Poststack.ai Privacy Policy
Last updated: 8/9/2026
About this notice
This privacy notice explains how Poststack.ai collects, uses, stores, transfers, and protects your personal data when you visit https://poststack.ai (our marketing site and agency directory) or use our scheduling application at https://app.poststack.ai (the "Service").
Who we are. Poststack.ai is the Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP"). The Data Fiduciary is the entity that, alone or jointly with others, determines the purpose and means of processing personal data. As a Data Fiduciary we decide why and how your personal data is processed.
Who you are. You are the Data Principal under DPDP — the individual to whom the personal data relates.
Framework priority. This notice is written primarily to satisfy the DPDP Act 2023 and the DPDP Rules 2025, because Poststack is India-focused and processes personal data of users in India. Sections covering the EU General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act ("CCPA") are included as secondary frameworks for visitors from the EU/EEA and California who are not Indian users.
Plain language. We have written this notice in plain language. Defined terms keep the same meaning throughout this notice and our Terms of Service.
Service intent and age. The Service is intended for business and professional use by individuals aged 18 and above. We do not knowingly collect personal data from anyone under 18. See the "Children's data" section below.
Personal data we collect, itemised
We collect only the personal data listed below. Each item shows the specific fields collected and the source. The next section ("Purposes for each data field") ties each field to a specific, enumerated purpose.
A. Account and profile data
- Email address — provided by you at signup or via OAuth login.
- Password — stored as a one-way hash; you provide it at signup. We cannot read it in plaintext.
- First name and last name — provided by you at signup or via OAuth.
- Bio and avatar — provided by you when editing your profile.
- Date of birth — provided by you at signup, used only to verify that you are 18 or older.
B. Contact data
- Email address — same as above; used for transactional and account-related communication.
- Phone number — collected only if you choose to provide it in a contact form or when claiming an agency listing.
C. Device and network data
- IP address — collected automatically when you connect to the Service.
- User agent (browser type and operating system) — collected automatically when you connect to the Service.
D. Social media platform data (app.poststack.ai users only)
- OAuth access tokens and refresh tokens — obtained from each platform you connect, stored encrypted at rest.
- Platform profile IDs, names, and profile pictures — obtained from each connected platform.
- Content you create for scheduling — posts, captions, images, videos, hashtags, links.
- Publishing history and scheduled post queue — for the platforms you connect.
- Engagement metrics and fetch history — pulled from platform APIs when you view analytics.
E. Workspace and organisation data
- Organisation name and description — provided by you when creating a workspace.
- Workspace members and roles — email addresses and role assignments you make within your workspace.
F. Payment data
- Customer ID, subscription ID, plan tier, subscription status, and trial dates — held by us to manage your subscription.
- Card and net-banking details — handled entirely by our payment processor Razorpay (India). We do not receive or store your full card number or net-banking credentials.
G. B2B directory data (agency listings)
- Agency name, description, public website, and public social handles — sourced from publicly available information or submitted by you. This is publicly available data and is exempt from DPDP consent requirements under the proviso to Section 3(b).
- Agency owner email and phone — collected only when an agency representative claims or edits a listing. This is personal data and is processed on the basis of your consent at the point of claim or edit.
H. Analytics data
- Engagement metrics, demographics, fetch history, and feature usage — derived from your use of the Service and stored in our analytics store.
I. Cookies and similar technologies
- Cookie identifiers and local storage entries — set when you visit the marketing site, subject to the cookie consent banner. See the "Cookies" section below.
Purposes for each data field
DPDP requires that each purpose be specific and limited to the personal data necessary for that purpose. The table below maps each data field to the specific purpose for which we process it. We do not use your personal data for any purpose not listed here.
A. Account and profile data
- Email address — to create and identify your account; to send you transactional emails about your account (login confirmations, password resets, security alerts); to send you product-update emails relevant to your account type, only if you opt in.
- Password (hashed) — to authenticate your login.
- First name and last name — to address you in the product and in transactional emails; to display your name within workspaces you belong to.
- Bio and avatar — to display your profile to other members of your workspace.
- Date of birth — to verify at signup that you are 18 or older. We do not use date of birth for any other purpose.
B. Contact data
- Email address — to respond to inquiries you send us; to send you account-related notifications.
- Phone number — to contact you about an agency listing you have claimed, only where you provided it for that purpose.
C. Device and network data
- IP address and user agent — to detect and prevent unauthorised access, fraud, and abuse of the Service; to maintain security logs required under DPDP Rule 6(1)(e). This use falls within Section 7(a) of DPDP (use for a purpose incidental to the functioning of the State, or for compliance with a legal obligation) and does not require separate consent.
D. Social media platform data
- OAuth access and refresh tokens — to publish posts to your connected social media accounts at the times you schedule; to refresh access when a token expires; to disconnect access when you remove a platform.
- Platform profile IDs, names, and profile pictures — to display connected accounts in your workspace and to attribute posts to the correct platform profile.
- Content you create for scheduling — to publish that content to the platforms you choose, at the times you choose.
- Publishing history and scheduled post queue — to show you what is scheduled and what has been published; to retry failed posts.
- Engagement metrics and fetch history — to show you analytics for content you have published through the Service.
E. Workspace and organisation data
- Organisation name and description — to label your workspace in the product.
- Workspace members and roles — to grant and manage access to your workspace; to enforce role-based permissions.
F. Payment data
- Customer ID, subscription ID, plan tier, subscription status, and trial dates — to manage your subscription, billing, and access to paid features.
- Card and net-banking details — processed by Razorpay (India) to collect payment. We do not receive or store full card numbers.
G. B2B directory data
- Agency name, description, public website, and public social handles — to display the agency in our public directory. This is publicly available data and is processed without consent under the proviso to DPDP Section 3(b).
- Agency owner email and phone — to verify the claim of an agency listing and to contact you about that listing. Processed on the basis of your consent at the point of claim or edit.
H. Analytics data
- Engagement metrics, fetch history, and feature usage — to analyse feature usage to improve the publishing workflow; to diagnose errors you report to support; to compute aggregate metrics shown in your analytics views. We do not run broad "platform improvement and analytics" processing; each analytics use is one of the specific purposes listed here.
- Demographics — to show you aggregate audience summaries for content you have published, where the connected platform provides this data.
I. Cookies and similar technologies
- Cookie identifiers and local storage entries — for the specific purposes described in the "Cookies" section below, per the consent category you select in the cookie banner.
We do not process your personal data for any purpose other than those listed above. If we intend to use your personal data for a new purpose, we will update this notice and obtain your consent for that new purpose before processing begins, in line with DPDP Section 6.
Lawful basis for processing under DPDP
DPDP does not have a "legitimate interest" catch-all basis. We process your personal data only on the following bases:
- Consent — for processing that requires your consent under DPDP Section 6, including the specific purposes listed above. You may withdraw consent at any time, as described below.
- Section 7 — certain legitimate uses — for processing that falls within DPDP Section 7, including use for compliance with a legal obligation (for example, retaining tax records under GST law) and use for security and fraud prevention. We rely on Section 7(a) for IP address and user agent processing for security, as noted above.
We do not rely on "legitimate interest" as a basis under DPDP. The GDPR section below describes the bases used for any EU/EEA visitors, where "legitimate interest" may apply for specific GDPR-only processing.
Consent and one-click withdrawal
Where we process your personal data on the basis of consent, you may withdraw that consent at any time. Withdrawal is one click and is as easy as giving consent.
- Cookie consent — withdraw or change your cookie choices at any time using the "Manage Cookies" link in the cookie banner or in the site footer.
- Marketing emails — unsubscribe using the link in any marketing email, or in your account settings.
- Social media connections — disconnect any platform from your account settings; we delete the related tokens and platform data within 48 hours.
- Account-level consent — review and withdraw any account-level consent in your account settings at app.poststack.ai/settings/privacy, or by emailing [email protected].
Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal. Where consent is withdrawn, we stop the related processing and erase the relevant personal data in line with the retention schedule below, unless a legal obligation requires us to retain it.
Burden of proof (DPDP Section 6(10)). We maintain a record of every consent event — when it was given, the notice version shown to you, the purposes consented to, your IP address, your user agent, and the language of the notice. We also record every withdrawal. These records are kept in an append-only log that cannot be edited or deleted, so we can demonstrate that valid consent was obtained for each processing activity.
Your rights as a Data Principal (DPDP Sections 11–14)
Under DPDP, you have the following rights. You can exercise any of them at no cost.
- Right to access (Section 11) — request a summary of the personal data we process about you and the processing activities it is used for.
- Right to correction and erasure (Section 12) — request correction of inaccurate or misleading personal data, request completion of incomplete personal data, and request erasure of your personal data (subject to legal retention exceptions such as tax records under GST law).
- Right to grievance redressal (Section 13) — file a grievance with our Grievance Officer and receive a response within the time described in the "Grievance Officer" section below.
- Right to nominate (Section 14) — nominate another individual to exercise your rights in the event of your death or incapacity. You may set or update a nominee in your account settings.
How to exercise your rights
- Self-service — most rights can be exercised directly in your account at app.poststack.ai/settings/privacy: access your data, correct your profile, request erasure, and download a data export.
- Email — write to [email protected] with the subject "DPDP Rights Request" and the right you wish to exercise. Include the email address associated with your account.
- Identity verification — we verify your identity before acting on a request, to protect your data from unauthorised access. We may ask you to confirm details from your account.
- Response time — we acknowledge requests promptly and respond fully within the timeframes described in the "Grievance Officer" section.
Right to complain to the Data Protection Board of India
If you are not satisfied with our response, or if you believe we have processed your personal data in violation of DPDP, you have the right to file a complaint with the Data Protection Board of India.
Board notifications and updates. The Data Protection Board of India does not yet operate its own dedicated complaints portal. Until it does, notifications and procedural updates are published by the Ministry of Electronics and Information Technology at meity.gov.in. We will add a direct link to the Board's own portal here as soon as it is operational.
Appeal to TDSAT (DPDP Section 29)
If you are aggrieved by an order of the Data Protection Board of India, you may prefer an appeal to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) within 60 days of the Board's order.
Grievance Officer
Under DPDP Rule 9, we have designated a Grievance Officer to handle complaints and rights requests from Data Principals.
Email: [email protected]
Response time: We acknowledge your complaint within 24 hours and respond fully within 90 days, in line with DPDP Rule 14(3).
Website: https://poststack.ai
Please include "DPDP Grievance" in the subject line and the email address associated with your account. If your request concerns a specific data field or processing activity, please describe it so we can route your request correctly.
Children's data (DPDP Section 9)
The Service is intended for business and professional use by individuals aged 18 and above. We do not knowingly collect personal data from anyone under 18.
Age verification at signup. We collect your date of birth at signup and block registration if the date indicates you are under 18. We do not process personal data of children.
Verifiable parental consent. We do not operate a verifiable parental consent mechanism because the Service is not directed at minors. If we become aware that we have collected personal data from a minor, we will delete that data promptly. If you believe we have collected personal data from someone under 18, contact us at [email protected].
Cross-border transfers (DPDP Section 16)
DPDP Section 16 uses a negative-list model: personal data may be transferred outside India unless the Central Government has notified the destination country or territory as restricted. As of the date of this notice, no country has been placed on the restricted list. We monitor MeitY notifications and will update this notice if any destination becomes restricted.
Where your personal data goes
Most of your personal data stays in India. The table below lists every cross-border flow.
- Account, profile, workspace, payment, and analytics data — stored on our production infrastructure at Hostinger Mumbai (VPS1 for applications, VPS2 for PostgreSQL and ClickHouse). No cross-border transfer.
- Database backups — stored on AWS in the ap-south-1 (Mumbai) region. No cross-border transfer.
- Payment data — processed by Razorpay, with payment data held in India under the RBI data localisation mandate. No cross-border transfer.
- Transactional and marketing emails — sent via Resend, which is based in the United States. Your email address and the content of the email are transferred to Resend in the US for the purpose of delivering that email. Legal basis: your consent at signup and the contractual necessity of operating the Service. We will update this notice if Resend is added to the restricted list.
- Media files (images, videos) — stored on Cloudflare R2, which may replicate objects across global edge locations for performance. Your media is accessible from Cloudflare edge nodes worldwide. Legal basis: your consent when you upload media for scheduling.
- Social media posts — when you publish to a connected platform (Meta, LinkedIn, X, or YouTube), your post content and the platform metadata needed to publish are transferred to that platform. Meta and X are US-based; LinkedIn and YouTube have their own processing locations described in their privacy policies. Legal basis: your consent via OAuth when you connect the platform. We cannot obtain Data Processing Agreements with these platforms; we rely on your OAuth authorisation and the platform's own terms.
We do not transfer your personal data to any other destination. If we add a new cross-border flow, we will update this notice and, where consent is required, obtain your consent before processing begins.
Data retention
We retain your personal data only for as long as necessary for the purposes listed in this notice, and in line with DPDP Section 8(7) and Rule 8. The schedule below applies to both live data and backups; backups are purged on the same schedule as live data, with the propagation windows noted.
- Account and profile data — retained for the lifetime of your account; erased on your request or on account deletion. Backups: 35-day rolling snapshots plus monthly manual snapshots kept for 12 months. Full purge of deleted account data from backups within 13 months via snapshot expiry.
- Social tokens (encrypted at rest) — retained until you disconnect the integration; purged with your account on deletion.
- Your social analytics (engagement metrics and demographics shown in your dashboard) — retained for the lifetime of your account; they are part of the Service you pay for. Erased with your account; backups purged on the account-data schedule above.
- Internal platform usage events — retained for 13 months, after which only aggregate, pseudonymised data is kept. Backups: 35-day rolling snapshots.
- Application and access logs — retained for 12 months, the minimum required under DPDP Rule 6(1)(e). Security logs are exempt from erasure during this mandated retention period.
- Consent records (ConsentEvent table) — retained for your account lifetime plus 3 years, to meet the burden of proof under DPDP Section 6(10). After account deletion, the user ID in these records is hashed so the record no longer identifies you; the record itself is not deleted.
- Billing and tax records — retained for 7 years as required under GST law. This is a statutory carve-out from erasure; we will not delete these records before the statutory period expires, even on erasure request.
- Media files — retained for 30 days after you delete them, to allow recovery; then permanently removed.
When you request erasure, we pseudonymise your data within 24 hours and schedule a hard delete. Backups containing your data are purged within the propagation windows above. Where a legal obligation requires longer retention (for example, GST records), we retain only the minimum data necessary to meet that obligation and erase everything else.
Security safeguards (DPDP Section 8(5), Rule 6)
We implement the following safeguards to protect your personal data:
- Encryption in transit — TLS 1.2+ for all data transmission between your browser, our applications, and our infrastructure.
- Encryption at rest — database encryption and secure file storage on Hostinger Mumbai infrastructure and AWS ap-south-1.
- Social token encryption — OAuth access and refresh tokens are encrypted at the application layer using AES-256-GCM before being written to the database. Tokens are never logged.
- Access control — role-based access control and multi-factor authentication for all administrative accounts.
- Logging and monitoring — security event logging with a minimum 12-month retention, in line with DPDP Rule 6(1)(e).
- Backups — automated RDS snapshots and S3 backups in AWS ap-south-1, with the retention schedule above.
- PII redaction in logs — application logs do not emit personal data; logger configuration redacts known PII fields.
Your duties as a Data Principal (DPDP Section 15)
DPDP Section 15 places certain duties on you as a Data Principal. You agree to:
- not register yourself with a false identity or impersonate another person;
- not suppress, where suppression would mislead us, any material information about yourself when providing personal data for processing;
- not provide false information to us;
- not impersonate another person or entity when using the Service.
These duties are also reflected in our Terms of Service.
GDPR section (for EU/EEA visitors)
If you are a resident of the EU/EEA, the GDPR applies to your use of the Service in addition to DPDP. This section applies only to the extent GDPR is relevant to you.
Legal bases under GDPR
- Consent — for cookies, marketing emails, and any processing where you have given explicit consent.
- Contract — to provide the Service you have signed up for, including account creation, scheduling, and publishing.
- Legal obligation — to comply with applicable laws, including tax record retention.
- Legitimate interest — for security, fraud prevention, and error diagnosis, where our interest is balanced against your rights and freedoms. This basis is used only within the GDPR section and is not used as a basis under DPDP.
Your GDPR rights
- Right of access, rectification, erasure, restriction, and portability.
- Right to object to processing based on legitimate interest.
- Right to withdraw consent at any time, without affecting lawfulness of processing carried out before withdrawal.
To exercise GDPR rights, write to [email protected]. We respond within 30 days, extendable by a further two months where the request is complex.
You also have the right to lodge a complaint with your local data protection authority. The lead supervisory authority for Poststack is the Irish Data Protection Commission where relevant; otherwise your local authority.
CCPA section (for California residents)
If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) apply to your use of the Service in addition to DPDP.
Categories of personal information we collect
- Identifiers (name, email, IP address).
- Commercial information (subscription tier, payment status).
- Internet activity (usage data on our site).
- Professional information (workspace details, agency listing information).
- Social media data (with your consent, for scheduling services).
Your CCPA rights
- Right to know what personal information we collect, use, disclose, and sell.
- Right to delete your personal information.
- Right to correct inaccurate personal information.
- Right to opt out of the sale or sharing of your personal information.
- Right to limit use of sensitive personal information.
- Right not to be discriminated against for exercising your privacy rights.
We do not sell your personal information and we do not share personal information for cross-context behavioural advertising.
To exercise CCPA rights, write to [email protected] with "California Privacy Rights" in the subject line.
मुख्य अनुभाग / Key sections (Hindi)
DRAFT — pending legal/certified translation review. The Hindi text below is a working draft for lawyer review. It is not a certified translation. In case of any inconsistency, the English version above governs.
व्यक्तिगत डेटा श्रेणियाँ (Data categories)
- खाता और प्रोफ़ाइल डेटा: ईमेल, पासवर्ड (हैश किया हुआ), नाम, जन्म तिथि (केवल आयु सत्यापन हेतु), बायो, अवतार।
- संपर्क डेटा: ईमेल, फ़ोन नंबर (केवल यदि आप प्रदान करते हैं)।
- डिवाइस और नेटवर्क डेटा: IP पता, उपयोगकर्ता एजेंट।
- सोशल मीडिया प्लेटफ़ॉर्म डेटा: OAuth टोकन, प्लेटफ़ॉर्म प्रोफ़ाइल आईडी, शेड्यूल किया गया कंटेंट, प्रकाशन इतिहास, एन्गेजमेंट मेट्रिक्स।
- वर्कस्पेस डेटा: संगठन का नाम, सदस्य, भूमिकाएँ।
- भुगतान डेटा: ग्राहक आईडी, सदस्यता आईडी, प्लान, स्थिति (कार्ड विवरण Razorpay द्वारा संभाले जाते हैं)।
- B2B निर्देशिका डेटा: एजेंसी का नाम, वेबसाइट, सार्वजनिक सोशल हैंडल (सार्वजनिक डेटा); दावा किए गए लिस्टिंग के लिए एजेंसी स्वामी का ईमेल/फ़ोन।
- एनालिटिक्स डेटा: एन्गेजमेंट मेट्रिक्स, फ़ीचर उपयोग, फेच इतिहास।
- कुकीज़ और समान तकनीकें: कुकी आईडी और लोकल स्टोरेज एंट्री (कुकी बैनर सहमति के अधीन)।
प्रयोजन (Purposes)
- खाता बनाना और पहचानना; लॉगइन प्रमाणीकरण; खाता-संबंधित लेन-देन ईमेल भेजना।
- आयु सत्यापन (केवल यह पुष्टि करने के लिए कि आप 18 वर्ष या अधिक हैं)।
- आपके द्वारा शेड्यूल किए गए समय पर आपके कनेक्टेड सोशल प्लेटफ़ॉर्म पर पोस्ट प्रकाशित करना।
- प्रकाशित कंटेंट के लिए एनालिटिक्स दिखाना; पब्लिशिंग वर्कफ़्लो बेहतर बनाने हेतु फ़ीचर उपयोग का विश्लेषण करना।
- वर्कस्पेस एक्सेस और भूमिकाएँ प्रबंधित करना।
- सदस्यता और बिलिंग प्रबंधित करना (Razorpay के माध्यम से भुगतान)।
- सुरक्षा, धोखाधड़ी की रोकथाम, और DPDP नियम 6(1)(e) के तहत आवश्यक लॉग बनाए रखना।
- एजेंसी निर्देशिका में सार्वजनिक रूप से उपलब्ध एजेंसी जानकारी प्रदर्शित करना (DPDP धारा 3(b) के निबंधन के तहत सहमति की आवश्यकता नहीं)।
आपके अधिकार (DPDP धारा 11–14)
- पहुँच का अधिकार (धारा 11): अपने व्यक्तिगत डेटा का सारांश अनुरोध करें।
- सुधार और विलोपन का अधिकार (धारा 12): गलत डेटा सुधारने और डेटा विलोपन का अनुरोध करें (कर रिकॉर्ड जैसी कानूनी अपवादों के अधीन)।
- शिकायत निवारण का अधिकार (धारा 13): हमारे शिकायत अधिकारी से संपर्क करें।
- नामांकन का अधिकार (धारा 14): मृत्यु या अक्षमता की स्थिति में अपने अधिकारों का उपयोग करने हेतु किसी अन्य व्यक्ति को नामित करें।
शिकायत अधिकारी (Grievance / DPO contact)
ईमेल: [email protected]
प्रतिक्रिया समय: हम आपकी शिकायत 24 घंटे के भीतर स्वीकार करते हैं और DPDP नियम 14(3) के अनुसार 90 दिनों के भीतर पूर्ण उत्तर देते हैं।
यदि आप हमारी प्रतिक्रिया से संतुष्ट नहीं हैं, तो आप डेटा प्रोटेक्शन बोर्ड ऑफ इंडिया में शिकायत दर्ज कर सकते हैं। बोर्ड का अपना शिकायत पोर्टल अभी परिचालन में नहीं है; अद्तन जानकारी के लिए meity.gov.in देखें।
Changes to this privacy notice
We may update this notice from time to time. When we do, we will:
- update the "Last updated" date at the top of this page;
- notify you of material changes via email or a website notice; and
- where a change introduces a new purpose or new processing that requires consent, obtain your consent before processing begins.
Contact
For any question about this notice or our data practices, contact our Grievance Officer:
Grievance Officer: [email protected]
General inquiries: [email protected]
Website: https://poststack.ai
We acknowledge inquiries within 24 hours and respond fully within 90 days, in line with DPDP Rule 14(3).