Instagram Shopping Legal addendum · Legal version v1 · Last updated: July 13, 2026
Instagram Shopping Data Handling & Meta Platform Terms
Last updated: August 24, 2026
This addendum describes AtlasCore controls for Instagram Shopping and Meta Commerce data in alignment with Meta Platform Terms and Developer Policies.
Independent application status
AtlasCore is an independent software application. Instagram, Meta, and related marks are trademarks of Meta Platforms, Inc. AtlasCore is not sponsored, endorsed, or affiliated with Meta.
Data we access
With merchant authorization, AtlasCore may access:
- Facebook Page and Instagram Commerce account identifiers
- Catalog and product metadata for dashboard views
- Order summaries for operational workflows (order id, status, date, item counts, operational totals)
- Buyer and shipping fields are not stored; webhook and order blobs are allowlisted operational envelopes only
Controls
- Token encryption: Meta OAuth long-lived access tokens are encrypted at rest using AES-256-GCM.
- Transport: TLS 1.2+ for all production API and webhook traffic.
- Webhooks: Incoming Meta webhooks are verified with `X-Hub-Signature-256` HMAC-SHA256 over the raw request body. The durable ledger stores event id, field, Page id, order id, and status only.
- Retention: An Instagram-owned worker redacts terminal orders 30 days after `order_date` and open / in-transit orders 90 days after first persist. Redacted rows are not rehydrated.
- Isolation: Instagram Shopping is a B2C seller connection. Personal accounts may have a null workspace id; enterprise workspaces optionally bind via `X-Tenant`.
- Compliance ingress: Data deletion, deauthorize, and webhook routes remain mounted for Meta App Review regardless of feature flags. Callbacks persist an Instagram receipt, then purge every matching account.
Seller controls
- Disconnect Instagram Shopping in AtlasCore to stop sync and purge credentials for the active workspace.
- Revoke AtlasCore in Meta Business Settings as needed.
- Export account metadata via authenticated Export My Data.
- Request deletion via Delete Account or privacy@atlascore-market.com.
See our Privacy Policy and Data & Retention policies.