01Who we are
Lofi Gangs ("Lofi Gangs", "we", "the Service") is a local news outlet covering Vigneux-sur-Seine (Essonne, France), published under the handle @lofi_gangs, and the editorial publishing tool its desk uses. The tool prepares editorial content and publishes it to the outlet's own Facebook Page, Instagram account and Threads profile.
The Service is operated by Omar Toure on a non-commercial basis. It is an internal tool: it is not offered to the public, and no account belonging to a third party can be connected to it.
The data controller for the processing described here is identified in full on our Legal Notice page. Contact: contact@lofigangs.store.
02Who this applies to
This Privacy Policy covers:
- Authorised users — the members of the Lofi Gangs desk who connect the outlet's own accounts and approve posts.
- Website visitors — anyone visiting https://lofigangs.store.
Lofi Gangs does not process personal data about the readers of the published posts, and collects no data about any Facebook or Instagram user other than the holder of a connected account.
03Data we collect
We collect only what is needed to publish to a connected account.
| Data | Source | Why we need it |
|---|---|---|
| Facebook Page ID and Page name | Facebook Graph API (pages_show_list) |
To identify which connected Page a post belongs to. |
| Instagram professional account ID and username | Facebook Graph API (instagram_basic) |
To identify the Instagram account linked to the Page. |
| User access token and Page access token | Facebook Login (OAuth) | To publish on the account holder's behalf without asking them to log in again. |
| Granted permissions (scopes) | Facebook Login (OAuth) | To know what the account holder actually authorised. |
| Content we publish: images, videos, captions | Created by the editorial user | This is the post itself. |
| Publication identifiers, status and timestamps | Graph API responses | To confirm a post went out, and to prevent publishing it twice. |
| Aggregate post metrics (views, interactions) | Graph API (pages_read_engagement) |
To report performance per post and per format. No individual reader is identified. |
| Technical logs (execution ID, error messages, timestamps) | Our own servers | To detect and fix failures, and to keep the Service secure. |
| Website request data (IP address, user agent) | Our web server and Google Fonts — see section 09 | Unavoidable in serving the page. Not used to build a profile. |
What we do not collect
- No data about Facebook or Instagram users other than the holder of a connected account.
- No follower lists, friend lists, direct messages, comments, or browsing activity.
- No identity of the people who view, like or share a published post — metrics are aggregate only.
- No advertising identifiers, no behavioural tracking, no cookies on this website.
- No payment data. Lofi Gangs takes no payment.
- No special-category data under Article 9 GDPR.
04Permissions we request
Lofi Gangs requests the minimum Meta permissions needed to do its job:
- pages_show_list — list the Pages the account holder administers, so the right one can be selected and shown in the Service.
- pages_manage_posts — publish an approved photo, video or text post to the connected Page.
- pages_read_engagement — read aggregate view and interaction counts on posts the Service published.
- instagram_basic — identify the Instagram professional account linked to the Page.
- instagram_content_publish — publish an approved post to that Instagram account.
These permissions are granted explicitly during the Facebook authorisation flow and can be withdrawn at any time. Withdrawal takes effect immediately: the tokens we hold stop working.
05How we use the data
- Authenticate with Meta and keep the connection alive.
- Upload and publish content the editorial user has approved.
- Record whether a publication succeeded or failed, and prevent duplicate publication.
- Report aggregate performance of published posts.
- Diagnose technical errors and protect the Service against abuse.
We do not use the data for profiling, for automated decision-making producing legal effects, or for advertising. We do not sell it, rent it, or share it with anyone.
06Legal basis (GDPR)
Lofi Gangs is operated from France and complies with Regulation (EU) 2016/679 (GDPR).
| Processing | Legal basis |
|---|---|
| Providing the Service: authentication, storing tokens, preparing and publishing content, reporting results | Performance of a contract — Art. 6(1)(b). The user asks us to publish to their account; we cannot do it without this data. |
| Connecting a Facebook Page or Instagram account and granting permissions | Consent — Art. 6(1)(a), given in Meta's own authorisation screen and withdrawable there at any time. |
| Technical logs, security, abuse prevention, duplicate-publication guards | Legitimate interest — Art. 6(1)(f), in keeping the Service working and secure. |
| Retaining records where the law requires it | Legal obligation — Art. 6(1)(c). |
Withdrawing the authorisation ends our ability to publish and triggers deletion of the tokens. It does not by itself erase everything we hold; to request full erasure, see section 11.
07Where data is stored
The Service runs on infrastructure located in the European Union: a dedicated virtual server hosted by Hetzner Online GmbH (Germany) and a managed PostgreSQL database and object storage hosted by Supabase in an EU region.
Access to the servers is restricted to the operator, over authenticated connections. All traffic to and from this website and to the Graph API uses HTTPS/TLS. Access tokens are held in a restricted database table, are never displayed publicly, and are never shared.
08International transfers
Our own hosting and database are in the European Union. However, some processing necessarily involves parties that may operate or provide support from outside the European Economic Area:
- Meta Platforms — content we publish is sent to Facebook, Instagram or Threads and becomes public there. From that point it is governed by Meta's own Privacy Policy and global infrastructure.
- Google (Fonts) — see section 09.
- Our own providers — even with EU-region hosting, a provider may use affiliates or sub-processors, or provide technical support, from a third country.
Where such a transfer occurs, it relies on the mechanisms available under Chapter V GDPR, typically Standard Contractual Clauses or an adequacy decision, as set out by the provider concerned. We do not claim that no data ever leaves the EEA.
09Cookies, analytics and web fonts
This website sets no cookies and runs no analytics, advertising or tracking scripts. There is no consent banner because there is nothing to consent to on that front.
Typefaces are loaded from Google Fonts (Google Ireland Limited, and Google LLC). As a result, your browser sends a request to Google's servers when you open a page, and Google receives your IP address, user agent and the referring page as part of serving the font files. Google acts as a separate provider for that request, may process it outside the EEA under the mechanisms described in section 08, and we have no access to what it records. The legal basis is our legitimate interest in presenting the site legibly and consistently — Art. 6(1)(f).
If you would rather avoid this, a browser extension that blocks third-party font requests will prevent it; the site remains readable with fallback typefaces.
10Retention
| Data | Kept for |
|---|---|
| Access tokens | While the account is connected. Deleted within 7 days of disconnection or revocation. |
| Page and Instagram account identifiers | While the account is connected; deleted with the connection. |
| Published content and publication identifiers | Up to 24 months as an editorial archive, then deleted. |
| Production images and video | Purged 7 days after publication. |
| Aggregate post metrics | Up to 24 months. |
| Technical logs | 90 days maximum. |
| Records we must keep by law, or must retain to establish or defend a legal claim | The period required by the applicable law, then deleted. |
11Your rights, and how to delete your data
Under the GDPR you have the right to access, rectify, erase, restrict and port your personal data, to object to processing based on legitimate interest, and to withdraw consent at any time.
Full step-by-step instructions, including what happens at each stage and how long it takes, are on our dedicated page: Lofi Gangs data deletion instructions. In summary:
- Revoke the authorisation in Facebook: Settings & privacy → Settings → Apps and websites → select Lofi Gangs → Remove. This invalidates our tokens immediately.
- Email contact@lofigangs.store to request erasure of everything else we hold. We confirm in writing.
We answer requests within one month, extendable by two further months for complex requests, in which case we will tell you why.
If a publication concerns you and you want a correction, a removal or a right of reply, write to the same address. Every request receives an answer within 30 days.
If you believe your data has been handled unlawfully, you may lodge a complaint with the French supervisory authority, the CNIL (www.cnil.fr), or with the authority of your habitual residence.
12Security incidents
If a personal data breach occurs that is likely to result in a risk to your rights, we notify the CNIL within 72 hours of becoming aware of it, and inform affected users directly where the risk is high.
13Children
Lofi Gangs is a professional editorial tool and is not directed at children. Authorised users must be at least 18. We do not knowingly collect data from anyone under 18.
14Changes to this policy
We may update this Privacy Policy. The effective date at the top of this page always reflects the current version. Material changes affecting how personal data is used are announced on this page before they take effect, and notified by email to connected users.
15Contact
Omar Toure — Lofi Gangs
contact@lofigangs.store
Full identification and hosting details: Legal Notice