Embedra

Privacy Policy

Last updated 21 July 2026

Embedra (embedra.io) is a product of Tecbot Pty Ltd (“we”, “us”, “our”). Embedra lets you embed a live, styleable Instagram feed on your website. This policy explains what personal information we collect, how we use and protect it, and your rights under the Protection of Personal Information Act 4 of 2013 (POPIA).

1. About the company

Tecbot Pty Ltd
71A 10th Avenue, Edenvale, Gauteng, South Africa
VAT: 4030293841
Registration number: 2017/154167/07

2. The information we collect

We collect and process your personal information mainly to contact you for the purposes of understanding your requirements and delivering services accordingly. For this purpose we collect contact details including your name and organisation. We collect information directly from you where you provide us with your personal details. Where possible, we will inform you what information you are required to provide and what is optional. Website usage information may be collected using cookies, which allows us to collect standard internet visitor usage information.

For the Embedra service specifically, we also collect:

  • Account details: your name, email address and workspace name.
  • The Instagram account you connect: your handle and public profile, and an access token which we store in encrypted form so we can fetch your feed. We never receive or store your Instagram password.
  • Your widget settings and the list of domains you allow the widget to run on.
  • Public Instagram content: the posts, captions, images and public metrics of the account you connect, which we cache to display your widget.
  • From visitors of sites where your widget is embedded: we do not collect their name, email or profile. To count views fairly we create a one-way salted hash of the visitor's IP address (the raw IP address is never stored) that expires on a rolling 30-minute window.

3. How we use your information

We will use your personal information only for the purposes for which it was collected and agreed with you. In addition, where necessary your information may be retained for legal, research, or marketing purposes. For example: to gather contact information; to confirm and verify your identity or that you are an authorised user for security purposes; for the detection and prevention of fraud, crime, money laundering or other malpractice; to conduct market or customer satisfaction research or statistical analysis; for audit and record keeping; in connection with legal proceedings; and to contact you via email, phone-call or social media platforms.

For the Embedra service we also use your information to:

  • Fetch and display your Instagram feed widget on the sites you choose.
  • Meter your usage against your plan, de-duplicate views, and prevent abuse.
  • Operate, secure, troubleshoot and support the service.

4. Disclosure of information (service providers)

We may disclose your personal information to our service providers who are involved in the delivery of products or services to you, or to our internal employees. We have agreements in place to ensure they comply with the privacy requirements of POPIA. We may also disclose your information where we have a duty or a right to do so in terms of law or industry codes, or where we believe it is necessary to protect our rights.

The service providers that process personal information to run Embedra are:

  • Supabase: database and authentication (stores account data).
  • Cloudflare: our edge service and cached feed media and storage.
  • Vercel: hosts the Embedra dashboard.
  • Meta Platforms / Instagram: the source of your feed data, accessed with your authorisation.
  • Google: optional sign-in, only if you choose it.

Some of these providers process data in other countries. Where personal information is transferred across borders, we take steps to ensure it receives protection comparable to that required by POPIA, or that the transfer is necessary to provide the service to you. We do not sell personal information.

5. Information security

We are legally obliged to provide adequate protection for the personal information we hold and to stop unauthorised access and use of it. On an ongoing basis we review our security controls and related processes to keep your personal information secure. Our policies and procedures cover physical security; computer and network security; access to personal information; secure communications; security in outsourced activities; retention and disposal of information; acceptable usage; governance and regulatory issues; monitoring access and usage; and investigating and reacting to security incidents. When we contract with third parties we impose appropriate security, privacy and confidentiality obligations on them.

For the Embedra service specifically: all traffic is encrypted in transit (HTTPS); Instagram access tokens are stored encrypted at rest; access to production data is restricted; and each widget only runs on the domains its owner has registered.

6. Your Instagram (Meta) data and how to delete it

We access your Instagram data through Instagram's API only with your authorisation, and only to display your feed widget. You can disconnect your Instagram account at any time from the Embedra dashboard, which stops any further access.

To request deletion of the data we obtained through Instagram or Meta, you can disconnect and delete your widget in the dashboard, or submit a request through Instagram (Settings and privacy → Apps and websites), which we honour through our data-deletion process. We provide a data-deletion status page that confirms completion with a reference code. Deleting your account removes your data and the associated cached media.

7. Your rights: access to information

You have the right to request a copy of the personal information we hold about you. To do this, contact us at the address below and specify what information you require. We may need a copy of your ID document to confirm your identity before providing details of your personal information. Please note that any such access request may be subject to a payment of a legally allowable fee.

8. Correction of your information

You have the right to ask us to update, correct or delete your personal information. We may require a copy of your ID document to confirm your identity before making changes to personal information we hold about you. We would appreciate it if you would help us keep your personal information accurate.

9. How long we keep it

We keep personal information for as long as necessary to fulfil the purposes it was collected for, or as required by law. Account data is kept while your account is active and removed when you delete it; Instagram access tokens are removed when you disconnect or delete a widget; salted view hashes expire on a rolling 30-minute basis, and aggregated view counts are retained in de-identified form.

10. Cookies

The Embedra dashboard uses strictly necessary session cookies to keep you signed in. The embedded widget does not set tracking cookies on your visitors' devices. We do not use advertising cookies.

11. Definition of personal information

According to the Act, “personal information” means information relating to an identifiable, living, natural person, and where applicable, an identifiable, existing juristic person. Further to the POPI Act, Embedra also treats the following as personal information: all addresses, including residential, postal and email addresses; and a change of name, for which we require a copy of the marriage certificate or official change-of-name document issued by the relevant state department.

12. Complaints

If you are not satisfied with how we have handled your personal information, you may lodge a complaint with the Information Regulator (South Africa): enquiries@inforegulator.org.za or POPIAComplaints@inforegulator.org.za, tel. 010 023 5200, inforegulator.org.za.

13. How to contact us

If you have any queries about this notice, need further information about our privacy practices, wish to withdraw consent, exercise preferences, or access or correct your personal information, please contact us at support@embedra.io.

14. Changes to this policy

We may update this policy from time to time. The current version is always published on this page. Last updated: 21 July 2026.