Privacy Policy

Last updated: [DATE]

Who we are

XinConnect is operated by Talent Reform Consulting Sdn. Bhd., 202401034083 (1579931-K), of No 22 Jalan USJ 3C/7, 47610 Subang Jaya, Selangor, Malaysia, Malaysia. We provide software that businesses use to publish social media content and to reply to comments and messages from their own customers.

For the personal data of a business's customers, that business is the data controller and we act as their data processor under the Malaysian Personal Data Protection Act. We process that data only on their instructions.

What we collect

  • Account details of the people who use XinConnect: name, email address, and a hashed password.
  • Connected social accounts: the identifier and name of each Facebook Page, Instagram account, TikTok account or YouTube channel you connect, and an access token which we store encrypted. The YouTube section below lists that platform's fields one by one.
  • Conversation content: public comments and private messages sent to your connected accounts, including the sender's display name and platform identifier, so that we can show them to you and help you reply.
  • Content you provide: product information, prices, answers and documents you add so the service can reply accurately on your behalf.
  • Operational records: logs of actions taken in the service, kept so we can answer questions about what was sent and when.

How we use it

  • To show you the comments and messages your accounts receive.
  • To send replies that you or your configured automation authorise.
  • To publish content you schedule.
  • To keep the service secure, prevent abuse, and diagnose faults.

We do not sell personal data. We do not use your customers' messages to train any general artificial intelligence model.

Automated replies

Where you enable automated replies, messages are processed to generate a suggested or automatic response. By default the first automated message in a direct message thread says that it came from an automated assistant, and it says so again after a long quiet spell and whenever a person hands the thread back to the assistant. A public reply left under a post does not carry that line, because it is not a conversation with any one person; and a message a member of staff reads and sends themselves is never labelled as automated, because it is not.

A person is always reachable behind it. Anything that reads as an order, a complaint, a negotiation over price, or anything the assistant is not confident about is passed to a person in the business rather than answered automatically, and a person can take over a conversation at any point. You can switch automation off at any time, for one channel or for all of them.

Cookies and what we store on your device

XinConnect sets cookies that the service cannot work without, and no others. There is no advertising cookie, no analytics cookie and no third-party tracker on any page of this site or of the app.

  • xc_session — set when you sign in and read on every request afterwards, so the service knows which workspace you are in. It holds a signed token, not your password, it cannot be read by scripts in the page, and it lasts 14 days or until you sign out.
  • xc_oauth_state, xc_youtube_oauth_state, xc_tiktok_oauth_state and xc_whatsapp_signup_state — written when you start connecting an account and read once when the platform sends you back, so that a connection can only be completed by the person who began it. Each lasts ten minutes — the WhatsApp sign-up one thirty, because its consent flow has more screens — and is discarded as soon as it has been used.

Who we share it with

  • Cloud hosting and database providers who store the data on our behalf.
  • Artificial intelligence providers who generate reply text. Before message text leaves our systems we remove phone numbers, identity card numbers, email addresses, postal addresses, personal names, order numbers and links from it, and put them back into the reply afterwards.
  • The social platforms themselves — Meta, TikTok, Google — when we send a reply or publish a post at your instruction.

Facebook and Instagram

When you connect a Facebook Page through Facebook Login, XinConnect also connects the Instagram professional account linked to that Page. You choose which Pages to share in Facebook's own dialog, and XinConnect receives only the Pages and permissions you grant there. For each connected Page and Instagram account we store:

  • the Page id and name, and the Instagram account id and @username;
  • a Page access token, encrypted before it is written down;
  • the Facebook user id of the person who connected it, so that a deletion or disconnection request Facebook sends us on that person's behalf can be matched to what they connected;
  • the comments left on the Page's posts and the Instagram account's media, and the messages sent to the Page or the Instagram account — with each sender's name and the page-scoped id Meta assigns them — so they can be shown in your inbox and answered;
  • when someone opens a conversation through one of your tracked Messenger or Instagram links, the reference on that link, so you can see which link the conversation came from.

This data is used only to show you your own comments and messages and to send the replies that you or your automation authorise. It is never used for advertising, never sold, and never shared with data brokers. If you choose to connect a Meta Conversions API dataset under Settings → Ad reporting, XinConnect sends the conversions you record to that dataset of your own; nothing is sent there unless you set it up.

Removing access. Under Settings → Connections → Disconnect you can remove a Page or Instagram account yourself; that deletes it and everything stored from it — the comments, the conversations and the token — as soon as you confirm, and asks Facebook to stop sending that Page's events to us. You can also remove XinConnect from your Facebook account's Business integrations settings, after which we stop using its connections; and a data deletion request made through Facebook deletes them and gives you a confirmation code you can check on our data deletion page, which also explains what to do if you messaged a business that uses XinConnect.

YouTube API Services

XinConnect uses YouTube API Services. When you connect a YouTube channel, we read the comments left on that channel's videos so we can show them to you and help you reply, and we upload videos you schedule to that same channel. Google's own handling of the data it receives is described in the Google Privacy Policy, and by using these features you also agree to be bound by the YouTube Terms of Service.

For a connected YouTube channel we store:

  • the channel id, the channel title and the channel's @handle;
  • the text of comments left on that channel's videos, and the display name of the person who left each one;
  • the comment thread id and the video id each comment belongs to;
  • an OAuth refresh token, encrypted before it is written down, so that replying and publishing keep working without asking you to sign in again;
  • the record of the channel owner's consent to have comments replied to automatically — who gave it, when, and the wording they were shown — for as long as that consent stands.

Comment text and message text — from YouTube and from every other connected platform — is sent to a third-party artificial intelligence provider so the service can generate a suggested reply. It is stripped of the identifying details listed above before it is sent. Stored YouTube data is deleted or refreshed within 30 days, as the YouTube API Services Terms of Service require.

Revoking access. You can remove a connected channel yourself at any time in XinConnect, under Settings → Connections → Disconnect. That deletes the channel and everything stored from it — the comments, the conversations and the token — as soon as you confirm it. Separately, you can revoke XinConnect's access to your data via the Google security settings page at https://security.google.com/settings/security/permissions. If you would rather ask us, write to xin-social@xininsight.com and we will action a YouTube deletion request within seven calendar days.

Transfers outside Malaysia

Some of these providers process data outside Malaysia. Where that happens we rely on contractual safeguards with the provider and, where required, your consent. We assess each destination before using it. [CONFIRM WITH COUNSEL BEFORE LAUNCH — see the transfer impact assessment.]

How long we keep it

  • Account details: while your account is open, and up to 90 days afterwards.
  • Conversation content: while your account is open, unless you delete it sooner.
  • YouTube data: deleted or refreshed within 30 days, as required by the YouTube API Services Terms of Service.
  • Operational logs: up to 12 months.

Your rights

You may ask us to give you a copy of your personal data, correct it, or delete it. Write to us at the address below and we will respond within the period required by law.

If you interacted with a business that uses XinConnect and want your data removed, see our data deletion page.

Security incidents

If personal data is compromised we will notify the Personal Data Protection Commissioner within 72 hours of becoming aware, and affected individuals within 7 days where there is a risk of significant harm.

Contact

Questions or complaints about privacy, including anything on this page, go to our data protection contact:

[DATA PROTECTION CONTACT NAME]
xin-social@xininsight.com · [PHONE]
No 22 Jalan USJ 3C/7, 47610 Subang Jaya, Selangor, Malaysia