Privacy Policy
Last updated: June 30, 2026
Data controller: Baldev Chaudhary
Contact: baldev7285@gmail.com
Address: Gandhinagar, Gujarat, India
This Privacy Policy describes how we handle personal data in connection with the Instaflax Social Feed WordPress plugin and this marketing website (instaflax.com).
---
1. Scope
This policy applies to:
- The Instaflax Social Feed plugin installed on customer WordPress sites (including the free build distributed on WordPress.org)
- This marketing website — instaflax.com
Hosted services used by the plugin and this site:
- OAuth token proxy (one.mahihub.in) — secure Instagram account connection for the WordPress plugin
- License validation API — Pro/Business purchases from instaflax.com only (not used by the free WordPress.org plugin build)
- Checkout (Razorpay) — payment processing on this marketing site
---
2. Data collected by the plugin (on customer sites)
When you install and use Instaflax Social Feed on your WordPress site, the plugin may store and process:
| Data | Purpose |
|---|---|
| Instagram OAuth access tokens (encrypted) | Fetch and display Instagram media via the Instagram Graph API; refresh long-lived tokens |
| Instagram user ID, username, profile metadata | Show profile header, link to profile, associate feeds with accounts |
| Site domain binding | Record your site domain when you confirm your website after Instagram login, so the account is linked to the correct site |
| Feed settings (layout, columns, shortcodes, display options) | Render feeds as you configure them |
| Cached Instagram media (WordPress transients) | Temporarily store post captions, media URLs, permalinks, and related metadata to reduce API calls |
| Pending OAuth session (short-lived) | Hold an encrypted token for up to 15 minutes while you confirm your website after Instagram authorization |
We do not store Instagram App Secrets in the WordPress plugin or your database. The App Secret is held only on Instaflax's OAuth proxy server.
Access tokens are encrypted with AES-256-CBC in the WordPress database using keys derived from your WordPress security salts. Tokens are not exposed in browser redirect URLs after the OAuth callback.
Pro/Business license keys: If you use a paid build purchased from instaflax.com, your license key and site URL may be sent to our license validation API. The free plugin on WordPress.org does not collect or send license keys.
Deleting plugin data:
- Disconnect an Instagram account in the plugin settings to remove that account's tokens without deleting your feeds.
- Delete the plugin from WordPress (Plugins → Delete, not just Deactivate) to remove all plugin data from your database, including encrypted tokens, connected-account records, saved feed settings, and cached Instagram media.
---
2a. Data sent outside your WordPress site (plugin)
When you connect Instagram or display a feed, your WordPress site communicates with:
Instagram / Meta (instagram.com, graph.instagram.com)
- During login: your Instagram App ID, OAuth redirect URI (your site URL), requested permissions (
instagram_business_basic), and a security state value. - After your account is connected: your long-lived access token, plus API requests for profile data (
/me), media (/me/media), and token refresh (/refresh_access_token).
Meta's use of data is governed by the Meta Privacy Policy and Instagram Terms of Use.
Instaflax OAuth proxy (https://one.mahihub.in/ig-proxy/)
Used only during account connection to exchange your Instagram authorization code for short-lived and long-lived access tokens.
The proxy receives:
- Your authorization code and redirect URI (which contains your site URL)
- Your short-lived Instagram access token (second step of the exchange)
The proxy does not receive: your feed settings, page content, or website visitor data.
Your Instagram App Secret is stored only on this proxy server, never in the plugin or your WordPress database.
License validation API (paid instaflax.com builds only)
If you activate a Pro or Business license from instaflax.com, your license key and site URL may be sent to our license server. The WordPress.org free build does not use this service.
---
2b. Your website visitors
Instaflax Social Feed displays Instagram content to visitors on your site. The plugin does not collect personal data from your website visitors for Instaflax or track visitors for advertising.
Visitors may load images or other media from Instagram/Meta servers when viewing your feed. That loading is subject to Meta's policies.
---
3. Data collected on this marketing website
- Contact form: name, email, website URL, subject, message
- Server logs: IP address, browser type, pages visited, timestamps
- Cookies: essential cookies; optional analytics if you consent (see Cookie Policy)
- Consent records: cookie preference stored in local storage
---
4. Third-party services
| Service | Role |
|---|---|
| Meta / Instagram (instagram.com, graph.instagram.com) | OAuth login; profile, media, and token refresh via Instagram Graph API after your account is connected |
| Instaflax OAuth proxy (one.mahihub.in) | Secure OAuth token exchange during Instagram connection; App Secret held on proxy only |
| Razorpay | Payment processing for Pro/Business purchases on instaflax.com |
| Hosting provider | Site delivery and logs (configure per deployment) |
| Analytics (optional) | Usage statistics if enabled and consented |
Each third party has its own privacy policy. We recommend reviewing the Meta Privacy Policy and Razorpay's privacy notice.
---
5. Purposes of processing
- Provide plugin functionality and Instagram feed display
- License enforcement and plan limits (paid instaflax.com builds only; the WordPress.org free build does not lock features by license)
- Customer support and sales communication
- Improve documentation and product experience
- Security, fraud prevention, and legal compliance
---
6. Legal bases (where GDPR applies)
- Contract: providing purchased services and support
- Legitimate interests: security, product improvement, marketing to business contacts
- Consent: non-essential cookies, marketing emails where required
---
7. Retention
- Support tickets: typically up to 24 months after resolution
- License records: duration of license plus a reasonable period for accounting and disputes
- Plugin data on your WordPress site: until you disconnect Instagram, clear cache, or delete the plugin. Cached Instagram media expires based on your feed cache settings. Pending OAuth data expires within 15 minutes if you do not complete website confirmation. Deleting the plugin removes all plugin-stored data from your database.
- OAuth proxy: connection requests are processed to complete token exchange; we do not permanently store authorization codes or access tokens on the proxy for ongoing feed operation (ongoing tokens remain on your WordPress site until you disconnect or uninstall).
---
8. Security
We use industry-standard measures including encryption at rest for OAuth tokens in the plugin, HTTPS for hosted APIs, and access controls on infrastructure. OAuth connection uses WordPress security nonces and administrator permission checks. Token exchange with Instagram is performed server-side from your WordPress installation.
No method is 100% secure. Report concerns to baldev7285@gmail.com.
---
9. International transfers
Data may be processed in India and other countries where our processors operate. Where required, we use appropriate safeguards (standard contractual clauses or equivalent).
---
10. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, or port personal data, and to object to processing. Contact baldev7285@gmail.com.
To remove Instagram data from your WordPress site:
- Disconnect the account in plugin settings, or
- Delete the plugin from the Plugins screen (full removal of all plugin data)
See also our Data Deletion Instructions page if published on this site.
You may lodge a complaint with your local supervisory authority.
---
11. Children's privacy
Our services are not directed at children under 16. We do not knowingly collect children's data.
---
12. Changes
We may update this policy. Material changes will be posted on this page with an updated "Last updated" date.
---
13. Contact
Privacy requests: baldev7285@gmail.com
Postal: Baldev Chaudhary, Gandhinagar, Gujarat, India