Privacy policy
Last updated September 27, 2026
This policy explains what information CommentGate collects, where it comes from, why we use it, who else handles it, how long we keep it, how we protect it, and the choices and rights you have. CommentGate is operated by CROapps Oy, a limited company registered in Finland (Business ID 3550932-5, VAT number FI35509325), Pohjoinen Rautatiekatu 29B, 00100 Helsinki, Finland ("we", "us"). We serve businesses worldwide, most of them in the United States, so this policy covers your rights under the GDPR and the UK GDPR, US state privacy laws including the California Consumer Privacy Act, and similar laws elsewhere. For privacy questions and requests, use the contact form and choose "Privacy or data deletion".
1. Who this policy is about, and our role
We handle information about three groups of people, and our role is different for each.
- Customers: the brands, agencies and team members who sign up for CommentGate, and people who contact us or visit our website. For this information we decide how it is used, so we are the controller.
- People who comment or send a message: anyone who comments on or replies to a Facebook Page, Instagram account, TikTok account, YouTube channel, Threads profile or ad that a customer connected, or who sends a direct message to a connected Facebook Page, Instagram account, TikTok account or WhatsApp number. We handle those comments and messages on the customer's behalf and on its instructions, so the customer is the controller and we are its processor (a "service provider" or "processor" under US state laws).
- The people who connect a platform account: when someone on a customer's team connects Facebook, Instagram, Threads, WhatsApp, TikTok or YouTube, we receive the details of that login described below.
If you commented on a brand's post or ad, or messaged a brand, and want to know what that brand does with your information, the brand is the right first contact. You can also ask us directly, and we will help or pass your request on. See Data deletion.
2. What we collect
From customers and their teams
- Account details: your name, email address, the brands you belong to and your role in them. Sign-in uses one-time links and codes sent by email, passkeys, authenticator apps or your company's single sign-on. We store no passwords.
- Brand settings you give us: brand descriptions, guidance, corrections you make to decisions, saved replies, knowledge, keyword lists, rules, campaigns, tags and notes.
- Product catalogs you add: from Meta (see below), a CSV file or a feed address you give us. We store product names, descriptions, brands, prices, availability, stock, sizes, colors, links and image links.
- Billing details: plan, billing address, tax number if you give one, and invoices. Card numbers go directly to our payment processor, Stripe, and we never see or store them.
- Integration settings you add: webhook, Slack and Discord addresses, your Klaviyo key and your Meta Conversions API dataset and token (all encrypted), and API keys (stored only as a one-way hash).
- Messages you send us through the contact form or by email: your name, email address, message, and the IP address and browser you sent it from.
- Usage and device information: sign-in sessions with IP address and browser, a record of important actions in your brands (the audit log, including sign-ins with IP address), and whether you allowed browser notifications.
From the platforms you connect
When you connect an account, you choose which Pages, profiles, channels, numbers and ad accounts CommentGate can see, and the platform shows you the permissions we ask for. What we receive from each platform is listed in Platform data we access. In short:
- Comments and replies: the text, any attached image, GIF or sticker reference, the time, and the public name, username, profile identifier and profile picture of the person who wrote it.
- Direct messages sent to a connected Facebook Page, Instagram account, TikTok account or WhatsApp number, and the replies sent from CommentGate: the text, the type of any attachment, the time, and the sender's name, username or phone number, and platform identifier. We do not download or store photos, videos or files people send.
- Posts, videos and ads the comments belong to: captions, titles, thumbnails, links and publish dates; ad, ad set and campaign names and identifiers and delivery status.
- Account details: Page names, usernames, channel names and handles, WhatsApp display names, quality rating and messaging limit, account identifiers and profile pictures.
- Access tokens that let us act on your behalf. They are encrypted, and we delete them the moment you disconnect.
People who comment on or message a connected account
We receive only what the platform shows the customer about you: the comment or message itself, and your public name, username or phone number (WhatsApp), profile identifier and profile picture. We do not ask for passwords, read your other posts or your private messages to anyone else, or look up information about you elsewhere. If you give a brand your email address or phone number in a conversation, or tap a button, the brand can store that in its contact list in CommentGate.
Visitors to our website
Our website sets no advertising or analytics cookies and runs no analytics or tracking scripts. Our hosting provider processes your IP address and browser details to deliver pages and protect the site from abuse.
3. Platform data we access, by platform
We access only the platform data needed for the features the customer uses, and only for accounts the customer connected.
Facebook and Instagram (Meta)
The customer connects through Facebook Login for Business and chooses the business, Pages, Instagram professional accounts, ad accounts and catalogs to share. We ask for these permissions:
| Permission | What we access | Why |
|---|---|---|
public_profile | Name and identifier of the person who connects | To show who connected the account |
pages_show_list | The list of Pages the person manages | To let the customer choose which Pages to moderate |
business_management | The assets shared from the business portfolio, and its system-user token | To moderate exactly the Pages, accounts, ad accounts and catalogs the customer shared |
pages_manage_metadata | The Page's webhook subscription | So new comments and messages reach CommentGate within seconds |
pages_read_engagement | Page posts and ad posts (text, image, link) | To show each comment next to the post it was left on |
pages_read_user_content | Comments people leave on the Page, with the commenter's name and picture | To moderate them |
pages_manage_engagement | Hide, unhide, delete, like and reply to Page comments | To carry out the customer's rules and actions |
instagram_basic | The Instagram account's username, picture and posts | To show the connected account and each comment's post |
instagram_manage_comments | Instagram comments: read, hide, unhide, delete and reply | To moderate them |
ads_read | Which posts run as ads, with ad, ad set and campaign names | To label ad comments and apply ad rules |
ads_management | Replies to the customer's Threads ads: hide and answer | Only for those two actions. We never create, edit or pay for ads |
catalog_management | The business's product catalogs and products (names, prices, availability, sizes, colors, links) | Read only, so replies quote real prices and stock. We never change a catalog |
pages_messaging | Messenger conversations with the Page | The Messages inbox, private replies to comments, and the campaigns and automatic answers the customer turns on |
instagram_manage_messages | Instagram direct messages with the account, story replies and mentions, and whether a person who wrote first follows the account | The same, for Instagram |
| Business Asset User Profile Access | The public name and picture of people who comment on or message the business | To show who wrote each comment or message |
| Human Agent | Sending a reply a person typed, up to 7 days after the customer's last message | Only once Meta approves it, and never for automated messages |
- Messaging windows: automated messages (campaigns, welcome messages and default replies) go only to people who commented on the business's post or ad or wrote to it first, and only within 24 hours of their last message. A private reply to a comment is one message, sent within 7 days of the comment. Only a person on the team can answer between 24 hours and 7 days, using the Human Agent tag once Meta has approved it. We never use message tags for automated messages.
- We do not store the media of stories people reply to or mention.
- Customers can connect a catalog and remove it at any time in Settings, Integrations; removing it deletes its products from CommentGate at once. Disconnecting the Facebook login that shared a catalog, or removing CommentGate on Facebook, deletes the catalog and its products within 7 days.
Meta Conversions API (only if the customer turns it on)
If a customer adds its own Meta dataset in Settings, Integrations and switches it on, we send events to that dataset on the customer's instruction: purchases the customer reports to us, and leads captured in Messenger or Instagram conversations. For a purchase we send the email address and phone number only as SHA-256 hashes, a hashed CommentGate identifier, the order value, currency and order number, and the browser, IP address and Meta click details the customer passes to us (we pass these through without storing them). For a lead we send only the Page or Instagram account and the person's Page- or Instagram-scoped identifier, never an email or phone number. The customer is responsible for telling its own customers about this. We never send data to Meta for our own advertising.
- The customer connects its own WhatsApp Business Account and number through Meta's signup window. We use
whatsapp_business_messagingto receive messages sent to that number and delivery statuses, and to send the replies the team writes and the automated answers the customer set up. We usewhatsapp_business_managementto read the account and number (display name, quality rating and messaging limit), subscribe to its webhooks, and create and list the customer's message templates. - We store each message's text and the type of any attachment (never the photo, video or file itself), the person's name and phone number, their WhatsApp identifier, the ad they clicked if they came from a click-to-WhatsApp ad, and when they consented to messages or opted in to marketing.
- Outside the 24-hour window after a person's last message, the business can only send templates WhatsApp approved, and only to people who opted in. Marketing templates go only to contacts the business marked as opted in to marketing, never to United States numbers, and never after a person asks to stop.
- Meta bills the customer's WhatsApp Business Account directly for messages. We do not resell messaging.
Threads
- When a customer connects a Threads profile in the Threads window, we ask for
threads_basic(the profile's identifier, username and picture),threads_read_replies(the profile's own recent posts, and replies to them with the text, any image, the time, whether the reply is hidden, and the replier's username and picture),threads_manage_replies(hide and unhide replies) andthreads_content_publish(post a reply as the profile). We do not read other profiles' posts or run searches. When a profile is connected, we bring in replies from the last 30 days so the team can review them. - Replies to Threads ads reach us through the Facebook login that manages the ad account, as described under Facebook and Instagram.
- Threads replies are shown only inside the brand's workspace, to people the account holder invited and can remove. We hide replies; we never delete someone else's reply.
TikTok
- TikTok accounts (organic): with
user.info.basicanduser.info.usernamewe read the connected account's display name, username and picture; withvideo.listthe account's own videos (caption, cover and link); withcomment.listandcomment.list.managethe comments and replies on those videos (text, time, and the commenter's username and display name), and we hide, unhide, reply to and like them. - TikTok ads: through TikTok's Marketing API we read comments on the customer's ads, hide, unhide and reply to them, keep the ad account's blocked words list in step with the customer's own keyword list, and read ad account, ad group, ad and identity names so comments show next to the right ad. We never create, edit or pay for ads, and we do not access reporting or audience data.
- We do not collect data about creators or audiences for discovery, profiling or resale, we do not download videos, and we do not publish posts.
TikTok direct messages
Once TikTok approves CommentGate for business messaging and the customer reconnects its TikTok account to allow it, we receive direct messages sent to that account and send replies from it. We store the message text, the sender's username and TikTok identifier, the time, and stickers or shared posts as links. Photos and videos people send are recorded only as "a photo" or "a video"; we never download or store them. Messages go only to people who wrote to the business first, within TikTok's limits. We also manage the account's welcome message, suggested questions and new follower message when the customer turns them on. TikTok does not offer business messaging for accounts created in the European Economic Area, the United Kingdom or Switzerland, so CommentGate does not provide it for those accounts, and when someone in those regions writes to a connected account we store nothing about it. Message text is used only to show the conversation to the business's team and to send its replies; if the business switches on AI answers in direct messages, the latest messages of that conversation are also sent to the AI service described in AI and automated decisions. Direct messages are kept, deleted and protected like the rest of the account's data (see How long we keep it and Security): when the business disconnects the account or revokes access in TikTok, we stop at once and delete its messages and conversations within 7 days.
YouTube
See the YouTube section below, which lists exactly what we read, store and share.
4. How we use it
- To read incoming comments and decide, following the customer's settings, rules and past corrections, whether to hide, delete, hold for review, allow, like or reply, and to send judgment calls to a person.
- To draft replies in the brand's voice for approval, or to send them when the customer has turned that on.
- To show direct messages to the team, send the replies they write, and run the campaigns and automatic answers the customer set up.
- To keep the customer's contact list, reports, alerts and exports, and to send events to tools the customer connected.
- To bill customers, provide support, and send service messages such as sign-in links, alerts and digests you chose. The weekly insights email is optional and every copy has a one-click unsubscribe.
- To keep the service secure, prevent abuse and fraud, and fix problems.
- To meet legal obligations such as accounting records and lawful requests.
What we never do
- We never sell, rent or license personal information or platform data, and we never share it for cross-context behavioral advertising.
- We never use platform data or the content of comments and messages for advertising, to build or enrich profiles of people, or to target anyone with ads.
- We never use it for surveillance, to discriminate against anyone, or to make decisions about eligibility for housing, employment, credit, insurance or similar.
- We never give it to data brokers or advertising networks, and never combine one customer's data with another's.
- We never use it to train AI models for anyone else. The only learning is the per-brand layer described in AI and automated decisions, which serves that brand alone.
5. AI and automated decisions
CommentGate uses automated tools to do what the customer asked it to do:
- A classifier (typesafe.ai's Jev model) rates each comment for categories such as scams, spam, hate and competitor mentions.
- Language models reached through OpenRouter (today an OpenAI model, with a Qwen model as a fallback for image checks) draft replies, translate, summarize weekly insights, check images attached to comments, and turn the customer's guidance and corrections into its brand policy.
- A small model of the customer's own corrections, trained only on that brand's data and used only for that brand, sets how confident CommentGate must be before acting on its own.
These services receive only what they need for one request: the comment or message text, the image, and the brand's guidance. They return a result and do not receive account tokens or contact lists. Apart from the per-brand layer above, we do not use customer data to train AI models, and we do not allow our providers to use it to train theirs.
- Every request we send through OpenRouter tells it to use only model hosts that, by OpenRouter's records, do not train on what they receive. OpenRouter does not send the request to any other host.
- Replies, translations, weekly insights, brand policy work and the main image check also require a host with a zero data retention policy, meaning it keeps no copy of the request. Today those requests go to OpenAI's model hosted by Microsoft Azure or Amazon Bedrock, not to OpenAI directly.
- The fallback image check (the Qwen model, used only when the main model cannot check an image) has no zero data retention host on OpenRouter. Its host, Alibaba Cloud, does not train on the image or text but may keep them for a period under its own terms.
- typesafe.ai, which rates comments, states that its Jev model is not trained on customer requests or responses. Its standard terms allow it to keep requests for as long as needed for the service and the law.
Hiding, holding and replying happen only because the customer turned on a setting or rule for it, and topics the customer marks (such as chargebacks, legal threats and safety reports) always go to a person. Drafts wait for a person to approve them unless the customer turns on sending, and replies that go out on their own pass a check first. If a comment of yours was hidden or answered by CommentGate and you disagree, contact the brand: it can review the decision, unhide the comment and answer you. You can also ask us through the contact form and we will pass it on. These decisions affect only whether a comment is visible on a brand's own post; they have no legal or similarly significant effect on you.
6. Legal bases (EU, EEA and UK)
Where the GDPR or UK GDPR applies to us as a controller, we rely on:
- Performance of a contract: running the service you signed up for, including account, sign-in, billing and support.
- Legitimate interests: keeping the service secure and free of abuse, improving it, answering people who contact us, and defending legal claims. We balance these against your rights, and you can object.
- Legal obligation: keeping accounting records and responding to lawful requests.
- Consent: where we ask for it, for example browser notifications and the optional weekly email. You can withdraw it at any time.
For comments, messages and contacts we process for customers, the customer is responsible for its own legal basis, usually its legitimate interest in keeping its pages free of scams, spam and abuse and in answering the people who contact it, or consent for marketing messages.
8. International transfers
We are established in Finland, in the European Union. Our database and email providers run in the United States (AWS US East, Northern Virginia), and our hosting provider runs worldwide, close to each visitor. When personal information from the EU, EEA, UK or Switzerland is transferred to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (with the UK International Data Transfer Addendum for UK data) in our agreements with each provider, or on the EU-US Data Privacy Framework where the provider is certified. Wherever you are, your information may be processed outside your own country, and we apply the protections in this policy to all of it.
9. How long we keep it
| Information | How long |
|---|---|
| Comments, replies, direct messages, conversations, posts, ad details, decisions and contacts of a connected account | While the account stays connected. Deleted within 7 days after the customer disconnects it or removes CommentGate in the platform's settings. Only the comment counts on bills stay. |
| Access tokens | Deleted the moment the account is disconnected or CommentGate is removed on Facebook, Instagram or Threads. On YouTube we also revoke our access with Google at that moment. |
| Access removed in Google's or TikTok's settings | The platform refuses our next request, usually within an hour, and the team is asked to reconnect. If nobody does within 4 days, we delete the account's data as for a disconnect, still within 7 days of the removal. |
| YouTube comment text and commenter names, handles and pictures | 30 days after the comment was written, even while the channel stays connected. Video titles and thumbnails are read again or cleared within 30 days. See YouTube. |
| A brand whose trial ended without a plan, or whose paid period ended after canceling | 30 days later we delete its comments, messages, conversations, contacts, posts, ad details and connected accounts. Its settings, rules, tags, catalogs, knowledge, client reports and billing records stay so you can come back, until you delete the brand. |
| Raw platform data attached to comment events | Cleared after 13 months. |
| A deleted brand | Everything in it is deleted right away, when you delete it. |
| A deleted user account | Deleted right away. |
| Product catalogs | Until the customer removes the catalog or deletes the brand. A catalog read from Meta is also deleted, with its products, within 7 days after the Facebook login that shared it is disconnected or removes CommentGate. |
| Audit log, including sign-ins with IP address | 13 months. |
| Sign-in sessions (with IP address and browser) | A session lasts 30 days, renewed as you use the app. Expired sessions, and sign-in codes and links once they expire, are deleted in our daily cleanup. |
| Browser notification subscriptions | Until you turn notifications off, or after 60 days unused once a delivery fails. |
| Tracked link clicks | 7 days (no IP address or browser details are stored). |
| Data deletion confirmation codes | 90 days. |
| Billing records and invoices | As long as Finnish accounting law requires, usually six years after the end of the financial year (ten years for the accounting books). |
| Contact form and support messages | Up to two years after the conversation ends. |
| Hosting provider logs | A few days, and never more than 30. |
When data is deleted, it is removed from our live systems and can no longer be seen by anyone at CommentGate or in any brand. Encrypted database backups roll over, so it disappears from them within a further 35 days. Deleting our copy does not delete anything on the platforms.
10. YouTube
CommentGate uses YouTube API Services to moderate comments on YouTube channels our customers connect. By connecting a YouTube channel, you agree to the YouTube Terms of Service. Google's handling of your information is described in the Google Privacy Policy.
What we access
When the owner or manager of a channel connects it, they allow CommentGate to see and act on comments on that channel. We ask Google only for the youtube.force-ssl permission, because it is the only one that allows moderating and replying to comments. We read:
- The channel's name, handle, identifier and picture, to show which channel is connected.
- Comments and replies on the channel's videos and Shorts, including videos used in ads: the text, the time, the number of likes, whether YouTube is holding the comment for review or flagged it as likely spam, and the commenter's public name, handle, channel identifier and picture.
- The title, thumbnail, link, length and publish date of each video that receives a comment, so comments appear next to the video they belong to.
We do not upload, edit or delete videos, and we do not read anything else in the Google account: no email, no watch history, no subscriptions, and nothing about other channels beyond the public commenter details above. We do not use Google to sign anyone in.
How we use it
- To check each comment against the settings and rules the channel's team set, and to hold comments for review on YouTube, publish them again, or post replies, as those settings and the team decide.
- When someone on the team explicitly chooses "Remove and block on YouTube", to remove that comment and hide the author's future comments on the channel.
- To show comments, decisions and reports to the people the channel's owner invited to the brand, and to no one else.
What we store and share
We store the items above, our decision on each comment, the replies the team sent and the record of actions taken. We share YouTube data only with the service providers that help us provide these features: our hosting and database providers, and the classifier and language models that check a comment and draft a reply (see AI and automated decisions). Comment text can also appear in alerts the team chose to receive (email, Slack, Discord or webhooks). We never sell YouTube data, never use it for advertising, and never use it, or let our service providers use it, to develop, improve or train generalized AI or machine learning models. People at CommentGate do not read it unless you ask us to (for example, in a support request), it is needed to investigate security or abuse, the law requires it, or it has been aggregated and anonymized for internal operations.
How long we keep it
- Comment text and the commenter's name, handle and picture: cleared 30 days after the comment was written, including copies in reports and weekly insights. We keep the comment's identifier, our decision, the replies your team sent and the record of actions taken, so your reports and history still add up.
- Video titles and thumbnails: read again from YouTube once our copy is 7 days old and the video gets new comments, and cleared if not refreshed, so no stored copy is older than 30 days.
- Access to the channel: kept, encrypted, only while the channel is connected. It is revoked with Google and erased the moment you disconnect.
- Everything else about the channel (its name and picture, comments, replies, our decisions and the action record): deleted within 7 days of disconnecting the channel or removing CommentGate in your Google account.
Removing access
You can remove CommentGate's access in two ways:
- In CommentGate: go to Accounts, choose the channel, then Disconnect. We revoke access with Google straight away, stop reading the channel, erase the stored access, and delete the channel's data within 7 days.
- In your Google account: open the Google security settings page, find CommentGate and remove its access. We stop reading the channel as soon as Google refuses our next request, usually within an hour, and the channel shows as needing to reconnect. If nobody reconnects within 4 days, we delete the channel's data, within 7 days of the removal.
Comments that CommentGate held for review stay held on YouTube until someone publishes them again in YouTube Studio. To ask us to delete YouTube data sooner, see Data deletion. For questions about YouTube data, use the contact form.
Google API Services User Data Policy
CommentGate's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice this means we use YouTube data only to provide and improve the moderation features you see in CommentGate; we transfer it only as needed to provide those features, to comply with the law, for security, or as part of a merger or acquisition with notice to you; we never use or transfer it to serve ads, including retargeting, personalized or interest-based ads; we never sell it; we never use it to determine anyone's creditworthiness or for lending; and people read it only in the cases listed above.
11. Disconnecting and deleting
- Disconnect an account in CommentGate (Accounts, choose the account, Disconnect), or remove CommentGate in the platform's settings: tokens are deleted at once and everything we hold for that account within 7 days.
- Remove CommentGate from Facebook (Settings and privacy, Settings, Business integrations), Threads (Settings, Account, Website permissions), TikTok (Settings and privacy, Security, Manage app permissions) or Google (the Google security settings page).
- If you ask Meta to delete your data, Meta tells us, we delete your connection and the comments, replies and messages we hold that you wrote, and Meta gives you a confirmation code. You can check its status at any time on Data deletion by opening the link Meta gives you.
- Delete a brand (Settings, Brand, Delete brand) or your user account (Settings, Profile, Delete account) at any time.
- Anyone can ask us to delete their information through the contact form. Step-by-step instructions for each case are on Data deletion.
12. Security
We protect information with measures appropriate to the risk, including:
- Encryption in transit (TLS) everywhere, and encryption at rest by our database and hosting providers.
- Access tokens, integration keys and signing secrets encrypted by the application with AES-256-GCM, each bound to its own record. API keys and sign-in codes are stored only as one-way hashes, and sign-in codes expire after 10 minutes.
- No passwords to leak: sign-in uses one-time links and codes, passkeys or single sign-on. Two-step sign-in with an authenticator is available, and a brand can require it for everyone.
- Roles and per-account limits inside each brand, so team members and agency clients see only the accounts they were given, and an audit log of important actions.
- Rate limits on sign-in, the API and the MCP server; checks on replies that go out on their own; and verification of every webhook and callback from the platforms.
- Production systems run on managed, isolated infrastructure, with no office network or servers of our own. Access to production data is limited to the people who run the service, protected with multi-factor authentication, and used only to operate and support it.
- The code has been through a full security review, and dependencies are kept up to date.
No system is perfectly secure. If a breach affects your information, we will tell the affected customers without undue delay, tell the platform concerned where its terms require it, and notify the supervisory authority within 72 hours where the law requires.
13. Your rights
Everyone
Wherever you live, you can ask us for a copy of your information, to correct it, to delete it, or to receive it in a portable format, and to object to or restrict certain uses. Customers can export comments from Reports and people as CSV, and delete accounts, brands and most other data from Accounts and Settings at any time. For anything else, use the contact form and choose "Privacy or data deletion". We answer within one month (we may extend that by two more months for complex requests and will tell you if we do), and may need to confirm your identity first. We never treat you differently for using your rights.
If your information reached us through a brand that uses CommentGate, we act for that brand. We will pass your request to the brand and help it answer, or, where the brand asks us to or you ask us to delete your comments and details, do it for every brand that holds them.
EU, EEA and UK
You also have the right to object to processing based on legitimate interests, to withdraw consent at any time, and to complain to a data protection authority, in the country where you live or work or where you think the law was broken. Our lead authority is the Office of the Data Protection Ombudsman (Finland) (tietosuoja.fi). We would appreciate the chance to help first.
California and other US states
Residents of California, Colorado, Connecticut, Virginia, Texas and other states with privacy laws have the right to know what personal information we collect and how we use and disclose it, to access it, to delete it, to correct it, and to opt out of its sale, of sharing for cross-context behavioral advertising, and of profiling with legal or similarly significant effects. We do none of these, so there is nothing to opt out of. You can use an authorized agent, and we may ask them for proof that you gave them permission. If we deny your request, you can appeal by replying to our decision, and we will review it again and tell you the result and how to contact your attorney general.
In the last 12 months we collected these categories of personal information, from the sources and for the purposes described above, and disclosed them only to the service providers and on the customer instructions described in Who we share it with:
- Identifiers: name, email address, username, platform identifiers, phone number (WhatsApp), IP address.
- Commercial information: plan, invoices and payment history.
- Internet or electronic network activity: actions in the app, sign-in records, browser type.
- Audio, electronic or visual information: profile pictures as the platforms show them.
- Professional information: your role in a brand.
- The content of comments and direct messages sent to connected accounts.
We did not sell or share any of it. We do not collect sensitive personal information for the purpose of inferring characteristics about anyone, and we do not use it for anything beyond what the law permits. We do not knowingly sell or share the personal information of anyone under 16.
Other countries
Residents of other countries with data protection laws, such as Brazil's LGPD, Canada's PIPEDA, Australia's Privacy Act and Japan's APPI, can use the same channel, and we honor the same rights.
15. Children
CommentGate is a service for businesses. Customers must be at least 18, and the service is not directed at children. We do not knowingly collect information from children under 16 as customers; if you believe a child has created an account, tell us through the contact form and we will delete it. Comments and messages we process may come from anyone the platforms allow to use them (the platforms themselves set a minimum age of 13), and we handle them only on our customers' behalf.
17. Changes to this policy
If we make material changes, we will tell customers by email or in the app before they take effect, and update the date at the top of this page. If a change means we would use platform data in a new way, we will ask the platform for approval first where its terms require it.
18. Contact
The controller is CROapps Oy, Pohjoinen Rautatiekatu 29B, 00100 Helsinki, Finland. Business ID 3550932-5, VAT number FI35509325.
For privacy questions and requests, including questions about data we receive from Meta, TikTok or Google, use the contact form and choose "Privacy or data deletion". A person reads every message. Our data protection contact is responsible for answering them and can be reached the same way.