Embedra

Privacy Policy

Last updated 24 August 2026

Embedra (embedra.io) is a product of Tecbot Pty Ltd (“we”, “us”, “our”). Embedra lets you embed live, styleable widgets on your website, such as an Instagram or Facebook feed or your Google reviews. This policy explains what personal information we collect, how we use and protect it, and your rights under the Protection of Personal Information Act 4 of 2013 (POPIA).

1. About the company

Tecbot Pty Ltd
71A 10th Avenue, Edenvale, Gauteng, South Africa
VAT: 4030293841
Registration number: 2017/154167/07

2. The information we collect

We collect and process your personal information mainly to contact you for the purposes of understanding your requirements and delivering services accordingly. For this purpose we collect contact details including your name and organisation. We collect information directly from you where you provide us with your personal details. Where possible, we will inform you what information you are required to provide and what is optional. Website usage information may be collected using cookies, which allows us to collect standard internet visitor usage information.

For the Embedra service specifically, we also collect:

  • Account details: your name, email address and workspace name.
  • The Instagram account you connect: your handle and public profile, and an access token which we store in encrypted form so we can fetch your feed. We never receive or store your Instagram password.
  • Your widget settings and the list of domains you allow the widget to run on.
  • The domains your widget is served on: when a page loads your widget we record that site's hostname (for example yoursite.com), so the widget's owner and our support can see where it is in use. We never record the full page address, and nothing about the visitor is attached to it.
  • An approximate country for your account, taken from your network address when you open the dashboard. We store the two-letter country code only, for support and anti-abuse, never a precise location.
  • Public Instagram content: the posts, captions, images and public metrics of the account you connect, which we cache to display your widget.
  • The Facebook Page you connect, if you choose to: the list of Pages your Facebook account manages (shown once so you can pick one), the Page you pick, and that Page's access token, which we store in encrypted form so we can fetch its posts. We never receive or store your Facebook password.
  • Public Facebook Page content: the Page's own published posts, their images, links, timestamps and public like, comment and share counts, which we cache to display your widget. We never read your Page's private messages, visitor posts or the content of comments.
  • The Google Business Profile you connect, if you choose to: the list of business locations that Google account manages, the location you pick, and a long-lived Google refresh token which we store in encrypted form so we can keep the reviews up to date. We never receive or store your Google password.
  • Public Google review content: for the business you choose, the reviews Google publishes, including each reviewer's display name, profile photo, star rating, review text, dates and the business owner's replies. We cache these to display your widget.
  • From visitors of sites where your widget is embedded: we do not collect their name, email or profile. To count views fairly we create a one-way salted hash of the visitor's IP address (the raw IP address is never stored) that expires on a rolling 30-minute window.
  • Profile and workspace details you choose to set: a display name, your workspace's display timezone and, if you provide one for invoicing, a VAT number.
  • Sign-in records: when you sign in we record the session's browser, IP address and last-active time, for security. You can see these sessions, and end any of them, in your account under Security.
  • An audit trail of administrative actions taken on your workspace (for example who invited a member, who granted support access, or who stopped a widget), kept so that both you and we can answer who did what, and when.

3. How we use your information

We will use your personal information only for the purposes for which it was collected and agreed with you. In addition, where necessary your information may be retained for legal, research, or marketing purposes. For example: to gather contact information; to confirm and verify your identity or that you are an authorised user for security purposes; for the detection and prevention of fraud, crime, money laundering or other malpractice; to conduct market or customer satisfaction research or statistical analysis; for audit and record keeping; in connection with legal proceedings; and to contact you via email, phone-call or social media platforms.

For the Embedra service we also use your information to:

  • Fetch and display your widgets, such as your Instagram feed, Facebook Page posts or Google reviews, on the sites you choose.
  • Meter your usage against your plan, de-duplicate views, and prevent abuse.
  • Operate, secure, troubleshoot and support the service.
  • Understand how Embedra is used so we can improve it: which widget types are popular, which sites widgets run on, which accounts are connected to them, and roughly where our customers are. This analysis stays inside Embedra, informs what we build, and is never sold or shared.

4. Disclosure of information (service providers)

We may disclose your personal information to our service providers who are involved in the delivery of products or services to you, or to our internal employees. We have agreements in place to ensure they comply with the privacy requirements of POPIA. We may also disclose your information where we have a duty or a right to do so in terms of law or industry codes, or where we believe it is necessary to protect our rights.

The service providers that process personal information to run Embedra are:

  • Supabase: database and authentication (stores account data).
  • Cloudflare: our edge service and cached feed media and storage.
  • Vercel: hosts the Embedra dashboard.
  • Meta Platforms (Instagram and Facebook): the source of your feed data, accessed with your authorisation.
  • Google: optional sign-in, and, if you connect a Business Profile, the source of your reviews, accessed with your authorisation. See section 7.

Some of these providers process data in other countries. Where personal information is transferred across borders, we take steps to ensure it receives protection comparable to that required by POPIA, or that the transfer is necessary to provide the service to you. We do not sell personal information.

5. Information security

We are legally obliged to provide adequate protection for the personal information we hold and to stop unauthorised access and use of it. On an ongoing basis we review our security controls and related processes to keep your personal information secure. Our policies and procedures cover physical security; computer and network security; access to personal information; secure communications; security in outsourced activities; retention and disposal of information; acceptable usage; governance and regulatory issues; monitoring access and usage; and investigating and reacting to security incidents. When we contract with third parties we impose appropriate security, privacy and confidentiality obligations on them.

For the Embedra service specifically: all traffic is encrypted in transit (HTTPS); the tokens for every account you connect, Instagram, Facebook and Google alike, are stored encrypted at rest; access to production data is restricted; and each widget only runs on the domains its owner has registered.

Our staff cannot open your workspace to see it as you do unless an owner or admin of that workspace grants support access from the dashboard. A grant states who asked and why, is limited to a duration you choose (at most seven days), can be ended by you at any time, and every use of it is counted and recorded. The full history of these requests and grants stays visible in your account under Support access. Independent of any grant, we may act on a specific widget or account to enforce our Terms of Service; those actions are recorded with a reason.

6. Your Instagram and Facebook (Meta) data and how to delete it

We access your Instagram and Facebook Page data through Meta's APIs only with your authorisation, and only to display your feed widgets. For Facebook we read the Page's own published posts, never visitor posts, comment content or messages. You can disconnect an account at any time from the Embedra dashboard, which stops any further access.

To request deletion of the data we obtained through Instagram, Facebook or Meta, you can disconnect and delete your widget in the dashboard, or submit a request through Instagram (Settings and privacy → Apps and websites) or Facebook (Settings and privacy → Business integrations), which we honour through our data-deletion process. We provide a data-deletion status page that confirms completion with a reference code. Deleting your account removes your data and the associated cached media.

7. Your Google Business Profile data and how to delete it

Google publishes only a business's five most relevant reviews to anyone. If you own or manage the business, you can connect its Google Business Profile to show more of your own reviews in your widget. This section covers that connection. It does not apply if you only searched for a business, which uses the reviews Google already shares publicly.

What we access. With your authorisation we read the list of business locations your Google account manages, so you can confirm which one the widget is for, and the reviews of the location you pick, including each reviewer's display name, profile photo, star rating, review text, dates and your replies. Nothing else on your Google account is read.

We only ever read. Google's consent screen asks you to allow managing your business listings, because Google offers no read-only permission for reviews. Embedra never creates, edits, replies to, deletes or publishes anything on your profile, and never posts on your behalf.

Why, and only why. We use this data for one purpose: displaying your own reviews in the widget you built, on the domains you allow. We do not use it for advertising, we never sell or transfer it, and we do not use it to train generalised artificial-intelligence or machine-learning models. No person at Embedra reads it except where you ask us to help, where our Terms of Service must be enforced, or where the law requires it.

What we store. A Google refresh token, encrypted at rest, which lets us fetch reviews on your widget's refresh schedule without asking you to sign in again, and a cached snapshot of your most recent reviews capped at 50, which is what the widget serves to visitors. Reviewer profile photos may be copied to our own storage so the widget does not load images from Google on every page view.

How to disconnect and delete it. Disconnect Google Business Profile in your widget's settings at any time. That deletes the stored token, the cached reviews it fetched and any reviewer photos we copied, and the widget falls back to the five reviews Google shares publicly. You can also revoke Embedra's access directly from your Google account under Security, then Third-party apps with account access, at myaccount.google.com/permissions. Deleting the widget or your account removes the same data.

Embedra's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

8. Your rights: access to information

You have the right to request a copy of the personal information we hold about you. To do this, contact us at the address below and specify what information you require. We may need a copy of your ID document to confirm your identity before providing details of your personal information. Please note that any such access request may be subject to a payment of a legally allowable fee.

9. Correction of your information

You have the right to ask us to update, correct or delete your personal information. We may require a copy of your ID document to confirm your identity before making changes to personal information we hold about you. We would appreciate it if you would help us keep your personal information accurate.

10. How long we keep it

We keep personal information for as long as necessary to fulfil the purposes it was collected for, or as required by law. Account data is kept while your account is active and removed when you delete it; Instagram and Facebook access tokens and Google refresh tokens are removed when you disconnect or delete a widget, along with the reviews cached under that connection; salted view hashes expire on a rolling 30-minute basis, and aggregated view counts are retained in de-identified form. Sign-in session records are removed when the session ends or when you end it; the audit trail of administrative actions is retained so the history of an account remains answerable.

11. Cookies

The Embedra dashboard uses strictly necessary session cookies to keep you signed in. The embedded widget does not set tracking cookies on your visitors' devices. We do not use advertising cookies.

12. Definition of personal information

According to the Act, “personal information” means information relating to an identifiable, living, natural person, and where applicable, an identifiable, existing juristic person. Further to the POPI Act, Embedra also treats the following as personal information: all addresses, including residential, postal and email addresses; and a change of name, for which we require a copy of the marriage certificate or official change-of-name document issued by the relevant state department.

13. Complaints

If you are not satisfied with how we have handled your personal information, you may lodge a complaint with the Information Regulator (South Africa): enquiries@inforegulator.org.za or POPIAComplaints@inforegulator.org.za, tel. 010 023 5200, inforegulator.org.za.

14. How to contact us

If you have any queries about this notice, need further information about our privacy practices, wish to withdraw consent, exercise preferences, or access or correct your personal information, please contact us at support@embedra.io.

15. Changes to this policy

We may update this policy from time to time. The current version is always published on this page. Last updated: 24 August 2026.