FFB Invite Assistant
How it worksPlansSign in
Legal · version 2026-08-31

Privacy Policy

Effective and last updated: 31 August 2026

This policy explains how FB Invite Assistant handles personal data through the website, subscription service, and Chrome and Firefox browser extensions.

Operator and contact details are available on the Legal information page.

1. Data handled by the extension

The extension reads the reaction type and Invite-button state rendered inside the Facebook reaction dialog you open. This processing happens locally in your browser. We do not receive or store Facebook passwords, cookies, profile names, profile URLs, reaction lists, page content, or the identities of people you invite.

Browser extension local storage keeps your settings, policy acknowledgement, generated installation identifier, license information, signed entitlement, learned Like/Love icon identifiers, and local session/daily counters. You can remove this local data by removing the extension or clearing its storage.

2. Account, license, support, quota, and billing data

We process your email address, email-verification status, plan, license-key hash and last four characters, hashed installation identifier, activation and last-seen timestamps, and device-slot history. To prevent repeated Free or trial claims, we also derive a keyed, non-reversible hash from a normalised email identity; this lets us recognise common aliases without storing that normalised address as a separate readable value. If you contact authenticated support, we store the ticket category, subject, messages, status, and timestamps, linked to your account. Do not include passwords, magic links, full card details, complete license keys, or third-party personal data in a ticket. For the Free plan, we store only the UTC date and total number of assisted invites used that day; we do not store who was invited or the post involved. For paid plans, we also process Stripe customer/subscription identifiers, subscription status, billing period, and contractual-email delivery evidence such as recipient, status, content hash, provider message identifier, and delivery timestamp. Stripe processes payment-card and payment-method details; we do not store full card details.

3. Authentication, acceptance, security, and website analytics

We process hashed sign-in tokens, hashed session and CSRF tokens, session timestamps, security-event records, and limited event metadata such as plan type or Stripe Checkout identifier. We use keyed hashes of the requesting IP address and installation identifier to limit rapid benefit claims across accounts and to prevent one installation from repeatedly claiming Free. These keyed hashes do not retain the raw IP address or installation identifier. When you accept legal terms or confirm a purchase, we also retain the policy version, plan, scope and time of acceptance, the relevant Checkout or plan-change identifier, contractual-confirmation status, and a keyed hash of the browser user-agent. Essential session and CSRF cookies are used for sign-in and account security.

If you select “Accept analytics”, Google Analytics 4 processes website usage information such as pages viewed, approximate location, device and browser characteristics, referral information, and interactions with the website. Google Analytics is not loaded and sends no data before you consent. We disable advertising storage, ad personalisation, ad user data, and Google Signals. You can reject analytics initially or withdraw consent at any time through Cookie settings in the footer. See the Cookie Policy for the cookies, durations, and controls.

4. Purposes and lawful bases

  • Contract: create and operate your account, subscription, license, device slots, billing portal, and support.
  • Consent: measure website use and improve the website through optional Google Analytics. Refusing or withdrawing analytics consent does not affect access to the service.
  • Legitimate interests: prevent fraud and abuse, secure accounts, diagnose failures, and maintain the service. You may object to this processing; we will assess your request against our compelling legitimate grounds.
  • Legal obligation: retain and disclose records where tax, accounting, consumer, or other law requires it.

5. Service providers and disclosures

We share only the data necessary with Stripe for payments and subscriptions, Resend for transactional sign-in, account, support, and contractual email, Google for consent-based website analytics, and our hosting/infrastructure providers for operating the service. Google Analytics is configured without advertising features and is not loaded until you accept analytics. We may disclose data to professional advisers, regulators, courts, or law enforcement where legally required, and to a successor if the business is reorganised or sold subject to appropriate safeguards. We do not sell personal data or use it for personalised advertising.

6. International transfers

Some providers may process data outside the UK. Where UK data-protection law requires it, we rely on an adequacy regulation or appropriate contractual and organisational safeguards. Contact us for information about safeguards relevant to your data.

7. Retention

  • Unused or expired magic-link records and expired/revoked web sessions are deleted shortly after expiry, normally within seven days.
  • Security audit records and processed Stripe-event identifiers are retained for up to 12 months.
  • Support tickets are normally retained for up to 24 months after closure so we can follow recurring problems and complaints. Relevant records may be kept longer where reasonably necessary for a legal claim or regulatory duty.
  • Versioned legal-acceptance and order records may be retained for up to six years after the relevant contract or account ends, where reasonably necessary to establish the agreement, respond to disputes, or meet legal and accounting duties.
  • Account, subscription, and license records are kept while the account or subscription is active and afterwards only as needed for disputes, fraud prevention, and legal, tax, or accounting duties, normally no longer than six years.
  • Stripe and other providers apply their own legally compliant retention schedules.

8. Your rights

Depending on the circumstances, you may request access, correction, erasure, restriction, portability, or object to processing. You may also complain to the UK Information Commissioner's Office. These rights are not absolute; we may retain data where law requires it or where we have a valid legal ground. Contact us using the Legal information page. We may verify your identity before acting.

9. Browser extension store policies

The Chrome version adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. The Firefox version adheres to Mozilla's Add-on Policies and declares its required data transmission in the installation flow. In both versions, extension data is used only to provide and secure the single disclosed purpose of assisting with eligible Invite buttons in an open Facebook reaction dialog.

10. Security and changes

We use access controls, hashing, signed short-lived entitlements, HTTPS in production, restricted infrastructure, and other safeguards appropriate to the service. No system is completely secure. We will publish material changes here and, where required, provide notice or request a renewed acknowledgement.

How it worksFAQPrivacyCookiesTermsRefundsSupportLegal information
Your privacy

Choose your cookie settings

We use essential cookies to keep your account secure. With your permission, Google Analytics helps us understand which pages are useful. Analytics stays completely off unless you accept.

See cookie details