Privacy Policy

Last updated: April 2026

Introduction

Sorbey ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.

Collection of Personal Data

We collect information that you provide directly to us, including:

  • Contact information (name, email address, phone number)
  • Business information (restaurant name, address, website)
  • Account credentials and authentication data
  • Communication data (messages, support requests, feedback)
  • Payment information (processed securely through our payment providers)

Data Collection Methods

We collect data through various methods:

  • Direct interactions when you create an account or contact us
  • Automated technologies including cookies and analytics tools
  • Third-party integrations such as Google Business Profile and review platforms
  • Public sources for business information verification

Use of Data

We use the information we collect to:

  • Provide, maintain, and improve our services
  • Process transactions and send related information
  • Send promotional communications (with your consent)
  • Respond to your comments, questions, and customer service requests
  • Monitor and analyze trends, usage, and activities
  • Detect, investigate, and prevent fraudulent transactions and other illegal activities
  • Personalize and improve your experience with our services

Sharing Data with Third Parties

We may share your information with:

  • Service providers who perform services on our behalf
  • Third-party platforms you authorize us to connect with (e.g., Google Business Profile)
  • Professional advisors such as lawyers and accountants
  • Law enforcement or government agencies when required by law
  • Business partners in connection with a merger, acquisition, or sale of assets

We do not sell your personal information to third parties.

Connecting Facebook and Instagram (Meta Platforms)

When you connect a Facebook Page or an Instagram Business account to Sorbey, we use Meta's Graph API under Meta's Platform Terms and Developer Policies. Sorbey's use of information received from Meta will comply with the Meta Platform Terms.

Data we store when you connect a Meta account:

  • Your Meta user identifier, the identifiers of the Facebook Pages you grant access to, and the identifier of the Instagram Business account linked to a selected Page
  • A long-lived Page access token (valid up to 60 days, refreshed automatically) used to publish on your behalf
  • Names and profile pictures of the connected Page and Instagram account, used only to display them in the Sorbey dashboard
  • The content (caption, media, scheduled time) of the posts you create in Sorbey for publication on your Page or Instagram account

How we use this data:

Solely to let you create, schedule and publish Facebook posts and Instagram feed posts to the Pages and Instagram Business accounts you have authorized. We do not read your private messages, advertise on your behalf, or sell any of this data.

Retention and deletion:

We keep the identifiers and access tokens only while the integration remains connected. You can disconnect at any time from the Sorbey dashboard (Integrations → Meta → Disconnect); upon disconnection or when Meta sends us a data-deletion signal, we revoke the token and remove the stored identifiers within 30 days. Removing the Sorbey app from your Facebook account (Settings → Apps and Websites) triggers the same deletion automatically.

AI Assistant Integrations (MCP)

The Model Context Protocol (MCP) is an open protocol that lets AI assistants interact with third-party services on a user's behalf. Sorbey operates an MCP server so AI assistants can read and act on your Sorbey data when you choose to connect them.

Supported AI assistants:

Sorbey integrates with Claude (Anthropic), ChatGPT (OpenAI), and any other MCP-compatible client you choose to authorize.

Data flow:

When you invoke a tool from an AI assistant, the assistant sends a request to our MCP server, which queries our Convex backend. We return only data that you have access to in your Sorbey account, scoped to the locations you manage. The AI assistant relays the response back to you.

Training:

Sorbey does not send your data to AI assistant providers for model training. Anthropic, OpenAI, and other providers handle prompts and responses according to their own privacy policies; we encourage you to review those policies before connecting an assistant.

Authentication and revocation:

Connecting an AI assistant uses OAuth 2.1. The access token issued to the assistant is scoped to your Sorbey locations and can be revoked at any time from your Sorbey account settings, which immediately blocks further access.

Your rights:

GDPR rights — including access, rectification, deletion, and portability — apply to all data in your Sorbey account, including data accessed via MCP. See "Your Rights" below for how to exercise them.

Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit and at rest
  • Regular security assessments and audits
  • Access controls and authentication requirements
  • Employee training on data protection practices

Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Right to access: Request a copy of your personal data
  • Right to rectification: Request correction of inaccurate data
  • Right to erasure: Request deletion of your personal data
  • Right to restrict processing: Request limitation of how we use your data
  • Right to data portability: Request transfer of your data to another service
  • Right to object: Object to processing of your personal data
  • Right to withdraw consent: Withdraw consent at any time where we rely on consent

To exercise any of these rights, please contact us using the information provided below.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. We encourage you to review this Privacy Policy periodically for any changes.

Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at contact@sorbey.co.