posto

Privacy & Terms

Privacy, service terms, role requirements, and technical data-handling terms for Posto are collected here in one place.

PostoX, Inc · Current release 2026-10-02 · Version archive

On this page Privacy PolicyTerms of ServiceAdvertiser TermsDeveloper TermsSDK Data Handling NoticeAdvertiser Event and Conversion API Data NoticeData Processing AddendumSubprocessors

Privacy Policy

The information Posto receives, the purposes for which it is processed, and the choices available to individuals who interact with Posto or its advertising services.

Effective 2026-10-02 · Version 2026-10-02 · Permanent version

1. Scope and processing roles

PostoX, Inc ('Posto') operates the Posto websites, advertising platform, software development kits (SDKs), application programming interfaces (APIs), and related services. This Policy covers visitors, account representatives, support correspondents, and individuals whose information reaches Posto through a participating application, advertisement, connected store, or measurement integration.

A Customer is a business entity or sole proprietor using the services. An Advertiser is a Customer purchasing or managing advertising; a Developer or Publisher is a Customer supplying an application, property, or advertising placement. An Authorized User acts for a Customer. An End User uses a participating application, visits an advertised destination, or interacts with an advertisement. These roles do not, by themselves, determine an individual's legal privacy rights.

Posto determines the purposes and means of processing for its account administration, billing, business records, legal compliance, and independently determined security and fraud-prevention activities, to the extent permitted by applicable law. Posto acts as a processor, service provider, or subprocessor only for activities actually carried out on a Customer's documented instructions and satisfying the applicable legal requirements. Contextual delivery and measurement may involve both types of activity. The Data Processing Addendum (DPA) governs processing on behalf of a Customer; this Policy describes Posto's information practices.

This Policy provides notice. Acknowledging it or accepting a business agreement does not supply every consent required for personal-data processing, authorize undisclosed collection, or waive an individual's rights. The party responsible for a particular activity shall obtain any specific consent or other lawful permission that activity requires.

2. Categories of information

Posto receives the following categories when the corresponding service or integration is used. Examples within each category are illustrative, including without limitation the listed fields; they do not authorize collection outside the disclosed categories or purposes. Optional features do not transmit information merely because integration code is available.

  • Account and business records: names, work email addresses, company or sole-proprietor details, business role, website, verification information, account status, communications, and records of contract acceptance or privacy choices.
  • Advertising and catalog content: campaign instructions, budgets, bids, products, descriptions, images, creatives, targeting constraints, availability, delivery settings, and performance. Connected-store imports can include draft, archived, or unlisted products and their images and metadata; importing content is distinct from authorizing its publication in an advertisement.
  • Developer and application records: application and placement configuration, registered domains and app identifiers, SDK versions, credentials, integrity-verification results, and integration diagnostics.
  • Ad-request context: recent interaction text and optional permitted age range, gender, and coarse country, region, or city supplied by the Developer within the applicable integration limits. Input filtering reduces certain identifiers but may leave personal information or sensitive inferences.
  • Delivery and interaction records: request, auction, candidate, impression, click, redirect, conversion, event time, and technical metadata; signed tracking tokens; and optional browser Pixel events from an Advertiser's verified domain.
  • Advertiser measurement events: event name and time, source URL, deduplication identifier, Posto click ID, transaction ID, value and currency where applicable, and supported optional email, phone, client, or user identifiers. Accepted identifiers are normalized and hashed before persistence in the event records; transient receipt precedes that processing. Hashes and click identifiers remain potentially personal information.
  • Shopify connection and commerce records: store domain, encrypted access credentials, imported product content and metadata, order and refund webhook information, order ID, checkout token, totals, currency, payment/refund/cancellation status, and attribution identifiers. Incoming Shopify payloads can transiently include customer details or line items beyond the fields retained for Posto's processing. Posto selects the fields needed for catalog, connection, attribution, and reconciliation records rather than retaining an unrestricted copy of each customer record.
  • Browser and device information: session and security state, browser technical information, a standalone Pixel client identifier, a stored Posto click identifier, and page URLs. Depending on the integration, URLs may include query parameters or fragments and can contain information entered by the merchant or visitor.
  • Security and fraud records: network and user-agent information received with requests, stored hashes, request velocity, HMAC verification, Apple App Attest or Google Play Integrity proofs and verdicts, risk reasons, and investigation records. The ad-request interface does not require a Customer-supplied hardware serial number or advertising identifier.
  • Payments and payouts: business and transaction details, payment and payout status, disputes, recipient references, and reconciliation records. Card, bank, and tax-document details submitted directly to payment or banking providers are handled by those providers; Posto does not store full card or bank-account numbers through the described flows.
  • Support and operational communications: questions, messages, supplied attachments or content, survey responses, website logs, and visible account context used to answer a request. Questions and account context sent to an assisted support feature may contain personal information.

3. Sources of information

Information comes from individuals and their Authorized Users; Customers and their applications, storefronts, servers, or measurement partners; browsers and devices interacting with enabled integrations; Shopify and other connected services; payment, cloud, email, integrity-verification, and model providers; and records generated when Posto operates the services. Posto may derive attribution, intent, risk, and performance information from these sources. Derived information is not automatically anonymous.

4. Purposes of processing

Posto uses information for the following disclosed purposes, subject to the applicable agreement, processing role, and law. A general reference to operating or improving a service does not permit unrelated use of Customer Personal Data.

  • Provide and authenticate accounts, integrations, catalog imports, creative workflows, support, and the contracted advertising services.
  • Match eligible advertisements to the context supplied for a request and apply configured category, language, location, price, audience, and safety constraints.
  • Run auctions, pace budgets, record delivery, deduplicate events, attribute conversions, reconcile cancellations and refunds, and produce Customer reports.
  • Detect invalid traffic, compromised integrations, replay, abuse, fraudulent conversions, payment discrepancies, and improper payouts, and investigate or resolve those issues.
  • Communicate about accounts, send transactional messages, process payments and supplier payouts, maintain financial and acceptance records, comply with legal obligations, and establish or defend legal claims.
  • Assess and improve the reliability and performance of the contracted services within the applicable processing permissions, and prepare aggregate or deidentified statistics subject to the safeguards described in this Policy.

5. Contextual matching and automated systems

Posto uses the permitted interaction context and applicable campaign or audience constraints to select eligible advertisements. Enabled automated assistance may also process submitted product, campaign, creative, or support information for the corresponding Service purpose. Third-party AI service providers may process information needed for these functions, subject to the applicable processing restrictions and provider arrangements.

Automated systems select and price advertisements, assess traffic and event validity, and assist campaign and support workflows. They are not offered for decisions about an End User's eligibility for employment, credit, housing, insurance, health care, or other opportunities producing legal or similarly significant effects. Customers shall not repurpose the services for such decisions. Campaign suggestions and generated content require the Customer's review before use where the workflow calls for approval.

Sensitive conversations are prohibited inputs. Input filters and other safeguards have limitations; they do not establish that every sensitive context will be detected or suppressed. The absence of a direct identifier does not make interaction text or an inferred characteristic anonymous.

6. Recipients and disclosures

Posto discloses information needed for the relevant purpose to its service providers and, where applicable, independent providers: hosting, storage, email, support, AI, payment, banking, and integrity-verification services. Relevant information may include permitted interaction text, product or campaign materials, Customer questions and account context for support, and app-integrity proofs. The public Subprocessors disclosure summarizes provider categories and selected providers. Current provider identities, locations, and other details needed for an applicable processing agreement are made available to affected Customers through the account or privacy-contact process before the relevant processing where required. A provider's legal role depends on the activity and its applicable agreement.

The relevant Advertiser or Developer receives campaign, delivery, attributed performance, and settlement information for its business relationship. Posto does not make submitted ad-request transcripts available to Advertisers as part of campaign reporting. After an intentional advertisement click, Posto may transmit a pseudonymous click identifier to the selected destination for redirect and attribution. A destination may independently collect browsing or transaction information under its own notice.

Shopping cards shown with Developer content can link to retailers through affiliate networks, such as Awin, CJ, FlexOffers, impact.com, or Rakuten Advertising, where Posto participates in the relevant program. After an intentional tap, Posto sends the End User to the retailer through that network's tracking link, which carries identifiers for the publishing app, placement, and content but no End User name, contact details, or advertising identifier. The network and the retailer may set cookies or similar technologies and record the visit and any purchase under their own notices to attribute a commission. Posto receives commission reports from the network that do not identify the End User.

Posto may disclose relevant information to professional advisers, prospective or actual transaction counterparties subject to appropriate confidentiality arrangements, courts, regulators, or other authorities when reasonably necessary for a transaction, legal obligation, lawful request, or protection of rights, security, and safety. These examples do not permit unlimited disclosure.

Posto's described service is contextual advertising and Customer measurement. Posto does not sell personal information or share it for cross-context behavioral advertising in the described processing, or combine optional demographics into unrelated profiles. A Customer shall not configure an integration to introduce such processing without the required assessment, disclosures, contractual arrangement, and controls.

7. Retention, deletion, and deidentification

Retention depends on the record's purpose. Removal of a direct identifier is not necessarily deletion or anonymization: financial references, hashes, tokens, and other residual records may remain linkable and are treated accordingly. Scheduled deletion and browser storage are separate processes.

  • Ad-request text and related original or derived text retained as delivery or diagnostic copies are removed under the applicable 30-day retention schedule and may be deleted earlier. Structured categories and numeric measures, event identities, hashes, risk outcomes, and permitted aggregates may remain for their separate documented purposes; their retention does not authorize reconstructing deleted conversations.
  • Raw advertiser event payloads and diagnostics are scheduled for removal after 30 days, including source URLs and the event-row copies of click/deduplication values and optional identifier hashes. Event identity, validation and attribution outcomes, payload hashes, durable deduplication evidence, canonical conversions, and necessary financial or fraud records may remain.
  • Raw traffic-risk records are retained for 30 days, with aggregated risk and velocity information retained for 180 days. Non-billable SDK test request records and tokens are retained for 7 days. Account action tokens are removed after use or expiry through maintenance.
  • Account information is maintained during the active relationship and the 30-day account-closure grace period. Closure then removes or pseudonymizes account data through the closure process; it is not a promise that every record becomes anonymous or is immediately erased. Financial, settlement, tax, contract-acceptance, confirmed fraud, and legal records may be retained for up to 7 years, or longer when a legal requirement or active dispute requires retention.
  • Shopify privacy requests and store disconnection are handled according to their respective purposes and applicable requirements. Erasing shopper-related information does not by itself delete merchant-owned catalog assets, campaign content, or every business record. Store disconnection and account closure have different effects; required financial and legal records may remain with access and use restricted.
  • The standalone browser Pixel's persistent client identifier has no automatic expiration in its local-storage implementation. Its locally stored Posto click identifier is subject to a 30-day validity period. Browser clearing, site storage settings, the merchant's consent implementation, and an applicable deletion request can affect these values. The server's 30-day event retention does not automatically clear a browser's storage.
  • Other catalog, support, connection, security, and operational information is kept for the period reasonably necessary for the applicable service, support, security, or legal purpose. Backup records are protected from ordinary use and removed through the applicable backup cycle or required deletion process; a legal hold may require restricted preservation.

8. Security and limits of safeguards

Posto maintains safeguards appropriate to the nature and risk of the processing, including applicable transport encryption, access restrictions, credential isolation, signed requests, integrity checks, idempotency controls, logging, and operational recovery procedures. Their applicability depends on the service and integration. No filter, authentication measure, or storage system guarantees complete security or the removal of all personal information. Suspected security incidents shall be reported promptly to legal@postoconnect.com.

Posto treats statistics as deidentified only where the applicable legal standard is satisfied. Posto shall take reasonable measures against association with an individual, maintain deidentified data in that form, refrain from attempting reidentification except where law permits validation of deidentification, and impose required restrictions on recipients. Information that remains reasonably linkable is subject to the safeguards and rights applicable to personal information.

9. United States service and international processing

Posto presently offers a United States business service. Information may nevertheless be processed by providers in other countries, and a provider's support, infrastructure, or subprocessors may involve additional locations. The Subprocessors disclosure does not establish a blanket United States-only processing commitment.

Before a Customer introduces an integration or transfer requiring an additional international data-protection arrangement, the Customer shall contact legal@postoconnect.com. Posto and the Customer shall establish the applicable lawful transfer mechanism and safeguards before carrying out a restricted transfer. This Policy does not itself complete European Standard Contractual Clauses, a UK transfer addendum, or a certification under a data-transfer framework. Applicable rights are not lost because the service is offered primarily in the United States.

10. Individual rights and requests

Individuals in the United States may ask Posto to confirm processing and request access, correction, deletion, and a portable copy. Depending on applicable law and Posto's role, additional rights may include obtaining information about recipients, opting out of sale, sharing, targeted advertising or covered profiling, limiting covered uses of sensitive information, using an authorized agent, and appealing a denied request. Requests and appeals may be sent directly to legal@postoconnect.com without creating an account or accepting new contractual terms.

California residents may exercise applicable rights to know, correct, delete, opt out of sale or sharing, and limit covered uses of sensitive personal information. Delaware residents may exercise applicable access, correction, deletion, portability, recipient-information, opt-out, and appeal rights. Scope, verification, exceptions, and response periods depend on the applicable law; business representatives do not necessarily have the same statutory coverage in every state. Posto shall not unlawfully discriminate against an individual for exercising a privacy right.

An End User may contact the relevant Developer or Advertiser, particularly where that business controls the information and Posto acts on its instructions. Contacting that business first is not a condition of contacting Posto or exercising a statutory right. Posto shall assist the responsible Customer or respond as its role and the law require. Posto may seek proportionate verification or information needed to locate records, explain an exception or denial, and provide the applicable appeal route and legally required response within the required period.

Authorized account representatives can use the account export and closure controls for records available through those tools. A tool's scope does not restrict other lawful requests. Posto shall honor legally binding opt-out signals, including Global Privacy Control where applicable, for processing covered by those signals. The absence of a current sale, sharing, or targeted-advertising activity does not waive rights if practices change.

11. Cookies, browser storage, and preferences

The Posto website uses session and security technologies for authentication, request integrity, and essential account state. The standalone Advertiser Pixel is a separate measurement integration: it can use persistent browser storage, transmit page URLs and events, and associate a stored client identifier or Posto click identifier with those events. It shall be installed only on the Advertiser's verified domains and subject to that Advertiser's lawful notices and choices.

The standalone Pixel does not supply a universal consent-management interface or automatically establish that a visitor has consented. The Advertiser shall gate loading, storage, and transmission when consent or an opt-out requires it, avoid sensitive information in transmitted URLs, and implement withdrawal or preference handling. The Shopify web-pixel integration uses Shopify's customer-privacy controls; those controls do not automatically govern a separate standalone Pixel installation.

The Posto microdrama player SDK sets no cookies and uses no browser storage for shopping cards. After an End User taps a card, the affiliate network and the retailer may use cookies or similar technologies on their own sites to attribute a resulting purchase, as described in Section 6.

Posto does not use website activity across unaffiliated services to build the behavioral advertising profiles excluded by the described service. The legacy Do Not Track browser setting does not alter essential website operation; legally binding universal opt-out mechanisms are handled according to the law applicable to the processing. Browser settings can clear or restrict local storage, but server-side rights requests may still be needed.

12. Children and prohibited sensitive information

Individual account holders and Authorized Users shall be at least 18. Posto is not directed to children and does not approve production integrations in child-directed properties. An account's adult-use requirement does not establish the age of an application's End Users or relieve a Customer of its children's-privacy duties.

Customers shall not submit children's personal information, health or crisis conversations, protected health information, precise geolocation, financial-account credentials, payment-card data, authentication secrets, biometric identifiers, government identifiers, or other legally sensitive information through ad-request or measurement interfaces. Customers shall assess their actual audience and inputs rather than relying on identifier filtering or a general acceptance checkbox.

A Customer considering a service that could involve those audiences or categories shall contact legal@postoconnect.com before integration. If prohibited information is sent inadvertently, the Customer shall promptly stop the affected submission and cooperate with Posto on containment, appropriate deletion, and any required notification. These restrictions and the contractual allocation of responsibility do not eliminate Posto's own legal obligations or an individual's nonwaivable rights.

13. Changes and contact

Posto shall publish an updated effective date when this Policy changes and provide additional notice or obtain specific consent where required before materially different processing begins. A revised Policy does not retroactively authorize an undisclosed use or change a contractual obligation without the applicable agreement process.

The operator is PostoX, Inc. Contact address: 131 Continental Drive Suite 305, Newark, DE 19702. Legal notices, privacy questions, data-rights requests, and appeals: legal@postoconnect.com. Security reports: legal@postoconnect.com.

Terms of Service

Business terms for the Posto services. Sections 16 and 17 provide for binding individual arbitration and limit court, jury, and class proceedings to the extent permitted by law. The Privacy Policy is a separate notice of information practices.

Effective 2026-10-02 · Version 2026-10-02 · Permanent version

1. Agreement, business use, and eligibility

These Terms form a contract between PostoX, Inc ('Posto') and the Customer identified in the account or applicable order when the Customer affirmatively accepts them. A person accepting for a business entity represents that the person is at least 18 and has authority to bind that entity. An individual accepting as a sole proprietor represents that the individual is at least 18 and is obtaining the services for business purposes. Customer shall provide accurate identity and account information.

The Agreement consists of these Terms, the Advertiser Terms or Developer Terms applicable to Customer's activities, the DPA where Customer Personal Data is processed on Customer's behalf, and any order or amendment executed by the parties. Customer shall comply with the SDK Data Handling Notice and Advertiser Event and Conversion API Data Notice for integrations it uses. An executed order controls an express conflict only to the extent it identifies the conflicting requirement or otherwise clearly provides for the variation. The DPA controls conflicts specifically concerning its regulated processing obligations; mandatory law controls in all cases.

The services are offered for United States business use. Customer shall obtain Posto's written approval and any required additional arrangement before introducing an unsupported jurisdiction, restricted international transfer, or prohibited audience. Reading a publicly available notice does not itself make an End User a party to this Agreement. Acceptance of these Terms and acknowledgment of the Privacy Policy are distinct from any specific consent required from an individual.

2. Definitions and interpretation

  • Customer means the legal business entity or individual sole proprietor accepting the Agreement. An Authorized User is an individual authorized by Customer to operate its account; an Authorized User does not become a separate contracting Customer solely by acting for that Customer.
  • Advertiser means a Customer that creates, funds, purchases, or manages advertising. Developer, also called Publisher for inventory and earnings purposes, means a Customer that integrates Posto into an application, website, service, or placement it owns or is authorized to operate. A Customer can hold both roles, in which case both sets of role terms apply to the corresponding activities.
  • End User means an individual using a participating property, visiting an advertised destination, or interacting with an advertisement. The term does not imply that the individual has accepted Customer's or Posto's contractual terms.
  • Service means the Posto platform, websites, SDKs, APIs, advertising delivery, campaign, catalog, creative, measurement, support, and related features made available under the Agreement.
  • Customer Content means content, instructions, and materials submitted or made available by or for Customer, including campaigns, product catalogs, unpublished listings, images, creatives, application content, and contextual or measurement submissions. Customer Personal Data means personal information processed by Posto on Customer's behalf in performing the Agreement, as further defined in the DPA.
  • Confidential Information means nonpublic information disclosed by one party to the other that is designated confidential or should reasonably be understood as confidential from its nature or disclosure circumstances, including unpublished Customer Content, credentials, personal information, business plans, pricing, and nonpublic technical or financial records.
  • An Order means an order form or other commercial agreement executed by both parties. References to applicable law include laws governing the relevant party, activity, and information. 'Including' and 'including without limitation' introduce examples within the stated subject; neither phrase expands an authorized purpose for processing personal information.

3. Accounts and Authorized Users

Customer shall designate appropriate Authorized Users, maintain accurate account and verification information, and take reasonable measures to protect credentials and access. Customer shall be responsible for the acts and omissions of its Authorized Users in connection with the Service, including their instructions, account activity, and compliance with the Agreement. Customer shall promptly withdraw access when authority ends and shall not share access in a manner that circumvents account controls.

Customer shall notify legal@postoconnect.com promptly after discovering compromised credentials or suspected unauthorized account access and shall cooperate reasonably in containment. Posto may require email, business, property, payment, or additional risk-based verification before enabling or continuing a feature. Those checks do not transfer Customer's operational responsibilities to Posto.

4. Service operation and changes

Posto shall provide the Service described in the applicable Agreement and enabled account features. Posto may improve, update, or modify the Service while preserving material contracted functionality. A material reduction of a committed paid service shall be addressed through the applicable Order or a reasonable remedy under the Agreement, including the refund principles in Section 8 where applicable.

Test, beta, preview, simulation, and non-billable features may be changed or discontinued and carry no production service commitment unless expressly stated in an Order. Customer shall not represent simulated outcomes, test credits, or preview functionality as actual advertising delivery, earned revenue, or a production guarantee. Third-party features remain subject to the corresponding provider's availability and terms.

5. Acceptable use and compliance

Customer shall use the Service lawfully and shall ensure that its Authorized Users, submitted content, and enabled integrations satisfy the obligations applicable to Customer's role. Without limiting the specific prohibitions below, Customer shall not:

  • Violate intellectual-property, privacy, publicity, consumer-protection, advertising, export-control, sanctions, or other applicable law, or submit content without the necessary rights, substantiation, notices, and permissions.
  • Introduce malware; evade security; probe without authorization; interfere with availability; scrape protected interfaces; misuse credentials; or obtain another Customer's data without authority.
  • Generate invalid traffic, falsify events, manipulate auctions or attribution, misrepresent identity or property ownership, or bypass authentication, device proof, rate limits, verification, or tracking controls.
  • Send prohibited sensitive information, children's personal information, health or crisis context, precise location, payment-card data, or authentication secrets through ad-request or measurement interfaces, or disable required filtering. Specific integration restrictions appear in the applicable role terms and data notices.
  • Offer, promise, authorize, solicit, or accept a bribe, kickback, or improper payment in connection with the Service, or use the Service in violation of anti-corruption requirements.
  • Use reports or other Service outputs to identify End Users, create prohibited sensitive profiles, or make unsupported decisions about individual eligibility for regulated or similarly significant opportunities.

6. Customer Content, ownership, and limited license

As between the parties, Customer retains all right, title, and interest in and to Customer Content, subject to the rights of third parties. Customer hereby grants Posto a nonexclusive, worldwide license during the Agreement to host, reproduce, format, transform, analyze, transmit, and display Customer Content only as reasonably necessary to provide, secure, measure, support, and improve the contracted Service within Customer's instructions and the applicable data-processing permissions. Posto may allow providers to perform those functions on its behalf subject to appropriate contractual restrictions.

This license does not authorize Posto to publish an unpublished product merely because it was imported, sell Customer's confidential catalog, disclose Customer Personal Data for unrelated advertising, or train an unrelated model using Customer Content. Public display is limited to content Customer authorizes for an enabled publication or advertising workflow. Draft, archived, and unlisted catalog materials remain subject to Section 9 even when a connector makes them technically available to Posto.

Customer represents that it has the rights, authority, notices, and lawful permissions required to submit Customer Content and permit the agreed processing. That representation does not replace any End User consent required by law or relieve Posto of its own obligations. Following termination, the license continues only to the extent reasonably necessary for permitted retention, deletion, settlement, security, or legal obligations and ends when that purpose ends.

7. Posto materials and permitted use

Posto and its licensors retain ownership of the Service, software, documentation, marks, and models they provide. Subject to Customer's compliance with the Agreement, Posto hereby grants Customer a limited, nonexclusive, nontransferable license during the Agreement to access the Service for its own business activities and to use the SDKs and APIs in authorized integrations. No ownership transfer, unrestricted right of resale, or license to Posto's marks is implied.

Posto may develop and use aggregate or deidentified platform insights where their creation and use comply with the Agreement, confidentiality duties, and applicable privacy law. Personal or pseudonymous records do not become unrestricted Posto property by being labeled an insight. For voluntary suggestions about the Service that Customer elects to provide as feedback, Customer hereby grants Posto a nonexclusive, worldwide, perpetual, irrevocable, royalty-free license to use, reproduce, modify, and incorporate those suggestions solely to develop or improve the Service, without compensation or attribution. This license applies to the suggestions themselves and does not expand any permission to use accompanying Customer Content, Confidential Information, or personal information.

8. Fees, taxes, credits, and refunds

Customer shall pay the fees and applicable taxes specified in its role terms, Order, or clearly presented account transaction. Customer authorizes the payment and ledger operations necessary to carry out its confirmed funding, campaign, and payout instructions. A budget limits authorized spend subject to the stated campaign rules; it does not guarantee that the budget will be spent or a particular result achieved.

Except where applicable law or an Order provides otherwise, payments and unused advertising funds are nonrefundable. Posto shall correct duplicate or erroneous charges and refund any resulting overpayment. Posto shall refund amounts attributable to a paid Service it is unable to provide, unless Customer agrees to an appropriate service credit. Returning an unused campaign reservation to the account balance does not itself constitute a refund to the original payment method. A Customer seeking correction or a refund shall contact Posto with the relevant transaction details; nothing in this process limits a legally required refund.

Promotional credits are subject to the offer's disclosed eligibility and expiry terms, have no cash value, and are neither transferable nor redeemable for cash. Posto may withhold or reverse them for payment reversals, abuse, duplicate accounts, or other disclosed ineligibility. Test and simulation balances have no monetary value. Developer earnings and payment review are governed by the Developer Terms.

9. Confidentiality

Each receiving party shall protect the other party's Confidential Information using reasonable care, no less than the care it uses for its own similar information, and shall use it only to perform the Agreement or exercise rights expressly allowed by it. Disclosure is permitted only to personnel, providers, and advisers with a need to know who are subject to appropriate confidentiality duties. Unpublished catalogs, drafts, credentials, and nonpublic campaign or performance information remain protected even if not individually marked confidential.

Confidential Information excludes information the receiving party can demonstrate was lawfully public without breach, already known without a confidentiality duty, independently developed without using the protected information, or properly obtained from another source without restriction. If disclosure is legally required, the receiving party shall limit disclosure to what is required and, where lawful and practicable, give advance notice and reasonable assistance with protective measures. These duties continue while the information remains confidential, subject to applicable law.

10. Privacy, instructions, and prohibited submissions

The Privacy Policy describes Posto's information practices; the DPA establishes contractual duties for processing Customer Personal Data on Customer's behalf. Customer shall maintain its own accurate privacy notices, establish the lawful basis for its collection and disclosures, obtain required specific consents, honor applicable choices, and cooperate in requests and incidents. A checkbox accepting this Agreement does not constitute an End User's blanket consent.

Customer shall minimize submissions and comply with the prohibitions and controls in the relevant role terms and data notices. Pattern filtering and hashing reduce certain risks but do not guarantee anonymization or removal of sensitive information. If prohibited data is submitted or a consent failure is discovered, Customer shall promptly stop the affected transmission, notify legal@postoconnect.com, and cooperate with containment, deletion, and required notices. Posto may reject, restrict, or suspend the affected processing. No provision excuses Posto's own nonwaivable duties or prevents individuals from exercising rights.

11. Suspension, termination, and survival

Customer may discontinue use and request account closure, subject to any Order's committed term and payment obligations. Either party may terminate as an Order or applicable role terms permit. Posto may suspend or terminate access to the extent reasonably necessary to address nonpayment, material breach, security, fraud, legal risk, or harm to the Service or others, and shall provide notice when practicable. Posto may preserve relevant evidence and apply lawful settlement holds during a review.

Termination does not erase accrued fees, valid Developer earnings, permitted adjustments, or records that must be retained. Customer shall stop using restricted Posto software and credentials and disable affected integrations. Return, deletion, or pseudonymization follows the DPA and applicable documented processes; a closure request is not a representation that all retained records are anonymous. The provisions concerning accrued obligations, confidentiality, ownership, permitted retention licenses, indemnity, disclaimers, liability, dispute resolution, audits, and necessary record retention survive to the extent their purpose requires.

12. Disclaimers and service limitations

EXCEPT FOR EXPRESS COMMITMENTS IN THE AGREEMENT, THE SERVICE IS PROVIDED 'AS IS' AND 'AS AVAILABLE.' TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, POSTO DISCLAIMS IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NONINFRINGEMENT.

Posto does not guarantee advertising fill, auction placement, audience reach, revenue, conversions, profitability, the accuracy of Customer-supplied content, uninterrupted third-party services, or that an automated model output is complete or error-free. No filter guarantees detection of every unsafe, unlawful, or sensitive input. Customer shall exercise appropriate review of its advertising, generated materials, and integration choices. These limitations do not negate an express contractual obligation or a warranty that applicable law does not permit to be excluded.

13. Mutual limitation of liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, NEITHER PARTY SHALL BE LIABLE TO THE OTHER FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR LOST PROFITS, REVENUES, GOODWILL, OR DATA, ARISING OUT OF OR RELATING TO THE AGREEMENT OR SERVICE.

SUBJECT TO THE EXCEPTIONS BELOW, EACH PARTY'S TOTAL AGGREGATE LIABILITY TO THE OTHER ARISING OUT OF OR RELATING TO THE AGREEMENT OR SERVICE SHALL NOT EXCEED THE GREATER OF: (A) THE AMOUNTS PAID OR PAYABLE BY CUSTOMER TO POSTO; OR (B) THE PUBLISHER EARNINGS PAID OR PAYABLE BY POSTO TO CUSTOMER, IN EACH CASE DURING THE 12 MONTHS IMMEDIATELY BEFORE THE EVENT GIVING RISE TO LIABILITY.

This is one aggregate limit across these Terms, the applicable role terms, the DPA, and related claims, including indemnification obligations, rather than a separate limit for each document, legal theory, event, or claimant acting through the same Customer. An expressly agreed different limit or excluded claim in an applicable Order controls that variation. The limit does not release an obligation to make a payment or correction otherwise required by the Agreement; damages for a breach remain subject to this Section as permitted by law.

Neither the exclusions nor the cap applies to the extent prohibited by applicable law, including liability for fraud, willful misconduct, gross negligence, or infringement of a statutory right where that liability cannot lawfully be excluded or limited. The parties do not purport to waive nonwaivable remedies or government enforcement. These provisions allocate commercial risk; they do not promise immunity from every claim or make every privacy, confidentiality, or indemnity claim automatically uncapped.

14. Customer indemnity and defense procedure

Subject to Section 13, Customer shall defend and indemnify Posto and its affiliates against third-party claims and resulting damages, settlements, and reasonable defense expenses to the extent arising from Customer Content, Customer's property or products, unlawful instructions or use, breach of the Agreement, or violation of another person's rights. The relevant role terms identify additional covered third-party claims and beneficiaries; they do not create duplicate recovery or a separate liability cap.

Posto shall give prompt notice of a covered claim, provide reasonable cooperation at Customer's expense, and permit Customer to control its defense through competent counsel. A delay in notice reduces the obligation only to the extent Customer is materially prejudiced. Posto may participate through its own counsel at its own expense. Customer shall not settle a claim by admitting fault for, imposing a nonmonetary obligation on, or failing to release an indemnified party without that party's prior written consent, which shall not be unreasonably withheld. This indemnity does not require reimbursement to the extent prohibited by law or to the extent a claim results from the indemnified party's own breach or unlawful conduct.

15. Governing law and court forum

The Agreement and disputes arising out of or relating to it are governed by Delaware substantive law, without applying conflict-of-laws rules that would select another jurisdiction's law, subject to applicable mandatory law. The Federal Arbitration Act governs the arbitration agreement and its enforcement. The arbitration seat and court forum are separately specified and do not change Posto's state of incorporation.

For a proceeding permitted in court under Sections 16 and 17, the parties consent to the jurisdiction of the state courts located in New York County, New York, and the United States District Court for the Southern District of New York where that court has subject-matter jurisdiction, and to venue there. This selection does not create federal jurisdiction or restrict a nonwaivable statutory forum, an eligible small-claims proceeding, or enforcement of an award or urgent protective relief in another competent court where necessary.

16. BINDING ARBITRATION AND INFORMAL RESOLUTION

Before commencing arbitration, a party shall send the other a written dispute notice describing the parties, relevant facts, and requested relief. Notices to Posto shall be sent to legal@postoconnect.com; Posto may send notices to Customer's designated account email. The parties shall attempt in good faith to resolve the dispute for 30 days after receipt. This negotiation process is separate from arbitration and does not authorize either party to impose a settlement. A party need not delay an urgent protective application or a filing necessary to preserve a limitation period; the parties may continue the informal process while that filing is pending.

EXCEPT FOR THE EXCEPTIONS IN THIS SECTION, CUSTOMER AND POSTO AGREE THAT ANY DISPUTE OR CLAIM ARISING OUT OF OR RELATING TO THE AGREEMENT OR SERVICE SHALL BE RESOLVED BY BINDING ARBITRATION ADMINISTERED BY THE AMERICAN ARBITRATION ASSOCIATION (AAA). A NEUTRAL ARBITRATOR, RATHER THAN A JUDGE OR JURY, SHALL DECIDE THE DISPUTE AND MAY ISSUE AN ENFORCEABLE AWARD. JUDICIAL REVIEW OF AN AWARD IS LIMITED AS PROVIDED BY LAW.

Arbitration shall proceed before one neutral arbitrator under the applicable AAA Commercial Arbitration Rules, except where AAA determines that other rules or a different fee schedule apply to the parties or dispute. This includes any applicable rules or fee treatment for an individual platform user, sole proprietor, or independent contractor. The legal seat shall be New York County, New York; proceedings shall be in English. Hearings may be conducted remotely or by document submission as agreed or directed under the applicable rules, subject to legally required accommodations and procedures.

Filing fees, administrative costs, arbitrator compensation, and allocation shall follow the applicable AAA rules and fee schedule unless the parties lawfully agree otherwise or applicable law requires otherwise. No Customer shall be required to bear charges that applicable law or binding AAA requirements allocate to Posto. Each party shall bear its own legal expenses unless an applicable statute, the Agreement, or a lawful award provides otherwise. Current rules and fees are available at https://www.adr.org/rules-forms-and-fees/.

Either party may bring its own eligible claim in a competent small-claims court. A party may seek temporary or preliminary relief needed to protect confidential information, intellectual property, security, assets, or the effectiveness of arbitration from a competent court without waiving arbitration of the merits. Proceedings to compel arbitration or confirm, enforce, or lawfully challenge an award may be brought in a court with jurisdiction. Claims that applicable law does not permit to be arbitrated remain outside this agreement to arbitrate. Nothing restricts a lawful report, complaint, or cooperation with a government agency.

The arbitrator may award the relief available under applicable law, subject to valid contractual limitations, and shall provide a reasoned written award. The existence and enforceability of an arbitration agreement remain subject to determinations required by law. This Section applies between the contracting parties and does not itself bind an End User who has not agreed to arbitrate with Posto.

17. INDIVIDUAL PROCEEDINGS AND JURY-TRIAL LIMITATIONS

TO THE EXTENT PERMITTED BY APPLICABLE LAW, CUSTOMER AND POSTO SHALL BRING COVERED CLAIMS AGAINST EACH OTHER ONLY IN THEIR INDIVIDUAL CAPACITIES, AND NOT AS A CLASS OR COLLECTIVE PLAINTIFF OR REPRESENTATIVE. NEITHER PARTY CONSENTS TO CLASS OR COLLECTIVE ARBITRATION OR TO AN ARBITRATOR CONSOLIDATING DIFFERENT CUSTOMERS' CLAIMS WITHOUT ALL AFFECTED PARTIES' EXPRESS AGREEMENT. FOR CLAIMS PROPERLY PROCEEDING IN COURT BETWEEN THE PARTIES, EACH PARTY WAIVES A JURY TRIAL ONLY TO THE EXTENT SUCH A WAIVER IS LAWFUL AND ENFORCEABLE.

These limitations do not waive nonwaivable representative remedies, public injunctive relief, privacy rights, or other statutory rights or enforcement mechanisms. If a limitation is unenforceable for a particular claim or remedy, that claim or remedy shall proceed in the forum required by law, and the remaining enforceable provisions continue to apply. A court proceeding may be stayed pending arbitration where law permits; no stay is required by this Agreement where it would defeat a nonwaivable right. No provision authorizes class arbitration without the parties' express agreement.

18. Assignment, force majeure, and general provisions

Neither party may assign the Agreement without the other's consent, except in connection with a merger, reorganization, or sale of substantially all the relevant business or assets, provided the successor assumes the applicable obligations. An assignment does not expand permitted use of personal or Confidential Information.

Neither party is liable for a delay or failure caused by an event beyond its reasonable control to the extent it could not reasonably prevent or mitigate the event; the affected party shall take reasonable steps to resume performance. This provision does not excuse accrued payment obligations or nonwaivable legal duties. The parties are independent contractors. No employment, partnership, agency, or joint venture is created solely by the Agreement.

A failure to enforce a provision is not a continuing waiver. If a provision is unenforceable, it shall be applied to the extent legally permissible and the remainder shall remain effective, subject to the specific dispute-resolution rules above. The Agreement constitutes the parties' agreement concerning its subject matter and supersedes prior discussions on that subject. Third-party indemnified beneficiaries may enforce the indemnity expressly granted to them, subject to its procedure and limits; no other third-party contractual rights are intended except as law requires.

19. Updates and electronic notices

Posto may propose updated Terms or role terms by publishing a new version and providing notice reasonably appropriate to the change. Material contractual changes shall take effect for an existing Customer only after any required notice and affirmative acceptance or other legally sufficient agreement. The applicable accepted version remains relevant to earlier events; a posted revision alone does not retroactively alter an accrued dispute.

Customer shall maintain a current notice email. Routine service and legal notices may be delivered electronically, subject to mandatory delivery requirements and any specific notice procedure in an Order. Records of acceptance identify the documents and versions presented; an acknowledgment that a privacy notice was made available is not a waiver of privacy rights.

20. Contact and formal notices

Legal and dispute notices, privacy and data-rights requests, appeals, and DPA matters: legal@postoconnect.com. Postal address: 131 Continental Drive Suite 305, Newark, DE 19702. Where a law or Order requires postal service or another delivery method, the sender shall comply with that requirement. Security reports: legal@postoconnect.com. Contracting entity: PostoX, Inc.

Advertiser Terms

Additional contractual terms for business entities and sole proprietors that create, fund, purchase, or manage advertising through Posto. These Terms supplement the Terms of Service.

Effective 2026-10-02 · Version 2026-10-02 · Permanent version

1. Advertiser authority and responsibilities

Advertiser shall be responsible for its account, Authorized Users, agents, campaign instructions, advertised products and services, creatives, offers, claims, disclosures, and landing destinations. Advertiser shall complete requested business verification and possess ownership or documented legal authority to advertise each product, brand, creative, destination, and associated intellectual property.

An agency, reseller, or other intermediary shall maintain authority to act for each represented business, identify that business when reasonably requested, and ensure that its instructions and submissions comply with the Agreement. Acting through an intermediary does not excuse the contracting Customer's obligations or create authority that the represented business has not granted.

2. Advertising standards

Advertiser shall ensure that each advertisement and destination satisfies the following requirements throughout the campaign:

  • Claims shall be truthful, current, adequately substantiated, and not misleading by statement, omission, presentation, or destination. Advertiser shall possess competent substantiation before making an objective claim and retain supporting records for the campaign and any reasonably relevant dispute or legal period.
  • Advertisements and destinations shall comply with applicable advertising, consumer-protection, intellectual-property, platform, and industry requirements and Posto's applicable published standards. Advertiser shall supply required sponsorship, endorsement, affiliate, material-connection, subscription, and recurring-charge disclosures.
  • Advertiser shall not promote illegal, infringing, deceptive, discriminatory, malicious, or unsafe content or products. A category restricted by Posto requires Posto's prior written approval, which does not authorize conduct prohibited by law.
  • Prices, availability, geographic limits, eligibility conditions, recurring charges, cancellation and refund conditions, and other material limitations shall be accurate and readily available where needed to avoid deception. Advertiser shall promptly update or pause a campaign when its content becomes materially inaccurate.

3. Campaign instructions and auction delivery

The budgets, objectives, target metrics, dates, eligible products, bids, and constraints confirmed by Advertiser constitute its campaign instructions. Posto may use automated matching and campaign-assistance systems within the configured controls. Advertiser shall review suggested or generated content and authorize publication through the applicable workflow; connecting a catalog or importing an unpublished listing does not itself authorize advertising that listing.

Auction delivery, placement, fill, and results are not guaranteed. Unless an Order expressly provides otherwise, eligible impressions are priced under the applicable disclosed auction rules, subject to bid, relevance, Publisher floor, pacing, available budget, and safety or eligibility controls. A target metric is an optimization instruction rather than a warranty of a particular outcome.

4. Funding, spend, and credits

Advertiser shall maintain sufficient available funds and pay valid advertising spend, applicable taxes, and chargeback or processor fees disclosed at checkout or in an Order. A campaign budget caps authorized spend under the campaign rules and does not require Posto to deliver enough advertising to spend that amount.

Unused campaign reservations return to the Posto account balance under the applicable product rules; they are not automatically refunded to the original payment method. Payments and unused funds are subject to the general nonrefundability rule in Section 8 of the Terms of Service, including its exceptions for legally required refunds, correction and refund of duplicate or erroneous overpayments, and a refund for a paid Service Posto cannot provide unless Advertiser agrees to an appropriate service credit.

Promotional credits are available only under the offer's disclosed eligibility and expiry conditions, have no cash value, and are not transferable or redeemable for cash. Posto may withhold or reverse a credit for a payment reversal, dispute, abuse, duplicate account, or other disclosed ineligibility. Simulation and test balances do not represent money.

5. Measurement and conversion accuracy

Posto measures delivery using authenticated application events and its tracking controls. Advertiser may enable the browser Pixel for supported website events and use the Conversion API, supported store integration, or trusted mobile measurement partner for eligible server-confirmed outcomes. The Advertiser Event and Conversion API Data Notice governs the relevant submissions and their handling.

Advertiser shall report genuine actions, use the same stable deduplication identifier for the same action across channels and retries, preserve the Posto click identifier required for final-event attribution, and provide accurate event time, transaction information, value, and currency. Advertiser shall correct or reverse outcomes that are cancelled, refunded, or invalid under the applicable event rules. Posto may reject, deduplicate, reverse, or exclude unsupported, unverifiable, fraudulent, or otherwise invalid events and may reconcile reporting and related charges accordingly.

6. Data use, privacy, and catalog confidentiality

Advertiser may use Posto reports to evaluate and operate its own campaigns. Advertiser shall not attempt to identify End Users, combine reports into sensitive profiles, target prohibited categories, or use Posto-provided data to train a model unrelated to campaign operation without Posto's written permission and any independently required legal authority. Posto does not disclose submitted ad-request transcripts to Advertisers through campaign reporting.

Advertiser shall provide accurate notices and obtain the lawful basis and specific permissions required for its measurement, browser storage, connected-store access, and disclosures to Posto. The standalone Pixel requires Advertiser's implementation of applicable consent and opt-out controls. Acceptance of the Agreement does not supply an End User's consent.

Customer Content remains subject to the ownership, limited license, and confidentiality provisions of the Terms of Service. Draft, archived, and unlisted catalog materials are not public merely because an integration imports them. Advertiser shall configure publication and data access within its authority and shall not include prohibited sensitive information in events, URLs, or submitted content.

7. Review, enforcement, and reconsideration

Posto may conduct automated checks and manual review before or after delivery and may request identity, agency authority, ownership, claim-substantiation, licensing, supply-chain, or destination records. Posto may reject, restrict, pause, preserve relevant evidence concerning, or remove content or campaigns to address applicable law, published standards, security, fraud, or credible account risk. Review or approval does not transfer Advertiser's responsibility for its advertising to Posto.

Advertiser may seek reconsideration through the support channel or legal@postoconnect.com by identifying the campaign and supplying relevant evidence. Posto shall provide a reason when legally and operationally practicable, subject to protection of investigations, security controls, and third-party information. Restoration does not validate previously invalid activity or eliminate accrued obligations.

8. Advertiser indemnity

Subject to Sections 13 and 14 of the Terms of Service, Advertiser shall defend and indemnify Posto and participating Developers against third-party claims and resulting covered losses to the extent arising from Advertiser's advertisements, products, destinations, offers, instructions, data, measurement events, regulatory noncompliance, or breach of these Advertiser Terms. The defense procedure, exclusions, aggregate liability limit, and prohibition on duplicate recovery in the Terms of Service apply. This provision does not impose liability for an indemnified party's own breach or unlawful conduct beyond what the Agreement and applicable law permit.

Developer Terms

Additional contractual terms for business entities and sole proprietors that supply advertising inventory or integrate Posto into an application, service, or placement. These Terms supplement the Terms of Service.

Effective 2026-10-02 · Version 2026-10-02 · Permanent version

1. Authorized properties and integrations

Developer shall use supported Posto SDKs, APIs, credentials, and documented test paths and shall register each application and placement accurately. Developer shall own each registered property or hold written authority from its owner, provide an official app-store listing or verified domain when requested, disclose material resellers or supply intermediaries, and keep package, bundle, domain, placement, and traffic-source declarations current.

Web applications shall use a Developer-controlled backend relay with server HMAC authentication. Supported native integrations shall use the required Apple App Attest or Google Play Integrity proof. Developer shall not embed server secrets in browser code or mobile binaries, circumvent integrity checks, or use a non-billable test path as production inventory.

2. End User experience and advertising disclosures

Developer controls its property and shall provide the notices, permissions, and lawful basis required to transmit context and display advertisements. Every advertisement shall be visually distinguishable from organic content and shall display the SDK-prescribed 'Sponsored' or 'Ad' label clearly and conspicuously, as close as reasonably possible to the headline or other primary focal point, on every supported device.

Developer shall not remove, obscure, minimize, misplace, or delay that disclosure; materially alter an advertisement without authority; force a click; or create a deceptive placement. A format in which the required disclosure cannot remain clear and conspicuous shall not serve Posto advertisements. Where necessary to prevent deception, an affiliate destination shall also be accompanied by a disclosure that Posto or the relevant party may earn a commission.

3. Data minimization and privacy notices

Developer shall submit only the bounded recent messages and optional coarse demographic fields allowed by the SDK Data Handling Notice, run the supplied filtering, and refrain from disabling or bypassing server filtering. Developer shall not submit names, contact details, authentication secrets, payment information, precise location, street addresses, protected health information, biometric or government identifiers, children's personal information, or other prohibited sensitive data. Filtering has limitations and does not authorize otherwise prohibited submissions.

Developer shall maintain an accurate, publicly accessible privacy notice identifying Posto as an advertising and measurement provider, linking to Posto's legal notices, and describing the categories, purposes, recipients, retention, and choices relevant to its integration. Developer shall obtain any required specific consent, including for storage or access technologies, and honor applicable platform and legally binding universal privacy signals. Posto does not currently approve child-directed production integrations.

4. Event validity and invalid traffic

Developer shall record an impression only after the advertisement is rendered and viewable under the applicable documentation and shall record a click only after an intentional human action. Developer shall take reasonable measures to detect and stop invalid activity and shall cooperate with a reasonable investigation.

Developer shall not cause or authorize bots, device farms, click injection or spamming, undisclosed incentives, forced redirects, deceptive pop-ups, self-clicks, replayed tokens, concealed traffic sources, manipulated context, spoofed SDK or location information, emulators outside documented test paths, or other inflation or fabrication of requests, impressions, clicks, installs, or conversions.

Posto may classify traffic as valid, observe, held, or invalid and may withhold, adjust, offset, or reverse affected earnings and restrict related payments while evidence is reviewed. Such action shall relate to the applicable invalid activity, credible risk, or lawful obligation; confirmed invalid activity does not become payable merely because an account is restored.

5. Shopping cards and affiliate programs

When Developer enables shopping cards for the looks in its content, Developer authorizes Posto to place affiliate links with participating networks and retailers in Developer's property. The program terms of those networks and retailers that Posto makes available apply to the shopping cards in Developer's property, and Developer shall comply with them.

Developer shall not offer coins, episode unlocks, rewards, or any other incentive for tapping a card or making a purchase, or connect a tap to any reward system. Developer shall open a card link only after a viewer's intentional tap, in the device's browser where the platform allows, and shall not use browser extensions, toolbars, automatic redirects, prefetching, hidden frames, or cookie stuffing. Developer shall not route traffic from another affiliate network or sub-network through Posto.

Developer shall provide, within 24 hours of a request, the information about the property, its audience, and its traffic that a network or retailer reasonably requires. Posto may remove a property, title, episode, or retailer from shopping cards at its own discretion or at the request of a network or retailer, including for a retailer's brand-safety requirements.

Any share of affiliate commissions payable to Developer is set out in the applicable Order or console setting and becomes payable only after the network reports the commission as final, net of returns, cancellations, reversals, and the network's deductions.

6. Earnings, supplier payments, and taxes

Developer supplies valid advertising inventory and related integration services as an independent business and controls operation of its property. The Agreement does not create employment, agency, partnership, or representative authority, and does not override a classification required by applicable law.

Valid Publisher earnings are calculated from finalized billable impressions after the applicable Posto fee. A minimum CPM applies only when expressly stated in an executed Order or eligible placement setting and only to finalized valid impressions. It does not guarantee payment for test, observe, held, invalid, unsupported, or no-fill traffic. Simulation balances have no cash value.

Finalized eligible earnings are an accounts-payable obligation of Posto, rather than a deposit, stored-value account, escrow balance, or segregated advertiser fund. There is no contractual right to an instant or automatic withdrawal. When the payment-request feature is enabled, Developer may request ACH payment after finalized available earnings reach the displayed minimum. Each request remains subject to Posto review, approval through the payment provider, fraud and compliance holds, and lawful withholding, adjustment, offset, or reversal. These controls do not extinguish an otherwise valid payment obligation.

A payment statement generated by Posto may serve as a self-billing record. Developer shall report a good-faith amount dispute promptly through support with the relevant statement and evidence; this request for prompt reporting does not shorten a nonwaivable statutory period.

Developer shall provide accurate legal name, address, banking details, taxpayer status, and any requested Form W-9, Form W-8, or other required documentation through the designated secure channel and shall promptly report changes. Developer is responsible for its income, employment, sales, use, value-added, and similar taxes, excluding taxes imposed on Posto. Posto may validate information, withhold payment or tax when legally required, and file and deliver required information returns. Payment-provider setup or acceptance does not establish that a tax authority has accepted a tax form or taxpayer identification number.

7. Security and supported versions

Developer shall protect credentials, signing keys, app identifiers, and administrative access; promptly install security-critical SDK updates; and maintain supported application versions. Developer shall notify legal@postoconnect.com promptly after discovering compromise, an integrity-verification failure, or suspected invalid traffic and shall cooperate in containment. Posto may rotate credentials or suspend an unsafe integration to address the risk.

8. Property content, compliance, and rights requests

Developer represents that it owns or has the necessary rights to its property and submitted content and that the integration complies with applicable platform, privacy, consumer-protection, advertising, commerce, intellectual-property, and product requirements and Developer's published notices. A property shall provide substantive, authentic functionality and shall not exist primarily to display advertisements.

Prohibited properties include child-directed services, services soliciting protected health information for ad matching, malware, deceptive or infringing services, and properties whose principal traffic source is undisclosed or invalid. Developer shall respond to End User requests within its responsibilities and forward requests requiring Posto's processor assistance. An End User remains free to contact Posto directly and exercise applicable statutory rights.

9. Review, suspension, appeal, and termination

Posto may use integrity checks, traffic analysis, and manual review to verify property ownership, integration, content, disclosures, and traffic quality. To investigate credible risk, Posto may pause a property or placement, delay a payment, hold affected earnings, rotate credentials, or suspend access as reasonably necessary.

Where practicable, Posto shall identify the relevant policy category and permit Developer to submit ownership records, implementation evidence, or a traffic explanation through support. Security-sensitive information and third-party data may be withheld. Confirmed invalid activity remains ineligible after restoration. On termination, Developer shall remove or disable affected Posto SDKs and credentials as directed; valid accrued earnings and permitted adjustments remain governed by the Agreement.

10. Developer indemnity

Subject to Sections 13 and 14 of the Terms of Service, Developer shall defend and indemnify Posto and participating Advertisers against third-party claims and resulting covered losses to the extent arising from Developer's property, placements, data collection, disclosures, invalid traffic, unauthorized modifications to advertisements, or breach of these Developer Terms. The defense procedure, exclusions, aggregate liability limit, and prohibition on duplicate recovery in the Terms of Service apply. This provision does not impose liability for an indemnified party's own breach or unlawful conduct beyond what the Agreement and applicable law permit.

SDK Data Handling Notice

The data accepted and returned by Posto's advertising SDK interfaces and the integration duties that accompany their use. This Notice forms part of the integration requirements under the Terms of Service and Developer Terms.

Effective 2026-10-02 · Version 2026-10-02 · Permanent version

1. Permitted request data

A production ad request includes a placement identifier, format, and recent interaction context permitted by the applicable integration documentation. Developer shall comply with the supported content schema and size limits and shall submit no more information than necessary for the requested advertising function. Detailed implementation requirements are supplied through the applicable developer documentation.

Developer may optionally submit an age range of 18–24, 25–34, 35–44, 45–54, or 55+; a gender value of women, men, or non-binary; and coarse country, region, or city, where obtained from a lawful first-party source. The interface does not accept GPS coordinates, postal codes, street addresses, interests, arbitrary user attributes, user identifiers, images, or commerce dictionaries as contextual fields. The listed schema is a limit on submissions, not authorization to infer or collect a prohibited sensitive characteristic.

2. Filtering, residual information, and retention

The integration includes input-filtering controls. Developer shall use the supplied filtering and shall not disable or evade it. Such controls can miss identifiers, sensitive subject matter, or combinations that reveal an individual. Filtered or redacted information shall therefore not be presumed anonymous, and filtering is not permission to send prohibited information.

Ad-request text and related original or derived text retained as delivery or diagnostic copies are removed under the applicable 30-day retention schedule and may be deleted earlier. Structured categories and numeric measures, hashes, event identities, risk outcomes, and permitted aggregates may remain for their separate operational or legal periods. Non-billable SDK test records and tokens are retained for 7 days. These periods do not authorize retaining an undisclosed copy of a conversation or treating pseudonymous residual records as anonymous.

3. Advertising selection and automated processing

Posto uses permitted request information and applicable campaign or audience constraints to select eligible advertisements and support the enabled Service functions. Optional demographic information shall be limited to the permitted audience purpose and shall not be used to create an unrelated profile.

Third-party AI service providers may process submitted information necessary for enabled advertising or assistance functions, as described in the Privacy Policy and provider disclosure. Input filtering does not guarantee that this information contains no personal information. Customer shall not submit sensitive conversations or rely on an assumption that every unsafe context will be suppressed.

4. Authentication and integrity

Web and backend integrations use per-application server HMAC authentication. Supported iOS direct requests use Apple App Attest and supported Android direct requests use Google Play Integrity. Applicable proofs and signed request controls bind app or installation information, request hashes, timestamps, and idempotency values to limit spoofing and replay.

The ad-request interface does not require a Customer-supplied advertising identifier or hardware serial number. Verification still involves technical and potentially personal information, including integrity proofs and request metadata. Non-attested test endpoints are non-billable and return test-only advertisements. Developer shall protect server credentials and use each authentication path only as documented.

5. Response fields and token confidentiality

A filled response contains a request identifier and one advertisement with its identifier, format, advertiser, headline, body, call to action, optional image URL, required image alternative text, and private impression and click tokens. A no-fill response contains the request identifier and a null advertisement.

The initial response does not expose the landing URL, auction identifier, match scores, internal product information, or raw tracking endpoints. The SDK shall retain tracking tokens privately for their intended event flow. Developer shall not extract or repurpose them to bypass verification or identify End Users.

6. Impressions, clicks, and disclosure

Developer shall invoke the SDK's impression method only after rendering the advertisement as required by the documentation. On an intentional human click, the SDK submits the signed click event; after validation, Posto returns a short-lived redirect URL that the SDK opens. Duplicate or replayed submissions are handled through the applicable idempotency controls and shall not be used to generate additional billable activity.

Developer shall display the prescribed advertising label clearly and conspicuously and comply with the affiliate-disclosure requirements where applicable. An impression, click, or contractual acceptance is not a substitute for any separate privacy consent required for the underlying processing.

7. Developer privacy responsibilities and requests

Developer shall maintain an accurate, easily accessible notice identifying Posto, linking to Posto's legal notices, and explaining the categories, purposes, recipients, retention, and choices applicable to its actual integration. Developer shall obtain a lawful basis and required specific consent, honor applicable platform requirements and legally binding privacy signals, avoid prohibited children's or sensitive information, minimize inputs, and provide a secure means of exercising rights.

Processor-assistance requests may be sent to legal@postoconnect.com. End Users may contact Developer or Posto directly; contacting Developer first is not a condition of exercising a statutory right. Developer's obligations supplement Posto's own obligations under the Agreement and applicable law rather than replacing them.

Advertiser Event and Conversion API Data Notice

The collection, validation, attribution, correction, and retention of events submitted through the browser Pixel, Conversion API, connected-store, and supported mobile measurement integrations.

Effective 2026-10-02 · Version 2026-10-02 · Permanent version

1. Purposes and event channels

A Posto Event Source may receive optional browser Pixel events, authenticated Conversion API events, supported connected-store events, and events from a trusted mobile measurement partner. Funnel events support the configured measurement, diagnostics, and optimization functions. Only supported final events, including purchase, generate_lead, and app_install, are projected into click attribution and conversion accounting under the applicable event rules.

An integration shall be enabled only for the Advertiser's authorized property and disclosed purposes. The presence of integration code does not mean a feature is active or that a visitor has given consent.

2. Verified domains and confidential credentials

A public Pixel identifier identifies an Event Source and may be used by the Posto Pixel on an exact verified HTTPS domain. It is not a secret or a substitute for domain verification. A Conversion API key is a confidential server credential and shall not be included in browser JavaScript, a tag-manager value exposed to a page, or a mobile binary. Mobile final events shall be transmitted by a trusted backend or authorized measurement partner.

Advertiser shall protect connected-store authorization tokens, use only the scopes and properties it is authorized to connect, rotate compromised credentials, and disable access when authority ends. Authentication verifies a technical submission; it does not establish that its collection or content is lawful.

3. Event fields and connected-store information

Events include a supported name and event time and may include a source URL, stable dedupe_id, Posto click identifier, and permitted event-specific data. Under the current Conversion API purchase schema, a purchase requires a transaction identifier, value, and USD currency; other supported channels shall follow their documented currency and event requirements. A final event requires the Posto click identifier for attribution.

Optional email, phone, client, or user identifiers are accepted only for permitted measurement support. Posto normalizes and SHA-256 hashes accepted values before storing them in event records; transient receipt occurs before hashing. A hash can remain linkable to an individual and is not treated as anonymous merely because plaintext is not retained.

The standalone Pixel may transmit the current page's full URL, including query parameters or a fragment, and use a persistent client identifier and a stored Posto click identifier. Advertiser shall prevent sensitive or unrelated personal information from entering transmitted URLs and shall send only permitted event fields.

Shopify checkout events may include order and checkout identifiers, click and client identifiers, totals, and currency. Shopify order and refund webhooks can transiently deliver broader JSON payloads, including customer details and line items. Posto selects information used for attribution, order status, refund calculations, and reconciliation; refund line items may be read to calculate an amount. Incoming transient payloads are distinct from the selected records retained by Posto.

Advertiser shall not submit names, street addresses, precise location, payment-card data, passwords, authentication secrets, health information, conversation content, or unrelated customer records through measurement fields. Supported store payload handling does not authorize Advertiser to add those details to optional API fields.

4. Deduplication and attribution

Advertiser shall use the same stable dedupe_id when multiple channels or retries report the same real-world action. Posto retains durable deduplication evidence so later retries do not create duplicate results. A Posto click identifier links a supported final event to the authenticated click and associated campaign, advertisement, application, and placement.

An unknown but well-formed click identifier may be recorded as unmatched. A final event lacking a required click identifier is rejected as an integration error. Attribution is limited to the applicable documented window and valid event conditions; submitting an event does not guarantee attribution, payment, or a particular campaign result.

5. Security, browser storage, and privacy choices

Advertiser shall use TLS, secret management, least privilege, stable idempotency, and appropriate key rotation. The Pixel shall operate only on controlled and verified domains after the required notice and subject to applicable consent and opt-out choices. Posto may record authentication and request metadata for abuse prevention and reject an unverified origin, invalid credential, unsafe content, or unsupported schema.

The standalone Pixel does not provide an internal universal consent or Global Privacy Control gate. Advertiser shall implement any required controls over script loading, browser storage, event transmission, withdrawal, and applicable opt-out signals. Its local-storage client identifier has no automatic expiry; the locally stored Posto click identifier has a 30-day validity period. Browser clearing and applicable preference or deletion controls affect local values separately from server retention.

The Shopify web-pixel integration uses Shopify's customer-privacy controls, including marketing-permission handling and clearing stored click information on withdrawal in that integration. This does not govern a separately installed standalone Pixel or relieve Advertiser of its own configuration and privacy duties.

6. Processing roles and individual rights

Advertiser shall establish the lawful basis, give required notices, obtain specific consent where required, ensure event accuracy, and handle rights requests within its responsibilities. Posto processes Customer Personal Data on Advertiser's instructions where the legal processor or service-provider requirements are met and determines certain security, billing-integrity, and legal-compliance purposes independently where permitted. Actual activities and applicable law determine the role; the DPA applies to processing on behalf of Advertiser.

Individuals may contact Advertiser or legal@postoconnect.com to exercise applicable rights. Posto shall assist the responsible business or respond as its role and law require. Neither a tracking identifier nor acceptance of a business agreement waives an individual's privacy rights.

7. Corrections, deletion, and residual records

Advertiser shall correct or reverse final events when an outcome is cancelled, refunded, or otherwise invalid under the applicable event rules. Posto may update attribution and financial reconciliation accordingly while preserving the evidence necessary to explain an adjustment.

Raw advertiser event payloads and diagnostics are scheduled for removal after 30 days, including source URLs, event-row copies of click and deduplication values, optional identifier hashes, and raw or normalized payloads. Event identities, names, times, channels, validation and attribution outcomes, payload hashes, durable deduplication evidence, canonical conversion links, permitted aggregates, and necessary financial or fraud-audit records may remain for their documented operational or legal period. A retained hash or reference is not necessarily anonymous.

A shopper privacy request, store disconnection, deletion of saved catalog content, and account closure are different operations. Disconnecting a store does not necessarily remove products, product sets, images, or other merchant materials already saved in the workspace. Shopper erasure does not require treating merchant-owned campaign assets as shopper data. Required financial and legal records may remain with their use restricted.

Privacy requests and correction assistance may be directed to legal@postoconnect.com. Posto shall apply the process and retention exception appropriate to the requested records; a 30-day server cleanup does not automatically erase browser storage or every related business record.

Data Processing Addendum

Contractual requirements governing personal information that Posto processes on a Customer's behalf. Processing roles and mandatory rights are determined by the actual activities and applicable law.

Effective 2026-10-02 · Version 2026-10-02 · Permanent version

1. Parties, incorporation, and precedence

This Data Processing Addendum ('DPA') forms part of the Agreement between PostoX, Inc ('Posto') and the business entity or sole proprietor accepting the Terms of Service or an applicable Order ('Customer'). It applies to Customer Personal Data processed by Posto on Customer's behalf in providing the contracted Service.

This DPA controls an express conflict with other provisions of the Agreement concerning the regulated processing obligations it addresses. The Terms of Service continue to govern commercial matters, including their aggregate liability limit, indemnity procedure, governing law, and dispute resolution, except to the extent an expressly agreed provision or mandatory law requires otherwise. Nothing in the Agreement limits a data subject's nonwaivable rights, a regulator's powers, or mandatory terms of a separately completed transfer mechanism.

2. Definitions and activity-specific roles

Personal data or personal information means information regulated as such by applicable data-protection law. Processing, controller, processor, business, service provider, contractor, data subject, personal-data breach, and supervisory authority have the meanings assigned by the law applicable to the relevant activity. Customer Personal Data means personal information processed by Posto on Customer's behalf under the Agreement, including information described in Annex I when used in that capacity.

Customer acts as controller or business, or as a processor acting with its controller's authority, for Customer Personal Data it instructs Posto to process. Posto acts as processor, service provider, contractor, or subprocessor only to the extent its actual processing and the applicable legal requirements support that role. Customer shall have authority to appoint Posto when acting for another controller.

Posto may determine separate purposes for account administration, independently determined security and fraud prevention, billing, legal compliance, and its business records where permitted by law. The Privacy Policy describes those activities. Labeling an activity 'security,' 'improvement,' or 'measurement' does not by itself remove it from this DPA or permit use beyond a lawful service-provider or processor role.

3. Documented instructions and use restrictions

Customer instructs Posto to process Customer Personal Data to perform the contracted activities described in the Agreement, the applicable service notices, and Customer's lawful configurations and confirmed instructions. Instructions shall be specific enough to identify the permitted purpose and shall not authorize unrelated profiling, publication of confidential materials, or a restricted transfer without the required arrangement. Posto shall process Customer Personal Data only on those instructions, unless applicable law requires otherwise; Posto shall inform Customer of such a requirement before processing unless legally prohibited.

Where Posto acts as a service provider or contractor under the California Consumer Privacy Act, Posto shall not sell or share Customer Personal Data; retain, use, or disclose it for a purpose other than the specified business purposes permitted by the Agreement and applicable law; or retain, use, or disclose it outside the direct business relationship except as the law permits. Posto shall not combine it with information received from another person or collected through its own interaction with an individual except where applicable law expressly permits the combination for the specified service purposes. Posto certifies that it understands and shall comply with these restrictions.

Posto shall not use Customer Personal Data to create another Customer's advertising profile or train an unrelated model. Security, fraud prevention, service integrity, permitted service improvement, and aggregate or deidentified measurement remain subject to the applicable instructions, confidentiality duties, and legal restrictions. Information is deidentified only if the applicable legal standard and required safeguards are met; hashes and filtered text do not qualify automatically.

Posto shall notify Customer if it determines that it can no longer meet its applicable data-protection obligations. If Posto reasonably believes an instruction violates applicable law, Posto shall inform Customer unless prohibited and may suspend the affected processing while the parties resolve the issue. Customer may take reasonable and appropriate steps to verify permitted use and, on notice, stop and remediate unauthorized use, including through the assistance and audit process below.

4. Customer instructions, lawful basis, and minimization

Customer shall supply lawful instructions, accurate notices, a valid legal basis, and any specific consent required for collection and disclosure to Posto, including browser storage or access where applicable. Customer shall respect applicable choices and binding privacy signals and maintain authority for the information it submits. Contract acceptance does not replace an End User's legally required consent.

Customer shall minimize submissions, maintain the accuracy required for the processing, configure audience and retention choices lawfully, and refrain from submitting unnecessary or prohibited sensitive information. Customer shall promptly notify Posto of unlawful submissions or material changes affecting the processing and cooperate on correction, deletion, and rights requests. These duties do not excuse Posto's own statutory or contractual obligations.

5. Confidentiality and security obligations

Posto shall ensure that personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations and receive access only as needed for authorized work. Posto shall maintain technical and organizational safeguards appropriate to the nature, scope, context, and risk of the processing, including the applicable measures described in Annex II.

Posto may update safeguards as technology and risk change while maintaining an appropriate level of protection. A technical control applies to the interface or environment for which it is designed; no statement in this DPA represents that filtering removes all sensitive information, that hashing anonymizes records, or that every integration uses an identical security mechanism.

6. Subprocessor authorization and changes

Customer grants general authorization for Posto to engage the current subprocessors whose identities and relevant processing details are made available to Customer for the applicable enabled Service, subject to this Section. The public provider-category summary is not an exhaustive named register or a substitute for information required by applicable law. Posto shall make the current details available through the account or privacy-contact process before relevant processing where required. Before a subprocessor processes Customer Personal Data, Posto shall impose written data-protection obligations appropriate to the activity and providing the protection required by applicable law. Posto remains responsible for the subprocessor's performance of those obligations to the extent required by the Agreement and law.

Posto shall maintain current subprocessor details and make updated information available before a new subprocessor begins the relevant processing. Where the Agreement or law requires individual advance notice, Posto shall send it to the affected account contact and state the proposed effective date. Customer may object before that date on reasonable data-protection grounds, identifying the concern and affected processing.

The parties shall work in good faith to address a reasonable objection through information, safeguards, an alternative provider, or a change to the affected feature where feasible. If no reasonable resolution is available, either party may terminate the affected processing or feature without requiring Customer to authorize an unlawful transfer; accrued payment duties and applicable refund rights remain governed by the Agreement. Independent payment providers and selected destinations are not subprocessors merely because they appear in the provider disclosure.

7. Individual requests and assistance

Taking account of the nature of processing, Posto shall provide reasonable technical and organizational assistance needed for Customer to fulfill applicable access, correction, deletion, portability, restriction, objection, opt-out, consent-withdrawal, and appeal obligations. Customer shall provide information reasonably needed to identify the relevant records without requiring unnecessary additional personal information.

If Posto receives a request relating to processing on Customer's behalf, Posto shall promptly inform or coordinate with Customer and assist the response, unless the law requires or permits Posto to respond directly. Posto may explain which business is responsible, but shall not require an individual to contact that business first as a condition of contacting Posto or exercising a statutory right. Verification, exceptions, and response periods shall follow the applicable law.

8. Personal-data breaches and incident cooperation

Posto shall notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data processed under this DPA. Posto shall not delay initial notice solely because an investigation is incomplete. Taking account of available information, the notice shall describe the nature and scope of the breach, affected categories and approximate quantities where known, likely consequences, protective measures taken or proposed, and a contact for further information; details may be supplied in phases without undue delay.

Posto shall take reasonable steps to contain, investigate, mitigate, and remediate the breach and provide information reasonably necessary for Customer's applicable notification duties. Notification is not an admission of fault. Each party remains responsible for notices concerning its own systems, role, and legal obligations and shall coordinate where appropriate without unlawfully delaying a required notice.

9. Assessments and regulatory consultation

Taking account of the nature of processing and information available to it, Posto shall provide information and reasonable assistance needed for Customer's applicable data-protection impact assessments, security assessments, and prior consultation with a competent authority concerning the contracted processing. Assistance shall be proportionate to the relevant risk and shall protect other Customers' information, privileged material, and sensitive security details through appropriate means rather than withholding information the law requires.

10. Return, deletion, and restricted retention

At termination of the relevant processing or on Customer's lawful request, Posto shall, at Customer's choice, return or delete Customer Personal Data through the applicable documented process, unless law requires retention. Posto shall provide available export mechanisms and, on reasonable request, confirm completion of the applicable deletion process. Deletion of one record type, shopper erasure, store disconnection, and account closure have different scopes and shall not be represented as interchangeable.

Posto may preserve information only where continued retention is permitted or required for an identified financial, acceptance-evidence, security, fraud, backup, dispute, or legal purpose. Such records shall be protected, access restricted, and use limited to that purpose. Pseudonymization is not a substitute for legally required deletion and does not make a retained record anonymous. Backup copies shall be protected from ordinary use and deleted through the applicable rotation or required deletion process.

The current retention rules are described in the Privacy Policy and applicable integration notice, including the 30-day account-closure grace period, the 30-day retention schedule for ad-request text, related delivery or diagnostic text copies, and raw measurement-event content, and longer necessary financial or legal retention. A required legal hold may suspend deletion for the affected records, but does not authorize unrelated use or unlimited retention.

11. Compliance evidence, audits, and remediation

Posto shall maintain information sufficient to demonstrate compliance with its obligations under this DPA and make appropriate current security documentation, relevant independent reports where available, or other compliance evidence available under confidentiality. Where legally required and reasonably necessary, Customer or a qualified independent auditor may assess the relevant processing on reasonable notice, during business hours, and with safeguards against disruption or access to another Customer's data.

Routine Customer audits are limited to one in a 12-month period where applicable law permits that limit. The limit does not restrict an additional assessment reasonably necessary following a material personal-data breach, credible evidence of material noncompliance, a regulator's request, or an applicable statutory requirement. The parties shall use existing evidence where it reasonably addresses the issue and agree on a proportionate scope and method.

Customer shall bear its audit costs unless material noncompliance is found or applicable law or a written agreement requires otherwise. Posto shall cooperate with a competent supervisory authority as required and take reasonable and appropriate steps to stop and remediate unauthorized processing. No audit condition waives a mandatory verification or oversight right.

12. United States scope and restricted transfers

The current offering is a United States business service. The parties shall identify any applicable international transfer restriction before introducing affected processing. Posto shall not carry out a restricted transfer without a lawful mechanism and the safeguards required for that transfer, including an appropriate onward-transfer arrangement where applicable.

If European Standard Contractual Clauses or a UK transfer addendum are required, the parties shall complete the applicable instrument, modules, party and transfer information, annexes, governing-law and forum selections, and any necessary assessment or supplementary measures before the restricted transfer begins. This DPA does not incorporate incomplete clauses or establish a blanket certification under a data-transfer framework. Mandatory terms of a completed transfer mechanism prevail over an inconsistent commercial governing-law, arbitration, liability, or other provision to the extent required.

13. Annex I — processing details

The following description covers information only to the extent processed on Customer's behalf. The enabled feature and actual instructions determine which categories apply.

  • Subject matter and purposes: contextual advertising delivery, campaign and catalog operations, creative assistance, attribution, measurement, reconciliation, Customer-requested support, and permitted security, fraud prevention, and service improvement within the contracted processing instructions.
  • Nature of processing: receipt, validation, filtering, hashing, organization, storage, retrieval, model-assisted analysis, matching, display of authorized advertising content, transmission to authorized providers, aggregation or legally compliant deidentification, correction, export, and deletion.
  • Data subjects: Customer's account representatives, participating applications' End Users, visitors and shoppers of advertised or connected properties, and individuals whose information is included in authorized support or business materials.
  • Data categories: bounded recent request text and derived context; optional permitted coarse demographics; application, placement, request, integrity-proof, impression, click, event, transaction, and conversion fields; optional hashed identifiers; technical metadata; account and business contact information; campaign, catalog, product, and image content; connected-store order, checkout, refund, and status information; and Customer questions or account context used in enabled support workflows. Filtered text, hashes, and inferred information may remain personal information.
  • Transient and provider inputs: supported store webhooks may deliver customer details or line items before selection of retained fields. Enabled third-party AI services may process permitted interaction text, product or campaign information, or Customer support questions and account context. Some submitted information may reach the relevant provider without identifier filtering and can remain personal information. The Privacy Policy and provider disclosure describe the applicable categories, purposes, and limitations.
  • Prohibited sensitive information: the current Service is not designed or approved for children's personal information, protected health information, health or crisis conversations, precise location, financial credentials, authentication secrets, government or biometric identifiers, or other prohibited sensitive categories. Any separately contemplated use requires express written service approval and an appropriate DPA amendment before it begins; a general account acceptance is insufficient.
  • Frequency and duration: processing occurs as Customer uses the enabled Service during the Agreement and the applicable documented return, deletion, and legally permitted retention periods. Long-term residual records remain limited to their identified purposes.

14. Annex II — technical and organizational safeguards

Posto shall maintain measures appropriate to the actual processing and risk, including the following as applicable to the relevant interface and environment:

  • Transport encryption for supported production communications and appropriate protection of production storage, backups, credentials, and connection secrets using the configured infrastructure and access controls.
  • Access restrictions, least privilege, confidentiality commitments, separation of production and simulation functions, controlled credentials and administrative access, and relevant operational logging.
  • Server HMAC authentication, supported Apple App Attest and Google Play Integrity verification, request hashing, signed event tokens, stable idempotency, and replay controls for the interfaces that use those mechanisms.
  • Strict request schemas, bounded context, pattern-based identifier filtering, input restrictions, configured eligibility controls, and automated cleanup for specified record classes. These controls do not guarantee universal sensitive-context detection or anonymization.
  • Risk monitoring, payment and event reconciliation, incident handling, appropriate vulnerability and dependency management, and backup and recovery procedures proportionate to service risk. Customer remains responsible for its own application, consent gate, domain configuration, and server secrets.

15. Annex III — providers and roles

The public provider disclosure summarizes cloud compute, database, storage, email, payment and payout, app-integrity, support, and third-party AI service providers. It states purposes and data categories and distinguishes subprocessors from independent providers and selected destinations where appropriate. Current identities, locations, and details needed for the applicable DPA are made available to affected Customers through the account or privacy-contact process in accordance with Section 6. A listed optional feature does not transmit information while disabled.

Provider processing locations, access, and onward transfers depend on the service configuration and applicable provider agreement; Posto shall supply information needed for a reasonable DPA or transfer assessment. A provider name or a general regional description does not establish that every service is United States-only, that no provider retains inputs, or that a provider has a contractual model-training restriction applicable to every account.

16. DPA contacts

Legal notices, privacy and data-rights requests, appeals, processor-assistance requests, subprocessor objections, and DPA notices: legal@postoconnect.com. Security reports: legal@postoconnect.com. Contracting entity: PostoX, Inc. Contact address: 131 Continental Drive Suite 305, Newark, DE 19702.

Subprocessors

A public summary of provider categories and selected recipients involved in Posto's enabled services. Current subprocessor identities and processing details required for Customer agreements are available through the account or privacy-contact process.

Effective 2026-10-02 · Version 2026-10-02 · Permanent version

Scope, provider roles, and change notices

This public disclosure summarizes provider categories and selected recipients; it is not an exhaustive named subprocessor register. A provider receives information only when the corresponding enabled feature or operational flow calls for it. A provider may act as a subprocessor for one function and independently for another, particularly payment compliance, banking, or a selected advertising destination. Actual activities, applicable law, and the provider agreement determine the role.

Posto shall update this disclosure before a new subprocessor begins relevant processing and provide individual advance notice where required by the Agreement or law. Affected Customers may send reasonable data-protection objections to legal@postoconnect.com before the stated effective date. The DPA governs authorization, objections, and appropriate contractual safeguards.

Processing and support locations depend on the provider service, configuration, and agreement. The regional descriptions below do not constitute a blanket United States-only commitment. Provider retention, abuse monitoring, training settings, and transfer safeguards also depend on the applicable service terms and account configuration; Posto does not represent that every provider offers zero retention or that a public statement establishes a restriction for every workflow.

Amazon Web Services, Inc. (AWS)

Functions: cloud compute and networking, database hosting, object storage, backups, keys and secrets, operational logs, and Amazon SES transactional email.

Information: account and business records, contextual request content, delivery and measurement events, security and financial records, stored reports and backups, recipient email addresses, and transactional message content. Contextual records can remain personal information after filtering.

Locations and role: the configured infrastructure and provider agreement govern the hosting region and any support, email-delivery, or security processing elsewhere. AWS ordinarily supplies infrastructure on Posto's behalf for these functions. An actual region commitment shall be established through the applicable service or transfer arrangement rather than inferred from this disclosure.

Stripe, Inc.

Functions: Advertiser checkout, payment confirmation, disputes, and payment-risk operations.

Information: account and business contact details, transaction identifiers and amounts, payment and dispute status, and card or bank-payment details submitted directly to Stripe Checkout. Posto does not store full card or bank-account numbers through this flow.

Locations and role: Stripe and its service providers may process information in the United States and other locations under the applicable Stripe terms and transfer safeguards. Stripe may act independently for certain payment, compliance, and fraud functions and is not characterized as Posto's processor for every activity.

Mercury and its banking and payment partners

Functions: recipient onboarding for eligible Developers, collection of ACH and tax-document details through the provider, supplier-payment requests and approval, and approved payments from Posto's business account.

Information: Developer legal or business name, work email, recipient and payment identifiers, amounts, status, and payment memos; banking details and tax documentation are submitted directly to the provider. Posto does not store full bank-account numbers or tax-form copies from this flow.

Locations and role: Mercury, its partner banks, and disclosed service providers use locations and safeguards governed by their applicable services. Banking and legally required compliance activities may be independent of Posto's instructions; the description of the payment flow does not make every participant a Posto subprocessor.

Third-party AI service providers

Functions: enabled advertising, product and campaign assistance, content generation, and Customer support services. The applicable feature determines the permitted purpose and information submitted.

Information: permitted interaction text; product, campaign, creative, and performance information; Customer questions; and relevant account context. Submitted information may remain personal information, and some inputs are not filtered for identifiers before reaching a provider. Customer shall not include prohibited sensitive information. The use of a provider does not authorize unrelated disclosure, profiling, or model training by Posto.

Provider details and terms: current identities, relevant processing locations, and the information needed for an applicable DPA or transfer assessment are made available to affected Customers through the account process or legal@postoconnect.com before relevant processing where required. The applicable provider agreement and actual service configuration govern retention, support access, onward transfers, and any restrictions on provider use. This public category summary does not establish zero retention, exclusive United States processing, or a blanket restriction applicable to every provider account.

Google LLC

Functions: Google Play Integrity verification for supported Android requests. Any separate AI service falls within the third-party AI provider category above.

Information: integrity tokens, request hashes, registered application identity, and verification verdicts needed for the integrity function.

Locations and terms: the applicable verification-service terms and infrastructure govern processing, support, and any transfer safeguards.

Apple Inc.

Functions: Apple App Attest proof and verification for supported iOS application and device-integrity checks.

Information: App Attest key identifiers, challenges, assertions, counters, and registered Team ID and Bundle ID, together with applicable request-verification information. Posto's ad-request interface does not require a Customer-supplied advertising identifier or hardware serial number.

Locations and role: the applicable Apple service terms and infrastructure govern verification and related processing, including any processing outside the United States. Technical proofs and installation-linked information may remain personal information even though an advertising identifier is not required.

Advertisers, destinations, and affiliate partners

The Advertiser and destination selected after an End User's intentional click are data recipients for that activity, rather than Posto subprocessors solely because they receive the click. Posto may send the selected destination a pseudonymous click identifier needed for redirect and attribution. The destination may collect subsequent browsing and transaction information under its own privacy notice and applicable obligations.

Affiliate networks that carry shopping-card links to retailers, such as Awin, CJ, FlexOffers, impact.com, or Rakuten Advertising, are independent recipients of the tap, the publishing app, placement, and content identifiers in their tracking links, and resulting commission information, once Posto participates in the network's program. They are not Posto subprocessors; each processes that information under its own terms and notice.

Affiliate integrations, including Trip.com, are production-disabled unless expressly enabled and disclosed for the applicable campaign. An enabled affiliate relationship requires the advertising and material-connection disclosures applicable to that experience. Posto does not disclose ad-request transcripts to Advertisers through ordinary campaign reporting.

Contact and due-diligence information

Legal notices and questions about enabled providers, processing locations, relevant safeguards, change notices, or data-protection objections may be sent to legal@postoconnect.com. Posto shall provide information required for an applicable processor or transfer assessment through the DPA process; a Customer shall arrange any required restricted-transfer terms before introducing the affected processing.

© PostoX, Inclegal@postoconnect.com