Privacy and cookie policy
Last updated: 25 September 2026
This policy explains how Medula S.r.l. processes personal data in connection with the TagoZago service (the "Service"), available at tagozago.com, pursuant to Regulation (EU) 2016/679 ("GDPR") and Italian Legislative Decree (D.Lgs.) 196/2003. It concerns two groups of people:
- Customers, meaning the people who access the TagoZago dashboard, including as members of another Customer's team;
- Visitors to the websites on which Customers install the TagoZago widget.
1. Data controller
Medula S.r.l., Via A. Mammucari 32, Roma. P.IVA 10346061004, registered with the Registro delle imprese di Roma.
For any privacy-related request: [email protected].
Medula is the controller of Customer data (account, billing, security). For the content that the Customer imports and publishes through the Service (Instagram posts, products, widget statistics), Medula acts as processor on behalf of the Customer, who remains the controller, as set out in the Terms of service.
2. Customer data
| Data | Why we process it | Legal basis |
|---|---|---|
| From Facebook login: name, email address (if available in your profile), profile picture, app-scoped Facebook ID. Access token, stored encrypted. | To create and manage your account and to log you in. | Performance of a contract (Art. 6(1)(b) GDPR) |
| Facebook Pages and Instagram Business accounts you choose to connect: Page name and ID, Instagram username, profile name and picture, Page access token (encrypted). | To import your posts and keep them up to date. | Performance of a contract |
| Content of Instagram posts (images, videos, captions, dates, links), and the products and tags you add. | To provide the Service: tag editor, widget, catalog feed. | Performance of a contract. For any third-party data contained in the content, see section 1. |
| Billing data: name or company name, address, VAT number, chosen plan, subscription status. Card details are collected and stored by Stripe only: Medula never sees them. | To manage subscriptions, payments and invoices. | Performance of a contract. Legal obligation to retain invoices (Art. 6(1)(c)). |
| Team members and invitations: invitee's email, role, who sent the invitation. | To allow several people to collaborate in a workspace. | Performance of the contract with the inviting Customer |
| Technical data: IP address, browser, date and time of requests, error logs. | Security, abuse prevention (rate limiting), troubleshooting. | Legitimate interest (Art. 6(1)(f)) |
We do not use your data for advertising, we do not sell it and we do not carry out profiling. We only read from Instagram the content of the accounts you connect, and we never publish anything on your behalf.
3. Data of Visitors to websites using the widget
The TagoZago widget is designed to collect only the bare minimum.
- No cookies and nothing stored in the Visitor's browser (no localStorage or persistent identifiers).
- To compute the Customer's statistics we record anonymous events: widget view, post opened, tag hovered, product clicked. Each event contains only the widget, post or product concerned, the website's domain and the date. We do not store the IP address or any other Visitor identifier. To count each event only once and to block abuse, the IP address is used only in memory, for no more than 30 minutes, without being recorded.
- To display the widget, the Visitor's browser downloads scripts, data and images from TagoZago's servers and from the DigitalOcean CDN. As with any web resource, the IP address is processed by the network infrastructure for the time needed to deliver the content and for security purposes.
- Product links lead to the Customer's website with UTM parameters, which do not identify the Visitor.
These statistics are processed on behalf of the Customer who installed the widget. The Customer is their controller and must disclose the use of TagoZago in its own privacy policy.
4. Service providers (processors and sub-processors)
| Provider | Service | Location |
|---|---|---|
| DigitalOcean, LLC | Application hosting, database, image and video storage with related CDN | Frankfurt data center (EU). US company: see section 5. |
| Cloudflare, Inc. | DNS and content delivery network for the tagozago.com domain | Global network: see section 5 |
| Meta Platforms Ireland Ltd | Facebook login, access to connected Pages and Instagram Business accounts | EU / USA. Processing by Meta is governed by its own privacy policy. |
| Stripe Payments Europe, Ltd | Payments, subscriptions and invoices. Stripe is an independent controller for payment data. | Ireland (EU), with transfers to the USA |
| SMTP2GO | Sending service emails (for example team invitations) | EU / New Zealand |
5. Transfers outside the European Union
Some providers are based, or have staff, outside the European Economic Area, mainly in the United States. These transfers take place on the basis of an adequacy decision, such as the EU-U.S. Data Privacy Framework for participating companies, or of the Standard Contractual Clauses approved by the European Commission.
6. How long we keep data
- Account, content, products and statistics: for as long as the account or workspace remains active. When you delete them, the data is immediately erased from the database, and files (images and videos) are removed from storage within a few hours.
- Database backups: deleted data may remain in automatic backups for up to 7 days, after which it is overwritten.
- Invoices and accounting data: 10 years, as required by law (Art. 2220 of the Italian Civil Code). They are retained by Stripe and by Medula even after the account is deleted.
- Technical logs: for a short period, linked to the operation of the infrastructure, unless needed to investigate abuse.
- Team invitations: expire after 48 hours and are deleted together with the workspace.
7. How to delete your data
- From the dashboard: My account → Delete my account, or Settings → Delete workspace (owner only).
- From Facebook: remove TagoZago from the apps connected to your profile (Settings & privacy → Settings → Apps and websites) and request deletion of your data. You will receive a code that you can check on the Data deletion page.
- By writing to [email protected].
8. Your rights
You may at any time request access to your data, its rectification or erasure, restriction of processing and data portability, and you may object to processing based on legitimate interest (Arts. 15–22 GDPR). Write to [email protected]: we will reply within 30 days, free of charge. If you believe the processing does not comply with the law, you may lodge a complaint with the Garante per la protezione dei dati personali (the Italian Data Protection Authority).
If you are a Visitor and wish to exercise your rights regarding widget statistics, please contact the website hosting the widget, which is their controller. We will assist with the necessary checks.
9. Cookies
The tagozago.com website uses only technical cookies, which are necessary for it to work. For this reason no consent is required and we do not display a banner.
| Cookie | Purpose | Duration |
|---|---|---|
| __Secure-better-auth.session_token | Keeps your session active after login | 7 days |
| __Secure-better-auth.session_data | Temporary copy of session data, to speed up pages | 5 minutes |
| __Secure-better-auth.state | Protection of Facebook login (anti-CSRF) | 5 minutes |
| tz_ig_oauth | Protection of Instagram account connection (anti-CSRF) | 10 minutes |
| __cf_bm | Set by Cloudflare to distinguish legitimate traffic from bots (security) | 30 minutes |
We do not use analytics, profiling or advertising cookies. The widget installed on Customers' websites does not use cookies. Stripe's payment pages and Facebook login use their own cookies, governed by their respective policies.
10. Security
Connections are encrypted (HTTPS/TLS) and Facebook and Instagram access tokens are stored encrypted (AES-256-GCM). Access to data is restricted by workspace and role. The database is managed with automatic backups.
11. Minors
The Service is intended for businesses and professionals and is not directed at persons under 18 years of age.
12. Changes
We may update this policy. In the event of material changes we will notify Customers by email or in the dashboard. The date at the top indicates the latest version.