NaniVani Privacy Policy
This policy explains what personal data the NaniVani Instagram service processes. NaniVani is operated by Business Together Limited (company number 9593738), trading as BTLITC (“we”, “us”), registered in England and Wales, registered office Oak House, Central Park, Reeds Crescent, Watford, WD24 4QN. We are the data controller. Contact: support@btlitc.co.uk.
What the service does
NaniVani connects, using Instagram API with Instagram Login, to one Instagram professional account that we own and operate: @itsnanivani. It publishes content that we create to that account and reads that account’s own performance insights. It is not offered to other businesses or the public, has no user accounts, and does not read messages or comments or collect data about other Instagram users.
Permissions we use
instagram_business_basic– identify the connected account and its media.instagram_business_content_publish– publish content we create to the connected account.instagram_business_manage_insights– read insights (for example reach, views, saves and shares) for the connected account and its posts.
Data we process
- Access token and account identifier for the connected account, issued by Instagram when we authorise. The token is kept in a file readable only by the service’s system account. It is never written to our logs.
- Token details: the permission names granted, issue and expiry dates, and a short non-reversible fingerprint used to recognise the token.
- Publishing records: captions and media links we write, publish status, and the Instagram media ID of each post.
- Insight snapshots for the connected account and its posts.
- Deletion request records: confirmation code, the Instagram user ID the request concerned, time and outcome.
- Technical logs: when you visit these pages or our service endpoints, our web server records your IP address, the time, the page requested and your browser’s user-agent. Application event logs record event names and non-secret identifiers; secrets, tokens and authorisation codes are redacted.
How long we keep it
- Access token: until it expires (about 60 days unless refreshed), the connection is removed, or a deletion request is processed.
- Insight snapshots and publishing records: we do not currently apply an automatic expiry. Insight snapshots are deleted when a deletion request is processed; publishing records (content we ourselves published) are kept.
- Web server logs: 14 days. Application event logs: 7 days.
- We do not keep separate backups of the token or the service database.
Who receives data
Instagram / Meta Platforms, because the service uses the Instagram API, and the hosting provider of the server that runs the service. We do not sell this data and do not use it for advertising or profiling.
Your rights and how to delete data
You can disconnect NaniVani at any time in Instagram under Settings → Apps and websites. See our Data Deletion page for how to have data removed. Your UK GDPR rights (access, correction, erasure, restriction, objection) and the right to complain to the Information Commissioner’s Office are described in the BTLITC Privacy Policy, which also applies. Contact support@btlitc.co.uk.
Changes
We will update this page and its date if the service changes how it uses data.