Privacy policy
This explains exactly what BackSoon stores about you and your business, what we access on Facebook and Instagram, and what you can ask us to do with it.
Last updated: 2026-08-11
Who is responsible for your data
The controller of your personal data is Melrox BV, trading as Melrox, Maldersesteenweg 11, 1840 Londerzeel, Belgium. Company number (KBO/BCE): BE 0759.572.158.
For any privacy question you can email yannick@melrox.be. For anything else about the service, email yannick@melrox.be.
Account data
When you sign up with Google we receive and store:
- your email address and your name as they appear on your Google account;
- the business details you type in yourself: business name, address or city, language, website address, and your public page link if you enter one.
We use this to create your account, show it to you, and contact you about the service.
Facebook data we access and why
When you press "Connect Facebook" we ask Facebook for permission to see the list of Facebook Pages you manage. We show you that list so you can pick which Page BackSoon should post to.
- List of Pages you manage — only so you can choose the right one. We do not keep the Pages you did not select beyond that choice.
- Selected Page name and Page ID — stored, so we know where to publish your holiday announcement and so you can see which Page is connected.
Instagram data we access and why
Instagram publishing works through the Instagram business account linked to your Facebook Page. When you connect Instagram we read and store:
- the Instagram business account ID linked to your selected Page;
- its username and display name, so you can confirm the right account is connected.
Publishing on your behalf
We publish holiday announcements to your Facebook Page and Instagram account only when you instruct us to, by pressing publish for a specific holiday period. When a post succeeds we store the ID of the created post so we can show you what was published and link to it.
We never read your private messages, your followers' personal data, your inbox, or your ad data. We do not post anything you have not asked us to post.
Access tokens
To publish, Facebook gives us an access token for your account and your Page. We store these tokens encrypted, on our server only. They are never sent to your browser and never shared with anyone else. They are used for one thing: publishing the content you asked us to publish.
When you disconnect a channel, the stored tokens for that channel are deleted.
Content you create
We store your holiday periods (dates, reopening date, language, and the announcement text) and the announcement card images generated from them. Card images are stored so the Instagram API can fetch them at publish time, which means the image file is reachable by the platform via a link while the holiday exists.
Payments
Payments are handled by our payment provider, Stripe. Your card details are entered on their side — we never see or store them. We keep a record of what you paid for, when, and the payment reference, which we need for accounting and to unlock the publish you paid for.
Who else processes your data
We use a small number of providers, each for a specific purpose:
- Hosting, database and file storage provider — runs the application and stores your account, holidays and card images.
- Meta (Facebook and Instagram) — the destination platform. Content you publish, and the connection itself, is processed by Meta under their own terms.
- Stripe — processes payments.
We do not sell your data and we do not use it for advertising.
Why we are allowed to do this (lawful bases)
- Performance of a contract — running your account, storing your holiday dates, publishing what you asked for, and taking payment.
- Your consent — connecting your Facebook Page and Instagram account. Connecting is optional and you can withdraw it at any time by disconnecting the channel.
- Legal obligation — keeping payment and invoicing records for the period Belgian law requires.
How long we keep things
- Account and business details: while your account exists.
- Access tokens: until you disconnect the channel or delete your account, then deleted.
- Holiday periods, publish logs and card images: while your account exists.
- Payment records: kept as long as accounting law requires, even after account deletion.
After deletion, copies may still exist in encrypted backups for a short rolling period before those backups expire.
Your rights
Under the GDPR you can ask us to:
- give you a copy of the data we hold about you (access);
- correct anything that is wrong (rectification);
- delete your data (erasure);
- pause our use of it while a dispute is sorted out (restriction);
- send it to you or another provider in a portable format (portability);
- stop a particular use (objection);
- withdraw a consent you gave, such as a platform connection.
Email yannick@melrox.be and we will respond within one month. See also the data deletion page for the fastest way to remove things yourself.
Complaints
If you think we handled your data badly, you can complain to the Belgian Data Protection Authority — Gegevensbeschermingsautoriteit / Autorité de protection des données, Drukpersstraat 35, 1000 Brussels, dataprotectionauthority.be.
Transfers outside the EEA
Meta and our hosting provider are able to process data outside the European Economic Area, including in the United States. Those transfers rely on the safeguards those providers put in place, such as the European Commission's standard contractual clauses and, where applicable, the EU–US Data Privacy Framework. If you connect a Meta platform, data necessary for that connection leaves the EEA.
Changes
If we change this policy we update the "last updated" date at the top and, for anything significant, tell you by email.
This document was drafted as a starting point and reviewed by the operator of this service, not by legal counsel.
BackSoon