Last updated 14 September 2026
Privacy policy for Facebook, Instagram, Threads and WhatsApp
What Zapket receives from Meta when an agency connects a Facebook Page, an Instagram account or a Threads profile, or sends approvals on WhatsApp, what we do with it, and how to remove it.
Who we are
Zapket is a tool that social media agencies use to plan, approve and publish posts for their clients. Asket Studio runs Zapket and is responsible for the data described here. You can reach us at help@asketstudio.in.
This page covers data from Meta's platforms. It adds to our main privacy policy, which covers everything else.
Who this covers
- People who connect a Facebook Page, an Instagram professional account or a Threads profile to Zapket, usually an agency's team or the business that owns the account.
- People who comment on or send a message to those accounts, whose comments and messages Zapket shows to the agency.
- Clients who receive approval requests from their agency on WhatsApp.
What we receive from Meta
Only what the person connecting the account agrees to on Meta's own permission screen, and only for the accounts they choose:
- Who connected: the Facebook user ID and name that Facebook Login provides, so we know which person gave access.
- Facebook Pages: each chosen Page's name, ID and profile picture; the posts Zapket publishes; comments and replies on those posts; Messenger conversations with the Page; and Page results such as reach and engagement.
- Instagram professional accounts: the account's name, username and profile picture; the posts Zapket publishes; comments and direct messages; and account and post results.
- Threads: the profile's name, username and picture; the posts Zapket publishes; replies to them; and post results.
- Boosted posts: only when an agency chooses to boost a post, the ad account, budget, audience settings and results of that promotion.
- People who comment or message: the public name, username and profile picture Meta shares with the account owner, and the text and attachments of their comment or message.
- WhatsApp: the client's WhatsApp number (entered by their agency), the approval messages we send, and the button the client taps or the reply they type.
- Access keys: the tokens Meta issues so Zapket can act for the account. They are stored encrypted.
We don't receive Facebook or Instagram passwords, and we don't ask for access to anyone's personal profile, friends or private posts.
How we use it
Only to provide the features the agency uses in Zapket:
- Publishing and scheduling the posts the agency prepares and the client approves.
- Showing comments and messages in the agency's inbox, and sending the replies a team member writes.
- Showing results in the agency's analytics and in each client's monthly report.
- Sending approval requests on WhatsApp and recording the client's answer.
- Keeping connections working and telling the agency when one needs attention.
We never sell data from Meta, never use it for advertising or to build profiles of people, and never share it with data brokers. We don't use it to train AI models. If an agency turns on AI writing help, only the text a team member chooses to send is shared with that service.
Who can see it
Only the agency that connected the account, and the client's own logins where the agency gives them access. Each agency can only ever see its own clients. We share data only with the providers Zapket needs to run, such as hosting and email, each bound to keep it confidential, and with authorities when the law requires it.
How we protect it
All connections to Zapket and to Meta are encrypted. Access keys are stored encrypted and are never shown to anyone, including the agency. Team members can protect their sign-in with a code from an authenticator app.
How long we keep it
- Access keys: until the account is disconnected in Zapket, when we delete them straight away. If access is removed in Facebook or Instagram, the keys stop working at once.
- Posts, comments, messages and results: while the agency keeps that client in Zapket. When the agency deletes the client, or anyone asks us to delete their data, we delete it within 30 days.
Removing access and deleting your data
- In Zapket, an agency admin or manager can open the client, go to Accounts and choose Disconnect.
- On Facebook, open Settings and privacy, then Settings, then Business integrations, find Zapket and choose Remove.
- On Instagram, open Settings, then Website permissions or Apps and websites, find Zapket and choose Remove.
- To have your data deleted, including a comment or message you sent to an account managed in Zapket, email help@asketstudio.in. We confirm within 30 days.
The same steps are on our data deletion instructions page.
Your rights
Under India's Digital Personal Data Protection Act, 2023, you can ask to see the personal data we hold about you, correct it or delete it, and withdraw your consent. Write to help@asketstudio.in. If you have a concern, our grievance officer answers at the same address within 7 days, and you can also complain to the Data Protection Board of India.
Changes
If we change how we use data from Meta, we'll update this page and tell agency admins by email before the change applies.