Legal
Privacy Policy — Hedi2
Last updated: 18 July 2026
This policy explains how Hedi2 (hedi2.com) and its companion browser extension, Hedi2 Connect, access data, how that information is used, and what we do not do with it. It covers both the Hedi2 Connect extension and any third-party accounts — such as Pinterest, Facebook, or Instagram — that you choose to connect to Hedi2.
Who this applies to
Hedi2 Connect is a companion tool for Hedi2 team members and authorized Hedi2 workspaces. It only functions after you sign in to your Hedi2 account; without an active Hedi2 session it does nothing.
What the extension accesses
- Your Hedi2 session (authentication token). When you use the extension, it reads the login token from your open Hedi2 tab so it can make requests to Hedi2 on your behalf. This is the same session you are already logged in with — the extension does not create a separate login.
- Content of the page you choose to capture. When you click a capture action (for example, "Capture Sample" on a product page), the extension reads that page's content — such as the title, description, images, and, where applicable, a file you are entitled to download — in order to send it to your Hedi2 workspace. It only reads a page when you actively trigger an action on it.
- Local settings. The extension stores, in your browser's local storage, the address of the Hedi2 server it should talk to and, optionally, a manually entered token. This never leaves your browser except to authenticate with Hedi2.
How the information is used
Captured content and your session token are used for one purpose only: to carry out the action you requested inside your own Hedi2 workspace — creating a sample, importing a design, saving an article, and so on. Access to each feature is further controlled by your Hedi2 account permissions.
What we do not do
- We do not sell or rent your data to anyone.
- We do not use your data for advertising, tracking, or any purpose unrelated to the extension's core function.
- We do not transfer your data to third parties. Captured content is sent only to your own Hedi2 account, which you control.
- We do not use your data to determine creditworthiness or for lending purposes.
Data storage and retention
Content you capture is stored in your Hedi2 workspace, under your Hedi2 account, and is governed by your organization's Hedi2 data. Local settings remain in your browser until you remove the extension or clear its storage. The extension keeps no separate database of its own.
Permissions
The extension requests browser permissions strictly to perform the functions above: reading the active page when you trigger a capture, detecting your logged-in Hedi2 tab to reuse your session, saving files you choose to import, and showing job-status notifications. The sites it can access are limited to the platforms you capture from and the Hedi2 servers.
Connecting social media accounts (Pinterest, Facebook & Instagram)
Hedi2 lets you connect your own social media business accounts so you can publish and schedule posts of your product listings directly from Hedi2. Connecting an account is entirely optional and always initiated by you.
- What we access. When you connect an account, you are sent through that platform's official OAuth login. After you authorize it, the platform gives Hedi2 an access token limited to the permissions you granted — for Pinterest, reading your boards and creating and reading Pins on your behalf; for Facebook and Instagram, reading the Pages and business accounts you manage and publishing to them. We also read the account's public identity (such as username or profile name) so we can show you which account is connected.
- How we use it. The access token is used only to perform the actions you start in Hedi2 — creating or scheduling a Pin or post to a board or page you own, and reading basic engagement metrics (for example saves, likes, or comments) for content you published through Hedi2. We publish only to accounts you connected, and only content you created in Hedi2.
- How tokens are stored. Access tokens are stored encrypted at rest, are never shown in the interface or logs, and are never shared with anyone. They are used only on our servers to talk to the platform on your behalf.
- No resale or unrelated use. We do not sell, rent, or share your social media data with third parties, and we do not use it for advertising or for any purpose beyond the publishing features you choose to use. We do not keep a separate copy of your platform data beyond the identifiers and metrics these features require.
- Disconnecting and deletion. You can disconnect a social account at any time in Hedi2 (Planner → Social Media → Disconnect), which removes the stored access token from Hedi2. You can also revoke Hedi2's access directly from your Pinterest, Facebook, or Instagram account settings. To request deletion of related data held by Hedi2, contact info@hedi2.com.
Contact
Questions about this policy, or data deletion requests: info@hedi2.com