Privacy Policy
1. Introduction
Posting Suite ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our social media management platform, website, and related services (collectively, the "Services").
By accessing or using Posting Suite, you agree to the terms of this Privacy Policy. If you do not agree, please discontinue use of our Services immediately.
We connect with multiple third-party social media platforms — including Meta (Facebook/Instagram), Google, TikTok, Pinterest, and Reddit — via OAuth 2.0 authorization. This policy explains specifically what data we access from each platform and how we use it, in compliance with each platform's developer policies and API terms of service.
2. Information We Collect
2.1 Account Information
When you register for an account, we collect:
Full name and email address
Company name (if applicable)
Billing information and payment details (processed securely via third-party payment processors)
Account credentials (passwords are hashed using bcrypt and never stored in plain text)
2.2 Social Media Account Data via OAuth
To provide our core Services, you may connect third-party social media profiles via OAuth 2.0 authorization. When you grant permission, we receive only the data scopes you explicitly authorize. We do not store your social media passwords.
The following table summarizes the data we collect from each connected platform:
Platform |
Data We Access |
Purpose |
Meta (Facebook / Instagram) |
Access tokens, Page/account IDs, profile name and photo, post performance metrics, audience insights, publishing capabilities |
Schedule and publish content; display analytics; manage your connected Pages and Instagram accounts |
Google (YouTube / Google Sign-In) |
Google account ID, name, email address, profile picture, YouTube channel data, video metadata, channel analytics |
Authenticate your account; schedule and publish YouTube content; display channel performance metrics |
TikTok |
TikTok user ID, display name, avatar URL, video list, engagement metrics (views, likes, shares, comments), publishing access |
Schedule and publish TikTok videos; display performance analytics for your TikTok content |
Pinterest user ID, username, profile info, board list, pin data, analytics (impressions, saves, clicks) |
Schedule and publish Pins; manage boards; display Pinterest analytics |
|
Reddit username, account ID, subscribed subreddits, post and comment history (for connected accounts), karma data |
Schedule and publish Reddit posts; display subreddit performance data |
Important: We only request the minimum OAuth scopes necessary to deliver the features you use. We do not access private messages, contact lists, or payment information from any connected platform. You may revoke our access at any time via each platform's app permissions settings. |
2.3 Content and Usage Data
Content Data: Posts, captions, images, videos, reels, carousels, and creative assets you create, upload, or generate via our AI tools
Scheduling Data: Publishing calendars, queue settings, timing preferences, and campaign configurations
Analytics Data: Post-level metrics, engagement statistics, reach, impressions, clicks, saves, and audience growth data retrieved from connected platforms
AI Interaction Data: Prompts and templates used, and outputs generated through our AI-powered content creation features
2.4 Log and Device Information
IP address and approximate geolocation
Browser type and version
Device type and operating system
Referring/exit pages, date/time stamps, clickstream data within our platform
2.5 Cookies and Tracking Technologies
We use cookies, web beacons, and similar technologies to:
Maintain secure user sessions
Remember preferences and settings
Analyze platform usage and performance
Deliver personalized experiences
You can manage cookie preferences through your browser settings. Cookies essential to platform functionality cannot be disabled. For more information, see our Cookie Policy.
3. How We Use Your Information
We use the information collected to:
Provide and Maintain Services — Enable account creation, social profile connections, content scheduling, publishing, and analytics.
AI Content Generation — Process your prompts and inputs to generate text, images, and video content through integrated AI models.
Improve Platform Performance — Analyze usage patterns, troubleshoot issues, and optimize the user experience.
Communications — Send service notifications, security alerts, billing updates, and optional marketing emails (you may opt out at any time).
Security and Fraud Prevention — Detect unauthorized access, abuse, or violations of our Terms of Service.
Legal Compliance — Fulfill regulatory obligations and respond to lawful requests from authorities.
4. Third-Party Platform OAuth Compliance
We connect to the following platforms via OAuth 2.0. Our use of each platform's data is governed by their respective developer policies in addition to this Privacy Policy.
4.1 Meta (Facebook & Instagram)
Our use of data obtained via Meta's APIs complies with the Meta Platform Terms and Meta's Developer Policies.
We access only the permissions you explicitly grant during Facebook/Instagram Login.
We use Meta platform data solely to provide scheduling, publishing, and analytics features within Posting Suite.
We do not use Meta user data to target advertisements outside of Meta's own advertising products.
We do not sell, license, or transfer Meta user data to third parties for any purpose not described in this policy.
We do not use Meta data to build profiles of users for purposes unrelated to the Services.
Meta Data Deletion You can request deletion of your Meta-related data at any time by: 1. Visiting our Contact Page: https://postingsuite.com/contact 2. Submitting a data deletion request with subject: 'Meta Data Deletion Request' 3. We will process your request within 30 days and confirm deletion by email.
Alternatively, you can disconnect our app via Facebook Settings > Apps and Websites. Revoking access stops all future data collection from Meta platforms immediately. |
4.2 Google (YouTube & Google Sign-In)
Our use of data obtained via Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
Google API Services User Data Policy Disclosure: Posting Suite's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. See: https://developers.google.com/terms/api-services-user-data-policy |
We access Google user data only to provide or improve the user-facing features described in this Privacy Policy.
We do not use Google user data for serving advertisements.
We do not allow humans to read your Google data unless you give explicit permission, it is necessary for security purposes, or we are required to do so by law.
We do not use or transfer Google user data for any purpose that is not disclosed in this policy.
We do not share Google user data with third parties except as necessary to provide our Services, subject to confidentiality agreements.
We store Google OAuth tokens securely using AES-256 encryption and rotate them on a regular schedule.
Google Data Deletion To delete your Google-related data from Posting Suite: 1. Visit our Contact Page: https://postingsuite.com/contact 2. Submit a request with subject: 'Google Data Deletion Request' 3. We will process your request within 30 days.
You can also revoke Posting Suite's access via Google Account Settings > Security > Third-party apps with account access at any time. |
4.3 TikTok
Our use of data obtained via TikTok's API complies with TikTok's Developer Terms of Service and Platform Policies.
We access only the TikTok API scopes required to deliver our scheduling and analytics features.
We use TikTok data solely to publish content on your behalf and to display analytics within our platform.
We do not sell, share, or transfer TikTok user data to third parties for advertising or any unauthorized purpose.
We do not use TikTok data to build independent user profiles or for behavioral tracking outside our Services.
TikTok access tokens are encrypted and stored securely; we do not retain tokens beyond their expiration period.
TikTok Data Deletion TikTok requires that apps provide a data deletion mechanism. To delete your TikTok data: 1. Visit our Contact Page: https://postingsuite.com/contact 2. Submit a request with subject: 'TikTok Data Deletion Request' 3. We will remove all TikTok-related tokens, profile data, and analytics from our systems within 30 days and confirm by email.
You may also revoke access via TikTok App > Settings > Apps & Integrations. |
4.4 Pinterest
Our use of data obtained via Pinterest's API complies with Pinterest's Developer Terms and API usage policies.
We access only the Pinterest scopes required to schedule Pins and display analytics.
We use Pinterest data solely to publish Pins on your behalf and show performance metrics within our platform.
We do not use Pinterest user data for ad targeting outside of Pinterest or for unauthorized profiling.
We do not share Pinterest user data with third parties beyond what is required to operate our Services.
Pinterest Data Deletion To delete your Pinterest-related data from Posting Suite: 1. Visit our Contact Page: https://postingsuite.com/contact 2. Submit a request with subject: 'Pinterest Data Deletion Request' 3. We will process your request within 30 days.
You can also disconnect our app via Pinterest Settings > Apps. |
4.5 Reddit
Our use of data obtained via Reddit's API complies with Reddit's API Terms of Use and Developer Guidelines.
We access only the Reddit OAuth scopes required to schedule posts and retrieve account analytics.
We use Reddit data solely to publish posts on your behalf and display subreddit performance metrics.
We do not use Reddit data for surveillance, user tracking, or any purpose not described in this policy.
We do not scrape, archive, or aggregate Reddit content in bulk beyond what is necessary to provide our Services.
We do not sell or share Reddit user data with third parties for commercial purposes unrelated to our Services.
Reddit Data Deletion To delete your Reddit-related data from Posting Suite: 1. Visit our Contact Page: https://postingsuite.com/contact 2. Submit a request with subject: 'Reddit Data Deletion Request' 3. We will process your request within 30 days.
You can also revoke our access via Reddit Preferences > Apps. |
5. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA) or United Kingdom, we process personal data under the following legal bases:
Contractual Necessity: To provide the Services you requested and fulfil our agreement with you
Legitimate Interests: Platform improvement, security monitoring, and fraud prevention
Consent: For marketing communications, non-essential cookies, and optional integrations
Legal Obligation: To comply with applicable laws and regulatory requirements
6. How We Share Your Information
We do not sell your personal data. We may share information only in the following circumstances:
6.1 Service Providers
Trusted third-party processors performing functions on our behalf, including:
Cloud hosting and infrastructure providers
Payment processing services (we do not store payment card data ourselves)
AI and machine learning model providers (for content generation features)
Analytics and error-tracking services
Email and communication platforms
All service providers are contractually bound to process data only for specified purposes and must maintain appropriate technical and organisational security measures.
6.2 Social Media Platforms
When you connect accounts and initiate publishing actions, the content and associated metadata you choose to post is transmitted to the respective social media platform (Meta, Google, TikTok, Pinterest, Reddit) according to your instructions and each platform's own privacy policy.
6.3 Business Transfers
In the event of a merger, acquisition, or asset sale, user data may be transferred subject to confidentiality obligations and prior notice to affected users.
6.4 Legal Requirements
We may disclose information if required by law, court order, or governmental request, or to protect our rights, property, users, or the public from harm.
7. How to Request Deletion of Your Data
You have the right to request that we delete your personal data, including data obtained from connected social media accounts. We take deletion requests seriously and will process them promptly.
7.1 How to Submit a Deletion Request
To request deletion of your data, visit our Contact Page: https://postingsuite.com/contact
Please include in your message: • Your registered email address • The type of data you wish deleted (All Data / Specific Platform / Account Only) • Subject line: 'Data Deletion Request' (or the platform-specific subject listed in Section 4) |
7.2 What Happens After You Submit
We will process your request according to the following steps:
Acknowledgement within 72 hours of receipt of your request.
Identity verification (we may ask you to confirm your registered email to prevent fraudulent deletion requests).
Processing your deletion request within 30 days of verification.
Confirmation email sent once deletion is complete, specifying what was removed.
7.3 Scope of Deletion
Data Type |
Deleted? |
Notes |
Account profile & credentials |
Yes |
Deleted within 30 days of account deletion request |
Scheduled posts & drafts |
Yes |
Removed immediately upon request |
OAuth tokens (Meta, Google, TikTok, Pinterest, Reddit) |
Yes |
All access tokens revoked and deleted |
Analytics & performance data |
Yes |
Deleted within 90 days |
Billing records |
Partial |
Retained 7 years for legal/tax compliance |
Published content on social platforms |
No |
Subject to each platform's own retention policy |
Anonymised aggregate analytics |
No |
No personal identifier retained; cannot be linked back to you |
7.4 Account Deletion vs. Data Deletion
Deleting your Posting Suite account will automatically trigger deletion of all personal data (excluding legally required records). You can delete your account from Account Settings > Danger Zone > Delete Account, or by submitting a request via the Contact Page.
7.5 Disconnecting a Specific Platform
If you only want to remove data from a specific connected platform without deleting your entire account:
Navigate to Settings > Connected Accounts in your dashboard.
Click "Disconnect" next to the relevant platform.
All OAuth tokens and platform-specific data for that connection will be deleted within 7 days.
For complete removal of historical data from that platform, submit a platform-specific deletion request via the Contact Page using the subject lines in Section 4.
8. Data Retention
We retain your personal data for as long as your account is active or as necessary to:
Provide Services and fulfil contractual obligations
Comply with legal, tax, and accounting requirements (typically 7 years for financial records)
Resolve disputes and enforce our agreements
Upon account deletion, we delete or anonymise your personal data within 90 days, except where retention is required by law or for legitimate purposes (e.g., fraud prevention, financial records).
Content published to third-party social platforms via our Services remains subject to those platforms' own retention and deletion policies.
9. Data Security
We implement industry-standard security measures, including:
TLS/SSL encryption for all data in transit
AES-256 encryption for sensitive data at rest (including OAuth tokens)
Secure OAuth token storage with automatic rotation and revocation on disconnect
Role-based access controls and multi-factor authentication for internal systems
Regular security audits, penetration testing, and vulnerability assessments
SOC 2 Type II compliant infrastructure
No method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. Please notify us immediately at support@postingsuite.com if you suspect unauthorised access to your account.
10. Your Privacy Rights
10.1 General Rights (All Users)
Depending on your location, you may have the following rights regarding your personal data:
Access: Request a copy of the personal data we hold about you
Correction: Update inaccurate or incomplete information
Deletion: Request deletion of your personal data (see Section 7)
Portability: Receive your data in a structured, machine-readable format (JSON or CSV)
Restriction: Request that we limit processing of your data
Objection: Object to processing based on legitimate interests or direct marketing
10.2 GDPR Rights (EEA / UK Users)
You have all rights listed above plus the right to lodge a complaint with your local supervisory authority (e.g., the ICO in the UK or relevant EU DPA). To exercise your GDPR rights, contact us at support@postingsuite.com or via the Contact Page.
10.3 CCPA / CPRA Rights (California Residents)
Right to Know: Request disclosure of categories and specific pieces of personal information collected about you in the past 12 months
Right to Delete: Request deletion of personal information we have collected from you
Right to Opt-Out: We do not sell personal information, so no opt-out is required
Right to Non-Discrimination: We will not discriminate against you for exercising any privacy rights
To exercise CCPA rights, email support@postingsuite.com with the subject line "California Privacy Rights" or submit via our Contact Page.
11. International Data Transfers
Posting Suite operates globally. Your data may be transferred to and processed in countries outside your jurisdiction, including the United States. We ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, to protect your data during international transfers.
12. Children's Privacy
Our Services are not intended for individuals under 16 years of age (or the applicable age of digital consent in your country). We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a minor, contact us immediately at support@postingsuite.com for deletion.
13. Third-Party Links and Integrations
Our platform contains links to third-party websites and integrations with social media platforms. This Privacy Policy does not apply to those platforms. We encourage you to review the privacy policies of:
Meta: https://www.facebook.com/privacy/policy
Google: https://policies.google.com/privacy
TikTok: https://www.tiktok.com/legal/page/us/privacy-policy
Pinterest: https://policy.pinterest.com/en/privacy-policy
Reddit: https://www.reddit.com/policies/privacy-policy
14. AI and Automated Decision-Making
Our AI content generation tools process your inputs to create text, images, and video structures. These tools operate entirely under your direction and do not make autonomous decisions that significantly affect you. You retain full editorial control over all AI-generated outputs before publication. We do not use automated processing to make decisions about your account access without human review.
15. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technologies, legal requirements, or the terms of our platform partners. Material changes will be communicated via:
Email notification to your registered email address
A prominent notice on our platform dashboard
Such notice will be provided at least 30 days before the changes take effect. Continued use of our Services after changes take effect constitutes your acceptance of the updated policy.
16. Contact Us
For questions, concerns, or to exercise any of your privacy rights described in this Policy, please contact us through one of the following channels:
Channel |
Details |
Use For |
Contact Page |
https://postingsuite.com/contact |
Data deletion requests, privacy enquiries, account issues |
Support Email |
support@postingsuite.com |
General privacy questions, GDPR/CCPA requests |
Mailing Address |
5400 Sharaqpur, Sheikhpura, Punjab, Pakistan |
Formal legal correspondence |
For platform-specific data deletion requests, please use the subject lines specified in Section 4 (e.g., 'Meta Data Deletion Request', 'Google Data Deletion Request', 'TikTok Data Deletion Request', 'Pinterest Data Deletion Request', 'Reddit Data Deletion Request').
Effective Date: April 5, 2026 | Last Updated: June 6, 2026
© 2026 Posting Suite. All Rights Reserved.