DocumentationPrivacy Policy

Privacy Policy

Effective date: [To be confirmed before launch]
Last updated: [To be confirmed before launch]

Draft. Requires review by qualified legal counsel before production launch.

1. Who we are

Directlee ("we", "us") provides a messaging automation and CRM platform for Instagram, Messenger, TikTok, and related channels.

Data controller (account & platform operations):
[PLACEHOLDER: Legal entity name and address]
Contact: contact@directlee.app
[PLACEHOLDER: EU/PL Data Protection Officer if applicable]

This Policy explains how we collect and use personal data when you visit our website, register, or use the Services.

2. Two roles: Directlee and our customers

RoleWhoExamples
ControllerDirectleeyour account email, billing, support, product analytics, marketing to you (with consent where required)
ProcessorDirectlee on your instructionsleads, DMs, comments, tags, and CRM notes in your workspace
Separate controllerMeta, TikTok, Stripe, Brevo (when you connect them)governed by their policies

When you message End Users through Directlee, you are typically the controller of their personal data. Our DPA governs our processing on your behalf.

3. How we collect data

  • Registration and onboarding: email, name, workspace name, terms acceptance (acceptedTermsAt), optional newsletter consent.
  • Social login connections: platform user IDs, usernames, profile metadata, and connection credentials (not your social passwords).
  • Webhooks and APIs: messages, comments, and events from connected platforms stored in your workspace.
  • Landing pages: emails and form data submitted by visitors to your /lp/[slug] pages.
  • Billing: payment metadata via Stripe (we do not store full card numbers).
  • Usage and security: logs, IP addresses, device/browser data, error reports.
  • Push notifications (optional): browser push subscription endpoints if you enable Web Push.
  • Cookies and local storage: see Cookies Policy.

4. What data we process

4.1 Customer account data

Name, email, password hash (if email/password login), locale, plan, workspace membership, consent timestamps, affiliate/referral codes where applicable.

4.2 Workspace / product data

Leads (usernames, platform IDs, email, phone, tags, notes, message history), automations, flows, broadcasts, activity logs, uploaded media (stored on Cloudflare R2 as WebP where applicable), team invitations.

4.3 Platform tokens

Encrypted OAuth tokens for Instagram, Facebook/Messenger, TikTok, and related integrations (see SECURITY-AUDIT.md in internal docs: AES-256-GCM at rest in production when ENCRYPTION_KEY is set).

5. Purposes and legal bases (EEA/UK)

PurposeLegal basis (typical)
Provide the Services (contract)Performance of contract
Billing and fraud preventionContract; legitimate interest
Security and abuse preventionLegitimate interest
Product improvement (aggregated)Legitimate interest
Marketing email to customersConsent where required
Compliance with lawLegal obligation

We process End User data on your documented instructions as processor (Art. 28 GDPR via DPA).

6. Sharing and subprocessors

We do not sell personal data. We share data with:

  • Infrastructure providers (hosting, database, optional Redis cache)
  • Cloudflare R2 (media storage)
  • Stripe (payments)
  • Brevo (transactional email: team invites, platform email; optional customer-initiated list sync)
  • Meta / TikTok (when you connect accounts; you instruct message delivery)

Current subprocessors: Subprocessors list.

We may disclose data if required by law or to protect rights, safety, and security.

7. International transfers

[PLACEHOLDER: Describe hosting region and transfer mechanisms, e.g. EU hosting, SCCs for US subprocessors such as Stripe/Meta.]

8. Retention

  • Account data: while your account is active and as needed for legal, tax, and dispute resolution.
  • Workspace data: until you delete content, workspace, or account, subject to backup retention (limited period).
  • Logs: rotated per operational policy.
  • Backups: may retain deleted data for a limited time before purge.

9. Your rights

Depending on your location, you may have the right to access, rectify, erase, restrict, port, or object to processing, and to withdraw consent. You may lodge a complaint with a supervisory authority.

Customers: use in-app Settings or contact contact@directlee.app.
End Users: contact the Directlee customer (brand) that collected their data; we assist customers via DPA.

10. Security

We use technical and organizational measures including TLS for database connections (where configured), encrypted storage of platform tokens, access controls, and workspace-scoped data isolation. No method of transmission is 100% secure.

11. Children

The Services are not directed at children under 16 (or local minimum age). We do not knowingly collect children's data.

12. Changes

We will update this Policy with a new effective date. Material changes will be communicated where required by law.

13. Contact

contact@directlee.app
[PLACEHOLDER: postal address, DPO contact]

Privacy Policy | Directlee