CCO Suite is a private marketing tool operated by Global Footcare Pty Ltd. It is used by our staff and by brands and retailers who ask us to manage their social media accounts.
This policy explains exactly what CCO Suite collects from Facebook and Instagram, why, how long it is kept, and how to have it removed. It covers only CCO Suite. It does not cover the Comfort Co, Naturalizer, Vionic or Natural Fit online stores, which have their own policies.
Two different groups of people appear in this policy, and it matters which one you are.
We only request the permissions the tool actually uses. This is the complete list.
| Permission | What it gives us | Why we need it |
|---|---|---|
| pages_show_list | The names and IDs of the Pages you manage | So you can pick which Page to work with |
| pages_read_engagement | Posts on your Page and whether they published | To show what has gone out and confirm a scheduled post succeeded |
| pages_read_user_content | Comments customers leave on your Page's posts | To show them in the inbox so your team can answer them |
| pages_manage_posts | Permission to publish to and delete from your Page | To schedule and publish the posts you plan in the tool |
| pages_manage_metadata | Permission to subscribe your Page to our notifications | So new messages and comments reach the inbox as they arrive, instead of us polling |
| pages_manage_engagement | Permission to reply to, hide and delete comments | To let your team moderate and answer comments |
| pages_messaging | Messages sent to your Page | To show customer messages in one inbox and let your team reply |
| instagram_basic | Your Instagram business account name, ID and follower count | To link the Instagram account to its Page and show its size |
| instagram_content_publish | Permission to publish to Instagram | To publish the posts and reels you schedule |
| instagram_manage_comments | Instagram comments and permission to reply | To let your team answer comments |
| instagram_manage_messages | Instagram direct messages, including story replies | To show them in the same inbox as Facebook messages |
| instagram_manage_insights | Aggregate figures only: when your followers are online, reach, follower count | To suggest the best time to post and show reach on the dashboard. No individual customer data |
| instagram_shopping_tag_products | Your own Instagram Shop catalogue, and permission to tag products in a post | So a post can tag the products it features and customers can tap through to buy |
| catalog_management | Read-only access to your own product catalogue | To let you search your catalogue and pick products to tag. We never create, edit or delete anything in it |
We do not request, and cannot see, your Facebook friends, your personal profile beyond your name and account ID, your posts on your own timeline, your email address from Facebook, your ad account, your advertising or billing data, or anything belonging to a Page you have not connected. We ask for read-only access to your product catalogue and never change it.
| Data | Kept for |
|---|---|
| Which Pages and Instagram accounts you connected | Until you disconnect them or ask us to delete your data |
| Access tokens | Until they expire or you disconnect. Never shown in the app once saved |
| Posts you scheduled through CCO Suite | Kept as a record of what was published |
| Customer messages and comments, and our replies | 120 days after a conversation is marked finished. Unresolved conversations are kept until they are resolved |
| Aggregate figures such as follower counts and reach | Around 13 months, as daily totals with no individual customer data |
Message and comment content is only ever read from the accounts you connected, and only from the point at which you connected them.
Nobody. We do not sell, rent, licence or share this data with any third party for their own purposes. We do not use it for advertising or profiling, we do not build audiences from it, and we do not use it to train machine learning models.
The tool runs on service providers who host it on our behalf and who process data only under our instruction:
Because our hosting is in the United States, data is transferred outside Australia. We rely on our providers' contractual data protection terms for that transfer.
You can have everything we hold about you removed. There are two ways:
Either way we delete every message and comment we hold from you, and the record of your connection. You can check a completed request at /data-deletion using the confirmation code Meta gives you. Note that removing it from CCO Suite does not remove your comment from Facebook or Instagram itself, which you control.
Disconnecting an account in Connections removes its tokens and stops all access. To have your user account and everything associated with it deleted, email ncoombridge@globalfootcare.net.
Under the Australian Privacy Act you can ask us what we hold about you, ask us to correct it, and ask us to delete it. Under the GDPR, if you are in the UK or EU, you additionally have the right to object to processing, to restrict it, and to receive a copy in a portable form. Email ncoombridge@globalfootcare.net and we will respond within 30 days.
If you are not satisfied with how we handle a request you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
CCO Suite is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children. If a customer message reaches us from someone we learn is a child, we delete it.
If we change what we collect or how long we keep it, we will update this page and change the date at the top. Material changes are told to connected account managers directly.
Global Footcare Pty Ltd, Queensland, Australia. Privacy enquiries: ncoombridge@globalfootcare.net.