TagoZago

Courtesy translation: in case of any discrepancy, the Italian version prevails. Read the Italian version

Privacy and cookie policy

Last updated: 25 September 2026

This policy explains how Medula S.r.l. processes personal data in connection with the TagoZago service (the "Service"), available at tagozago.com, pursuant to Regulation (EU) 2016/679 ("GDPR") and Italian Legislative Decree (D.Lgs.) 196/2003. It concerns two groups of people:

1. Data controller

Medula S.r.l., Via A. Mammucari 32, Roma. P.IVA 10346061004, registered with the Registro delle imprese di Roma.
For any privacy-related request: [email protected].

Medula is the controller of Customer data (account, billing, security). For the content that the Customer imports and publishes through the Service (Instagram posts, products, widget statistics), Medula acts as processor on behalf of the Customer, who remains the controller, as set out in the Terms of service.

2. Customer data

DataWhy we process itLegal basis
From Facebook login: name, email address (if available in your profile), profile picture, app-scoped Facebook ID. Access token, stored encrypted.To create and manage your account and to log you in.Performance of a contract (Art. 6(1)(b) GDPR)
Facebook Pages and Instagram Business accounts you choose to connect: Page name and ID, Instagram username, profile name and picture, Page access token (encrypted).To import your posts and keep them up to date.Performance of a contract
Content of Instagram posts (images, videos, captions, dates, links), and the products and tags you add.To provide the Service: tag editor, widget, catalog feed.Performance of a contract. For any third-party data contained in the content, see section 1.
Billing data: name or company name, address, VAT number, chosen plan, subscription status. Card details are collected and stored by Stripe only: Medula never sees them.To manage subscriptions, payments and invoices.Performance of a contract. Legal obligation to retain invoices (Art. 6(1)(c)).
Team members and invitations: invitee's email, role, who sent the invitation.To allow several people to collaborate in a workspace.Performance of the contract with the inviting Customer
Technical data: IP address, browser, date and time of requests, error logs.Security, abuse prevention (rate limiting), troubleshooting.Legitimate interest (Art. 6(1)(f))

We do not use your data for advertising, we do not sell it and we do not carry out profiling. We only read from Instagram the content of the accounts you connect, and we never publish anything on your behalf.

3. Data of Visitors to websites using the widget

The TagoZago widget is designed to collect only the bare minimum.

These statistics are processed on behalf of the Customer who installed the widget. The Customer is their controller and must disclose the use of TagoZago in its own privacy policy.

4. Service providers (processors and sub-processors)

ProviderServiceLocation
DigitalOcean, LLCApplication hosting, database, image and video storage with related CDNFrankfurt data center (EU). US company: see section 5.
Cloudflare, Inc.DNS and content delivery network for the tagozago.com domainGlobal network: see section 5
Meta Platforms Ireland LtdFacebook login, access to connected Pages and Instagram Business accountsEU / USA. Processing by Meta is governed by its own privacy policy.
Stripe Payments Europe, LtdPayments, subscriptions and invoices. Stripe is an independent controller for payment data.Ireland (EU), with transfers to the USA
SMTP2GOSending service emails (for example team invitations)EU / New Zealand

5. Transfers outside the European Union

Some providers are based, or have staff, outside the European Economic Area, mainly in the United States. These transfers take place on the basis of an adequacy decision, such as the EU-U.S. Data Privacy Framework for participating companies, or of the Standard Contractual Clauses approved by the European Commission.

6. How long we keep data

7. How to delete your data

8. Your rights

You may at any time request access to your data, its rectification or erasure, restriction of processing and data portability, and you may object to processing based on legitimate interest (Arts. 15–22 GDPR). Write to [email protected]: we will reply within 30 days, free of charge. If you believe the processing does not comply with the law, you may lodge a complaint with the Garante per la protezione dei dati personali (the Italian Data Protection Authority).

If you are a Visitor and wish to exercise your rights regarding widget statistics, please contact the website hosting the widget, which is their controller. We will assist with the necessary checks.

The tagozago.com website uses only technical cookies, which are necessary for it to work. For this reason no consent is required and we do not display a banner.

CookiePurposeDuration
__Secure-better-auth.session_tokenKeeps your session active after login7 days
__Secure-better-auth.session_dataTemporary copy of session data, to speed up pages5 minutes
__Secure-better-auth.stateProtection of Facebook login (anti-CSRF)5 minutes
tz_ig_oauthProtection of Instagram account connection (anti-CSRF)10 minutes
__cf_bmSet by Cloudflare to distinguish legitimate traffic from bots (security)30 minutes

We do not use analytics, profiling or advertising cookies. The widget installed on Customers' websites does not use cookies. Stripe's payment pages and Facebook login use their own cookies, governed by their respective policies.

10. Security

Connections are encrypted (HTTPS/TLS) and Facebook and Instagram access tokens are stored encrypted (AES-256-GCM). Access to data is restricted by workspace and role. The database is managed with automatic backups.

11. Minors

The Service is intended for businesses and professionals and is not directed at persons under 18 years of age.

12. Changes

We may update this policy. In the event of material changes we will notify Customers by email or in the dashboard. The date at the top indicates the latest version.