1. Introduction
This Privacy Policy explains how Social Hampster collects, uses, stores, shares, and deletes information when you use our Framer plugin, our web dashboard, and our website.
Social Hampster is a plugin for Framer that displays live social media feeds on websites. To do that, we connect to social platforms on your instruction, retrieve content from the accounts you authorise, store that content temporarily, and display it on the websites you specify.
Please read Section 4 and Section 7 carefully. They describe exactly what we retrieve from social platforms and how we handle access tokens.
2. Who we are
Social Hampster is operated by 7 Seers, the data controller for the purposes of this policy.
Entity: 7 Seers
Attn: Privacy Department
Registered address: Lucknow, Uttar Pradesh, India
Privacy contact: hello@7seersmedia.com
Security contact: security@7seersmedia.com
Website: https://socialhampster.com
3. Scope
This policy applies to three groups of people:
Account holders. Designers, agencies, and site owners who create a Social Hampster account and connect social accounts.
Connected account owners. The owner of any social media account authorised through Social Hampster, where this differs from the account holder (for example, an agency connecting a client's Instagram account).
Site visitors. People who visit a website displaying a Social Hampster component.
4. Information we collect
4.1 Account information
When you create an account we collect your name, email address, password (stored hashed, never in plain text), and, where applicable, your company name.
4.2 Content and data from connected social platforms
When you authorise a social account, we retrieve data through the official APIs of Instagram, Facebook, Threads, YouTube, and Dribbble. Depending on the platform and the components you use, this includes:
Public posts, captions, and post text
Images, video files, thumbnails, and the media URLs pointing to them
Post timestamps and permalinks
Engagement counts such as likes, views, and comments
Profile information for the connected account: username, display name, profile picture, biography, follower and post counts
We store this content on our servers. We do not fetch it live on every page load. We cache it and refresh it on a schedule determined by your plan (every 24 hours on Free, every 6 hours on Personal, every 2 hours on Business). This caching is what allows feeds to load quickly and to keep working between refreshes.
We retrieve only content that is public or that the account owner has explicitly authorised us to access. We do not access private messages, direct messages, follower lists, or any content the connected account has not made available through the platform's API.
4.3 Access tokens
When you authorise a connection, the social platform issues us an access token. We store these tokens. They are how we retrieve your content on the refresh schedule described above without asking you to log in again. See Section 7 for full detail on how tokens are secured and deleted.
4.4 Site visitor and analytics data
When a visitor loads a page containing a Social Hampster component, we collect limited technical data in order to serve the feed, apply plan limits, and provide the analytics available on paid plans:
IP address (used for delivery, security, and abuse prevention; not used to build advertising profiles)
Browser type, device type, and operating system
The referring domain and page
Component impressions and clicks
This data is aggregated for reporting. We do not use it to identify individual visitors, and we do not sell it or share it with advertisers. Analytics are computed on our own infrastructure; we do not use a third-party analytics provider. When you disconnect a social account, the analytics associated with it are deleted along with everything else.
4.5 Payment information
Paid subscriptions are processed by Polar, our payment provider. We do not receive or store full card numbers. We retain a record of your subscription tier, billing status, and transaction identifiers.
4.6 Support communications
If you contact us we retain the correspondence and any information you include in it.
5. How we use information
We use the information described above to:
Provide the service: retrieve, store, and display your social content on your websites
Authenticate you and secure your account
Enforce plan limits such as connected websites and monthly view allowances
Provide the analytics dashboard on paid plans
Respond to support requests
Detect, investigate, and prevent abuse, fraud, and security incidents
Send service announcements and, where you have consented, product updates
Comply with legal obligations
We do not sell, license, or rent any data obtained from social platforms. We do not use it to build advertising profiles, and we do not use it to train machine learning models.
6. Legal bases for processing (GDPR)
Where the GDPR applies, we rely on:
Contract: to provide the service you have signed up for
Consent: for connecting social accounts, for optional cookies, and for marketing email
Legitimate interests: for security, abuse prevention, and service improvement
Legal obligation: where we are required by law to retain or disclose information
You may withdraw consent at any time by disconnecting a social account, adjusting cookie settings, or unsubscribing from marketing email.
7. Access tokens and credentials
This section describes our handling of the credentials that connect your social accounts.
What we never collect. We never ask for, receive, or store your social media username and password. Authorisation happens entirely on the social platform's own login screen through OAuth. Your password is never transmitted to us.
What we do store. The social platform issues us an access token, and in some cases a refresh token, representing the permissions you granted. We store these tokens because they are required to refresh your feed on schedule.
How tokens are secured.
Encrypted at rest using AES-256
Transmitted only over TLS
Access restricted to the systems that perform feed synchronisation
Never exposed to browsers, never included in the published output of your website, and never shared with any third party other than the subprocessors listed in Section 10
Note on component identifiers. The siteId you paste into a Framer component is a public identifier, not a credential. It carries no access rights to your social account. Feed delivery is restricted to the domains you whitelist in your dashboard.
Token deletion. When you disconnect a social account, we revoke and delete the associated tokens immediately. Residual copies in encrypted backups are purged within 30 days. The same applies if you revoke access from the social platform's own settings.
8. Data retention and deletion
We retain data only as long as necessary for the purposes described in this policy.
Deleted immediately when you disconnect a social account:
Access and refresh tokens for that connection
All cached posts, captions, media URLs, thumbnails, timestamps, and engagement counts
Profile information retrieved for that account
Component analytics associated with that connection, including impressions and clicks
Disconnection is immediate and irreversible. We do not retain a copy in order to restore the connection later. Residual copies in encrypted backups are purged within 30 days.
Everything else:
Account information — for the life of your account, then deleted within 30 days of your deletion request
Site visitor analytics — retained for a maximum of 12 months while a connection is active, then aggregated or deleted, and deleted immediately on disconnection
Billing records — retained as required by applicable tax and accounting law
Support correspondence — 24 months from last contact
We also delete data promptly when it is no longer necessary for a legitimate business purpose, when we stop operating the service through which it was collected, when you ask us to, or when a social platform requires us to.
9. How to delete your data
To delete the data for one social account, disconnect it. You can do this at any time, yourself, from either the Social Hampster plugin inside Framer or the web dashboard. Everything listed in Section 8 is deleted immediately. No request to us is required.
To delete your Social Hampster account and all remaining personal information, email hello@7seersmedia.com from your registered email address with the subject "Data Deletion Request." We complete account deletion within 30 days and may ask you to verify your identity first.
Full instructions, including how to remove Social Hampster's access from each social platform's own settings, are at https://socialhampster.com/data-deletion.
10. Data sharing and subprocessors
We do not sell your data. We share it only in these circumstances:
Subprocessors. We use the following third-party providers to operate the service. Each is contractually bound to process data only on our instructions and to standards consistent with this policy.
Google Cloud Platform — hosting and application infrastructure
Google Cloud Platform (Cloud SQL for PostgreSQL) — database and storage
Polar — payment processing
Zoho ZeptoMail — transactional email
We do not use a third-party analytics provider. All analytics are computed and stored on our own infrastructure.
Legal requirements. Where we are required by law, court order, or a valid request from a public authority.
Business transfer. If 7 Seers is involved in a merger, acquisition, or sale of assets, data may transfer as part of that transaction. We will notify you before your data becomes subject to a different privacy policy.
With your direction. Where you explicitly instruct us to share data with a third party.
11. Cookies and tracking
We use:
Essential cookies for authentication and security. These cannot be disabled.
Analytics cookies to understand how the dashboard is used.
Preference cookies to remember your settings.
You can manage cookies through your browser settings. Disabling essential cookies will prevent you from logging in.
Social Hampster components displayed on customer websites do not inject social platform tracking scripts. Content is rendered as native Framer elements.
12. International data transfers
We operate from India, and our infrastructure runs on Google Cloud Platform. If you are in the European Economic Area, the United Kingdom, or another region with data transfer restrictions, your data will be transferred to and processed in these locations.
Where required, we rely on the European Commission's Standard Contractual Clauses, and the UK International Data Transfer Addendum for UK transfers, together with appropriate technical and organisational safeguards. You may request a copy of the relevant transfer mechanism by writing to hello@7seersmedia.com.
13. Data security
We maintain administrative, physical, and technical safeguards designed to protect data against unauthorised access, disclosure, alteration, and destruction, including:
Encryption in transit (TLS) and at rest (AES-256)
Role-based access control, limited to personnel who need it
Domain whitelisting for feed delivery
Logging and monitoring of access to systems holding platform data
Reporting a vulnerability. If you believe you have found a security vulnerability in Social Hampster, email security@7seersmedia.com. We will acknowledge your report within 3 business days and keep you updated as we investigate. Please do not publicly disclose the issue until we have had a reasonable opportunity to address it.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant supervisory authority as required by law.
14. Your privacy rights
All users. You may request access to your data, correction of inaccurate data, deletion of your data, a copy of your data in portable form, restriction of processing, or object to processing. To exercise any of these, email hello@7seersmedia.com. We respond within 30 days and may ask you to verify your identity.
EEA and UK residents (GDPR). You have the rights above and the right to lodge a complaint with your local supervisory authority.
California residents (CCPA/CPRA). You have the right to know what personal information we collect and the purposes for it, the right to delete it, the right to correct it, and the right not to be discriminated against for exercising these rights. We do not sell or share personal information as those terms are defined under the CCPA. To make a request, email hello@7seersmedia.com.
15. Children's privacy
Social Hampster is not intended for anyone under 13, and we do not knowingly collect personal information from children under 13. If we learn we have done so, we will delete it. If you believe a child has provided us information, contact hello@7seersmedia.com.
16. Platform-specific disclosures
Meta platforms (Instagram, Facebook, Threads). Our use of data obtained through Meta's APIs complies with the Meta Platform Terms and Developer Policies. We process this data solely to provide the service you requested, we keep data belonging to different customers separated, and we delete it as described in Section 8.
YouTube. Social Hampster uses YouTube API Services. By using our YouTube components you agree to be bound by the YouTube Terms of Service. Google's handling of data is governed by the Google Privacy Policy. You can revoke our access to your YouTube data at any time via Google's security settings.
Dribbble. Our use of the Dribbble API is governed by Dribbble's own terms and privacy policy.
You can revoke our access at any time from each platform's own connected-apps settings, independently of anything you do in Social Hampster.
17. Links to other websites
Our website and dashboard may link to third-party sites. We are not responsible for their privacy practices and encourage you to read their policies.
18. Changes to this policy
We may update this policy. Material changes will be notified by email or by an in-product notice before they take effect. The date at the top reflects the most recent revision.
19. Contact us
7 Seers — Attn: Privacy Department
Lucknow, Uttar Pradesh, India
Privacy: hello@7seersmedia.com
Security: security@7seersmedia.com
Data deletion: https://socialhampster.com/data-deletion
