App privacy policy
Last updated · 29 September 2026
This policy covers the MorePanache app, the tool real estate and brokerage professionals use to write, illustrate, schedule and publish their social media content. Data collected through the morepanache.com website is covered by a separate policy.
01Data controller
The app is published by MOREpanache, the communication and digital marketing studio run by Vincent Herbelet. It is a sole proprietorship based in Amsterdam, registered with the Amsterdam Chamber of Commerce under KVK 59874929 (VAT NL002443736B35). Address: Prins Hendrikkade 21e, 1012 TL Amsterdam, the Netherlands. For any privacy-related question, write to hey@morepanache.com.
02What we process
- Account data. Title, first name, last name, business email address, phone number, agency and city, as well as the date of last sign-in. This identifies the user, links them to their agency and allows us to send the messages the service requires; the date of last sign-in is used to delete unused accounts.
- Content created. Text, visuals and posts written or generated in the app, including uploaded photographs. This content may include images of properties and, where the user chooses to publish them, client testimonials.
- Social media connection data. When a user connects their agency's accounts, we store the Facebook Page ID, the associated Instagram professional account ID, their display names, and an access token issued by Meta. That token allows us only to publish to those accounts and to read their statistics.
- Usage statistics. We record the actions performed in the app (generating a text or a visual, importing a listing…), with their author and date, without IP address, to measure use of the service and its cost. After 13 months, they are linked to the agency only.
- Publishing statistics. Follower counts, reach and engagement, collected periodically from Meta. These measurements are aggregated at page level and do not identify any individual.
- Activity logs. For security and traceability, we keep a record of actions performed in the app — publishing, scheduling, editing, cancelling, connecting a social account — with their author, date and originating IP address.
- Support messages. When a user sends a suggestion or reports a problem from within the app, we receive their message together with their name, email address, agency, the page they were on and their browser type, so that we can reply and reproduce the problem.
- Rights requests. When a user asks for their account to be deleted, we keep a record of the request and of how it was handled: date, account identity, and any reason given.
What we do not access. Neither your pages' private messages, nor your contact list, nor your followers' personal data. Access tokens are encrypted before being stored.
03Legal bases
| Purpose | Legal basis |
|---|---|
| Providing the service and managing the account | Performance of a contract |
| Publishing to the agency's social media accounts | Performance of a contract |
| Security, logging, abuse prevention | Legitimate interest |
| Measuring use of the service | Legitimate interest |
| Service-related notifications | Performance of a contract |
| Replying to suggestions and problem reports | Legitimate interest |
| Handling rights requests | Legal obligation |
| Invoicing and accounting obligations | Legal obligation |
04Recipients and processors
We do not sell any data and never pass it on for advertising purposes. The following providers act on our behalf:
| Provider | Role | Hosting |
|---|---|---|
| Infomaniak | Hosting of the app, its database, its files and their backups; sending the service's emails | Switzerland |
| Meta Platforms | Publishing to Facebook and Instagram, audience measurement | Outside the European Union |
| Anthropic | Text generation from the instructions entered by the user | Outside the European Union |
| Pexels | Royalty-free image library. Searches and image display go through our servers: Pexels receives only the keywords entered, with no personal data | Germany |
Switzerland is recognised by the European Commission as providing an adequate level of protection. Transfers to the other providers rely on the European Commission's standard contractual clauses.
No payment provider is involved at this stage: subscriptions are invoiced directly by the publisher. Should a payment provider be introduced, this page will be updated before it goes live.
05Retention periods
| Data | Period |
|---|---|
| User account and associated content | For as long as the account is used. After 12 months without sign-in, a warning email is sent; without a new sign-in, the account is deleted 14 months after the last sign-in. When the subscription ends, content remains exportable for 30 days, then is deleted |
| Social media access tokens | Deleted as soon as the social account is disconnected or the user account is deleted |
| Temporary copies of visuals exposed for publishing | A few minutes, purged automatically after upload |
| Publishing statistics | 3 years |
| Activity logs | 12 months |
| Usage statistics | Linked to the account for 13 months, then to the agency only; deleted after 10 years |
| Support messages | 12 months |
| Rights requests | 3 years after they are closed |
| Backups | 30 days, with a secondary copy on a second Infomaniak hosting service in Switzerland |
| Accounting records | 10 years (legal obligation) |
06Publishing visuals
For a visual to be published, Meta's servers must download it themselves. A temporary copy is therefore made available on our domain, under a random, non-guessable file name, for the duration of the upload — a few minutes at most. That copy is deleted as soon as publishing succeeds or fails. The original remains privately stored.
07Withdrawing the Facebook authorisation
Disconnecting a social account from within the app permanently deletes the access tokens we hold: we can then no longer publish or read anything.
The authorisation nonetheless remains recorded in the account holder's Facebook settings, which only they can change, under Settings & privacy › Settings › Business integrations.
08Your rights
You have the right to access, rectify, erase, restrict, object to the processing of, and port your data. You can exercise these rights at hey@morepanache.com. We respond within one month.
To delete your account and all associated data, request it from the My account page in the app, or follow the procedure described on the Data deletion page. You will receive an acknowledgement, then a confirmation once the deletion has been carried out.
You may lodge a complaint with a data protection authority. As the publisher is established in the Netherlands, the lead authority is the Autoriteit Persoonsgegevens. If you reside in another EU member state, you may equally contact your own country's authority: the Regulation leaves that choice to you.
09Security
Traffic is encrypted over HTTPS. Social media access tokens are encrypted before storage. Passwords are stored as non-reversible hashes. Access to an agency's data is restricted to the members of that agency.
10Cookies
The app uses a session cookie, strictly necessary for the service to work: it keeps the user signed in. It serves no analytics or advertising purpose, and therefore requires no prior consent. No other cookie is set.
The app's fonts are hosted on our own servers: displaying them involves no connection to any third-party service.
11Changes
This policy may change. Any substantial change is communicated to users by email before it takes effect. The date at the top of the page always indicates the version in force.
