Last updated: 1 August 2026
SocialPosts is a Shopify app that renders your products as branded image posts and publishes them to your Instagram account. This policy explains exactly what it reads, what it stores, what it sends elsewhere, and how to get rid of it.
It is written to be checked against the app rather than to sound reassuring. If something here does not match what the app does, the app is wrong and we want to hear about it: support@socialltd.com.
The short version
- We read your products, collections and translations from Shopify.
- We never read or store customer data, orders, payment details or email addresses. The app does not request those permissions and there is nowhere in the database to put them.
- We send your poster image, caption and alt text to Instagram, because that is the post. Nothing else leaves our servers.
- There is no AI and no analytics. Your product data is not used to train anything, and is not shared with any third party for any purpose.
- Uninstalling deletes everything.
Who we are
SocialPosts is operated by Social Technologies. For anything in this policy, including access and deletion requests, contact support@socialltd.com.
For UK/EU data protection purposes, Social Technologies is the data controller for the account data described below, and a data processor acting on your instructions for the Shopify store data the app reads.
What we read from Shopify
The app requests five permissions and no others. Shopify shows you these at install and you can see them at any time under Apps in your admin.
| Permission | What it is used for |
|---|---|
read_products |
Product titles, prices, images, tags, type, vendor and status — the content of a poster and its caption |
read_files |
Reading image URLs attached to products |
write_files |
Uploading the rendered poster to your Shopify Files, so Instagram can fetch it from your own CDN |
read_translations |
Your own product translations, so a poster can be rendered in a second language |
read_locales |
Which languages your store publishes, so we only offer those |
We also read basic shop details: your store name, currency, timezone and primary domain. Currency and timezone are used to format prices correctly and to fire posts at the right local time.
We do not request, receive or store: customers, orders, checkouts, carts, payment details, email addresses, phone numbers, physical addresses, inventory costs, margins or supplier information.
What we store, and for how long
Everything is stored in a PostgreSQL database hosted by Neon in AWS us-east-2 (Ohio, USA), and the application runs on Google Cloud Run in us-central1 (Iowa, USA).
| Data | Retention |
|---|---|
| Your store domain and app access token (encrypted) | Until you uninstall |
| Your settings: timezone, posting limits, caption template, brand hashtags | Until you uninstall |
| Which collections you post from, and at what times | Until you uninstall |
| Your poster templates, including any background image you upload | Until you uninstall |
| Post history: product title, caption, Instagram link, status | Until you uninstall |
| Rendered poster images | 7 days by default, then deleted automatically. Adjustable in Settings |
| Fonts you install from Google Fonts | Until you uninstall |
| Your Instagram account id, username and access token (encrypted) | Until you disconnect or uninstall |
| Diagnostic event log | 30 days, then deleted automatically |
Rendered images and the diagnostic log are pruned by a nightly job. Nothing else expires on its own.
What we send to other services
Instagram / Meta. When a post is published we send the poster image, the caption, and the image’s alt text to the Instagram Graph API, along with the access token you authorised. This is the post itself — it is the purpose of the app. Meta’s handling of it is governed by their own privacy policy.
Shopify. With poster hosting set to Shopify Files (the default), the rendered image is uploaded to your own Shopify Files library so Instagram can fetch it from your CDN rather than from us.
Google Fonts. When you install a font, we request that font family from fonts.googleapis.com and fonts.gstatic.com. The request contains a font family name and nothing else — no shop, product or account data. It happens when you install a font, never when a post is rendered, and the font is stored with us afterwards so no further requests are made.
That is the complete list. There is no analytics provider, no error-tracking service, no advertising network, no AI or machine-learning service, and no data broker. Your product data is never used to train a model.
Rendered posters are publicly reachable
This is worth stating plainly because it is not obvious.
Instagram fetches the poster image from a public URL — it cannot log in to get it. That means a rendered poster is readable by anyone who has its URL, for as long as it is retained.
The URLs are long and not guessable, and they are not linked from anywhere, but they are not secret. This is why the app deliberately does not allow cost price, margin or supplier fields on a poster: they would become public. Only fields that are already public on your storefront can be placed on a poster.
Posts published to Instagram are, of course, public in the ordinary way.
Security
- Access tokens for both Shopify and Instagram are encrypted at rest with AES-256-GCM. They are never written to logs and never shown in the app.
- All traffic is over HTTPS.
- Shopify access tokens expire after one hour and are refreshed automatically; refresh tokens rotate on every use.
- The diagnostic block on the app’s Contact us page deliberately contains no tokens, no product data and no customer data, so it is safe to send to us.
No system is perfectly secure, and we do not claim otherwise. If you believe you have found a vulnerability, please email support@socialltd.com before disclosing it publicly.
Deleting your data
Uninstall the app. That is the whole process. When Shopify tells us the app has been uninstalled we clear your access token immediately, and Shopify’s mandatory shop/redact request — which arrives about 48 hours later — deletes everything: settings, collections, posting times, templates, post history, rendered images, installed fonts, your Instagram connection, and the diagnostic log.
Posts already published to Instagram are not deleted. They belong to your Instagram account, not to this app, and only you can remove them.
You can also:
- Disconnect Instagram from the Instagram tab, which deletes the stored Instagram token and account details immediately, without uninstalling.
- Ask us directly at support@socialltd.com. We will confirm within 30 days.
We support Shopify’s mandatory privacy webhooks: customers/data_request, customers/redact and shop/redact. The two customer topics are answered and logged, and there is nothing to hand over or erase, because the app holds no customer data.
Your rights
If you are in the UK or EU, you have the right to access your data, correct it, delete it, restrict or object to its processing, and receive a copy in a portable format. If you are in California, you have equivalent rights under the CCPA, and we do not sell or share personal information as those terms are defined there.
Exercise any of these by emailing support@socialltd.com.
Our lawful basis for processing is the performance of our contract with you — we cannot publish your products without reading them. Where we rely on legitimate interests, it is limited to keeping the service secure and diagnosing faults.
Because the app holds no customer data, a request under this policy concerns your own store and account data only.
International transfers
Our servers are in the United States. If you are outside the US, using the app transfers your store data there. Transfers from the UK/EU rely on the standard contractual clauses operated by our hosting providers, Google Cloud and Neon.
Children
The app is a business tool sold to merchants and is not directed at children. We do not knowingly collect data from anyone under 16.
Changes
We will update this page when the app changes and move the date at the top. If a change materially affects what we collect or who we send it to, we will say so in the app before it takes effect.
Contact
Social Technologies

