, and lead records the store’s bot collects.
- When a store clicks Connect with Facebook: the Facebook user ID of the person who authorized the app, Pages they grant access to (Page ID and name), a Page access token, and, if linked, the Instagram professional account ID and username.
From Facebook and Instagram (customers)
When someone messages a connected Page or Instagram account, Meta sends us webhook events. We store:
- The Messenger Page-scoped ID (PSID) or Instagram-scoped ID (IGSID).
- Message text, Meta message IDs, and timestamps.
- The Page or Instagram account the message was sent to, so we can route it to the right store.
We do not ask Meta for friends lists, photos, likes, or other profile data that is not required to receive and reply to a message. We do not use the Facebook JavaScript SDK or social plugins to track browsing on third-party sites.
From the website widget
Visitor messages, optional name, email, or phone if the store’s widget asks for them, a browser fingerprint used to keep the chat thread, and standard technical logs (IP address, user agent) needed to run the service.
3. How we use information
We use this information only to operate the product:
- Show the conversation in the store’s inbox and send replies through Messenger, Instagram, or the website widget.
- Generate an AI reply from the store’s knowledge base and settings.
- Qualify leads for the store when that feature is enabled.
- Keep the Facebook or Instagram connection working (refreshing Page tokens, verifying webhooks, handling deauthorize and data-deletion callbacks from Meta).
- Secure the service, prevent abuse, and comply with law.
Messenger and Instagram message content is used solely to provide messaging for that store. We do not sell it, use it for independent advertising, or use Meta user data to train generalized AI models.
4. How we share information
We do not sell personal information. We share it only as follows:
- The store. Customer messages and leads belong to the store that owns the widget. Store staff who can sign in to that account can read them.
- AI providers. Message text is sent to the store’s configured AI provider (for example OpenAI) only to generate a reply. Those providers process data under their own terms as our subprocessors.
- Hosting and infrastructure. Our servers and database host the application.
- Meta. We send replies and webhook acknowledgements back through Meta’s APIs so the customer receives the message in Messenger or Instagram.
- Legal. If required by law, or to protect the service, a store, or a person from harm.
Other stores on the platform cannot see another store’s conversations or Facebook/Instagram tokens.
5. Facebook Login and Meta Platform Terms
Store operators connect Pages with Facebook Login for Business. We request only the permissions needed to list Pages, send and receive messages, subscribe the Page to webhooks, and (when Instagram is linked) manage Instagram messages. Access tokens are stored encrypted on our servers. Stores never need to paste an App Secret.
We comply with Meta’s Platform Terms, Developer Policies, and Messenger/Instagram messaging rules, including limited use of messaging data. If Meta notifies us that a user removed the app, we disable that user’s connected channels. If Meta sends a data-deletion request, we disconnect those channels and remove stored access tokens.
6. Retention
Conversations, leads, and channel connections are kept while the store’s account is active, unless the store deletes them or disconnects the channel. Page access tokens are kept only while the channel is connected. After a Meta deauthorize or data-deletion callback, we disable the channel and delete the tokens. Backup copies may persist for a short period, then are overwritten.
7. Access, correction, and deletion
Store operators can disconnect Facebook or Instagram in widget Channels, delete conversations, or ask us to delete the account.
Customers can ask the store they messaged to delete the thread, use Facebook or Instagram’s tools to delete a message, or send a deletion request to us at admin@cmsmystorefront.com. You may also use Facebook’s “Remove app” and data-deletion flow. Our callback URL is https://chat.cmsmystorefront.com/channels/facebook/data-deletion.
8. Security
Traffic uses HTTPS. Channel credentials are stored encrypted. Access to the dashboard requires a signed-in store account. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
9. Cookies
We use a session cookie so store operators can stay signed in. The public website widget does not use Facebook cookies. We do not use Meta’s pixel on this product for advertising.
10. Children
The service is for businesses. It is not directed at children under 13, and we do not knowingly collect personal information from children under 13.
11. International processing
We currently host the application in the United States. If you access the service from elsewhere, your information is processed in the United States.
12. Changes
We may update this policy. The effective date at the top will change. Continued use of the service after an update means you accept the revised policy.
13. Contact
MYSTOREFRONT INC
Privacy questions: admin@cmsmystorefront.com
Support: mystorefrontcms.com/support
This page is the public privacy policy URL for the MyStorefrontChat Meta app: https://chat.cmsmystorefront.com/privacy