Legal

Privacy policy

What we collect, why we are allowed to hold it, who else sees it, and how to get it deleted. Written against our own code rather than copied from a template, so it describes the system that actually exists.

  • No account to create
  • No password ever requested
  • Card details never touch this site
  • One address for every data request

Last updated 8 August 2026.

Who is responsible for your data

InstaBoostNow operates instaboostnow.com and decides how the data described on this page is used. Under UK GDPR (the UK's data protection law, which sits alongside the Data Protection Act 2018) that makes us the data controller.

The way to reach us about anything on this page is [email protected]. We have not appointed a data protection officer, because a business of this size and kind is not required to have one, and we are not going to name a person or a registration that does not exist.

What we actually collect

When you place an order

  • The Instagram username, or the link to the post, reel or story the order is for. This is the only part of an order that identifies anyone at all.
  • The service and the quantity you chose.
  • An order reference generated in your browser. It is what joins your payment, your order and any later support request together.
  • The email address PayPal passes back after a payment. We do not ask for it on our form. PayPal sends it with the payment so we can email you a receipt.
  • The payment reference PayPal gives the completed payment. Not your card details - see below.
  • Housekeeping fields: the status of the order, the supplier's own order number once it has one, whether a confirmation email has been sent, and the date and time the record was created.

If you start checkout and do not finish

When you open checkout we save the link, the service and the quantity before the payment screen appears. That happens whether or not you go on to pay, so if you close the tab we still hold that record. No email address is attached to it, because we never asked you for one.

We keep those rows for two honest reasons. A payment can occasionally arrive without its order details attached, and that row is the only thing we could match it to. And a pattern of abandoned checkouts is how we find out that something on the page has broken. They are deleted within 12 months.

What we never collect

  • Your Instagram password. We never ask for your Instagram password, and no page on this site has a field for one.
  • Your card, bank or PayPal login details. Payment happens entirely on PayPal's own screens. Those details never touch this site, are never sent to our server and are never stored by us.
  • Your name, phone number or postal address. Our order form does not ask, because PayPal collects what it needs on its own screens.
  • Anything from inside your Instagram account. We only ever have the public username or post link you type in yourself.

Analytics and server records

We use Google Analytics 4, Google's website measurement tool, to count visits and see which pages and which steps people use. It is measurement only: it is never used to build an advertising audience and never used to follow you around other websites.

The events the site is set up to send are page_view, select_service, begin_checkout and purchase. Between them they record which page you looked at, which service you picked, and whether you started and finished checkout. None of them carries your username, your link or your email address.

Cloudflare serves this site and runs the code that handles orders. Like any web server it records the internet address (IP address, the number that identifies a connection) a request came from, along with the browser and the time, and uses that to deliver the page and to block automated abuse.

Why we are allowed to hold it

UK GDPR requires a lawful basis for every use of personal data. Ours are:

  • Performing a contract. The link, the service, the quantity, the order reference and the email address are what an order is made of. Without them we cannot deliver what you paid for or send you a receipt.
  • Legitimate interests. Abandoned checkout records, server records and analytics sit here: keeping the site working, matching a payment that arrives without its details, spotting fraud, and finding out where checkout is failing. We have weighed that against your privacy, which is why an abandoned row holds a link and a quantity and nothing more.
  • Legal obligation. A record of a completed sale has to be kept for tax.

Who else sees it

A small number of companies help us run the service. Each one gets only what it needs.

  • PayPal takes the payment. It receives the amount, the currency, a neutral description of what you bought and the order reference, and it sends back your email address and the payment reference. Your card details go to PayPal and stay with PayPal, which handles them as a data controller in its own right.
  • The supply panel places the order. It receives exactly three things: the service, the link or username, and the quantity. It does not receive your email address, your payment details or your order reference.
  • Resend sends the two emails this site can send: your order confirmation, and an internal alert to us when a paid order has not been delivered. It receives your email address and the contents of that message.
  • Google Analytics receives the analytics events described above.
  • Cloudflare serves the site and runs the order code, so every request passes through it.
  • The order database is a managed Postgres database (Postgres is a widely used database system) hosted in London. Reaching the order records at all requires a key that exists only as an encrypted secret on the server and is never present in your browser.

We do not sell your data, we do not share it for advertising, and we do not pass it to anybody outside that list.

Data leaving the UK

PayPal, Google, Resend and Cloudflare are international companies, and some of them process data outside the UK. Where that happens, the transfer relies on the safeguards UK data protection law allows for it, such as an adequacy decision covering the country involved or standard contractual clauses in the provider's own terms. The order database itself is hosted in the UK.

How long we keep it

  • A paid order: up to six years. A business has to keep its sales records for several years for tax, and a payment dispute can be raised long after delivery.
  • An abandoned checkout record: no longer than 12 months.
  • Emails you send us: as long as the conversation is useful, and no longer than six years where it relates to a paid order.
  • Analytics: for the retention period set inside Google Analytics, which is measured in months rather than years.

If you ask us to delete your data sooner we will, unless we are required to keep the record of a sale. In that case we keep the minimum that record needs and delete the rest.

Your rights

UK GDPR gives you the following rights over your own data, and every one of them is free to use.

  • Access - ask for a copy of what we hold about you.
  • Rectification - have something wrong corrected.
  • Erasure - have it deleted, where we are not required to keep it.
  • Restriction - have us keep it but stop using it while something is sorted out.
  • Portability - receive the data you gave us in a machine-readable form.
  • Objection - object to us relying on legitimate interests, including for analytics.
  • Withdrawing consent - wherever we rely on your consent, you can take it back at any time.
  • Automated decisions - we do not make automated decisions about you that have legal or similarly significant effects. The link check that runs before payment is a format check, not a decision about you.

To use any of them, email [email protected] from the address PayPal holds for your order, or quote the order reference on your receipt. Those are the only two ways we can tell that an order is yours, and we would rather ask than hand your details to somebody else. We answer within one month, which is the limit UK GDPR sets, and we aim to do it within a few working days.

If you are unhappy with how we have handled it, you can complain to the Information Commissioner's Office, the UK's data protection regulator.

Cookies

Our own code does not set a single cookie. There is no login on this site, no basket and no preference to remember, so there is nothing for us to store on your device.

Two other things can set one:

  • Google Analytics sets its own cookies, to tell one visit from another and to recognise a returning visitor.
  • Cloudflare may set a short-lived cookie to tell a real visitor from an automated one.

Your browser can block both. Blocking them will not break anything here, including checkout, because none of the ordering code reads a cookie.

Security

Everything is served over HTTPS. The order table has row level security switched on with no public policies, which in plain terms means the key a browser could ever see has no access to those records at all; the key that does have access exists only as an encrypted secret on the server. We hold no card details, so there is nothing of that kind here to steal.

Changes to this policy

We update this page when what we do changes, not on a schedule. The date at the top is the real one.

See also our terms and conditions and our refund policy, or go back to the homepage.

The short version

A username or a link, a service, a quantity, and the email address PayPal gives us. We never ask for your Instagram password, we never see your card details, and you can have any of it deleted by email.