Privacybeleid

Kennisgeving: Dit bericht wordt voor uw gemak in de door u geselecteerde taal weergegeven. Alle juridische documenten van InstaGet worden uitsluitend in het Engels gepubliceerd en de Engelse versie is de leidende, juridisch bindende versie.

Elke niet-Engelse vertaling, indien beschikbaar, is uitsluitend voor het gemak en wijzigt de Engelse voorwaarden niet.

Hulp nodig of een toegankelijk formaat nodig? Gebruik dan de pagina Contact opnemen.

Effective Date: 2026-09-04

Last Updated: 2026-09-04

Policy ID: PRIVACY-InstaGet-v1.0

1) Who We Are & Scope

2740993 ALBERTA INC., operating as InstaGet (“we”, “us”, “our”), provides account, subscription, and people-discovery tools (the “Service”). Public People pages may include confirmed Wiki-backed records, eligible Wikimedia Commons photos, and approved social-profile projections from requested public profiles or posts. Separate access-controlled systems may contain connected datasets, restricted archives, and local face-matching data. Those systems are not part of public pages, the public API, or MCP. We are based in Alberta, Canada and operate internationally, subject to applicable privacy, consumer, data-broker, biometric, copyright, platform, and online-safety laws.

When social processing is available, a requested public profile or post may produce an approved public profile projection or durable post-metadata page. Media is delivered through a short-lived InstaGet-controlled lease, not a public archive. Raw provider responses and URLs, review evidence, restricted archive data, and biometric fields are not included in public pages, the public API, or MCP. Face Finder and Deep Search are disabled on the public production Service.

This Privacy Policy works together with our People Data & Data Broker Notice, Biometric / Face Finder Notice, Privacy Request & Opt-Out Center, Do Not Sell/Share, Cookie / Tracking Notice, Terms of Service, and Copyright & Removal.

2) What We Collect

  • Account and subscription data: email, hashed password, plan status, billing identifiers, entitlement records, support history, security logs, and preferences.
  • Payment data: payment processing is handled by payment providers such as Stripe. We receive limited billing metadata, fraud/risk signals, tax/accounting records, and subscription status. We do not store full card numbers.
  • Usage, device, and security data: IP address, approximate location from IP, user-agent, language, referrer, timestamps, feature usage, rate-limit data, session identifiers, consent records, and limited device signals used for security, fraud prevention, abuse prevention, and diagnostics.
  • Communications: support, report, privacy, legal, billing, DMCA, removal, and vulnerability messages, including attachments and verification materials you provide.
  • Public catalog data: Wiki-backed names, biographies, roles, locations, dates, Wikidata/Wikipedia identifiers, source links, eligible Wikimedia Commons photos with available author and licence information, and approved social-profile projections such as a public handle, bio overview, and changed-field snapshots.
  • Private social processing data: normalized results from requested public profile or post URLs, request and safety records, and encrypted raw-provider artifacts where retention is enabled. A public post page may retain approved metadata after its media lease expires; raw provider URLs, raw payloads, and private media sources are not public.
  • Managed People Data: connected datasets may contain names, aliases, public social links, professional roles, organizations, locations, public records, registry records, residential/contact data, emails, phones, addresses, birth year or age ranges, inferred/enriched fields, and source metadata. These categories are not part of the public catalog allowlist. See the People Data & Data Broker Notice.
  • Local Face Finder and biometric-related data: if the restricted local feature is enabled after separate review, it may process a user's self-photo, reference photos, face thumbnails, face-detection boxes, face embeddings/templates, similarity scores, match results, and security logs. See the Biometric / Face Finder Notice.
  • Cookies and similar technologies: essential cookies, consent records, optional analytics, optional functional storage, and optional advertising/measurement storage as described in our Cookie / Tracking Notice.

3) Sources of Personal Information

We may collect information from you directly, from your device, from public web pages, from public records and official registers, from social platforms and linked public profiles, from licensed/acquired datasets, from user submissions, from service providers, from enrichment and matching systems, and from internal analysis. Public availability does not mean a person has waived privacy or other rights.

4) How We Use Information

  • Operate, maintain, secure, debug, and improve the Service.
  • Provide public People pages, requested social-profile and post-metadata results where enabled, source linking, restricted archive research, and locally enabled self-search face matching.
  • Verify, correct, suppress, delete, de-index, geo-block, or restrict information in response to privacy, safety, legal, or rights requests.
  • Prevent fraud, scraping abuse, harassment, impersonation, account takeover, spam, payment abuse, and security incidents.
  • Process subscriptions, payments, refunds, taxes, account notices, support, legal notices, and service messages.
  • Run analytics and optional advertising/measurement only as permitted by law and your choices.
  • Comply with law, enforce our Terms, respond to lawful requests, preserve evidence, and defend legal claims.

5) Legal Bases: GDPR, UK GDPR, Germany, and Similar Laws

  • Contract: to provide accounts, subscriptions, downloads, requested searches, support, and user-requested features.
  • Legitimate interests: where available for the specific processing, possible interests include operating and securing the Service, preventing abuse, improving features, and handling legal claims. Applicability requires a dataset- and jurisdiction-specific assessment of necessity, proportionality, source context, sensitivity, reasonable expectations, safeguards, and objection rights.
  • Consent: for optional cookies/marketing and particular sensitive processing where valid consent is required and obtained through a separate appropriate flow.
  • Legal obligation: for tax/accounting, court orders, regulator requests, DMCA/copyright records, privacy-rights records, and security incident obligations.
  • Vital/public interests or legal claims: only where applicable for urgent safety, abuse, illegal content, or claims handling.

For data not collected directly from the individual, this policy, source labels where feasible, rights channels, and suppression mechanisms are intended to support transparency. They do not by themselves determine a lawful basis or satisfy every notice requirement. We may limit or geoblock People Search features, and the public production Service does not provide Face Finder.

6) Sensitive Data, Biometrics, and High-Risk Uses

If Face Finder is enabled in an approved local environment, it uses face-detection and face-matching technology and may create or store face embeddings/templates. Some laws treat face geometry, biometric identifiers, political data, precise location, government identifiers, health data, religion, ethnicity, children’s data, and similar categories as sensitive or special-category data. We apply additional controls, including masking/tier gates, region policies, access limits, audit logs, deletion/suppression, abuse detection, and human review. We prohibit using our Service for eligibility decisions involving employment, credit, housing, insurance, education, government benefits, law-enforcement identification without valid legal process, stalking, harassment, or doxxing.

Local Face Finder is restricted to searching with a photo of yourself. Do not upload or search for another person. Acceptance of the Terms or a cookie choice is not biometric consent, and self-search does not establish that the reference index may lawfully be processed.

7) Public Display, Masking, and Searchability

Public People Search and public profile pages use a limited projection: confirmed People may show approved bio information, public social handles, tags, News associations, and profile-change snapshots. Durable post pages may show approved metadata, while social media is available only through an InstaGet-controlled one-hour lease. We do not publish contact details, raw provider payloads or URLs, private media sources, restricted archive contents, connected-dataset evidence, face embeddings, or match results. Eligible Wikimedia Commons photos may be displayed with available source, author, and licence information. Records may be masked, de-indexed, region-gated, suppressed, or removed. Search engines, third-party caches, and source platforms remain outside our control.

8) Sharing, Sale/Sharing, and Recipients

  • Public users: the approved People and social-post metadata projections displayed on public search, profile, and post pages are disclosed to visitors. Restricted archive, connected-dataset, raw-provider, and biometric fields are not public.
  • Service providers/processors: hosting, CDN, DDoS/security, logging, analytics, payments, email, support, storage, search, enrichment, and content-processing providers.
  • Advertising/measurement partners: only where enabled and permitted by consent/opt-out settings. Some U.S. state laws may treat certain disclosures as “sale,” “sharing,” or targeted advertising.
  • Legal/safety recipients: courts, regulators, law enforcement, rights holders, affected users, or advisors when required or reasonably necessary.
  • Corporate transactions: in connection with mergers, financing, restructuring, sale of assets, or similar transactions, subject to appropriate protections.

Because People Search is a broker-style product, sale/share terminology depends on the law that applies. We provide U.S. state opt-outs and honor Global Privacy Control where supported. Use Do Not Sell/Share or the Privacy Request & Opt-Out Center.

9) International Transfers

We operate from Canada and use providers in multiple countries, including Canada, the United States, and Europe. Where required, we use appropriate safeguards such as data-processing agreements, Standard Contractual Clauses, transfer assessments, access controls, encryption, vendor review, and supplementary measures.

10) Retention and Suppression

  • Server and security logs: typically 90 days unless needed for safety, fraud, abuse, or legal claims.
  • Analytics: typically up to 18 months, de-identified or aggregated where feasible.
  • Privacy, takedown, consent, and audit records: typically 3 years or longer where needed to prove compliance, prevent abuse, or defend claims.
  • Backups: rolling backups typically expire within 45 days.
  • Public catalog and managed research records: retained according to source, purpose, rights, access, and jurisdictional review unless deleted, suppressed, expired, or restricted.
  • Face Finder data: the production Service does not accept Face Finder uploads. Any approved local deployment must use a documented, purpose-specific retention and deletion schedule established before processing begins.

When we grant deletion or opt-out, we may keep a minimal suppression record, such as a hashed identifier, source key, URL, email hash, phone hash, or other limited marker, so the same person or record does not reappear from future imports.

11) Your Rights and Choices

Depending on your location, you may have rights to access, know, correct, delete, object, restrict, withdraw consent, opt out of sale/sharing/targeted advertising, limit sensitive data use, appeal a decision, or complain to a regulator. Submit requests through the Privacy Request & Opt-Out Center or email privacy@instaget.online.

We verify requests proportionately, support authorized agents where required, may ask for additional proof, and may deny or narrow requests where law permits, including for public interest, freedom of expression, legal claims, fraud prevention, security, or inability to verify.

12) Canada and Publicly Available Information

Under Canadian privacy laws such as PIPEDA and Alberta PIPA, publicly available information can still be personal information. We assess whether collection, use, and disclosure are reasonable, whether a consent exception applies, and whether safeguards, access/correction rights, and complaint channels are available.

13) U.S. State Privacy and Data Broker Notices

Some U.S. laws define businesses that collect and sell or disclose personal information about people with whom they do not have a direct relationship as data brokers. Whether a registration, notice, deletion mechanism, security program, or other obligation applies must be evaluated for each relevant product, disclosure, and jurisdiction.

14) EU Digital Services Act and Illegal Content

Users in the EU may submit notices about illegal content, privacy violations, impersonation, unsafe content, or other unlawful material through our reporting and removal channels. We may disable access pending review, provide decision information where required, and offer appeal or human review for moderation decisions.

15) Security

We use technical and organizational safeguards such as HTTPS/HSTS, access controls, role-based permissions, rate limits, audit logging, encryption where appropriate, security review, DDoS/bot controls, and vendor safeguards. No system is perfectly secure, and we will notify authorities and affected people of breaches where required.

16) Automated Decisions, Profiling, and Appeals

We use automated systems for matching, ranking, search, fraud prevention, abuse prevention, rate limits, and feature gating. We do not use the Service to make solely automated decisions that produce legal or similarly significant effects about individuals. If an automated restriction affects your access or privacy request, you may ask for human review.

17) Children and Minors

The Service is intended for people 18 or older. We do not knowingly solicit children’s personal information. If we identify minors in People Search, public-source data, images, or face data, we may suppress, remove, restrict, or geoblock the data, and we prioritize guardian or safety requests.

18) Changes

We may update this policy as products, laws, vendors, or datasets change. Material changes will be posted with a new Last Updated date, and where required we will seek consent or provide additional notice.

19) Contact and Privacy Officer

Controller / Business: 2740993 ALBERTA INC. o/a InstaGet
Email: privacy@instaget.online
Support: support@instaget.online
Mailing Address: 932 17 AVE SW, Calgary, AB T2T 0A2, Canada