Privacy Policy
Last updated: August 4, 2026
Privacy Policy
MINICMO ("MINICMO", "we", "us") is operated by Mánahöll ehf., a private limited company registered in Iceland (company registration number / kennitala 510523-1050). This Privacy Policy describes how we collect, use, and protect personal data when you use the MINICMO platform at minicmo.io and app.minicmo.io.
We are committed to complying with the EU General Data Protection Regulation (GDPR), which applies in Iceland through the EEA Agreement and the Icelandic Data Protection Act no. 90/2018.
Contact for all privacy matters: help@minicmo.io
1. Our Two Roles: Controller and Processor
- For the MINICMO platform (your account, your organization, billing, platform usage), Mánahöll ehf. is the data controller.
- For websites our customers publish with MINICMO (sites on
*.minicmo.siteor custom domains) and for data our customers collect through the platform (e.g. contact-form submissions from their site visitors, their CRM records), the customer's organization is the data controller and Mánahöll ehf. acts as a data processor on their behalf. If you are a visitor to a customer's website, please contact that business directly about your data; we will assist them in fulfilling your request.
2. Information We Collect
Information you provide
- Account information: name, email address, and password (if you sign up with email) or your Google account profile (name, email, profile picture) if you sign in with Google
- Organization information: company name, industry, team members and roles
- Brand and content data: brand guides, logos, images, documents, personas, campaigns, and other content you upload or create in the platform
- Billing information: handled by our payment provider, Paddle (see section 5) — we do not store card numbers
- Communications: support requests and feedback
Information collected automatically
- Usage and technical data: IP address, browser type, device information, pages visited, and interactions with the platform
- Error and performance data: error logs and diagnostics (via Sentry) to keep the platform reliable
- Aggregate analytics: privacy-friendly, aggregated usage statistics (Vercel Analytics)
Cookies
We use cookies as described in our Cookie Policy — primarily strictly-necessary cookies for authentication and session handling.
3. Data from Connected Services (Facebook, Instagram, Google, and others)
MINICMO lets you connect third-party accounts to your organization. We only receive this data when you explicitly connect an account, and we use it solely to provide the feature you connected it for:
Facebook and Instagram (Meta Platforms)
- Instagram feed integration: when you connect an Instagram business account (via Facebook Login), we receive and store your Instagram business account ID and username, the connected Facebook Page's ID and name, and access tokens (stored encrypted). We fetch your Instagram media (posts, captions, images) to display it on your own website built with MINICMO.
- Meta Ads integration: when you connect a Meta ad account, we receive and store the ad account ID and name, an access token (stored encrypted), and daily aggregate campaign metrics (spend, impressions, clicks, conversions) for your marketing analytics dashboard.
- We do not post to Facebook or Instagram through these connections, and we never receive your Facebook password.
- You can disconnect these integrations at any time in the platform, which stops all further data collection. See our Data Deletion page for how to have this data deleted.
Google (Analytics and Search Console)
When you connect Google Analytics 4 or Google Search Console, we receive aggregate website metrics for your own properties to display in your marketing analytics dashboard.
Social publishing (Zernio)
If you use the Social Studio app, approved posts and their media are transmitted to our scheduling vendor, Zernio, to be published to the social accounts you connected there.
4. How We Use Personal Data and Legal Bases
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Providing the platform: accounts, organizations, apps, publishing websites | Contract performance (6(1)(b)) |
| Billing and subscription management | Contract performance (6(1)(b)) |
| AI-powered features you invoke (see section 6) | Contract performance (6(1)(b)) |
| Security, fraud prevention, error monitoring | Legitimate interests (6(1)(f)) |
| Service improvement via aggregate analytics | Legitimate interests (6(1)(f)) |
| Product updates and marketing emails | Consent (6(1)(a)) — withdraw anytime via unsubscribe |
| Legal compliance (accounting, tax) | Legal obligation (6(1)(c)) |
5. Who We Share Data With
We do not sell personal data. We share data only with service providers (sub-processors) that help us run the platform:
- Vercel — hosting and content delivery (also aggregate analytics)
- Neon — database hosting (PostgreSQL)
- Amazon Web Services — file storage (S3, EU region — Stockholm) and transactional email (SES)
- Paddle — payment processing and merchant of record for subscriptions; Paddle is the controller of the payment data it collects
- Sentry — error monitoring
- AI providers (OpenAI, Google, Anthropic) — only the content needed to fulfil an AI request you make (see section 6)
- Zernio — social media scheduling, only if you use Social Studio
- Meta Platforms and Google — when you connect those integrations (section 3)
We may also disclose data if required by law, and in connection with a merger, acquisition, or sale of assets (with notice to you).
6. AI Features
When you use AI features (content generation, image generation, and similar), the relevant input — such as your prompt and applicable brand-guide context — is sent to one of our AI providers (OpenAI, Google, or Anthropic) to generate the result. We use these providers through their business APIs, under terms that do not permit them to use your content to train their models. We never sell your content or use it to train models ourselves.
7. International Transfers
Your data is primarily stored in the EU/EEA. Where a provider processes data outside the EEA (e.g. in the United States), transfers rely on the EU–US Data Privacy Framework and/or Standard Contractual Clauses.
8. Data Retention
- Account and organization data: kept while your account is active; deleted within 30 days after account or organization deletion
- Billing records: kept for 7 years as required by the Icelandic Accounting Act
- Connected-service tokens (e.g. Instagram): deleted when you disconnect the integration or delete your account
- Error logs and backups: rotated automatically on fixed schedules
9. Your Rights
Under the GDPR you have the right to access, rectify, erase, restrict, and port your personal data, and to object to processing based on legitimate interests. You can:
- Delete your account yourself under Account → Delete account in the app
- Follow the instructions on our Data Deletion page
- Email help@minicmo.io — we respond within 30 days
You also have the right to lodge a complaint with the Icelandic Data Protection Authority, Persónuvernd (personuvernd.is), or your local supervisory authority.
10. Data Security
Data is encrypted in transit (TLS) and at rest; third-party access tokens are additionally encrypted at the application level. Access to production systems is restricted and authenticated.
11. Children
MINICMO is a business tool and is not directed at children. You must be at least 18 years old to create an account.
12. Changes to This Policy
We will post updates on this page and update the "Last updated" date. For material changes we will notify you by email or in-app notification.
13. Contact
Mánahöll ehf. (kennitala 510523-1050), Iceland Email: help@minicmo.io