Skip to content

Privacy Policy

Last updated: January 2025

This Privacy Policy describes how PostPiloter collects, uses, and protects your information when you use our services.

What Information Is Collected

We collect information you provide directly, information collected automatically, and information from third parties.

Account Data

Name, email, password hash, phone number, locale, and authentication preferences you provide during registration and profile updates.

Workspace and Organization Data

Agency and brand membership, roles, invitations, and workspace settings.

User-Generated Content

Briefs, comments, approvals, revisions, deliverables, and other content you create within the platform.

Uploaded Files

Files you upload (images, documents, assets) and their metadata. Files are stored on our infrastructure or configured storage providers.

Usage and Technical Information

IP address, browser type, device information, access times, pages viewed, and interaction data collected via server logs and analytics.

Cookies

We use essential cookies for authentication, session management, and security. We do not use third-party advertising cookies.

Authentication Data

Login timestamps, refresh tokens (hashed), MFA secrets (encrypted), and device trust records for security purposes.

Billing and Payment Information

Subscription plan, billing period, and invoice history. Payment card details are processed by Paddle and not stored by PostPiloter.

Paddle Payment Processing

As Merchant of Record, Paddle processes payments and collects necessary billing data per their privacy policy. PostPiloter receives only transaction status and subscription updates.

Email and Notification Systems

We send transactional emails (verification, password reset, notifications) via Resend. You can manage notification preferences in settings.

Security

We implement appropriate technical and organizational measures including encryption, access controls, and regular security reviews.

Data Retention

We retain personal data while your account is active and as needed to provide services, comply with legal obligations, and resolve disputes.

Data Deletion

You may request account deletion from settings. Deletion removes personal data within 30 days, except where retention is legally required.

Third-Party Processors

We use subprocessors for hosting (Hetzner), email (Resend), payments (Paddle), and WhatsApp (Twilio). Each has a data processing agreement.

International Transfers

Data may be processed in the EU, US, and other jurisdictions. We rely on standard contractual clauses and adequacy decisions where applicable.

Your Privacy Rights

You have rights to access, rectify, erase, restrict, and port your data. Contact us at privacy@postpiloter.com to exercise these rights.

KVKK Considerations

For users in Turkey, we comply with the Law on Protection of Personal Data (KVKK). You have rights under Article 11 of KVKK.

GDPR Considerations

For users in the EEA, we comply with GDPR. Legal bases include contract performance, legitimate interest, and consent where required.

Children's Privacy

PostPiloter is not directed to children under 16. We do not knowingly collect personal data from children.

Policy Changes

We may update this policy. Material changes will be communicated via email or in-app notice with a revised effective date.

Contact

Privacy questions? Contact our Data Protection team at privacy@postpiloter.com

Still have questions?

Need help with legal, privacy, or billing questions? Our team is here to assist.