Shoot to Social

Privacy Policy

Last updated: 1 October 2026

This policy explains what personal data Shoot to Social handles, why, who receives it and what you can do about it.

1. Who is responsible

The data controller is Better Quality Assurance S.R.L. (BetterQA), registration RO39687318, Strada Transilvaniei 202, Baciu 407055, Cluj County, Romania. Contact: brad@betterqa.co.

2. What we collect

From the Telegram chats that use the bot. The Telegram chat ID; the Telegram file identifiers of the photos, videos and voice notes you send; the photos and videos themselves while they are being published; the text you type to describe a job; and, if you describe it by voice, a written transcript of the voice note. We do not keep the voice recording itself.

From the business's website administration. Some businesses also send posts from their own website's admin area. In that case we receive links to the photos or videos, the captions and the platforms to publish to.

What the service produces. The captions it writes for each platform, the list of platforms a post goes to, and a publishing record for each platform: whether it succeeded, the ID or link of the published post, and any error message.

From the connected platforms. For Facebook and Instagram: the ID of the business's Facebook Page and of its Instagram account, a Page access token and the token's expiry date. For TikTok: see section 6.

What appears in the content. Photos and videos can show people, number plates or documents. We do not analyse images to identify anyone, but whatever is in a picture you send will be published where you sent it.

3. Why we use it, and on what legal basis

We do not sell the data, use it for advertising or build profiles from it.

4. Who receives it

Some of these providers are based outside the European Economic Area, for example in the United States.

Photos sent to the website gallery are public: they appear on the business's own website.

5. How long we keep it

6. TikTok

When a business connects TikTok, it logs in on TikTok's own page and approves these permissions (scopes):

From TikTok we store the account's open ID and username, the access token and refresh token, and their expiry dates. The tokens are encrypted. We do not read the account's followers, messages, viewing history or other videos.

Videos arrive in the TikTok inbox as drafts. The account owner chooses who can see each one and posts it from the TikTok app. If they never post it, it stays a draft. For a post made only of photos, the service first asks TikTok which visibility settings the account allows and uses one of those. TikTok fetches the photos from a temporary public copy, which we delete once TikTok has finished.

You can stop the service's access to TikTok in two ways: remove Shoot to Social from the apps connected to your account in TikTok's settings, or email us. When we disconnect an account, we delete the stored TikTok data and ask TikTok to revoke the token.

7. Security

Access tokens for every platform are encrypted with AES-256-GCM before they are stored. Only Telegram chats we have explicitly allowed can use the bot. Connections to the platforms use HTTPS.

8. Your rights

Under the GDPR you have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to how we use it, and to receive it in a portable form. To use any of these rights, email brad@betterqa.co. We will answer within one month.

You also have the right to complain to the Romanian data protection authority, the National Supervisory Authority for Personal Data Processing (ANSPDCP), at www.dataprotection.ro.

9. Changes

If the service starts handling data differently, we will update this policy and the date at the top.

10. Contact

Questions about this policy or your data: brad@betterqa.co.