← Back to Routella

Meta Business Messaging Privacy Notice

Last updated: September 24, 2026 · Operator: Routella, LLC, a Delaware limited liability company · 131 Continental Dr, Suite 305, Newark, DE 19713, United States · +44 7756 988088

This notice explains how Routella MCP handles data when an authorized business connects a Facebook Page or Instagram professional account to Routella's shared business-support inbox. It supplements Routella's general Privacy Policy for this specific Meta business-messaging connection.

1. Scope and Privacy Roles

Routella MCP is the Meta app used to connect business-owned or business-managed Facebook Pages and Instagram professional accounts to a shared, self-hosted Chatwoot inbox operated by Routella, LLC. Authorized staff use that inbox to receive and answer customer-support conversations for the connected business.

For messages and customer profile data handled for a connected business, that business decides why its customer conversations are handled and is the controller or business. Routella, LLC acts as its processor or service provider and follows the business's documented instructions. Routella, LLC separately controls the limited administrator, security, support, and compliance records it needs to operate and protect Routella MCP.

This notice applies only to the Routella MCP Facebook and Instagram business-messaging connection. Meta separately processes information under Meta's own terms and privacy policy.

2. Data the Connection Handles

The exact fields available depend on the connected Meta asset, the permissions approved by Meta, and the information the customer makes available on Facebook or Instagram.

  • Connected business asset data — Facebook Page or Instagram professional-account identifiers; Page or account name and username; available business profile picture; connection, subscription, permission, and webhook status. Source: Meta and the authorized business administrator. Purpose: connect the intended business asset, label the correct inbox, and keep message delivery working.
  • Authorization data — OAuth authorization codes or access tokens, token expiry or permission state, and the identity needed to record which authorized administrator connected the business asset. Routella does not receive the administrator's Facebook or Instagram password. Purpose: maintain the connection, receive approved webhook events, and send replies for the connected business.
  • Customer conversation data — platform-scoped customer identifiers; available display name and profile picture; message text; images, audio, video, documents, stickers, and other attachments that Meta makes available; message and conversation identifiers; timestamps; delivery, read, reply, reaction, and error events; and the staff replies sent through the connected business account. Source: the customer, Meta, and authorized business staff. Purpose: place the conversation in the correct business inbox, help staff recognize the customer, provide human support, and keep the business's support history.
  • Staff and inbox activity — the staff account handling a conversation, assignment and conversation status, internal notes, and the time of staff actions. Source: authorized staff. Purpose: coordinate support work, prevent duplicate replies, and keep an auditable record for the connected business.
  • Operational and security data — webhook and API event identifiers, request times, delivery results, error codes, and limited technical logs needed to secure, troubleshoot, and maintain the connection. Routella does not use this operational data for advertising.

3. How the Data Is Used

  • Connect the business asset selected by an authorized administrator and show its correct identity in the shared inbox.
  • Receive customer messages and attachments from Meta, route them to the correct business inbox, and show the available customer name and profile picture to authorized staff.
  • Notify authorized staff of incoming customer messages by email and mobile push. These alerts can include the customer's available name and message text.
  • Send human-written support replies and supported attachments back through the connected Facebook Page or Instagram professional account.
  • Assign conversations, keep support history, diagnose delivery failures, prevent abuse, secure the service, and provide support to the connected business.
  • Comply with Meta platform rules and legal obligations. Routella does not sell this data, use customer conversations for advertising, or combine one connected business's customer conversations with another business's inbox.

4. Who Receives the Data

Access is limited to the connected business, its authorized staff, Routella personnel who need access to operate or support the service, and the providers needed for the connection.

  • Meta Platforms and its affiliates — Meta supplies the connected business-asset information, customer identity fields, messages, attachments, and messaging events made available through its APIs and webhooks. Meta receives staff replies and related delivery requests for the connected Facebook Page or Instagram professional account. Meta processes information under its own terms and privacy policy.
  • Routella's self-hosted Chatwoot deployment — Routella operates the inbox software to display, organize, assign, and answer the connected business conversations. The separate Chatwoot Hub service used for mobile alerts is described below.
  • Railway — provides the hosting infrastructure used for Routella's self-hosted Chatwoot deployment and therefore processes the business-inbox requests and stored operational data needed to run that deployment.
  • Resend — delivers inbox notification emails to authorized staff. These emails can include the customer's available name and message text. The staff member's email provider also handles the delivered copy.
  • Chatwoot Inc. — operates the Chatwoot Hub relay that passes mobile push alerts from Routella's self-hosted inbox to the delivery service. The alert payload can include the customer's available name and message text.
  • Google Firebase Cloud Messaging (FCM) — delivers those mobile push alerts to authorized staff devices. The alert payload can include the customer's available name and message text.
  • Legal or security recipients — Routella may disclose the minimum necessary information where required by law, to protect people or the service, or to investigate fraud or abuse.

5. Retention and Disconnection

Routella keeps a connected business's message history while that business needs it for customer support, service records, security, or dispute handling, or until the business instructs Routella to delete it or ends the service. Routella does not currently apply one automatic deletion period to every Meta inbox record.

Disconnecting a Facebook Page or Instagram professional account stops future access through that connection, but it does not by itself erase conversation history already stored in the shared inbox. The connected business or an eligible customer must make a separate deletion request for stored history.

Disconnecting the Meta asset or deleting Chatwoot history does not automatically erase notification emails already delivered to staff mailboxes or alerts already delivered to staff devices. Removing those copies may require separate action by the connected business or Routella, depending on who controls the mailbox or device.

When deletion is valid and no legal, security, fraud, or dispute reason requires a record to remain, Routella deletes or de-identifies the eligible data. Limited copies may remain temporarily in protected backups or technical logs until their normal rotation completes. Meta may independently retain information under Meta's own policy.

6. Access, Correction, Export, and Deletion Instructions

A Facebook or Instagram customer should first contact the business whose Page or professional account handled the conversation. The connected business can identify the correct inbox and instruct Routella as its processor. The customer may also email support@routella.app, and Routella will route the request to the responsible business and assist it.

For a Routella request, use the subject “Meta business messaging data request” and include the connected business name, whether the conversation was on Facebook or Instagram, the profile name or username used for the conversation, and an approximate conversation date. Do not send a password, login code, access token, or unnecessary copy of private message content. Routella or the connected business may ask for limited additional information to verify identity and locate the correct record.

An authorized business administrator can also email support@routella.app to disconnect a business asset, delete eligible stored conversations or profiles, or export the business's inbox data. Disconnecting and deletion are separate actions. Routella will complete or assist with the request subject to identity, authority, legal-retention, security, fraud, and dispute requirements.

7. Security and International Processing

Routella limits inbox access to authorized staff, uses encrypted HTTPS connections, and applies application and infrastructure access controls to the Meta connection and stored inbox. No system can be guaranteed perfectly secure.

Routella, LLC is a United States company. Meta, Railway, Resend, Chatwoot Inc., Google, and other infrastructure involved in the connection may process data in the United States and other countries where they operate. The connected business and Routella remain responsible for the transfer safeguards required for the data they control.

8. Changes and Contact

Routella may update this notice when the Routella MCP data flow, providers, or legal requirements change. The current last-updated date appears on this page.

Privacy contact: Routella, LLC · support@routella.app · 131 Continental Dr, Suite 305, Newark, DE 19713, United States · +44 7756 988088.


This Meta Business Messaging Privacy Notice supplements Routella's general Privacy Policy for the Routella MCP business-messaging connection. The English version of this document is authoritative; any translation is provided for convenience only. Related documents: Terms · Privacy · DPA · Acceptable Use · Security. Questions: support@routella.app

Privacy controls: Cookie settings · Do Not Sell or Share My Personal Information