Legal
Privacy Policy
Last updated: 3 August 2026
1. About This Policy
This Privacy Policy explains how Friendswith Limited (NZBN: 9429048141116), trading as Forme Studio (“we”, “us”, “our”), collects, holds, uses, and discloses personal information. We operate the Forme Studio platform available at formestudio.io (the “Platform”).
We are committed to protecting your privacy and handling your personal information in accordance with:
- The New Zealand Privacy Act 2020 and the 13 Information Privacy Principles (IPPs);
- The Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs);
- The Australian Spam Act 2003 (Cth);
- Meta Platform’s developer policies and data handling requirements; and
- Stripe’s connected account and data handling requirements.
By accessing or using the Platform, you agree to the collection and use of your information as described in this policy. If you do not agree, please do not use the Platform.
2. Who We Are
- Legal Entity: Friendswith Limited
- Trading Name: Forme Studio
- Country of Incorporation: New Zealand
- Website: https://formestudio.io
- Contact Email: hello@formestudio.io
- Privacy Enquiries: hello@formestudio.io
3. Information We Collect
3.1 Information You Provide Directly
- Account information: name, email address, password (hashed), and profile details when you register;
- Payment information: billing name, billing address, and payment card details (processed and stored by Stripe — we do not store raw card data);
- Enquiry & contact information: name, phone number, email, business name, and any message content you submit via our enquiry forms;
- Content: photos, videos, captions, hashtags, and other materials you upload or create on the Platform;
- Communications: messages exchanged with our team through the Platform, including package notes and quote discussions.
3.2 Information We Collect Automatically
- Log data: IP address, browser type, pages visited, referring URL, and timestamps;
- Device information: device type, operating system, and unique device identifiers;
- Usage data: features used, content scheduled, actions taken within the Platform;
- Cookies and similar technologies: session cookies required for authentication and security (see Section 10).
3.3 Information from Third Parties
- Meta (Instagram and Facebook): when you connect Meta products to Forme Studio, we receive Platform Data you authorise through Meta’s OAuth / Facebook Login for Business flows. Depending on the connection you choose, this may include Instagram professional account identifiers, usernames, profile pictures, media metadata and insights, Facebook Page identifiers and names, linked Instagram accounts, access tokens, and — where you separately authorise advertising — ad account identifiers, business portfolio asset lists, and advertising performance metrics needed to operate managed campaigns. See Section 5 for full detail.
- Stripe: payment confirmation, transaction identifiers, and subscription status to manage your billing;
- Google reCAPTCHA Enterprise: anti-fraud signals to protect our forms from automated abuse.
4. How We Use Your Information
We use personal information for the following purposes:
4.1 Providing and Improving the Platform
- Creating and managing your account;
- Scheduling and publishing Instagram content on your behalf where you have connected an Instagram account;
- Where the Facebook integration is enabled and you connect and authorise a Facebook Page (and any linked Instagram professional account), displaying those assets in your account settings and using the authorised data to support Instagram publishing, organic Facebook Page feed posting, and related workflows;
- Where advertising features are enabled for your subscription, and subject to Meta granting the required permissions and your explicit authorisation of an ad account and Page, drafting, syncing, reporting on, and — only after your approval — activating or pausing Meta advertising campaigns on your selected ad account;
- Processing package bookings, quotes, and payments;
- Delivering content calendars, templates, and studio resources;
- Responding to your support enquiries and messages;
- Improving Platform features, security, and user experience.
4.2 Communications
- Sending transactional emails (booking confirmations, payment receipts, package updates);
- Sending service notifications and important Platform updates;
- With your consent, sending marketing communications about new features or offers (you may opt out at any time).
4.3 Legal & Safety
- Complying with applicable laws, regulations, and court orders;
- Preventing fraud, abuse, and security incidents;
- Enforcing our Terms of Service;
- Responding to data subject rights requests.
4.4 Legal Basis (Australian users)
We collect and use personal information where it is reasonably necessary for our functions or activities, with your consent, or as otherwise permitted under the Australian Privacy Act 1988.
5. Meta Platform Data (Instagram, Facebook Login, and Advertising)
Forme Studio integrates with Meta products (including Instagram and, where enabled, Facebook Login for Business and the Meta Marketing API) so that you can connect your own business assets and authorise Forme to act on your behalf. This section describes the Platform Data we process from Meta, why we process it, and how you can request its deletion. We only process the Meta permissions and asset access that you grant, and only for the purposes described below.
5.1 Instagram Connection
Where you connect an Instagram Business or Creator account, Forme Studio uses Meta’s APIs to provide scheduling and publishing features. By connecting your Instagram account, you authorise us to:
- Read your Instagram profile, media, and account insights;
- Publish posts, stories, and reels to your Instagram account on your specified schedule (including where Forme Studio team members act on your behalf under your subscription workflow).
5.2 Facebook Login for Business
Where the Facebook integration is enabled on the Platform, you may connect using Facebook Login for Business. When a client connects and authorises a Facebook Page (and any Instagram professional account linked to that Page), Forme will use the authorised data to:
- List and display the Facebook Pages and linked Instagram professional accounts you select so you can choose which assets Forme may manage;
- Resolve Page and Instagram identity needed for Instagram publishing workflows connected through Facebook Login;
- Maintain encrypted access tokens and connection status so Forme can perform the authorised actions until you disconnect or revoke access.
Subject to Meta granting the required permissions, the Facebook Login connection may request access such as listing your Pages, reading Page engagement metadata needed to resolve linked Instagram accounts, and — when advertising is separately authorised — using a selected Page as the identity for advertisements.
5.3 Meta Advertising (Where Enabled)
Where Meta advertising features are enabled for your subscription, and subject to Meta granting the required permissions, you may complete a separate advertising authorisation. When you grant advertising access and select an ad account, Facebook Page, and (where shown) business portfolio assets, Forme will use the authorised data to:
- List ad accounts and business assets you grant so you can confirm the correct advertising identity;
- Allow Forme admins to draft Campaign, Ad Set, Creative, and Ad objects in your selected ad account (typically created in a paused state);
- Sync campaign status and advertising performance metrics for reporting and operations;
- Activate, pause, resume, or permanently stop campaigns only in accordance with your approval workflow and emergency controls on the Platform.
Forme does not ask for your Facebook or Business Manager password. Access is limited to the assets you select in Facebook Login for Business. Advertising spend is billed by Meta to the ad account you authorise; Forme does not take over unrestricted agency control of your Business Manager.
5.4 Platform Data We Receive and Store
Depending on which Meta products you connect and which permissions you grant, we may receive and store only the Platform Data necessary to provide those features, including:
- Instagram user / professional account IDs, usernames, profile pictures, and account connection status;
- Facebook user identifiers associated with the authorisation, Facebook Page IDs and names, and linked Instagram professional account metadata;
- Where advertising is authorised: ad account IDs and names, business portfolio / asset relationship metadata you grant, selected Page identity for ads, campaign/ad object identifiers, and advertising insights or performance metrics needed for reporting and operations;
- Long-lived access tokens and permission/grant metadata (stored encrypted at the application layer);
- Published or scheduled media metadata and insight snapshots used to operate calendars, publishing, and reporting.
5.5 How We Use Meta Platform Data
- Meta Platform Data is used solely to provide the Meta-connected features you enable (Instagram scheduling/publishing, organic Facebook Page feed posting, Facebook Page / Instagram asset connection, and — where authorised — managed Meta advertising and related reporting);
- We do not sell, licence, or share your Meta Platform Data with third parties for their own advertising or any unrelated purpose;
- We do not use Meta Platform Data to build advertising audiences or profiles for unrelated third parties;
- Where you authorise Meta advertising, Forme uses your selected ad account and Page only to operate campaigns you approve for your own business;
- Access tokens are encrypted at the application layer and deleted from our systems upon disconnection, deauthorisation, or a verified deletion request.
5.6 How to Request Deletion of Meta Platform Data
In compliance with Meta’s Platform Terms, you may request deletion of Platform Data we have received from Meta about you. The right to request deletion is available to all users who can access the Platform. You can request deletion by:
- Disconnecting Meta accounts in Forme Studio Account settings (stops new processing and removes local authorisation data according to our retention practices); or
- Deleting your Forme Studio account from Account Settings; or
- Visiting our data deletion instructions page at https://www.formestudio.io/data-deletion; or
- Emailing us at hello@formestudio.io with the subject line “Meta data deletion request” and enough detail for us to locate your account (for example, your Forme account email); or
- Revoking Forme Studio’s access in your Facebook App Settings. When Meta notifies us via deauthorisation or data-deletion callbacks, we delete or scrub the associated Meta-sourced authorisation data and identifiers we hold.
Upon a verified deletion request (or Meta deauthorisation / data-deletion callback), we will permanently delete or de-identify Meta-sourced Platform Data as soon as reasonably possible and within 30 days, except where we are required by law to retain a limited record (for example, a deletion confirmation code or billing records that no longer contain Platform Data). Where Meta provides a confirmation code for a data-deletion callback, you can check status at https://www.formestudio.io/data-deletion.
5.7 Meta’s Privacy Policy
Your use of Instagram, Facebook, and Meta advertising products is also subject to Meta’s Privacy Policy and Meta’s terms for those products. We are not responsible for Meta’s own data practices.
6. Payment Processing (Stripe)
All payment processing is handled by Stripe, Inc. and its affiliates (“Stripe”). When you make a payment on the Platform:
- Your payment card details are submitted directly to Stripe and are never stored on our servers;
- We receive from Stripe: transaction IDs, last-four card digits, card type, billing address, payment status, and subscription details;
- Stripe processes your data in accordance with the Stripe Privacy Policy and is certified to PCI DSS standards.
We use Stripe payment data solely to process transactions, manage subscriptions, issue refunds, and resolve billing disputes.
7. Disclosure of Personal Information
We do not sell your personal information. We may disclose it to:
7.1 Service Providers
- Google Firebase / Firestore — database, authentication, and file storage (data stored in selected regions);
- Stripe — payment processing;
- Meta Platforms — Instagram content publishing and, where you authorise them, Facebook Login for Business connections and Meta Marketing API advertising operations;
- Google reCAPTCHA Enterprise — fraud prevention;
- Vercel — hosting and infrastructure;
- Email delivery providers for transactional communications.
All service providers are contractually required to protect personal information and use it only for the specified purpose.
7.2 Legal Requirements
We may disclose personal information if required to do so by law, court order, or governmental authority, or to protect the rights, property, or safety of Friendswith Limited, its users, or the public.
7.3 Business Transfers
In the event of a merger, acquisition, or sale of all or substantially all of our assets, personal information may be transferred to the acquiring entity, subject to the same privacy protections.
7.4 Cross-Border Transfers
Some of our service providers are located outside New Zealand and Australia (including the United States). Where we transfer personal information overseas, we take reasonable steps to ensure the recipient handles it consistently with applicable privacy laws, including through contractual protections.
8. Your Rights
8.1 New Zealand Users
Under the New Zealand Privacy Act 2020, you have the right to:
- Access the personal information we hold about you;
- Request correction of inaccurate personal information;
- Make a complaint to the Office of the Privacy Commissioner if you believe we have breached the Act.
8.2 Australian Users
Under the Australian Privacy Act 1988, you have the right to:
- Access the personal information we hold about you;
- Request correction of inaccurate, incomplete, or out-of-date personal information;
- Opt out of direct marketing communications;
- Make a complaint to the Office of the Australian Information Commissioner (OAIC) if you believe we have breached the APPs.
8.3 Exercising Your Rights
To exercise any of these rights, please contact us at hello@formestudio.io. We will respond within 20 working days (as required under the NZ Privacy Act 2020). We may ask you to verify your identity before processing your request.
9. Data Retention
We retain personal information for as long as:
- Your account is active and we are providing you services;
- Necessary to fulfil the purposes described in this policy;
- Required by applicable law (e.g. tax and financial records — generally 7 years in New Zealand and Australia).
When you close your account, we will delete or anonymise your personal information within 90 days, except where we are required by law to retain it.
Meta-sourced Platform Data (including Instagram, Facebook Login, and advertising authorisation data described in Section 5) is deleted or de-identified within 30 days of disconnection, account closure, a verified deletion request, or a Meta deauthorisation / data-deletion callback, except where a limited non-Platform record must be retained by law.
10. Cookies and Tracking Technologies
We use the following types of cookies:
- Strictly necessary cookies: required for authentication, session management, and security. These cannot be disabled.
- Google reCAPTCHA: anti-fraud and bot detection cookies set by Google on our forms.
We do not currently use advertising cookies, third-party tracking pixels, or behavioural profiling cookies. If this changes, we will update this policy and seek your consent where required.
11. Security
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. Our security measures include:
- Encryption of data in transit (TLS/HTTPS);
- Encryption of sensitive data at rest (including access tokens);
- Firebase Security Rules restricting data access to authorised users;
- Role-based access controls for administrative functions;
- PCI-compliant payment processing via Stripe.
In the event of a notifiable privacy breach affecting New Zealand users, we will notify the Privacy Commissioner and affected individuals as required under the Privacy Act 2020. For Australian users, we will comply with the Notifiable Data Breaches scheme under the Privacy Act 1988.
12. Children’s Privacy
The Platform is intended for use by businesses and individuals who are at least 18 years of age. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information promptly.
13. Links to Third-Party Sites
The Platform may contain links to third-party websites (including Meta, Stripe, and others). We are not responsible for the privacy practices of those sites. We encourage you to read the privacy policies of any third-party sites you visit.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by posting a prominent notice on the Platform at least 14 days before the changes take effect. The “Last updated” date at the top of this page reflects when the policy was last revised.
Your continued use of the Platform after any changes constitutes your acceptance of the revised policy.
15. Complaints
If you believe we have breached your privacy, please contact us first at hello@formestudio.io so we can attempt to resolve the issue. If you are not satisfied with our response:
- New Zealand: You may complain to the Office of the Privacy Commissioner at privacy.org.nz.
- Australia: You may complain to the Office of the Australian Information Commissioner at oaic.gov.au.
16. Contact Us
For any privacy enquiries, please contact:
Friendswith Limited (trading as Forme Studio)
Email: hello@formestudio.io
Website: https://formestudio.io