Privacy Policy
The information Posto receives, the purposes for which it is processed, and the choices available to individuals who interact with Posto or its advertising services.
Effective 2026-09-07 · Version 2026-09-07-r2 · Permanent version
1. Scope and processing roles
PostoX, Inc ('Posto') operates the Posto websites, advertising platform, software development kits (SDKs), application programming interfaces (APIs), and related services. This Policy covers visitors, account representatives, support correspondents, and individuals whose information reaches Posto through a participating application, advertisement, connected store, or measurement integration.
A Customer is a business entity or sole proprietor using the services. An Advertiser is a Customer purchasing or managing advertising; a Developer or Publisher is a Customer supplying an application, property, or advertising placement. An Authorized User acts for a Customer. An End User uses a participating application, visits an advertised destination, or interacts with an advertisement. These roles do not, by themselves, determine an individual's legal privacy rights.
Posto determines the purposes and means of processing for its account administration, billing, business records, legal compliance, and independently determined security and fraud-prevention activities, to the extent permitted by applicable law. Posto acts as a processor, service provider, or subprocessor only for activities actually carried out on a Customer's documented instructions and satisfying the applicable legal requirements. Contextual delivery and measurement may involve both types of activity. The Data Processing Addendum (DPA) governs processing on behalf of a Customer; this Policy describes Posto's information practices.
This Policy provides notice. Acknowledging it or accepting a business agreement does not supply every consent required for personal-data processing, authorize undisclosed collection, or waive an individual's rights. The party responsible for a particular activity shall obtain any specific consent or other lawful permission that activity requires.
2. Categories of information
Posto receives the following categories when the corresponding service or integration is used. Examples within each category are illustrative, including without limitation the listed fields; they do not authorize collection outside the disclosed categories or purposes. Optional features do not transmit information merely because integration code is available.
- Account and business records: names, work email addresses, company or sole-proprietor details, business role, website, verification information, account status, communications, and records of contract acceptance or privacy choices.
- Advertising and catalog content: campaign instructions, budgets, bids, products, descriptions, images, creatives, targeting constraints, availability, delivery settings, and performance. Connected-store imports can include draft, archived, or unlisted products and their images and metadata; importing content is distinct from authorizing its publication in an advertisement.
- Developer and application records: application and placement configuration, registered domains and app identifiers, SDK versions, credentials, integrity-verification results, and integration diagnostics.
- Ad-request context: recent interaction text and optional permitted age range, gender, and coarse country, region, or city supplied by the Developer within the applicable integration limits. Input filtering reduces certain identifiers but may leave personal information or sensitive inferences.
- Delivery and interaction records: request, auction, candidate, impression, click, redirect, conversion, event time, and technical metadata; signed tracking tokens; and optional browser Pixel events from an Advertiser's verified domain.
- Advertiser measurement events: event name and time, source URL, deduplication identifier, Posto click ID, transaction ID, value and currency where applicable, and supported optional email, phone, client, or user identifiers. Accepted identifiers are normalized and hashed before persistence in the event records; transient receipt precedes that processing. Hashes and click identifiers remain potentially personal information.
- Shopify connection and commerce records: store domain, encrypted access credentials, imported product content and metadata, order and refund webhook information, order ID, checkout token, totals, currency, payment/refund/cancellation status, and attribution identifiers. Incoming Shopify payloads can transiently include customer details or line items beyond the fields retained for Posto's processing. Posto selects the fields needed for catalog, connection, attribution, and reconciliation records rather than retaining an unrestricted copy of each customer record.
- Browser and device information: session and security state, browser technical information, a standalone Pixel client identifier, a stored Posto click identifier, and page URLs. Depending on the integration, URLs may include query parameters or fragments and can contain information entered by the merchant or visitor.
- Security and fraud records: network and user-agent information received with requests, stored hashes, request velocity, HMAC verification, Apple App Attest or Google Play Integrity proofs and verdicts, risk reasons, and investigation records. The ad-request interface does not require a Customer-supplied hardware serial number or advertising identifier.
- Payments and payouts: business and transaction details, payment and payout status, disputes, recipient references, and reconciliation records. Card, bank, and tax-document details submitted directly to payment or banking providers are handled by those providers; Posto does not store full card or bank-account numbers through the described flows.
- Support and operational communications: questions, messages, supplied attachments or content, survey responses, website logs, and visible account context used to answer a request. Questions and account context sent to an assisted support feature may contain personal information.
3. Sources of information
Information comes from individuals and their Authorized Users; Customers and their applications, storefronts, servers, or measurement partners; browsers and devices interacting with enabled integrations; Shopify and other connected services; payment, cloud, email, integrity-verification, and model providers; and records generated when Posto operates the services. Posto may derive attribution, intent, risk, and performance information from these sources. Derived information is not automatically anonymous.
4. Purposes of processing
Posto uses information for the following disclosed purposes, subject to the applicable agreement, processing role, and law. A general reference to operating or improving a service does not permit unrelated use of Customer Personal Data.
- Provide and authenticate accounts, integrations, catalog imports, creative workflows, support, and the contracted advertising services.
- Match eligible advertisements to the context supplied for a request and apply configured category, language, location, price, audience, and safety constraints.
- Run auctions, pace budgets, record delivery, deduplicate events, attribute conversions, reconcile cancellations and refunds, and produce Customer reports.
- Detect invalid traffic, compromised integrations, replay, abuse, fraudulent conversions, payment discrepancies, and improper payouts, and investigate or resolve those issues.
- Communicate about accounts, send transactional messages, process payments and supplier payouts, maintain financial and acceptance records, comply with legal obligations, and establish or defend legal claims.
- Assess and improve the reliability and performance of the contracted services within the applicable processing permissions, and prepare aggregate or deidentified statistics subject to the safeguards described in this Policy.
5. Contextual matching and automated systems
Posto uses the permitted interaction context and applicable campaign or audience constraints to select eligible advertisements. Enabled automated assistance may also process submitted product, campaign, creative, or support information for the corresponding Service purpose. Third-party AI service providers may process information needed for these functions, subject to the applicable processing restrictions and provider arrangements.
Automated systems select and price advertisements, assess traffic and event validity, and assist campaign and support workflows. They are not offered for decisions about an End User's eligibility for employment, credit, housing, insurance, health care, or other opportunities producing legal or similarly significant effects. Customers shall not repurpose the services for such decisions. Campaign suggestions and generated content require the Customer's review before use where the workflow calls for approval.
Sensitive conversations are prohibited inputs. Input filters and other safeguards have limitations; they do not establish that every sensitive context will be detected or suppressed. The absence of a direct identifier does not make interaction text or an inferred characteristic anonymous.
6. Recipients and disclosures
Posto discloses information needed for the relevant purpose to its service providers and, where applicable, independent providers: hosting, storage, email, support, AI, payment, banking, and integrity-verification services. Relevant information may include permitted interaction text, product or campaign materials, Customer questions and account context for support, and app-integrity proofs. The public Subprocessors disclosure summarizes provider categories and selected providers. Current provider identities, locations, and other details needed for an applicable processing agreement are made available to affected Customers through the account or privacy-contact process before the relevant processing where required. A provider's legal role depends on the activity and its applicable agreement.
The relevant Advertiser or Developer receives campaign, delivery, attributed performance, and settlement information for its business relationship. Posto does not make submitted ad-request transcripts available to Advertisers as part of campaign reporting. After an intentional advertisement click, Posto may transmit a pseudonymous click identifier to the selected destination for redirect and attribution. A destination may independently collect browsing or transaction information under its own notice.
Posto may disclose relevant information to professional advisers, prospective or actual transaction counterparties subject to appropriate confidentiality arrangements, courts, regulators, or other authorities when reasonably necessary for a transaction, legal obligation, lawful request, or protection of rights, security, and safety. These examples do not permit unlimited disclosure.
Posto's described service is contextual advertising and Customer measurement. Posto does not sell personal information or share it for cross-context behavioral advertising in the described processing, or combine optional demographics into unrelated profiles. A Customer shall not configure an integration to introduce such processing without the required assessment, disclosures, contractual arrangement, and controls.
7. Retention, deletion, and deidentification
Retention depends on the record's purpose. Removal of a direct identifier is not necessarily deletion or anonymization: financial references, hashes, tokens, and other residual records may remain linkable and are treated accordingly. Scheduled deletion and browser storage are separate processes.
- Ad-request text and related original or derived text retained as delivery or diagnostic copies are removed under the applicable 30-day retention schedule and may be deleted earlier. Structured categories and numeric measures, event identities, hashes, risk outcomes, and permitted aggregates may remain for their separate documented purposes; their retention does not authorize reconstructing deleted conversations.
- Raw advertiser event payloads and diagnostics are scheduled for removal after 30 days, including source URLs and the event-row copies of click/deduplication values and optional identifier hashes. Event identity, validation and attribution outcomes, payload hashes, durable deduplication evidence, canonical conversions, and necessary financial or fraud records may remain.
- Raw traffic-risk records are retained for 30 days, with aggregated risk and velocity information retained for 180 days. Non-billable SDK test request records and tokens are retained for 7 days. Account action tokens are removed after use or expiry through maintenance.
- Account information is maintained during the active relationship and the 30-day account-closure grace period. Closure then removes or pseudonymizes account data through the closure process; it is not a promise that every record becomes anonymous or is immediately erased. Financial, settlement, tax, contract-acceptance, confirmed fraud, and legal records may be retained for up to 7 years, or longer when a legal requirement or active dispute requires retention.
- Shopify privacy requests and store disconnection are handled according to their respective purposes and applicable requirements. Erasing shopper-related information does not by itself delete merchant-owned catalog assets, campaign content, or every business record. Store disconnection and account closure have different effects; required financial and legal records may remain with access and use restricted.
- The standalone browser Pixel's persistent client identifier has no automatic expiration in its local-storage implementation. Its locally stored Posto click identifier is subject to a 30-day validity period. Browser clearing, site storage settings, the merchant's consent implementation, and an applicable deletion request can affect these values. The server's 30-day event retention does not automatically clear a browser's storage.
- Other catalog, support, connection, security, and operational information is kept for the period reasonably necessary for the applicable service, support, security, or legal purpose. Backup records are protected from ordinary use and removed through the applicable backup cycle or required deletion process; a legal hold may require restricted preservation.
8. Security and limits of safeguards
Posto maintains safeguards appropriate to the nature and risk of the processing, including applicable transport encryption, access restrictions, credential isolation, signed requests, integrity checks, idempotency controls, logging, and operational recovery procedures. Their applicability depends on the service and integration. No filter, authentication measure, or storage system guarantees complete security or the removal of all personal information. Suspected security incidents shall be reported promptly to security@postoconnect.com.
Posto treats statistics as deidentified only where the applicable legal standard is satisfied. Posto shall take reasonable measures against association with an individual, maintain deidentified data in that form, refrain from attempting reidentification except where law permits validation of deidentification, and impose required restrictions on recipients. Information that remains reasonably linkable is subject to the safeguards and rights applicable to personal information.
9. United States service and international processing
Posto presently offers a United States business service. Information may nevertheless be processed by providers in other countries, and a provider's support, infrastructure, or subprocessors may involve additional locations. The Subprocessors disclosure does not establish a blanket United States-only processing commitment.
Before a Customer introduces an integration or transfer requiring an additional international data-protection arrangement, the Customer shall contact legal@postoconnect.com. Posto and the Customer shall establish the applicable lawful transfer mechanism and safeguards before carrying out a restricted transfer. This Policy does not itself complete European Standard Contractual Clauses, a UK transfer addendum, or a certification under a data-transfer framework. Applicable rights are not lost because the service is offered primarily in the United States.
10. Individual rights and requests
Individuals in the United States may ask Posto to confirm processing and request access, correction, deletion, and a portable copy. Depending on applicable law and Posto's role, additional rights may include obtaining information about recipients, opting out of sale, sharing, targeted advertising or covered profiling, limiting covered uses of sensitive information, using an authorized agent, and appealing a denied request. Requests and appeals may be sent directly to legal@postoconnect.com without creating an account or accepting new contractual terms.
California residents may exercise applicable rights to know, correct, delete, opt out of sale or sharing, and limit covered uses of sensitive personal information. Delaware residents may exercise applicable access, correction, deletion, portability, recipient-information, opt-out, and appeal rights. Scope, verification, exceptions, and response periods depend on the applicable law; business representatives do not necessarily have the same statutory coverage in every state. Posto shall not unlawfully discriminate against an individual for exercising a privacy right.
An End User may contact the relevant Developer or Advertiser, particularly where that business controls the information and Posto acts on its instructions. Contacting that business first is not a condition of contacting Posto or exercising a statutory right. Posto shall assist the responsible Customer or respond as its role and the law require. Posto may seek proportionate verification or information needed to locate records, explain an exception or denial, and provide the applicable appeal route and legally required response within the required period.
Authorized account representatives can use the account export and closure controls for records available through those tools. A tool's scope does not restrict other lawful requests. Posto shall honor legally binding opt-out signals, including Global Privacy Control where applicable, for processing covered by those signals. The absence of a current sale, sharing, or targeted-advertising activity does not waive rights if practices change.
11. Cookies, browser storage, and preferences
The Posto website uses session and security technologies for authentication, request integrity, and essential account state. The standalone Advertiser Pixel is a separate measurement integration: it can use persistent browser storage, transmit page URLs and events, and associate a stored client identifier or Posto click identifier with those events. It shall be installed only on the Advertiser's verified domains and subject to that Advertiser's lawful notices and choices.
The standalone Pixel does not supply a universal consent-management interface or automatically establish that a visitor has consented. The Advertiser shall gate loading, storage, and transmission when consent or an opt-out requires it, avoid sensitive information in transmitted URLs, and implement withdrawal or preference handling. The Shopify web-pixel integration uses Shopify's customer-privacy controls; those controls do not automatically govern a separate standalone Pixel installation.
Posto does not use website activity across unaffiliated services to build the behavioral advertising profiles excluded by the described service. The legacy Do Not Track browser setting does not alter essential website operation; legally binding universal opt-out mechanisms are handled according to the law applicable to the processing. Browser settings can clear or restrict local storage, but server-side rights requests may still be needed.
12. Children and prohibited sensitive information
Individual account holders and Authorized Users shall be at least 18. Posto is not directed to children and does not approve production integrations in child-directed properties. An account's adult-use requirement does not establish the age of an application's End Users or relieve a Customer of its children's-privacy duties.
Customers shall not submit children's personal information, health or crisis conversations, protected health information, precise geolocation, financial-account credentials, payment-card data, authentication secrets, biometric identifiers, government identifiers, or other legally sensitive information through ad-request or measurement interfaces. Customers shall assess their actual audience and inputs rather than relying on identifier filtering or a general acceptance checkbox.
A Customer considering a service that could involve those audiences or categories shall contact legal@postoconnect.com before integration. If prohibited information is sent inadvertently, the Customer shall promptly stop the affected submission and cooperate with Posto on containment, appropriate deletion, and any required notification. These restrictions and the contractual allocation of responsibility do not eliminate Posto's own legal obligations or an individual's nonwaivable rights.
13. Changes and contact
Posto shall publish an updated effective date when this Policy changes and provide additional notice or obtain specific consent where required before materially different processing begins. A revised Policy does not retroactively authorize an undisclosed use or change a contractual obligation without the applicable agreement process.
The operator is PostoX, Inc. Contact address: 131 Continental Drive Suite 305, Newark, DE 19702. Legal notices, privacy questions, data-rights requests, and appeals: legal@postoconnect.com. Security reports: security@postoconnect.com.