iGCSocial
Terms · Data deletion · Sign in

Privacy Policy

Last updated: June 2026. This policy describes how iGCSocial, operated by iGuides Canada ("we", "us"), handles personal information. It is written to align with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).

1. Who we are

iGCSocial is a social media management platform that lets our team, and the businesses we work with, plan, create, schedule, and publish content to connected social media accounts. Questions about this policy or your information can be sent to social@iguides.ca.

2. Information we collect

  • Account information — your name, email address, and a securely hashed password; optional second-factor (authenticator/passkey) data.
  • Connected social accounts — when you authorize a platform (Facebook, Instagram, Threads, X, LinkedIn, Bluesky, Google Business Profile, TikTok), we receive and store the access tokens and the account identifiers needed to publish on your behalf. For Google Business Profile this is the business account and location identifiers of the locations you choose to connect; for TikTok it is your account's open ID and display handle. Tokens are encrypted at rest.
  • Content you create — posts, captions, comments, media, campaigns, brand profiles, and RSS sources you add.
  • AI provider keys — if you enable AI features, the API keys you supply are encrypted at rest and used only to call the provider you chose.
  • Usage and audit records — actions taken in the platform (logins, connections, approvals, publishing), with timestamps, IP address, and user agent, kept for security and accountability.
  • Cookies — a single session cookie to keep you signed in. We do not use advertising or third-party tracking cookies.

3. How we use information

  • To operate the service: scheduling and publishing the content you direct to the accounts you connect.
  • To generate content through the AI providers you configure, using your own keys.
  • To communicate with you about your account, approvals, and requests.
  • To secure the service, prevent abuse, and maintain an audit trail.
  • To meet legal and regulatory obligations.

We do not sell personal information, and we do not use the content of your connected accounts for advertising.

4. Platform data and third parties

We access your social media accounts only with your authorization, through each platform's official API, and only to provide the features you use (scheduling, publishing, and managing the content you direct). Our use of information received from Meta, LinkedIn, X, Google, TikTok, and other platforms complies with their respective Platform Terms and Developer Policies. We share information with service providers only as needed to run the platform, including:

  • Social platforms — Meta (Facebook, Instagram, Threads), X, LinkedIn, Bluesky, Google Business Profile, TikTok, to publish your content.
  • AI providers — OpenAI, Anthropic, and/or Google, only when you enable AI features and only with your keys.
  • Email delivery — our SMTP provider (e.g., Amazon SES or Google Workspace) for service messages.
  • Hosting — Canadian-based infrastructure.

4a. Google API Services — Limited Use

iGCSocial's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We request the business.manage scope for one purpose: to list the Business Profile locations you manage so you can choose which to connect, and to publish the posts you have composed and approved to those locations. We do not read or reply to reviews, do not change your business information, do not use Google user data to train generalized artificial-intelligence models, do not transfer it except as needed to provide this feature or as required by law, and do not use it for advertising. You can disconnect a location at any time from Channels, and revoke our access entirely at myaccount.google.com/permissions.

5. Data residency

We host platform data on servers located in Canada. Some third parties you choose to use (for example, a social platform or AI provider) may process data outside Canada under their own policies.

6. Security

Sensitive data — including OAuth tokens, second-factor seeds, and AI keys — is encrypted at rest with AES-256-GCM. Passwords are stored using bcrypt. Access is restricted, changes are recorded in an append-only audit log, and connections to the service use TLS.

7. Retention and deletion

We keep information for as long as your account is active or as needed to provide the service. You can disconnect any social account at any time, which revokes and deletes its stored tokens. To request access to, correction of, or deletion of your personal information, contact social@iguides.ca. We respond within the timelines required by PIPEDA. Step-by-step instructions are on our User Data Deletion page.

8. Your rights

Under PIPEDA you may request access to the personal information we hold about you, ask us to correct it, and withdraw consent (subject to legal or contractual limits). You may also contact the Office of the Privacy Commissioner of Canada.

9. Children

The service is intended for businesses and people 18 and older. It is not directed to children, and we do not knowingly collect their information.

10. Changes

We may update this policy. Material changes will be reflected by the "last updated" date above and, where appropriate, communicated to account holders.

Terms of Service · Sign in
© 2026 iGuides Canada . All rights reserved.