Skip to content

Legal

Privacy Policy

Last updated:

This Privacy Policy explains what information Postvertise processes in the current product, how we use it, and the choices available for account data, profiles, campaigns, and connected social accounts.

This document is provided for informational purposes and is subject to final legal review. It does not constitute legal advice.

1. Who Operates Postvertise

This Privacy Policy describes how RightBack.com LLC d/b/a Postvertise ("Postvertise," "we," "us," or "our") processes information when you use the Postvertise website and related services (the "Platform").

The Platform is operated by RightBack.com LLC d/b/a Postvertise.

Questions about this policy may be sent using the contact details in Section 30.

2. Scope of This Policy

This policy applies to visitors, Creators, and Brands who use the Platform.

It should be read with our Terms of Service, Cookie Policy, Social Data Disclosure, and Data Deletion pages.

This policy describes the current production implementation. It does not describe unimplemented roadmap features such as payments, messaging inboxes, or publishing content to social platforms.

3. Information Collected

We process information you provide, information generated by the Platform, and information received from social platforms you choose to connect.

  • Account and authentication data
  • Creator and Brand profile data
  • Campaign, invitation, application, participant, deliverable, and submission data
  • Connected social account identity and synced metrics/content permitted by your authorization
  • Technical session data needed to operate login
  • Transactional email content related to magic links, verification, and service messages

4. Information You Provide

Depending on account type and forms you complete, you may provide:

  • Email address and account type (Creator or Brand)
  • Name and Creator display name / username / niche
  • Brand company name, username, and optional website, industry, description, logo, and location
  • Creator bio, profile photo, country, optional date of birth, gender, and gender self-description
  • Campaign briefs, budgets, targeting metadata, invitation/application messages, and submission captions, URLs, and notes

5. Information Received from Connected Social Platforms

If you connect Instagram, Facebook, TikTok, or X, Postvertise receives information permitted by the scopes you approve and by each provider's APIs.

Typical categories include provider account identifiers, usernames, display names, profile URLs, profile images, connection status, and OAuth tokens needed to maintain the connection.

Depending on the provider, Postvertise may also sync profile metrics, audience counts, and a limited sample of public content metrics. TikTok sync does not ingest video content items. See Social Data Disclosure for provider detail.

Postvertise does not receive payment-card data from social platforms and does not use social connections to publish posts on your behalf.

6. Information Generated by Postvertise

We generate technical and derived records such as:

  • Session records (including IP address and user agent stored with Laravel sessions)
  • Email verification timestamps and magic-link token hashes
  • Social sync status, snapshots, and derived metrics (for example engagement-related calculations from synced data)
  • Campaign participant/deliverable status transitions and review timestamps

7. How Information Is Used

We use information to:

  • Create and authenticate accounts (including passwordless magic-link sign-in)
  • Operate Creator and Brand profiles and onboarding
  • Provide creator discovery/search and public Creator profiles
  • Sync and display authorized social metrics for marketplace and Creator analytics features
  • Operate campaigns, invitations, applications, participants, deliverables, and submissions
  • Send transactional email (magic links, welcome, verification, password reset where used)
  • Secure the Platform, debug failures, and enforce Terms
  • Respond to lawful requests

8. Creator / Brand Marketplace Functionality

Postvertise helps Brands discover Creators and helps users run campaign workflows on the Platform.

Public Creator directory and profile pages expose allowlisted profile and social aggregate fields to visitors. Authenticated campaign features share campaign-related data between the Brand and participating Creators.

Postvertise does not sell personal information.

9. Social Account Connections

Creators may connect supported social accounts through provider OAuth/OIDC flows. Credentials (access and refresh tokens) are stored encrypted at rest in Postvertise's database and are never shown in public API resources.

You can disconnect a social account in the dashboard. Disconnecting deletes that connection's stored credentials and synced social snapshots/metrics/content for that account.

Connecting an account does not grant Postvertise permission to publish content to that platform; current integrations are read/sync oriented only.

10. Social Metrics and Analytics

After a connection is established, Postvertise may run a sync job (automatically after linking and when you trigger manual sync). There is no continuous scheduled monitoring job in the current implementation.

Synced metrics may include follower-style audience counts, profile counters, verification flags where provided, content engagement counters for ingested items, aggregated platform audience demographics (location/age/gender) when an official Insights API returns them for Instagram or Facebook, and derived metrics calculated by Postvertise from those platform-supplied aggregates.

Platform audience demographics are never scraped or inferred from individual followers. TikTok and X do not supply creator follower demographics through the currently authorized integrations. Age/gender shown publicly on Creator profiles may come from Creator-provided profile fields (with date of birth reduced to age or age range publicly)—not from platform audience Insights.

In-product “Analytics” refers to these synced social metrics, not third-party advertising pixels or website analytics suites. The frontend does not load Google Analytics, Meta Pixel, or similar marketing trackers.

11. Campaign Functionality

Brands may create campaigns with budgets, schedules, platform targets, audience targeting metadata, and deliverable definitions.

Creators may receive invitations, submit applications, join as participants, receive deliverable tasks, and submit content URLs/captions/notes for Brand review.

Campaign data is visible to the relevant Brand and Creator counterparties through authenticated APIs. It is not published on the public marketing Creator profile endpoints.

12. Communications

We send transactional messages required to operate the Platform, including magic-link emails, welcome messages, email verification, and password-reset messages where that flow is used.

Email delivery is processed by Resend using Laravel Mail. Account creation does not depend on successful email delivery succeeding in every case, but magic-link sign-in requires email delivery to complete authentication.

13. Authentication and Magic Links

The primary authentication flow is passwordless: we email a short-lived magic link (token hashed at rest; plain token sent only in the email link). Links expire quickly (currently one minute in application configuration).

Sessions use Laravel Sanctum cookie/session authentication for the SPA. The browser stores session and CSRF cookies required for authenticated API calls. Authentication tokens are not stored in localStorage or sessionStorage.

Passwords may still exist for some accounts or legacy flows and are stored hashed when present. Password fields are nullable for magic-link accounts.

14. Security

We apply technical controls appropriate to the current stack, including hashed passwords when used, encrypted storage of social OAuth access and refresh tokens via application encryption, server-side session authentication, and CSRF protection for cookie-authenticated API requests.

No method of transmission or storage is perfectly secure. Absolute security is not guaranteed.

15. Token and Credential Handling

Social provider access tokens and refresh tokens are stored in `social_account_credentials` with application-level encryption and are hidden from API serialization.

Magic-link secrets are stored as hashes. CSRF secrets are handled via Sanctum/Laravel cookie conventions.

Tokens are used only to maintain authorized connections and perform permitted syncs. They are deleted when you disconnect the social account.

16. Data Sharing

We share information as follows:

  • Public Creator profile and search visitors: allowlisted profile and social aggregate fields
  • Brands and Creators interacting on a campaign: campaign, participation, deliverable, and submission fields needed for that workflow
  • Service providers: currently Resend for email; social platforms when you authorize connections; optional cloud object storage if configured for files
  • Legal: if required by law or to protect rights and safety
  • Business transfers: if Postvertise assets are transferred, information may move with them subject to continued protections

17. Third-Party Service Providers

Known processors/integrations in the current implementation include Resend (email), Meta/Instagram/Facebook APIs, TikTok Open API, and X API, plus the database and hosting infrastructure used to run the application.

Production hosting provider and primary data-center region are not documented in the application repository and should be published by the operator when available.

Each social platform processes data under its own terms and policies when you authorize access.

18. Public Creator Information

Public Creator profiles and search results may show username, display name, bio, profile image, country, niche, limited demographic labels derived from profile inputs, connected provider labels/usernames, and aggregate social metrics such as followers, views, and engagement-related figures when available.

Email addresses, passwords, session data, OAuth tokens, date of birth (raw), and non-public account settings are not included in public Creator profile resources.

19. Information Visible to Brands

Brands can access the same public discovery/profile information available to visitors.

When a Brand invites a Creator, reviews an application, or works with a participant, the Brand can also see campaign workflow data (messages, statuses, deliverables, submissions, and review notes) exchanged for that campaign.

Brands do not receive Creator OAuth tokens or magic-link secrets through Postvertise APIs.

20. Information That Remains Private

Examples of data not exposed on public profiles include account email, authentication secrets, social access/refresh tokens, provider credential rows, internal sync failure details, and raw date of birth.

Creator analytics detail endpoints require Creator authentication.

21. International Data Transfers

Social platform APIs and Resend are third-party services that may process data in multiple countries.

Because production hosting region is not documented in this repository, we cannot assert a single storage country here. If you need transfer details for a specific region, contact us using Section 30 after the operator publishes infrastructure details.

22. Data Retention

Account and profile data are retained while your account remains open. The application does not currently include an automated retention purge job for closed accounts.

Magic-link tokens expire after a short period and are marked consumed when used. Sessions expire according to server session configuration (default idle lifetime is 120 minutes).

Social connection data and synced metrics/content are retained until you disconnect the account (which deletes that connection's stored social data) or until you delete your Postvertise account.

We do not publish fixed multi-year retention schedules in code; any legal hold requirements would be handled operationally.

23. Account Deletion

Authenticated Creators and Brands can delete their Postvertise account from Dashboard → Settings (Danger Zone), which calls DELETE /api/account for the signed-in owner only.

Deletion disconnects social accounts, removes stored social credentials and synced social data from Postvertise, invalidates sessions and unused magic-link tokens, and removes or anonymizes personal profile information. Shared campaign relationship rows may remain in anonymized form where required for referential integrity.

Postvertise deletes stored credentials and connection data on its side. Provider-side OAuth token revocation with Instagram, Facebook, TikTok, or X is not currently implemented.

If you cannot sign in, follow the offline request instructions on our Data Deletion page and contact us using Section 30.

24. Social-Account Disconnection

Creators can disconnect a connected social account from Social Accounts in the dashboard.

Disconnection deletes stored OAuth credentials and synced social snapshots, metrics, and content items for that connection from Postvertise.

25. Social-Data Deletion

Disconnecting a social account is the self-service method to delete that provider's stored connection and synced data from Postvertise.

Deleting your Postvertise account also removes all social connections on that account as described on Data Deletion.

Data may remain in encrypted backups or logs for a limited operational period until overwritten; the application does not expose a backup-purge SLA.

26. User Rights

Depending on where you live, you may have rights to request access, correction, deletion, or restriction of certain personal information.

Self-service account deletion is available while signed in. A formal DSAR portal is not implemented; other rights requests can be made by contacting us using Section 30. We may need to verify control of the account email before acting.

This policy describes practices; it does not claim certification under any specific privacy law framework.

27. Cookies

Postvertise uses essential cookies for session authentication and CSRF protection. See the Cookie Policy for details.

We do not currently use analytics or marketing cookies or third-party advertising pixels on the site.

28. Children's / Minors Policy

Postvertise is intended for users who are at least 18 years old (or the higher age of majority required where you live).

We do not knowingly collect personal information from children under 18. If you believe a minor has created an account, contact us using Section 30.

29. Policy Changes

We may update this Privacy Policy to reflect product or legal changes. We will post the updated policy and revise the “Last updated” date.

Material changes should be reviewed on this page before you continue using the Platform.

30. Contact Information

Privacy and data requests:

RightBack.com LLC d/b/a Postvertise

Email: support@postvertise.com

Address: 8101 College Blvd Ste 100-1023 Overland Park, KS 66210 United States

Use the email above for privacy and deletion requests.