Security & data handling

This page doubles as the answer sheet for Meta's data processing questionnaire.

What data the connector accesses and why

Data Purpose Retention
Email (verified), optional name, phone Account identity, receipts, OTP sign-in Until the user deletes their account or 24 months of inactivity
Recipient name, email, phone, shipping address Passed to Snappy to fulfil the order; carriers need the phone Life of the order + 7 years (tax/accounting), then anonymised
Quotes, checkouts, orders, event timeline Purchase history, support, refunds Same as above
Stripe payment intent / refund ids Reconciliation and refunds. No card data ever reaches the platform Same as above
Agent client id and scopes Authorization and audit Life of the grant
Sent messages (email/SMS bodies) Proof of delivery for receipts 90 days
SMS consent records (number, time, agent, consent text, STOP) Legal basis for texting; opt-out enforcement 5 years (TCPA record keeping)
Support requests Returns, damaged / missing items, refunds Life of the order + 7 years

We do not sell data, build advertising profiles, or use it for anything other than fulfilling and supporting purchases. Deleting a user removes their profile and tokens immediately and anonymises orders after the legal retention period.

Protection

Credentials and prompts

Access tokens are never placed in tool descriptions, URLs, responses or logs (log redaction on authorization and cookie). Error messages never echo secrets.

Incident response

Security contact: security@snappy.com. We notify Meta at vendor-incident@meta.com within 48 hours of confirming an incident that affects Muse users, and cooperate with the investigation.

User controls

Snappy Agents · agents.snappy.com · support@snappy.com