Last updated 21 September 2026
Privacy Policy
This policy explains what information HookSend collects, what we use it for, who helps us process it, how long we keep it and how you can have it deleted. It covers HookSend customers and the people who comment on or message our customers' Instagram accounts.
1. Who we are
HookSend is run by HOOKSEND SOFTWARE, a business registered under Udyam with the Ministry of MSME, Government of India. "We" and "us" in this policy mean HOOKSEND SOFTWARE.
This policy covers the HookSend website (https://hooksend.in), the dashboard, and the automations HookSend runs on connected Instagram accounts. It applies to two groups of people:
- customers, meaning the people and businesses who sign up for HookSend and connect an Instagram professional account
- contacts, meaning the people who comment on, reply to, mention or message a customer's Instagram account
We decide how customers' own account details are used. For contacts, the customer decides what their automations collect and why, and HookSendprocesses that information on the customer's behalf.
2. Information you give us
- Your name, email address, mobile number and password when you sign up. We store only a hash of your password, never the password itself.
- Your name, email address and profile picture from Google, if you sign in with Google.
- The email addresses of team members you invite to your workspace.
- What you set up in HookSend: campaign keywords and messages, links, buttons and product cards, your storefront, images you upload, and the documents and text you add to knowledge bases.
- Support tickets, including any files you attach.
- Your UPI ID, the name on it and your PAN, only if you join the affiliate programme and ask to be paid in cash.
3. Information we receive from Instagram
When you connect an Instagram professional account through Meta's login, you grant HookSend these permissions, and Meta sends us the data each one covers:
instagram_business_basic: your account's Instagram ID, username, name, profile picture and follower count, and your posts and reels with their captions, images and links.instagram_business_manage_comments: comments on your posts and reels, with each commenter's username and Instagram ID. This permission also lets HookSend reply to, hide or delete comments for you.instagram_business_manage_messages: messages people send to your account, including story replies and mentions, button taps and read receipts. This permission also lets HookSend send DMs for you.instagram_business_manage_insights: account and post insights, such as daily follower changes and the views, reach, saves and shares of your posts and reels.
Meta also gives us an access token that lets HookSendact for your account. We never receive or ask for your Instagram password, and we don't scrape Instagram or automate a browser to use it.
4. Information about contacts
When someone comments on, replies to, mentions or messages a customer's Instagram account, HookSend receives:
- their Instagram username, Instagram ID and, where Instagram provides it, their name
- the text of their comment or message
- whether they follow the customer's account, when the customer uses the follow gate
- an email address or phone number, only if they type one in reply to a customer's lead form or flow
- when they open a tracked link: the time, their browser's user agent, the referring page, and their IP address stored only as a one-way hash
5. How we use information
We use the information above:
- To run the automations each customer sets up: private replies to comments, DMs, public comment replies, follow-ups, lead capture, DM flows and knowledge base answers.
- To run Comment Guard, which checks new comments against the customer's rules and can hide or delete them, when the customer turns it on.
- To spot brand collaboration offers in a customer's DMs and flag likely scams. Customers can turn this off.
- To show customers their reports, DM logs, leads, inbox and storefront.
- To sign you in, take payments, send receipts and answer support requests.
- To send service emails, such as sign-in codes, plan reminders, weekly reports and the daily brand collaboration summary.
- To keep sending within Meta's limits, prevent abuse and keep HookSend secure.
We use Instagram data only to provide these features to the customer who connected the account. We don't sell or rent any data, share it with data brokers or advertisers, or use it for advertising. HookSend does not train AI models on your data.
6. AI processing
Some features send text to AI models to do their job:
- Comment Guard's AI rules send the comment being checked, and the one-line description of your business if you have added one.
- Knowledge base answers send the person's question, the relevant parts of your documents, and their name for the greeting.
- Brand collaboration detection sends incoming DMs, apart from very short ones such as greetings.
- The AI writing tools send the campaign text or description you give them.
- When you upload a knowledge base document, its text is turned into search data (embeddings) by Cloudflare Workers AI.
The AI models are run by Groq, Cloudflare Workers AI and Google (Gemini), and by an AI service we run ourselves. We may also use another model provider we choose.
7. Who processes data for us
- Meta Platforms, Inc.: Instagram login, the Instagram API and webhooks.
- Groq, Cloudflare and Google, and any other model provider we use: the AI features described above. Some AI requests run on our own service instead.
- Zoho ZeptoMail: sends our emails, such as sign-in codes, receipts and notifications.
- Google Firebase: sends a code by SMS if you reset your password by phone, with Google reCAPTCHA checking the request.
- Google: sign-in, if you choose to sign in with Google.
- Google Analytics: website statistics, only if you accept analytics cookies.
- Our UPI payment gateway at
upi.hooksend.in: creates each payment and receives the name, email address and mobile number on your account, the amount and the order ID. The payment itself is handled by your UPI app and the banks involved. We never see your UPI PIN or bank account details. - Dodo Payments, for card payments made outside India. Dodo sells the purchase to you as our merchant of record: it receives your name, email address, billing country and postal code, and the order, collects any sales tax or VAT, and issues the invoice. You type your card details into Dodo's own form, so they go to Dodo directly and we never see them.
HookSend runs on servers that we rent and manage, and the images you upload are stored there. Some of the providers above are based outside India, so your information may be processed in other countries.
Apart from these providers, we share information only when the law requires it.
8. Cookies
Necessary cookies keep you signed in, protect forms, show prices in the currency you would pay in (rupees in India, US dollars elsewhere) and remember your cookie choice. Whether you are in India is worked out on our own server from the country of your internet address, using APNIC's allocation records and the ip-location-db country data from the NRO (CC BY 4.0). Your address is not sent anywhere to do it. A functional cookie remembers the referral link you arrived through, so whoever invited you gets credit. Analytics cookies, such as Google Analytics, load only if you accept them.
You choose in the cookie banner, where rejecting is as easy as accepting. To change your answer later, clear HookSend's cookies in your browser and the banner will ask again.
9. How long we keep information
- Your account and workspaces, and everything in them, including Instagram data, DM logs and leads: until you delete them or delete your account.
- Instagram access tokens: until you disconnect the Instagram account or delete your HookSend account.
- Comments that Comment Guard deletes: the text is kept for 48 hours, so a wrong call can be noticed and an impersonator reported, and then erased.
- Copies of the events Instagram sends us, such as new comments and messages, and our service logs: kept to run, fix and secure HookSend. They can contain comment and message text, and they are not removed automatically when an account is deleted. We delete them on request (see section 11).
- Payment records: kept for our accounts, for tax, and in case a payment is disputed.
- Support tickets: kept after an account is deleted, so we have a record of what was asked and answered, unless you ask us to delete them.
10. How we protect information
- Instagram access tokens are encrypted with AES-256-GCM before they are stored. The keys we use for AI providers are encrypted the same way.
- Passwords are stored only as bcrypt hashes.
- Data travels over HTTPS between your browser and HookSend, and between HookSend and Meta.
- Every webhook from Meta is checked against Meta's signature (
X-Hub-Signature-256) before we act on it, so forged events are rejected. - IP addresses from tracked link clicks and referral link visits are stored only as one-way hashes.
11. Deleting your data and other choices
- Customers can delete their HookSend account in Settings, under Danger Zone. This deletes the account and the workspaces it owns straight away.
- You can disconnect an Instagram account in Settings, or remove HookSend from Instagram under Settings, Website permissions, Apps and websites.
- To have the rest deleted, including the records that account deletion does not reach, sign in and open a support ticket asking for it. We act on deletion requests only when they come from inside the account, so we know the account's owner asked. We don't accept them by email.
- If you commented on or messaged a business that uses HookSend, ask that business. It decides what happens to the details you gave it.
Step-by-step instructions, and what is deleted and what is kept, are on our data deletion page.
You can change most of your details yourself in Settings. For any other request about your data, such as a correction, write to [email protected]. The daily brand collaboration email has a one-click unsubscribe link.
12. Age
HookSend accounts are for people aged 18 or over.
13. Changes to this policy
We may update this policy. When we do, we change the date at the top of this page.
14. Contact
For questions about this policy or your data, write to us: