Security & data handling
This page doubles as the answer sheet for Meta's data processing questionnaire.
What data the connector accesses and why
| Data | Purpose | Retention |
|---|---|---|
| Email (verified), optional name, phone | Account identity, receipts, OTP sign-in | Until the user deletes their account or 24 months of inactivity |
| Recipient name, email, phone, shipping address | Passed to Snappy to fulfil the order; carriers need the phone | Life of the order + 7 years (tax/accounting), then anonymised |
| Quotes, checkouts, orders, event timeline | Purchase history, support, refunds | Same as above |
| Stripe payment intent / refund ids | Reconciliation and refunds. No card data ever reaches the platform | Same as above |
| Agent client id and scopes | Authorization and audit | Life of the grant |
| Sent messages (email/SMS bodies) | Proof of delivery for receipts | 90 days |
| SMS consent records (number, time, agent, consent text, STOP) | Legal basis for texting; opt-out enforcement | 5 years (TCPA record keeping) |
| Support requests | Returns, damaged / missing items, refunds | Life of the order + 7 years |
We do not sell data, build advertising profiles, or use it for anything other than fulfilling and supporting purchases. Deleting a user removes their profile and tokens immediately and anonymises orders after the legal retention period.
Protection
- All traffic TLS 1.2+ behind a Google global load balancer; HSTS on.
- Cloud SQL with private IP only, inside the project VPC; encrypted at rest (Google-managed keys).
- Secrets in Secret Manager, injected into Cloud Run at runtime; nothing in the repo or CI logs.
- Tokens, OTP codes and client secrets are stored as salted SHA-256 hashes.
- Stripe and Snappy webhooks are signature-verified and replay-protected (unique event ids).
- Every admin action is audited with actor, target and before/after.
- Admin portal behind Google Identity-Aware Proxy (organisation accounts only), plus an in-app allowlist with viewer/admin roles; every privileged action audited.
- Provider credentials (Snappy, Stripe, SendGrid, Twilio) are entered in the portal and written straight to Secret Manager; they are never displayed, logged or stored in the database (only a masked last-4 and timestamp).
- Minimum-privilege IAM: separate service accounts for runtime, deploy, Terraform plan and Terraform apply (GitHub OIDC, no long-lived keys).
Credentials and prompts
Access tokens are never placed in tool descriptions, URLs, responses or logs (log redaction on authorization and cookie). Error messages never echo secrets.
Incident response
Security contact: security@snappy.com. We notify Meta at vendor-incident@meta.com within 48 hours of confirming an incident that affects Muse users, and cooperate with the investigation.
User controls
- Read-only grant at consent time.
- Revoke the agent at any time (
POST /oauth/revokeor via the agent platform); refresh-token reuse detection kills the whole family. - Receipt preferences and saved addresses are editable through the
profilescope.
Snappy Agents · agents.snappy.com · support@snappy.com