Privacy Policy

Effective 15 August 2026. Applies to Ghostbuilder's Instagram business messaging and website-preview service.

This policy explains what personal data Ghostbuilder collects, why, where it is stored, who else processes it, and how to ask for it to be deleted. It is written to describe what this service actually does — not a generic template.

Who we are

Henry Puttock, trading as Ghostbuilder, a sole trader based in the United Kingdom, operating an Instagram Professional (Business) account. This policy is written under UK GDPR and the Privacy and Electronic Communications Regulations (PECR). Contact: puttockh@gmail.com.

What this service does

Ghostbuilder does two distinct things with Instagram data, described separately below because they involve different people and different data:

  1. Conversation handling — if you message Ghostbuilder's Instagram business account, that conversation is processed to reply to you (in part with the help of automated drafting tools, always reviewed by a human before anything is sent).
  2. Website previews for prospective clients — Ghostbuilder builds sample preview websites for small UK businesses that run a public Instagram business account, as a way of pitching web design services to them. This uses only content those businesses have already made public on Instagram.

What data we collect

CategoryWhatFrom
Conversation data Message text, your Instagram-scoped sender ID, message timestamps, and (where used) message reactions and message edits on a conversation. Instagram's official Messaging API, when you message our business account.
Public business profile data Public Instagram business profile content: bio, profile photo, publicly posted photos, public contact details if listed (phone/email/address), and public reviews. Publicly accessible Instagram content for businesses being considered for a preview website — never private accounts, never DMs.
Generated content The preview website itself (text and images derived from the public profile data above), and drafted message replies. Produced by us from the data above.

Why we process it

Our lawful basis is legitimate interests under UK GDPR: operating a business-to-business messaging channel and outreach service. We do not process this data for any purpose unrelated to responding to conversations or producing/pitching a preview website. We do not sell personal data, and we do not use it for third-party advertising.

Where your data is stored

Conversation and profile data is stored in a Supabase database and file storage (see Supabase's own privacy policy for the specifics of their hosting infrastructure). The Instagram webhook that receives messages runs on Cloudflare Workers, which processes messages in transit but does not retain them — everything is written through to Supabase.

Who else processes your data

We use the following processors to run this service. Each only receives the data needed for its specific role:

ProcessorRole
Meta (Instagram / WhatsApp Business Platform)The messaging platform itself — delivers messages to and from our business account.
ApifyRetrieves publicly available Instagram profile/post content for prospective-client businesses, so a preview website can be built.
SupabaseDatabase and file storage for conversation records, profile data, and generated previews.
Google (Gemini API)Processes conversation text to classify what a message is about and to help draft candidate replies. Replies are never sent without a human reviewing them first.
Anthropic (Claude API)Processes public business profile content to help generate website copy for preview sites.
CloudflareHosts the messaging webhook (Workers), the message queue (Queues), and preview websites (Pages).

We do not use any processor beyond these to handle the data described on this page.

How long we keep it

We keep conversation and profile data for as long as it is relevant to an active or prospective business relationship — for example, while a conversation is ongoing or a preview is being pitched. We do not run this on a fixed automatic deletion schedule; instead, data is deleted when it is no longer needed for that purpose, or sooner on request (see below).

Your rights under UK GDPR

You have the right to:

We will respond within one calendar month, as required by UK GDPR. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk if you believe we have not handled your data properly.

How to request data deletion

To ask us to delete data we hold about you or your business, email puttockh@gmail.com with the subject line "Data deletion request", and include:

We will delete the relevant records from our active systems and confirm by email once done, within one calendar month. If your data was shared with a processor listed above as part of providing the service, we will also ask that processor to delete it from their systems, subject to that processor's own retention obligations (for example, standard short-term backup cycles, which we do not control).

Cookies and tracking

This page does not use cookies, analytics, or any tracking technology.

Children

This is a business-to-business service. We do not knowingly collect data from, or target, children.

Changes to this policy

If this policy changes, the "Effective" date at the top of this page will be updated. This page is the only version we consider current.

Contact

For anything on this page, including data requests: puttockh@gmail.com.