Veqlio Privacy Policy
Last updated: August 5, 2026
Veqlio (“Veqlio”, “we”, “us”) is a product of Thriveark Inc., 1250 René-Lévesque Blvd W, Montréal, QC H3B 4W8, Canada. This policy explains what data we collect, why, and what your rights are. It covers both our customers (businesses and agencies using Veqlio, “Clients”) and the people who interact with those businesses on Instagram (“End Users”).
1. What Veqlio does
Veqlio connects to a Client’s Instagram professional account through Meta’s official Instagram API to automate replies to comments and direct messages, provide a shared team inbox, and maintain a lightweight CRM for the Client.
2. Data we collect
From Clients (account holders)
- Account data: name, email address, password credentials (managed by our authentication provider), team member names and roles.
- Instagram connection data: your Instagram professional account ID, username, and the access tokens Meta issues when you authorize Veqlio. Tokens are stored encrypted.
- Optional AI configuration: if you connect your own OpenAI or Anthropic API key, we store it encrypted and use it only to generate replies on your behalf.
- Billing data, if applicable, processed by our payment provider (we never store full card numbers).
From End Users (people who message or comment on a Client’s Instagram)
Received through Meta’s Instagram API only:
- Instagram-scoped user ID, username, display name, and profile picture.
- The content of comments and direct messages sent to the Client’s account, including timestamps.
- Any information an End User voluntarily provides in conversation (for example an email address or phone number they type to the business).
We do NOTreceive or collect End Users’ email addresses, phone numbers, passwords, or contact lists from Instagram — Meta’s API does not expose them.
Automatically
Standard server logs (IP address, browser type, timestamps) for security and debugging; minimal cookies strictly required for authentication and session management. We do not use advertising cookies or third-party tracking.
3. How we use data
- To provide the service: receiving comments/messages via Meta webhooks, sending replies the Client configures, displaying conversations in the Client’s inbox, and maintaining the Client’s contact records.
- To generate AI-assisted replies, only when the Client enables it, using the Client’s own AI provider key.
- To secure, debug, and improve the service.
- To communicate with Clients about their account.
We do NOT: sell any data; use End User data for advertising; combine one Client’s End User data with another Client’s; use Platform Data (data received from Meta) for any purpose other than providing the service to the Client it belongs to, in accordance with Meta Platform Terms.
4. Legal basis
For Clients: performance of contract. For End Users: legitimate interest of the Client in responding to messages directed at them; the Client is the data controller for End User conversation data, and Veqlio acts as a processor/service provider on the Client’s behalf.
5. Who we share data with
Only sub-processors necessary to run the service:
- Hostinger International Ltd. (application hosting and infrastructure, EU)
- Supabase (database, authentication and realtime infrastructure, EU region)
- Email delivery: Resend (transactional email)
- AI processing: OpenAI and/or Anthropic, only when the Client enables AI replies, under the Client’s own API key and the provider’s terms
- Payment processing: Stripe, if billing is enabled
Each processes data only on our instructions. We never sell or rent data. We may disclose data if required by law.
6. Data retention
- Client account data: retained while the account is active and deleted within 30 days of account closure.
- End User conversation and contact data: retained while the Client’s account is active or until the Client deletes it (Clients can delete conversations and contacts at any time).
- Instagram access tokens: deleted immediately when a Client disconnects their Instagram account or closes their account.
- Server logs: retained up to 90 days.
7. Deletion rights
Clients can delete their data in-app or by request. End Users can request deletion of their data — see our Data Deletion page. When a Client disconnects Instagram or deletes their account, associated Platform Data is deleted. We honor deletion requests initiated through Meta (data deletion callbacks) automatically.
8. Security
Data is encrypted in transit (TLS) and at rest. Access tokens and API keys are stored encrypted. Access to production data is restricted to authorized personnel. Row-level access controls isolate each Client’s data.
9. International transfers
Our infrastructure is located in the European Union. Where data is transferred across borders, we rely on our providers’ standard contractual safeguards.
10. Children
Veqlio is a business tool, not directed at children. We do not knowingly collect data from anyone under 13 (or the applicable age of digital consent). Instagram requires its users to meet its own minimum age.
11. Changes and contact
We will post changes to this policy on this page with an updated date.
Contact: privacy@veqlio.com · +1 438 803-2333 — Thriveark Inc., 1250 René-Lévesque Blvd W, Montréal, QC H3B 4W8, Canada.
Veqlio is not affiliated with Meta Platforms, Inc. Instagram is a trademark of Meta Platforms, Inc.