1. Information We Collect
We collect information you provide directly to us, such as when you create an account, as well as data related to your use of our services (e.g., keywords tracked, project settings).
2. How We Use Your Information
We use your information to provide, maintain, and improve our services, communicate with you, and process payments.
3. Data Security
We implement reasonable security measures to protect your personal information. However, no method of transmission over the internet is 100% secure.
4. Third-Party Services
We use third-party services like Stripe for payments and Resend for emails. These services have their own privacy policies.
5. Cookies
We use cookies to enhance your experience and remember your login session. You can manage cookie preferences in your browser settings.
6. Your Rights (GDPR / UK GDPR / CCPA)
If you are in the EEA, UK, or California, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — request correction of inaccurate data.
- Erasure ("right to be forgotten") — request deletion of your account and data.
- Portability — request an export of your data in a common format.
- Restriction & Objection — ask us to stop processing your data for specific purposes.
- Withdraw consent — at any time, where processing is based on consent.
- Lodge a complaint — with your local data protection authority.
To exercise any of these rights, email privacy@postbing.com. We will respond within 30 days.
7. Legal Basis for Processing
We process your personal data on the following lawful bases under GDPR Article 6:
- Contract — to deliver the services you signed up for.
- Legitimate interest — to secure, debug, and improve our product.
- Legal obligation — to meet tax, accounting, and regulatory requirements.
- Consent — for optional marketing emails and non-essential cookies.
8. Data Retention
We retain personal data only as long as it is needed for the purposes described above:
- Account data: for the life of your account, and up to 90 days after account closure.
- Billing records: up to 7 years (tax & accounting obligations).
- Server logs: up to 30 days.
- Email delivery logs: up to 90 days.
- Backups: rolling 35-day retention window.
9. International Data Transfers
Postbing is operated from the United States. When you use our services from outside the US, your data is transferred to and processed in the US. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission to safeguard cross-border transfers, and contract with sub-processors (e.g. Vercel, Stripe, Resend, OpenAI, Google) who provide equivalent protections.
10. Sub-Processors
We share personal data only with the service providers we need to run Postbing. Current sub-processors include:
- Vercel — hosting & edge delivery (US).
- Stripe — payment processing (US).
- Resend — transactional email (US).
- OpenAI / Google / Anthropic / Perplexity — AI checks (US).
- Serper — search result data (EU/US).
- Google Search Console — search analytics (if connected) (US).
11. Data Controller & Contact
The data controller is Postbing. Privacy questions: privacy@postbing.com. General support: support@postbing.com.
12. Changes to this Policy
We will post material changes here and, where legally required, notify you by email. Your continued use of the service after the effective date of the update constitutes acceptance of the new policy.