POSTRIVET / LEGAL
Privacy Policy
Effective October 5, 2026 · Last updated October 5, 2026
This policy explains how PostRivet handles personal information when you visit our website, create an account, connect a social platform, or use our scheduling tools and API. It covers PostRivet’s processing, not the independent practices of connected platforms.
1. Who is responsible for your information
The operator identified here is responsible for the personal information handled by PostRivet as described in this policy. Where data protection law uses the term, that operator is the controller for account administration, security, and operation of the Service.
Luke Patterson, operator of PostRivet Texas, United States privacy@postrivet.comIf you use PostRivet on behalf of an organization, that organization may separately be responsible for personal information it includes in scheduled content. It must have authority to use and disclose that information. Contact the organization as well as us if your request concerns its content.
2. Information we collect
- Account information: your email address, internal account identifiers, a password hash, and account security and authorization records. We do not store your PostRivet password as readable text.
- Connected account information: the platform you connect, your handle and platform identifier, connection status, permissions, and authorization credentials such as access and refresh tokens. Authorization is completed with the platform; do not send us your platform password.
- Content and schedules: text, uploaded images or videos where supported, media descriptions and metadata, destination accounts, time and time-zone choices, and changes or cancellation instructions.
- Publishing records: delivery status, attempts and timestamps, platform post identifiers, error codes and diagnostic details, and records needed to prevent duplicate operations or investigate uncertain results.
- Technical and security information: request timing, response status, correlation and resource identifiers, security events, and administrative audit records. Hosting infrastructure may also process IP addresses, browser information, and request metadata.
- Communications: information you provide when contacting us, reporting a problem, or making a privacy request.
We receive information directly from you, from your browser or API client, and from connected platforms when you authorize access. Public platform identifiers may also be resolved to establish a connection. Information required to create an account, authorize a connection, or process a schedule is necessary for those features; if you do not provide it, those features cannot operate.
3. Why we use information
We use information to create and secure accounts; connect authorized platforms; store and deliver scheduled content; check publication outcomes; display history and errors; provide support; diagnose failures; prevent misuse; enforce our terms; and comply with legal obligations. Access by administrators is limited to operational purposes such as support, security, and maintenance.
Where applicable law requires a legal basis, we rely on:
- Performance of our agreement: providing accounts, connections, scheduling, publishing, and related support you request.
- Legitimate interests: securing and maintaining the Service, preventing abuse, diagnosing reliability problems, and handling disputes, balanced against your rights and expectations.
- Legal obligations: responding to valid legal requirements and retaining records when legally required.
- Consent: where required for a particular optional purpose. You may withdraw that consent, without affecting processing already lawfully completed.
Approving a platform connection gives PostRivet permission to act within the platform’s authorization scope; it does not give us unrestricted permission to use your information. We do not use scheduled content to train generative AI models, and the current Service does not use advertising trackers or sell personal information.
6. How long we keep information
Account details, schedules, content, connected-account records, and publishing history are retained while needed to provide the Service, maintain your history, resolve publishing results, and support account administration. The current Service does not automatically erase all content after publication or cancellation. Cancelling a post changes its publishing state; it is not a request to erase its stored record.
Disconnecting an account through PostRivet removes its stored publishing credentials from the active database. Revoking access at the platform stops authorized access there but does not automatically erase PostRivet’s account or publishing history. Deleting eligible uploaded media removes its file data from active storage; metadata and audit records may remain, and media needed by an unresolved publication cannot be deleted until that operation is cancelled or resolved.
Operational logs are rotated using configured age and storage limits; database history and audit records have separate retention needs. To request account closure or deletion beyond the available controls, contact us. We will assess what can be deleted and what must be retained for legal obligations, security, fraud prevention, or unresolved disputes. We do not currently offer a self-service account-deletion button.
Deletion from active systems may not immediately remove copies in backups or recovery systems. Such copies remain subject to access restrictions and applicable backup-retention cycles. Public copies and information independently held by platforms are governed by their own practices. Retention decisions consider the type and sensitivity of information, the purpose for keeping it, applicable obligations, and whether deletion would prevent resolution of an outstanding operation or claim.
7. Security and international processing
We use measures including encrypted connections, password hashing, encryption of stored platform credentials, account authorization checks, and safeguards against unauthorized requests. No storage or transmission system can be guaranteed completely secure. Protect your sign-in credentials and notify us if you suspect a compromise.
The Service uses Microsoft Azure infrastructure in the United States. Connected platforms and service providers may process information in other countries, whose privacy laws may differ from those where you live. Where applicable law requires safeguards for a cross-border transfer, we will use the safeguards that law requires. Contact us for information about transfers relevant to your data. Using the Service does not waive any protections or transfer requirements that apply to you.
8. Your choices and privacy rights
You can review your schedules and delivery results, use available cancellation and media controls, and revoke a connection through the relevant platform. These actions have the limits described above. Contact us to request access to, correction of, a copy of, or deletion of your personal information, or to close your account.
Depending on your location and the law that applies, you may also have rights to restrict or object to processing, receive portable information, withdraw consent, or appeal a decision on your request. Where processing relies on legitimate interests, you may object based on your circumstances. You may complain to your relevant privacy regulator and need not contact us first. We will not unlawfully discriminate against you for exercising your rights.
Send your request from your account email when possible and explain the action requested. We may need proportionate information to verify your identity or an authorized representative’s authority. Do not include passwords, access tokens, or unnecessary identity documents. We will respond within the period required by applicable law and explain relevant exceptions, identity-verification needs, or lawful extensions. Rights are not absolute: we may need to retain information for legal or security reasons or protect other people’s rights.
PostRivet does not use personal information for automated decisions producing legal or similarly significant effects. Automated scheduling, validation, and security controls are used to operate and protect the Service.
9. Children’s information
PostRivet is intended for people legally able to enter the agreement described in our Terms of Service and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided information contrary to these requirements, contact us so we can investigate and take appropriate action, including deletion where required. Connected platforms may impose additional age restrictions.
10. Changes and contact
We will update this policy as our practices change and revise the date above. For material changes, we will provide notice through the Service or your account email and seek consent where required. A revised notice will not, by itself, authorize an incompatible new use of previously collected information.
For privacy questions, data requests, or security concerns, contact:
Luke Patterson, operator of PostRivet Texas, United States privacy@postrivet.com