PostStage Legal

Privacy Policy

Effective date: 23 September 2026

1. Who we are

PostStage (“PostStage”, “we”, “us”, “our”) is a social media scheduling and publishing application available at trypoststage.com. We are based in India and our service is available to customers worldwide, without geographic restriction.

This Privacy Policy explains what personal data we collect, how we use it — including data we receive through the official APIs of Meta (Facebook, Instagram, Threads), Google (YouTube, Google Business Profile), X (formerly Twitter), TikTok, Pinterest, LinkedIn, Bluesky, Tumblr, Mastodon, Telegram, Discord, WordPress (both WordPress.com and WordPress sites you host yourself), and Dev.to, and of Canva, which we use only as a source of artwork you import — and the choices and rights you have. It applies to every visitor, registered user, and connected social account on PostStage.

If you have questions about this policy or wish to exercise any of the rights described below, contact our Privacy / Grievance Officer at info@trypoststage.com.

2. Information we collect

2.1 Information you provide directly

  • Account details: name, email address, password (stored as a salted hash, never in plain text), and profile image.
  • Optional profile fields: Instagram handle entered at signup (kept for reference/display only — it is not used for API authentication), and your preferred timezone.
  • Content you create or upload: post captions, hashtags, hashtag groups, templates, drafts, and media files (images/videos) you schedule or publish through PostStage.
  • Billing details you enter at checkout, processed directly by our payment processor (see Section 5).
  • Communications you send us — support tickets (including replies you send by email), feedback, live-chat messages, demo bookings, and enquiry-form submissions.
  • Text you give the AI Caption Generator or caption-fitting tools — your brief, draft caption, tone and target platform (see Section 3.2).
  • Team details: the name and email address of anyone you invite to your workspace, their role, and the approvals, comments and changes they make.

2.2 Information collected automatically

  • Login/session metadata: IP address and user-agent captured at signup for anti-abuse review, and session/authentication cookies needed to keep you signed in.
  • Usage data: pages viewed, features used, posting activity, and error/diagnostic logs, used to operate and improve the service.
  • Google reCAPTCHA signals on certain forms, used purely for bot/abuse prevention.
  • Browser push subscription details, only if you turn on push notifications, so we can deliver them through your browser's push service.
  • Approximate country, derived from your IP address by our hosting provider, used only to decide which cookie-consent rules apply to you. We do not store precise location.
  • Advertising measurement — only with your consent (or, outside the EEA, UK and Switzerland, unless you opt out; see Section 7). We use Google Tag Manager, the Meta Pixel, the Meta Conversions API and the Google Ads tag to measure whether our own ads lead to signups. These may record the ad-click identifier you arrived with, pages you visit on our website, and your browser and device type. When you create an account, we send Meta a CompleteRegistration event containing your email address (irreversibly hashed with SHA-256 before it leaves our servers — never sent in plain text), your IP address and your browser's user-agent string. No content you create, and no data from your connected social accounts, is ever shared for advertising.

2.3 Information from connected social media accounts

When you connect a social account, PostStage uses that platform's official OAuth flow. You are shown the platform's own consent screen and you control exactly what is authorized. We request only the permissions (“scopes”) needed to schedule, publish, and report on your content — nothing more. Per platform:

PlatformScopes requestedWhat we use it for
Facebook Pages (Meta)pages_show_list, pages_manage_posts, pages_read_engagement, pages_manage_engagement, business_management, public_profileList Pages you administer (directly or via a Business Portfolio), publish posts/photos to a Page you select, and read basic engagement metrics on your own posts.
Instagram (Meta)instagram_business_basic, instagram_business_content_publish, instagram_business_manage_commentsIdentify your connected Instagram Business/Creator account, publish posts/Reels/carousels you schedule, and manage the auto first-comment feature (if you enable it).
Threads (Meta)threads_basic, threads_content_publishIdentify your Threads profile and publish posts you schedule.
X (Twitter)tweet.read, users.read, tweet.write, offline.accessIdentify your X profile, publish posts you schedule, and refresh your access token in the background (offline.access) so you don't have to reconnect every two hours.
YouTube (Google)youtube.upload, youtube.readonlyUpload videos/Shorts you schedule to your channel and read basic channel/video information needed to confirm a successful upload.
Google Business Profilebusiness.manageList the business locations you manage and publish Business Profile posts/updates you schedule to a location you select.
Pinterestboards:read, boards:write, pins:read, pins:write, user_accounts:readList your boards, create/schedule Pins to a board you select, and read your basic Pinterest account info.
LinkedInopenid, profile, w_member_socialIdentify your LinkedIn profile and publish posts you schedule as you.
TikTokuser.info.basic, video.publish, video.uploadIdentify your TikTok creator profile (display name and avatar) and publish videos you schedule to your TikTok account.
Tumblrbasic, write, offline_accessIdentify your Tumblr blog and publish text, photo, and video posts you schedule to your blog. offline_access lets us refresh your token in the background so you don't need to reconnect periodically.
Mastodonread, writeIdentify your Mastodon account on your chosen instance and publish posts you schedule. Because Mastodon is federated, the OAuth app is registered on your specific instance at the time you connect.
WordPress.comglobalList the blogs on your WordPress.com account and publish the posts you schedule — title, body, featured image, categories and tags — to the blog you choose.global is the only scope WordPress.com's REST API accepts for publishing: its narrower posts scope is refused with “Required scope: global”, so asking for less is not something the API permits. WordPress.com is operated by Automattic Inc.
WordPress (self-hosted)Application Password — no OAuth scopesPublish the posts you schedule to your own WordPress site, and read the site's existing categories and tags so you can pick them in the composer. Unlike every other row in this table, no third-party company is involved — see the callout below.
Canvaprofile:read, design:meta:read, design:content:read, design:content:write, folder:readCanva is a content source, not a posting destination — PostStage never publishes anything to Canva. These permissions let us show your account name, list your designs so you can pick one, export a design you choose, and create a new blank design at the right size when you use “Design in Canva”. folder:read lets us list the contents of folders you can already see, because designs owned by a Canva Team don't appear in your personal design list otherwise. We read a design only when you explicitly import it; we never scan or copy your Canva library in the background, and we never create, move or delete anything in your folders.
Google Drivedrive.file, openid, email, profileGoogle Drive is a content source, not a posting destination — PostStage never uploads to, changes or deletes anything in your Drive. drive.file is the narrowest Drive permission Google offers: it grants access only to the individual files you pick in Google's own file chooser. We cannot list, search or read the rest of your Drive, and we deliberately did not request the permission that would allow it. When you pick a file we copy it once into PostStage's own storage so it can be attached to a post; nothing is read in the background. The identity permissions are used only to show which Google account is connected.

For each connected account we store: the platform's account/page/channel/board ID, username or display name, profile picture URL, account type, and the OAuth access token (and refresh token, where the platform issues one). Tokens are encrypted at rest and are used solely to publish the content you schedule and to display basic account status inside your PostStage dashboard. We do not read your DMs, private messages, contacts, or any content other platforms also let people see publicly unless that data is required to perform the publishing action you requested.

Telegram works differently — no OAuth consent screen is involved. You create a Telegram Bot via @BotFather and enter the resulting Bot Token and your Channel username or ID directly into PostStage. We use the token to verify access to the channel and then store it encrypted the same way as every other platform's token. Because you own the bot, you can delete it or revoke its access to a channel at any time directly in Telegram, independently of disconnecting it in PostStage. We store your channel ID, channel title/username, and the bot token — nothing more.
Discord works differently — no OAuth consent screen is involved. You create a webhook for a channel in your own Discord server (Server Settings → Integrations → Webhooks) and paste the resulting Webhook URL directly into PostStage. We use it to verify the webhook and then store it encrypted the same way as every other platform's token. Because you own the webhook, you can delete it or regenerate its URL at any time directly in Discord, independently of disconnecting it in PostStage. We store the webhook's ID, its configured name, and the webhook URL itself — nothing more. Posting via a webhook does not give PostStage access to your server's messages, member list, or any other channel.
Bluesky works differently — no OAuth consent screen is involved. You generate a revocable “App Password” yourself in your Bluesky account settings and enter it, together with your handle, directly into PostStage. We use it once to obtain a session (an access token and refresh token issued by Bluesky), which we store encrypted the same way as every other platform's token. Because you create and control this credential, you can revoke it at any time directly on Bluesky — at bsky.app/settings/app-passwords — independently of disconnecting it in PostStage. We store your handle, DID (Bluesky's permanent account identifier), the session tokens, and the post content/images you schedule — nothing more.
A self-hosted WordPress site works differently — the destination is your own server. Every other platform on this page is a company we transmit your content to. A WordPress site you host is not: you give us its address, and we send your post to that server. No third party receives it, and Automattic — which operates WordPress.com — is not involved at all. So for this one destination there is no third-party privacy policy sitting behind ours; there is only yours.
How a self-hosted WordPress site is authenticated. You generate an Application Password in your own wp-admin (Users → Profile) and enter it, with your WordPress username and site address, directly into PostStage. There is no OAuth consent screen. Because you created the credential, you can revoke it in wp-admin at any time, independently of disconnecting the site in PostStage. An Application Password cannot be exchanged for a short-lived token — it is replayed on every publish — so we additionally encrypt it with AES-256-GCM at the application layer, on top of the encryption our database provider applies at rest. We store the site address, your WordPress user ID and username, the site title, and that credential — nothing more. We connect only to publicly resolvable site addresses, and we read nothing from your site beyond the categories and tags needed to fill in the composer.
Dev.to uses an API key you create. You generate a key in your Dev.to account settings (Extensions → DEV Community API Keys) and paste it into PostStage; there is no OAuth consent screen. We encrypt the key at the application layer, use it only to publish the articles you schedule (to your own profile or an organisation you choose), and store your Dev.to username, profile details and that key — nothing more. You can revoke the key on Dev.to at any time, independently of disconnecting it here.

2.4 Payment information

Subscription payments are processed by Razorpay, a PCI-DSS compliant payment gateway. PostStage does not collect or store your full card number, CVV, or UPI PIN — Razorpay handles that directly. We retain only the transaction reference, plan, billing cycle, amount, and GST details needed for invoicing and accounting under Indian tax law.

2.5 Information about other people

Using PostStage you may handle personal data about other people — comments, mentions and direct messages from your audience shown in the Inbox, team members you invite, or people who appear in your content. For that data you (or the business you work for) are the controller and PostStage processes it on your instructions, only to provide the Service. You are responsible for having a lawful basis to handle it and for telling those people about it where the law requires. Business customers who need a Data Processing Addendum can request one at info@trypoststage.com.

3. How we use your information

  • To provide the core service: scheduling, queuing, and publishing your content to the platforms you connect, at the time you choose.
  • To authenticate you, maintain your session, and protect your account (fraud/abuse detection, signup review).
  • To process payments, issue receipts, and manage your subscription.
  • To send transactional emails and in-app notifications you've opted into (post failures, channel/connection updates, post confirmations, billing) — each is individually toggleable in Settings.
  • To provide customer support and respond to enquiries.
  • To maintain, debug, and improve PostStage's reliability and features.
  • To generate AI caption suggestions when you ask for them (Section 3.2).
  • To measure our own advertising campaigns, where you have allowed advertising cookies (Section 7).
  • To comply with legal obligations, including tax, accounting, and law-enforcement requests.
  • To establish, exercise or defend legal claims and enforce our Terms.

We do not sell your personal data for money. We do not show ads inside PostStage, and we never use your content or your connected-account data for advertising or to build advertising profiles.

3.1 Legal bases (EEA, UK and Switzerland)

  • Contract — running your account, publishing your posts, billing, AI features you request, and support.
  • Legitimate interests — security, fraud and abuse prevention, signup review, debugging, and improving the Service. You can object to this processing at any time.
  • Consent — advertising cookies and measurement, optional notifications, and the permissions you grant each connected platform. You can withdraw consent at any time without affecting processing that happened before.
  • Legal obligation — tax, accounting and invoicing records, and responding to lawful requests from authorities.

3.2 AI features

The AI Caption Generator and caption-fitting tools are powered by Anthropic (Claude models). When you use them, we send Anthropic only the text needed for that request: your brief or draft caption, the tone you chose and the target platform. We do not send your media, your password, your connected-account tokens, or data we receive from social platform APIs.

  • Your inputs and the captions generated are not used to train AI models, by us or by Anthropic. Anthropic processes them under its commercial terms and may keep them only for a limited period for trust-and-safety purposes.
  • AI features are optional. Nothing is sent to Anthropic unless you click a generate or fit action.
  • AI output can be wrong or inappropriate. Always review it before you publish.

4. Platform API data — Limited Use & policy compliance

Where PostStage accesses data through a third-party platform's API, our use of that data is limited to providing or improving the user-facing features you request (publishing, scheduling, and basic status/analytics for your own content), and is governed by that platform's developer policy in addition to this Privacy Policy:

  • Meta Platform Terms & Developer Policies (Facebook, Instagram, Threads)
  • Google API Services User Data Policy, including its Limited Use requirements (YouTube, Google Business Profile)
  • X Developer Agreement and Policy
  • TikTok Developer Terms of Service and Platform Guidelines
  • Pinterest Developer Terms
  • LinkedIn API Terms of Use
  • Tumblr API License Agreement
  • Mastodon API terms (as set by the specific instance you connect)
  • Telegram Bot API Terms of Service
  • Discord Developer Terms of Service and Developer Policy
  • WordPress.com REST API terms (Automattic). A WordPress site you host yourself has no third-party developer policy behind it — the software is open source and the server is yours.
  • Forem / DEV Community API terms (Dev.to)
  • Canva Developer Terms and Canva Connect API terms
In line with these policies: PostStage does not sell platform API data, does not use it for advertising, and does not allow employees or contractors to read it except where necessary for security, legal compliance, or with your explicit consent for support purposes (e.g., debugging a failed post at your request). Data is transferred to a third party only as described in Section 5, or with your direction. Platform API data is never sent to our advertising partners and is never used to train AI models, including general-purpose or foundation models.

4.1 YouTube API Services (Google)

PostStage uses YouTube API Services to provide its YouTube features (connecting your channel and uploading/scheduling videos). By using these features you also agree to the YouTube Terms of Service, and Google's handling of your information is described in the Google Privacy Policy.

What we store, and for how long. When you connect a YouTube channel we store, in our database: your channel ID, channel title, handle, and channel thumbnail URL, plus the OAuth access and refresh tokens Google issues (encrypted at rest). When you schedule a video we also store the title, description, privacy setting, and the video file until it is uploaded. Stored channel information is refreshed from the YouTube API at least every 24 hours (and in any event within 30 days) so it never goes stale, and is updated or removed if it can no longer be refreshed.

Deleting your stored YouTube data. You can delete the data PostStage has stored from the YouTube API at any time, in any of these ways:

  • Disconnect the channel from the Accounts page — this immediately deletes the stored access/refresh tokens and clears the cached channel data, and we also ask Google to revoke the grant on their side.
  • Delete your PostStage account (see our Data Deletion Instructions) — all connected-account data, including YouTube data, is deleted with it.
  • Email info@trypoststage.com and we will delete it for you.

Revoking access on Google's side. Independently of PostStage, you can revoke PostStage's access to your YouTube/Google data at any time from the Google security settings page at myaccount.google.com/connections. Once revoked, our stored tokens stop working, and the cached channel data is removed when the next refresh fails.

4.2 TikTok API Services

PostStage uses TikTok API Services to provide its TikTok features (connecting your creator account and publishing videos you schedule). By using these features you also agree to TikTok's Terms of Service and Privacy Policy. Our use of TikTok API data is limited to: identifying your TikTok creator profile and publishing the video content you explicitly schedule through PostStage. We do not access your TikTok messages, followers list, or any data beyond what is necessary to perform the publishing action you requested.

Revoking access. You can disconnect your TikTok account at any time from the Accounts page in PostStage, which immediately deletes the stored access token on our side. You can also revoke PostStage's access directly from your TikTok account settings under “Manage app permissions”.

5. Who we share information with

We use a small number of trusted service providers (“subprocessors”) to run PostStage. They process data only on our instructions and are not permitted to use it for their own purposes.

  • Vercel — application hosting and object/blob storage for uploaded media.
  • Neon / Vercel Postgres — primary database (account, post, and scheduling data).
  • Razorpay — payment processing (India).
  • Zoho ZeptoMail — transactional email delivery (account, billing, and post notifications).
  • Upstash (QStash) — background job scheduling that triggers your posts to publish at the exact time you set.
  • Google reCAPTCHA — bot/abuse protection on public forms.
  • tawk.to — live chat support. Receives the messages you send us in the chat window, and — when you are signed in — your name and email address, so we can identify your account and answer you properly.
  • Anthropic — AI caption generation, only for text you submit to the AI tools (Section 3.2).
  • Mailgun — receives email replies you send to support tickets so they can be attached to the ticket.
  • Browser push services (operated by your browser vendor, e.g. Google, Mozilla, Apple, Microsoft) — deliver push notifications, only if you turn them on.
  • The social platforms themselves — when you schedule a post, the content you authored is sent to that platform's API at publish time, exactly as if you had posted it yourself.
  • Your own WordPress server, for a self-hosted site you connect — your post is sent directly to the address you gave us. This is listed for completeness, not as a subprocessor: that server is operated by you, not by a provider we have engaged.

Advertising partners. Where advertising cookies are allowed (Section 7), Google (Tag Manager and Google Ads) and Meta (Pixel and Conversions API) receive the measurement data described in Section 2.2. They act as independent controllers under their own privacy policies, and may use it to measure and improve ad delivery. They receive nothing if you reject advertising cookies or your browser sends a Global Privacy Control signal.

We may also disclose information if required by law, to enforce our Terms of Service, to protect the rights/safety of PostStage or our users, or in connection with a merger, acquisition, or sale of assets (with notice to you).

6. Data storage, security & retention

  • All traffic to PostStage is encrypted in transit (HTTPS/TLS).
  • Social platform access and refresh tokens are encrypted at rest.
  • A WordPress Application Password is encrypted a second time, with AES-256-GCM at the application layer, because unlike an OAuth token the credential itself has to be stored and replayed on every publish.
  • Passwords are stored as salted hashes — we never store or have access to your plaintext password.
  • Access to production data is restricted to authorized PostStage personnel on a need-to-know basis.
  • When you disconnect a social account, its access tokens are deleted from our systems immediately; historical post records for that account are kept for your own reference unless you request their deletion.
  • We retain account data for as long as your account is active. If you delete your account (Section 8 and our Data Deletion page), we delete your personal data and connected-account tokens, except billing/invoice records, which Indian tax law requires us to retain for up to 8 years.
  • Backups are rotated and purged on a routine schedule; deleted data is removed from backups within a reasonable period as part of that cycle.

How long we keep each kind of data:

  • Account, content, team and connected-account data — while your account exists. Deleted within 30 days of a verified account-deletion request.
  • Support tickets, chat and feedback — while your account exists, so we can see the history of an issue. Deleted with your account.
  • Signup IP address and user-agent — while your account exists, for abuse prevention.
  • Billing and invoice records — up to 8 years, as required by Indian tax law, even after account deletion.
  • Your cookie-consent choice — about 6 months in your browser, after which we ask again.
  • Data needed for a legal claim or investigation — for as long as that claim or investigation lasts.

Media retention (images and videos)

  • Published media is kept for 3 months. The image and video files you upload are stored for 3 months after the post they belong to is published, then deleted automatically from our storage. This is a storage-cost measure and applies to all plans.
  • Your published posts are unaffected. Once a post is published, the destination platform (Instagram, Facebook, LinkedIn, X, and so on) holds its own copy of the media, and that copy governs what your audience sees. Deleting our copy does not remove, alter or unpublish anything on the platform.
  • Your post records are kept. Captions, hashtags, scheduling history, publish status, platform links and engagement metrics are retained for as long as your account is active. Only the stored media file is removed; where it was displayed in PostStage, we show a note saying it was removed under this policy.
  • Unpublished media is never removed on this schedule. Media attached to drafts, scheduled posts, posts awaiting approval, and posts that failed to publish is retained regardless of the age of the upload, because you may still need it to publish.
  • Uploads never attached to a post (for example, a file selected in the composer and then abandoned) may be deleted after 7 days, since they are not reachable in the app.
  • Direct-message attachments received in the engagement Inbox are re-hosted by us so the thread history remains readable, and are deleted on the same 3-month schedule. The message text and thread history are kept.
  • Keep your own originals. PostStage is a scheduling and publishing tool, not a media archive or backup service. If you need long-term access to your source files, retain your own copies.

No system is 100% secure. If we become aware of a data breach affecting your personal data, we will notify you and the relevant authorities as required by applicable law, including the Data Protection Board of India and CERT-In under Indian law.

7. Cookies

We use three kinds of cookies and similar technologies:

  • Strictly necessary — always on, because the site cannot work without them: your signed-in session, two-factor and OAuth-connection cookies (to verify the round-trip and prevent CSRF), a cookie that remembers your consent choice (ps_consent), and one that records which consent rules apply in your country (ps_region).
  • Functional — set only when you use the feature: Google reCAPTCHA on protected forms (bot prevention) and our live chat provider, tawk.to, which keeps your conversation attached to you. Each is governed by its provider's privacy policy.
  • Advertising and measurement — Google Tag Manager, the Google Ads tag (for example _gcl_au), the Meta Pixel (_fbp, _fbc), and our own first-party cookie that remembers which ad or campaign link first brought you to us (ps_attribution, up to 30 days). These measure our own ads only.

Your choice depends on where you are:

  • EEA, UK and Switzerland — advertising cookies stay off until you click “Accept all”.
  • Everywhere else, including India and the United States — advertising cookies are on unless you click “Reject non-essential”.
  • Global Privacy Control — if your browser sends this signal, we treat it as a rejection wherever you are.

You can change your mind at any time from Cookie Preferences (also in the footer of every marketing page). Rejecting removes the advertising cookies we can reach and reloads the page without those tags. You can also block or delete cookies in your browser settings, though blocking strictly necessary cookies will stop you signing in.

8. Your rights & choices

Regardless of where you live, you can at any time:

  • Access, correct, or update your account information from Settings.
  • Disconnect any connected social account from the Accounts page — this immediately revokes and deletes the stored token.
  • Export or request a copy of the personal data we hold about you.
  • Request deletion of your account and associated personal data — see our Data Deletion Instructions.
  • Opt in or out of individual notification types from Settings → Notifications.
  • Withdraw consent for a connected platform at any time by disconnecting it or revoking access directly on that platform's app-permissions page.
  • Turn advertising cookies off from Cookie Preferences.

We will not charge you, or treat you differently, for exercising any of these rights.

8.1 India — Digital Personal Data Protection Act, 2023

As an Indian entity, we process personal data consistent with the DPDP Act, 2023. You have the right to a summary of the personal data we process and who we share it with, to correct, complete, update and erase it, to withdraw consent at any time (as easily as you gave it), and to nominate another person to exercise your rights if you die or become incapacitated. Our Grievance Officer for DPDP Act purposes is reachable at info@trypoststage.com; we aim to acknowledge grievances within 7 days and resolve them within 30 days. If you are not satisfied with our response, you may complain to the Data Protection Board of India.

8.2 EEA, UK and Switzerland — GDPR

If you are in the EEA, UK or Switzerland, you have the right to access your personal data, to rectify it, to have it erased, to restrict its processing, to data portability, to object to processing based on legitimate interests (including any direct marketing, which you can always stop), to withdraw consent at any time, and to lodge a complaint with your local data protection authority. Our legal bases are listed in Section 3.1. We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.

8.3 California — CCPA/CPRA

In the last 12 months we have collected these categories of personal information: identifiers (name, email, IP address, account IDs), commercial information (plan and payment records), internet activity (pages and features used), approximate location (country from IP address), and the content you create. Sources, purposes and recipients are described in Sections 2 to 5. We do not collect sensitive personal information for the purpose of inferring characteristics about you.

We do not sell personal information for money. Our advertising cookies and the Meta Conversions API may count as “sharing” for cross-context behavioural advertising under the CPRA. You can opt out at any time from Cookie Preferences, and we honour Global Privacy Control signals as an opt-out. We do not knowingly sell or share the personal information of anyone under 16.

You have the right to know, access, correct and delete your personal information, to opt out of sharing, and not to be discriminated against for using these rights. You may use an authorised agent, who must show us your signed permission. Residents of other US states with similar privacy laws have the same rights, which we honour in the same way.

To exercise any of these rights, email info@trypoststage.com. We may need to verify your identity before fulfilling a request.

9. International data transfers

PostStage is operated from India and uses service providers (including Vercel, Neon, Upstash and Anthropic) that may process data on servers located outside India, including in the United States. By using PostStage, you understand your data may be transferred to and processed in countries with different data protection laws than your own. For personal data from the EEA, UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum and Swiss amendments where needed), adequacy decisions, or our providers' certifications under the EU-US Data Privacy Framework. We do not transfer personal data to any country the Government of India has restricted under the DPDP Act. You can ask us for details of the safeguard that applies.

10. Children's privacy

PostStage is not directed at, and is not intended for use by, anyone under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us personal data, contact us at info@trypoststage.com and we will delete it.

11. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal/regulatory reasons. We will post the revised policy here with an updated effective date, and for material changes we will notify you by email or an in-app notice.

12. Contact us

Questions, requests, or complaints about this Privacy Policy or our data practices can be sent to info@trypoststage.com. We aim to respond within 5 business days.