Data controller: FELIX ONLINE CONCEPT SRL
Trade Register J23/4628/2019 · Tax ID (CUI) 41786909
Str. Macului, Nr. 1, Dragomirești-Deal, Ilfov County, Romania
E-mail for any data request: [email protected] · Phone: +40 762 030 710
This is the English version of our Romanian privacy policy. If the two versions differ, the Romanian version prevails. How to delete your data: Data Deletion Instructions.
1. Scope
MOON Post is a service that writes blog articles and social media posts for businesses with the help of artificial intelligence. The business owner reviews every post in our dashboard, and approved posts are published to the business's own blog, Facebook Page and Instagram professional account. This policy explains what data we process through the moonpost.ro website and the MOON Post service, why, who we share it with and what rights you have.
For data we process on behalf of our customers — the content published on their accounts and the access keys to those accounts — we act as a data processor, and the customer remains the controller.
2. Visitors of this website
- Contact form: name, company, website address, e-mail, phone, the selected topic and the message. We use them to answer your request and, if you become a customer, to prepare an offer. Legal basis: legitimate interest in answering a business request and, later, performance of the contract.
- Technical data: IP address, browser type and pages visited, processed by the infrastructure that serves the website, for operation and security.
- Marketing cookies: described in our cookie policy (in Romanian); you can refuse them from "Setări cookies" in the footer.
3. Customers of the service
- Account and billing data: company name, tax identification data, contact person, e-mail, phone. Legal basis: performance of the contract and tax obligations.
- Access keys to the customer's blog, Meta accounts and, for online shops, product catalog. They are entered in the dashboard, cannot be read back from the interface and are used only to publish approved content and to sync the catalog.
- Generated content: drafts, articles, social texts, images, topic history, approval status and publishing date.
- Catalog data for online shops: product name, price, stock, categories, image and link — public business data, not personal data.
- Public pages of the customer's website, read so the service learns what to write about.
- Usage data: number of posts generated and published and the related generation cost, for billing and statistics.
We do not collect or process data about the visitors of our customers' websites. MOON Post publishes content; it does not track readers.
4. Data received from Facebook and Instagram
A customer can connect their Facebook Page and the Instagram professional account linked to it from the MOON Post dashboard, with the "Connect Facebook + Instagram" button (Facebook Login for Business, through our app on the Meta platform). Alternatively, an access token can be entered manually in the dashboard. We process this data only to publish on the customer's behalf and on their instructions.
What we receive and keep
- the Page access token of the selected Page — if Facebook does not issue one, we keep the long-lived user access token, valid for 60 days;
- the Facebook Page ID and the ID of the linked Instagram account;
- the Page name and the Instagram username, together with the connection date;
- the links to the posts MOON Post published on the Page and the Instagram account;
- the profile picture of the Page or Instagram account — only if the customer presses the dashboard button that takes the logo from there.
If you manage several Pages, Facebook sends us the list of Pages you granted us access to (name, ID, token, linked Instagram account) so you can pick one. The list is kept on our server for at most 10 minutes and deleted after you choose; we keep only the chosen Page.
We do not read messages, comments, reactions, insights or followers, we receive no data about people who interact with the Page, and we do not access friend lists, ad accounts or other Business Manager data. We never edit or delete existing posts and never publish on anyone's personal profile.
How we use it
- to publish to the Facebook Page and Instagram account only the posts the customer approved in the dashboard;
- to show the connected Page and Instagram account in the dashboard and check that the connection works (the "Test" button and an automatic daily connection check);
- to show a link to each published post next to it;
- when the customer asks, to use the profile picture as the brand logo on the images we generate for them.
Legal basis: performance of the contract with the customer. We do not use this data for advertising, we do not sell it and we do not share it with other companies; it is only sent to Meta in the publishing calls.
Where it is stored
The token, IDs, names and links are stored in the customer account configuration, in the service database hosted by Cloudflare; a logo taken from Facebook or Instagram is stored in Cloudflare storage. The token is never sent to the browser: the dashboard shows it masked and it cannot be read back. Only our server uses it, in calls to the Meta Graph API.
How long
For as long as the Page stays connected to the customer account. A new connection replaces the old token. The token is deleted when the contract ends or as soon as you ask; the other data is deleted together with the customer account, at the latest 60 days after the contract ends, or within 30 days of a deletion request.
How to revoke access
- On Facebook: Settings & privacy → Settings → Business Integrations → the app you used to connect MOON Post → Remove. From that moment the token stops working and we can no longer publish.
- Through us: write to [email protected] and we disconnect the Page from your account, deleting the token and the IDs.
Removing the app on Facebook stops access but does not delete the data already stored by us. To have it deleted, also send a deletion request.
How to request deletion
Follow the steps in our Data Deletion Instructions. Posts already published stay on your Page and Instagram account; you can delete them at any time from Facebook or Instagram.
5. Who we share data with
We use providers that process data on our behalf, strictly to run the service:
- Cloudflare — hosting of the website, the dashboard, the database and the generated images.
- Google (Gemini models) and OpenAI — generation of text and images. We send them the topic and content instructions, not your billing data and not your access keys.
- Meta Platforms — publishing to the customer's Facebook Page and Instagram account (see section 4).
- The customer's blog platform (WordPress) — publishing the article.
- Telegram — a notice that a new draft is ready, if the customer turned this on.
- GitHub — the infrastructure that triggers scheduled generation.
- Our transactional e-mail provider and invoicing platform, for notifications and tax documents.
We do not sell personal data and do not share it for third-party marketing. Some providers may process data outside the European Economic Area, based on the European Commission's standard contractual clauses.
6. Retention
- Contact form messages: 24 months after the last communication.
- Account data and generated content: for the duration of the contract and 60 days after it ends.
- Access keys, including the Facebook/Instagram token: deleted when the contract ends or as soon as you ask.
- Facebook Page and Instagram account IDs and names: while connected, then together with the account data.
- Tax documents: 10 years, as required by law.
7. Your rights
You have the right of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent where processing is based on it. Write to [email protected] and we will answer within 30 days. For deletion, see the Data Deletion Instructions.
If you are not satisfied with our answer, you can contact the Romanian data protection authority (ANSPDCP), dataprotection.ro.
8. Security
Dashboard passwords are stored as cryptographic hashes, not in plain text. Customer access keys cannot be read back from the interface. Dashboard access is role-based and permissions are checked on the server, not only in the browser.
9. Automatically generated content
Content is generated by artificial intelligence models and must be approved by the customer before it is published. We make no automated decisions with legal effect on any person and do no profiling.
10. Changes
We may update this policy. The version in force is the one published here, with the update date shown at the top. Active customers are notified of important changes by e-mail.