Skip to content

Privacy policy.

Last updated

Vitraz helps you display content you already publish. This page explains what we collect to do that, why we collect it, and what control you have.

Who we are

Vitraz (“we”, “us”) is a hosted service for collecting, curating and embedding social content and reviews, operated by INNOVATION FACTORY DOO. For data protection purposes we are the controller of the account data described below, and a processor of the content you choose to aggregate.

The controller is:
INNOVATION FACTORY DOO KRALJEVO, registered under the abbreviated business name INNOVATION FACTORY DOO
Heroja Maričića 93
36000 Kraljevo, Serbia
Company registration number: 22050494
Tax identification number (PIB): 114640955

You can reach us about anything on this page at hello@vitraz.io.

What we collect

Account data

When you sign up we store your name, email address, hashed password (or the identifier from your Google sign-in), and your workspace name. This is necessary to give you an account.

Content you connect

When you connect a source we retrieve the public posts, reviews and videos that source exposes, along with their authors’ public handles, avatars and timestamps. We store this so your feed can render without calling the network on every page view.

Connected account credentials

Instagram, Facebook and LinkedIn require the account holder to grant access before anything can be read. When they do, we store the access token that grant produces, any refresh token, its expiry, the permissions actually granted, which account was chosen, and an identifier for the person who authorised us. Tokens are encrypted before they are written to the database, and they are never sent to the browser.

We use these only to read the account’s own posts for display in the feeds you build. We do not post, message, follow, advertise or change anything, we do not use this data to build profiles of people, and we do not sell it or share it with data brokers.

An X account, hashtag or mention uses an application token rather than anyone’s login. We read public posts matching the handle, tag or @mention you chose, store those posts for your feed, and do not follow, message or profile the authors.

Data from Meta

Data obtained through Instagram or Facebook is handled in line with Meta’s Platform Terms and Developer Policies, including their limited use requirements. It is used solely to provide the feed feature the account holder consented to, is kept only while that connection is live, and is deleted when the connection is removed. See deleting your data.

Usage data

We count how many times your embedded feeds are viewed, so we can apply plan limits and show you analytics. To count a viewer once per day rather than once per page load, we derive a one-way hash from the viewer’s IP address and browser user-agent. We do not store the IP address itself, and the hash cannot be reversed to identify anyone.

On vitraz.io itself, and inside the application once you sign in, we use PostHog to see which pages are visited and which features get used. Once you are signed in we attach your account to that measurement, so we can tell how the product is actually used rather than only counting anonymous visits. It runs on our site only, never on embedded feeds on your visitors’ sites.

Billing data

Payments are handled by Dodo Payments, who act as merchant of record. We never see or store your card details, only a customer reference, your plan, and its status.

Why we’re allowed to use it

  • To perform our contract with you: running your account, fetching your sources, serving your embeds, taking payment.
  • Legitimate interests: keeping the service secure, preventing abuse, and understanding aggregate usage so we can improve it.
  • Legal obligation: retaining billing records for as long as tax law requires.

Who we share it with

We do not sell your data. We share it only with the providers needed to run the service:

  • Supabase: database, authentication and file storage.
  • Railway: application hosting and content delivery.
  • Vercel: DNS for vitraz.io.
  • Dodo Payments: payment processing and invoicing.
  • PostHog: product analytics on vitraz.io and inside the application, processed on PostHog’s EU infrastructure. PostHog’s privacy policy applies to that processing.
  • Cloudflare: analytics requests reach PostHog through data.vitraz.io, a subdomain we control, and Cloudflare carries that traffic on PostHog’s behalf.
  • The networks you connect: when you link an account, that network receives the request and applies its own privacy policy to it.

Cookies

The session cookie that keeps you signed in is required for the application to function. On vitraz.io, PostHog sets a cookie (ph_<project token>_posthog) so a returning browser is recognised across pages and we can tell which pages are used. We do not run advertising cookies. Embedded feeds on your visitors’ sites set no cookies at all.

How long we keep it

Account and content data lives for as long as your account is open. Delete your account and we remove your workspace, feeds, sources and collected posts. Aggregated view counts that cannot identify anyone may be retained. Billing records are kept for the period tax law requires.

Access tokens for connected accounts are kept only while the connection exists. Removing the connection here, or removing Vitraz from your Instagram or Facebook settings, deletes the token immediately. When the account holder asks Meta to delete their data we also remove every post imported through that connection, and keep only a record that the request happened: a confirmation code, the date, and a count, so the code stays resolvable. That record holds no profile information. Full detail is on the data deletion page.

Your rights

Depending on where you live you may have the right to access, correct, export, restrict or delete your personal data, and to object to processing based on legitimate interests. You can edit or delete your account directly in Settings, or write to hello@vitraz.io and we will respond within 30 days. If you are in the EEA or UK and are unhappy with our response, you may complain to your local supervisory authority.

International transfers

Our providers may process data outside your country, including in the United States. Where that happens we rely on the transfer mechanisms those providers put in place, such as Standard Contractual Clauses.

Children

Vitraz is a business tool and is not directed at children under 16. We do not knowingly collect their data.

Changes

If we make a material change to this policy we will update the date at the top and notify account holders by email before it takes effect.