Privacy Policy: Relay Order Desk
How the Relay Order Desk testing software handles personal data: the Instagram events it receives, the records it stores, how long it keeps them, and how to request deletion.
Page details
- Operator
- Lyra Data Systems
- Product
- Relay Order Desk
- Privacy contact
- [email protected]
- Effective date
- 6 October 2026
1. Current status and intended scope
Relay Order Desk is in controlled technical testing. The intended scope is Instagram professional accounts controlled by Lyra Data Systems and test senders Lyra has authorized. It is not offered to merchants or the public.
Because the webhook is connected to a live Instagram account, messages from people outside that test group may arrive unexpectedly. When this happens, we store the event under the same retention limits as every other captured event (section 6). We do not reply to it.
This policy describes what the current testing software does. It does not describe planned production features.
2. Information we receive from Instagram
What Meta sends
Meta’s webhook delivers events for connected Instagram accounts. Its documented message events include the Instagram-scoped IDs of the sender and of the receiving account, a timestamp, the message ID, and the message text and attachments where present. A reply includes a reference to the message it replies to. Read receipts arrive as a separate event that names the message that was read. Meta signs each webhook payload with an X-Hub-Signature-256 header.
Meta: Instagram webhook examples
What our software does
The software checks each delivery’s signature against the app secret before storing anything. Deliveries that fail the check are rejected and not stored.
Personal identifiers. We treat Instagram-scoped IDs, and the usernames given in deletion requests, as personal identifiers. Even where a stored record does not have a sender ID in a searchable field, the record can still contain a Lyra account ID, message text, or a raw payload. We do not treat any stored record as anonymous.
3. What is stored, and why
| Data | Purpose | Where it is stored (testing stage) |
|---|---|---|
| Received message events: sender ID, receiving account ID, message ID, timestamp, text, attachment types, subtype, reply reference, dedupe key, and 24-hour window flag | Testing whether inbound messages are received and recorded correctly | A local database file on Lyra’s test machine |
| Other received events: event type and field names | Testing webhook coverage | Same file |
| Verification direct message sent by the requester (the one-time code) | Verifying ownership of the account for a deletion request | Lyra’s Instagram inbox copy: the operator removes it within 30 days after the request is completed, whether or not the message reached the webhook. Any copy in the local database (the same file as received message events) is deleted by the earlier applicable deadline (see section 6). We cannot guarantee removal of the requester’s copy or data Meta retains independently. |
| Deletion-request data: requester email address, Instagram username, verification code, and request correspondence | Confirming the request and matching the verification message to the requester’s account | Lyra’s mailbox and Lyra’s Instagram inbox. Kept separately from the capture database. Deleted within 30 days after the request is completed. |
| Outbound send attempts: receiving account ID, recipient ID, SHA-256 hash of the text (not the text), state, provider message ID, HTTP status, error code and message | Testing the send path and its refusal rules | Same file |
| Access token for the Lyra test account | Calling Meta’s API for that account | Local environment or token file with restricted permissions. Never stored in the database. |
| Server request log: UTC time, method, path, status, duration | Operating and debugging the test server | Local log file saved by the operator. Each request entry holds only these fields: no query strings, headers, bodies, or account IDs. |
Raw webhook payloads are not stored by default. The software keeps them only when the operator turns on raw capture for a short diagnostic session. They are deleted immediately after that session ends. This rule is separate from the 30-day limit in section 6, which never extends it.
4. Purposes
Data is used only to test whether the Instagram messaging integration receives, verifies, records, and sends messages correctly. It is not used for advertising, profiling, analytics, model training, or automated decisions about people.
5. AI tools
Customer conversations
The running proof software does not call an AI service to process or reply to Instagram messages.
Development and debugging
An AI coding assistant helped write and debug this software. During debugging, the assistant received counts, event types, timestamps, the shape of payload fields, and yes/no results for checks on known test phrases. It did not receive message text.
6. Storage, access, and retention
The proof server keeps its capture database and request logs in local files on Lyra’s test machine. No production database or cloud storage is used for them. Deletion-request correspondence is also held in Lyra’s mailbox and Lyra’s Instagram inbox. Access is limited to the Lyra operator. The send endpoint requires a bearer token and sends only to an allowlisted test recipient. No public viewer or export exists.
The software does not delete data on its own. The operator deletes data by hand, within the limits below.
Retention
- Captured events and other identifiable test records are deleted within 30 days of collection, or when controlled testing ends, whichever comes first. This includes unexpected messages from people outside the test group, other webhook events, and outbound send attempts.
- The server request log is kept for no more than 30 days. The operator deletes older log files by hand.
- Raw debugging payloads are deleted immediately after each diagnostic session ends. The 30-day limit never extends this period.
- Only synthetic test fixtures and sanitized summaries without message text or account identifiers are kept beyond these limits.
- A verification message captured in the capture database is deleted by the earlier of the two deadlines that apply to it: the capture-retention limit (30 days from collection, or when controlled testing ends) or the deletion-request deadline (30 days after the request is completed).
- Deletion-request materials are deleted within 30 days after we complete the request. They are the request emails and correspondence, verification codes, usernames given in requests, internal request notes, any verification direct message captured as a received event, and Lyra’s copy of that message in its Instagram inbox.
Backups
If a backup of the test machine exists, records deleted from the live store may remain in that backup until the backup expires or is overwritten.
7. Third parties
Meta (Instagram platform)
Delivers webhook events to Lyra and receives the send requests the software makes. This page describes only what the software does with that data. It does not describe Meta’s own processing.
Cloudflare
While the temporary HTTPS tunnel is running, webhook traffic reaches the test server through Cloudflare’s network.
No analytics, advertising, or email providers are connected to the testing software.
8. Your choices and deletion
To ask us to delete records linked to your Instagram account, use the Relay data deletion request page. Requests go to [email protected].
9. Changes
We will update this page before any change in scope, including before any move beyond controlled testing.