Privacy Policy
Carosell — last updated: August 2026
Carosell ("the Service") helps users create, schedule, and publish content on their own social profiles. This notice, provided pursuant to art. 13-14 of Regulation (EU) 2016/679 ("GDPR"), explains what data we process, why, with whom, and what your rights are.
Data controller
The data controller is iESTETIC S.r.l., with registered office at via Alfredo Fiorini 122, 00132 Roma (RM), VAT 14247541007. You can contact us at any time at supporto@carosell.it.
Data we process
- Account: email, password (stored only in encrypted/hashed form, never in plain text), name and optional phone number, subscription plan.
- Social account connection: when you connect an account (e.g. Instagram or TikTok) we receive from the platform an access token and basic profile information (username/display name, account identifier) and, where available, aggregated profile and post statistics (followers, views, likes, comments, saves, shares).
- Content: the text and images of the carousels you create and publish, and your brand elements (logo, colors).
- Support: the messages you send us via chat or ticket, which may contain name, email, and phone number.
- Technical and security data: IP address and log information needed to protect access (abuse prevention, limiting login attempts).
Why we process data (purposes and legal bases)
- Providing the Service — creating, scheduling, and publishing the content you approve and managing your account. Legal basis: performance of a contract (art. 6.1.b).
- Connecting your social profiles — only at your request and voluntary action. Legal basis: consent (art. 6.1.a), revocable by disconnecting the account.
- Security and abuse prevention — logs and IP addresses, limiting login attempts. Legal basis: legitimate interest (art. 6.1.f).
- Improving suggestions based on your results. Legal basis: legitimate interest (art. 6.1.f).
- Legal obligations — tax and accounting requirements related to the subscription. Legal basis: legal obligation (art. 6.1.c).
We do not sell your data and do not use it for third-party advertising.
Providers and recipients
To operate the Service we rely on selected providers who process data on our behalf (data processors) or who receive it only through your voluntary action (recipients). We do not disclose your data to other parties.
| Provider | Role | Data | Location |
|---|---|---|---|
| Vercel Inc. | Website hosting and delivery (CDN) | App delivery; technical logs and server IP addresses | USA (SCC) |
| Supabase | Account data database | Account, content, brand, tickets, encrypted tokens | EU |
| Stripe | Payment and subscription management | Email, billing data, and payment status (card data stays with Stripe, never on our servers) | USA (SCC) |
| Anthropic (Claude) | Artificial intelligence for generating content and support | Content texts and instructions; support messages | USA (SCC) |
| Aruba S.p.A. | Sending service emails | Recipient email and message content | Italy (EU) |
| Sign-in with Google (only if you use it) | Email and name of the Google profile | USA (SCC) | |
| Meta / Instagram | Publishing to your profiles (only if you connect the account) | Access token and profile statistics | USA (SCC) |
| TikTok | Publishing to your profiles (only if you connect the account) | Access token and basic profile data | Outside the EU (SCC) |
| Google Analytics | Website traffic statistics (only with your consent) | Pseudonymous usage data: pages viewed, referral source, device | USA (SCC) |
| Meta Pixel | Advertising campaign measurement and effectiveness (only with your consent) | Navigation and conversion events for retargeting | USA (SCC) |
Transfers outside the European Union
Some providers (e.g. Vercel, Anthropic, Google, Meta, TikTok) are based or have servers in the United States or other non-EU countries. In these cases the transfer takes place on the basis of the Standard Contractual Clauses approved by the European Commission (art. 46 GDPR) and with adequate security safeguards. The database that hosts your data, on the other hand, is configured in a region of the European Union (EU).
How long we keep data
- Account and content: for as long as you keep your account active; upon deletion they are removed, except for legal obligations (e.g. tax data kept for the periods required by law).
- Login session: up to 30 days, then it expires.
- Connected social tokens: until you disconnect the account or delete the profile.
- Security logs and IP: for the time strictly necessary to protect the Service.
- Password reset link: valid for a very short time, then no longer usable.
Your rights
Pursuant to art. 15-22 GDPR you have the right to:
- access your data and request a copy of it;
- rectify inaccurate or incomplete data;
- request erasure ("right to be forgotten") or restriction of processing;
- obtain portability of your data in a readable format;
- object to processing based on legitimate interest and withdraw any consent given, at any time.
To exercise them, write to supporto@carosell.it. You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante).
Security
We adopt appropriate technical measures: passwords protected with hashing functions, session and social tokens stored in encrypted form, encrypted connections (HTTPS), and access protected against repeated attempts.
Cookies
We use necessary technical cookies and, only with your consent, statistics and marketing cookies. You can accept, refuse, or withdraw them at any time. Details are in the Cookie Policy.
Changes
We may update this notice; in case of significant changes we will announce it on the website and update the date above.
Contact
For any request regarding your data: supporto@carosell.it. See also the Terms and the Cookie Policy.