Privacy policy — URL to IRL
Updated 7 September 2026. This policy covers the Instagram connection and automation service operated by LUCAS VERRA EURL.
Operator and contact
LUCAS VERRA EURL, SIREN 921 979 472, 1 rue de Stockholm, 75008 Paris, France. Contact lucas@verra.com.ar.
EURL handles service enquiries, account administration and security for its own purposes. When running a client's campaign on documented instructions, EURL acts as a service provider for that campaign. The campaign organiser determines its campaign purposes and must identify itself and explain its data use. The applicable agreement determines the parties' responsibilities; they are not automatically the same for every campaign. POAP Studio is a separate company to which EURL provides services, not the operator of this app.
Instagram data and its use
- Connected professional accounts: Instagram account ID, username, account type, granted permissions, access token and expiry, connection and disconnection dates. These identify the authorised account and enable server-side requests. We do not receive your Instagram password.
- People interacting with an account: Instagram-scoped participant identifiers, usernames when supplied, message or comment content, event identifiers and timestamps, and supported Story-interaction information. We use these to route the interaction and send configured replies.
- Conversation state: selected buttons or quick replies, pending conversation steps and information voluntarily supplied to a configured flow. This allows the requested conversation to continue.
- Optional campaign features: a flow may request an email or link to a separate registration or collectible experience. These are not required merely to connect Instagram. The organiser must explain any additional collection before requesting it.
- Technical requests and deletion records: delivery/security logs and deletion request identifiers help operate the service and handle rights requests.
Purposes and legal bases
EURL uses business-contact and account-administration data to provide requested services and manage contractual or pre-contractual relationships, and technical data for its legitimate interests in secure operation and troubleshooting. Where EURL acts on a campaign organiser's instructions, the organiser must establish and disclose the applicable legal basis. Granting an Instagram permission is technical authorisation; it does not by itself establish the legal basis for every campaign use. Campaign messages can contain automated, rule-based responses.
Recipients
The service uses Vercel for application hosting and Supabase for database storage. The public website also uses Cloudflare for routing and Bunny Fonts for fonts. Meta processes Instagram activity under its own terms. Authorised operators and providers may access data needed for their tasks. A configured campaign integration can transmit selected information to another service; the organiser must identify that recipient and purpose in the campaign's disclosures. Contact us for details relevant to your campaign, including processing locations and any applicable international-transfer safeguards.
Retention and disconnection
Account credentials support the authorised connection. When the app receives a valid deauthorisation callback, it clears the stored access token and marks the account disconnected. A daily database cleanup removes stored Instagram event records older than 90 days and Instagram conversation records, including stored fields and pending replies, after 270 days without inbound interaction. For conversations with no recorded inbound interaction, the first-seen date is used. Cleanup occurs on the next daily run after the threshold. This cleanup does not delete campaign artwork, collectible claims, or separate campaign and marketing records; those require their own purpose-specific retention arrangements. Backup copies and external services have separate retention arrangements; we do not promise their immediate erasure. Contact us to request deletion or clarification.
Your rights and deletion
You may request access, correction, erasure, restriction, portability or object where applicable, and withdraw consent where a use relies on consent. Email lucas@verra.com.ar, identifying the account or campaign involved. Do not send passwords or access tokens. We will assess the request and respond within one month; if a lawful extension is necessary, we will explain it. Where a client is responsible for the campaign, we will help route the request appropriately. You may lodge a complaint with the CNIL.
See data deletion instructions for the distinction between removing access and deleting stored data. A campaign website, third-party service or public blockchain may hold separate records that cannot be erased by removing the Instagram connection.
Security and essential storage
The connection uses server-side token exchange and an essential state cookie to check the authorisation response. A session cookie displays the connected username. Incoming webhook signatures are checked before processing. These controls do not constitute a guarantee against every security risk. This policy makes no claim of application-layer token encryption, a certified security audit or review by POAP Studio's counsel.