Smash Balloon plugins can send us a small weekly report about how the plugin is set up and running on your site. We use it to find bugs sooner, decide which features to build or improve, and understand which WordPress and PHP versions we need to support.
This page explains what the report contains, what it never contains, and how to turn it off.
Is usage tracking on by default?
It depends on which version of the plugin you use:
- Free plugins (from WordPress.org): usage tracking is off by default. Nothing is sent unless you turn it on.
- Pro plugins: usage tracking is on by default. You can turn it off at any time, and it stays off.
You’ll find the setting in your plugin’s settings, on the Advanced tab, under Usage Tracking. For example: Instagram Feed → Settings → Advanced → Usage Tracking.
What gets collected
Site environment
- Your site’s address (URL), used to tell one site’s reports from another’s
- WordPress version, PHP version, web server software, and site language (locale)
- Whether the site is a multisite network, and how many sites it has
- Your site’s timezone offset and the total number of user accounts (a count only, never names or emails)
- How many days ago the plugin was first installed
Theme and plugins
- The name and version of your active theme
- The names, versions, and authors of your active plugins
We never collect the settings, license keys, or content of other plugins or themes.
Smash Balloon plugin setup
- Plugin version, whether you use the Free or Pro version, and your license tier, status, and expiry date
- The number of feeds you have, and which feed types, layouts, and templates they use
- Which features are switched on (lightbox, load more, carousel, or header, for example)
- Display settings from your 10 most recently created feeds, plus the names you gave those feeds
- The number and type of connected social accounts (for example, “2 business accounts”). Account names and access tokens are never included.
- Global settings like caching interval, image optimization, and GDPR mode
Weekly activity
- How many API errors happened that week, grouped by type (sign-in, rate limit, network, and so on)
- The 10 most recent error messages. We remove access tokens, API keys, and other credentials before sending, and cut each message down to 300 characters.
- How many days that week someone used the plugin’s admin screens, and how long those sessions lasted
- How often certain admin actions happened (a settings change, for example), as counts only
- Cache counts that help us spot performance problems
What is never collected
- Names, email addresses, or any other personal information about your site’s visitors
- The content of your feeds: posts, photos, videos, captions, comments, or reviews
- Access tokens, passwords, API keys, or license keys
- The names or details of the social media accounts you connect
- Any information about your site’s users beyond a total count
How the data is sent and stored
The report goes out once a week, at a random time picked for your site, over an encrypted HTTPS connection to servers Smash Balloon controls. We use the data only to support and improve our products. Any usage data we share outside Smash Balloon is de-identified and combined with data from other sites first.
We keep usage data only as long as we need it for these purposes. For details on retention, international transfers, and your rights, see our Privacy Policy.
Connecting your social accounts
Usage tracking is separate from connecting your social accounts. When you connect Instagram, Facebook, TikTok, X (Twitter), YouTube, or a review platform, the plugin uses Smash Balloon services to authorize the account and, for some platforms, fetch your feed data:
- connect.smashballoon.com: authorizes third-party accounts so they can feed data to your site, and upgrades your plugin after you buy a Pro product
- tiktok.smashballoon.com: requests data from TikTok’s API for TikTok Feeds
- reviews.smashballoon.com: requests data from review providers’ APIs for Reviews Feed
- ctf.smashballoon.com: requests data from X (Twitter)’s API for Custom Twitter Feeds
Our Instagram Feed and Custom Facebook Feed plugins are self-hosted. Your account names and related data are stored only on your website and go directly between your site and Meta’s APIs. Our team can’t see this information, and it doesn’t pass through any servers we control. You can delete all of this Platform Data instantly with the Delete All Platform Data button in the plugin settings.
For the full list of Meta permissions we request and why we need each one, see our Privacy Policy and App Privacy Policy.
Turning it off and requesting deletion
You can switch off usage tracking at any time under Settings → Advanced → Usage Tracking in your plugin. The next weekly report is cancelled, and no more are sent.
To request access to, or deletion of, the data we already hold for your site, contact us. Include your site’s URL so we can find its reports.
Related: Privacy Policy · App Privacy Policy · GDPR Compliance · Terms & Conditions