1 Introduction
SpotLand is a PropTech real estate marketplace operated by SocialPartners that connects Buyers, Sellers, Property Owners, Builders, Real Estate Agents, and Tenants across India. Beyond property discovery, buying, selling, and renting, SpotLand offers Home Loan applications, subscription and premium listing plans, Builder/Agent KYC verification, saved properties and wishlists, lead management, reviews, and — for Business Accounts — Facebook Page management, Instagram Business integration, and Meta Ads Management.
This Privacy Policy applies to every person who visits, browses, registers on, or otherwise interacts with SpotLand, whether as a Visitor, a registered User, or a connected Meta Account holder, across our website, mobile-responsive web app, and any associated APIs. It does not apply to third-party websites or services we link to, which are governed by their own privacy policies.
By creating an account, browsing listings, submitting a property, connecting a Facebook or Instagram account, or otherwise using SpotLand, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, and disclosure of your information as described here. If you do not agree, please discontinue use of SpotLand. Where required by applicable law — for example, before connecting a Meta Account or processing Sensitive Personal Data — we will ask for your explicit consent separately, in addition to this Policy.
Our key commitments to you
- SpotLand never sells your personal data to anyone, under any circumstance.
- We only access your Facebook or Instagram account after you explicitly authorize it, and only for the features you choose to use.
- You can revoke Meta access, or delete your account, at any time — see Facebook & Instagram Data Deletion and Account Deletion.
- OAuth permissions are used only for the specific features that require them — never bundled or requested speculatively.
- Access tokens are encrypted at rest and never exposed to your browser or any other User.
- Your password is never stored in plain text — it is one-way hashed.
- All payment processing is handled by our PCI-DSS-compliant partner Razorpay — SpotLand does not store your complete card details.
2 Definitions
To make this Policy easier to read, the following terms have the specific meanings below wherever they appear, capitalized, in this document:
- User
- Any individual who accesses or uses SpotLand, including Buyers, Sellers, Owners, Builders, Agents, Tenants, and Visitors.
- Buyer
- A User who searches for, enquires about, or purchases a Property listed on SpotLand.
- Seller
- A User — including a Property Owner or their authorized representative — who lists a Property for sale on SpotLand.
- Owner
- A User who holds legal title to, or is otherwise legally authorized to deal with, a Property listed on SpotLand.
- Builder
- A User, typically a registered real estate developer, who lists residential or commercial Projects for sale or booking on SpotLand.
- Agent
- A User registered on SpotLand to represent Buyers, Sellers, Owners, Builders, or Tenants in property transactions in a professional capacity.
- Tenant
- A User who searches for, enquires about, or rents a Property listed on SpotLand.
- Visitor
- Any person who browses SpotLand without creating or logging into an account.
- Property
- Any residential, commercial, or land listing — including apartments, villas, plots, and Builder Projects — published on SpotLand.
- Personal Data
- Any information that identifies, or can reasonably be used to identify, a specific individual, such as a name, email address, phone number, or government ID number.
- Sensitive Personal Data
- A category of Personal Data requiring heightened protection, including government identity numbers (e.g. PAN, Aadhaar), financial information, biometric data collected for selfie verification, and KYC documents.
- Business Account
- A SpotLand account registered by a Builder, Agent, or other organization to list Properties, manage leads, and access business features such as Subscription Plans and Meta Ads Management.
- Meta Account
- A Facebook or Instagram account that a User voluntarily connects to SpotLand via Facebook Login or Meta Business Login to enable social publishing, Page management, or advertising features.
3 Information We Collect
We collect information that you provide directly to us, information collected automatically as you use SpotLand, and information received from third parties (including Meta and our OAuth/payment partners):
- Identity & contact details — name, email address, phone number, and profile photo provided during sign-up or via Social Login.
- Verification documents — government ID, PAN, business/RERA/GST registration, or other KYC documents submitted by Owners, Agents, and Builders (see KYC & Identity Verification).
- Property information — listing details, images, videos, floor plans, pricing, and location submitted when you list a Property.
- Home Loan information — income, employment, and financial details submitted when applying for a Home Loan (see Home Loan Services).
- Meta Account data — when you connect Facebook or Instagram, we receive the profile, Page, and Business Manager information covered by the permissions you grant (see Facebook & Instagram Integration).
- Usage data — pages viewed, searches performed, properties saved, shared, or reviewed, and interactions with listings and Agents.
- Device & technical data — IP address, browser type, device identifiers, operating system, and approximate location.
- Payment data — transaction references and billing details processed via Razorpay; we do not receive or store your full card number, CVV, or online-banking credentials.
Some of the above — such as government ID numbers, financial information submitted for a Home Loan, and biometric selfie-verification data — qualifies as Sensitive Personal Data and receives additional safeguards described in Data Security and KYC & Identity Verification.
4 Account Registration
You need a registered account to save properties, contact Owners or Agents, and publish listings. You may register using an email/password combination or via Social Login (Google OAuth or Facebook Login) — in either case, you agree to provide accurate, current, and complete information and to keep it updated. Builders and Agents may be required to complete additional KYC verification before their listings go live. Each individual may maintain only one personal account; impersonation or the use of false credentials is prohibited and may result in account suspension.
5 Legal Basis for Processing
Wherever applicable law requires us to identify a legal basis for processing your Personal Data (including under the GDPR for Users in the European Economic Area, and under India's Digital Personal Data Protection Act, 2023), we rely on one or more of the following:
- Consent — for optional activities such as connecting a Facebook/Instagram account, receiving marketing communications, or providing Sensitive Personal Data (e.g. Aadhaar, selfie verification). You may withdraw consent at any time, without affecting processing already carried out.
- Contract — to create and administer your account, publish your listings, process Subscription Plan or premium listing payments, and deliver any service you specifically request.
- Legal obligation — to retain KYC, tax, and payment records as required by Indian financial, real estate, and accounting regulations, and to respond to lawful requests from courts or regulators.
- Legitimate interest — to secure the platform against fraud and abuse, improve our services through aggregated analytics, and operate core business functions such as lead management and dispute resolution — always balanced against your rights, and never for connecting your Meta Account, which is consent-based only.
6 Property Listings & Content
Property Owners, Agents, and Builders are solely responsible for the accuracy and legality of the listings they publish, including pricing, ownership status, and supporting documentation. SpotLand may review, moderate, feature, or remove listings that violate our content guidelines, contain misleading information, or are reported by other Users.
Ownership of listing content. You retain ownership of the images, videos, floor plans, descriptions, documents, location data, and pricing you submit for a Property. By publishing a listing, you grant SocialPartners a non-exclusive, royalty-free, worldwide license to host, display, reproduce, and — where you choose to use our promotion features — publish that content to a Facebook Page or Instagram Business account you connect, solely for the purpose of operating and promoting the listing on and through SpotLand. Listing details and images you submit may be displayed publicly on the platform and shared with prospective buyers or tenants who express interest.
7 How We Use Your Information
We use the information we collect to:
- Operate, maintain, and improve the SpotLand platform and its search, matching, and recommendation features.
- Connect Buyers, Tenants, Owners, and Agents, and facilitate property enquiries and site-visit requests.
- Personalize content, pricing insights, and property recommendations based on your activity and preferences.
- Process Home Loan applications, Subscription Plan and premium listing payments, and KYC verification.
- Publish your listings to a connected Facebook Page or Instagram Business account, and manage Meta Ads campaigns, only where you have explicitly enabled these features.
- Send transactional updates, respond to support requests, and process payments.
- Detect, investigate, and prevent fraud, spam, and misuse of the platform.
- Comply with applicable legal, regulatory, and tax obligations.
8 Home Loan Services
If you use SpotLand's Home Loan application feature, we collect additional information necessary to process your application, including:
- Income & employment details — occupation, employer, and income range.
- Loan preferences — desired loan amount, tenure, and the Property being financed.
- Supporting documents — income proof, identity proof, and property documents you upload.
- Bank information — bank name and account details relevant to loan disbursal, where applicable.
- Application status — the state of your loan application as it moves through review.
This information is used solely to process your Home Loan application and, only where you consent, may be shared with partner banks or lending institutions for the purpose of evaluating and processing that application. We do not use Home Loan data for advertising or unrelated marketing purposes.
9 KYC & Identity Verification
Owners, Builders, and Agents who wish to publish listings or access business features may be required to complete Know-Your-Customer (KYC) verification. This can include:
- Government-issued photo ID, and PAN where applicable.
- Aadhaar details, only where explicitly required and provided by you for a specific verification flow.
- Business registration, RERA registration, and GST documentation for Builders and Agents.
- Property ownership or authorization documents.
- Selfie verification, used to confirm that the person submitting documents matches the identity on them.
Purpose. KYC data is collected to verify identity, prevent fraudulent listings, build trust between Buyers/Tenants and Sellers/Owners, and meet applicable regulatory obligations for real estate intermediaries.
Retention. KYC documents are retained for the period set out in Data Retention, after which they are securely deleted unless a longer period is required by law.
Security. KYC documents and Sensitive Personal Data are encrypted at rest, accessible only to authorized verification personnel on a need-to-know basis, and are never used for advertising or shared with Meta, Google, or any other third party for marketing purposes.
10 Facebook & Instagram Integration
SpotLand offers optional integrations with Meta's platforms so Business Accounts can promote listings on Facebook and Instagram directly from SpotLand. Every part of this integration is opt-in — nothing connects to Meta unless you take an explicit action to do so.
Facebook Login & Meta Business Login
You may sign in to SpotLand using Facebook Login, which shares your public profile and email with us via OAuth (see below), or connect a Business Manager using Meta Business Login to manage Pages, Instagram accounts, and ad accounts you're authorized on. Neither requires a Meta connection to use SpotLand's core property features.
Facebook Pages & Instagram Professional/Business Accounts
From Settings → Social Accounts, you can connect a Facebook Page you administer and, where linked to it, an Instagram Professional (Business) Account. Once connected, you can publish a Property or Project listing — including its caption and up to ten approved images as a carousel — directly to that Page or Instagram account, optionally scheduled for a future time.
Facebook Graph API, Instagram Graph API, Marketing API & Messenger API
These integrations are built on Meta's official Facebook Graph API and Instagram Graph API (for connecting Pages/Instagram accounts and publishing content), Meta's Marketing API (for Ads Manager — see Advertising & Meta Ads), and, for planned future features, the Messenger API and Meta Webhooks (to keep connected Pages in sync and, eventually, to support lead-reply features). We call these APIs only for the actions you initiate, and only using the specific permissions described in Meta Permissions Reference.
OAuth, Permissions & User Consent
Connecting a Meta Account uses the industry-standard OAuth 2.0 protocol: you are redirected to Facebook, where you review and approve the specific permissions SpotLand is requesting, and Facebook returns an authorization token to us — we never see or handle your Facebook password. You can review exactly what each permission does in the Meta Permissions Reference table below, and you can revoke consent at any time from either SpotLand or your own Facebook settings (see Facebook & Instagram Data Deletion).
Page Tokens & Long-Lived Tokens
When you connect a Page or ad account, Meta issues a Page Access Token or user token, which we exchange for a long-lived token to avoid asking you to reconnect frequently. These tokens are encrypted before storage and are handled exactly as described in Security of Access Tokens — they are never persisted in a Marketing API call and are re-derived fresh, from encrypted storage, at the moment each request is made.
Business Verification
Certain Meta permissions — particularly those used by Ads Manager — require Meta to have completed Business Verification for our app, and for some permissions, Advanced Access approval through Meta's App Review process. Until that review is complete for a given permission, the corresponding feature is limited to accounts added as Admins, Developers, or Testers on our Meta App, exactly as it would be for any developer building on Meta's platform.
11 Meta Permissions Reference
The table below lists every Facebook/Instagram permission SpotLand requests, why we request it, exactly what data it gives us access to, and whether it's required or optional. Permissions marked Planned are not currently requested by our app — they're listed here for transparency about upcoming features and will only become active, and only be requested from you, once those features ship and pass Meta's review.
| Permission | Status | Why we request it | Data accessed | Required / Optional |
|---|---|---|---|---|
public_profile | Active | Authenticate you via Facebook Login and display your name and photo on your SpotLand profile. | Facebook User ID, public name, profile picture | Required for Facebook Login |
email | Active | Create or link your SpotLand account without a separate password. | Facebook-verified email address | Required for Facebook Login |
pages_show_list | Active | Show you the list of Facebook Pages you manage so you can choose one to connect. | List of Page IDs and names you administer | Optional — requested only in Settings → Social Accounts |
pages_manage_posts | Active | Publish your Property/Project listings as posts on a Page you connect. | Ability to create, edit, and delete posts on the connected Page | Optional — requested only when you connect a Page |
pages_manage_metadata | Active | Configure the webhook subscription required to keep your connected Page in sync with SpotLand. | Page subscription and webhook configuration | Optional — requested only when you connect a Page |
pages_read_engagement | Active | Required by Meta alongside posting permissions; used to read engagement on posts SpotLand publishes on your behalf. | Likes, comments, and share counts on Page posts SpotLand creates | Optional — requested only when you connect a Page |
pages_manage_engagement | Planned | Reserved for a planned feature that will let you view and reply to comments on your published posts directly from SpotLand. | Comments on Page posts | Not currently requested — will be optional when released |
instagram_basic | Active | Identify and display the Instagram Business account you connect. | Instagram Business Account ID, username, profile picture | Optional — requested only when you connect Instagram |
instagram_content_publish | Active | Publish your Property/Project photos, including multi-image carousels, to your connected Instagram Business account. | Ability to publish photos/carousels to the connected account | Optional — requested only when you connect Instagram |
instagram_manage_comments | Planned | Reserved for the same planned comment-management feature described above, applied to Instagram posts. | Comments on Instagram posts | Not currently requested — will be optional when released |
instagram_manage_messages | Planned | Reserved for a planned feature allowing Agents and Builders to reply to Instagram Direct enquiries from within SpotLand. | Instagram Direct messages sent to your connected account | Not currently requested — will be optional when released |
instagram_manage_insights | Planned | Reserved for a planned analytics dashboard showing how your Instagram posts perform. | Post reach, impressions, and engagement metrics | Not currently requested — will be optional when released |
ads_management | Active | Let you create, edit, pause, resume, and delete ad campaigns, ad sets, ads, and ad creatives from SpotLand’s Ads Manager. | Read/write access to campaigns, ad sets, ads, and creatives on the ad account you connect | Optional — requested only when you connect an ad account in Ads Manager |
ads_read | Active | Show ad performance — reach, impressions, clicks, spend, CTR, and CPM — inside SpotLand’s Ads Manager. | Ad account performance and insights data | Optional — requested only when you connect an ad account in Ads Manager |
business_management | Active | Confirm which Meta Business Manager(s) and ad accounts you are authorized to manage before letting you connect them. | Read-only list of Business Manager(s) and associated ad accounts | Optional — requested only when you connect an ad account in Ads Manager |
12 Advertising & Meta Ads
Business Accounts can connect a Meta ad account to SpotLand's Ads Manager to promote listings as paid Facebook Ads and Instagram Ads, built on Meta's Marketing API. Through Ads Manager, you can:
- Campaign Management — create, pause, resume, and delete campaigns, ad sets, and ads, with budgets set entirely by you.
- Audience Management — define who your ads reach (location, age, gender, and platform placements) using targeting criteria you configure; SpotLand does not build its own separate audience-tracking profile of you for this purpose beyond what you configure in the tool.
- Ad Analytics — view reach, impressions, clicks, spend, CTR, and CPM for your campaigns, sourced directly from Meta's reporting via the
ads_readpermission. - Conversion Tracking — where you choose to enable it in future, Meta's own conversion tools may be used to measure ad effectiveness; SpotLand does not currently embed the Meta Pixel on public listing pages.
Special Ad Categories. Meta requires every campaign to be flagged with any applicable Special Ad Category. In particular, U.S. Fair Housing Act rules restrict targeting (e.g. no age, gender, or ZIP-radius targeting) for any campaign categorized as Housing. If you are advertising a U.S. property or project listing to U.S. audiences, you are responsible for marking your campaign as Housing; Ads Manager passes this flag through to Meta as-is and does not attempt to auto-detect when it applies, since that is a legal determination for you to make.
All ads are created, paused, and deleted at your direction — SpotLand never launches or spends on an ad campaign without your explicit action, and every new campaign defaults to a paused state until you activate it.
13 AI & Recommendation Systems
SpotLand currently uses conventional, rules-based logic — not machine-learning models — to power search ranking and "properties you may like" suggestions, based on factors like your search history, saved properties, and listing recency. We are evaluating AI-powered recommendation features for a future release, which would use similar signals (search behavior, saved/viewed properties, and stated preferences) to generate more personalized suggestions and analytics. Should we introduce such features, we will update this Policy beforehand to describe exactly what data feeds them and, where required by law, obtain your consent before enabling AI-driven processing of your data.
14 Communication Preferences
We may contact you via email, SMS, WhatsApp, or push notifications for account, transactional, and service-related communication (e.g. inquiry alerts, KYC status, payment receipts) — these cannot be opted out of while your account is active. Marketing communications such as property recommendations and promotional offers are optional, and you can manage your preferences anytime from Profile > Notification Settings, or by using the unsubscribe link included in our emails. Where we use WhatsApp Business messaging, it is subject to WhatsApp's own terms in addition to this Policy.
16 Data Security
We apply layered, industry-standard safeguards to protect your information across the SpotLand stack:
- Encryption in transit — all traffic is served over HTTPS with TLS encryption; our servers do not accept unencrypted connections.
- Encryption at rest — Sensitive Personal Data, KYC documents, and Meta access tokens are encrypted in our MySQL database.
- Password hashing — passwords are never stored in plain text; they are one-way hashed using industry-standard algorithms, so even we cannot read them.
- JWT & OAuth tokens — authenticated sessions use signed JSON Web Tokens with defined expiry; OAuth tokens for Google and Meta are handled per Security of Access Tokens.
- Role-based access control — internal access to Personal Data, KYC documents, and admin tooling is restricted by role, on a need-to-know basis.
- Audit logs — sensitive actions (KYC approvals, ownership transfers, admin actions) are logged for accountability and incident investigation.
- Firewall & rate limiting — our Nginx-fronted infrastructure applies request rate limiting and firewall rules to mitigate abuse and denial-of-service attempts.
- Backups — the production database is backed up regularly to support recovery from failure or data loss.
- Monitoring & server security — our Ubuntu-based servers, managed via PM2, are patched and monitored for suspicious activity and uptime.
Despite these measures, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your login credentials confidential and for notifying us immediately of any unauthorized use of your account.
17 Security of Access Tokens
OAuth and Meta access tokens receive dedicated protection beyond our general security measures, because they represent direct access to your connected accounts:
- Secure, encrypted storage — Facebook, Instagram, and Google tokens are encrypted before they are ever written to our database.
- Never persisted for Marketing API use — for Ads Manager specifically, no token is cached in memory or logs between requests; it is decrypted fresh from storage at the moment each Meta API call is made.
- Never shared or exposed — tokens are never sent to your browser, displayed in our UI, shared with any other User, or provided to any third party other than Meta/Google themselves as required to make the authorized API call.
- Automatically revoked when disconnected — disconnecting a Facebook Page, Instagram account, or ad account (or deleting your SpotLand account) immediately deletes the corresponding stored token; see Facebook & Instagram Data Deletion.
- Ownership re-verified on every use — every action taken with a stored token re-confirms that the requesting User actually owns the connected Page, Instagram account, or ad account, so a token can never be used on another User's connection.
18 Third-Party Service Providers
SpotLand integrates with trusted third-party providers to deliver our services. Each processes only the data necessary for the function it performs, under its own privacy policy:
- Meta (Facebook & Instagram) — Facebook Login, Meta Business Login, Facebook Pages, Instagram Business accounts, and Meta Ads Management, as described in Facebook & Instagram Integration.
- Google — Google OAuth for Social Login, and Google Maps for location display and search.
- Razorpay — processes Subscription Plan and premium listing payments. SpotLand does not store your complete card, UPI, or net-banking credentials; Razorpay is PCI-DSS compliant.
- Mapbox & Google Maps — power interactive maps, geocoding, and location search for listings.
- Cloud storage providers — property images, videos, and documents are stored with a cloud storage provider (currently, or in future, services such as AWS S3 or Cloudinary), accessed only by SpotLand's backend.
- SMS & WhatsApp providers — deliver OTPs, alerts, and (where enabled) WhatsApp Business notifications.
- Email providers — deliver transactional and, where you opt in, marketing email.
- Hosting & infrastructure — our application runs on Ubuntu servers behind Nginx, managed with PM2, using Redis for caching/session support and MySQL for persistent storage.
- Analytics providers — help us understand aggregate usage patterns to improve the platform.
We do not sell your personal data to third parties. We may share information with the service providers above (each bound by confidentiality and data-processing obligations), with legal authorities when required by law, or in connection with a business transfer such as a merger or acquisition (see Business Transfers).
19 International Data Transfers
SpotLand primarily stores and processes data on servers located in India. However, some of our third-party providers — including Meta, Google, and certain cloud storage or email providers — may process or store data outside India, including in jurisdictions that may have different data protection standards than your home country. Where we transfer Personal Data internationally, we take reasonable steps to ensure it receives an equivalent level of protection, including relying on providers who maintain recognized safeguards (such as Standard Contractual Clauses, where applicable, for transfers involving the European Economic Area). By using SpotLand, you understand that your information may be processed outside your country of residence.
20 Children's Privacy
SpotLand is intended for use only by individuals who are at least 18 years old and legally capable of entering into binding property, loan, and payment-related agreements. We do not knowingly collect Personal Data from anyone under 18. If we become aware that we have inadvertently collected data from a person under 18, we will take reasonable steps to delete it promptly. If you believe a minor has provided us with Personal Data, please contact us using the details in Contact Information.
21 User Rights
Subject to applicable law (including the GDPR and India's DPDP Act, 2023, where applicable to you), you have the right to:
- Access — request a copy of the personal data we hold about you.
- Correction — request correction of inaccurate or incomplete information.
- Deletion — request deletion of your account and associated data, subject to the legal and regulatory retention requirements described in Data Retention.
- Portability — request your data in a structured, commonly used, portable format.
- Restriction — request that we limit how we process your data in certain circumstances.
- Objection — object to processing based on legitimate interest, including for direct marketing.
- Consent withdrawal — withdraw consent for optional processing, such as marketing communications or a connected Meta Account, at any time.
- Complaint — lodge a complaint with your local data protection authority (for example, India's Data Protection Board under the DPDP Act, or your national supervisory authority under the GDPR) if you believe we have not handled your data lawfully.
You can exercise most of these rights directly from your account settings, or by reaching out using the details in Contact Information below. We will respond to verified requests within the timeframe required by applicable law.
22 Data Retention
We keep different categories of data for different lengths of time, based on why we collected it and what the law requires:
| Data category | Retention period | Why |
|---|---|---|
| Account & Profile Data | While your account is active, plus 90 days after deletion | To let you recover an accidentally deleted account and to complete any in-progress transactions. |
| Property & Project Listings | While the listing is active, plus up to 3 years after removal | To resolve ownership or transaction disputes and satisfy real estate record-keeping norms. |
| Payment & Invoice Records | Up to 8 years | Required under Indian tax and accounting regulations for financial records. |
| KYC & Verification Documents | Up to 5 years after account closure | Regulatory and fraud-prevention obligations applicable to real estate and payment intermediaries. |
| Support Tickets & Enquiries | Up to 2 years | To maintain service-quality history and resolve recurring issues. |
| Meta Access & Refresh Tokens | Until you disconnect, or automatically per Meta’s token expiry — whichever comes first | Tokens are never kept longer than needed to keep your connection active — see Security of Access Tokens. |
| Session / OAuth Tokens | Duration of your login session only | Session tokens are short-lived and are not stored beyond your active session. |
| Server & Security Logs | Up to 12 months | To investigate security incidents, detect fraud, and maintain platform reliability. |
| Marketing Consent Records | Until you withdraw consent, plus the applicable statutory limitation period | To demonstrate compliance with consent-based marketing rules if ever required. |
Aggregated or anonymized data that can no longer identify you may be retained indefinitely for analytics and platform improvement.
23 Account Deletion
How to delete your account. You can request deletion of your SpotLand account from your account settings, or by emailing us at the address in Contact Information with the subject line "Account Deletion Request." We will verify your identity before processing the request.
What gets deleted. Once processed, your profile, saved properties, wishlist, and account credentials are deleted or irreversibly anonymized, and any connected Meta Account is disconnected (see Facebook & Instagram Data Deletion).
What we retain, and why. As described in Data Retention, we are required to retain certain records — such as payment/invoice history, KYC documents, and records tied to an active listing or ongoing dispute — for defined periods after account deletion to meet legal, tax, and regulatory obligations. This retained data is restricted from further active use and is deleted once the applicable retention period ends.
24 Facebook & Instagram Data Deletion
In line with Meta's Platform Terms, you can disconnect your Meta Account and request deletion of the data SpotLand has received through it at any time, using either method below:
- In SpotLand: Go to Settings → Social Accounts and select Disconnect next to your connected Facebook or Instagram account. This immediately: (1) deletes the stored access/refresh tokens for that connection, (2) removes the connected Facebook Page record, (3) removes any linked Instagram Business Account connection, and (4) stops any further posting or ad activity on your behalf through that connection.
- Via Facebook: You can also revoke SpotLand's access directly from your Facebook Settings & Privacy → Settings → Apps and Websites. Meta will notify us of the revocation, and we will delete the associated tokens on our side even if you did not use the in-app Disconnect option.
- By request: Email us at the address in Contact Information with the subject line "Meta Data Deletion Request." We will verify your identity against your SpotLand account before deleting the requested data, and will confirm once the deletion is complete, consistent with Meta's Data Deletion Request requirements for platform apps.
Disconnecting does not delete your underlying SpotLand account or your Property/Project listings — it only removes the Meta connection and any Meta-derived data (tokens, Page/Instagram links, and cached account identifiers). Content already published to Facebook or Instagram before disconnection remains on those platforms unless you separately remove it there, or unless you request removal as part of your deletion request and it is still technically possible for us to do so via the API at that time.
25 Business Transfers
If SocialPartners is involved in a merger, acquisition, financing, reorganization, or sale of all or a portion of its assets, your Personal Data may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on SpotLand before your Personal Data becomes subject to a different privacy policy, and any such transfer will remain subject to protections consistent with this Policy for previously collected data.
26 Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy, your personal data, or a Meta Account connection, please reach out using any of the details below:
For privacy-specific requests (data access, correction, deletion, or Meta data deletion), please use the subject-line conventions described in the relevant sections above so we can route your request efficiently.
27 Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, integrations (including new Meta permissions or third-party providers), or legal requirements. The "Last updated" date at the top of this page indicates when the policy was last revised. For material changes — particularly any that affect how we use Meta Account data or expand the permissions we request — we will provide additional notice via email or an in-app announcement before the change takes effect. Your continued use of SpotLand after changes take effect constitutes acceptance of the revised policy.
28 Meta Platform Compliance
SpotLand's use of Facebook and Instagram integrations is designed to comply with, and is governed in addition to this Policy by, Meta's own platform rules, including the Meta Platform Terms, Meta Developer Policies, the Facebook Graph API and Instagram Graph API terms of use, the Instagram Platform Policy, and the Marketing API Terms. We request only the permissions necessary for the features described in this Policy (see Meta Permissions Reference), never request more access than a feature requires, honor Meta's Data Deletion Request requirements (see Facebook & Instagram Data Deletion), and will not use data obtained via Meta's APIs for any purpose inconsistent with what you were told when you granted access.