InPoint
Back to home

Legal information

Privacy Policy

This document explains how InPoint collects, uses, stores, and protects personal data.

Last updatedJuly 29, 2026
01

General Information

This Privacy Policy explains how the InPoint platform collects, uses, stores, and protects personal data.

Platform operator
Legal name
Individual Entrepreneur Nika Melkoniani
Brand
InPoint
Website
inpoint.ge

In this Policy, “InPoint,” “we,” or the “Platform” means the operator identified above.

02

InPoint’s Role in Data Processing

InPoint is the data controller for information that we process in order to:

  • create an InPoint user account;
  • administer the Platform;
  • provide security, technical support, and service improvements;
  • fulfil contractual and legal obligations.

When processing messages received on a partner business’s Facebook Page, customer orders, recipient data, and delivery information, the relevant partner business determines the purposes and legal basis for collecting the data. In these cases, InPoint processes the data on the partner business’s instructions in order to provide the Platform’s functionality.

The partner is responsible for obtaining and using its customers’ data lawfully and for providing those customers with appropriate information about the processing of their data.

03

Data We Collect

3.1. Account and business data

We may process:

  • first and last name;
  • email address;
  • telephone number;
  • company, store, or business name;
  • user role and permissions;
  • authentication and account security information;
  • Platform settings and activity history.

3.2. Facebook and Messenger integration data

When a Facebook Page is connected to InPoint, we may receive and process:

  • technical identifiers for the Facebook user and Page;
  • the Facebook Page name;
  • the list of Pages selected by the user;
  • permissions granted to the integration;
  • an encrypted Page Access Token;
  • webhook subscription and integration status;
  • Messenger conversations, message text, and attachments;
  • the sender’s name, profile picture, and platform identifier;
  • message time, status, and technical metadata.

InPoint does not receive or store a user’s Facebook password.

Independent processing of data by Facebook and Meta is governed by Meta’s own terms and privacy policy.

3.3. Order and delivery data

A partner or its customer may provide the Platform with:

  • the recipient’s first and last name;
  • telephone number;
  • delivery address and location details;
  • a description of the order or parcel;
  • the amount payable and payment status;
  • delivery time, status, and history;
  • comments intended for the courier or operator;
  • communications between the customer and the partner.
Full payment card details, passwords, or other secret authentication data must not be entered in Messenger messages or order comments.

3.4. Technical data

For security and operation of the Platform, we may process:

  • IP address;
  • browser and device data;
  • technical session and cookie identifiers;
  • login and security events;
  • technical records of errors, requests, and API operations.
04

Sources of Data

We receive data from:

  • InPoint users directly;
  • partner businesses;
  • Facebook Pages connected by partners and Meta APIs;
  • Messenger messages sent by a partner’s customers;
  • order and delivery processes;
  • the Platform’s technical and security logs.
05

Purposes of Data Processing

We process data for the following purposes:

  • user registration and authentication;
  • connecting and managing a Facebook Page;
  • receiving and displaying Messenger messages in the InPoint Inbox;
  • sending replies to customers through Messenger;
  • converting a message into an order;
  • managing orders, inventory, finances, and deliveries;
  • providing courier services;
  • customer support;
  • preventing fraud, unauthorised access, and security incidents;
  • improving the system and diagnosing errors;
  • fulfilling contracts and obligations imposed by law;
  • establishing, exercising, or defending legal claims and rights.

InPoint does not sell personal data and does not use the content of Messenger messages for third-party advertising purposes.

07

Who We May Share Data With

Data may be shared only to the extent necessary to provide the service with:

  • the partner business and its authorised employees;
  • a courier or courier service provider;
  • Meta Platforms in connection with Facebook and Messenger integrations;
  • hosting, database, security, and technical infrastructure providers, including Render, Vercel, and Supabase;
  • professional advisers, auditors, or lawyers;
  • a court, investigative body, or other competent authority where required by law;
  • a business successor in the event of a sale, reorganisation, or transfer of assets, subject to appropriate privacy safeguards.

Service providers are given access to data only as necessary to perform their functions and subject to appropriate security obligations.

08

International Data Transfers

Some of InPoint’s technical providers may store or process data outside Georgia.

In such cases, we seek to use appropriate contractual, organisational, and technical data protection measures and transfer only the data necessary to provide the service.

09

Data Retention Period

We retain data only for as long as necessary to:

  • provide the service;
  • perform functions requested by a partner;
  • investigate security incidents;
  • comply with financial, tax, or other legal obligations;
  • establish or defend legal claims.

A Facebook Page Access Token is stored in encrypted form and used only for integration with the connected Page. When the integration is disconnected, the relevant access is revoked or deleted, except for information that must be retained by law or for security purposes.

After an account or data is deleted, some information may remain temporarily in protected backups until the backup is replaced as part of the normal backup cycle.

10

Security

We use appropriate technical and organisational measures to protect data, including:

  • encrypted HTTPS connections;
  • encrypted storage of Facebook Page Tokens;
  • role- and permission-based access;
  • authentication and session protection mechanisms;
  • security logs and monitoring;
  • redaction of secret data in logs;
  • restricted employee and system access.

No electronic system is completely secure. If we discover a security incident, we will act in accordance with applicable law.

11

Your Rights

To the extent provided by applicable law, a data subject may request:

  • information about personal data processed about them;
  • access to or a copy of their data;
  • correction of inaccurate or incomplete data;
  • cessation, blocking, or restriction of data processing;
  • deletion of data;
  • withdrawal of consent;
  • information about data transfers;
  • information about automated decision-making, if used;
  • the right to challenge the lawfulness of data processing.

To fulfil a request, we may need to verify the applicant’s identity and their relationship to the relevant data.

12

Deleting Facebook Data and Your Account

A user can disconnect the Facebook integration from the InPoint integrations page.

To request deletion of data, the user must email us at:

Subject“Personal Data Deletion Request”

The email must state:

  • the email address associated with the InPoint account;
  • the name of the connected business or Facebook Page;
  • the specific data the user wants deleted.

After confirming the request, we will delete or anonymise the data in accordance with applicable law, except where retention is required by law, for security purposes, or to defend legal claims.

13

Partner Business Responsibilities

A partner must:

  • process through the Platform only data obtained lawfully;
  • provide customers with the required information about data processing;
  • keep its employees’ accounts and passwords secure;
  • not use InPoint for spam, unlawful surveillance, or infringement of customer rights;
  • not upload special-category or other particularly sensitive data without an appropriate legal basis and security measures;
  • notify us immediately of unauthorised access or a potential security incident.
14

Minors

InPoint is intended for businesses and their authorised representatives and is not intended for independent use by minors.

If we discover that a minor’s data has been processed without an appropriate legal basis, we will take steps to delete it.

15

Cookies and Session Data

InPoint may use essential cookies and similar technologies to:

  • authenticate users;
  • maintain a secure session;
  • protect against CSRF and other attacks;
  • remember user settings;
  • identify technical problems.

Disabling essential cookies may prevent some or all of the Platform from functioning.

16

Changes to this Policy

This Policy may be updated periodically to reflect changes to the Platform, applicable law, or our data processing activities.

If there is a material change, the updated version will be published on the InPoint website and the “Last updated” date will be changed.

17

Complaints and Contact Information

For privacy-related questions or requests:

contact@inpoint.geBrand: InPoint