Orlin

Privacy Policy

Orlin — operated by MUAWI Technologies LLP

Last updated: [DD Month YYYY] Effective date: [DD Month YYYY]


1. Introduction

MUAWI Technologies LLP ("MUAWI", "we", "us", "our") is a limited liability partnership incorporated in India under the Limited Liability Partnership Act, 2008, with LLPIN [LLPIN] and registered office at [REGISTERED_ADDRESS].

We operate Orlin (the "Service"), a software platform available at https://orlin.social and https://app.orlin.social that helps businesses and creators:

  • automate replies to Instagram Direct Messages, comments, and story replies;
  • route conversations to a human agent when needed;
  • publish and manage a link-in-bio landing page.

This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and the rights you have over it. It applies to everyone who interacts with Orlin, including:

  • Customers — businesses and individuals who create an Orlin account and connect an Instagram account;
  • End Users — people who message, comment on, or reply to a story of a Customer's connected Instagram account and whose messages are handled by Orlin;
  • Visitors — people who browse https://orlin.social or view a Customer's Orlin link-in-bio page.

Please read Section 6 (Meta Platform Data) and Section 12 (Deleting your data) carefully — these describe how we handle data received from Instagram and Meta.


2. Our role: who is responsible for your data

DataOur roleCustomer's role
Customer account data (your name, email, billing)Data Fiduciary / ControllerData Principal / Data Subject
End User messages and profile data received from InstagramData Processor, acting on the Customer's instructionsData Fiduciary / Controller
Link-in-bio visitor analyticsJoint — we as Processor for page-level analytics; the Customer determines what the page containsData Fiduciary / Controller of their page
Website visitor data on https://orlin.socialData Fiduciary / Controller

Under India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), "Data Fiduciary" and "Data Processor" carry the meanings given in that Act. Under the EU/UK GDPR, "Controller" and "Processor" carry the meanings given in Article 4.

Where we act as a Processor, the Customer is responsible for having a lawful basis to process End User data and for providing notice to their own audience. Our processing is governed by the Data Processing Addendum available at https://orlin.social/dpa.


3. Information we collect

3.1 Information you give us directly

CategoryExamplesWhy we need it
Account identityName, email address, password hash, profile photo, business name, countryCreate and secure your account
Contact and supportMessages you send to support, attachments, call notesRespond to you, keep a support record
BillingBilling name, address, GSTIN, invoice history, subscription plan, last four digits and card brandTake payment, issue tax invoices, meet accounting law
ConfigurationAutomation rules, keyword triggers, message templates, flow logic, link-in-bio content you publishOperate the features you set up

We do not store full payment card numbers, CVV, or UPI credentials. Card and UPI details are collected and stored by our payment processor [e.g. Razorpay / Stripe] on PCI-DSS-compliant infrastructure. We receive only a token and a transaction result.

3.2 Information we receive from Meta / Instagram

When you connect an Instagram Professional account, you complete Meta's OAuth flow and grant Orlin a set of permissions. Meta shows you every permission before you approve it, and you choose which to grant. We request only the permissions listed below and only use the resulting data for the stated purpose.

Meta permissionData we receiveWhat we use it forStored?
instagram_business_basicInstagram user ID, username, account type, profile picture URL, follower count, media countIdentify the connected account in your dashboard; confirm the account is a Professional accountYes — account identifiers and username. Metrics refreshed, not archived.
instagram_business_manage_messagesDirect message content sent to and from your account, sender's Instagram-scoped ID (IGSID), sender's username and profile picture, message timestamps, attachments, reactionsTrigger and deliver your automations; show you the conversation; hand off to a human agentYes — see retention in Section 9
instagram_business_manage_commentsComments on your posts and reels, commenter IGSID and username, comment text and timestampsFire comment-to-DM automations and auto-repliesYes — comment ID and trigger record; comment text retained per Section 9
instagram_business_content_publish (only if you enable publishing)Media you choose to publish through OrlinPublish the content you asked us to publishMedia not retained after successful publish
pages_show_list, business_management (where required by Meta's flow)List of Pages/business assets linked to your accountLet you select the correct account to connect; complete the connectionOnly the selected asset ID

We also store the access token issued by Meta. Tokens are encrypted at rest, never exposed in our UI or logs, and never shared with any third party.

Data about End Users. When someone messages your Instagram account, we necessarily process that person's message and their Instagram-scoped identifiers in order to deliver your automation. That person is not an Orlin user and has no Orlin account. We process their data solely as your Processor, only to operate the Service, and never for our own purposes.

3.3 Information collected automatically

CategoryExamples
Device and connectionIP address, browser type and version, operating system, device type, language, referring URL
Product usagePages viewed, features used, automations triggered, buttons clicked, session timestamps, error events
Link-in-bio analyticsPage views, link clicks, referrer, coarse geolocation derived from IP (country/region — we do not use GPS), device category
Security logsLogin attempts, IP addresses, session tokens, API request logs

Cookies and similar technologies used to collect some of this data are described in our Cookie Policy.

3.4 Information we do not collect

We do not knowingly collect:

  • Special category / sensitive personal data (health, biometrics, religious or political belief, sexual orientation, financial account credentials) — do not send it to us;
  • Data from users under the age of 18 (see Section 13);
  • Precise GPS location;
  • Data from Instagram accounts you have not connected and authorised.

4. How we use your information

We use personal data for the following purposes:

  1. To provide the Service — authenticate you, connect your Instagram account, evaluate your automation rules, send replies on your behalf, render your link-in-bio page.
  2. To maintain and improve the Service — diagnose faults, monitor performance, fix bugs, understand which features are used, and develop new ones. Where we analyse usage for improvement we use aggregated or de-identified data wherever it will serve the purpose.
  3. To communicate with you — service notices, security alerts, billing notices, changes to terms, and responses to your support requests. Service and transactional messages are not marketing and you cannot opt out of them while you hold an account.
  4. To take payment — process subscriptions, prevent failed charges, issue GST invoices.
  5. For safety, security and abuse prevention — detect fraud, rate-limit abuse, investigate violations of our Terms, and protect End Users from spam sent through our platform.
  6. For marketing, only with your consent — product announcements and offers, with an unsubscribe link in every message.
  7. To comply with law — tax, accounting, and lawful requests from authorities.
PurposeLegal basis (GDPR Art. 6)
Providing the Service, billingPerformance of a contract
Security, fraud prevention, product improvementLegitimate interests
Marketing emails, non-essential cookiesConsent
Tax and statutory recordsLegal obligation

Where the DPDP Act applies, we process personal data on the basis of your consent, given at sign-up and separately for each Meta permission through Meta's own authorisation screen, or on the basis of "certain legitimate uses" as defined in Section 7 of the Act. You may withdraw consent at any time (Section 11).


5. What we will never do with your data

To be explicit, and in line with the Meta Platform Terms and Developer Policies:

  • We do not sell personal data. Not to anyone, ever, under any definition of "sell" including that used in the CCPA/CPRA.
  • We do not share Platform Data with data brokers, information brokers, or resellers.
  • We do not use Platform Data for advertising, ad targeting, building ad audiences, ad measurement, or to enrich advertising profiles.
  • We do not use Platform Data to build or enrich user profiles for any purpose other than operating the Service for the Customer who supplied it.
  • We do not train machine learning or AI models on Platform Data for any purpose other than delivering the Service to the Customer whose data it is, and we do not use Platform Data to train general-purpose or foundation models.
  • We do not transfer Platform Data to any party except the service providers in Section 7, each of which is contractually bound to equivalent restrictions.
  • We do not attempt to re-identify de-identified data, and we do not combine Platform Data with data from other sources to identify individuals.
  • We do not send unsolicited or bulk promotional messages on our own behalf through connected accounts.

6. Meta Platform Data — specific commitments

Data we receive through Meta's APIs ("Platform Data") is subject to additional protections.

Compliance. Our access to and use of Platform Data is governed by the Meta Platform Terms, the Meta Developer Policies, the Instagram Platform Policy, and the Meta Data Protection Assessment requirements, in addition to this Policy. Where this Policy conflicts with those terms in respect of Platform Data, those terms prevail.

Purpose limitation. We use Platform Data only to provide and improve the specific features of Orlin that the Customer has enabled. We do not repurpose it.

Messaging window. We deliver automated messages in compliance with Instagram's messaging policies, including the 24-hour standard messaging window and permitted message tags. We do not use Orlin to send promotional content outside the windows Meta permits.

Access control. Access to Platform Data inside MUAWI is limited to employees and contractors who need it to operate or support the Service. Access is role-based, individually authenticated, logged, and reviewed at least every six months. All personnel are bound by written confidentiality obligations.

Token handling. Meta access tokens are encrypted at rest using AES-256, transmitted only over TLS, scoped to the minimum permissions needed, never logged, and revoked immediately when a Customer disconnects an account or deletes their Orlin account.

Revocation. You can disconnect Instagram from Orlin at any time — inside Orlin under Settings → Connected Accounts → Disconnect, or from Instagram under Settings → Website Permissions / Apps and Websites. Disconnecting immediately stops all data flow and revokes our token. We then delete the associated Platform Data as described in Section 9.

Incidents. If we become aware of a security incident affecting Platform Data, we will notify Meta without undue delay and cooperate fully with Meta's investigation, in addition to our obligations to Customers and regulators under Section 10.

Audit. We will cooperate with any audit or assessment Meta requires to confirm our compliance, including providing evidence of our security controls and data-handling practices.


7. When we share information

We share personal data only in the situations below.

7.1 Service providers (sub-processors)

ProviderFunctionDataLocation
[e.g. Amazon Web Services / Google Cloud]Application hosting, database, object storageAll categories[e.g. ap-south-1, Mumbai]
[e.g. Razorpay / Stripe]Payment processingBilling data[India / US]
[e.g. Resend / SendGrid]Transactional emailEmail address, name[US / EU]
[e.g. PostHog / Plausible]Product analyticsUsage and device data[EU / self-hosted]
[e.g. Sentry]Error monitoringTechnical logs, user ID[US / EU]
[e.g. Intercom / Crisp]Customer supportSupport conversations, email[US / EU]

Every sub-processor is bound by a written contract that limits them to processing on our instructions, imposes confidentiality and security obligations at least as protective as this Policy, and prohibits any independent use of the data. An up-to-date list is maintained at https://orlin.social/subprocessors; we will give Customers at least 30 days' notice before adding a sub-processor that processes Platform Data.

7.2 Meta Platforms

We send data to Meta's APIs in order to deliver the messages and actions you have configured. This is the Service functioning as intended.

We may disclose data where we believe in good faith it is necessary to comply with a law, regulation, court order, or valid governmental request; to enforce our Terms of Service; to detect or prevent fraud or security issues; or to protect the rights, property or safety of MUAWI, our users, or the public. Where legally permitted, we will notify the affected Customer before disclosing.

7.4 Business transfer

If MUAWI is involved in a merger, acquisition, restructuring, or sale of assets, personal data may transfer to the successor entity. We will notify you before your data becomes subject to a different privacy policy, and any successor remains bound by the Meta Platform Terms in respect of Platform Data.

7.5 With your direction

If you connect a third-party integration (for example a CRM or spreadsheet), we transmit the data you configure to that service. Its handling of your data is governed by its own privacy policy, not this one.


8. International transfers

We are based in India and store primary data in [e.g. AWS ap-south-1, Mumbai]. Some sub-processors listed in Section 7.1 operate outside India.

  • For EEA/UK data subjects: transfers out of the EEA/UK rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with supplementary technical measures including encryption in transit and at rest.
  • For Indian users: we transfer personal data only to countries not restricted by the Central Government under Section 16 of the DPDP Act.

9. How long we keep data

DataRetention
Customer account dataFor the life of the account, then 90 days after deletion (to allow recovery), then permanent deletion
Meta access tokensUntil you disconnect, your account is deleted, or the token expires — whichever is first. Deleted immediately on revocation.
Instagram DM and comment content[e.g. 90 days] rolling, or until you delete the conversation, or until you disconnect the account — whichever is first
End User Instagram-scoped IDs used for automation stateUntil the account is disconnected or the End User's data is deleted on request
Automation configurations and templatesFor the life of the account
Link-in-bio page contentFor the life of the account
Link-in-bio analytics[e.g. 24 months], in aggregated form after [e.g. 90 days]
Billing records and tax invoices8 years from the end of the relevant financial year (Indian tax and Companies Act requirements)
Security and access logs[e.g. 12 months]
Support conversations[e.g. 24 months] from last contact
BackupsDeleted data persists in encrypted backups for up to [e.g. 35 days] before backups are rotated out

When retention ends, we delete the data or irreversibly anonymise it. Anonymised, aggregated statistics that cannot identify any individual may be kept indefinitely.


10. Security

We maintain technical and organisational measures appropriate to the risk, including:

  • TLS 1.2+ for all data in transit; AES-256 encryption at rest for databases, backups, and access tokens;
  • Passwords stored using a slow, salted hashing algorithm ([e.g. bcrypt / argon2]) — never in plaintext or reversible form;
  • Role-based access control, least privilege, and mandatory multi-factor authentication for all administrative access;
  • Network isolation, security groups, and no public database exposure;
  • Audit logging of administrative and Platform Data access;
  • Dependency and vulnerability scanning, and a documented patching process;
  • Secure development practices, code review, and separation of production from development environments;
  • An incident response plan with defined roles and escalation paths;
  • Annual review of access rights, vendors, and this Policy.

No system is perfectly secure. If a personal data breach occurs, we will notify affected Customers and the relevant supervisory authority without undue delay — within 72 hours where GDPR Article 33 applies, and to the Data Protection Board of India as required under the DPDP Act — and we will notify Meta where Platform Data is affected.


11. Your rights

Depending on where you live, you may have the following rights.

RightWhat it means
AccessGet confirmation of whether we process your data and a copy of it
CorrectionHave inaccurate or incomplete data corrected
Erasure / DeletionHave your data deleted (see Section 12)
Withdraw consentWithdraw consent at any time, without affecting processing already carried out
PortabilityReceive your data in a structured, machine-readable format
Restriction and objectionRestrict or object to certain processing, including profiling and direct marketing
Nomination (India)Nominate another individual to exercise your rights in the event of death or incapacity
Non-discrimination (California)Not be discriminated against for exercising your rights
ComplaintLodge a complaint with a supervisory authority or the Data Protection Board of India

How to exercise them. Email privacy@orlin.social or use the in-app controls under Settings → Privacy. We will respond within 30 days, and will tell you if we need an extension. We may ask you to verify your identity before acting.

If you are an End User (you messaged a business that uses Orlin, and you don't have an Orlin account): the business is the Data Fiduciary / Controller of that data, and we act only as its Processor. Contact the business first — they are best placed to action your request. If you email privacy@orlin.social instead, we will verify your identity as set out in Section 12.3 and forward your request to the relevant Customer for action. We will only carry out a deletion directly, without the Customer's instruction, where we are legally required to do so or where the data is technically isolated to systems solely under our control.


12. Deleting your data

This section is Orlin's user data deletion instruction. It is published at https://orlin.social/legal/privacy-policy#12-deleting-your-data.

12.1 Disconnect Instagram only

  1. Sign in to Orlin at https://app.orlin.social.
  2. Go to Settings → Connected Accounts.
  3. Click Disconnect next to the Instagram account.

This immediately revokes our access token and stops all data flow. Platform Data associated with that account is deleted within 30 days.

You can also revoke from Meta's side: on Instagram, go to Settings → Website Permissions → Apps and Websites (or, for accounts managed through Facebook, Settings → Business Integrations), select Orlin, and choose Remove. When Meta notifies us of the revocation, we run the same deletion.

12.2 Delete your whole Orlin account

  1. Sign in to Orlin at https://app.orlin.social.
  2. Go to Settings → Account → Delete Account.
  3. Confirm. Your account is deactivated immediately.

Or email privacy@orlin.social from your registered address with the subject "Delete my account".

We permanently delete your account data, automations, link-in-bio pages, conversation history, and all associated Platform Data within 30 days, except billing records we are legally required to keep (Section 9) and encrypted backups, which rotate out within [e.g. 35 days].

12.3 If you are an End User (you messaged a business using Orlin)

For End User data, the Customer (the business you messaged) is the Data Fiduciary / Controller, and we act only as its Processor (Section 2). We cannot unilaterally alter or delete a Customer's records without the Customer's instruction, contractual authority, or a legal requirement to do so, and we cannot verify that an emailed Instagram handle actually belongs to you without further checks.

To request deletion, email privacy@orlin.social with:

  • the subject line "End User data deletion request";
  • the Instagram username you message from;
  • the Instagram username of the business you messaged;
  • any information we reasonably request to verify that you control the Instagram account named.

Once we have verified your identity, we will:

  1. Forward your request to the Customer so they can action it as Controller, and confirm to you once this is done; or
  2. Delete the data directly, without waiting on the Customer, only where we are legally required to do so or where the relevant data is technically isolated to systems solely under our control (for example, data already scheduled for deletion under our own retention schedule).

We will acknowledge your request within 7 days and use reasonable efforts to complete the applicable step within 30 days. There is no charge and you do not need an Orlin account.


13. Children

Orlin is a business tool and is not directed at children. You must be at least 18 years old to create an Orlin account. We do not knowingly collect personal data from anyone under 18. If we learn we have collected such data, we will delete it promptly. If you believe a minor has provided us data, contact privacy@orlin.social.

Customers must not use Orlin to target or collect data from children in violation of applicable law, including COPPA where relevant.


14. Cookies

We and our providers use cookies and similar technologies on https://orlin.social, in the Orlin app, and on Customer link-in-bio pages. See the Cookie Policy for the full list and your controls.


Orlin link-in-bio pages and our website may link to third-party sites we do not control. We are not responsible for their content or privacy practices. Review their policies before sharing data with them.


16. Changes to this Policy

We may update this Policy. When we do, we will change the "Last updated" date above. For material changes — for example a new purpose for Platform Data, or a new category of recipient — we will give notice by email and/or an in-app notice at least 30 days before the change takes effect, and where the law requires it, we will ask for your consent again. Continued use after the effective date means you accept the updated Policy.

An archive of previous versions is available at https://orlin.social/legal/archive.


17. Contact us

MUAWI Technologies LLP [REGISTERED_ADDRESS] LLPIN: [LLPIN]

  • General privacy questions: privacy@orlin.social
  • Support: support@orlin.social
  • Data deletion: see Section 12 above, or email privacy@orlin.social

Grievance Officer (India)

In accordance with the Information Technology Act, 2000 and the rules made thereunder, and the DPDP Act, 2023:

Name: [GRIEVANCE_OFFICER_NAME] Designation: Grievance Officer / Data Protection Officer Email: grievance@orlin.social Address: [REGISTERED_ADDRESS] Response time: We acknowledge grievances within the statutory timeline (currently 24 hours) and use best commercial efforts to resolve them within 15 business days of acknowledgment. Where a grievance involves a complex inquiry — such as a cross-border data audit or a disputed automated message trace — that cannot reasonably be completed in that time, we may take a reasonable extension as permitted by applicable law, and will keep you informed of progress.

If you are not satisfied with our response, you may complain to the Data Protection Board of India, or — if you are in the EEA/UK — to your local supervisory authority.

EU / UK representative

[Name and address of Article 27 representative, if you have EEA or UK users. Delete this block if not applicable.]


Orlin is an independent product of MUAWI Technologies LLP. It is not affiliated with, endorsed by, or sponsored by Meta Platforms, Inc. Instagram and Meta are trademarks of Meta Platforms, Inc.

Orlin