top of page

Meta Platform Permissions

Last Updated: 22 July 2026
 

Purpose of this page
This page explains how Toretto META API uses Meta Platform permissions. It is intended to provide transparency
for customers and reviewers. Replace or remove any permission below that your application does not actually request.


Our Approach
We request only the minimum Meta permissions required to provide authorised functionality. We do not
request permissions that are unnecessary for the services offered, and we do not sell or misuse Meta Platform Data.
 

instagram_basic
Used to identify the connected Instagram Professional account and obtain basic account information needed to configure and operate the service.


instagram_manage_messages
Used, where enabled, to receive and respond to Direct Messages sent to an authorized Instagram Professional account. Message processing may include customer-defined workflow automation and AI-assisted draft responses.
 

instagram_manage_comments
Used to read, moderate and respond to comments on posts belonging to an authorized Instagram
Professional account.

 

pages_show_list
Allows an authorized user to select the Facebook Page they manage when linking Instagram Professional
accounts to the application.


pages_read_engagement
Used to read engagement information necessary to support authorized messaging, comments and business
workflows.


pages_manage_metadata
Required to subscribe authorized Pages to Meta Webhooks so the application can receive approved events,
such as new comments or messages.


business_management (only if requested)
If your application requests this permission, explain exactly why it is required. Remove this section if the
permission is not part of your App Review submission.


How Meta Platform Data is used
Meta Platform Data is processed only to provide the services requested by authorised customers. Depending
on customer configuration, this may include receiving webhook events, routing conversations, generating
AI-assisted draft responses, maintaining workflow history, and supporting customer service operations.
 

How we protect Meta Platform Data

We apply reasonable technical and organisational safeguards including access controls, encrypted
communications where appropriate, credential protection, monitoring, logging and least-privilege access.
Access tokens are treated as confidential.
 

Data retention
We retain Meta Platform Data only for as long as reasonably necessary to operate the service, meet legal
obligations, resolve disputes, maintain security and satisfy customer requirements. Customers may
disconnect their accounts or request deletion of eligible data.
 

Data deletion
Users may request deletion of eligible information by following the instructions published on our Data Deletion
page or by contacting our privacy team.
 

Third-party providers
The application may use trusted service providers such as Meta, OpenAI, n8n, ManyChat, Wix and secure
cloud infrastructure where necessary to provide the service. Each provider processes data in accordance
with its own contractual obligations and privacy practices.
 

Our commitment
We are committed to transparency, responsible AI, privacy by design and compliance with Meta Platform
Terms and applicable privacy laws.
 

Contact
Business: Toretto Coffee
Trading Name: Toretto Coffee
Website: https://www.torettocoffee.com
Support: support@torettocoffee.com
Privacy: privacy@torettocoffee.com

bottom of page