Privacy Policy
1. Introduction
This Privacy Policy explains how Codian Limited collects, uses, shares, and protects personal data when you use Postid (the "Service"). It applies to anyone who:
- Registers an account with the Service.
- Visits postid.app and provides information through forms (e.g., the contact form).
- Joins a Workspace as an invited team member.
- Connects a third-party social media account to the Service.
We are the data controller for the personal data described in this notice. If you are a member of a Workspace owned by someone else, that Workspace Owner may also act as a controller for content and metadata you produce inside their Workspace; we act as a processor of that content on their behalf.
This Policy is supplemented by:
- The Kullanım Koşulları / Terms of Service — defines the contract between you and us.
- The KVKK Aydınlatma Metni — additional disclosures required by Turkish Personal Data Protection Law No. 6698 ("KVKK") for data subjects in Türkiye.
If anything in this Policy conflicts with the KVKK Aydınlatma Metni for data subjects in Türkiye, the KVKK Aydınlatma Metni governs to the extent of the conflict.
2. Personal Data We Collect
The categories of personal data we process and the sources are summarised below.
2.1 Account and identity data
| Field | Source | Purpose summary |
|---|---|---|
| Email address | You, when you register | Identifier, login, transactional emails, password reset, billing notices |
| Password (hashed) | You, when you register | Authentication |
| Display name | You, when you register or update profile | Display in dashboard, notifications |
| Preferred locale (tr, en) | You, browser default | UI language and email templates |
| Preferred timezone (IANA identifier) | You, browser default | Scheduling correctness |
| Two-factor authentication secret + recovery codes | You, when you enable 2FA | Authentication |
| Email verification / password-reset / email-change tokens | Generated by us | Account-security flows |
| Last login timestamp | Generated by us | Account-security display |
2.2 Workspace and billing data
| Field | Source | Purpose summary |
|---|---|---|
| Company name, tax number, tax office, address, city, country, postal code, phone | You, in Workspace settings | Invoicing, tax compliance |
| Stripe Customer ID | Stripe, when you subscribe | Linking your account to a Stripe customer record |
| Subscription state (plan, trial end, cancellation date, extra seats/workspaces/accounts) | You and Stripe | Plan enforcement, billing |
| Credit balance and transaction history | Generated by us | Credit-based features |
We do not store full payment card numbers, CVV codes, or card expiry data. Stripe holds and processes that information under its own privacy notice.
2.3 Connected Account (Meta) data
When you connect a Facebook Page, Instagram Business profile, or Threads profile via OAuth:
| Field | Source | Purpose summary |
|---|---|---|
| Platform user ID, Page ID, Instagram Business ID | Meta (Graph API) | Identifying the Connected Account |
| OAuth access token | Meta | Authentication when posting on your behalf |
| OAuth refresh token (where issued) | Meta | Long-lived token renewal |
| Token expiry timestamp | Meta | Token-refresh scheduling |
| Account name and profile image URL | Meta | Display in dashboard |
| Login method (Facebook / Instagram / Threads) | Determined by you | OAuth flow routing |
OAuth tokens are stored encrypted at rest and are used only to perform actions you have authorised: publishing content to the Connected Account, refreshing tokens, fetching analytics for content published through the Service, and disconnecting the account on your request.
2.4 User-generated content
| Field | Source | Purpose summary |
|---|---|---|
| Post text, scheduling time | You | Storing and publishing the post |
| Uploaded media (images, video) | You | Hosting in MinIO object storage; publishing to Connected Accounts |
| Approval workflow events (submit, approve, reject, comments) | You and your collaborators | Approval workflow audit trail |
| Saved replies and channel groups | You | Composer convenience features |
2.5 Analytics data
For posts you publish through the Service, we collect from Meta:
- Post-level metrics (impressions, engagement counts).
- Aggregated demographics for the Connected Account audience.
This data is stored in our Elasticsearch index for the retention period described in Section 7.
2.6 Technical and security data
| Field | Source | Purpose summary |
|---|---|---|
| IP address | Browser / Cloudflare | Audit log, abuse prevention, geographic rate-limiting |
| User agent string | Browser | Audit log, troubleshooting |
| Correlation ID and request log | Generated by us | Operational diagnostics |
| Rate-limit counters | Generated by us | Service-level enforcement |
| Activity log entries (e.g., PostCreated, PostPublished, AccountConnected) | Generated by us | Tenant audit timeline |
| Audit log entries (entity changes, who changed what, when) | Generated by us | KVKK Article 11 compliance, internal compliance |
2.7 Communications data
| Field | Source | Purpose summary |
|---|---|---|
| Email messages sent to [email protected] (or other support addresses) | You | Responding to and processing your requests |
| Notification preferences and read/unread state | You and your activity | Notification dispatch |
| Enterprise inquiry form submissions | You, through the marketing site | Sales follow-up |
3. How We Use Your Personal Data and the Legal Basis
We process your personal data for the purposes below. The "legal basis" column refers to Article 6 of the GDPR and UK GDPR.
| Purpose | Categories of data | Legal basis |
|---|---|---|
| Provide the Service (account creation, authentication, content publishing, analytics, notifications) | Account, Workspace, Connected Account, User Content, Technical | Performance of contract (Art 6(1)(b)) |
| Bill you for paid Subscriptions and credit purchases | Account, Workspace, Stripe Customer ID | Performance of contract (Art 6(1)(b)); compliance with tax law (Art 6(1)(c)) |
| Send transactional emails (verification, password reset, billing notices, post-status alerts) | Account, Communications | Performance of contract (Art 6(1)(b)) |
| Detect, prevent, and respond to abuse, fraud, and security incidents | Technical, Audit log | Legitimate interest (Art 6(1)(f)) — operating a secure service |
| Comply with legal obligations (tax records, court orders, regulatory inquiries) | Workspace, billing, Audit log | Legal obligation (Art 6(1)(c)) |
| Improve and develop the Service (aggregate usage analysis) | Aggregated and pseudonymised | Legitimate interest (Art 6(1)(f)) |
| Respond to your support requests | Communications, Account | Performance of contract (Art 6(1)(b)) |
| Marketing communications (only with your prior consent) | Account, email | Consent (Art 6(1)(a)) |
We do not sell personal data, and we do not use Connected Account data or User Content to train artificial intelligence models that operate outside the Service you signed up for.
4. Who We Share Personal Data With (Sub-Processors)
We share personal data with the third parties listed below, each of whom acts as our processor or as an independent controller for limited purposes.
| Sub-processor | Location | Data shared | Purpose | Safeguards |
|---|---|---|---|---|
| Meta Platforms, Inc. (Facebook, Instagram, Threads) | United States | OAuth credentials, posted content, analytics requests | Authentication, content publishing, analytics retrieval | Their own Privacy Policy; EU-US Data Privacy Framework where applicable |
| Stripe, Inc. | United States | Billing details (name, address, tax ID, email, payment card via Stripe Elements) | Payment processing, invoice generation, tax calculation (Stripe Tax) | Standard Contractual Clauses; Stripe's GDPR programme |
| Cloudflare, Inc. | Global edge (data centres including EU) | IP address, request metadata | DDoS protection, content delivery, WAF | Standard Contractual Clauses; Cloudflare DPA |
| OVH SAS (infrastructure host) | EU data centre | All server-side data (encrypted at rest) | Hosting the Service's compute and storage | GDPR-compliant hosting agreement; data centre located in the EU |
Transactional emails (account verification, password reset, billing notices, post-status alerts) are sent via our own self-hosted mail server (IredMail) running on a private network secured by Tailscale. The server is located in the European Union. No third-party email delivery provider receives recipient addresses or message contents for our transactional mail.
We do not share personal data with any party other than as described above, except:
- When you direct us to (for example, by connecting an account or sharing a post link).
- To comply with a binding legal request from a competent authority.
- In connection with a merger, acquisition, or sale of assets — in which case we will notify affected data subjects in advance where possible.
We do not sell personal data to advertisers, data brokers, or any other third party.
5. International Data Transfers
Our primary infrastructure is hosted in an OVH data centre in the European Union. Some sub-processors (Meta, Stripe, Cloudflare) operate globally. When personal data is transferred outside the United Kingdom or the European Economic Area, we rely on the following safeguards:
- The European Commission's Standard Contractual Clauses (Module 2 — controller-to-processor) and the UK International Data Transfer Addendum, included in our agreements with sub-processors.
- The EU-US Data Privacy Framework for transfers to certified US sub-processors, where applicable.
- For Türkiye-based data subjects, transfers comply with the requirements of KVKK Article 9 (transfers based on explicit consent, an adequacy decision, or other applicable lawful grounds).
You may request a copy of the safeguards by contacting [email protected]. [LEGAL REVIEW: confirm sub-processor agreements actually incorporate the SCCs / UK Addendum.]
6. Cookies and Similar Technologies
We use a minimal set of cookies necessary to operate the Service:
| Purpose | Category | Expiry |
|---|---|---|
| Authentication session (so you stay signed in across pages) | Strictly necessary | ~15 minutes (sliding renewal) |
| Long-lived session refresh (so you don't have to sign in repeatedly) | Strictly necessary | 30 days |
| Cross-site request forgery (CSRF) protection | Strictly necessary | Session |
| Language preference (tr/en) | Functional | 1 year |
All authentication-related cookies are set with the HttpOnly, Secure, and SameSite=Lax flags so they cannot be read by JavaScript, only travel over HTTPS, and are not sent on cross-site requests.
We currently do not use third-party analytics cookies (Google Analytics, Facebook Pixel, etc.). If we add such cookies in future we will deploy a consent banner and obtain your consent before setting them, in line with applicable ePrivacy law and KVKK guidance on online tracking.
You can disable cookies in your browser settings, but the Service will not work without the strictly-necessary cookies above.
7. How Long We Keep Your Personal Data
We retain personal data only for as long as necessary for the purposes for which it was collected, subject to applicable retention requirements.
| Category | Retention period |
|---|---|
| Account data (email, name, locale, timezone) | For as long as the Account is active, plus 30 days after account closure. Backups containing this data are rotated out within 60 days. |
| Password hash and 2FA secrets | For as long as the Account is active. Permanently deleted on Account closure. |
| Workspace and billing data | 10 years after the end of the Subscription, to comply with UK and Turkish tax/accounting record-keeping obligations. |
| OAuth tokens for Connected Accounts | Until you disconnect the account or your Account is closed. Tokens are revoked promptly on disconnection. |
| User Content (posts, media) | For as long as you keep them in the Service. Deleted within 30 days of deletion from the dashboard. |
| Analytics data | 24 months from collection (subject to your plan's analytics retention; lower tiers have shorter retention as described on the pricing page). |
| Activity log and audit log | 2 years from creation, subject to longer retention where required by law (e.g., security incident investigation). |
| Email communications with support | 3 years from the last message, then deleted unless required for a legal claim. |
| Backup snapshots | Rotated out within 60 days. |
When the retention period expires, we delete or irreversibly anonymise the data.
8. Your Rights
Under the UK GDPR, EU GDPR, and Turkish Personal Data Protection Law No. 6698 (KVKK), you have the following rights regarding your personal data:
- Right of access — request a copy of the personal data we hold about you.
- Right of rectification — request correction of inaccurate or incomplete data.
- Right of erasure ("right to be forgotten") — request deletion of your personal data where the legal grounds for processing have ended.
- Right of restriction — ask us to limit how we process your data while a complaint is investigated or in other limited circumstances.
- Right of data portability — receive your data in a structured, commonly used, machine-readable format and have it transmitted to another controller, where technically feasible.
- Right to object — object to processing based on our legitimate interests, including profiling.
- Right to withdraw consent — where processing is based on consent, withdraw it at any time without affecting processing carried out before withdrawal.
- Right to lodge a complaint — with a supervisory authority. For data subjects in the UK: the Information Commissioner's Office (ICO). For data subjects in the EU: your local data-protection authority. For data subjects in Türkiye: the Kişisel Verileri Koruma Kurumu (KVKK Kurumu) — see also our KVKK Aydınlatma Metni.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days, or sooner where required by law (KVKK requires response within 30 days; UK GDPR within one month).
You can also exercise some rights directly through the Service:
- View and update your profile data in Settings → Profile.
- Download an export of your Workspace data via Settings → Export (subject to plan).
- Close your Account from Settings → Account → Close Account, which triggers deletion within 30 days.
If we cannot identify you with the information you provide, we may ask you for additional information to verify your identity before acting on a request.
9. Security
We protect personal data through technical and organisational measures, including:
- In-transit encryption (TLS 1.2+) for all browser and API traffic.
- At-rest encryption for OAuth tokens, 2FA secrets, and database backups.
- Role-based access control for internal access to production systems, with the principle of least privilege.
- Audit logging of administrative and data-access events.
- Rate-limiting to mitigate brute-force and abusive traffic.
- Two-factor authentication for user accounts (optional) and for staff accounts.
- HashiCorp Vault for secret storage, with environment-segregated paths.
- Regular dependency updates and automated security scanning in our CI pipeline.
- Incident response procedures for personal data breaches.
No system can be guaranteed completely secure. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 48 hours of becoming aware of the breach, and affected data subjects without undue delay, in accordance with GDPR Article 33-34 and KVKK Article 12.
10. Children
The Service is not intended for children under 16. We do not knowingly collect personal data from children under 16. If you believe we have collected personal data from a child under 16, contact [email protected] and we will delete it without undue delay.
11. Automated Decision-Making and Profiling
We do not make decisions about you that produce legal or similarly significant effects based solely on automated processing. We do not engage in profiling for advertising or marketing purposes.
Rate-limiting decisions (e.g., temporarily slowing requests from an IP showing abusive behaviour) are automated but do not produce legal effects and are reversible on appeal.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified to you by email or by an in-Service notice at least 30 days before they take effect. Non-material changes (clarifications or typo fixes) may take effect immediately.
The current version of the Policy is always available at https://postid.app/legal/privacy.
13. Contact
For questions about this Privacy Policy, to exercise your data-subject rights, or for any data protection matter:
- Data Protection Officer: Postid Privacy Team
- DPO Email: [email protected]
- General contact: [email protected]
- Postal address: Codian Limited, Suite 8791, 5 Brayford Square, London, United Kingdom, E1 0SG
- Company Number: 16333262
For data-subject rights requests under GDPR / UK GDPR / KVKK, please email the DPO at [email protected]. The DPO oversees compliance with applicable data protection law and is the primary contact for supervisory authorities (the ICO, EU DPAs, and the KVK Kurumu) where applicable.