Legal
Privacy Policy
This Privacy Policy explains how Chiang Mai Tennis Pages ("the App", "we", or "us") handles information when an authorized operator connects a Facebook Page or a linked Instagram professional account.
1. Scope
The App is a private business operations tool. It is not intended for general consumer registration. It only connects Meta business assets that an authenticated operator explicitly selects and is authorized to manage.
2. Information we process
- Meta account and business-asset identifiers, names, granted permissions, and access tokens.
- Facebook Page posts, comments, and related identifiers that the connected Page is permitted to read.
- Basic information and comments from a linked Instagram professional account when the operator grants those permissions.
- Language, timestamps, keyword matches, generated reply drafts, and action records needed to operate and audit the workflow.
- Technical logs limited to service health, errors, and action outcomes. Access tokens are not intentionally written to public application logs.
3. How we use information
We use the information solely to connect authorized business assets, monitor relevant tennis-related activity, prepare English or Thai responses, perform operator-configured engagement actions, prevent duplicate actions, enforce rate limits, and maintain an audit trail.
4. Legal basis and operator control
Processing is performed at the request of the authorized business-asset operator. The operator can disable monitoring, remove the local authorization, or revoke the App in Meta settings at any time.
5. Sharing and automated processing
We do not sell personal information. Limited text may be sent to a contracted AI service to generate a reply only when that feature is enabled. Author names, access tokens, and unnecessary account identifiers are excluded from AI prompts by design. Service providers may process data only to provide their contracted service.
6. Storage and security
Operational data and credentials are stored in an access-restricted operator environment. We apply least-privilege access, local permission controls, bounded processing, and action logging. No system can guarantee absolute security.
7. Retention
Credentials are retained until they expire, the connected asset is removed, or the operator requests deletion. Operational records are retained only as long as needed for security, duplicate prevention, and business operations, then deleted or de-identified. A verified deletion request is completed within 30 days unless a longer period is required by law.
8. Your choices and rights
You may revoke the App in Facebook or Instagram settings, disconnect the Page in the App, or request access, correction, or deletion. See the User Data Deletion instructions.
9. Children
The App is not directed to children and is not designed to collect information from children.
10. Changes
We may update this policy when the App or legal requirements change. The effective date above will be updated when material changes are published.
11. Contact
Privacy inquiries and deletion requests: privacy@cmtennis.net.