1. Who Operates Postvertise
This Privacy Policy describes how RightBack.com LLC d/b/a Postvertise ("Postvertise," "we," "us," or "our") processes information when you use the Postvertise website and related services (the "Platform").
The Platform is operated by RightBack.com LLC d/b/a Postvertise.
Questions about this policy may be sent using the contact details in Section 30.
2. Scope of This Policy
This policy applies to visitors, Creators, and Brands who use the Platform.
It should be read with our Terms of Service, Cookie Policy, Social Data Disclosure, and Data Deletion pages.
This policy describes the current production implementation. It does not describe unimplemented roadmap features such as payments, messaging inboxes, or publishing content to social platforms.
3. Information Collected
We process information you provide, information generated by the Platform, and information received from social platforms you choose to connect.
- Account and authentication data
- Creator and Brand profile data
- Campaign, invitation, application, participant, deliverable, and submission data
- Connected social account identity and synced metrics/content permitted by your authorization
- Technical session data needed to operate login
- Transactional email content related to magic links, verification, and service messages
4. Information You Provide
Depending on account type and forms you complete, you may provide:
- Email address and account type (Creator or Brand)
- Name and Creator display name / username / niche
- Brand company name, username, and optional website, industry, description, logo, and location
- Creator bio, profile photo, country, optional date of birth, gender, and gender self-description
- Campaign briefs, budgets, targeting metadata, invitation/application messages, and submission captions, URLs, and notes
6. Information Generated by Postvertise
We generate technical and derived records such as:
- Session records (including IP address and user agent stored with Laravel sessions)
- Email verification timestamps and magic-link token hashes
- Social sync status, snapshots, and derived metrics (for example engagement-related calculations from synced data)
- Campaign participant/deliverable status transitions and review timestamps
7. How Information Is Used
We use information to:
- Create and authenticate accounts (including passwordless magic-link sign-in)
- Operate Creator and Brand profiles and onboarding
- Provide creator discovery/search and public Creator profiles
- Sync and display authorized social metrics for marketplace and Creator analytics features
- Operate campaigns, invitations, applications, participants, deliverables, and submissions
- Send transactional email (magic links, welcome, verification, password reset where used)
- Secure the Platform, debug failures, and enforce Terms
- Respond to lawful requests
8. Creator / Brand Marketplace Functionality
Postvertise helps Brands discover Creators and helps users run campaign workflows on the Platform.
Public Creator directory and profile pages expose allowlisted profile and social aggregate fields to visitors. Authenticated campaign features share campaign-related data between the Brand and participating Creators.
Postvertise does not sell personal information.
11. Campaign Functionality
Brands may create campaigns with budgets, schedules, platform targets, audience targeting metadata, and deliverable definitions.
Creators may receive invitations, submit applications, join as participants, receive deliverable tasks, and submit content URLs/captions/notes for Brand review.
Campaign data is visible to the relevant Brand and Creator counterparties through authenticated APIs. It is not published on the public marketing Creator profile endpoints.
12. Communications
We send transactional messages required to operate the Platform, including magic-link emails, welcome messages, email verification, and password-reset messages where that flow is used.
Email delivery is processed by Resend using Laravel Mail. Account creation does not depend on successful email delivery succeeding in every case, but magic-link sign-in requires email delivery to complete authentication.
13. Authentication and Magic Links
The primary authentication flow is passwordless: we email a short-lived magic link (token hashed at rest; plain token sent only in the email link). Links expire quickly (currently one minute in application configuration).
Sessions use Laravel Sanctum cookie/session authentication for the SPA. The browser stores session and CSRF cookies required for authenticated API calls. Authentication tokens are not stored in localStorage or sessionStorage.
Passwords may still exist for some accounts or legacy flows and are stored hashed when present. Password fields are nullable for magic-link accounts.
14. Security
We apply technical controls appropriate to the current stack, including hashed passwords when used, encrypted storage of social OAuth access and refresh tokens via application encryption, server-side session authentication, and CSRF protection for cookie-authenticated API requests.
No method of transmission or storage is perfectly secure. Absolute security is not guaranteed.
15. Token and Credential Handling
Social provider access tokens and refresh tokens are stored in `social_account_credentials` with application-level encryption and are hidden from API serialization.
Magic-link secrets are stored as hashes. CSRF secrets are handled via Sanctum/Laravel cookie conventions.
Tokens are used only to maintain authorized connections and perform permitted syncs. They are deleted when you disconnect the social account.
17. Third-Party Service Providers
Known processors/integrations in the current implementation include Resend (email), Meta/Instagram/Facebook APIs, TikTok Open API, and X API, plus the database and hosting infrastructure used to run the application.
Production hosting provider and primary data-center region are not documented in the application repository and should be published by the operator when available.
Each social platform processes data under its own terms and policies when you authorize access.
18. Public Creator Information
Public Creator profiles and search results may show username, display name, bio, profile image, country, niche, limited demographic labels derived from profile inputs, connected provider labels/usernames, and aggregate social metrics such as followers, views, and engagement-related figures when available.
Email addresses, passwords, session data, OAuth tokens, date of birth (raw), and non-public account settings are not included in public Creator profile resources.
19. Information Visible to Brands
Brands can access the same public discovery/profile information available to visitors.
When a Brand invites a Creator, reviews an application, or works with a participant, the Brand can also see campaign workflow data (messages, statuses, deliverables, submissions, and review notes) exchanged for that campaign.
Brands do not receive Creator OAuth tokens or magic-link secrets through Postvertise APIs.
20. Information That Remains Private
Examples of data not exposed on public profiles include account email, authentication secrets, social access/refresh tokens, provider credential rows, internal sync failure details, and raw date of birth.
Creator analytics detail endpoints require Creator authentication.
21. International Data Transfers
Social platform APIs and Resend are third-party services that may process data in multiple countries.
Because production hosting region is not documented in this repository, we cannot assert a single storage country here. If you need transfer details for a specific region, contact us using Section 30 after the operator publishes infrastructure details.
22. Data Retention
Account and profile data are retained while your account remains open. The application does not currently include an automated retention purge job for closed accounts.
Magic-link tokens expire after a short period and are marked consumed when used. Sessions expire according to server session configuration (default idle lifetime is 120 minutes).
Social connection data and synced metrics/content are retained until you disconnect the account (which deletes that connection's stored social data) or until you delete your Postvertise account.
We do not publish fixed multi-year retention schedules in code; any legal hold requirements would be handled operationally.
23. Account Deletion
Authenticated Creators and Brands can delete their Postvertise account from Dashboard → Settings (Danger Zone), which calls DELETE /api/account for the signed-in owner only.
Deletion disconnects social accounts, removes stored social credentials and synced social data from Postvertise, invalidates sessions and unused magic-link tokens, and removes or anonymizes personal profile information. Shared campaign relationship rows may remain in anonymized form where required for referential integrity.
Postvertise deletes stored credentials and connection data on its side. Provider-side OAuth token revocation with Instagram, Facebook, TikTok, or X is not currently implemented.
If you cannot sign in, follow the offline request instructions on our Data Deletion page and contact us using Section 30.
26. User Rights
Depending on where you live, you may have rights to request access, correction, deletion, or restriction of certain personal information.
Self-service account deletion is available while signed in. A formal DSAR portal is not implemented; other rights requests can be made by contacting us using Section 30. We may need to verify control of the account email before acting.
This policy describes practices; it does not claim certification under any specific privacy law framework.
28. Children's / Minors Policy
Postvertise is intended for users who are at least 18 years old (or the higher age of majority required where you live).
We do not knowingly collect personal information from children under 18. If you believe a minor has created an account, contact us using Section 30.
29. Policy Changes
We may update this Privacy Policy to reflect product or legal changes. We will post the updated policy and revise the “Last updated” date.
Material changes should be reviewed on this page before you continue using the Platform.
30. Contact Information
Privacy and data requests:
RightBack.com LLC d/b/a Postvertise
Email: support@postvertise.com
Address: 8101 College Blvd Ste 100-1023 Overland Park, KS 66210 United States
Use the email above for privacy and deletion requests.
5. Information Received from Connected Social Platforms
If you connect Instagram, Facebook, TikTok, or X, Postvertise receives information permitted by the scopes you approve and by each provider's APIs.
Typical categories include provider account identifiers, usernames, display names, profile URLs, profile images, connection status, and OAuth tokens needed to maintain the connection.
Depending on the provider, Postvertise may also sync profile metrics, audience counts, and a limited sample of public content metrics. TikTok sync does not ingest video content items. See Social Data Disclosure for provider detail.
Postvertise does not receive payment-card data from social platforms and does not use social connections to publish posts on your behalf.