Privacy Policy
Last updated: January 2025
This Privacy Policy describes how PostPiloter collects, uses, and protects your information when you use our services.
What Information Is Collected
We collect information you provide directly, information collected automatically, and information from third parties.
Account Data
Name, email, password hash, phone number, locale, and authentication preferences you provide during registration and profile updates.
Workspace and Organization Data
Agency and brand membership, roles, invitations, and workspace settings.
User-Generated Content
Briefs, comments, approvals, revisions, deliverables, and other content you create within the platform.
Uploaded Files
Files you upload (images, documents, assets) and their metadata. Files are stored on our infrastructure or configured storage providers.
Usage and Technical Information
IP address, browser type, device information, access times, pages viewed, and interaction data collected via server logs and analytics.
Authentication Data
Login timestamps, refresh tokens (hashed), MFA secrets (encrypted), and device trust records for security purposes.
Billing and Payment Information
Subscription plan, billing period, and invoice history. Payment card details are processed by Paddle and not stored by PostPiloter.
Paddle Payment Processing
As Merchant of Record, Paddle processes payments and collects necessary billing data per their privacy policy. PostPiloter receives only transaction status and subscription updates.
Email and Notification Systems
We send transactional emails (verification, password reset, notifications) via Resend. You can manage notification preferences in settings.
Security
We implement appropriate technical and organizational measures including encryption, access controls, and regular security reviews.
Data Retention
We retain personal data while your account is active and as needed to provide services, comply with legal obligations, and resolve disputes.
Data Deletion
You may request account deletion from settings. Deletion removes personal data within 30 days, except where retention is legally required.
Third-Party Processors
We use subprocessors for hosting (Hetzner), email (Resend), payments (Paddle), and WhatsApp (Twilio). Each has a data processing agreement.
International Transfers
Data may be processed in the EU, US, and other jurisdictions. We rely on standard contractual clauses and adequacy decisions where applicable.
Your Privacy Rights
You have rights to access, rectify, erase, restrict, and port your data. Contact us at privacy@postpiloter.com to exercise these rights.
KVKK Considerations
For users in Turkey, we comply with the Law on Protection of Personal Data (KVKK). You have rights under Article 11 of KVKK.
GDPR Considerations
For users in the EEA, we comply with GDPR. Legal bases include contract performance, legitimate interest, and consent where required.
Children's Privacy
PostPiloter is not directed to children under 16. We do not knowingly collect personal data from children.
Policy Changes
We may update this policy. Material changes will be communicated via email or in-app notice with a revised effective date.
Contact
Privacy questions? Contact our Data Protection team at privacy@postpiloter.com
Still have questions?
Need help with legal, privacy, or billing questions? Our team is here to assist.