Privacy policy
This policy explains what personal data Postauto collects, why, and what rights you have over it. The data controller is Postauto ("Postauto", "we"). Contact: [email protected]. The short version: we collect only what the product needs to publish your posts, we encrypt your social credentials, and we do not sell your data.
1. Data we collect
- Account data. Email address, name, and a password hash (we never store plaintext passwords), managed by our authentication system.
- Social account credentials. When you connect a channel we store the OAuth tokens, app passwords, bot tokens, or webhook URLs needed to publish on your behalf. These are encrypted at rest with AES-256-GCM before they reach our database and are never logged or displayed in plaintext.
- Content. The posts you draft, the media you upload, schedule times, and the per-channel publish results (including error messages returned by networks).
- Billing data. Payments are processed by Stripe. We store your plan, billing status, and Stripe customer reference. Your full card details never touch our servers.
- Technical data. Server logs (IP address, timestamps, requested endpoints) kept for security and debugging, and the emails we send you (delivery status).
We do not run advertising trackers, and at launch we set only strictly necessary cookies. See the cookie policy.
2. Why we process it (lawful bases)
- Performance of a contract: operating your account, storing your drafts, and publishing to the channels you connect.
- Legitimate interests: securing the service, preventing abuse, debugging failures, and sending essential service emails about your account.
- Legal obligation: tax and accounting records tied to payments.
- Consent: anything optional we add later (such as a newsletter) will be opt-in and withdrawable at any time.
3. Sharing
We share data only with the service providers that run Postauto (hosting, payments, email, CDN) and with the social networks you explicitly connect, and only as needed to publish your content. The current list, with locations, is on the subprocessors page. We do not sell personal data and we do not share it for advertising.
4. International transfers
Our primary infrastructure is hosted in the EU (Germany). Some providers (for example payment and email delivery) process data in the United States; where they do, transfers rely on recognized safeguards such as the EU Standard Contractual Clauses or an adequacy decision.
5. Retention
- Account and content data: kept while your account exists.
- Social credentials: deleted when you disconnect the channel or delete your account.
- Account deletion: personal data is deleted or anonymized within 30 days, except records we must keep for legal or accounting reasons.
- Server logs: kept for a short rolling window for security and debugging.
6. Your rights (GDPR)
If you are in the EEA, UK, or Switzerland you can ask us to access, correct, delete, or export your personal data, to restrict or object to processing, and to withdraw consent where processing is based on consent. Email [email protected] with your request; we respond within one month. You may verify your identity from your account email. You can also lodge a complaint with your local supervisory authority.
7. California residents (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect (listed in section 1), to request deletion, to request correction, and to not be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined in the CCPA, and we have not done so in the preceding 12 months. Submit requests to [email protected]; we verify requests using your account email and respond within the statutory window. Authorized agents may submit requests with proof of authorization.
8. Security
Credentials are encrypted at rest, traffic is encrypted in transit, and access to production systems is restricted. Details, including our vulnerability disclosure contact, are in the security overview. No system is perfectly secure; if a breach affects your data we will notify you and the relevant authorities as required by law.
9. Children
Postauto is not directed at children and may not be used by anyone under 16 (or the local age of digital consent). We do not knowingly collect data from children.
10. Changes
We will update this policy as the product evolves and change the date at the top. For material changes we will notify you by email or in the app before they take effect.
11. Contact
Postauto
Email: [email protected]