LightsStory Applications, Integrations and APIs Privacy Policy

Last updated: September 20, 2026

This Privacy Policy explains how LightsStory collects, uses, protects, and handles information when you use a LightsStory application, website integration, API connection, or connected third-party service.

This policy applies to integrations with platforms and services including, but not limited to, Pinterest, Meta, Facebook, Instagram, Google, Shopify, and other third-party applications and APIs.

Our approach is straightforward:

We use information only for legitimate business and service purposes, we protect the information entrusted to us, and we do not sell customer data or provide it to third parties for their own unrelated commercial purposes.

1. Information We May Receive

Depending on the application or integration you use, LightsStory may receive information from a third-party platform that you have authorized us to access.

This may include:

  • Name and account information

  • Email address

  • Business or company information

  • Account, profile, page, or user identifiers

  • Access tokens and authorization information

  • Content, images, posts, Pins, products, catalogs, or other platform data

  • Advertising or campaign information where an advertising integration has been authorized

  • Analytics and performance information

  • Information necessary to operate or maintain the integration

The information available to LightsStory depends on the permissions granted to the particular application.

2. Authorization

When you connect a third-party account or service to LightsStory, authorization is generally handled through the third party's own authentication and authorization system.

LightsStory does not request your third-party account password when an integration uses OAuth or another supported authorization method.

You choose which services to connect and which permissions to authorize. Where supported, LightsStory requests only the permissions reasonably necessary for the functionality being provided.

3. How We Use Integration and API Data

Information obtained through an application or API may be used to:

  • Provide the service or functionality you requested

  • Connect your account with a third-party platform

  • Publish, manage, synchronize, or retrieve content you have authorized

  • Manage products, catalogs, pages, accounts, or other connected resources

  • Provide analytics or reporting that you have requested

  • Maintain and troubleshoot integrations

  • Detect unauthorized access, abuse, fraud, or security issues

  • Maintain, secure, and improve the operation of our applications

We do not use information obtained through third-party APIs for purposes unrelated to the service or integration for which it was provided.

4. Customer Data Is Not Sold

LightsStory does not sell, rent, trade, or license customer data to third parties.

We do not provide customer data to third parties for their own:

  • Advertising

  • Data brokerage

  • Customer profiling

  • Marketing databases

  • Unrelated commercial purposes

Information may be transmitted to a third-party platform when this is necessary to perform an action you have specifically authorized, such as publishing content, synchronizing a product catalog, or connecting an account.

5. Third-Party Service Providers

LightsStory may use trusted technology and infrastructure providers to operate our applications and services.

These providers may process limited information on our behalf where necessary to provide services such as:

  • Cloud hosting and storage

  • Application infrastructure

  • Security and fraud prevention

  • Email and communications

  • Technical support

  • Data processing

  • Application monitoring

These providers receive only the information reasonably necessary for the service they provide and are not authorized to use LightsStory customer data for their own unrelated advertising or data-brokerage activities.

6. API Credentials and Access Tokens

API keys, OAuth access tokens, application credentials, secrets, and similar authentication information are treated as confidential.

LightsStory uses reasonable technical and organizational safeguards to protect these credentials against unauthorized access, disclosure, alteration, or misuse.

We do not intentionally expose API credentials or access tokens publicly or provide them to unrelated third parties.

Where appropriate, credentials are protected using access controls, secure storage, and encrypted communications.

7. Information From Social and Content Platforms

Some LightsStory applications may interact with social media, content, advertising, commerce, or publishing platforms.

These may include services such as:

  • Pinterest

  • Meta, including Facebook and Instagram

  • Google

  • Shopify

  • Other social, commerce, advertising, publishing, analytics, or technology platforms

The information LightsStory can access depends on the permissions granted to the relevant application and the rules of the platform providing the API.

LightsStory uses such information only for the authorized functionality of the relevant application.

Where a platform imposes additional requirements concerning the collection, use, storage, or deletion of API information, LightsStory follows those applicable requirements.

8. Data Retention

LightsStory retains information only for as long as reasonably necessary for the purpose for which it was collected, to provide requested services, maintain security, resolve disputes, or satisfy legal and regulatory obligations.

Where an integration or third-party platform requires information obtained through its API to be deleted or limits how that information may be retained, LightsStory follows those applicable requirements.

When information is no longer required, LightsStory may delete or securely dispose of it, subject to legitimate legal or operational retention requirements.

9. Disconnecting an Integration

You may disconnect a third-party integration where the relevant application or platform provides that functionality.

After an integration is disconnected, LightsStory will no longer use that connection to access the connected account.

Disconnecting an integration does not automatically delete information that you independently provided to LightsStory or information that LightsStory is legally permitted or required to retain.

Where applicable, you may contact us to request deletion of information associated with an integration.

10. Data Security

LightsStory takes reasonable measures to protect information against unauthorized access, loss, misuse, alteration, or disclosure.

Security measures may include access controls, secure authentication, encrypted communications, restricted credentials, monitoring, and appropriate technical safeguards.

No internet-based service can guarantee absolute security. We therefore cannot guarantee that information will always remain completely secure, but we take reasonable measures appropriate to the information we handle.

11. Information Required by Law

LightsStory may disclose information where reasonably necessary to:

  • Comply with applicable law or legal process

  • Respond to a valid governmental or regulatory request

  • Protect the rights, property, or security of LightsStory

  • Protect customers or other individuals

  • Investigate fraud, abuse, security incidents, or unauthorized activity

Any disclosure will be limited to what LightsStory reasonably believes is necessary for the relevant purpose.

12. Third-Party Privacy Policies

When you connect LightsStory to another platform, that platform may separately collect and process information under its own privacy policy and terms.

LightsStory does not control the privacy practices of third-party services.

You should review the applicable privacy policy and terms of any service you choose to connect to LightsStory.

13. Your Privacy Rights

Depending on your location and applicable law, you may have rights concerning your personal information, including rights to:

  • Access information we hold about you

  • Request correction of inaccurate information

  • Request deletion of certain information

  • Request restriction of certain processing

  • Withdraw authorization for certain integrations

  • Request information about how your data is handled

To make a privacy request, contact us at:

support@lightsstory.com

We may need to verify your identity before completing certain requests.

14. Changes to This Policy

LightsStory may update this policy when we introduce new applications, integrations, APIs, technologies, or services, or when legal or regulatory requirements change.

The latest version will always show the date it was last updated.

15. Contact

LightsStory
Website: lightsstory.com
Email: support@lightsstory.com

For questions about applications, integrations, APIs, or the handling of information by LightsStory, please contact us at support@lightsstory.com.