Privacy Policy
Y&A Co., Ltd. ("Y&A") provides YA Social Sync for business users. This policy explains the information we collect, use and retain through the service and how we protect it.
Information we process
- Name, company name, email address, language preference, account and login/security information.
- Subscription term, licensed locations, pricing, payment status, agent attribution and coupon-use records. Card details are processed by Stripe and are not stored by YA Social Sync.
- Information required for synchronization from an Instagram Professional account that the customer explicitly connects and authorizes, such as account identifiers, captions, media and post IDs.
- Connected Google Business Profile account/location identifiers and synchronization results.
- Security and operational information such as encrypted/pseudonymized IP evidence, audit logs, error logs and webhook events.
How we use information
We use information to provide accounts, verify users and subscriptions, manage billing and renewals, synchronize authorized Instagram content to Google Business Profile, provide support, troubleshoot, prevent abuse, secure and audit the service, and meet legal, accounting or dispute obligations. We do not sell or share customer data for unrelated advertising purposes.
Service providers and sharing
We use providers such as Meta/Instagram, Google, Stripe, hosting providers and email delivery providers only as needed to operate the service. Their own terms and privacy policies apply to their processing. Y&A does not disclose personal information to unrelated third parties except where required by law, necessary to protect rights or safety, or directed/authorized by the customer.
Agents and access isolation
Agents can access only referred-client and commission data scoped to their authenticated agent ID. They cannot access another agent’s identity, pricing, coupons, clients, payments or settlements and cannot view client OAuth tokens. Clients cannot access another client’s or agent’s private data.
Retention
Account and integration information is retained while needed to provide the service. After termination or a deletion request, records that must be kept for legal, accounting, security, fraud-prevention, audit or dispute purposes are retained only as necessary; other deletable information is removed or anonymized.
Security
Passwords are one-way hashed. Sensitive data that the service must later use, including email addresses and OAuth access/refresh tokens, is protected with authenticated encryption. We also use role-based authorization, CSRF protection, rate limiting, audit logging and webhook-signature verification.
Your choices and deletion
Instagram or Google Business Profile can be disconnected from the Connections page. See the Data Deletion page for instructions to request deletion of integration or account data. View Data Deletion
Contact
Y&A株式会社
contact@yanda.ooo