Privacy Policy
How Spotlight handles your information.
Last updated: 14 September 2026
About this policy
This policy covers Spotlight at bspotlight.in, including profile nominations, ownership claims, paid boosts and collaboration enquiries. Spotlight is an independent service and is not operated by Instagram or Meta.
Information we process
- Account information: an account identifier, sign-in information and, when you connect Google, the name and email supplied by that provider. Guest sessions use a browser-based account identifier.
- Profiles: Instagram handles, display names, profile categories and locations, and information submitted by verified owners, such as biographies, images, contact details and links. A public profile may be nominated by someone other than its owner.
- Ownership verification: claim status, expiring verification-code hashes, submitted evidence and review history. When Instagram DM verification is enabled, we process verification messages sent to our official account, message identifiers, Instagram-scoped sender identifiers and profile information returned through Meta’s authorized API to check the sender against the claimed profile.
- Payments: boost amounts, order and payment references, payment status and refund records. Razorpay processes payment credentials; Spotlight does not require your card number, CVV or UPI PIN in its own forms.
- Activity and support: profile interactions, traffic signals, collaboration enquiries, reports and technical logs, including IP-related security information used to prevent abuse.
Why we use it
We use this information to operate the boards, attribute verified boosts, maintain rankings, verify profile ownership, deliver enquiries, respond to support requests, prevent fraud and investigate disputes. Connecting Instagram does not authorize Spotlight to publish posts or send unrelated messages on your behalf.
Public and private information
Profile details, rankings and information intentionally published on a profile are visible to visitors. Ownership evidence, private sender identifiers and payment references are not intended for public display. Collaboration enquiries are shared with the authorized profile owner and administrators who need to handle them. Avoid submitting sensitive personal information in public profile fields.
Service providers
Spotlight uses Netlify for hosting, Google Firebase for authentication, database and backend services, Razorpay for payments, and Meta for enabled Instagram features. Their services may process information on infrastructure outside your country. External images or links may also connect your browser to their providers. We disclose relevant information to these providers to operate the requested features, and may disclose information when required by law or necessary to investigate abuse.
Browser storage
Browser storage keeps your sign-in session and interface preferences. Clearing it may remove access to an unlinked guest account. It does not delete the corresponding data held by Spotlight.
Retention and security
We retain information while needed for the service, ownership checks, dispute resolution and legitimate record-keeping. Verification codes expire, but expiry does not itself erase the associated claim or audit records. Payment, fraud-prevention and legally required records may remain after an account-deletion request. Access controls and server-side checks restrict private data; no online service can guarantee absolute security.
Your choices and requests
You can request access, correction or deletion by contacting @bspotlight.in on Instagram. Include your profile link and the information you want us to review. We may ask for proportionate proof that the request concerns your account. Never send passwords, OTPs, payment PINs or access tokens. See our data-deletion instructions for details.
Changes and contact
Changes to this policy will be posted on this page with an updated date. For privacy questions, contact @bspotlight.in on Instagram.