Privacy Policy
1. Scope and identity
This Policy explains how Rosetta Ventures FZ-LLC (“Rosetta”, “we”, “us”) processes personal data through StoryBam, associated dashboards, reward-validation tools, websites and Meta/Instagram integrations (together, the “Service”). It applies to business customers, authorised operators, website visitors, connected professional Instagram accounts and individuals whose interaction with a participating business triggers a reward workflow.
Rosetta is controller for account administration, security, billing, product operation and its own compliance records. A participating business generally determines the campaign, eligibility rules, reward and use of end-user interaction data and may therefore be an independent controller for that processing. Where Rosetta processes such data solely on documented instructions, Rosetta acts as service provider or processor. Mandatory applicable law always prevails over this allocation.
2. Data we process
| Category | Examples |
|---|---|
| Account and business data | Name, business/legal name, email, phone, country/city, account ID, roles, permissions, language and timezone. |
| Meta/Instagram connection data | Professional-account identifiers, username, account-scoped identifiers, connection status, granted permissions, OAuth access token and expiry. We do not request an Instagram password. |
| Interaction and webhook data | Story-mention or messaging event identifiers, sender-scoped ID, timestamps, delivery/processing status and limited raw webhook payload needed to verify and process an event. |
| Campaign and reward data | Campaign rules, schedules, reward description, design revisions, QR/manual code, issue/expiry/redemption status, operator validation and immutable reward snapshots. |
| Temporary media | A rendered reward-card PNG used only to allow Meta/Instagram to retrieve and deliver the card. We do not intentionally store the customer’s Instagram Story photograph as a reward record. |
| Billing and commercial data | Plan, currency, payment/customer references, invoices, payment status, affiliate and commission records. Full payment-card details are handled by the payment provider, not stored in the Service database. |
| Technical and security data | Authentication/session records, request logs, error data, IP/device information made available by infrastructure providers and deletion confirmation records. |
3. Sources
Data comes from the customer or its authorised users; Meta/Instagram after an explicit professional-account authorisation; end-user interactions with a participating business; Stripe or another payment provider; and security, hosting or delivery infrastructure. We do not purchase lists of Instagram users.
4. Purposes and legal grounds
We process data to provide and secure the Service; connect a professional Instagram account; receive authorised webhook events; apply customer-configured campaign rules; generate, deliver and validate rewards; prevent duplicate claims, misuse and fraud; administer users and permissions; provide support; bill customers; comply with law and enforce agreements.
Depending on the person and jurisdiction, the legal ground is performance of a contract or pre-contract steps, legitimate interests in operating and protecting a B2B service, consent where legally required, or compliance with legal obligations. Where GDPR or equivalent law applies, interests are balanced against the individual’s rights and the individual may object as described below.
5. Rule-based processing
Reward eligibility is determined by transparent rules configured by the participating business, such as campaign dates, frequency limits, public-profile requirements or follower-only settings. For example, a Story tag or mention may need to come from a public Instagram account to be eligible. The Service does not use these rules to make decisions producing legal or comparably significant effects. A business remains responsible for its campaign rules and may review customer-support disputes.
6. Recipients and processors
Data may be disclosed only as needed to: Supabase for database, authentication, storage and server functions; Cloudflare for website delivery and security; Meta/Instagram for account connection, event delivery and messaging; Stripe or the selected payment provider for billing; professional advisers, auditors and authorities where legally required; and a successor in a lawful corporate transaction. Providers are authorised only for their contracted purpose. We do not sell personal data or rent it to data brokers.
7. International transfers
The Service is operated from the United Arab Emirates and uses providers that may process data in other countries. Where required, transfers use contractual safeguards, adequacy mechanisms or another lawful basis. No internet service can guarantee that all processing occurs in one country.
8. Retention actually applied
| Record | Normal retention |
|---|---|
| Temporary reward-card PNG | Target retention is 48 hours for newly generated cards, after which cleanup may delete the delivery image. Earlier or later removal can occur where required by operational incidents, retries or authorised deletion actions. |
| Raw Instagram webhook/event record | Held only while reasonably needed for processing, troubleshooting, security and lawful deletion handling. Records are deleted on verified Meta deletion, authorised disconnection or workspace closure, and may also be reduced through operational cleanup cycles. |
| Instagram username or sender ID attached to a reward | Removed or anonymised when required by a verified Meta deletion, authorised disconnection, workspace closure or another lawful minimisation workflow. We avoid keeping those identifiers longer than reasonably necessary for support, fraud control and disputes. |
| Reward ledger without Instagram identity | While reasonably required for validation, customer support, fraud prevention, disputes and the business account; it may be anonymised or deleted when no longer required. |
| Campaign configuration and immutable design revision | For the customer account and legitimate campaign-history period. One revision is stored per distinct configuration, not one permanent design image per reward. |
| Meta deletion request audit | 24 months, containing confirmation/status information rather than the signed request or access token. |
| Account and connection data | For the account relationship; Meta-derived identifiers and tokens are removed on a verified Meta deletion request or authorised disconnection, subject to legal exceptions. |
| Tax, invoice and accounting records | As required by applicable UAE tax law, commonly up to seven years for Corporate Tax records and longer where an audit, dispute or other rule requires it. |
Backups and provider caches may expire on separate protected cycles. When immediate physical erasure is not technically possible, data is isolated from ordinary use and removed through the applicable expiry cycle.
9. Security
We use HTTPS, authenticated sessions, role-based workspace permissions, row-level database controls, server-only service credentials, signed webhook verification, signed Meta deletion verification, restricted administrative access and separation of temporary media from permanent reward records. Access tokens are restricted to backend operations. No system is perfectly secure; users must protect credentials, limit operator permissions and report suspected compromise promptly.
10. Meta and Instagram data
Meta data is used only to provide the expressly connected functionality, maintain security, satisfy customer instructions and comply with law and Meta platform requirements. Revoking the connection stops future authorised collection but does not automatically erase records that must lawfully be retained; use the deletion process for erasure. StoryBam is an independent service and is not endorsed by, sponsored by or part of Meta or Instagram.
11. Rights and choices
Subject to applicable law, an individual may request access, correction, deletion, restriction, objection, portability, withdrawal of consent and information about recipients or transfers. Requests may be refused or limited where identity cannot reasonably be verified, another person’s rights would be affected, or retention is legally required. Contact info@storybam.com. Individuals may also complain to the competent data-protection authority.
12. Deletion, disconnection and account closure
Instructions and the Meta callback flow are described at Meta Data Deletion. A verified Meta callback or authorised Instagram disconnection removes connection tokens and identifiers, deletes Instagram event records tied to the connected business, removes temporary card images where tracked for cleanup, anonymises Instagram identifiers on reward records where applicable and disables the connection. It does not delete the StoryBam login, business workspace, independent accounting records or business-authored campaign history.
An authorised primary owner may close a business workspace. Closure immediately ends campaigns, cancels active rewards, disconnects integrations, removes operators and campaign media, isolates a minimal tax/accounting snapshot for seven years and marks the workspace for later operational purge handling. A personal login enters a recoverable deletion flow for 14 days: sessions are revoked and user memberships and preferences are removed immediately, while final removal of the authentication user occurs after the recovery window. If the person deleting their login is the sole primary owner of an active workspace, that workspace is closed automatically as part of the deletion (disconnecting Instagram, ending campaigns, cancelling active rewards and retaining the required tax snapshot); closed workspaces are not restored if the login is recovered. A workspace that has another primary owner is not closed — only that person's access is removed.
13. Cookies and local storage
The Service may use strictly necessary browser storage for authentication, language, security and active-workspace selection. Any non-essential analytics or advertising technology will be subject to the consent or notice required in the relevant jurisdiction.
14. Children
The Service is a B2B tool and is not directed to children. Businesses must not configure campaigns that unlawfully target minors or promote age-restricted goods without legally sufficient age controls.
15. Changes
We may update this Policy to reflect legal, provider or product changes. The effective date will be revised and material changes will be notified where required. A change does not retrospectively authorise materially different processing without an appropriate legal basis.