Table of Contents
Privacy Policy
Effective Date: July 21, 2025
We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our social media management platform ("the Service"). By using the Service, you agree to the terms below.
Definitions
Personal Data: Any information about an individual from which the individual can be identified (for example, name, email, social media username, profile picture).
Usage Data: Information collected automatically when you use our Service, including device and browser information, pages visited, and timestamps.
Cookies: Small data files stored on your device by websites or apps, used to recognize your preferences and track activity. Cookies that identify you can be treated as personal data under the GDPR.
Data Controller: We (the company operating this Service) determine the purposes and means of processing your data.
Data Subject / User: You, the person using the Service and the subject of any Personal Data.
Information We Collect
We collect several types of information to provide and improve the Service:
Personal Data: When you register or connect social media accounts, we may collect your name, email address, and any other information you choose to provide (e.g. profile data). We may also collect information from the social media accounts you link (such as your social media username, profile picture, and content you post) in order to manage your social media presence and provide analytics or machine learning features (e.g., optimizing captions).
Google Account Data: When you sign in with Google, we collect the Google account information you authorize, including your name, email address, and profile picture. We use this Google profile information strictly to authenticate you and to provide the Service features you request (e.g. account creation, profile setup). We do not use your Google account data for any other purpose.
Social Media Content and Data: Content (posts, comments, images, etc.) and associated metadata from connected social media accounts may be processed to deliver the Service (e.g. scheduling posts, providing analytics) and to train machine learning models for features like caption suggestions. We do not sell or share this content except as necessary to provide the Service.
Usage and Analytics Data: We automatically collect Usage Data such as pages you visit in the Service, the time and date of your visit, and your actions (e.g. clicks, features used). This includes technical data like your device type, operating system, browser type, and unique device identifiers. We use Google Analytics and Vercel's analytics tools to gather aggregate usage statistics. Google Analytics 4, for example, does not log your IP address and only derives coarse geo-location (city, region, country) before discarding the IP. Vercel Web Analytics uses only anonymized data and does not use cookies. Vercel Speed Insights similarly collects only anonymous performance metrics (e.g. page load times, connection speed) and country-level information, without identifying individual users.
Cookies and Tracking: We use cookies and similar technologies to improve the Service. Cookies may store a unique identifier and remember your preferences. See the Cookies and Tracking section below for details.
How We Use Your Information
We use your information only as necessary to provide, maintain, and improve the Service, including for the following purposes:
- Service Provision: To operate the Service and enable its features (e.g. posting to social media, scheduling, analytics dashboards).
- Communication: To contact you about your account, respond to support requests, and send administrative messages (account confirmations, security alerts).
- Notifications: To notify you of important changes to the Service or policy updates.
- Machine Learning: To analyze data and train algorithms that improve our features (for example, to optimize post captions or recommend content). Any automated decision-making is designed to improve functionality and you will be informed of its significance and consequences.
- Research and Development: To analyze usage trends and customer needs so we can improve the Service.
- Compliance and Security: To prevent fraud and abuse, and to comply with legal obligations. For example, we may analyze usage patterns to detect unauthorized access.
- Marketing Communications: If you opt in, we may use your contact information to send newsletters or promotional materials about our products and services (you can unsubscribe at any time). We will not sell your Personal Data or use it for marketing without your permission.
We do not share personal data with unrelated third parties for their own marketing. We do not sell or rent any Google user data under any circumstances. We only disclose data as described below or as required by law.
Data Retention
We retain your Personal Data only as long as needed for the purposes outlined above. We determine retention periods based on the nature of the data and legal requirements. For example, we keep billing and account records for financial and legal compliance. OAuth authentication data (including Google access tokens) are retained only as long as necessary to provide the Service and are automatically deleted when you disconnect your account or delete your Postify account. When personal data is no longer needed, we securely delete or anonymize it.
International Data Transfers
Our servers and service providers may be located worldwide. If you are outside our home country, your Personal Data may be transferred to, stored, or processed in countries with different data protection laws. We will implement appropriate safeguards (such as standard contractual clauses or other legal mechanisms) to ensure your data is protected to GDPR (or similar) standards when transferred.
Third-Party Services
We use third-party service providers to support the Service. These providers process your data only on our behalf and are contractually bound to protect it. For example:
- Analytics: We use Google Analytics (Google LLC) and Vercel's analytics tools to analyze Service usage. Google processes data per its Privacy Policy and does not store IP addresses. Vercel's Web Analytics only stores anonymized visitor data and uses no cookies. Vercel Speed Insights collects only anonymous performance data.
- Hosting and Infrastructure: We rely on cloud hosting (such as Vercel's platform). These providers may collect system logs or crash reports.
- Payment Processors: If you make payments through the Service, we use PCI-compliant processors (e.g. Stripe, Apple Pay) and do not store your payment card details. (These processors have their own privacy policies.)
Disclosure of Your Data
We may share your Personal Data in the following situations:
- Legal Compliance: If required by law, regulation, or valid governmental request, we may disclose your data. We will respond to lawful requests by public authorities (e.g. court orders, subpoenas).
- Protecting Rights: We may share information if needed to protect our rights, property or safety, or the rights, property or safety of others. This includes enforcing our terms of use or preventing fraud.
- Business Transfers: If our company is involved in a merger, acquisition, or sale of assets, your Personal Data may be transferred as part of that transaction. We will notify you before any such transfer.
- Service Providers: We share data with vendors who perform services on our behalf (as noted above). They have access only to the data necessary to perform their functions and are not allowed to use it for other purposes.
Google Account Data: We do not share, sell, or rent your Google account information to third parties for their own marketing, advertising, or any other purposes beyond those listed above. Your Google account data is used solely for authentication and providing our Service to you.
Your Rights
Depending on where you live, you may have the following rights regarding your Personal Data:
- Access: You can request a copy of the personal data we hold about you.
- Correction: You can request that we correct any inaccurate or incomplete data.
- Deletion: You can request that we delete your personal data from our systems (the "right to be forgotten"), subject to legal exceptions (e.g. data we must retain for legal compliance).
- Portability: You can request a copy of your data in a common electronic format so you can transfer it to another service.
- Restriction: You can request that we temporarily limit how we use your personal data.
- Objection: You can object to our processing your data for certain purposes (e.g. direct marketing).
- Withdraw Consent: If we are processing your data based on your consent, you may withdraw that consent at any time without affecting the lawfulness of processing done before withdrawal.
- Lodge a Complaint: You have the right to file a complaint with a data protection authority if you believe we are not complying with applicable laws.
If you wish to exercise any of these rights, please contact us (see Contact below). We will verify your identity before fulfilling such requests. We aim to respond within one month, as required by law.
Data Security
We implement security measures (encryption, access controls, secure servers) to protect your data, including your OAuth authentication tokens (including Google OAuth tokens), and are transmitted over TLS 1.2+ connections to our servers. However, no system is 100% secure. We cannot guarantee the absolute security of your information. In the event of a data breach, we will follow applicable laws in notifying affected users and authorities. Only authorized personnel have access to your Personal Data, and they are bound by confidentiality obligations.
International Use
Our Service is available globally. If you are accessing the Service from the EU or other regions with data protection laws, please note that your data will be processed in compliance with those laws (e.g. GDPR). By using the Service, you consent to the transfer of information to countries outside your own jurisdiction (such as the U.S. or Canada) and storage on servers located there, with appropriate safeguards in place.
Children's Privacy
The Service is not intended for children under 13. We do not knowingly collect personal information from users under 13. If we learn that we have collected such information without parental consent, we will promptly delete it. If you believe a child under 13 may have provided us with personal data, please contact us to have it removed.
Changes to This Policy
We may update this Privacy Policy occasionally to reflect changes in our practices or legal requirements. When we make changes, we will update the "Effective Date" at the top and notify users (e.g. via email or an in-app notice) before the changes take effect. Please review this policy periodically for any updates.
Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us:
Email: privacy@postify.tech
Mail: BUSINICE S.R.L., Strada Fetesti nr 52, Bucharest, Romania
For EU residents: You may also lodge a complaint with your local Data Protection Authority if you believe your rights have been violated. We will cooperate with authorities to resolve any complaints.
Thank you for trusting us with your data. We are committed to transparency and will not use or share your information beyond the purposes described above.