Wellness CRM — Privacy Policy
Effective date: 6 October 2026
Who we are
Wellness CRM is operated by ИП Монастырская Жанна Феликсовна (individual entrepreneur) in the Russian Federation. For privacy questions and data deletion requests, contact zhanna.monas@yandex.ru.
Wellness CRM helps customers manage professional Instagram account interactions, contacts, messages, comments, automations, campaigns and activity analytics. We process customers' service-account information to provide the service. Customers are responsible for the lawful use of contact information, messages and automations connected through their Instagram accounts. We process Instagram data only to support functions initiated or configured by the customer through the service.
Information we collect
We process the following information, depending on the functions used and the information available through Meta:
- CRM account and authentication information: login email, user and workspace identifiers, workspace settings, membership roles, password hashes, session information and OAuth authorization state. Passwords are processed during authentication. Session cookies support sign-in and security.
- Connected Instagram account information: account ID, username, access token, token expiration, granted permissions, connection status and related operational metadata.
- Instagram interactions: Direct message text, sender and recipient identifiers, message and conversation records, timestamps, quick-reply and postback values, delivery status and errors; comment text, comment/media/author identifiers, usernames where supplied, and replies.
- Profile and media information: recipient names, usernames, profile-image URLs and follow status where available; account-media captions, links, thumbnail URLs and publication information. Links and media URLs may also appear in customer-configured messages.
- CRM content: contacts, tags, notes, custom fields, opt-out/status information, automation rules and execution history, campaign definitions, activity records and contact-associated link-click analytics.
- Technical information: request IP addresses used for security and recorded in applicable server logs, session cookies, application/error logs and normalized webhook events. Stored event content can also appear in message records and automation history.
We do not automatically import every historical Instagram conversation. Data availability depends on permissions, account eligibility and Meta's APIs. Incoming webhook bodies are processed for signature checking and parsing; persistent webhook records contain normalized events. The current incoming-message processing does not save attachment objects as message fields, although profile, media and configured-message URLs can be stored elsewhere.
If you use the optional browser network connector, its proxy settings and routing-session information are stored locally in your browser extension. Disabling routing does not automatically remove its saved settings.
How we use information
We use information to authenticate users, control workspace access, maintain authorized Instagram connections, display and respond to interactions, manage contacts, execute customer-configured automations and campaigns, respect messaging opt-outs, report activity, troubleshoot problems, protect the service and maintain backups. We also process privacy and deletion requests and information necessary to meet applicable legal obligations and protect rights.
Storage and retention
Service data is stored in the database and supporting server storage used to operate Wellness CRM. Provider access tokens are encrypted at rest. The service also maintains operational logs, processing queues and backups.
We retain information for as long as necessary to provide the service, meet applicable legal obligations and protect rights. The current software does not enforce a general automatic retention period for all customer content. Automatic account/workspace deletion is not offered. Disconnecting Instagram, logging out or a token expiring does not by itself delete historical CRM information.
Deletion requests are processed by the operator within up to 30 days and may be handled manually. The operator informs the requester of the result and any information that remains. Information that must be retained by law may be kept only to the extent necessary. Backups may retain earlier copies until their scheduled rotation; immediate deletion of every backup copy is not promised.
Sharing and third parties
Information is exchanged with Meta/Instagram to support the customer's authorized connection and service functions. Hosting and network infrastructure providers support storage, operation and connectivity. Authorized workspace members can access information within their workspace.
If a customer configures an external automation webhook endpoint, the current function sends contact and automation-run identifiers to that customer-selected endpoint. Customers may also export data or direct recipients to external links; those separate destinations and copies are under the customer's control.
Privacy and deletion requests sent to zhanna.monas@yandex.ru are processed through the operator's email service. No external analytics, error-monitoring or payment integration was identified in the audited CRM implementation.
Security
Confirmed safeguards include HTTPS, access controls, access-token encryption at rest, server secrets stored outside application code and webhook signature validation. These measures reduce risk but do not guarantee absolute security.
Your choices and data deletion
You can request access to, correction of or deletion of your information by emailing zhanna.monas@yandex.ru. The operator may request reasonable confirmation of identity or authority, particularly for shared-workspace or business-contact information. Do not send passwords, tokens or app secrets.
To disconnect Instagram, open Accounts / Аккаунты, select the connected account, choose Disconnect / Отключить and confirm. This marks the connection disconnected and removes the access token from the active account record. It does not delete existing CRM history, erase Instagram messages or automatically revoke Meta permissions.
For deletion, identify your CRM login email and the relevant workspace, Instagram account or contact, and describe the requested scope. The operator processes the request within up to 30 days, may perform deletion manually and sends confirmation of the result. Full automatic user/workspace erasure is not currently implemented. Some records require separate handling beyond the existing contact-deletion function. Any retained records or limitations will be explained in the response. See Wellness CRM — Data Deletion Instructions for the request steps.
CRM deletion cannot erase copies independently held on Instagram, customer exports or other external destinations. Technical limitations do not themselves exempt the operator from handling a deletion request.
International processing
The integration with Meta/Instagram may result in processing by Meta's infrastructure in the jurisdictions where Meta provides its services. Meta operates its platform under its own terms and privacy policy. We do not promise that all information remains within one country.
Age requirement
Service is intended only for persons aged 18 or older.
Changes and contact
Updates will be reflected in this policy and its effective date. For questions, requests or concerns, contact ИП Монастырская Жанна Феликсовна at zhanna.monas@yandex.ru.