Privacy Policy
Last updated: August 27, 2026
MicroTribe ("we", "us", "our") operates the website at community.microtribe.net and the related MicroTribe Staff Scanner application (together, the "Service"). This Privacy Policy explains what information we collect, how we use it, how long we keep it, and the choices you have.
This policy covers three different kinds of people:
- Businesses and their staff who have a MicroTribe account.
- Customers who fill in a business's MicroTribe form or use a MicroTribe wallet card.
- People who tag a business on Instagram and have never signed up for anything. If that is you, you still have rights here and we still hold data about you — read section 5, which is written for you.
You can ask us to delete your information at any time, whether or not you have an account. See How to delete your data for the exact steps, or section 11 below.
1. Who we are
The Service is operated by Plateforme Microtribe, a business established in the province of Quebec, Canada. MicroTribe is a customer engagement platform that helps local businesses turn their customers into advocates through QR codes, digital wallet cards, follow-up campaigns, and an optional Instagram integration that tells a business when someone mentions them.
You can contact us at any time at support@microtribe.net.
2. Our privacy officer
Quebec's Act respecting the protection of personal information in the private sector (chapter P-39.1, as amended by the statute commonly called Law 25) requires every enterprise to name a person in charge of the protection of personal information and to publish that person's title and contact information. Ours is:
- Name: Corina Ciorba
- Title: Person in Charge of the Protection of Personal Information (Privacy Officer), Plateforme Microtribe
- Email: support@microtribe.net — please put "Privacy Officer" in the subject line.
Requests for access, correction, deletion, withdrawal of consent, or a complaint should be addressed to the privacy officer at that address. We acknowledge every request within 2 business days (Mon–Fri, and usually the same day) and complete it within 30 days. The same two commitments appear on our data deletion page and they are the same commitments — there is no separate, slower process for any category of request or of person.
3. Information we collect
From business owners and staff:
- Name, email address, phone number, and password (hashed) used to create and secure your account.
- Business information you provide (business name, address, branding, social handles, Google Business listing).
- Team members you add and the role assigned to them.
- Content you create on the platform (forms, message templates, campaigns, uploaded images and assets).
- Billing details you enter on our Stripe checkout page. We never see or store your full card number.
From customers who interact with a business through MicroTribe:
- Information voluntarily submitted through a business's MicroTribe form (such as name, email, phone, birthday, social handles, and reviews).
- Submission metadata such as the time of submission and the form used.
- Engagement signals such as wallet card downloads, link clicks, and email opens, used to measure campaign performance.
From Instagram, when a business connects its account:
- Data about the connected business account, and data about people who mention that business on Instagram. This is set out in full in section 4, and section 5 is addressed specifically to the people who do the mentioning.
Automatically collected:
- Basic device, browser, and IP information needed to deliver and secure the Service.
- Cookies and similar technologies used to keep you signed in and to remember preferences (such as language).
4. Instagram integration (Meta Platform Data)
A business using MicroTribe may choose to connect its Instagram professional account. This is optional, it is off until someone with access to the business's MicroTribe account turns it on, and it can be disconnected at any time. Once connected, MicroTribe tells the business when someone mentions them on Instagram and can send that person one automatic thank-you message.
4.1 What we ask Instagram for
When a business connects its account, we request these Instagram permissions and nothing else:
instagram_business_basic— to read the connected account's username, ID, profile picture, and follower count, so the business can confirm the right account is linked.instagram_business_manage_comments— to receive mentions of the business that arrive in posts and reels.instagram_business_manage_messages— to receive story mentions and to send the single thank-you message described below.
We subscribe to exactly two Instagram webhook fields: comments and messages. We do not request permission to publish content, and we do not request Instagram Insights.
4.2 What we store about the connected business account
- Instagram account ID and username.
- Profile picture URL and follower count.
- The long-lived access token Instagram issues to us (valid for about 60 days) and its expiry date. The token is stored so the integration keeps working between visits, and it is erased the moment the account is disconnected.
- Connection housekeeping: who connected the account, when it was connected, when it was disconnected, whether the webhook is healthy, and when we last heard from Instagram.
4.3 What we store about each mention
- About the post or story: its Instagram media ID, media type (image, video, carousel, reel, or story), the caption text if there is one, the permalink, the time it was posted, and the time we received it.
- About the person who tagged the business: their Instagram handle, their Instagram-scoped user ID, their display name, their profile picture URL, their follower count, whether their account is verified, whether they follow the business, and whether the business follows them.
- About the thank-you message: whether it was sent, skipped, or failed, when it was sent, the message ID Instagram returned, and any error text.
- If the handle matches a customer the business already has in MicroTribe, we link the two records so the business does not see the same person twice.
4.4 We never store the photo or video
We do not copy, cache, or mirror the image or video itself onto our servers. We keep only the temporary link that Instagram's own content network serves it from, and we display the picture by loading it from that link. Instagram's story links expire after roughly 24 hours; when that happens the picture simply stops loading and MicroTribe shows "Story expired". We do not go looking for another copy, and there is no copy of the media on our infrastructure to delete, share, or lose.
4.5 Why we collect it
- To show the business who is talking about them, in one place.
- To send one automatic thank-you message to the person who mentioned them, inside the 24-hour window that Instagram opens when someone contacts a business.
- To help the business recognise their most engaged customers. Follower count and the follow relationship are used for that and for nothing else.
We do not sell this data. We do not use it for advertising. We do not use it to build profiles across other apps or websites, and we do not combine it with data from other businesses.
5. If you tagged a business on Instagram
This section is for you if you mentioned a business on Instagram and have never signed up for MicroTribe. You are not our customer and you never gave us anything — but we do hold information about you, so here is exactly what is going on.
5.1 What we hold about you, and where it came from
You did not give it to us. We received it from Meta (Instagram) because you mentioned a business that uses MicroTribe. It is: your Instagram handle and Instagram-scoped user ID, your display name, your profile picture URL, your follower count, whether your account is verified, whether you follow that business, whether that business follows you, the caption and link of the post or story you mentioned them in, and a record of the message we sent you. We do not store the photo or video itself (see 4.4). We do not have your email address, your phone number, or anything else about you.
5.2 The message you received
MicroTribe sends one automated thank-you message from the business's Instagram account, once, for that mention. It is text only — no offers, no discounts, no follow-up sequence — and it is sent inside the 24-hour window that your own mention opened. If the window has closed, nothing is sent.
Please note: this automatic reply is off unless the business has written a message and switched it on. If no active reply is set up, we record the mention and send nothing. A business that has switched it on can switch it off again at any time in its MicroTribe settings.
5.3 How to stop receiving these messages
- Block or restrict the business on Instagram. This is the fastest and most certain option, it takes effect immediately, and it does not depend on us: it removes our ability to reach you at all.
- Email us. Write to support@microtribe.net with your Instagram handle and the words "stop messaging me". A person on our team switches off the automatic reply on the business's account so that it stops sending, and deletes the records we hold about you if you ask for that too. We do this within 2 business days of receiving your message, and we do not ask you to explain why.
- Don't tag them again. We only ever message someone in reply to their own mention, once. We never start a conversation, we send nothing on a schedule, and if you do not mention a MicroTribe-connected business there is nothing to reply to and no new record about you.
Being straight with you about the limits: we do not currently operate an automatic block-list that recognises your handle across every business on the platform, and we do not read replies to the thank-you message — so replying "STOP" to it will not reach anyone. Email us instead, or use the Instagram block. These are the routes that actually work today, and we would rather tell you that than promise you a switch we have not built.
5.4 How to have your information deleted
You do not need a MicroTribe account and we will not ask you to create one. Email support@microtribe.net from any address, tell us your Instagram handle, and ask us to delete your data. We will delete every record tied to that handle — the mention, your profile fields, and the message log — across all businesses on the platform, and confirm when it is done. Full instructions are on our data deletion page.
You can also ask us to stop displaying a mention without deleting anything else, to correct information that is wrong, or to tell you which businesses hold a record of you. Same address, same 30-day commitment. We handle these ourselves — we will not send you off to the café.
6. How we use information
- To create accounts, authenticate users, and keep the Service secure.
- To deliver the features you or your business have configured (forms, wallet cards, scanner, campaigns, Instagram mentions).
- To send transactional messages such as one-time passcodes, password resets, and service notifications.
- To send campaign messages on behalf of a business to that business's own customers, when the business has configured them.
- To send the single automatic thank-you message described in sections 4 and 5.
- To analyze usage in aggregate so we can improve the Service.
- To comply with legal obligations and enforce our terms.
We do not use your information for anything else without telling you first and, where the law requires it, asking for your consent.
7. MicroTribe Staff Scanner (iOS & Android) — Mobile App Privacy Policy
This section applies specifically to the MicroTribe Staff Scanner mobile application.
7.1 Dedicated B2B usage
The MicroTribe Staff Scanner is a business-to-business (B2B) tool. It is intended exclusively for business owners and pre-registered staff members who are already part of the MicroTribe ecosystem. This app is not intended for use by the general public or end-consumers.
7.2 Data collection & authentication
- Sign-in data: We collect and use the email addresses and phone numbers of owners and staff solely for secure account authentication via passwordless One-Time Passcode (OTP).
- Existing records: This data is not "new" collection; it is the same data already provided by the business during the main MicroTribe onboarding process.
- Identifiers: We use internal User IDs to maintain a secure session and to provide an audit log of which staff member performed a loyalty action (such as adding a stamp or redeeming a reward).
7.3 No third-party sharing or marketing
- No reselling: We do not sell, rent, or trade staff or business data to third parties.
- No marketing: We do not use the contact information collected via the app for marketing or advertising purposes.
- No tracking: We do not use data from this app to track user activity across other companies' apps or websites.
7.4 Customer data
The app does not collect personal identity information from end-customers. It only processes anonymous MicroTribe Customer UUIDs scanned via QR code to update loyalty balances (stamps/rewards) within the specific business's database.
The Instagram integration is not part of the Staff Scanner app. No Instagram data is sent to, or read by, the scanner.
8. How information is shared
We do not sell personal information. We share information only in the following limited cases:
- With the business that collected it. When a customer submits a form, that information is made available to the business that owns the form so they can serve and contact the customer. When someone mentions a business on Instagram, that mention and the profile fields listed in section 4.3 are shown to that business only — never to any other business on the platform.
- With service providers that help us run the Service. Each is engaged under a written contract that limits them to providing their service to us and requires them to delete or return the data when the contract ends. They are:
- Meta Platforms (Instagram) — the Instagram integration and the delivery of thank-you messages.
- Amazon Web Services — our main database and our file storage.
- Supabase — hosting for our server-side functions, and the Google sign-in handshake.
- Stripe — subscription payments and checkout.
- Resend — email delivery.
- Twilio and Telnyx — SMS delivery.
- Google — Google Wallet passes and Maps.
- Apple — Apple Wallet passes.
- When required by law, such as to comply with a subpoena, court order, or other legal process, or to protect the rights, property, or safety of MicroTribe, our users, or others.
- In a business transfer, such as a merger, acquisition, or sale of assets, in which case we will require the recipient to honour this Privacy Policy.
9. Where your information is stored and processed
MicroTribe is operated from Quebec, Canada. Some of your information is processed outside Quebec, and we think you should know exactly where:
- Our main database is in Quebec. Accounts, customers, forms, loyalty records, and Instagram mention records are stored on Amazon Web Services in the Montréal region (ca-central-1).
- Uploaded files are in the United States. Images and attachments uploaded to the platform are stored on Amazon S3 in the Ohio region (us-east-2).
- Instagram data travels to and from Meta in the United States. That is inherent to using Instagram: the mention originates on Meta's systems and the thank-you message is delivered through them.
- Other providers named in section 8 (Stripe, Resend, Twilio, Telnyx, Google, Apple, Supabase) process data in the United States and, in some cases, elsewhere.
Quebec law requires us to assess, before entrusting personal information to a provider outside Quebec, whether it will receive adequate protection there, and to record that transfer in a written agreement. We are working through that assessment and those agreements for each destination we use, and it is not yet complete for all of them. If you want to know the current status for a specific transfer, ask our privacy officer.
10. How long we keep information
- Account data — for as long as the account is active, then deleted within 90 days of closure, apart from records we must keep for tax or accounting purposes.
- Customer submissions — for as long as the owning business keeps them in the platform, or until the customer or the business asks us to delete them.
- Instagram mention records, including the tagger profile fields in section 4.3 — for as long as the business's Instagram connection is active. Deleted on request, and deleted along with the connection when a business disconnects Instagram or removes MicroTribe. We do not yet apply an automatic age limit beyond that.
- Instagram access tokens — replaced each time they are refreshed, and erased immediately when the account is disconnected or access is revoked.
- Media links — kept with the mention record. The link itself normally stops working within about 24 hours for stories. The media is never stored by us at all.
- Message delivery logs — deleted together with the mention record they belong to.
- Security and billing logs — up to 12 months, then deleted or anonymised.
When the purpose we collected something for has been achieved, we destroy it or anonymise it.
11. How to delete your data
You can have your data deleted, whoever you are and whether or not you have an account. There are three routes:
- Email us. Write to support@microtribe.net with the subject "Delete my data". Tell us your account email, or your Instagram handle if you do not have an account. Step-by-step instructions are on our data deletion page.
- Remove MicroTribe from Instagram. In the Instagram app, under your account's apps and website permissions, you can revoke MicroTribe's access. From that moment we can no longer call Instagram for your account: the token we hold stops working. We erase our stored copy of it as soon as we are told the access was revoked, and if you would rather not wait on that, email us and we will remove the connection record by hand.
- Send a deletion request through Instagram. If Instagram offers you a "Send Request" option when you remove the app and you use it, Meta passes us a formal deletion request. We delete the Instagram connection and every mention record captured through it, and we answer with a confirmation code. If you were given a code, you can look up what happened to the request on our deletion status page. If you were not offered that option, or you have no code, the email route above is always available and always works — nothing depends on you finding a button inside Instagram.
We acknowledge within 2 business days and confirm completion within 30 days, usually much sooner.
12. Your rights
If you live in Quebec, the following rights are yours unconditionally. We extend them to everyone who uses the Service.
- Access — ask us what personal information we hold about you, and where we got it.
- Correction — have inaccurate or incomplete information fixed.
- Deletion — have your information deleted (section 11).
- Portability — receive the computerised information you gave us, in a structured, commonly used technological format. This covers information collected from you, not information we worked out about you.
- Withdraw consent — withdraw your consent to us using or sharing your information, at any time.
- Stop dissemination or de-indexing — ask us to stop displaying information about you, or to remove a link to it. This applies to Instagram mentions shown in a business's MicroTribe dashboard.
Send any of these to our privacy officer at support@microtribe.net. We may ask you to confirm your identity, but only as far as needed to be sure we are giving your data to you and not to someone else.
Instagram and Meta data. For any information we obtained through Instagram or Meta — including everything in sections 4 and 5 — MicroTribe acts on your request directly. We will not redirect you to the business, and you do not need their permission or ours.
For information a business collected about you through its own MicroTribe forms, you may contact either that business or us. If you contact us, we will act on the request ourselves and let the business know.
13. Complaints
If you are unhappy with how we handled your information or your request, write to our privacy officer at support@microtribe.net with "Privacy complaint" in the subject. We acknowledge complaints within 2 business days, investigate, and give you a written answer with reasons within 30 days.
If our answer does not satisfy you, you may complain to the Commission d'accès à l'information du Québec, or to the privacy regulator where you live.
14. Security
We use industry-standard measures to protect your information, including encrypted connections (HTTPS), passwords that are never stored in readable form (each is salted, combined with a server-side secret, and put through PBKDF2-HMAC-SHA256 over 100,000 iterations), tenant-isolated data access, and access controls on our infrastructure. Instagram access tokens are held only in server-side storage and are never sent to a browser. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If a breach creating a risk of serious injury occurs, we will notify affected people and the Commission d'accès à l'information as the law requires.
15. Children
The Service is not directed to children. In Quebec, a minor under 14 cannot consent to the collection of their own personal information — consent must come from a parent or tutor — and we do not knowingly collect information from anyone under 14. Elsewhere we apply the local minimum age. If you believe a child has provided us with personal information, or has been recorded through the Instagram integration, contact us and we will delete it.
16. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, where appropriate, notify you through the Service or by email. Continued use of the Service after a change means you accept the updated policy.
17. Contact
Questions about this policy or about your data? Email us at support@microtribe.net. We acknowledge within 2 business days (Mon–Fri) and usually reply the same day. To delete your data, see our data deletion instructions.
Cette politique est publiée en anglais. Une version française vous sera fournie sur simple demande à support@microtribe.net, et vous pouvez nous écrire en français à tout moment — y compris pour toute demande d'accès, de rectification ou de suppression.