Privacy Policy — Social Embed to WP
Last updated: August 26, 2026 Applies to: Social Embed to WP, version 1.5.1 and later Provided by: Ascend Digital (ascenddigital.ca)
This policy explains what data Social Embed to WP (“the Plugin”) collects, why, and how it’s handled — both on your own WordPress site and on Ascend Digital’s license/sync servers. It’s written for site administrators installing the Plugin, and is also intended to be shared with your own site’s visitors if your privacy policy needs to disclose it.
1. Who Processes What
Two parties are involved:
- You (the site administrator) — you control your WordPress site’s database, your Facebook Page, and what galleries you create.
- Ascend Digital — operates the license validation server and the Facebook-sync relay the Plugin depends on (see Section 3).
Social Embed to WP does not collect any data about the people who visit your website and view a gallery. Displaying synced photos is a plain, static page element — no cookies, tracking, or analytics are added by the Plugin.
2. Data Stored on Your Own WordPress Site
The Plugin stores the following in your site’s own database — this data never leaves your server except where explicitly sent to Ascend Digital’s servers as described in Section 3:
| Data | Purpose |
|---|---|
| Facebook Page ID and Page Access Token (per gallery) | Needed to fetch that Page’s posts |
| Your license key and its activation status | Unlocks sync features for this site |
| Synced photos, captions, and post metadata | Downloaded into your Media Library to build the gallery |
| Gallery configuration (style, layout options, sync interval, etc.) | Your own settings |
You can delete any of this at any time by deleting a gallery, deactivating your license, or removing the Plugin.
3. Ascend Digital’s Servers
The Plugin communicates with servers Ascend Digital operates (hosted on AWS) for two purposes: license validation and fetching your Facebook Page’s content on your behalf. Specifically:
License validation
When you activate, check, or deactivate a license, the Plugin sends your license key and your site’s URL to confirm the license is valid and assigned to your site. This is the minimum information needed to enforce one active site per license.
Facebook sync
Rather than your site talking to Facebook’s API directly, sync requests go through Ascend Digital’s server, which validates your license and then calls Facebook’s Graph API on your behalf. On each sync, your site sends:
- Your license key and site URL (to verify the request is authorized)
- The Facebook Page ID and Page Access Token configured for that gallery
- The results (post captions, photo URLs, post IDs) are returned to your site and nothing further is retained
Your Facebook Page Access Token is used only for that single request and is never stored on Ascend Digital’s servers.
“Connect with Facebook”
If you use the one-click “Connect with Facebook” option instead of entering a token manually, the OAuth flow works like this:
- You log into Facebook directly (Ascend Digital never sees your Facebook password)
- Facebook redirects back through Ascend Digital’s server with an authorization code
- That server exchanges the code for a Page Access Token and holds it in temporary storage for up to 10 minutes, tied to a single-use claim token
- Your WordPress site retrieves it once and stores it locally — the temporary copy is deleted immediately after being claimed, and automatically expires and is purged even if never claimed
Purchase and billing
If you purchased a license, payment was processed by Stripe — Ascend Digital never receives or stores your payment card details. Stripe shares your name, email, and subscription status with Ascend Digital’s license server so a license key can be issued and billing/support can be provided. See Stripe’s Privacy Policy.
Software updates
To check for and deliver Plugin updates, your site periodically sends your license key and site URL to confirm you’re entitled to the current version, and downloads the update package if a newer one exists.
4. Third-Party Services
The Plugin and its backend rely on these third parties. Each has its own privacy policy governing data they process:
- Meta/Facebook — provides the Graph API and Facebook Login used to fetch your Page’s content. See Meta’s Privacy Policy.
- Stripe — processes payment for license purchases. See Stripe’s Privacy Policy.
- Amazon Web Services (AWS) — hosts Ascend Digital’s license and sync servers (Lambda, DynamoDB, S3) in the United States. See AWS’s Privacy Notice.
5. Data Retention
- Facebook Page Access Tokens are never stored on Ascend Digital’s servers — used transiently per-request only (or held up to 10 minutes during the OAuth handoff described above).
- License and activation records (license key, associated email, site URL, activation status) are retained for the life of the license, plus a reasonable period after cancellation for billing/support records.
- Synced photos and post data live entirely in your own WordPress site’s database and Media Library, retained until you delete them.
6. Data Sharing
Ascend Digital does not sell or share license, billing, or Facebook token data with any third party except the service providers named in Section 4, each acting to provide the specific function described (payment processing, Facebook API access, cloud hosting).
7. Security
Facebook Access Tokens and Facebook data sent to Ascend Digital’s servers travel over HTTPS. Presigned download links for plugin updates are time-limited (5 minutes) and tied to your specific license and site. License keys act as a bearer secret for your account with Ascend Digital — keep yours confidential the same way you would a password.
8. Your Rights and Choices
- Deactivate your license at any time from the Plugin’s License page — this removes your site’s activation record from Ascend Digital’s system.
- Disconnect Facebook by removing the Page ID/token from a gallery’s settings, or deleting the gallery entirely.
- Delete synced photos individually or in bulk from your own Media Library at any time — Ascend Digital has no copy of them.
- Request deletion of your license/billing records by contacting Ascend Digital (see Section 10).
If you are in the EU/UK, California, or another jurisdiction with data protection rights (access, correction, deletion, portability), you can exercise these by contacting Ascend Digital directly.
9. Children’s Privacy
Social Embed to WP is a website administration tool not directed at children, and is not knowingly used to collect data from children under 13 (or the relevant age in your jurisdiction).
10. Changes to This Policy
This policy may be updated as the Plugin’s features change. The “Last updated” date at the top reflects the most recent revision. Material changes affecting how your data is handled will be noted in the Plugin’s changelog.
11. Contact
Questions about this policy or your data can be directed to:
Ascend Digital ascenddigital.ca
This policy describes the Plugin’s and Ascend Digital’s own data handling. If you display Facebook-sourced content publicly on your website, you remain responsible for your own site’s privacy policy and for complying with applicable law (including GDPR, CCPA, or PIPEDA) as it applies to your use of the Plugin and your relationship with your site’s visitors.