Last updated 24 August 2026
Embedra (embedra.io) is a product of Tecbot Pty Ltd (“we”, “us”, “our”). Embedra lets you embed live, styleable widgets on your website, such as an Instagram or Facebook feed or your Google reviews. This policy explains what personal information we collect, how we use and protect it, and your rights under the Protection of Personal Information Act 4 of 2013 (POPIA).
We collect and process your personal information mainly to contact you for the purposes of understanding your requirements and delivering services accordingly. For this purpose we collect contact details including your name and organisation. We collect information directly from you where you provide us with your personal details. Where possible, we will inform you what information you are required to provide and what is optional. Website usage information may be collected using cookies, which allows us to collect standard internet visitor usage information.
For the Embedra service specifically, we also collect:
We will use your personal information only for the purposes for which it was collected and agreed with you. In addition, where necessary your information may be retained for legal, research, or marketing purposes. For example: to gather contact information; to confirm and verify your identity or that you are an authorised user for security purposes; for the detection and prevention of fraud, crime, money laundering or other malpractice; to conduct market or customer satisfaction research or statistical analysis; for audit and record keeping; in connection with legal proceedings; and to contact you via email, phone-call or social media platforms.
For the Embedra service we also use your information to:
We may disclose your personal information to our service providers who are involved in the delivery of products or services to you, or to our internal employees. We have agreements in place to ensure they comply with the privacy requirements of POPIA. We may also disclose your information where we have a duty or a right to do so in terms of law or industry codes, or where we believe it is necessary to protect our rights.
The service providers that process personal information to run Embedra are:
Some of these providers process data in other countries. Where personal information is transferred across borders, we take steps to ensure it receives protection comparable to that required by POPIA, or that the transfer is necessary to provide the service to you. We do not sell personal information.
We are legally obliged to provide adequate protection for the personal information we hold and to stop unauthorised access and use of it. On an ongoing basis we review our security controls and related processes to keep your personal information secure. Our policies and procedures cover physical security; computer and network security; access to personal information; secure communications; security in outsourced activities; retention and disposal of information; acceptable usage; governance and regulatory issues; monitoring access and usage; and investigating and reacting to security incidents. When we contract with third parties we impose appropriate security, privacy and confidentiality obligations on them.
For the Embedra service specifically: all traffic is encrypted in transit (HTTPS); the tokens for every account you connect, Instagram, Facebook and Google alike, are stored encrypted at rest; access to production data is restricted; and each widget only runs on the domains its owner has registered.
Our staff cannot open your workspace to see it as you do unless an owner or admin of that workspace grants support access from the dashboard. A grant states who asked and why, is limited to a duration you choose (at most seven days), can be ended by you at any time, and every use of it is counted and recorded. The full history of these requests and grants stays visible in your account under Support access. Independent of any grant, we may act on a specific widget or account to enforce our Terms of Service; those actions are recorded with a reason.
We access your Instagram and Facebook Page data through Meta's APIs only with your authorisation, and only to display your feed widgets. For Facebook we read the Page's own published posts, never visitor posts, comment content or messages. You can disconnect an account at any time from the Embedra dashboard, which stops any further access.
To request deletion of the data we obtained through Instagram, Facebook or Meta, you can disconnect and delete your widget in the dashboard, or submit a request through Instagram (Settings and privacy → Apps and websites) or Facebook (Settings and privacy → Business integrations), which we honour through our data-deletion process. We provide a data-deletion status page that confirms completion with a reference code. Deleting your account removes your data and the associated cached media.
Google publishes only a business's five most relevant reviews to anyone. If you own or manage the business, you can connect its Google Business Profile to show more of your own reviews in your widget. This section covers that connection. It does not apply if you only searched for a business, which uses the reviews Google already shares publicly.
What we access. With your authorisation we read the list of business locations your Google account manages, so you can confirm which one the widget is for, and the reviews of the location you pick, including each reviewer's display name, profile photo, star rating, review text, dates and your replies. Nothing else on your Google account is read.
We only ever read. Google's consent screen asks you to allow managing your business listings, because Google offers no read-only permission for reviews. Embedra never creates, edits, replies to, deletes or publishes anything on your profile, and never posts on your behalf.
Why, and only why. We use this data for one purpose: displaying your own reviews in the widget you built, on the domains you allow. We do not use it for advertising, we never sell or transfer it, and we do not use it to train generalised artificial-intelligence or machine-learning models. No person at Embedra reads it except where you ask us to help, where our Terms of Service must be enforced, or where the law requires it.
What we store. A Google refresh token, encrypted at rest, which lets us fetch reviews on your widget's refresh schedule without asking you to sign in again, and a cached snapshot of your most recent reviews capped at 50, which is what the widget serves to visitors. Reviewer profile photos may be copied to our own storage so the widget does not load images from Google on every page view.
How to disconnect and delete it. Disconnect Google Business Profile in your widget's settings at any time. That deletes the stored token, the cached reviews it fetched and any reviewer photos we copied, and the widget falls back to the five reviews Google shares publicly. You can also revoke Embedra's access directly from your Google account under Security, then Third-party apps with account access, at myaccount.google.com/permissions. Deleting the widget or your account removes the same data.
Embedra's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You have the right to request a copy of the personal information we hold about you. To do this, contact us at the address below and specify what information you require. We may need a copy of your ID document to confirm your identity before providing details of your personal information. Please note that any such access request may be subject to a payment of a legally allowable fee.
You have the right to ask us to update, correct or delete your personal information. We may require a copy of your ID document to confirm your identity before making changes to personal information we hold about you. We would appreciate it if you would help us keep your personal information accurate.
We keep personal information for as long as necessary to fulfil the purposes it was collected for, or as required by law. Account data is kept while your account is active and removed when you delete it; Instagram and Facebook access tokens and Google refresh tokens are removed when you disconnect or delete a widget, along with the reviews cached under that connection; salted view hashes expire on a rolling 30-minute basis, and aggregated view counts are retained in de-identified form. Sign-in session records are removed when the session ends or when you end it; the audit trail of administrative actions is retained so the history of an account remains answerable.
The Embedra dashboard uses strictly necessary session cookies to keep you signed in. The embedded widget does not set tracking cookies on your visitors' devices. We do not use advertising cookies.
According to the Act, “personal information” means information relating to an identifiable, living, natural person, and where applicable, an identifiable, existing juristic person. Further to the POPI Act, Embedra also treats the following as personal information: all addresses, including residential, postal and email addresses; and a change of name, for which we require a copy of the marriage certificate or official change-of-name document issued by the relevant state department.
If you are not satisfied with how we have handled your personal information, you may lodge a complaint with the Information Regulator (South Africa): enquiries@inforegulator.org.za or POPIAComplaints@inforegulator.org.za, tel. 010 023 5200, inforegulator.org.za.
If you have any queries about this notice, need further information about our privacy practices, wish to withdraw consent, exercise preferences, or access or correct your personal information, please contact us at support@embedra.io.
We may update this policy from time to time. The current version is always published on this page. Last updated: 24 August 2026.