◆ Noran Shine CRM
FeaturesUse CasesHow It Works
Get started
Legal

Privacy Policy

Effective date: June 13, 2026 · Last updated: June 13, 2026

This Privacy Policy explains how Noran Shine Photography LLC (“we,” “us,” “our”), a Florida limited liability company, collects, uses, stores, and shares information in connection with Noran Shine CRM (the “Service”), a customer relationship management (CRM) application. It applies to the people and businesses who create an account and use the Service.

1. Who we are

Operated by Noran Shine Photography LLC, 14627 Gallop Run Dr, Lithia, FL 33547, Florida, United States. Contact: support@noranshine.com.

2. Information we collect

  • Account info — name, email, business name, and authentication details.
  • Your contacts/leads — your clients' names, emails, phone numbers, and notes that you add to the Service.
  • Data from connected Instagram/Facebook accounts (Meta permissions) , with your explicit authorization: direct-message content between you and your clients; sender profile information Meta provides; page/account metadata; and access tokens. In the future, with separate authorization, we may schedule posts or read insights — requesting the minimum permissions only.
  • Other connected services — such as Stripe and, in the future, Google Business.
  • Workflow/automation configuration that you create.
  • Technical/usage data generated when you use the Service.

We do not intentionally collect sensitive special-category data.

3. How we use information

To provide and operate the CRM; receive, display, and send Instagram and Facebook direct messages; capture leads; run your workflows; secure the Service; and comply with law. We process Meta-permission data solely to provide the messaging/CRM features you enabled — never for advertising, and we do not sell or rent it.

4. Storage & security

Your data is stored in a PostgreSQL database hosted on Railway, in the United States, with per-tenant (per-organization) isolation. Access tokens are stored securely; data is encrypted in transit over HTTPS; and incoming Meta webhooks are signature-verified.

5. Retention & deletion

Disconnecting a Meta account immediately removes the connection and stored access tokens. Messages already received into your CRM are your business records and are retained unless you delete them in the app or request full account deletion. We honor message-unsend/deletion events from Meta (we remove our stored copy). Removing the app from Facebook/Instagram triggers an automated data-deletion callback. For full deletion, email support@noranshine.com; we complete it within 30 days, except for records required by law. See our Data Deletion page for full instructions.

6. Sharing

We do not sell or rent data. We share only: with subprocessors under contract (Resend for email, Twilio for SMS, Railway, and Stripe); with Meta as needed to deliver messaging; as required by law; and in connection with a business transfer. Our use and transfer of Meta API data adheres to the Meta Platform Terms and Developer Policies.

7. Your rights

  • GDPR (EEA/UK): access, correct, delete, restrict, object, portability, and withdraw consent — email support@noranshine.com.
  • CCPA/CPRA (California): know, delete, correct, and opt out — we do not sell or share personal information, and we do not discriminate for exercising these rights.
  • Your clients' data: you are the controller; we refer their requests to you and assist as a processor.

8. Children

The Service is not intended for children under 16.

9. International

Data is stored and processed in the United States.

10. Changes

We may update this policy; we will revise the “Last updated” date above when we do.

11. Contact

Noran Shine Photography LLC, 14627 Gallop Run Dr, Lithia, FL 33547, support@noranshine.com.

◆ Noran Shine CRM

Turn every Instagram and Facebook message into a booked client — in one CRM.

Legal Privacy PolicyTerms of ServiceData Deletion

© 2026 Noran Shine. All rights reserved.

support@noranshine.com