Avionettashare

Legal

Privacy policy

Last updated 25 August 2026 · Version 1.0

This policy explains what Avionettashare does with data, in plain terms. It covers the website you are reading and the Avionettashare API and dashboard. If something here is unclear, write to [email protected] and we will answer it.

Section 1Who we are

Avionettashare is operated by Avionetta Technology (FZE), a free zone establishment licensed by SRTIP, the Sharjah Research, Technology and Innovation Park, under trade licence number 11711.

Avionetta Technology (FZE)
Sharjah Research, Technology and Innovation Park (SRTIP)
Block B-B58-170, University City
Sharjah, United Arab Emirates
[email protected]

Three parties, and which one we are

There are three parties in every Avionettashare integration:

  • Avionettashare — us, the operator of the API and dashboard.
  • The Customer — the business or developer who holds an Avionettashare account and builds our API into their own product.
  • The End User — the Customer's user, who owns the Instagram professional account, Facebook Page, YouTube channel or TikTok account being connected.

We are the controller of Customer account data — the name, email, company, password hash, API keys and billing records of the person who signs up with us.

We are a processor for End User platform data. The Customer is the controller of their End Users' data, and we act only on the Customer's documented instructions. If you are an End User and want your data removed, you can ask either the Customer whose product you used or us directly — see section 13.

Section 2What we collect

This is the complete list. There is no residual category, and nothing outside this table is collected.

Customer account data — we are the controller
DataWhy we hold itLegal basisRetention
Name, email address, company nameTo identify the account holder, sign them in and contact them about the servicePerformance of a contractLife of the account, then 30 days
Password hashTo authenticate sign-in. We never store the password itselfPerformance of a contractLife of the account, then 30 days
API keysTo authenticate API requests and attribute them to an accountPerformance of a contractUntil revoked, or 30 days after account closure
Billing records — plan, invoices, payment status, last four digits and card brandTo charge for the service and to meet tax and accounting obligationsContract, and legal obligationRetained for the statutory period required by UAE law
End User connection data — we are a processor
DataWhy we hold itLegal basisRetention
Platform user ID (Instagram professional account ID, Facebook Page ID, YouTube channel ID, TikTok open ID)To address the correct account when publishing and when reading metricsThe End User's consent, given at the OAuth screenUntil disconnection or revocation
Username or handle, and profile picture URLSo the End User can tell their connected accounts apart in the interfaceThe End User's consentUntil disconnection or revocation
OAuth access token and refresh tokenTo act on the account with the permission the End User grantedThe End User's consentUntil disconnection or revocation
Granted scopes and permissionsTo know what we are allowed to do, and to refuse anything outside itThe End User's consentUntil disconnection or revocation
Content submitted for publishing — we are a processor
DataWhy we hold itLegal basisRetention
Media files — images and video uploaded for publishingTo transfer the file to the platform's upload endpointPerformance of a contract with the CustomerDeleted after successful publication, or within 30 days at the latest
Captions, titles, descriptions, hashtagsTo send with the postPerformance of a contractLife of the account
Scheduling timesTo publish at the time requestedPerformance of a contractLife of the account
Results and metrics — we are a processor
DataWhy we hold itLegal basisRetention
Platform post IDs, publish status, error messagesTo report back whether each destination succeeded, and to retry the ones that did notPerformance of a contractLife of the account
Post metrics — views, likes, comments, shares, savesTo display the analytics the End User authorised us to readThe End User's consentLife of the account, or until disconnection
Page and account level insightsSameThe End User's consentLife of the account, or until disconnection
Operational data — we are the controller
DataWhy we hold itLegal basisRetention
IP address and user agentTo rate limit, to investigate abuse and to secure the serviceLegitimate interests — keeping the service available and secure90 days
API request logs — endpoint, timestamp, response code, accountTo debug failures, to enforce plan limits and to answer support questionsLegitimate interests90 days
Support correspondenceTo answer and to keep a record of what was agreedLegitimate interests24 months

Section 3How we collect it

Data reaches us in exactly three ways:

  • Directly from the Customer, when they create an account, set up billing, upload content or call the API.
  • From the End User's OAuth consent, when they connect an account. The End User sees the platform's own consent screen, listing the permissions being requested, and grants or refuses them there.
  • From the platform APIs, when we publish on an authorised account or read the metrics for a post we published.

Avionettashare never asks for, receives or stores a social account password. Authorisation happens entirely on the platform's own login and consent screens. We only ever hold the token the platform issues afterwards, and that token can be revoked by the End User at any time.

Section 4Facebook and Instagram

Where an End User connects a Facebook Page or an Instagram professional account, Avionettashare uses the APIs provided by Meta Platforms, Inc. With the permissions the End User grants, we retrieve:

  • the list of Facebook Pages the End User administers;
  • Page access tokens for the Pages they select;
  • the Instagram professional account ID and username linked to those Pages;
  • the profile picture URL of the connected account;
  • the post IDs of content we publish on the account;
  • Page insights and media insights for that content.

Data received from Meta — Platform Data — is used solely to deliver the publishing and analytics features the End User authorised. Specifically, and without exception:

  • Platform Data is never sold, licensed or rented to anyone.
  • Platform Data is never used for advertising, ad targeting, profiling or audience building.
  • Platform Data is never combined with data from other platforms, or with data from any other source, to build a profile of a person.
  • Platform Data is never used to train machine learning or AI models.

When an End User disconnects a Facebook Page or Instagram account, we revoke the token with Meta and delete the stored tokens, media, post records and metrics for that account within 24 hours. See data deletion.

Meta's own handling of your data is governed by the Meta Privacy Policy.

Section 5TikTok

Where an End User connects a TikTok account, Avionettashare uses the APIs provided by TikTok. With the permissions the End User grants, we retrieve:

  • the open ID that identifies the account to our application;
  • the username and display name;
  • the avatar URL;
  • the creator's available privacy options and posting settings, so the End User can choose them before a video is published;
  • the video IDs of content we publish on the account;
  • post metrics for that content.

As with every other platform, TikTok data is used only to deliver the publishing and analytics features the End User authorised. It is never sold, never used for advertising or profiling, never combined with data from other platforms, and never used to train machine learning or AI models. Disconnecting revokes the token and deletes the associated data within 24 hours.

TikTok's own handling of your data is governed by the TikTok Privacy Policy.

Section 6YouTube and Google

Avionettashare uses YouTube API Services. By connecting a YouTube channel you also agree to be bound by the YouTube Terms of Service.

Google's handling of your data is described in the Google Privacy Policy.

You can revoke Avionettashare's access to your Google account at any time through the Google security settings page at https://myaccount.google.com/permissions.

With the permissions the End User grants, we retrieve:

  • the YouTube channel ID and channel title;
  • the channel thumbnail URL;
  • the video IDs of content we upload to the channel;
  • view, like and comment counts for that content.

Limited Use

Avionettashare's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

What we do with YouTube API data

  • We use it only to upload the videos the End User asked us to upload, and to show them the metrics for those videos.
  • Google user data is never used to train machine learning or AI models, ours or anyone else's.
  • It is never sold, never used for advertising, and never transferred to anyone except as needed to provide the feature the user asked for, or where required by law.
  • No human at Avionettashare reads Google user data except with the End User's explicit permission for a support request, for security purposes, or where required by law.

How long we keep it

  • Stored YouTube API data is refreshed or deleted within 30 days. Anything older than 30 days is either re-fetched from the API or removed.
  • When an End User disconnects their channel, or revokes access at https://myaccount.google.com/permissions, the authorised data we hold is deleted immediately.

Section 7How we use data

We use data for these purposes and no others:

  • to publish the content an End User authorised us to publish;
  • to display the metrics for that content;
  • to operate, monitor, debug and secure the service;
  • to bill Customers and meet our tax and accounting obligations;
  • to answer support requests and send service notices about outages, security or changes to this policy.

And to be explicit about what we do not do:

  • We do not sell data. There is no circumstance in which we would.
  • We do not share data with advertisers, ad networks or data brokers.
  • We do not use any data — from any platform — to train machine learning or AI models.
  • We do not access account content beyond the scopes the End User granted. If a feature would need a wider scope, we ask for it at the consent screen or we do not build it.
  • We do not send marketing email to End Users. We are not their vendor; the Customer is.
  • We do not run advertising on this site or in the product.

Section 8Sub-processors

These are the only third parties that process data on our behalf. Each is bound by a written agreement that limits them to our instructions and requires confidentiality and appropriate security.

Sub-processorWhat it doesWhere it processes
Cloudflare, Inc.DNS, CDN, DDoS protection and R2 object storage for media awaiting publicationUnited States, with global edge locations
Namecheap, Inc.Application hosting and databaseUnited States
Namecheap Private EmailTransactional and support emailUnited States
Tap PaymentsCard payment processing for regional cardsUnited Arab Emirates
Stripe, Inc.Card payment processing for international cardsUnited States and Ireland

We do not give any of them permission to use the data for their own purposes. Payment processors receive only what they need to take a payment; we never see or store a full card number. If this list changes we update this page and give Customers notice before the new sub-processor starts handling data.

Section 9International transfers

Data is processed primarily in the United States, on the infrastructure listed in section 8. Administrative access is exercised from the United Arab Emirates, where we are established, so data may be accessed from and transferred to the UAE.

Where personal data is transferred out of the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission's Standard Contractual Clauses, or the UK International Data Transfer Addendum, as incorporated into our agreements with each sub-processor, together with the technical measures in section 11. A copy of the clauses we rely on is available on request to [email protected].

Section 10Retention

The per-item periods are in the tables in section 2. The defaults are:

  • OAuth access and refresh tokens — held until the End User disconnects the account or revokes access at the platform, then deleted.
  • Media files — deleted from object storage after successful publication, and in any case within 30 days of upload.
  • Post records and metrics — retained for the life of the account, or until the account they belong to is disconnected.
  • YouTube API data — refreshed or deleted within 30 days, as required by section 6.
  • API request logs, IP addresses and user agents — 90 days.
  • Backups — purged within 35 days, so deleted data disappears from backups within 35 days of deletion.
  • Billing records — retained for the period UAE tax law requires, and for nothing beyond it.

Section 11Security

  • OAuth access and refresh tokens are encrypted at rest.
  • All traffic is served over TLS 1.2 or higher. The site sets HTTP Strict Transport Security.
  • Passwords are stored only as salted hashes, never in a recoverable form.
  • Access to production systems is restricted to named personnel, uses multi-factor authentication, and is logged.
  • Media is deleted from object storage after successful publication or on expiry, so uploaded files are not accumulated.
  • API keys can be rotated or revoked by the Customer at any time.

No system is completely secure, and we will not pretend otherwise. What we commit to instead is this: if a breach affects your personal data, we will notify affected Customers and, where the law requires it, the relevant supervisory authority, without undue delay and within 72 hours of becoming aware of it. The notice will say what happened, what data was involved, and what we are doing about it.

Section 12Your rights

Depending on where you live, you have the right to:

  • access the personal data we hold about you;
  • correct anything inaccurate;
  • delete it — see section 13;
  • receive a portable copy in a machine-readable format;
  • object to or restrict processing based on our legitimate interests;
  • withdraw consent at any time, which for platform data means disconnecting the account or revoking access at the platform;
  • complain to a supervisory authority in your country.

If you are a Customer, exercise these rights from the dashboard, or by writing to [email protected].

If you are an End User, you have two routes and both work. You can ask through the product you used — the Customer is your data controller and can act on your request. Or you can write to us directly at [email protected]; we will act on it and inform the Customer.

We respond to every request within 30 days. We do not charge for it. We may ask you for enough information to confirm you are who you say you are, and for nothing more than that.

Section 13Deletion

There are three ways to have your data deleted, all free: disconnect a single account, delete your whole account, or email us. Each one, what it removes and how long it takes is set out on the data deletion page, together with the exact path for revoking access at Facebook, Instagram, YouTube and TikTok.

Section 14Children

Avionettashare is not offered to anyone under 18, and we do not knowingly collect data from anyone under 18. Account holders must also meet the minimum age of each platform they connect. If we learn that we hold data belonging to a child, we delete it. If you believe that has happened, write to [email protected].

Section 15Cookies

This website sets no cookies. It runs no analytics, no tag manager, no advertising pixel and no session tracking. It makes no request to any third-party host — the typefaces are served from this domain, so nothing about your visit is disclosed to a font provider or a CDN operated by someone else.

When the dashboard opens, it will set one cookie: a session cookie that keeps you signed in. It is marked HttpOnly, Secure and SameSite=Lax, it holds a random session identifier and nothing else, and it expires when you sign out. That cookie is strictly necessary to operate a login, so it does not require consent — and there will be no others to consent to.

If that ever changes, this section changes first and we ask before setting anything new.

Section 16Changes

The date at the top of this page is the date it was last changed. For a material change — a new purpose, a new category of data, a new sub-processor — we give Customers 30 days' notice by email before it takes effect, and post the updated page here on the day the notice goes out. Minor corrections take effect when posted.

Previous versions are available on request.

Section 17Contact

For any privacy question, data request or complaint, write to [email protected]. We acknowledge within 72 hours and answer within 30 days.

Avionetta Technology (FZE)
Trade licence 11711, issued by SRTIP
Sharjah Research, Technology and Innovation Park (SRTIP)
Block B-B58-170, University City
Sharjah, United Arab Emirates
[email protected]