Privacy Policy
Last updated August 5, 2026
The short version
We collect the minimum needed to run your workspace: your account details, the content and schedules you create, the connected-account tokens you authorise, and the click and order events your store sends us for affiliate attribution. We do not sell personal data and we do not run advertising trackers on this site.
What we collect and why
| Data | Why | Kept for |
|---|---|---|
| Email and password hash | Create and secure your account, sign you in, reset your password. | Life of the account, then deleted within 30 days |
| Workspace content — brands, drafts, posts, schedules, messages | Provide the core product; publish what you ask us to publish. | Until you delete it or close the account |
| Connected platform tokens (Meta, TikTok, X, Google, LinkedIn, Pinterest, Reddit, Threads) | Publish, read metrics, and send DMs on accounts you authorise. | Until you disconnect; deleted immediately on disconnect |
| Affiliate click and conversion events (click id, referrer, coarse country, order id, order value, coupon) | Attribute sales to the right affiliate and calculate commissions. | 24 months, then aggregated |
| Contacts you capture (email, social handle, message history) | Run your own DM automations and broadcasts to people who opted in. | Until you delete the contact or the account |
| Operational logs and audit records | Security, debugging, abuse prevention, and a record of sensitive actions. | 12 months |
| Site analytics (page views, referrer) | Understand which pages are useful. No cross-site advertising profile. | 14 months |
Legal bases
Where GDPR or UK GDPR applies we rely on: performance of a contract (running your workspace), legitimate interests (security, abuse prevention, product analytics), and consent where required (for example optional marketing email). You can withdraw consent at any time.
Who processes data for us
We use a small set of processors, each under a data-processing agreement and used only for the purpose listed:
- Supabase — database, authentication, and file storage (United States).
- Cloudflare — application hosting, CDN, and DDoS protection.
- Lovable — application platform and AI gateway used for content generation.
- Meta, TikTok, X, Google/YouTube, LinkedIn, Pinterest, Reddit — only when you connect that account, and only to carry out actions you request.
- Twilio — WhatsApp and SMS delivery, where you enable it.
- SendGrid — transactional email delivery.
- PayPal — affiliate payout execution, where you enable it.
Content you send to the AI gateway for drafting is processed to return a draft and is not used by us to train models.
Your rights
You can request access to your data, correction, deletion, a portable export, or restriction of processing, and you can object to processing based on legitimate interests. Email privacy@mangobby.com and we will respond within 30 days. If you are in the EEA or UK you may also complain to your local supervisory authority. California residents have the equivalent rights to know, delete, correct, and opt out of sale or sharing — we do not sell or share personal information as those terms are defined by the CCPA.
Security
Data is encrypted in transit. Connected-platform tokens are encrypted at rest with AES-256-GCM and are never exposed to the browser. Every workspace table is protected by row-level security so one account cannot read another's data. Admin actions are gated server-side and recorded in an audit log.
Cookies
We set a session cookie so you stay signed in, and an affiliate click cookie (30 days) on stores that install our tracking snippet so a sale can be credited to the right partner. No advertising or cross-site profiling cookies are used on this site.
Children
Mangobby is not intended for anyone under 18 and we do not knowingly collect their data.
Contact
Privacy questions or requests: privacy@mangobby.com.
Mangobby