Privacy policy · Last updated 28 August 2026
Your information, handled with care.
This policy explains how Florist Touch Social Inbox processes information when a florist connects a Facebook Page and uses the Messenger enquiry service.
The current integration covers one authorised Facebook Page, available Messenger conversation history, new Messenger enquiries and deliberate staff-written replies. Instagram, advertising, publishing, comments, insights, WhatsApp and automated outbound messaging are not included in this release.
1. Who we are
Florist Touch Ltd (company number 12456022) provides Florist Touch Social Inbox. For florist account, service-administration and security information, Florist Touch Ltd is the data controller.
For customer enquiries and Messenger conversations handled for a florist, the florist business is normally the controller and Florist Touch Ltd acts as its processor. Meta separately processes information under its own terms and privacy notice.
2. Information we process
We may process:
- florist user names, business contact details, account membership and login/security records;
- the connected Facebook Page name, Page identifier and authorisation details;
- the provider-scoped identifier, Meta-authorised name and profile picture of a person messaging the Page, where Meta makes these available;
- available Messenger content, attachments, timestamps and recent conversation history;
- conversation status, staff assignments, private notes and reminders created by authorised florist users;
- outbound replies deliberately sent by authorised florist staff; and
- technical records needed to verify webhooks, avoid duplicates, secure the service and diagnose faults.
Provider restrictions may mean that only recent or eligible conversation information is available. We do not infer or fabricate missing customer identities or profile photographs.
3. Why we use it
We process information to provide the contracted inbox service, let authorised florist staff handle customer enquiries, maintain conversation context, protect the service, investigate faults and comply with legal obligations. Where Florist Touch is controller, the main lawful bases are performance of a contract, legitimate interests in operating and securing the service, and legal obligation.
Florist Touch does not use florist-customer Messenger content for Florist Touch advertising or unrelated profiling. The current service does not automatically send customer messages.
4. Facebook permissions and connection
A florist owner or manager chooses whether to connect an eligible Facebook Page through Meta’s authorisation process. Florist Touch requests only permissions needed to show eligible Pages, establish the Page connection, receive Messenger events, read available conversations and send a staff-authored reply where Meta permits it.
Access credentials are stored server-side, encrypted at rest and never exposed to ordinary website visitors. A florist may disconnect its Page from Settings → Facebook connection or revoke access through Meta.
5. Sharing and international transfers
Information is processed through Meta and our current cloud infrastructure provider, Akamai Technologies, Inc. / Linode. The application database, queue and private object storage are self-hosted on the authorised Linode server. We limit access to what is necessary and use appropriate contracts and UK international-transfer safeguards where required. We may also disclose information where lawfully required or necessary to protect legal rights.
6. Retention
Provider credentials and the authorising user’s connection record are removed immediately when the relevant connection is deleted, Meta sends a valid deauthorisation event or Meta sends a valid deletion request. Successfully processed raw Meta events are retained for up to 30 days; failed diagnostic events for up to 90 days; cached profile images for up to 30 days without refresh; security and integration audit records for up to 24 months; and deletion-confirmation records for up to 12 months.
Imported Messenger conversations, customer details and florist notes are retained under the florist controller’s instructions, with a default maximum of 24 months after the conversation’s last activity unless a different necessary period or legal hold is documented. Existing imported archives are reviewed with the florist controller before automated deletion is enabled. Disconnecting stops future synchronisation but does not automatically erase those florist-controlled records. Any operational backup introduced for this service must age out deleted or expired data within 35 days.
7. Security
We use access controls, tenant separation, encryption, audit records, signature verification and monitoring designed to protect information. No internet service is risk-free, but access is restricted to authorised staff and service processes.
8. Your rights and deletion
Depending on the circumstances, UK data-protection rights may include access, correction, deletion, restriction, objection and portability. A customer seeking action concerning a florist’s copy of a conversation should normally contact that florist as controller. We assist florists with appropriate requests.
Florists can follow our Facebook data deletion instructions. Deleting information from Social Inbox does not delete Meta’s own copy of a conversation.
9. Cookies
The public information pages do not use advertising cookies. Essential cookies may be used for secure sign-in and authenticated sessions. We may retain limited server logs for security and reliability.
10. Contact and complaints
Contact Florist Touch Ltd through our Social Inbox contact page. Registered office: 3rd Floor Suite, 207 Regent Street, London, W1B 3HH. You may complain to the UK Information Commissioner’s Office at ico.org.uk; we encourage you to contact us first.
11. Changes
We may update this policy when the service or legal requirements change. The latest version and its revision date will remain available on this page. Optional future integrations will apply only when a florist enables them and grants the necessary provider permissions.